Skip to content

Commit 82cb3c6

Browse files
authored
doc: add meeting minutes 22-06 (#1035)
1 parent c89dbfb commit 82cb3c6

File tree

1 file changed

+76
-0
lines changed

1 file changed

+76
-0
lines changed

Diff for: meetings/2023-06-22.md

+76
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
# Node.js Security team Meeting 2023-06-22
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=bXmuOBod2RU
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1026
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/1X2F4JTChNLEod7qzh9aTEqgIJtGrvLumnnLk7efiE_o/edit
8+
9+
## Present
10+
11+
* Security wg team: @nodejs/security-wg
12+
* Rafael Gonzaga: @RafaelGSS
13+
* Michael Dawson: @mhdawson
14+
* Ulises Gascon: @UlisesGascon
15+
16+
## Agenda
17+
18+
## Announcements
19+
20+
*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting.
21+
22+
- New Security Releases!
23+
- Since Tuesday available. Details: https://nodejs.org/en/blog/vulnerability/june-2023-security-releases
24+
25+
- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
26+
- 0.2 decrease in undici (expected)
27+
28+
- [x] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/pull/1033
29+
- In the next call we will discuss about the future of this initiative (aside of monitoring)
30+
31+
### nodejs/security-wg
32+
33+
* Permission - Environment variables [#993](https://github.com/nodejs/security-wg/issues/993)
34+
* Open for support from the community
35+
* Removed from agenda
36+
37+
* Requirement: Secure development knowledge [#987](https://github.com/nodejs/security-wg/issues/987)
38+
* Removed from agenda
39+
* Requirement: Publicly known medium-high vulnerabilities unpatched for +60 days [#986](https://github.com/nodejs/security-wg/issues/986)
40+
* Removed from agenda
41+
* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953)
42+
* Silver level almost concluded.
43+
* Waiting for badge resolution in the Entry level
44+
* Waiting for access to the OSSF Best practices website
45+
46+
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
47+
* New improvements and fixes shipped in the last release
48+
* Investigation ongoing for symlinks
49+
50+
* Update Charter / Readme.md [#874](https://github.com/nodejs/security-wg/pull/874)
51+
* We want to keep this in the loop as we need to do more changes in the repo name, etc..
52+
* PR merged
53+
54+
* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
55+
* The three new releases were created the automation made by Rafael
56+
* It will require some extra work to fine tune details (like multi-commits…), see: https://github.com/nodejs/security-wg/issues/860#issuecomment-1602747118
57+
58+
* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
59+
* Once the gold standard is done, this initiative will be closed
60+
61+
* Discussion about policy-integrity integration on Windows [#856](https://github.com/nodejs/security-wg/issues/856)
62+
* Removed from the agenda
63+
64+
## Q&A, Other
65+
66+
* New initiatives will be starting soon
67+
* Dependencies immutability
68+
* Supply chain attacks mitigation (monitoring and promoting best practices)
69+
70+
71+
## Upcoming Meetings
72+
73+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
74+
75+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.
76+

0 commit comments

Comments
 (0)