-
-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Universal Action to rotate NPM keys #46
Comments
I think the main thing we need to work out is the automated release workflows. This is what @sheplu will be working on as part of our STF funding this year. I have pretty strong opinions on this but probably not yet the time for me to write it up here. I will jot down some basic requirements I think we have though.
|
Thanks for the summary @wesleytodd. @sheplu happy to discuss this with you! |
What level of engagement would you like from me here? I can assist with the below security items:
I am personally invested in the security of this project as Express.JS is a critical supply chain item for my projects/apps. |
Thanks for the offer @elliot-huffman! We will be putting together plans in the coming weeks afaik and am sure there will be things which can be helped with. I would suggest starting with finding and engaging in the many existing discussions in our repos and finding where there are already opportunities to contribute, then engaging in a discussion in our Slack (on the OpenJS Slack workspace). As much of this work is funded by the STF I believe there will be more structure around the work than normal so that it can all be reported correctly, so make sure to sync with @sheplu on it as he is leading that milestone. |
Hi folks,
I'm opening this issue just to get more attention from the express side. I opened fastify/fastify#5984 to discuss a feasible approach to rotate npm keys across many repositories of an organization, and I believe the same problem we are facing on
fastify
would happen here.@UlisesGascon has mentioned you all would be working on something similar soon, so I thought I could help and we could create something more universal. Where can I get more info about this initiative?
The text was updated successfully, but these errors were encountered: