You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
***Minutes Google Doc**: https://docs.google.com/document/d/1zPUOHww6WD9VtLoTeoMaPuoWeHi6_6uujHcVNG1SeF0/edit?tab=t.0
8
+
9
+
## Present
10
+
11
+
* Security wg team: @nodejs/security-wg
12
+
13
+
* Ulises Gascón: @UlisesGascon
14
+
* Rafael Gonzaga: @RafaelGSS
15
+
16
+
## Agenda
17
+
18
+
## Announcements
19
+
* A targeted campaign has emerged against npm package maintainers, where attackers are leveraging stolen authentication tokens to impersonate maintainers and publish malicious package versions: https://jfrog.com/blog/new-compromised-packages-in-largest-npm-attack-in-history/
20
+
21
+
22
+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
0 commit comments