File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ # Node.js Security team Meeting 2025-09-11
2+
3+ ## Links
4+
5+ * ** Recording** : https://www.youtube.com/watch?v=2_exLrhF5YM&ab_channel=node.js
6+ * ** GitHub Issue** : https://github.com/nodejs/security-wg/issues/1518
7+ * ** Minutes Google Doc** : https://docs.google.com/document/d/1zPUOHww6WD9VtLoTeoMaPuoWeHi6_6uujHcVNG1SeF0/edit?tab=t.0
8+
9+ ## Present
10+
11+ * Security wg team: @nodejs/security-wg
12+
13+ * Ulises Gascón: @UlisesGascon
14+ * Rafael Gonzaga: @RafaelGSS
15+
16+ ## Agenda
17+
18+ ## Announcements
19+ * There is a campaign against npm maintaienrs where attackers are using stolen tokens to impersonate maintainers and publish malicious versions:
20+ - https://jfrog.com/blog/new-compromised-packages-in-largest-npm-attack-in-history/
21+
22+
23+ * Extracted from ** security-wg-agenda** labelled issues and pull requests from the ** nodejs org** prior to the meeting.
24+
25+ - [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
26+ - [X] OpenSSF Scorecard Monitor Review
27+ - No Action needed from our team. Last PR can be merged: https://github.com/nodejs/security-wg/pull/1520
28+
29+ ### nodejs/node
30+
31+ * src: add WDAC integration (Windows) #54364
32+ * No updates
33+
34+ * Option to enable inspection mode along with permission model #48534
35+ * Rafael opened a PR to add –allow-inspector https://github.com/nodejs/node/pull/59711
36+ * Seems ready to go
37+
38+ ### nodejs/security-wg
39+
40+ * Create a VEX file for Node.js #1517
41+ * Leaving that open for further discussion with Marco
42+
43+ * Update on CVEs for EOL Release Lines – MITRE Removal & Next Steps #1443
44+ * Closing as completed
45+
46+ * Node.js maintainers: Threat Model #1333
47+ * Closing as completed
48+
49+ ## Q&A, Other
50+
51+ https://github.com/nodejs/node/pull/59806
52+
53+ ## Upcoming Meetings
54+
55+ * ** Node.js Project Calendar** : < https://nodejs.org/calendar >
56+
57+ Click ` +GoogleCalendar ` at the bottom right to add to your own Google calendar.
58+
You can’t perform that action at this time.
0 commit comments