Skip to content

doc: document OpenJS CNA publication step in security release#63894

Draft
UlisesGascon wants to merge 1 commit into
nodejs:mainfrom
UlisesGascon:support-openjs-cna
Draft

doc: document OpenJS CNA publication step in security release#63894
UlisesGascon wants to merge 1 commit into
nodejs:mainfrom
UlisesGascon:support-openjs-cna

Conversation

@UlisesGascon

@UlisesGascon UlisesGascon commented Jun 13, 2026

Copy link
Copy Markdown
Member

Related to:

Important: This is the final step on large chain of PRs (cna api deployment, NCU support, testing it against MITRE, etc..) so the PR reminds as draft until is clear that we are adopting this 👍

When `cve_source` is set to `openjs-cna` in `.ncurc`, NCU reserves CVE
ids via the OpenJS Foundation CNA and publication to MITRE becomes a
separate post-release step (`git node security --publish-cve`).

Update the security release runbook accordingly:

  * Note the OpenJS CNA option under 'Requesting CVEs' with a forward
    reference to the Post-Release section.
  * Add a new Post-Release step for `--publish-cve`, scoped to the
    OpenJS CNA path. Includes a safety note: MITRE rejects cross-owner
    publication attempts loudly, but an accidental publication of one
    of the caller's own reserved CVEs goes through and becomes
    permanent.
  * Annotate the existing 'Request publication of H1 CVE requests'
    bullet in cleanup as a no-op under the OpenJS CNA path.

Signed-off-by: Ulises Gascon <ulisesgascongonzalez@gmail.com>
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/security-stewards
  • @nodejs/tsc

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

doc Issues and PRs related to the documentations.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants