Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Learn more about potential security audit #1094

Closed
mhdawson opened this issue Aug 31, 2023 · 10 comments
Closed

Learn more about potential security audit #1094

mhdawson opened this issue Aug 31, 2023 · 10 comments
Labels

Comments

@mhdawson
Copy link
Member

One of the requirements for the OSSF best practices Gold Level badge is a security audit every 5 years.

Through the Sovereign tech fund OpenJS will be supported some security audits for OpenJS projects. The discussion the security team meeting today on the Gold level badge had team members wondering about what an audit might look like and how they are carried out.

@bensternthal @rginn would it be possible to have somebody come to a future Security team meeting to present/lead a discussion on that?

@bensternthal
Copy link

Yes we can do that. We are working with OSTIF, and I am sure they would be both willing and happy to chat.

@mhdawson
Copy link
Member Author

mhdawson commented Sep 1, 2023

@bensternthal would it be possible to schedule it for one of the next Security team meetings. The next two are Thursday Sep 14 at 10 ET and then Thursday the 28th of Sep at 10 ET

@bensternthal
Copy link

I invited Amir to both. He is traveling during this time but will let us know which meeting will work for him when we get closer.

@bensternthal
Copy link

Amir will be attending today's meeting.

@bensternthal
Copy link

Oops invited him to the security collab space meetings by accident.

I will get him on the node meetings :)

@UlisesGascon
Copy link
Member

@bensternthal this is the next meeting details: #1100

@bensternthal
Copy link

Amir will unfortunately not be able to attend tomorrow's meeting.

@bensternthal
Copy link

Confirmed. Amir will attend the Node.js TSC Meeting on Wednesday, September 27⋅06:00 – 07:00 (PT)

Copy link
Contributor

This issue is stale because it has been open many days with no activity. It will be closed soon unless the stale label is removed or a comment is made.

@github-actions github-actions bot added the stale label Dec 12, 2023
@RafaelGSS
Copy link
Member

Closing it as completed since we have Amir on board.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants