Skip to content

Commit 730e87c

Browse files
patrickm68tniessen
andcommitted
docs: added meeting minutes 2023-05-11 (#983)
* docs: added meeting minutes 2023-05-11 related nodejs/security-wg#977 * Update meetings/2023-05-11.md Co-authored-by: Tobias Nießen <[email protected]> --------- Co-authored-by: Tobias Nießen <[email protected]>
1 parent 82882b9 commit 730e87c

File tree

1 file changed

+65
-0
lines changed

1 file changed

+65
-0
lines changed

meetings/2023-05-11.md

+65
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,65 @@
1+
# Node.js Security WorkGroup Meeting 2023-05-11
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=xtbjcbMjAvQ
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/977
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/19rq7F__F3qSdW8v3CeACJ6LpWHLlnWZsTgJWVWUwltI/edit
8+
9+
## Present
10+
11+
* Security wg team: @nodejs/security-wg
12+
* Marco Ippolito @marco-ippolito
13+
* Thomas GENTILHOMME @fraxken
14+
* Ulises Gascon: @ulisesGascon
15+
16+
## Agenda
17+
18+
## Announcements
19+
20+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
21+
22+
- [ ] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
23+
- Waiting for OpenSSL release
24+
- [ ] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
25+
https://github.com/nodejs/security-wg/pull/981
26+
- No big changes. Just some organic changes for Undici
27+
28+
### nodejs/security-wg
29+
30+
* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953)
31+
* Ulises: will merge and resolve the discussions for Entry-level PR: https://github.com/nodejs/security-wg/pull/954
32+
* Ulises will ask for permissions to push the changes to the OpenSSF project site
33+
* We can start the discussion for silver-level in PR: https://github.com/nodejs/security-wg/pull/955
34+
* We have discussed if we can extend this to Undici as well
35+
* Improve Node.js Scorecard [#929](https://github.com/nodejs/security-wg/issues/929)
36+
* Ulises will update the report and remove it from the agenda
37+
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
38+
* Marco started to work in the path resolver in c++
39+
* Improve SecurityWG Scorecard [#884](https://github.com/nodejs/security-wg/issues/884)
40+
* Ulises will update the report and remove it from the agenda
41+
* We need to check how to get access to the security tab in Github for the Security WG team members. Ulises will create an issue about it
42+
* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
43+
* During the collaborators summit Rafael mentioned that there is room for the community to support this initiative with automations/tooling..
44+
* Ulises to discuss with Refael if we can create a task list/introduction in the next session so the community can pick pending actions and help us.
45+
* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
46+
* It will be great to update the issue (as it is a reference) and update the pending actions and activities on going.
47+
* Discussion about policy-integrity integration on Windows [#856](https://github.com/nodejs/security-wg/issues/856)
48+
* No forum to discuss about it
49+
* Automate updates of all dependencies [#828](https://github.com/nodejs/security-wg/issues/828)
50+
* Marco has almost completed all the dependencies
51+
* There is a discussion ongoing about this PR: https://github.com/nodejs/node/pull/47742. Your feedback is appreciated to unblock the discussion.
52+
* Next step is to work in the regression so we can port the updated dependencies to the other Node.js versions available (16,18..).
53+
* Marco will add more issues to the agenda for the next phase
54+
55+
## Q&A, Other
56+
57+
* Congratulations to the Security WG from the collaborators summit, there is a very positive feedback for the job we made the last months.
58+
* Security is going to be a key part in Node.js for the following years.
59+
60+
## Upcoming Meetings
61+
62+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
63+
64+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
65+

0 commit comments

Comments
 (0)