Backlog: Adopt OpenJS CNA for CVE Operations
Open
@UlisesGascon is already working on this.
Since Jul 6, 2026.
security-wg-agenda
wg-agenda
- Dominant language
- Go
- Stars
- 548
- Forks
- 133
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 2
Description
This issue is for tracking the initiative to adopt OpenJS CNA for CVE Operations.
Blockers:
- We are waiting until
Phase 1: Build the APIhttps://github.com/openjs-foundation/security-wg/issues/337 is completed to porperly test the workflow with NCU
Backlog:
- Update Node.js Security process documentation (https://github.com/nodejs/node/pull/63894)
- Add support to the OpenJS CNA to NCU (https://github.com/nodejs/node-core-utils/pull/1093)
- Check how the H1 integration will work (confirm workflow and data details)
- Check if @UlisesGascon can get an API Token in H1 to validate the implementation
References:
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.