Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reaching out to other projects of the OpenJS Foundation #511

Closed
vdeturckheim opened this issue Apr 5, 2019 · 23 comments
Closed

Reaching out to other projects of the OpenJS Foundation #511

vdeturckheim opened this issue Apr 5, 2019 · 23 comments
Labels

Comments

@vdeturckheim
Copy link
Member

We should probably start to reach out to other projects in the Foundation to check which ones would be interested in building a larger security community around JavaScript.

Do we have any way to setup such discussion?

@mhdawson
Copy link
Member

mhdawson commented Apr 5, 2019

One the CPC is established there will be representatives from each of the projects and it should be pretty easy. At this point @jorydotcom would be the best intermediary. It might be good to wait for the CPC to ramp up but if we want to start earlier than that then we could start by reaching out to Jory for contacts.

@vdeturckheim
Copy link
Member Author

@mhdawson thanks for the clarifications! Let's wait for the CPC indeed.

@jorydotcom
Copy link

@vdeturckheim in the interim I can sent an old-fashioned email to our old-fashioned JSF mailing list pointing folks to this repo!

@vdeturckheim
Copy link
Member Author

@jorydotcom thanks a lot! Let's discuss this in our next meeting!

@christian-bromann
Copy link

I am in 💪

@sam-github
Copy link
Contributor

Discussed at #541 , removing from agenda (but please add back if it should be discussed again).

@sam-github
Copy link
Contributor

@mhdawson
Copy link
Member

mhdawson commented Oct 8, 2019

This was mentioned in the CPC meeting today in the context of openjs-foundation/cross-project-council#326. I think its the right time to discuss/make a decision on what we think is best.

@nodejs/security-wg what are your thoughts? I'm thinking it would make sense to have a group at the OpenJS level, and that the ecosystem triage might fit at that level as well.

@lirantal
Copy link
Member

lirantal commented Oct 8, 2019

I think that's a good idea and perhaps that's an additional one on top of the Node.js one. Just a thought, but I figure that at that level there will be many project ecosystems and so processes and systems (i.e: H1) might vary. So to say, I don't think we'd be copy&pasting the Node.js Security WG to the OpenJS as-is.

@MarcinHoppe
Copy link
Contributor

If I understand things correctly, the scope here is slightly different: for the Node.js ecosystem we are handling responsible disclosure to a large extent and for OpenJS right now we are more interested in having consistent policies across several high profile projects. Then helping those projects out from triage and disclosure perspective (as we do today for Node.js) would be the next step.

@mhdawson @lirantal Does it sounds reasonable?

@sam-github
Copy link
Contributor

Note that this program is already implicitly handling triage and disclosure for some of https://openjsf.org/projects/, because they are published to npmjs.com

As I noted during the initial adoption of the nsp vuln DB, calling it a "node.js vuln DB" is inaccurate, since its scope is packages on npmjs.com, and while many of those packages run in node.js, many run in the browser, many are CLI tools that run in node.js but are only used for browser development, some only run in the browser, and a tiny minority aren't in js at all...

@MarcinHoppe
Copy link
Contributor

@sam-github Thanks for calling this out, this is definitely true.

@sam-github
Copy link
Contributor

Feedback from last sec-wg meeting: For this to move forward, it will need a champion, someone willing to follow up with the OpenJS foundation, and keep this moving forward. Do we have a volunteer?

@jorydotcom
Copy link

@sam-github @mhdawson I'm happy to help broadcast this group's meetings or generally put out a call for participation in the weekly update I send out to the projects email list. Also, we could encourage some discussion in the openjsf slack workspace.

@MarcinHoppe
Copy link
Contributor

@jorydotcom I'd love to be a part of this. I already had a preliminary conversation about it with @mhdawson. I will reach out on Slack.

@sam-github
Copy link
Contributor

There doesn't seem to be any topic to discuss live, so removed agenda.

If folks want to champion this, they should get involved, it seems reasonable.

@MarcinHoppe
Copy link
Contributor

I am already doing some work with the CPC but it's progressing very slowly, mostly due to my availability. I will report back when there is progress.

For now we have a stage 0 proposal about security reporting for OpenJSF projects:

openjs-foundation/cross-project-council#489

@lirantal
Copy link
Member

Is it worth to create a new doc in processes/ folder to document progress which you can PR to as things progress and close this one?

@MarcinHoppe
Copy link
Contributor

Or perhaps link to process docs being worked on with the OpenJSF CPC?

@lirantal
Copy link
Member

Yep, good enough too.

@MarcinHoppe
Copy link
Contributor

I need to take one more action on the OpenJSF proposal. I will link to that proposal from our docs next week and close this issue then.

@fraxken
Copy link
Member

fraxken commented Jul 17, 2022

@MarcinHoppe can we close the issue ?

@fraxken fraxken closed this as completed Jul 17, 2022
@fraxken fraxken reopened this Jul 17, 2022
@github-actions
Copy link
Contributor

This issue is stale because it has been open many days with no activity. It will be closed soon unless the stale label is removed or a comment is made.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

8 participants