-
-
Notifications
You must be signed in to change notification settings - Fork 4
Closed
Description
Prompted by https://openjs-foundation.slack.com/archives/CVAMEJ4UV/p1757449417911409, we should create incident response plans for the services & tools that the web team maintains.
As to what this can detail,
- For general public,
- Repeat how to report a vulnerability
- For members of the web team,
- General directions on what to do in the event of a security incident
- Specific per-repository directions if needed
- List of who should be involved
- Break glass procedures
- ...
Related: #14
cc @nodejs/security-wg
avivkeller