loopbackio / loopbackio/security
Track adoption of potential OpenJSF Security Program
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- TypeScript
- Sterne
- 4
- Forks
- 1
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
The OpenJS Foundation (OpenJSF) (and previously Node.js Foundation) has indicated plans of creating a new security program for the Node.js ecosystem, scoped more narrowly to the OpenJSF projects.
The previous Node.js Third-Party Ecosystem Security Program that was managed by the Node.js Security Working Group was scoped to:
- Managed a HackerOne Program with bounties for select NPM packages
- Managed a vulnerability database for NPM packages (initially donated by NSP)
Although it's not clear at this moment what this new program would entail, it seems like it might be a lift-and-shift, but with a focus on OpenJSF projects.
This issue is to track this work of the OpenJSF and to hold discussions on its applicability to LoopBack.
see: https://github.com/openjs-foundation/cross-project-council/issues/826#issuecomment-1077764219
see: https://github.com/nodejs/security-wg/issues/662#issuecomment-637623656
see: https://github.com/nodejs/security-wg/issues/494#issuecomment-780019393
see: https://github.com/nexB/vulnerablecode/issues/488#issuecomment-868489895
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne damit, das verlinkte Issue des OpenJS Foundation cross-project-council sowie die in der Beschreibung zitierten Issues der Node.js Security Working Group zu lesen. Vergleiche das vorgeschlagene Programm mit dem bisherigen Umfang der HackerOne- und NPM-Schwachstellendatenbank und dokumentiere anschließend, ob und wie es auf LoopBack anwendbar ist, sobald die Pläne von OpenJSF klar sind.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- nodejs
- Bereich
- security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Veraltet
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 25/100