Skip to content

Commit

Permalink
doc: add meeting minutes (#1067)
Browse files Browse the repository at this point in the history
  • Loading branch information
RafaelGSS authored Aug 4, 2023
1 parent 4511cf8 commit 50963d0
Showing 1 changed file with 58 additions and 0 deletions.
58 changes: 58 additions & 0 deletions meetings/2023-08-03.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# Node.js Security team Meeting 2023-08-03

## Links

* **Recording**: https://www.youtube.com/watch?v=fJNDQz9sAQo&ab_channel=node.js
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1059
* **Minutes Google Doc**: https://docs.google.com/document/d/1eLSRK2nKeEnWD1YcEjjROYgVOfuVRPupi7BS5kIMH4I/edit

## Present

* Security wg team: @nodejs/security-wg
* Marco Ippolito @marco-ippolito
* Rafael Gonzaga @RafaelGSS
* Michael Dawson @mhdawson
* Ulises Gascon @ulisesgascon
* Ruy Adorno @ruyadorno

## Agenda

## Announcements

*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting.

- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
* Wait NVD database to be fixed - Ref: https://github.com/vehemont/nvdlib/issues/26

- [X] OpenSSF Scorecard Monitor Review
- Last report: https://github.com/nodejs/security-wg/pull/1066
- Organic improvements due SAST analysis and variations based on increasing/decreasing unreviewed changesets
- Ulises will apply stepsecurity auto-prs to all the repos in the org
- We will focus on monitoring from now on using the issue generated.

### nodejs/security-wg

* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
* No progress. Just for visibility.
* Marco is investigating this initiative.

* Initiative for CII-Best-Practices for Node.js Projects [#953](https://github.com/nodejs/security-wg/issues/953)
* Ulises will ask TSC for final approval in silver level
* Ulises will prepare the next step: gold level to be reviewed by the team following the previous process.

* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
* Discussion around https://github.com/nodejs/security-wg/issues/1039. We agreed to follow option 2 (array/multiple flags)

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
* OSSF Funding approved by TSC (no objections until the end of the week)
* OSSF is approved the budget is no objections are presented before the end of the week

* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)

## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 comments on commit 50963d0

Please sign in to comment.