PGP keys verification
Context
- The full context can be found at GHSA-76h5-j8cf-q8vj and GHSA-jcj3-qxpv-gxm2.
- Additional offline conversation at Slack
Action items
- [ ] As part of the onboarding the releasers should add the PGP key(s) to the Github profile, like Ulises' example
- [x] Create a PR to update the onboarding steps (@UlisesGascon). https://github.com/nodejs/Release/pull/966
- [ ] Ensure that all the releasers has completed this step
Aside: why is the website repo being used for security advisories? That doesn't seem to line up with the security reporting policy
Aside: why is the website repo being used for security advisories? That doesn't seem to line up with the security reporting policy
IDK, someone just created one for nodejs.org; I'm not sure if this is a setting on the nodejs.org repository, and if yes, if I should disable. cc @nodejs/tsc
I was checking the changes with the team, I am waiting for a final update for two signatures and then we can close this issue.
Is there any update here?