Coder Social home page Coder Social logo

Name this Working Group about security-wg HOT 7 CLOSED

nodejs avatar nodejs commented on August 23, 2024 1
Name this Working Group

from security-wg.

Comments (7)

joshgav avatar joshgav commented on August 23, 2024

Thinking and thinking, Security seems the most concise and descriptive title for what this WG proposes to do. Other suggestions that come to mind include:

  • Trust - because the goal of better security policy is to promote trust. But it doesn't tell much about what this WG proposes to do.
  • Security Policy - because this group is about managing security rather than security itself. But that's not really true, it's also an advisory group for security itself.
  • Vulnerability - because a prime job will be managing policy and process for vulnerabilities. But that's a negative name and also only part of the proposed scope.

So I think we should call this group Security as proposed, and rename the private group as Disclosures or Vulnerabilities.

@rvagg @Trott

it may lure people to think that they should report issues via the issue tracker here

We could have a big (blinking!) banner on the README and in the issue and PR templates redirecting people to the Disclosures email for actual vulnerability reports. Seems that would be sufficient diligence.

from security-wg.

gibfahn avatar gibfahn commented on August 23, 2024

+1 to Security WG for this group and Vulnerabilities for the private one.

The private group is only used for reporting vulnerabilities right? So that name really makes more sense. (IMHO).

from security-wg.

williamkapke avatar williamkapke commented on August 23, 2024

At NINA, there was positive opinion towards the existing one being called the Security Response Team (it isn't a Working Group)

My opinion is that the new group should be called the Node Security Committee which oversees the Node Security Project... along with the other proposed security activities.

from security-wg.

sam-github avatar sam-github commented on August 23, 2024

I like the names proposed in #4 (comment), with the caveat that we most emphatically do not oversee the Node Security Project, that is an existing project, not ours, we shouldn't steal its name, and the name wasn't given to use. The group will oversee a Node Foundation Vulnerabilty Database (EDIT: actual name is still TBD) (seeded with a donation from nsp).

from security-wg.

sam-github avatar sam-github commented on August 23, 2024

Any other thoughts, @nodejs/security-wg ?

from security-wg.

drifkin avatar drifkin commented on August 23, 2024

👍 to Security Response Team and Node Security Committee. I think it makes things more clear.

from security-wg.

sam-github avatar sam-github commented on August 23, 2024

I don't think there is any appetite to rename this from "Security WG", though perhaps if the security response team at-nodejs/security gets reorganized the issue will come up again.

Shall we close for now if there isn't something actionable?

from security-wg.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.