-
Notifications
You must be signed in to change notification settings - Fork 123
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
1 changed file
with
59 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,59 @@ | ||
# Node.js Security team Meeting 2024-07-18 | ||
|
||
## Links | ||
|
||
* **Recording**: https://www.youtube.com/watch?v=53lm-l1gMJA&ab_channel=node.js | ||
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1348 | ||
* **Minutes Google Doc**: https://docs.google.com/document/d/1h7FO8GIipJYrSbINeq3N0d28FZZok8sHIwmKnpvaTh0/edit | ||
|
||
## Present | ||
|
||
* Michael Dawson: @mhdawson | ||
* Ulises Gascón: @ulisesgascon | ||
* Rafael Gonzaga: @RafaelGSS | ||
* Marco Ippolito | ||
* Richard Lau | ||
|
||
## Agenda | ||
|
||
## Announcements | ||
|
||
* The OSSF Scorecard Monitor is now an official OSSF Tool. See: https://github.com/ossf/scorecard-monitor/issues/79 | ||
|
||
* Rafael, security release last week, please upgrade | ||
|
||
* Some CVE’s not yet published. - https://github.com/nodejs/nodejs-cve-checker | ||
|
||
*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting. | ||
|
||
- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues | ||
* Failure on nvd database side resolved | ||
* No new issues | ||
* CVEs from last security release were not published yet | ||
|
||
- [X] OpenSSF Scorecard Monitor Review - | ||
- PR: https://github.com/nodejs/security-wg/pull/1351 | ||
- Actions: in nodejs/node-addon-api there is a new workflow that can be improved (decrease 0.9), details: https://ossf.github.io/scorecard-visualizer/#/projects/github.com/nodejs/node-addon-api/compare/7e1aa06132558fcc3de4ef5f4f6b84ff10c32502/12ffe91b8f94c0b2491fcc5b15547a3ff23ceb07 | ||
|
||
### nodejs/security-wg | ||
|
||
* Automate security release process #860 | ||
* Rafael is working on git node security –finish | ||
* Tests added to security-release repository | ||
* Opened https://github.com/nodejs/node/pull/53877 | ||
|
||
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037) | ||
* Michael, still on my list to work on WASM building side of things, just have not managed to | ||
carve out time yet. | ||
|
||
* Node.js maintainers: Threat Model [#1333](https://github.com/nodejs/security-wg/issues/1333) | ||
* Working on Access per Group table | ||
|
||
## Q&A, Other | ||
|
||
## Upcoming Meetings | ||
|
||
* **Node.js Project Calendar**: <https://nodejs.org/calendar> | ||
|
||
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar. | ||
|