Coder Social home page Coder Social logo

security-wg's Introduction

Node.js Security WG Security WG Meetings Security WG Twitter Hashtag OpenJS Slack Invite OpenSSF scorecard

Ecosystem Security Working Group

Table of Contents

Charter

The Ecosystem Security Working Group works to improve the security of the Node.js Ecosystem.

Responsibilities include:

  • Work with the Node Security Platform to bring community vulnerability data into the foundation as a shared asset.
  • Ensure the vulnerability data is updated in an efficient and timely manner. For example, ensuring there are well-documented processes for reporting vulnerabilities in community modules.
  • Maintain and make available data on disclosed security vulnerabilities in:
    • the core Node.js project
    • other projects maintained by the Node.js Foundation technical group
    • the external Node.js open source ecosystem
  • Promote the improvement of security practices within the Node.js ecosystem.
  • Facilitate and promote the expansion of a healthy security service and product provider ecosystem.

This Working Group is not responsible for managing or responding to security reports against Node.js itself. That responsibility remains with the Node.js TSC.

Node.js Bug Bounty Program

The program is managed through the HackerOne platform at https://hackerone.com/nodejs with further details.

Current Initiatives

We are currently defining the Initiatives for 2023, feel free to participate.

Initiative Champion Status Links
Permission Model @RafaelGSS In Progress PR #44004
Automate update dependencies @facutuesca In Progress Issue #828
Assessment against best practices @fraxken In Progress Issue #859
Automate Security release process @RafaelGSS In Progress Issue #860

Current Project Team Members

Emeritus Members

Code of Conduct

The Node.js Code of Conduct applies to this WG.

Moderation Policy

The Node.js Moderation Policy applies to this WG.

security-wg's People

Contributors

bengl avatar brycebaril avatar chalker avatar cjihrig avatar danbev avatar danielruf avatar dependabot[bot] avatar dgonzalez avatar evilpacket avatar fraxken avatar greysteil avatar grnd avatar joker314 avatar knqyf263 avatar lirantal avatar marcinhoppe avatar mcollina avatar mgalexander avatar mhdawson avatar mikesamuel avatar nschonni avatar pxlpnk avatar rafaelgss avatar ronperris avatar rvagg avatar sam-github avatar trott avatar ulisesgascon avatar vdeturckheim avatar waveywaves avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.