Skip to content

2026-04-27 Express TC Meeting #491

Description

@github-actions

Date/Time

TimezoneDate/Time
America/Los_AngelesMon, Apr 27, 2026, 11:00 AM
America/DenverMon, Apr 27, 2026, 12:00 PM
America/ChicagoMon, Apr 27, 2026, 01:00 PM
America/BogotaMon, Apr 27, 2026, 01:00 PM
America/New_YorkMon, Apr 27, 2026, 02:00 PM
UTCMon, Apr 27, 2026, 06:00 PM
Europe/LondonMon, Apr 27, 2026, 07:00 PM
Europe/MadridMon, Apr 27, 2026, 08:00 PM
Europe/ParisMon, Apr 27, 2026, 08:00 PM
Europe/WarsawMon, Apr 27, 2026, 08:00 PM
Europe/MoscowMon, Apr 27, 2026, 09:00 PM
Asia/KolkataMon, Apr 27, 2026, 11:30 PM
Asia/ShanghaiTue, Apr 28, 2026, 02:00 AM
Asia/TokyoTue, Apr 28, 2026, 03:00 AM
Australia/SydneyTue, Apr 28, 2026, 04:00 AM

Or in your local time:

Agenda

  • Enable Organization Billing for GitHub Codespaces in express/pillarjs/jshttp Repositories #488
    • Left a comment on this, lets explore what gratis offerings GH can give us before we decide to pay for something that is only used by 1 or few people in the org
  • docs: add YesWeHack policy security-wg#90
    • Parking this for now. The future of paid bounty programs is in the air, lets look for an OpenJS level conversation about this. Removed agenda label comment
  • Free form discussion about the state and workload of vuln reporting, ways to help stem the tide etc etc.
    • Resourcing problem, time is ultimately the issue here. Unclear what can fix or reduce the invalid reports coming in, @UlisesGascon idea being used in Lodash is updating the threat model w/ more context about some rejected classes of issues, to hopefully better inform folks and their agents before they even open a report that we will ulltimately close.

Proposed Topics

Extracted from tc agenda labelled issues and pull requests from expressjs/discussions prior to the meeting.

Invited

  • @expressjs/express-tc
  • @expressjs/triagers
  • @expressjs/security-wg

Observers/Guests

This meeting is open for anyone who wants to attend. Reminder to follow our Code of Conduct.

Joining the meeting


Please use the following emoji reactions in this post to indicate your
availability.

  • 👍 - Attending
  • 👎 - Not attending
  • 😕 - Not sure yet

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions