Skip to content

Commit fd5583e

Browse files
doc: add 2024-01-04 notes (#1183)
* doc: add 2024-01-04 notes * Update meetings/2024-01-04.md Co-authored-by: Ulises Gascón <[email protected]> * Update meetings/2024-01-04.md Co-authored-by: Ulises Gascón <[email protected]> --------- Co-authored-by: Ulises Gascón <[email protected]>
1 parent 33f2d8a commit fd5583e

File tree

1 file changed

+61
-0
lines changed

1 file changed

+61
-0
lines changed

meetings/2024-01-04.md

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
# Node.js Security team Meeting 2024-01-04
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=0g6fJw11KrI
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1175
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/1qNM01Xw0S_U4JTtJcoF1m5PQQUl9PkyVRGjxcetz8eY/edit
8+
9+
## Present
10+
11+
* Security wg team: @nodejs/security-wg
12+
* Rafael Gonzaga (@RafaelGSS)
13+
* Ulises Gascon (@ulisesGascon)
14+
* Marco Ippolito (@marco-ippolito)
15+
* Michael Dawson (@mhdawson)
16+
* Carlos Espa (@Ceres6)
17+
18+
## Agenda
19+
20+
## Announcements
21+
22+
*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.
23+
24+
- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
25+
- [X] OpenSSF Scorecard Monitor Review
26+
- [Issue details](https://github.com/nodejs/security-wg/issues/1179)
27+
- [Pr Details](https://github.com/nodejs/security-wg/pull/1180)
28+
- Undici increased 0.1 due Code Review. [see](https://kooltheba.github.io/openssf-scorecard-api-visualizer/#/projects/github.com/nodejs/undici/compare/c5c6648a7d2097f9be4d1f7d06df9f158eff049d/990b96ebb138ecf9fb93fea0f2a832ae322c939f)
29+
- Node.js decreased 0.3 due Code Review. [see](https://kooltheba.github.io/openssf-scorecard-api-visualizer/#/projects/github.com/nodejs/node/compare/f9675e104e25ae7da5215f338f5e2609c85025a2/515b007faedf529861b22823f8a722eebed837fa)
30+
31+
### nodejs/security-wg
32+
33+
* Security initiative in December 2023: fuzzing Nodejs: https://github.com/google/oss-fuzz/tree/master/projects/nodejs
34+
* Skipped - OSTIF didn’t join
35+
36+
[#1159](https://github.com/nodejs/security-wg/issues/1159)
37+
* NodeJS Code integrity on Windows
38+
* Skipped - Microsoft folks didn’t join
39+
40+
[#1149](https://github.com/nodejs/security-wg/issues/1149)
41+
* Have a SBOM for Node.js? [#1115](https://github.com/nodejs/security-wg/issues/1115)
42+
* Skipped - no progress since the last meeting
43+
44+
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
45+
* Stopped until SBOMs resolution
46+
47+
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
48+
* Several fixes coming with the 21.6.0 release
49+
* two new features - support for relative paths and –allow-addons flag
50+
51+
* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953)
52+
* Recap
53+
* Deep dive
54+
55+
## Q&A, Other
56+
57+
## Upcoming Meetings
58+
59+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
60+
61+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 commit comments

Comments
 (0)