Skip to content

Node.js Security WG Initiatives 2023 #846

@RafaelGSS

Description

@RafaelGSS

Hey!

Since May 2022 the Security WG was reactivated and the team took the lead in 4 initiatives:

  1. Node.js Dependency Vulnerability Workflow (Done)
  2. Node.js Threat Model (Done)
  3. Node.js Security Best Practices (Done)
  4. Permission System (Work-in-progress)

First of all, thanks to everyone that helped on that journey, brilliant work.

As I mentioned on #843, it's time to think about future initiatives to improve the Node.js security ecosystem. So, I'd like to use this issue as a brainstorming thread to share some ideas. Ideally, share the problem and a potential solution, but, if you don't have a clear solution, don't worry, share it anyway.

This thread will be reviewed and discussed through the Node.js Security WG meetings (feel free to join).

@nodejs/security-wg

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions