File tree Expand file tree Collapse file tree 1 file changed +52
-0
lines changed
Expand file tree Collapse file tree 1 file changed +52
-0
lines changed Original file line number Diff line number Diff line change 1+ # Node.js Security team Meeting 2025-01-30
2+
3+ ## Links
4+
5+ * ** Recording** : https://www.youtube.com/watch?v=iEgHs7V6BvU
6+ * ** GitHub Issue** : https://github.com/nodejs/security-wg/issues/1431
7+ * ** Minutes Google Doc** : https://docs.google.com/document/d/10qmMTdpDWZDf04mNObBWQTKK_xlZa2zify7x6CiVsO4/edit?tab=t.0
8+
9+ ## Present
10+
11+ * Rafael Gonzaga: @RafaelGSS
12+ * Michael Dawson: @mhdawson
13+ * Thomas GENTILHOMME: @fraxken
14+ * Robert W
15+
16+ ## Agenda
17+
18+ ## Announcements
19+
20+ * Extracted from ** security-wg-agenda** labelled issues and pull requests from the ** nodejs org** prior to the meeting.
21+
22+ - [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
23+ * Nothing new this week
24+
25+ - [X] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
26+ * No update this week
27+
28+ ### nodejs/node
29+
30+ * src: add WDAC integration (Windows) [ #54364 ] ( https://github.com/nodejs/node/pull/54364 )
31+ * Remaining feedback has been addressed on the PR
32+ * Discussion on how to move forward.
33+
34+ ### nodejs/security-wg
35+
36+ * Node.js maintainers: Threat Model [ #1333 ] ( https://github.com/nodejs/security-wg/issues/1333 )
37+ * Rafael will sync the progress from this meeting with Github once other PRs gets landed
38+
39+ * Audit build process for dependencies [ #1037 ] ( https://github.com/nodejs/security-wg/issues/1037 )
40+ * Michael, next step is looking at updaters for amaro and cjs-module-lexer
41+
42+ * Automate security release process [ #860 ] ( https://github.com/nodejs/security-wg/issues/860 )
43+ * Excellent progress since Dec 24. A blog post is being created to share with OpenJS Foundation (part of OpenSSF)
44+
45+ ## Q&A, Other
46+
47+ ## Upcoming Meetings
48+
49+ * ** Node.js Project Calendar** : < https://nodejs.org/calendar >
50+
51+ Click ` +GoogleCalendar ` at the bottom right to add to your own Google calendar.
52+
You can’t perform that action at this time.
0 commit comments