loopbackio / loopbackio/security

Track adoption of potential OpenJSF Security Program

Offen
#23 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
TypeScript
Sterne
4
Forks
1
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

The OpenJS Foundation (OpenJSF) (and previously Node.js Foundation) has indicated plans of creating a new security program for the Node.js ecosystem, scoped more narrowly to the OpenJSF projects.

The previous Node.js Third-Party Ecosystem Security Program that was managed by the Node.js Security Working Group was scoped to:

  • Managed a HackerOne Program with bounties for select NPM packages
  • Managed a vulnerability database for NPM packages (initially donated by NSP)

Although it's not clear at this moment what this new program would entail, it seems like it might be a lift-and-shift, but with a focus on OpenJSF projects.

This issue is to track this work of the OpenJSF and to hold discussions on its applicability to LoopBack.

see: https://github.com/openjs-foundation/cross-project-council/issues/826#issuecomment-1077764219
see: https://github.com/nodejs/security-wg/issues/662#issuecomment-637623656
see: https://github.com/nodejs/security-wg/issues/494#issuecomment-780019393
see: https://github.com/nexB/vulnerablecode/issues/488#issuecomment-868489895

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne damit, das verlinkte Issue des OpenJS Foundation cross-project-council sowie die in der Beschreibung zitierten Issues der Node.js Security Working Group zu lesen. Vergleiche das vorgeschlagene Programm mit dem bisherigen Umfang der HackerOne- und NPM-Schwachstellendatenbank und dokumentiere anschließend, ob und wie es auf LoopBack anwendbar ist, sobald die Pläne von OpenJSF klar sind.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
nodejs
Bereich
security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.