nodejs / security-wg

Node.js Ecosystem Security Working Group
MIT License
496 stars 122 forks source link

Node.js Security team Meeting 2024-02-29 #1237

Closed mhdawson closed 7 months ago

mhdawson commented 7 months ago

Time

UTC Thu 29-Feb-2024 15:00 (03:00 PM):

Timezone Date/Time
US / Pacific Thu 29-Feb-2024 07:00 (07:00 AM)
US / Mountain Thu 29-Feb-2024 08:00 (08:00 AM)
US / Central Thu 29-Feb-2024 09:00 (09:00 AM)
US / Eastern Thu 29-Feb-2024 10:00 (10:00 AM)
EU / Western Thu 29-Feb-2024 15:00 (03:00 PM)
EU / Central Thu 29-Feb-2024 16:00 (04:00 PM)
EU / Eastern Thu 29-Feb-2024 17:00 (05:00 PM)
Moscow Thu 29-Feb-2024 18:00 (06:00 PM)
Chennai Thu 29-Feb-2024 20:30 (08:30 PM)
Hangzhou Thu 29-Feb-2024 23:00 (11:00 PM)
Tokyo Fri 01-Mar-2024 00:00 (12:00 AM)
Sydney Fri 01-Mar-2024 02:00 (02:00 AM)

Or in your local time:

Links

Agenda

Extracted from security-wg-agenda labelled issues and pull requests from the nodejs org prior to the meeting.

nodejs/security-wg

Invited

Observers/Guests

Notes

The agenda comes from issues labelled with security-wg-agenda across all of the repositories in the nodejs org. Please label any additional issues that should be on the agenda before the meeting starts.

Joining the meeting

https://zoom.us/j/92309450775


Invitees

Please use the following emoji reactions in this post to indicate your availability.

UlisesGascon commented 7 months ago

I won't be ale to attend today, but I am trying to generate the OSSF reporting. Seems like GitHub at the moment is having some issues with the Actions, GitHub Status

UlisesGascon commented 7 months ago

Fast analysis from my side on the scoring:

marco-ippolito commented 7 months ago

Mind that today security wg will be followed by the next-10 deep dive.

richardlau commented 7 months ago

FYI, I've opened https://github.com/nodejs/security-wg/issues/1243 to cover the increasing number of 503 errors being hit in https://github.com/nodejs/nodejs-dependency-vuln-assessments/actions/workflows/daily.yml.

RafaelGSS commented 7 months ago

I won't be able to host it due to https://github.com/nodejs/admin/issues/854