|
| 1 | +# Node.js Security WorkGroup Meeting 2023-01-19 |
| 2 | + |
| 3 | +## Links |
| 4 | + |
| 5 | +* **Recording**: https://www.youtube.com/watch?v=qzLZbdHSfZE |
| 6 | +* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/862 |
| 7 | +* **Minutes Google Doc**: https://docs.google.com/document/d/1poZvCtSlrw7aPjldNwHyJUToZu7RsBlnFDRV5VpIDtg/edit |
| 8 | + |
| 9 | +## Present |
| 10 | + |
| 11 | +* Security wg team: @nodejs/security-wg |
| 12 | +* Rafael Gonzaga: @RafaelGSS |
| 13 | +* Ulises Gascon: @UlisesGascon |
| 14 | +* Thomas GENTILHOMME: @fraxken |
| 15 | +* Robert Waite |
| 16 | +* Joe Sepi: @joesepi |
| 17 | +* Joyce Brum from GOSST @joycebrum |
| 18 | +* Gabriela Gutierrez from GOSST @gabibguti |
| 19 | +* Pedro Nacht from GOSST @pnacht |
| 20 | +* Diogo Sant'Anna from GOSST @diogoteles08 |
| 21 | +* Michael Dawson @mhdawson |
| 22 | + |
| 23 | +## Agenda |
| 24 | + |
| 25 | +## Announcements |
| 26 | + |
| 27 | +*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting. |
| 28 | + |
| 29 | +- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues |
| 30 | + |
| 31 | +### nodejs/security-wg |
| 32 | + |
| 33 | +* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859) |
| 34 | +* Add OSSF Scorecard [#851](https://github.com/nodejs/security-wg/issues/851) |
| 35 | + * Discussion with GOSST about implementing it on Node.js |
| 36 | + * The Nodejs currently report is located [here](https://deps.dev/project/github/nodejs%2Fnode), also [json version available](https://api.securityscorecards.dev/projects/github.com/nodejs/node) |
| 37 | + * Agreement to update action version tag by hash in GHA, following [this example](https://app.stepsecurity.io/secureworkflow/nodejs/node/coverage-linux.yml/main?enable=pin), lead by GOSST |
| 38 | + * Agreement to add/document the next steps in [this issue](https://github.com/nodejs/security-wg/issues/859) in order to provide a good context for the following PRs and TSC Meetings, lead by GOSST |
| 39 | + |
| 40 | +* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860) |
| 41 | + |
| 42 | +* Discussion about policy-integrity integration on Windows [#856](https://github.com/nodejs/security-wg/issues/856) |
| 43 | + * We will discuss this issue as first topic in the next meeting |
| 44 | + |
| 45 | +* Automate updates of all dependencies [#828](https://github.com/nodejs/security-wg/issues/828) |
| 46 | + |
| 47 | +* Permission Model [#791](https://github.com/nodejs/security-wg/issues/791) |
| 48 | + * Got 3 approvals so far |
| 49 | + * Remaining work: |
| 50 | + * Windows issue to fix |
| 51 | + * Native modules support |
| 52 | + |
| 53 | +### nodejs/nodejs-dependency-vuln-assessments |
| 54 | + |
| 55 | +* Recursive support on Node.js dependencies [#89](https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/89) |
| 56 | + |
| 57 | +## Q&A, Other |
| 58 | + |
| 59 | +## Upcoming Meetings |
| 60 | + |
| 61 | +* **Node.js Project Calendar**: <https://nodejs.org/calendar> |
| 62 | + |
| 63 | +Click `+GoogleCalendar` at the bottom right to add to your own Google calendar. |
0 commit comments