2021-01-08 Meeting Notes
Date
08 Jan 2021
Attendees
Discussion items
Time | Item | Who | Notes |
---|---|---|---|
Review Security Issues | Team | Review Kanban board | |
Stripes Node version restriction | The FOLIO Security Team should give the Technical Council a proposal how to proceed with STCOR-497 "Node.js TLS, HTTP and OpenSSL security vulnerabilities (CVE-2020-8265, CVE-2020-8287, CVE-2020-1971)" and the pull request stripes-core/pull/982. Option a): Close as "Won't do" and create a separate Jira to create documentation for DevOps and SysOps about secure Node versions. Option b): Commit. The pull request is a one-line change in stripes-core package.json: The engine "node" is incompatible with this module. Stripes developers don't want to take care for DevOps and SysOps that fail to use a fully-patched system and suggest option a) whereas option b) requires less effort for the whole project and results in security by default. For details see the discussion on stripes-core/pull/982. | ||
Safe harbor, policies | Safe Harbor Statement/Acceptable Use Policy - Mike will make this request next week for funding legal review. | ||
Creation of JIRA issues | Team | We talked in the past about having a Security Issue automatically be created if an email is sent to security@folio.org, and, we are currently relying on people reviewing the vulnerability reports.
|