expressjs / security-wg

Express.js Security Working Group

Repository from Github https://github.comexpressjs/security-wgRepository from Github https://github.comexpressjs/security-wg

Express.js Threat Model

UlisesGascon opened this issue · comments

Good news the proposal expressjs/express#5526 in in the oven 🎉

Next step, as discussed with @ruddermann is to prepare a private meeting with the @expressjs/security-triage to cover the details before #6 starts.

So I move the discussion for this to Slack private channel

Relevant links

Current discussion about the Threat Model:

  • Regarding prototype pollution context. see
  • Regarding Middleware/Plugins/libraries. see