Skip to content

Commit

Permalink
doc: add minutes 2023-05-01
Browse files Browse the repository at this point in the history
  • Loading branch information
RafaelGSS committed Jan 5, 2023
1 parent 7f356f2 commit b5b7e64
Showing 1 changed file with 55 additions and 0 deletions.
55 changes: 55 additions & 0 deletions meetings/2023-01-05.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# Node.js Security WorkGroup Meeting 2023-01-05

## Links

* **Recording**: http://www.youtube.com/watch?v=5qxzF0v-nPc
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/855

## Present

* GENTILHOMME Thomas: @fraxken
* Ulises Gascon: @ulisesGascon
* Michael Dawson: @mhdawson
* Rafael Gonzaga: @rafaelgss
* Joe Sepi: @joesepiw

## Agenda

## Announcements

*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting.

- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues

### nodejs/security-wg

* Abort when vulnerable flag [#852](https://github.com/nodejs/security-wg/issues/852)
* @rafaelgss will create a module as a first step that will do the check, could be used with npx

* Add OSSF Scorecard [#851](https://github.com/nodejs/security-wg/issues/851)
* Will defer to next meeting and make sure we give Gabriela a heads up on the meeting time

* Permission Model [#791](https://github.com/nodejs/security-wg/issues/791)
* Rafael made a good progress
* He’s waiting access to a windows machine to fix a test bug
* There are some discussions but no objections, so the feature will be soon approved/merged

* Node.js Security WG Initiatives 2023 [#846](https://github.com/nodejs/security-wg/issues/846)
* Rafael will open an issue on OpenSSL project to see how doable is to get early security patches.
* All the updates were commented in the issue
* TL;DR: We have defined the 2023 initiatives

* Automate updates of all dependencies [#828](https://github.com/nodejs/security-wg/issues/828)


### nodejs/nodejs-dependency-vuln-assessments

* Recursive support on Node.js dependencies [#89](https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/89)

## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 comments on commit b5b7e64

Please sign in to comment.