Skip to content

Commit e06ed22

Browse files
authored
docs: meeting notes for 2024-10-24 (#1397)
1 parent e170d68 commit e06ed22

File tree

1 file changed

+50
-0
lines changed

1 file changed

+50
-0
lines changed

meetings/2024-10-24.md

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# Node.js Security team Meeting 2024-10-24
2+
3+
## Links
4+
5+
* **Recording**:
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1396
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/1IzdqODrouMHFXZiEpTkW74QBNyA123d1vFgEafnv4aw/edit?tab=t.0
8+
9+
## Present
10+
11+
* Michael Dawson (@mhdawson)
12+
* Marco Ippolito (@marco-ippolito)
13+
* Ulises Gascón (@UlisesGascon)
14+
15+
16+
## Agenda
17+
18+
## Announcements
19+
20+
* Ulises - is-my-node-vulnerable, work to move over to Node.js org - https://github.com/RafaelGSS/is-my-node-vulnerable
21+
22+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
23+
24+
- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
25+
* No new issues
26+
- [x] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
27+
* It will happen after the meeting
28+
29+
* Audit build process for dependencies [1037](https://github.com/nodejs/security-wg/issues/1037)
30+
* Michael made a great progress (using already containers)
31+
* Expected to start open PRs soon
32+
* Abort when vulnerable flag [852](https://github.com/nodejs/security-wg/issues/852)
33+
* Probably this will be moved to a separate repo (TBC)
34+
* Automate security release process [860](https://github.com/nodejs/security-wg/issues/860)
35+
* no updates this week
36+
* Skipped working on the threat model this week as we only had 2 people
37+
38+
## Q&A, Other
39+
40+
* security guidelines being developed in OpenJS collaboration space https://github.com/openjs-foundation/security-collab-space/issues/211
41+
* Would be good to apply to the Node.js project and see how it works/does not and provide
42+
Feedback.
43+
44+
45+
## Upcoming Meetings
46+
47+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
48+
49+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
50+

0 commit comments

Comments
 (0)