Read about the accomplishments for Node.js security for May!
Security for Node.js has continued to be a top priority for the OpenJS Foundation and the team has been progressing on the ease and function of security processes.
Read more below for details on the past month’s progress. The Open Source Security Foundation (OpenSSF) Project Alpha-Omega support has been critical in helping strengthen Node.js security practices – thank you!
34 reports were processed over March, April and May. We’re excited to share that the nodejs-cve-checker has been added to the Node.js organization. This is a simple tool that validates CVEs that were published to NVD after a Node.js Security Release.
Two major releases were coordinated in April, one for HTTP/2 & HTTP/1.1 fixes and the other for fixing Windows BadBatBug. The team coordinated these releases via MITRE with success. Check them at https://nodejs.org/en/blog/vulnerability.
Over the past few months, the team has been working on redefining a new set of security initiatives to work on for the remainder of 2024 and beyond. In addition to the below, the team also hopes to include prioritizing SBOMs in the future.
Additionally, Microsoft joined Node.js Security Team meeting to discuss a replacement to --policy-integrity and compromising on supporting an eventual feature.
The Permission Model has continued to gain traction and now includes support for `--allow-wasi` and `process.chdir`. There were other notable changes as well, including a breaking change for throwing async errors for async APIs.
This phase of the Permission Model is now complete per the Node.js Security Team.
The team has also redesigned processes to make the security release more streamlined – including updates to `node-core-utils`.
Interested in getting involved with Node.js security? We are actively looking for new contributors!
Find out more about the Node.js Security Team here: https://github.com/nodejs/security-wg.
If you want to join Node.js, there are multiple ways and places you can contribute. Please see here for more details: https://nodejs.org/en/get-involved/contribute. We also have a Slack channel for Node.js first contribution guidance – join `#nodejs-mentoring` if you are interested.