-
Notifications
You must be signed in to change notification settings - Fork 122
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
doc: add meeting minutes 2023-09-28 (#1123)
- Loading branch information
1 parent
cb2caf7
commit 4264722
Showing
1 changed file
with
66 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,66 @@ | ||
* # Node.js Security team Meeting 2023-09-28 | ||
|
||
## Links | ||
|
||
* **Recording**: https://www.youtube.com/watch?v=0HkA6BPPqfo | ||
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1118 | ||
* **Minutes Google Doc**: https://docs.google.com/document/d/1izd5CipgVQTT2qeMDJ4KzxiAfZqME3y6TSr4gOl3m6c/edit | ||
|
||
## Present | ||
|
||
* Security wg team: @nodejs/security-wg | ||
* Ulises Gascon: @ulisesGascon | ||
* Thomas GENTILHOMME: @fraxken | ||
* Carlos Espa: @Ceres6 | ||
* Michael Daawson: @mhdawson | ||
* Darcy Clarke: @darcyclarke | ||
|
||
|
||
## Agenda | ||
|
||
## Announcements | ||
|
||
*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting. | ||
|
||
- [ ] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues | ||
- Nothing new to discuss this week | ||
|
||
- [ ] OpenSSF Scorecard Monitor Review | ||
* Last report: https://github.com/nodejs/security-wg/issues/1119 | ||
* Waiting for the bug to be fixed | ||
|
||
### nodejs/security-wg | ||
|
||
* Have a SBOM for Node.js? [#1115](https://github.com/nodejs/security-wg/issues/1115) | ||
* defer until we have right people to discuss | ||
|
||
* License checker process/script [#1104](https://github.com/nodejs/security-wg/issues/1104) | ||
* @fasenderos has volunteered to do some work | ||
* Michael - should try to re-used some existing license checker | ||
* Darcy - Is the idea to generate an SBOM & diff that? Because that _should_ have the license information in it | ||
|
||
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037) | ||
* Marco led session to discuss how to progress | ||
|
||
* Initiative for CII-Best-Practices for Nodejs Projects [#953](https://github.com/nodejs/security-wg/issues/953) | ||
*some issue getting the answers updated, will continue to push forward when @ulisesGascon | ||
returns in a few weeks | ||
|
||
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898) | ||
* No update this week | ||
|
||
* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860) | ||
* No update this week | ||
|
||
* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859) | ||
* Covered in earlier discussion | ||
|
||
|
||
## Q&A, Other | ||
|
||
## Upcoming Meetings | ||
|
||
* **Node.js Project Calendar**: <https://nodejs.org/calendar> | ||
|
||
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar. | ||
|