Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Write first draft of responsible security reporting guidelines for OpenJS Foundation #589

Closed
mhdawson opened this issue Oct 8, 2019 · 21 comments
Labels

Comments

@mhdawson
Copy link
Member

mhdawson commented Oct 8, 2019

Based on openjs-foundation/cross-project-council#326 we are looking for a volunteer to write the first version of the security reporting guidelines, following the https://github.com/openjs-foundation/cross-project-council/blob/master/STAGING_PROCESS.md to make the proposal.

Ideally the work would be:

  1. review the reporting procedures (or gap) for existing member projects
  2. Propose a first draft of guidelines that would apply for member projects. It might be different based on level of project (For example may be required for Impact project, optional for add-hoc)
  3. Consider and recommend whether the OpenJS foundation should offer support in satisfying the guidelines
@mhdawson
Copy link
Member Author

mhdawson commented Oct 8, 2019

@nodejs/security-wg any volunteers?

@MarcinHoppe
Copy link
Contributor

I could devote some time for it starting next week, I think this is in line with what I wanted to propose for nodejs/package-maintenance#159.

@mhdawson
Copy link
Member Author

@MarcinHoppe thanks !

@mhdawson
Copy link
Member Author

@MarcinHoppe I'm wondering if you think you'll still have time to get to this.

@MarcinHoppe
Copy link
Contributor

MarcinHoppe commented Oct 29, 2019

Thanks for a reminder! I actually have a draft that I need to put in a PR and start the discussion. I will do my best to wrap it up by the end of this week.

@SomeoneWeird
Copy link
Member

Very keen on helping with this one - let me know if you want any help @MarcinHoppe

@MarcinHoppe
Copy link
Contributor

@SomeoneWeird amazing! I should have a PR up soon.

@MarcinHoppe
Copy link
Contributor

@mhdawson @SomeoneWeird I put together a draft PR under the Package Maintenance WG and I'd love to know if you think we could re-use this somehow for the OpenJS Foundation guidelines?

The PR is: nodejs/package-maintenance#277.

@mhdawson
Copy link
Member Author

mhdawson commented Nov 1, 2019

@MarcinHoppe I think that is a good baseline. What I think we'd want to do for the OpenJS Foundation guidelines (ie scope of this issue) is to narrow down the choices to what we'd want to recommend for OpenJS projects (although maybe with options based on at-large, impact etc if that makes sense) and provide a recommend template for the policy itself.

@MarcinHoppe
Copy link
Contributor

Makes sense, thanks for clarification. Honestly I'd prefer for the discussion in Node.js Package Maintenance WG to take place first, and then we can extract guidance that we arrive at there (hopefully soon-ish) and apply it to OpenJS Foundation projects.

Does it sound like an acceptable course of action, or do you want to move faster with this issue?

@mhdawson
Copy link
Member Author

mhdawson commented Nov 4, 2019

@MarcinHoppe sounds good to me.

@MarcinHoppe
Copy link
Contributor

@mhdawson I feel that nodejs/package-maintenance#277 is close to landing. Would now be an appropriate time to engage with the OpenJS Foundation to draft the security reporting guidelines?

@mhdawson
Copy link
Member Author

mhdawson commented Jan 6, 2020

@MarcinHoppe yes, I had commented on #277 since it landed. Are you able to take a first cut or do you think we need to gather info/feedback first?

@MarcinHoppe
Copy link
Contributor

MarcinHoppe commented Jan 7, 2020

Yes. I need to familiarize myself a bit more with OpenJSF projects and processes first, but I would definitely like to put together an initial proposal and kick off the discussion.

@mhdawson
Copy link
Member Author

mhdawson commented Jan 9, 2020

Ok sounds good. Let me know if you need any help or are want me to co-ordinate getting more input on the first cut.

@joesepi
Copy link
Member

joesepi commented Jan 21, 2020

Thanks @MarcinHoppe for your work on this issue. As @mhdawson says, if we at the OpenJSF/Cross Project Council can help in any way (context, content, etc) just let us know! 🎉

@MarcinHoppe
Copy link
Contributor

I actually do have an idea where your assistance might be helpful. I will reach out on Slack.

@fraxken
Copy link
Member

fraxken commented Jul 18, 2022

👋 Is the subject still relevant? I see that some work has been done on the OpenJS side but I have trouble understanding everything.

I remember we add some Responsible Disclosure Policy here but I think it was deleted with the end of the HackerOne program: 1393717

@lirantal
Copy link
Member

It isn't relevant to the Node.js ecosystem program because that's been retired, but the broader security reporting guideline for projects under the OpenJS Foundation would be useful (so other projects can apply it if they would want to opt-in for being the source for disclosures).

@mhdawson
Copy link
Member Author

I suggest that this be closed here, but put on to the agenda for the security collaboration space @joesepi is spinning up under the OpenJS Foundation.

@github-actions
Copy link
Contributor

This issue is stale because it has been open many days with no activity. It will be closed soon unless the stale label is removed or a comment is made.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

6 participants