File tree Expand file tree Collapse file tree 1 file changed +45
-0
lines changed
Expand file tree Collapse file tree 1 file changed +45
-0
lines changed Original file line number Diff line number Diff line change 1+ # Node.js Security team Meeting 2024-11-21
2+
3+ ## Links
4+
5+ * ** Recording** : https://www.youtube.com/watch?v=lo_bzAYU7Bs
6+ * ** GitHub Issue** : https://github.com/nodejs/security-wg/issues/1400
7+
8+ ## Present
9+
10+ * Michael Dawson (@mhdawson )
11+ * Ulises Gascon (@ulisesGascon )
12+ * Marco Ippolito (@marco-ippolito )
13+ * Richard Lau (@richardlau )
14+
15+
16+ ## Announcements
17+
18+ _ N/A_
19+
20+ ## Agenda
21+
22+ - [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
23+ * Nothing new this time
24+ - [x] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
25+ * https://github.com/nodejs/security-wg/pull/1405
26+ * Nothing to discuss this week.
27+ - Add a warning on EOL versions [ security-wg-agenda] ( https://github.com/nodejs/security-wg/issues/1401 )
28+ * general agreement from those in the meeting that a single CVE on EOL is a good idea
29+ * Ulises will get some feedback form those in the OpenJS Security Collaboration space
30+ * we should probably also share as a proposal with the TSC
31+ - Node.js maintainers: Threat Model [ 1333] ( https://github.com/nodejs/security-wg/issues/1333 )
32+ * We were working in the modeling (mostly CI related vectors)
33+ * We map some new potential threats like comms channels (added in a new section in the document)
34+ * Working document: https://hackmd.io/@M_jNX2MrSVuhJwhDnKOLHg/Hk-E22bLA/edit
35+
36+ ## Q&A, Other
37+
38+ _ N/A_
39+
40+ ## Upcoming Meetings
41+
42+ * ** Node.js Project Calendar** : < https://nodejs.org/calendar >
43+
44+ Click ` +GoogleCalendar ` at the bottom right to add to your own Google calendar.
45+
You can’t perform that action at this time.
0 commit comments