10000 Incident Response Plan by UlisesGascon · Pull Request #6028 · lodash/lodash · GitHub
[go: up one dir, main page]

Skip to content

Conversation

@UlisesGascon
Copy link
Member
@UlisesGascon UlisesGascon commented Oct 21, 2025

Main Changes

This PR includes an Incident Response Plan (IRP) that is heavily inspired by Express.

This is an early version intended to serve as a runbook to guide us during the security triage process.

This PR is very open to feedback and suggestions.

Assumptions

  • A security triage team is in place, so this PR might need to wait until that process is finalized. This is currently being discussed in Backlog: Adopt Security Best Practices #6027.
  • The private repository lodash/security-triage exists and can be used to handle discussions confidentially, since reporters in security advisories have access to all conversation threads — which is not always ideal.
  • The security triage team also uses the private channel #lodash-security-triage for internal communications.
  • As Lodash does not have official social media accounts or a blog, we can request the foundation’s assistance to promote important security communications when necessary. Otherwise, we can limit announcements to release notes or create an issue to notify the community of an upcoming impactful security release (without sharing sensitive details to prevent early disclosure).

Context

@UlisesGascon UlisesGascon changed the title docs: add an IRP Incident Response Plan Oct 21, 2025
@UlisesGascon UlisesGascon marked this pull request as ready for review October 21, 2025 22:54
@jdalton
Copy link
Member
jdalton commented Oct 27, 2025

Thank you @UlisesGascon!

@jdalton jdalton merged commit 23903d3 into lodash:main Oct 27, 2025
@UlisesGascon UlisesGascon added the STA-2025 Issues and tasks related to the work funded by STA for Q4 2025. label Nov 7, 2025
@UlisesGascon UlisesGascon self-assigned this Nov 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

STA-2025 Issues and tasks related to the work funded by STA for Q4 2025.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

0