Skip to content

Latest commit

 

History

History
65 lines (44 loc) · 2.33 KB

File metadata and controls

65 lines (44 loc) · 2.33 KB

Node.js Security team Meeting 2026-03-19

Links

Present

  • Security wg team: @nodejs/security-wg
  • Rafael Gonzaga: @RafaelGSS
  • Marco Ippolito: @marco-ippolito
  • Beth Griggs: @BethGriggs

Agenda

Announcements

*Extracted from security-wg-agenda labelled issues and pull requests from the nodejs org prior to the meeting.

nodejs/security-wg

  • Node.js PURL is missing namespace #1552

    • PURL = Package URL
    • It needs to be fixed. It's missing the protocol (should be generic
    • The ecosystem refers to Node.js as node while the project itself refers to nodejs/node.
    • Proposal to use nodejs/node as preference in the VEX file
  • regenerate node.openvex.json #1549

    • Remove from the agenda.
  • update deps index.json #1547

    • Approved and merged.
  • Tracking: LLM-assisted H1 report triage #1554

    • Beth is working on a model to classify open reports based on
      • All closed reports
      • SECURITY.md
      • Next: Node.js documentation

nodejs/TSC

  • Proposal: Moving security reports to a public workflow #1826
    • We are going to discuss it in depth in the collaborator summit
    • An intermediary proposal is to avoid CI embargo. Under discussion with releasers team.

nodejs/node

Q&A, Other

Upcoming Meetings

Click Add to Google Calendar at the bottom left to add to your own Google calendar.