Skip to content

Update Security Working Group - #1348

Merged
Trott merged 1 commit into
nodejs:mainfrom
FraxkenFork:update-security-wg
Mar 15, 2023
Merged

Trott merged 1 commit into
nodejs:mainfrom
FraxkenFork:update-security-wg

Conversation

@fraxken

@fraxken fraxken commented Mar 4, 2023

Copy link
Copy Markdown
Member

Hello 👋

Updating the WORKING_GROUPS.md file following recommandation of @mhdawson in the following issue: nodejs/security-wg#874

I've made the same changes:

  • remove reference to legacy nsp (Node Security Project) which was acquired by npm inc. (which was then acquired by GitHub)
  • remove "ecosystem" prefix for the WG as this has been promoted & is canonically known as Node.js's "Security WG"

Comment thread WORKING_GROUPS.md Outdated
@Trott

Trott commented Mar 4, 2023 •

Copy link
Copy Markdown
Member

If I'm not mistaken, the name and the responsibilities come from the working group's charter and can only be changed by the TSC. However, consensus should be sufficient for such a change. @nodejs/tsc

@Trott

Trott commented Mar 4, 2023

Copy link
Copy Markdown
Member

When this working group was initially chartered, it was proposed to name it "Security working group" but people (including me) were concerned that they would start receiving vulnerability reports about Node.js from well-meaning researchers and other community members. Is that still a concern of TSC members?

@Trott

Trott commented Mar 4, 2023

Copy link
Copy Markdown
Member

I'm putting this on the TSC agenda to maximize TSC input. Consensus should be enough for this--it shouldn't require a vote unless there are one or more TSC members opposed (and one or more in favor).

@fraxken
fraxken force-pushed the update-security-wg branch from 5ad80f9 to f37ae3d Compare March 6, 2023 19:17

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@mhdawson mhdawson left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mhdawson mhdawson left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Trott
Trott merged commit ea020c4 into nodejs:main Mar 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.