Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: added potential initiatives for 2023 #854

Merged
merged 4 commits into from
Jan 3, 2023
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
15 changes: 15 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,21 @@ the [Node.js TSC][].

The program is managed through the HackerOne platform at [https://hackerone.com/nodejs](https://hackerone.com/nodejs) with further details.

## Current Initiatives

We are currently defining the Initiatives for 2023, [feel free to participate](https://github.com/nodejs/security-wg/issues/846).

| Initiative | Champion | Status | Links
|----------------------|--------------------------------------------------|------------------------------------------|-------------------------------------------------
| Permission Model | [@RafaelGSS](https://github.com/RafaelGSS) | PR In Review | [PR #44004](https://github.com/nodejs/node/pull/44004)
| Automate update dependencies | [@facutuesca](https://github.com/facutuesca) | Well defined | [Issue #828](https://github.com/nodejs/security-wg/issues/828)
UlisesGascon marked this conversation as resolved.
Show resolved Hide resolved
| Flag to emit a warning when vulnerable | [@RafaelGSS](https://github.com/RafaelGSS) | Started TSC Discussion | _pending_
UlisesGascon marked this conversation as resolved.
Show resolved Hide resolved
| Enforce communication with Node.js dependencies | N/A | Under discussion | [Issue #846](https://github.com/nodejs/security-wg/issues/846)
| Explore using SigStore to sign our releases | N/A | Under discussion | [Issue #846](https://github.com/nodejs/security-wg/issues/846)
| Figure out how we stand in terms of key supply chain standards/frameworks | N/A | Under discussion | [Issue #846](https://github.com/nodejs/security-wg/issues/846)
| Explore how the projects stand on the OSSF Scorecard | N/A | Under discussion | [issue #851](https://github.com/nodejs/security-wg/issues/851)
| Better versioning and management of tools need to build/update dependencies | N/A | Under discussion | [Issue #846](https://github.com/nodejs/security-wg/issues/846)
UlisesGascon marked this conversation as resolved.
Show resolved Hide resolved

## Current Project Team Members

* [ChALkeR](https://github.com/ChALkeR) - **Сковорода Никита Андреевич**
Expand Down