Skip to content

Commit

Permalink
doc: add 2025-01-30 minutes
Browse files Browse the repository at this point in the history
  • Loading branch information
RafaelGSS committed Feb 1, 2025
1 parent b6ac043 commit 00f4073
Showing 1 changed file with 52 additions and 0 deletions.
52 changes: 52 additions & 0 deletions meetings/2025-01-30.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# Node.js Security team Meeting 2025-01-30

## Links

* **Recording**: https://www.youtube.com/watch?v=iEgHs7V6BvU
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1431
* **Minutes Google Doc**: https://docs.google.com/document/d/10qmMTdpDWZDf04mNObBWQTKK_xlZa2zify7x6CiVsO4/edit?tab=t.0

## Present

* Rafael Gonzaga: @RafaelGSS
* Michael Dawson: @mhdawson
* Thomas GENTILHOMME: @fraxken
* Robert W

## Agenda

## Announcements

*Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting.

- [X] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
* Nothing new this week

- [X] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+
* No update this week

### nodejs/node

* src: add WDAC integration (Windows) [#54364](https://github.com/nodejs/node/pull/54364)
* Remaining feedback has been addressed on the PR
* Discussion on how to move forward.

### nodejs/security-wg

* Node.js maintainers: Threat Model [#1333](https://github.com/nodejs/security-wg/issues/1333)
* Rafael will sync the progress from this meeting with Github once other PRs gets landed

* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
* Michael, next step is looking at updaters for amaro and cjs-module-lexer

* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
* Excellent progress since Dec 24. A blog post is being created to share with OpenJS Foundation (part of OpenSSF)

## Q&A, Other

## Upcoming Meetings

* **Node.js Project Calendar**: <https://nodejs.org/calendar>

Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 comments on commit 00f4073

Please sign in to comment.