File tree 1 file changed +52
-0
lines changed
1 file changed +52
-0
lines changed Original file line number Diff line number Diff line change
1
+ # Node.js Security team Meeting 2025-01-30
2
+
3
+ ## Links
4
+
5
+ * ** Recording** : https://www.youtube.com/watch?v=iEgHs7V6BvU
6
+ * ** GitHub Issue** : https://github.com/nodejs/security-wg/issues/1431
7
+ * ** Minutes Google Doc** : https://docs.google.com/document/d/10qmMTdpDWZDf04mNObBWQTKK_xlZa2zify7x6CiVsO4/edit?tab=t.0
8
+
9
+ ## Present
10
+
11
+ * Rafael Gonzaga: @RafaelGSS
12
+ * Michael Dawson: @mhdawson
13
+ * Thomas GENTILHOMME: @fraxken
14
+ * Robert W
15
+
16
+ ## Agenda
17
+
18
+ ## Announcements
19
+
20
+ * Extracted from ** security-wg-agenda** labelled issues and pull requests from the ** nodejs org** prior to the meeting.
21
+
22
+ - [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
23
+ * Nothing new this week
24
+
25
+ - [X] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
26
+ * No update this week
27
+
28
+ ### nodejs/node
29
+
30
+ * src: add WDAC integration (Windows) [ #54364 ] ( https://github.com/nodejs/node/pull/54364 )
31
+ * Remaining feedback has been addressed on the PR
32
+ * Discussion on how to move forward.
33
+
34
+ ### nodejs/security-wg
35
+
36
+ * Node.js maintainers: Threat Model [ #1333 ] ( https://github.com/nodejs/security-wg/issues/1333 )
37
+ * Rafael will sync the progress from this meeting with Github once other PRs gets landed
38
+
39
+ * Audit build process for dependencies [ #1037 ] ( https://github.com/nodejs/security-wg/issues/1037 )
40
+ * Michael, next step is looking at updaters for amaro and cjs-module-lexer
41
+
42
+ * Automate security release process [ #860 ] ( https://github.com/nodejs/security-wg/issues/860 )
43
+ * Excellent progress since Dec 24. A blog post is being created to share with OpenJS Foundation (part of OpenSSF)
44
+
45
+ ## Q&A, Other
46
+
47
+ ## Upcoming Meetings
48
+
49
+ * ** Node.js Project Calendar** : < https://nodejs.org/calendar >
50
+
51
+ Click ` +GoogleCalendar ` at the bottom right to add to your own Google calendar.
52
+
You can’t perform that action at this time.
0 commit comments