Skip to content

Commit

Permalink
doc: add meeting minutes 2023-09-28 (#1123)
Browse files Browse the repository at this point in the history
  • Loading branch information
UlisesGascon authored Sep 30, 2023
1 parent cb2caf7 commit 4264722
Showing 1 changed file with 66 additions and 0 deletions.
66 changes: 66 additions & 0 deletions meetings/2023-09-28.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
* # Node.js Security team Meeting 2023-09-28

## Links

* **Recording**: https://www.youtube.com/watch?v=0HkA6BPPqfo
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1118
* **Minutes Google Doc**: https://docs.google.com/document/d/1izd5CipgVQTT2qeMDJ4KzxiAfZqME3y6TSr4gOl3m6c/edit

## Present

* Security wg team: @nodejs/security-wg
* Ulises Gascon: @ulisesGascon
* Thomas GENTILHOMME: @fraxken
* Carlos Espa: @Ceres6
* Michael Daawson: @mhdawson
* Darcy Clarke: @darcyclarke


## Agenda

## Announcements

*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting.

- [ ] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
- Nothing new to discuss this week

- [ ] OpenSSF Scorecard Monitor Review
* Last report: https://github.com/nodejs/security-wg/issues/1119
* Waiting for the bug to be fixed

### nodejs/security-wg

* Have a SBOM for Node.js? [#1115](https://github.com/nodejs/security-wg/issues/1115)
* defer until we have right people to discuss

* License checker process/script [#1104](https://github.com/nodejs/security-wg/issues/1104)
* @fasenderos has volunteered to do some work
* Michael - should try to re-used some existing license checker
* Darcy - Is the idea to generate an SBOM & diff that? Because that _should_ have the license information in it

* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
* Marco led session to discuss how to progress

* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953)
*some issue getting the answers updated, will continue to push forward when @ulisesGascon
returns in a few weeks

* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
* No update this week

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
* No update this week

* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
* Covered in earlier discussion


## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 comments on commit 4264722

Please sign in to comment.