Skip to content

Commit 20440f4

Browse files
doc: add 2025-09-11 meeting notes (#1521)
* doc: add 2025-09-11 meeting notes * Update meetings/2025-09-11.md Co-authored-by: Ulises Gascón <[email protected]> --------- Co-authored-by: Ulises Gascón <[email protected]>
1 parent e00712e commit 20440f4

File tree

1 file changed

+57
-0
lines changed

1 file changed

+57
-0
lines changed

meetings/2025-09-11.md

Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
# Node.js Security team Meeting 2025-09-11
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=2_exLrhF5YM&ab_channel=node.js
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1518
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/1zPUOHww6WD9VtLoTeoMaPuoWeHi6_6uujHcVNG1SeF0/edit?tab=t.0
8+
9+
## Present
10+
11+
* Security wg team: @nodejs/security-wg
12+
13+
* Ulises Gascón: @UlisesGascon
14+
* Rafael Gonzaga: @RafaelGSS
15+
16+
## Agenda
17+
18+
## Announcements
19+
* A targeted campaign has emerged against npm package maintainers, where attackers are leveraging stolen authentication tokens to impersonate maintainers and publish malicious package versions: https://jfrog.com/blog/new-compromised-packages-in-largest-npm-attack-in-history/
20+
21+
22+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
23+
24+
- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
25+
- [X] OpenSSF Scorecard Monitor Review
26+
- No Action needed from our team. Last PR can be merged: https://github.com/nodejs/security-wg/pull/1520
27+
28+
### nodejs/node
29+
30+
* src: add WDAC integration (Windows) #54364
31+
* No updates
32+
33+
* Option to enable inspection mode along with permission model #48534
34+
* Rafael opened a PR to add –allow-inspector https://github.com/nodejs/node/pull/59711
35+
* Seems ready to go
36+
37+
### nodejs/security-wg
38+
39+
* Create a VEX file for Node.js #1517
40+
* Leaving that open for further discussion with Marco
41+
42+
* Update on CVEs for EOL Release Lines – MITRE Removal & Next Steps #1443
43+
* Closing as completed
44+
45+
* Node.js maintainers: Threat Model #1333
46+
* Closing as completed
47+
48+
## Q&A, Other
49+
50+
https://github.com/nodejs/node/pull/59806
51+
52+
## Upcoming Meetings
53+
54+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
55+
56+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
57+

0 commit comments

Comments
 (0)