nodeshift / web-application-reference

WIP repo to hold Red Hat/IBM web application reference
Apache License 2.0
14 stars 6 forks source link

🔐 Security Section #3

Open DavidSint opened 1 year ago

DavidSint commented 1 year ago

Not sure the way of working previously, but I like my teams to raise PRs at the beginning to allow for early feedback.

This WIP PR will be used for my draft of the security section, as taken on at the meeting on 2023/06/21.

joesepi commented 1 year ago

There is work going on in the Security Collaboration Space at the OpenJS Foundation to help give guidance to JavaScript developers around security as well. Part of our plan is go take guidance and direction from the OpenSSF and tailor it to JS projects. That being said, we may want to highlight some of the resources at OpenSSF for the time being might be good.

A couple examples:

Note: the Security Collab Space is something of a new effort and there isn't a lot in the repo. We have shifted a lot of our focus at the moment on standing up the grant we received from the Sovereign Tech Fund. See more info on that grant here: https://openjsf.org/blog/2023/05/02/openjs-foundation-receives-major-government-investment-from-sovereign-tech-fund-for-web-security-and-stability/

DavidSint commented 1 year ago

@joesepi are you suggesting that we include some OpenSSF links as a separate section for external resources or, do you think it should be included in one of the existing titles?