Skip to content

Commit 4561902

Browse files
authored
doc: add 2025-05-08 meeting minutes (#1476)
1 parent 1b56285 commit 4561902

File tree

1 file changed

+60
-0
lines changed

1 file changed

+60
-0
lines changed

meetings/2025-05-08.md

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
# Node.js Security team Meeting 2025-05-08
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=XIoC0l7QOeA
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1475
7+
8+
## Present
9+
10+
* Rafael Gonzaga (@RafaelGSS)
11+
* Michael Dawson (@mhdawson)
12+
* Marco Ippolito (@marco-ippolito)
13+
* Robert W
14+
15+
## Agenda
16+
17+
## Announcements
18+
19+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
20+
21+
- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
22+
* nothing new this week
23+
24+
- [X] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
25+
* No update this week
26+
27+
### nodejs/node
28+
29+
* src: add WDAC integration (Windows) [#54364](https://github.com/nodejs/node/pull/54364)
30+
* some discussion, nearing ready to get reviewers to re-review after addressing comments.
31+
32+
### nodejs/security-wg
33+
34+
* Review Code Scanning Alerts [#1453](https://github.com/nodejs/security-wg/issues/1453)
35+
* We spent some time to go through the report to decide what to do with some of them
36+
37+
* Update on CVEs for EOL Release Lines – MITRE Removal & Next Steps #1443
38+
* We are waiting for the HackerOne team to update the list of CVEs
39+
40+
* OpenJS Security Compliance Checker #1440
41+
* Defer this discussion to talk with Ulises so he can propagate our thoughts to OpenSSF.
42+
43+
* Node.js maintainers: Threat Model [#1333](https://github.com/nodejs/security-wg/issues/1333)
44+
* Most of the table has been migrated to https://github.com/nodejs/security-wg/blob/main/MAINTAINERS_THREAT_MODEL.md
45+
* Discussed next step which we will do in the next meeting
46+
47+
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
48+
* [MD] updating Amaro build is still on my list, just not at the top yet
49+
50+
* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
51+
* Closing as completed
52+
53+
## Q&A, Other
54+
55+
## Upcoming Meetings
56+
57+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
58+
59+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
60+

0 commit comments

Comments
 (0)