Node.js Ecosystem Security Working Group
548
stars
849
commits
Go
primary language
Aug 25, 2026
updated
Table of Contents
This team is not responsible for managing or responding to security reports against Node.js itself. That responsibility remains with the Node.js TSC.
The program is managed through the HackerOne platform at https://hackerone.com/nodejs with further details.
| Initiative | Champion | Status | Links |
|---|---|---|---|
| Automate Security release process | @marco-ippolito / @RafaelGSS | In Progress | Issue #860 |
| Node.js maintainers: Threat Model | Group effort | In Progress | Issue #1333 |
| Audit build process for dependencies | @mhdawson | TODO | Issue #1037 |
| Adopt OpenJS CNA for CVE Operations | @UlisesGascon | In progress | Issue #1576 |
The Node.js Code of Conduct applies to this team.
The Node.js Moderation Policy applies to this team.
(top 30 of 71)
Go
62.9%
JavaScript
37.1%
Node.js Ecosystem Security Working Group
548
stars
849
commits
Go
primary language
Aug 25, 2026
updated
Table of Contents
This team is not responsible for managing or responding to security reports against Node.js itself. That responsibility remains with the Node.js TSC.
The program is managed through the HackerOne platform at https://hackerone.com/nodejs with further details.
| Initiative | Champion | Status | Links |
|---|---|---|---|
| Automate Security release process | @marco-ippolito / @RafaelGSS | In Progress | Issue #860 |
| Node.js maintainers: Threat Model | Group effort | In Progress | Issue #1333 |
| Audit build process for dependencies | @mhdawson | TODO | Issue #1037 |
| Adopt OpenJS CNA for CVE Operations | @UlisesGascon | In progress | Issue #1576 |
The Node.js Code of Conduct applies to this team.
The Node.js Moderation Policy applies to this team.
(top 30 of 71)
Go
62.9%
JavaScript
37.1%