security-wg icon indicating copy to clipboard operation
security-wg copied to clipboard

Node.js Ecosystem Security Working Group

Node.js Security WG Security WG Meetings Security WG Twitter Hashtag Security Responsible Disclosure

Ecosystem Security Working Group

Table of Contents

  • Vulnerability Management
    • Vulnerability Database
    • Recognition for Security Researchers
  • Processes for Security WG Members
    • Security Team Membership Policy
    • On-boarding Team Members
    • Off-boarding Team Members
  • Node.js Bug Bounty Program
  • Charter
  • Code of Conduct
  • Moderation Policy
  • Current Project Team Members
  • Emeritus Members

Charter

The Ecosystem Security Working Group works to improve the security of the Node.js Ecosystem.

Responsibilities include:

  • Work with the Node Security Platform to bring community vulnerability data into the foundation as a shared asset.
  • Ensure the vulnerability data is updated in an efficient and timely manner. For example, ensuring there are well-documented processes for reporting vulnerabilities in community modules.
  • Maintain and make available data on disclosed security vulnerabilities in:
    • the core Node.js project
    • other projects maintained by the Node.js Foundation technical group
    • the external Node.js open source ecosystem
  • Promote the improvement of security practices within the Node.js ecosystem.
  • Facilitate and promote the expansion of a healthy security service and product provider ecosystem.

This Working Group is not responsible for managing or responding to security reports against Node.js itself. That responsibility remains with the Node.js TSC.

Node.js Bug Bounty Program

The program is managed through the HackerOne platform at https://hackerone.com/nodejs with further details.

Current Project Team Members

Emeritus Members

Code of Conduct

The Node.js Code of Conduct applies to this WG.

Moderation Policy

The Node.js Moderation Policy applies to this WG.