The main goal is to enable projects such as Node.js to use our API the same way they use HackerOne (compatibility layer). Also any other foundation project can use the HTTP API to manage their own CVEs. There are quite interesting features included in the API from the CNA perspective like credentials segmentation or guardrails on the payloads. This will help us to make easier for us to delegate the CVE management responsibility to the projects.
As Node.js will require the most complex compatibility layer, I will also contribute to the project the changes needed to use our API with minimal disruption on the current Security Release process (nodejs/security-wg#1570).
We did the kick off officially on #338. So here you can find:
Backlog
Phase 0: Prepare the repo
Goals
In order to make the API work we need to migrate the current CNA repo stack to Node.js from Jekyll. In this opportunity window we can do other changes. The idea is to create small PRs porting changes from https://github.com/UlisesGascon/openjs-cna-api-poc to https://github.com/openjs-foundation/security-advisories
Backlog
Discussions
Decisions made
Waiting for discussions
Phase 1: Build the API
Goals
We need to agree on the final architecture and deliver it
Backlog
Discussions
Decisions made
Waiting for discussions
Phase 2: Enable Node.js
Goals
Once the API is clear, the goal is to integrate the OpenJS CNA within the existing tools and process for the Node.js team
Backlog
Discussions
Decisions made
Waiting for discussions
Phase 3: Enable for other projects
Goals
The main goal is to onboard existing projects to the API and decide if we want to support an official client or not.
Backlog
Discussions
Decisions made
Waiting for discussions
The main goal is to enable projects such as Node.js to use our API the same way they use HackerOne (compatibility layer). Also any other foundation project can use the HTTP API to manage their own CVEs. There are quite interesting features included in the API from the CNA perspective like credentials segmentation or guardrails on the payloads. This will help us to make easier for us to delegate the CVE management responsibility to the projects.
As Node.js will require the most complex compatibility layer, I will also contribute to the project the changes needed to use our API with minimal disruption on the current Security Release process (nodejs/security-wg#1570).
We did the kick off officially on #338. So here you can find:
documentation: https://github.com/UlisesGascon/openjs-cna-tools
Backlog
Phase 0: Prepare the repo
Goals
In order to make the API work we need to migrate the current CNA repo stack to Node.js from Jekyll. In this opportunity window we can do other changes. The idea is to create small PRs porting changes from https://github.com/UlisesGascon/openjs-cna-api-poc to https://github.com/openjs-foundation/security-advisories
Backlog
/security-advisories.json(and the existing RSS) expose the full published-advisory list to programmatic consumers./security-advisories.htmlwith a clear visual differenceDiscussions
Decisions made
Waiting for discussions
Phase 1: Build the API
Goals
We need to agree on the final architecture and deliver it
Backlog
Discussions
Decisions made
Waiting for discussions
Phase 2: Enable Node.js
Goals
Once the API is clear, the goal is to integrate the OpenJS CNA within the existing tools and process for the Node.js team
Backlog
Discussions
Decisions made
Waiting for discussions
Phase 3: Enable for other projects
Goals
The main goal is to onboard existing projects to the API and decide if we want to support an official client or not.
Backlog
Discussions
Decisions made
Waiting for discussions