-
Notifications
You must be signed in to change notification settings - Fork 122
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
doc: add 2024-03-14 meeting notes (#1251)
* doc: add 2024-03-14 meeting notes * Update 2024-03-14.md
- Loading branch information
Showing
1 changed file
with
48 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,48 @@ | ||
# Node.js Security team Meeting 2024-03-14 | ||
|
||
## Links | ||
|
||
* **Recording**: https://www.youtube.com/watch?v=FfonqliWfhY&ab_channel=node.js | ||
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1245 | ||
* **Minutes Google Doc**: https://docs.google.com/document/d/1eNytfV8Xm0x_K4ajb7kgLlw_9SnjE4hmLhydLD5u0-M/edit | ||
|
||
## Present | ||
|
||
* Michael Dawson: @mhdawson | ||
* Rafael Gonzaga: @RafaelGSS | ||
* Marco Ippolito: @marco-ippolito | ||
|
||
## Agenda | ||
|
||
## Announcements | ||
|
||
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting. | ||
|
||
- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues | ||
- Check the rate limit | ||
|
||
- [X] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+ | ||
* Propose to talk about it only when it really matters (significant updates) | ||
|
||
### nodejs/security-wg | ||
|
||
* Proposed approach for build steps in deps which are not in make node [#1236](https://github.com/nodejs/security-wg/issues/1236) | ||
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037) | ||
|
||
* Security initiative in December 2023: fuzzing Nodejs: https://github.com/google/oss-fuzz/tree/master/projects/nodejs [#1159](https://github.com/nodejs/security-wg/issues/1159) | ||
* waiting to get issue in H1 with full report. | ||
|
||
* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953) | ||
* work with Ulises to submit the report and see what’s the next steps (if we don’t get the gold badge) | ||
|
||
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898) | ||
* no updates | ||
|
||
## Q&A, Other | ||
|
||
## Upcoming Meetings | ||
|
||
* **Node.js Project Calendar**: <https://nodejs.org/calendar> | ||
|
||
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar. | ||
|