-
-
Notifications
You must be signed in to change notification settings - Fork 129
Closed
Labels
Description
Hey!
Since May 2022 the Security WG was reactivated and the team took the lead in 4 initiatives:
- Node.js Dependency Vulnerability Workflow (Done)
- Node.js Threat Model (Done)
- Node.js Security Best Practices (Done)
- Permission System (Work-in-progress)
First of all, thanks to everyone that helped on that journey, brilliant work.
As I mentioned on #843, it's time to think about future initiatives to improve the Node.js security ecosystem. So, I'd like to use this issue as a brainstorming thread to share some ideas. Ideally, share the problem and a potential solution, but, if you don't have a clear solution, don't worry, share it anyway.
This thread will be reviewed and discussed through the Node.js Security WG meetings (feel free to join).
@nodejs/security-wg