Skip to content

Commit

Permalink
doc: add august 1st meeting notes (#1358)
Browse files Browse the repository at this point in the history
  • Loading branch information
RafaelGSS authored Aug 2, 2024
1 parent 5453dcd commit 68209ac
Showing 1 changed file with 50 additions and 0 deletions.
50 changes: 50 additions & 0 deletions meetings/2024-08-01.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# Node.js Security team Meeting 2024-08-01

## Links

* **Recording**: https://www.youtube.com/watch?v=uYjkIe3yhPE
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1355

## Present

* Security wg team: @nodejs/security-wg
* Rafael Gonzaga: @Rafaelgss
* Thomas Gentilhomme: @fraxken
* Ulises Gascón: @UlisesGascon
* Michael Dawson: @mhdawson

## Agenda

## Announcements

*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.

- [x] Vulnerability Review -
https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
* Nothing new this week

- [x] OpenSSF Scorecard Monitor Review -
- Seems like GH has some rate limits currently in our region https://github.com/nodejs/security-wg/actions/runs/10199208188/job/28215763563. Ulises will retry after the meeting.

### nodejs/security-wg

* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
* Michael added PR for undici to get us one step closer to having everything we need in deps
to rebuild

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
* PR landed to update security release process to use the automated support
* PRs to update the security automation and move templates towards end goal
* Currently working on automating cleanup

* Node.js maintainers: Threat Model [#1333](https://github.com/nodejs/security-wg/issues/1333)
* Deep Dive session

## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 comments on commit 68209ac

Please sign in to comment.