File tree Expand file tree Collapse file tree 1 file changed +50
-0
lines changed
Expand file tree Collapse file tree 1 file changed +50
-0
lines changed Original file line number Diff line number Diff line change 1+ # Node.js Security team Meeting 2024-10-24
2+
3+ ## Links
4+
5+ * ** Recording** :
6+ * ** GitHub Issue** : https://github.com/nodejs/security-wg/issues/1396
7+ * ** Minutes Google Doc** : https://docs.google.com/document/d/1IzdqODrouMHFXZiEpTkW74QBNyA123d1vFgEafnv4aw/edit?tab=t.0
8+
9+ ## Present
10+
11+ * Michael Dawson (@mhdawson )
12+ * Marco Ippolito (@marco-ippolito )
13+ * Ulises Gascón (@UlisesGascon )
14+
15+
16+ ## Agenda
17+
18+ ## Announcements
19+
20+ * Ulises - is-my-node-vulnerable, work to move over to Node.js org - https://github.com/RafaelGSS/is-my-node-vulnerable
21+
22+ * Extracted from ** security-wg-agenda** labelled issues and pull requests from the ** nodejs org** prior to the meeting.
23+
24+ - [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
25+ * No new issues
26+ - [x] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
27+ * It will happen after the meeting
28+
29+ * Audit build process for dependencies [ 1037] ( https://github.com/nodejs/security-wg/issues/1037 )
30+ * Michael made a great progress (using already containers)
31+ * Expected to start open PRs soon
32+ * Abort when vulnerable flag [ 852] ( https://github.com/nodejs/security-wg/issues/852 )
33+ * Probably this will be moved to a separate repo (TBC)
34+ * Automate security release process [ 860] ( https://github.com/nodejs/security-wg/issues/860 )
35+ * no updates this week
36+ * Skipped working on the threat model this week as we only had 2 people
37+
38+ ## Q&A, Other
39+
40+ * security guidelines being developed in OpenJS collaboration space https://github.com/openjs-foundation/security-collab-space/issues/211
41+ * Would be good to apply to the Node.js project and see how it works/does not and provide
42+ Feedback.
43+
44+
45+ ## Upcoming Meetings
46+
47+ * ** Node.js Project Calendar** : < https://nodejs.org/calendar >
48+
49+ Click ` +GoogleCalendar ` at the bottom right to add to your own Google calendar.
50+
You can’t perform that action at this time.
0 commit comments