Skip to content

Conversation

RafaelGSS
Copy link
Member

@RafaelGSS RafaelGSS requested a review from a team as a code owner August 19, 2025 16:33
@RafaelGSS
Copy link
Member Author

@bensternthal could you please add it to the agenda?

Copy link
Member

@bjohansebas bjohansebas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shouldn't this document reference https://github.com/openjs-foundation/cross-project-council/blob/main/PROJECT_SECURITY_REPORTING.md, with the new one you'r creating? Or could they be merged?

Copy link
Member

@UlisesGascon UlisesGascon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Regardless of the final location

@RafaelGSS
Copy link
Member Author

Shouldn't this document reference https://github.com/openjs-foundation/cross-project-council/blob/main/PROJECT_SECURITY_REPORTING.md, with the new one you'r creating? Or could they be merged?

That document seems too specific to vulnerability reporting; of course, they overlap as we must mention how to report vulnerabilities on SECURITY.md. In other words, I think they could be merged, yes, but it's not necessary.

@tobie
Copy link
Contributor

tobie commented Aug 22, 2025

To @bjohansebas's point above, shouldn't we structure this like we've structured CoC handling?

  • Suggest everyone adopts a SECURITY.md that's a one line that contains a link to https://security-policy.openjsf.org
  • https://security-policy.openjsf.org redirects to ./SECURITY.md on this repo.
  • Projects who wish to opt-in to manage security reports themselves have a few additional requirements and are listed at the top of this repo's ./SECURITY.md.

@RafaelGSS
Copy link
Member Author

We have briefly discussed this in the security-collab-space, and it seems there is an objection against those redirects. I don't have a strong opinion on this to be honest, so I'll defer this to the next CPC meeting.

@tobie
Copy link
Contributor

tobie commented Aug 26, 2025

Would you mind sharing what the objections are? (Not that I want to dispute them, just that it's useful information to have.)

@ctcpip
Copy link
Member

ctcpip commented Aug 26, 2025

"objection" is a strong word 😅

the issue is that the single most important thing in this document is the instructions for privately reporting security issues, which is going to vary from project to project

there are other aspects as well, such as categories of things that a project will not consider to be a vulnerability, response expectations, report handling and coordination, etc.

ultimately, projects need to be thinking about how they handle security reporting. it's great that we provide them a template but it will always need to be modified to fit project needs and operating procedures

RafaelGSS and others added 2 commits August 26, 2025 09:50
Co-authored-by: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Signed-off-by: Rafael Gonzaga <rafael.nunu@hotmail.com>
@ctcpip ctcpip force-pushed the add-minimal-security-md branch from 5f8a098 to 7c2e004 Compare August 26, 2025 14:51
nzakas pushed a commit to eslint/.github that referenced this pull request Aug 28, 2025
@tobie
Copy link
Contributor

tobie commented Sep 2, 2025

Notes from this week's CPC call:

This was discussed in the CPC Call today. Decision was made to follow the initial route and not use the same structure as the code of conduct as I suggested above.

Goal is to merge by end of week to unblock related work.

@UlisesGascon UlisesGascon merged commit d082491 into openjs-foundation:main Sep 8, 2025
1 check passed
@UlisesGascon UlisesGascon self-assigned this Sep 8, 2025
UlisesGascon added a commit to expressjs/.github that referenced this pull request Sep 8, 2025
UlisesGascon added a commit to UlisesGascon/webpack that referenced this pull request Sep 8, 2025
Updated the security policy to include detailed reporting guidelines and escalation procedures for vulnerabilities.

Ref: openjs-foundation/cross-project-council#1588
jlipps pushed a commit to appium/.github that referenced this pull request Sep 9, 2025
* docs: revise security reporting guidelines and escalation process

ref: openjs-foundation/cross-project-council#1588

* docs: remove emails from sec policy
nodejs-github-bot pushed a commit to nodejs/node that referenced this pull request Sep 15, 2025
PR-URL: #59806
Refs: openjs-foundation/cross-project-council#1588
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
This was referenced Sep 15, 2025
targos pushed a commit to nodejs/node that referenced this pull request Sep 18, 2025
PR-URL: #59806
Refs: openjs-foundation/cross-project-council#1588
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
targos pushed a commit to nodejs/node that referenced this pull request Sep 24, 2025
PR-URL: #59806
Refs: openjs-foundation/cross-project-council#1588
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants