Node.js Security team Meeting 2024-03-14
mhdawson opened this issue · comments
Time
UTC Thu 14-Mar-2024 14:00 (02:00 PM):
Timezone | Date/Time |
---|---|
US / Pacific | Thu 14-Mar-2024 07:00 (07:00 AM) |
US / Mountain | Thu 14-Mar-2024 08:00 (08:00 AM) |
US / Central | Thu 14-Mar-2024 09:00 (09:00 AM) |
US / Eastern | Thu 14-Mar-2024 10:00 (10:00 AM) |
EU / Western | Thu 14-Mar-2024 14:00 (02:00 PM) |
EU / Central | Thu 14-Mar-2024 15:00 (03:00 PM) |
EU / Eastern | Thu 14-Mar-2024 16:00 (04:00 PM) |
Moscow | Thu 14-Mar-2024 17:00 (05:00 PM) |
Chennai | Thu 14-Mar-2024 19:30 (07:30 PM) |
Hangzhou | Thu 14-Mar-2024 22:00 (10:00 PM) |
Tokyo | Thu 14-Mar-2024 23:00 (11:00 PM) |
Sydney | Fri 15-Mar-2024 01:00 (01:00 AM) |
Or in your local time:
- https://www.timeanddate.com/worldclock/fixedtime.html?msg=Node.js+Foundation+Security%20team+Meeting+2024-03-14&iso=20240314T1400
- or https://www.wolframalpha.com/input/?i=02PM+UTC%2C+Mar+14%2C+2024+in+local+time
Links
- Minutes Google Doc: https://docs.google.com/document/d/1eNytfV8Xm0x_K4ajb7kgLlw_9SnjE4hmLhydLD5u0-M/edit
Agenda
Extracted from security-wg-agenda labelled issues and pull requests from the nodejs org prior to the meeting.
nodejs/security-wg
- Proposed approach for build steps in deps which are not in make node #1236
- Security initiative in December 2023: fuzzing Nodejs: https://github.com/google/oss-fuzz/tree/master/projects/nodejs #1159
- Audit build process for dependencies #1037
- Initiative for CII-Best-Practices for Nodejs Projects #953
- Permission Model - Roadmap #898
Invited
- Security wg team: @nodejs/security-wg
Observers/Guests
Notes
The agenda comes from issues labelled with security-wg-agenda
across all of the repositories in the nodejs org. Please label any additional issues that should be on the agenda before the meeting starts.
Joining the meeting
- link for participants: <>
- For those who just want to watch We stream our conference call straight to YouTube so anyone can listen to it live, it should start playing at https://www.youtube.com/c/nodejs+foundation/live when we turn it on. There's usually a short cat-herding time at the start of the meeting and then occasionally we have some quick private business to attend to before we can start recording & streaming. So be patient and it should show up.
- youtube admin page: https://www.youtube.com/my_live_events?filter=scheduled
Invitees
Please use the following emoji reactions in this post to indicate your
availability.
- 👍 - Attending
- 👎 - Not attending
- 😕 - Not sure yet
@mhdawson I noticed the scheduled time has changed, I'm fine with it, I just wonder if its gonna change again?
@marco-ippolito I think that's because of the timezone change in North America, it will likely change for you again when the timezone changes in the UK at which point it should be back to the original time in both places.
I won't be able to make due the timezone change, but I will update the scorecard report:
- PR: #1248
- Issue: #1247 (with the review table)
- I am working on adding some changes in undici (BTW 8.5 score 🎉): nodejs/undici#2957