Skip to content

Latest commit

 

History

History
80 lines (55 loc) · 3.31 KB

File metadata and controls

80 lines (55 loc) · 3.31 KB

Update April-May 2024

The following update is according to the Security Support Role document.

Each section points to at least one item on the priority list defined by the Security Support Role document.

1) Fix and Triage Security Issues

  • 34 reports were submitted during March 15 to May 31.

    • 3 New
    • 3 Triaged
    • 4 Duplicated
    • 4 Non applicable
    • 1 Spam
    • 19 Informative
  • nodejs-cve-checker is now part of Node.js organization

2) Support for Security Releases

  • Two security releases

    • April 3 - HTTP/2 & HTTP/1.1 fixes (High and Medium severity respectively)
    • April 10 - Fixing Windows BadBatBug (High severity)
    • Coordinated via MITRE with other platforms (Rust, PHP, ...)
  • Node.js 22 release (team effort - Rafael and Marco Ippolito)

  • Some updates to the release workflow were made

    • Mention export GPG=$(TTY) to show password UI when signing keys
    • Disable --follow-tags by default to avoid pushing "Working on" commit with the tag
  • Onboard Marco Ippolito to the Releasers team

3) Node.js Security Team Initiatives

Selected Initiatives for 2024:

    1. Automate Security release process - Champion: @RafaelGSS / @marco-ippolito
    1. Node.js maintainers: Threat Model - Champion: @nodejs/security-wg
    1. Audit build process for dependencies - Champion: @mhdawson

Please note we have skipped item 3 (SBOM) as we don't have a volunteer for that.

4) Node.js Security Sustainability

  • Active work on #nodejs-mentoring and live streams

5) Improving Security Processes