Skip to content

doc: clarify security triage dispositions and permission boundaries - #65436

Open
RafaelGSS wants to merge 1 commit into
nodejs:mainfrom
RafaelGSS:security-triage-permission-boundaries
Open

doc: clarify security triage dispositions and permission boundaries#65436
RafaelGSS wants to merge 1 commit into
nodejs:mainfrom
RafaelGSS:security-triage-permission-boundaries

Conversation

@RafaelGSS

Copy link
Copy Markdown
Member

Clarify SECURITY.md by defining security triage dispositions, documenting same-process self-harm exclusions, and separating Permission Model reports into vulnerability, security-interest, and excluded cases. Also correct the worker_threads guidance: workers with modified execArgv or env may not inherit the parent permission configuration, while worker creation itself remains gated by --allow-worker.

Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/tsc

@nodejs-github-bot nodejs-github-bot added the doc Issues and PRs related to the documentations. label Aug 20, 2026
@RafaelGSS RafaelGSS added the author ready PRs that have at least one approval, no pending requests for changes, and a CI started. label Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs that have at least one approval, no pending requests for changes, and a CI started. doc Issues and PRs related to the documentations.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants