expressjs / security-wg

Express.js Security Working Group
MIT License
6 stars 2 forks source link

Express.js Threat Model #3

Open UlisesGascon opened 4 months ago

UlisesGascon commented 4 months ago

We need to define a solid Threat Model. Initial comment by Wess

Resources

UlisesGascon commented 3 months ago

Good news the proposal https://github.com/expressjs/express/pull/5526 in in the oven 🎉

Next step, as discussed with @ruddermann is to prepare a private meeting with the @expressjs/security-triage to cover the details before #6 starts.

So I move the discussion for this to Slack private channel

Relevant links

UlisesGascon commented 3 months ago

Current discussion about the Threat Model: