Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

doc: add 2024-09-12 meeting notes #1380

Merged
merged 2 commits into from
Sep 25, 2024
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 60 additions & 0 deletions meetings/2024-09-12.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# Node.js Security team Meeting 2024-09-12

## Links

* **Recording**: https://www.youtube.com/watch?v=9xrNEZPBFD0
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1375
* **Minutes Google Doc**: https://docs.google.com/document/d/1eGBJFVcCE6pfRoWoBRjIgwehPl0SzxiNG70YiYeJw68/edit

## Present

* Security wg team: @nodejs/security-wg
* Thomas GENTILHOMME: @fraxken
* Marco Ippolito: @marco-ippolito
* Rafael Gonzaga: @RafaelGSS
* Michael Dawson: @mhdawson

RafaelGSS marked this conversation as resolved.
Show resolved Hide resolved
## Agenda

## Announcements

*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.

* Express v5 came with security fixes to body-parser plugin
* Node.js vulnerability database now includes a severity field
* https://github.com/nodejs/nodejs-cve-checker - Rafael will double check if the scheduled CVE were now published

- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
- V8 backport to Node.js v18 is unlikely to happen as there’s a risk to break users in general
- [X] OpenSSF Scorecard Monitor Review
- No action is needed from our side. PR: https://github.com/nodejs/security-wg/pull/1378

### nodejs/node

* src: add WDAC integration (Windows) [#54364](https://github.com/nodejs/node/pull/54364)
* no action this week

### nodejs/security-wg

* Node.js maintainers: Threat Model [#1333](https://github.com/nodejs/security-wg/issues/1333)
* Team effort to fill all fields of access-per-group
* Rafael will open a PR to TSC to ask for feedback
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
* no action this week

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
* no action this week
* https://github.com/nodejs/node-core-utils/pull/835 this PR automates promotion step


## Q&A, Other
@Ulises: Let’s review https://github.com/nodejs/nodejs.org/pull/6979 (alternative: https://github.com/nodejs/nodejs.org/pull/7034)



## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

Loading