nodejs / nodejs/security-wg

Node.js Security team Meeting 2026-09-03

Open
#1,583 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
548
Forks
133
Avg merge
1d 22h
Merged PRs (30d)
2

Description

Time

UTC Thu, Sep 03, 2026, 02:00 PM:

Timezone Date/Time
US / Pacific Thu, Sep 03, 2026, 07:00 AM
US / Mountain Thu, Sep 03, 2026, 08:00 AM
US / Central Thu, Sep 03, 2026, 09:00 AM
US / Eastern Thu, Sep 03, 2026, 10:00 AM
EU / Western Thu, Sep 03, 2026, 03:00 PM
EU / Central Thu, Sep 03, 2026, 04:00 PM
EU / Eastern Thu, Sep 03, 2026, 05:00 PM
Moscow Thu, Sep 03, 2026, 05:00 PM
Chennai Thu, Sep 03, 2026, 07:30 PM
Hangzhou Thu, Sep 03, 2026, 10:00 PM
Tokyo Thu, Sep 03, 2026, 11:00 PM
Sydney Fri, Sep 04, 2026, 12:00 AM

Or in your local time:

Links

Invited

  • Security wg team: @nodejs/security-wg
Observers/Guests

None.

Agenda

Issues and Pull Requests

Extracted from security-wg-agenda labelled issues and pull requests from the nodejs org prior to the meeting.

nodejs/security-wg
  • Backlog: Adopt OpenJS CNA for CVE Operations #1576
  • regenerate node.openvex.json #1574
  • AI-assisted H1 report triage - TSC 2026-05-27 follow up #1566
nodejs/TSC
  • Proposal: Moving security reports to a public workflow #1826
nodejs/nodejs-dependency-vuln-assessments
  • feat: add VEX automation for closed issues #225

Joining the meeting


Invitees

Please use the following emoji reactions in this post to indicate your availability.

  • 👍 - Attending
  • 👎 - Not attending
  • 😕 - Not sure

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

This issue is a meeting announcement rather than an implementation task. Read the meeting time, agenda, linked issues and pull requests, plus the meeting minutes link. There is no code change or completion criterion described for a contributor.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.