Skip to content

Commit f883bf3

Browse files
mhdawsondanielleadams
authored andcommitted
doc: add security steward on/offboarding steps
Signed-off-by: Michael Dawson <[email protected]> PR-URL: #41129 Reviewed-By: James M Snell <[email protected]> Reviewed-By: Richard Lau <[email protected]> Reviewed-By: Luigi Pinca <[email protected]> Reviewed-By: Rich Trott <[email protected]>
1 parent 03e6771 commit f883bf3

File tree

1 file changed

+23
-0
lines changed

1 file changed

+23
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Security Steward Onboarding/OffBoarding
2+
3+
## Onboarding
4+
5+
* Confirm the new steward agrees to keep all private information confidential
6+
to the project and not to use/disclose to their employer.
7+
* Add them to the security-stewards team in the GitHub nodejs-private
8+
organization.
9+
* Ensure they have 2FA enabled in H1.
10+
* Add them to the standard team in H1 using this
11+
[page](https://hackerone.com/nodejs/team_members).
12+
* Add them as managers of the
13+
[nodejs-sec](https://groups.google.com/g/nodejs-sec/members) mailing list.
14+
15+
## Offboarding
16+
17+
* Remove them from security-stewards team in the GitHub nodejs-private
18+
organization.
19+
* Unless they have access for another reason, remove them from the
20+
standard team in H1 using this
21+
[page](https://hackerone.com/nodejs/team_members).
22+
* Downgrade their account to regular member in the
23+
[nodejs-sec](https://groups.google.com/g/nodejs-sec/members) mailing list.

0 commit comments

Comments
 (0)