Giter VIP home page Giter VIP logo

security-wg's Introduction

Node.js Security WG Security WG Meetings Security WG Twitter Hashtag GitHub Logo Security Responsible Disclosure

Ecosystem Security Working Group

Table of Contents

The Ecosystem Security Working Group works to improve the security of the Node.js Ecosystem.

Responsibilities include:

  • Work with the Node Security Platform to bring community vulnerability data into the foundation as a shared asset.
  • Ensure the vulnerability data is updated in an efficient and timely manner. For example, ensuring there are well-documented processes for reporting vulnerabilities in community modules.
  • Define and maintain policies and procedures for the coordination of security concerns within the external Node.js open source ecosystem.
  • Offer help to npm package maintainers to fix high-impact security bugs.
  • Maintain and make available data on disclosed security vulnerabilities in:
    • the core Node.js project
    • other projects maintained by the Node.js Foundation technical group
    • the external Node.js open source ecosystem
  • Promote the improvement of security practices within the Node.js ecosystem.
  • Facilitate and promote the expansion of a healthy security service and product provider ecosystem.

This Working Group is not responsible for managing or responding to security reports against Node.js itself. That responsibility remains with the Node.js TSC.

Node.js Bug Bounty Program

The Node.js project engages in an official bug bounty program for security researchers and responsible public disclosures. We have established a first draft of accepted criteria and npm modules and projects that are eligible for monetary reward at Bug Bounty Criteria.

The program is managed through the HackerOne platform at https://hackerone.com/nodejs with further details.

Participate in Responsible Security Disclosure

As a module author you can provide your users with security guidelines regarding any exposures and vulnerabilities in your project, based on a responsible dislcosure policy document we've already put in place.

You can show your users you take security matters seriously and drive higher confidence by following any of the below suggested actions:

  1. Adding a SECURITY.md file in your repository that you can copy&paste from us. Just like having a contribution of code of conduct guidelines, a security guideline will help user or bug hunters with the process of reporting a vulnerability or security concern they would like to share.

  2. Adding our Responsible Security Dislosure badge to your project's README which links to the SECURITY.md document.

Current Project Team Members

Emeritus Members

Ecosystem Vulnerability Triage Team

Note that membership in the Ecosystem Security WG does not automatically give access to undisclosed vulnerabilities on HackerOne

Code of Conduct

The Node.js Code of Conduct applies to this WG.

Moderation Policy

The Node.js Moderation Policy applies to this WG.

security-wg's People

Contributors

lirantal avatar vdeturckheim avatar chalker avatar sam-github avatar mhdawson avatar greysteil avatar dgonzalez avatar rvagg avatar marcinhoppe avatar evilpacket avatar trott avatar bengl avatar grnd avatar mgalexander avatar mikesamuel avatar brycebaril avatar ronperris avatar mcollina avatar cjihrig avatar pxlpnk avatar waveywaves avatar joker314 avatar yonjah avatar tomoyamachi avatar bnb avatar knqyf263 avatar refack avatar reedloden avatar rajivshah3 avatar mbleigh avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.