Skip to content

Conversation

@fraxken
Copy link
Member

@fraxken fraxken commented Mar 4, 2023

Hello 👋

Updating the WORKING_GROUPS.md file following recommandation of @mhdawson in the following issue: nodejs/security-wg#874

I've made the same changes:

  • remove reference to legacy nsp (Node Security Project) which was acquired by npm inc. (which was then acquired by GitHub)
  • remove "ecosystem" prefix for the WG as this has been promoted & is canonically known as Node.js's "Security WG"

@Trott
Copy link
Member

Trott commented Mar 4, 2023

If I'm not mistaken, the name and the responsibilities come from the working group's charter and can only be changed by the TSC. However, consensus should be sufficient for such a change. @nodejs/tsc

@Trott
Copy link
Member

Trott commented Mar 4, 2023

When this working group was initially chartered, it was proposed to name it "Security working group" but people (including me) were concerned that they would start receiving vulnerability reports about Node.js from well-meaning researchers and other community members. Is that still a concern of TSC members?

@Trott
Copy link
Member

Trott commented Mar 4, 2023

I'm putting this on the TSC agenda to maximize TSC input. Consensus should be enough for this--it shouldn't require a vote unless there are one or more TSC members opposed (and one or more in favor).

@fraxken fraxken force-pushed the update-security-wg branch from 5ad80f9 to f37ae3d Compare March 6, 2023 19:17
Copy link
Member

@mcollina mcollina left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Copy link
Member

@mhdawson mhdawson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Member

@mhdawson mhdawson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Trott Trott merged commit ea020c4 into nodejs:main Mar 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.