Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

doc: add minutes 08-06-23 #1021

Merged
merged 1 commit into from
Jun 12, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 71 additions & 0 deletions meetings/2023-06-08.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# Node.js Security WorkGroup Meeting 2023-06-08

## Links

* **Recording**: https://www.youtube.com/watch?v=mwLJ_XD8cgk&ab_channel=node.js
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1012
* **Minutes Google Doc**: https://docs.google.com/document/d/1rtug7HnSLdTlCrdwMltQyh3vpQt9GWuGP1y2XRKA--Q/edit

## Present

* Security wg team: @nodejs/security-wg
* Marco Ippolito: @marco-ippolito
* Michael Dawson @mhdawson
* Rafael Gonzaga @RafaelGSS
* Thomas GENTILHOMME @fraxken
* Ulises Gascon @UlisesGascon
* Andrea Fassina @fasenderos

## Agenda

## Announcements

*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.

- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
Added `confirmed` label to c-ares and OpenSSL issues

- [x] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
A few issues in the OSSF Dashboard - Ulises will report it to Laurent (OpenSSF/Google team) and Teba (@kooltheba)

### nodejs/security-wg

* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
* Discussion CII-Entry level badge
* Met all the requirements
* Ulises will create a PR to nodejs/node#README.md to include the badge (it’s a requirement for the Silver level)
* Entry level is concluded
* Working on Silver level

* Issue for Security wg project related news? [#1006](https://github.com/nodejs/security-wg/issues/1006)
* Issue renamed to “News”
* Removed from the agenda
* Lock conversation to collaborators only (to restrict the comments to only news)

* Permission - Environment variables [#993](https://github.com/nodejs/security-wg/issues/993)
* Removed from the agenda
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
* Rafael is working to accept relative paths in the CLI

* Overlap with single-executable effort [#879](https://github.com/nodejs/security-wg/issues/879)
* Removed from the agenda

* Update Charter / Readme.md [#874](https://github.com/nodejs/security-wg/pull/874)
* We should start using the Team terminology
* We’ve defined a few months ago to update the charter to Node.js Security Team

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)

* Discussion about policy-integrity integration on Windows [#856](https://github.com/nodejs/security-wg/issues/856)
* If someone wants to take action on that, feel free
* Removed from the agenda


## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.