# Node.js Security team Meeting 2026-04-16 ## Links * **Recording**: * **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1563 * **Minutes**: https://hackmd.io/@openjs-nodejs/Sk72KaHh-e ## Present * Security wg team: @nodejs/security-wg ## Agenda ## Announcements *Extracted from **security-wg-agenda** labelled issues and pull requests from the **nodejs org** prior to the meeting. - [ ] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues - [ ] OpenSSF Scorecard Monitor Review - https://github.com/nodejs/security-wg/issues?q=is%3Aissue+OpenSSF+Scorecard+Report+Updated%21+ ### nodejs/security-wg * regenerate node.openvex.json [#1562](https://github.com/nodejs/security-wg/pull/1562) * Tracking: LLM-assisted H1 report triage [#1554](https://github.com/nodejs/security-wg/issues/1554) * Node.js PURL is missing namespace [#1552](https://github.com/nodejs/security-wg/issues/1552) ### nodejs/TSC * Proposal: Moving security reports to a public workflow [#1826](https://github.com/nodejs/TSC/issues/1826) ### nodejs/nodejs-dependency-vuln-assessments * feat: add VEX automation for closed issues [#225](https://github.com/nodejs/nodejs-dependency-vuln-assessments/pull/225) ## Q&A, Other ## Upcoming Meetings * **Node.js Project Calendar**: <https://nodejs.org/calendar> Click `Add to Google Calendar` at the bottom left to add to your own Google calendar.