From 4bfdba9ff0efbf7553dddf0cc01e088b987da0ff Mon Sep 17 00:00:00 2001 From: Sam Roberts Date: Thu, 4 Jul 2019 14:41:33 -0700 Subject: [PATCH] doc: link to the Node.js triage team Remove teams unused since vulnerability tracking moved to HackerOne --- README.md | 3 +- processes/security_team_members.md | 122 +++++++++++------------------ 2 files changed, 47 insertions(+), 78 deletions(-) diff --git a/README.md b/README.md index 0ea06964d..d63d42143 100644 --- a/README.md +++ b/README.md @@ -138,7 +138,7 @@ undisclosed vulnerabilities in any of the Node.js programs on HackerOne Managed by the [Ecosystem Triage Team][]. * [*Node.js Vulnerabilities*](https://hackerone.com/nodejs): Managed by the - @nodejs/security team. + [Node.js Triage Team][]. # Code of Conduct @@ -150,3 +150,4 @@ The [Node.js Moderation Policy](https://github.com/nodejs/admin/blob/master/Mode [Node.js TSC]: https://github.com/nodejs/TSC [Ecosystem Triage Team]: processes/third_party_vuln_process.md#members +[Node.js Triage Team]: processes/security_team_members.md#team-that-triages-security-reports-against-node-core diff --git a/processes/security_team_members.md b/processes/security_team_members.md index fa33d86a4..c0ea78ef4 100644 --- a/processes/security_team_members.md +++ b/processes/security_team_members.md @@ -13,88 +13,56 @@ and must be approved by current team members. Members of the security teams should indicate that they accept the privacy policies by PRing their acceptance to this file. -## Team that triages security reports against node core +## Team that triages security reports against Node.js -- @cjihrig - **Colin Ihrig** -- @indutny - **Fedor Indutny** -- @jasnell - **James M Snell** -- @mcollina - **Matteo Colina** -- @mhdawson - **Michael Dawson** -- @MylesBorins - **Myles Borins** -- @rvagg - **Rod Vagg** -- @vdeturckheim - **Vladimir de Turckheim** +The [TSC](https://github.com/nodejs/node#tsc-technical-steering-committee) +are all members of the Triage Team. -### Emeritus +These non-TSC and TSC Emeriti are Triage Team members: +- [bnoordhuis](https://github.com/bnoordhuis) - **Ben Noordhuis** +* [indutny](https://github.com/indutny) - **Fedor Indutny** +* [rvagg](https://github.com/rvagg) - **Rod Vagg** +- [vdeturckheim](https://github.com/vdeturckheim) - **Vladimir de Turckheim** -- @bnoordhuis - **Ben Noordhuis** -- @jasnell - **James M Snell** -- @shigeki - **Shigeki Ohtsu** - -List is from ["security" alias](https://github.com/nodejs/email/blob/master/iojs.org/aliases.json). - -## Team with access to security issues - -- @ChALkeR - **Сковорода Никита Андреевич** -- @Fishrock123 - **Jeremiah Senkpiel** -- @MylesBorins - **Myles Borins** -- @Trott - **Rich Trott** -- @addaleax - **Anna Henningsen** -- @bnoordhuis - **Ben Noordhuis** -- @cjihrig - **Colin Ihrig** -- @dougwilson - **Douglas Wilson** -- @ejratl - **Emily Ratliff** -- @evanlucas - **Evan Lucas** -- @evilpacket - **Adam Baldwin** -- @grnd - **Danny Grander** -- @indutny - **Fedor Indutny** -- @jasnell - **James M Snell** -- @jbergstroem - **Johan Bergström** -- @joaocgreis - **João Reis** -- @joshgav - **Josh Gavant** -- @mhdawson - **Michael Dawson** -- @mscdex - **Brian White** -- @ofrobots - **Ali Ijaz Sheikh** -- @rvagg - **Rod Vagg** -- @saghul - **Saúl Ibarra Corretgé** -- @sam-github - **Sam Roberts** -- @shigeki - **Shigeki Ohtsu** -- @targos - **Michaël Zasso** -- @thefourtheye - **Sakthipriyan Vairamani** -- @trevnorris - **Trevor Norris** - -List is from [nodejs/teams/security](https://github.com/orgs/nodejs/teams/security/members). +List is from the [member page](https://hackerone.com/nodejs/team_members) for +the Node.js program on HackerOne. ## Team with access to private security patches -- @addaleax Anna Henningsen -- @bnoordhuis Ben Noordhuis -- @ChALkeR Сковорода Никита Андреевич -- @cjihrig Colin Ihrig -- @dougwilson Douglas Wilson -- @evanlucas Evan Lucas -- @evilpacket Adam Baldwin -- @Fishrock123 Jeremiah Senkpiel -- @hackygolucky Tracy -- @indutny Fedor Indutny -- @jasnell James M Snell -- @jbergstroem Johan Bergström -- @joaocgreis João Reis -- @joshgav Josh Gavant -- @mhdawson Michael Dawson -- @mrhinkle Mark Hinkle -- @MylesBorins Myles Borins -- @ofrobots Ali Ijaz Sheikh -- @rvagg Rod Vagg -- @saghul Saúl Ibarra Corretgé -- @sam-github Sam Roberts -- @targos Michaël Zasso -- @thefourtheye Sakthipriyan Vairamani -- @Trott Rich Trott + -List is from -[orgs/nodejs-private/people](https://github.com/orgs/nodejs-private/people), -who have access to -[nodejs-private/node-private](https://github.com/nodejs-private/node-private). +- [@addaleax](https://github.com/addaleax) - Anna Henningsen +- [@apapirovski](https://github.com/apapirovski) - Anatoli Papirovski +- [@BethGriggs](https://github.com/BethGriggs) - Bethany Nicolle Griggs +- [@bnoordhuis](https://github.com/bnoordhuis) - Ben Noordhuis +- [@BridgeAR](https://github.com/BridgeAR) - Ruben Bridgewater +- [@ChALkeR](https://github.com/ChALkeR) - Сковорода Никита Андреевич +- [@cjihrig](https://github.com/cjihrig) - Colin Ihrig +- [@codebytere](https://github.com/codebytere) - Shelley Vohr +- [@danbev](https://github.com/danbev) - Daniel Bevenius +- [@dougwilson](https://github.com/dougwilson) - Douglas Wilson +- [@evanlucas](https://github.com/evanlucas) - Evan Lucas +- [@evilpacket](https://github.com/evilpacket) - Adam Baldwin +- [@fhinkel](https://github.com/fhinkel) - F. Hinkelmann +- [@Fishrock123](https://github.com/Fishrock123) - Jeremiah Senkpiel +- [@gabrielschulhof](https://github.com/gabrielschulhof) - Gabriel Schulhof +- [@gibfahn](https://github.com/gibfahn) - Gibson Fahnestock +- [@gireeshpunathil](https://github.com/gireeshpunathil) - Gireesh Punathil +- [@indutny](https://github.com/indutny) - Fedor Indutny +- [@jasnell](https://github.com/jasnell) - James M Snell +- [@jbergstroem](https://github.com/jbergstroem) - Johan Bergström +- [@joaocgreis](https://github.com/joaocgreis) - João Reis +- [@joyeecheung](https://github.com/joyeecheung) - Joyee Cheung +- [@mcollina](https://github.com/mcollina) - Matteo Collina +- [@mhdawson](https://github.com/mhdawson) - Michael Dawson +- [@MylesBorins](https://github.com/MylesBorins) - Myles Borins +- [@rvagg](https://github.com/rvagg) - Rod Vagg +- [@saghul](https://github.com/saghul) - Saúl Ibarra Corretgé +- [@sam-github](https://github.com/sam-github) - Sam Roberts +- [@shigeki](https://github.com/shigeki) - Shigeki Ohtsu +- [@targos](https://github.com/targos) - Michaël Zasso +- [@thefourtheye](https://github.com/thefourtheye) - Sakthipriyan Vairamani +- [@Trott](https://github.com/Trott) - Rich Trott +- [@vdeturckheim](https://github.com/vdeturckheim) - Vladimir de Turckheim -Every member of the team with access to security issues should have access to -the private security patches as well. +