Skip to content

Create Security Incident Response Plans #40

@flakey5

Description

@flakey5

Prompted by https://openjs-foundation.slack.com/archives/CVAMEJ4UV/p1757449417911409, we should create incident response plans for the services & tools that the web team maintains.

As to what this can detail,

  • For general public,
    • Repeat how to report a vulnerability
  • For members of the web team,
    • General directions on what to do in the event of a security incident
    • Specific per-repository directions if needed
    • List of who should be involved
    • Break glass procedures
  • ...

Related: #14

cc @nodejs/security-wg

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions