Skip to content

Commit 2497544

Browse files
authored
docs: meeting notes for 2024-11-21 (#1406)
1 parent e1d50b1 commit 2497544

File tree

1 file changed

+45
-0
lines changed

1 file changed

+45
-0
lines changed

meetings/2024-11-21.md

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# Node.js Security team Meeting 2024-11-21
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=lo_bzAYU7Bs
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1400
7+
8+
## Present
9+
10+
* Michael Dawson (@mhdawson)
11+
* Ulises Gascon (@ulisesGascon)
12+
* Marco Ippolito (@marco-ippolito)
13+
* Richard Lau (@richardlau)
14+
15+
16+
## Announcements
17+
18+
_N/A_
19+
20+
## Agenda
21+
22+
- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
23+
* Nothing new this time
24+
- [x] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
25+
* https://github.com/nodejs/security-wg/pull/1405
26+
* Nothing to discuss this week.
27+
- Add a warning on EOL versions [security-wg-agenda](https://github.com/nodejs/security-wg/issues/1401)
28+
* general agreement from those in the meeting that a single CVE on EOL is a good idea
29+
* Ulises will get some feedback form those in the OpenJS Security Collaboration space
30+
* we should probably also share as a proposal with the TSC
31+
- Node.js maintainers: Threat Model [1333](https://github.com/nodejs/security-wg/issues/1333)
32+
* We were working in the modeling (mostly CI related vectors)
33+
* We map some new potential threats like comms channels (added in a new section in the document)
34+
* Working document: https://hackmd.io/@M_jNX2MrSVuhJwhDnKOLHg/Hk-E22bLA/edit
35+
36+
## Q&A, Other
37+
38+
_N/A_
39+
40+
## Upcoming Meetings
41+
42+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
43+
44+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
45+

0 commit comments

Comments
 (0)