Skip to content

Commit e1aca29

Browse files
authored
doc: add 2025-06-05 meeting notes (#1490)
1 parent c3c6e17 commit e1aca29

File tree

1 file changed

+62
-0
lines changed

1 file changed

+62
-0
lines changed

meetings/2025-06-05.md

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
# Node.js Security team Meeting 2025-06-05
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=x0KMcmXM42k
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1487
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/1mKs0C0bE9nLbzsOI7b0Mg4ZoZgdPSPxlYW83MddZ6yk/edit?tab=t.0
8+
9+
## Present
10+
11+
* Security wg team: @nodejs/security-wg
12+
13+
* Rafael Gonzaga: @RafaelGSS
14+
* Ulises Gascón: @UlisesGascon
15+
* Michael Dawson: @mhdawson
16+
* Marco Ippolito: @marco-ippolito
17+
* Richard Lau: @richardlau
18+
* Elves Viera
19+
* Jean Pierre
20+
21+
## Agenda
22+
23+
## Announcements
24+
25+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
26+
27+
- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
28+
* No new issues
29+
30+
- [X] OpenSSF Scorecard Monitor Review
31+
- No additional work is required from the team (1m period) https://github.com/nodejs/security-wg/pull/1489#pullrequestreview-2900462698
32+
33+
34+
### nodejs/node
35+
36+
* src: add WDAC integration (Windows) [#54364](https://github.com/nodejs/node/pull/54364)
37+
* LGTM from code perspective
38+
* Asking for a review from Yagiz and James, who previously requested changes on this PR.
39+
* Rafael will see this in action on a Windows machine, setting some WDAC policies
40+
* Michael will take a look at the PR as well
41+
42+
### nodejs/security-wg
43+
44+
* Wrong CVE Creation - May 14th Security Releases https://github.com/nodejs/security-wg/issues/1483
45+
* Thanks to H1 for their help; all CVEs were resolved
46+
* We need to align with them to see if the recent changes in their UI also reflect in the API.
47+
48+
* Review Code Scanning Alerts #1453
49+
* We have reviewed some alerts and wrote a set of rules: https://github.com/nodejs/security-wg/issues/1453#issuecomment-2944902765
50+
51+
* Update on CVEs for EOL Release Lines – MITRE Removal & Next Steps [#1443](https://github.com/nodejs/security-wg/issues/1443)
52+
* Node.js maintainers: Threat Model [#1333](https://github.com/nodejs/security-wg/issues/1333)
53+
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
54+
55+
## Q&A, Other
56+
57+
## Upcoming Meetings
58+
59+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
60+
61+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
62+

0 commit comments

Comments
 (0)