Skip to content

Commit e0a2cb6

Browse files
doc: add meeting minutes 2023-08-17 (#1081)
* doc: add meeting minutes 2023-08-17 * Update meetings/2023-08-17.md Co-authored-by: Ulises Gascón <[email protected]> --------- Co-authored-by: Ulises Gascón <[email protected]>
1 parent 94f017f commit e0a2cb6

File tree

1 file changed

+56
-0
lines changed

1 file changed

+56
-0
lines changed

meetings/2023-08-17.md

+56
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
# Node.js Security team Meeting 2023-08-17
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=7MGcnoZW_cE&ab_channel=node.js
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1072
7+
8+
## Present
9+
10+
* Michael Dawson (@mhdawson)
11+
* Rafael Gonzaga (@RafaelGSS)
12+
* Ulises Gascon (@ulisesGascon)
13+
* Marco Ippolito (@marco-ippolito)
14+
15+
## Agenda
16+
17+
## Announcements
18+
19+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
20+
21+
- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
22+
- closed all of the OpenSSL vulns as they were fixed in the last security release
23+
- some discussion of how to get the llhttp reports fixed as problem in how levels affected were were reported as it does not apply to 16 or 18
24+
25+
- [x] OpenSSF Scorecard Monitor Review
26+
- https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
27+
- Ulises will check with @ovflowd if a refactor can be done in one of the workflows for nodejs/nodejs.org
28+
29+
### nodejs/security-wg
30+
31+
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
32+
* Marco is looking to it
33+
34+
* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953)
35+
* Silver level is going to be merged, and then Ulises will coordinate the update in the website
36+
* Gold level seems more related to organizational matters, we start to work offline on it to update the PR.
37+
38+
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
39+
* Breaking change coming: https://github.com/nodejs/node/pull/49047
40+
* Discussion around config file support https://github.com/nodejs/security-wg/issues/1074
41+
* path.resolve implementation in stand-by
42+
43+
* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
44+
* No updates. Waiting OpenJS response.
45+
46+
* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
47+
* Ulises will open PRs to increase the scoring in key projects within the org
48+
49+
## Q&A, Other
50+
51+
## Upcoming Meetings
52+
53+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
54+
55+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
56+

0 commit comments

Comments
 (0)