Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

doc: add meeting update 2023-03-16 #911

Merged
merged 1 commit into from
Mar 17, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 71 additions & 0 deletions meetings/2023-03-16.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# Node.js Security WorkGroup Meeting 2023-03-16

## Links

* **Recording**: https://www.youtube.com/watch?v=x3I5fVRRAvA
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/905
* **Minutes Google Doc**: https://docs.google.com/document/d/1jRii66Jp_TR0YXsXp15Lx-tGXFTPF7_k5mwOvjMsK6k/edit

## Present

* Security wg team: @nodejs/security-wg
* Rafael Gonzaga: @RafaelGSS
* Ulises Gascon: @UlisesGascon
* Michael Dawson: @mhdawson
* Ashish Kurmi: @boahc077
* Varun Sharma: @varunsh-coder


## Agenda

## Announcements

N/A
Ashish and Varun from StepSecurity had joined the session to demo a solution, [More details](https://github.com/nodejs/security-wg/issues/905#issuecomment-1469441002)

*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.

- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues

### nodejs/security-wg

* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
New roadmap available (on going)
There is an issue preventing the final release. See: https://github.com/nodejs/node/pull/44004#issuecomment-1458726634

* Improve SecurityWG Scorecard [#884](https://github.com/nodejs/security-wg/issues/884)
Great progress has been made with good participation from the community.
Fuzzing will require more support as we are not yet sure how to be implemented (Thomas is leading)
Code-review can be considered completed, but as it is an accumulative score it will take a while to reflect the full score.
Varun/Ashish will investigate why we still get a HIGH tag when score is 8/10

* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
Ulises will change the current workflow to use Pull Request and not directly writing files in the repo
Demo driven by Varun/Ashish about https://app.stepsecurity.io/.
Created this issue to see if nodejs/official-images is used - https://github.com/nodejs/docker-node/issues/1865

* Add OSSF Scorecard [#851](https://github.com/nodejs/security-wg/issues/851)
* Closed as completed

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
Rafael made some progress

* Discussion about policy-integrity integration on Windows [#856](https://github.com/nodejs/security-wg/issues/856)
N/A

* Automate updates of all dependencies [#828](https://github.com/nodejs/security-wg/issues/828)
Marco can lead the initiative from April (TBC)

### nodejs/nodejs-dependency-vuln-assessments

* Recursive support on Node.js dependencies [#89](https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/89)
N/A

## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.