Skip to content

Commit

Permalink
✨ 2024-03-13
Browse files Browse the repository at this point in the history
  • Loading branch information
ctcpip committed Mar 14, 2024
1 parent 87e2f80 commit 0898fbb
Show file tree
Hide file tree
Showing 5 changed files with 138 additions and 49 deletions.
26 changes: 5 additions & 21 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,50 +6,34 @@ See [Scope](#scope) for our mandate.

## Agenda

see [2024-03-13](meetings/2024/2024-03-13.md) and [the backlog](meetings/backlog.md) 👀
see [2024-03-13](meetings/2024/2024-03-20.md) and [the backlog](meetings/backlog.md) 👀

## Meetings

Meetings are bi-weekly, alternating between an APAC-friendly time and an EMEA-friendly time. The meetings appear on the [TC39 private calendar](https://github.com/tc39/Reflector#tc39-private-calendar).
Meetings occur every Wednesday and appear on the [TC39 private calendar](https://github.com/tc39/Reflector#tc39-private-calendar).

Meeting link: <https://meet.google.com/rwh-opnw-cnk>
Meeting link: [join zoom meeting](https://us02web.zoom.us/j/81143085896?pwd=TUE3WGgrdEZmNFZJc0g4QzBHUWczdz09)

<!-- DST below -->

### 2nd Wednesday / Thursday each month (EMEA-friendly)
### Every Wednesday

| | |
| -----------: | --------------- |
| US / Central | 12:00 Wednesday |
| UTC | 17:00 Wednesday |
| China | 01:00 Thursday |

### 4th Tuesday / Wednesday each month (APAC-friendly)

| | |
| -----------: | --------------- |
| US / Central | 20:00 Tuesday |
| UTC | 01:00 Wednesday |
| China | 09:00 Wednesday |

<!-- not DST below -->

<!--
### 2nd Wednesday / Thursday each month (EMEA-friendly)
### Every Wednesday
| | |
| -----------: | --------------- |
| US / Central | 12:00 Wednesday |
| UTC | 18:00 Wednesday |
| China | 02:00 Thursday |
### 4th Tuesday / Wednesday each month (APAC-friendly)
| | |
| -----------: | --------------- |
| US / Central | 20:00 Tuesday |
| UTC | 02:00 Wednesday |
| China | 10:00 Wednesday |
-->

## Folks
Expand Down
65 changes: 48 additions & 17 deletions meetings/2024/2024-03-13.md
Original file line number Diff line number Diff line change
@@ -1,30 +1,61 @@
# 17th Meeting of TC39-TG3 - 2024-03-13

| | |
| -----------: | --------------- |
| US / Central | 12:00 Wednesday |
| UTC | 17:00 Wednesday |
| China | 01:00 Thursday |

Meeting link: [join zoom meeting](https://us02web.zoom.us/j/81143085896?pwd=TUE3WGgrdEZmNFZJc0g4QzBHUWczdz09)

## Folks

| Name | GH Username | TLA | Affiliation |
| --------- | --------------- | --- | ------------ |
| Full Name | @githubUsername | FNE | organization |
| | | | |
> [!NOTE]
> Add a ✅ to the `Present` column in the table below, and add anyone missing. Also add to [the template](../template.md) and [GitHub team](https://github.com/orgs/tc39/teams/tg3) if the individual is a regular attendee.
| Present | Name | GH Username | TLA | Affiliation |
| ------- | ---------------- | ----------- | --- | ----------- |
|| Caridy Patiño | @caridy | CP | Salesforce |
|| Chip Morningstar | @FUDCo | CM | Agoric |
|| Chris de Almeida | @ctcpip | CDA | IBM |
|| Daniel Veditz | @dveditz | DPV | Mozilla |
|| Kris Kowal | @kriskowal | KKL | Agoric |
|| Mark Miller | @erights | MM | Agoric |
|| Peter Hoddie | @phoddie | PHE | Moddable |
|| Richard Gibson | @gibson042 | RGN | Agoric |

## Agenda

> [!NOTE]
> See [backlog.md](../backlog.md) for outstanding action items and agenda topics.
| Topic | Presenter(s) |
| ------------------------------------------------------------------------------- | ---------------- |
| APAC meeting rescheduling | Chris de Almeida |
| TG3 meeting on public calendar? | Chris de Almeida |
| TG3 participants in readme? (GH team is not public) | Chris de Almeida |
| ? structs update ? | |
| review issues in security repo | Chris de Almeida |
| does TC39 need a formal security review for proposals? [related issue][related] | |
| | |
| Topic | Presenter(s) |
| ------------------------- | ---------------- |
| APAC meeting rescheduling | Chris de Almeida |

### meeting rescheduling

- do we need the 2nd meeting?

- suggestion to just have the weekly SES slot for TG3/SES purposes
- agenda convergence? how to manage?
- KKL happy to use SES time, provided some topics can be recorded
- Agoric offers zoom for meeting (recording)
- currently posts to SES YT and goes through Agoric marketing
- shouldn't be the case for TG3, but some venue is desired for publication (YT)
- need to determine a neutral venue
- TG3: consensus to eliminate the APAC-friendly meeting
- clarification: TG3 meetings are open to all interested parties
- proposal: TG3 meetings Wednesdays at 10AM PT
- KKL would join convenors group
- consensus?
- +1 MM, KKL, PHE, CDA, DPV, CM

### review issues in security repo
- can we record TG3 meetings?

- index accessors: 5% usage in 2017 is now over 30% in 2024, likely due to use in popular lib(s)
- <https://chromestatus.com/metrics/feature/timeline/popularity/2238>
- no prohibition on this from Ecma perspective
- ultimately, up to participants
- recordings can be stopped as needed
- there can also be requests for redaction, or delay publication

[related]: https://github.com/tc39/security/issues/4
- PHE: contributors to TC/TG need to sign RFTG agreement, etc.
33 changes: 33 additions & 0 deletions meetings/2024/2024-03-20.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# 18th Meeting of TC39-TG3 - 2024-03-20

## Folks

> [!NOTE]
> Add a ✅ to the `Present` column in the table below, and add anyone missing. Also add to [the template](../template.md) and [GitHub team](https://github.com/orgs/tc39/teams/tg3) if the individual is a regular attendee.
| Present | Name | GH Username | TLA | Affiliation |
| ------- | ---------------- | --------------- | --- | ----------- |
| | Chip Morningstar | @FUDCo | CM | Agoric |
| | Chris de Almeida | @ctcpip | CDA | IBM |
| | Daniel Veditz | @dveditz | DPV | Mozilla |
| | Jack Works | @Jack-Works | JWK | Sujitech |
| | Jordan Harband | @ljharb | JHD | HeroDevs |
| | Kris Kowal | @kriskowal | KKL | Agoric |
| | Mark Miller | @erights | MM | Agoric |
| | Mathieu Hofman | @mhofman | MHN | Agoric |
| | Michael Ficarra | @michaelficarra | MF | F5 |
| | Peter Hoddie | @phoddie | PHE | Moddable |
| | Richard Gibson | @gibson042 | RGN | Agoric |
| | | | | |

## Agenda

> [!NOTE]
> See [backlog.md](../backlog.md) for outstanding action items and agenda topics.
| Topic | Presenter(s) |
| ------------------------------------------ | ------------ |
| review of previous agenda and action items | |
| | |

### review of previous agenda and action items
20 changes: 13 additions & 7 deletions meetings/backlog.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,19 @@

## Agenda Items

- need a (neutral) place to make meeting recordings available
- TG3 meeting on public calendar?
- TG3 participants in readme? (GH team is not public)
- proposals
- review security impact of (Shared) Structs proposal - <https://github.com/tc39/proposal-structs>
- and [WasmGC shared memory proposal](https://github.com/WebAssembly/shared-everything-threads/blob/main/proposals/shared-everything-threads/Overview.md)
- review issues in security repo
- index accessors: 5% usage in 2017 is now over 30% in 2024, likely due to use in popular lib(s)
- <https://chromestatus.com/metrics/feature/timeline/popularity/2238>
- does TC39 need a formal security review for proposals?
- related issues on this:
- <https://github.com/tc39/security/issues/4>
- <http://github.com/tc39/process-document/pull/18>
- Strategies used and features/invariants relied upon to write secure programs today (Michael Ficarra)
- Adopting something like the W3C Self-Review Questionnaire: Security and Privacy
- IETF has a similar doc: <https://datatracker.ietf.org/doc/html/rfc3552>
Expand All @@ -26,13 +39,6 @@
- <https://github.com/LavaMoat/LavaMoat>
- JHD: what i like about LavaMoat's approach is that it reduces the set of "potential package vectors" from "all deps" down to "only deps that already legitimately have dangerous permissions", which drastically reduces the manual auditing/review work required.
- Explore language capabilities that are undeniable, not virtualizable. (MF)
- proposals
- review security impact of (Shared) Structs proposal - <https://github.com/tc39/proposal-structs>
- and [WasmGC shared memory proposal](https://github.com/WebAssembly/shared-everything-threads/blob/main/proposals/shared-everything-threads/Overview.md)
- does TC39 need a formal security review for proposals?
- related issues on this:
- <https://github.com/tc39/security/issues/4>
- <http://github.com/tc39/process-document/pull/18>
- MM: Existing code can run in hardened mode
- biggest problem with running existing code in hardened mode wrt builtins is overriding
- find a means to suppress override mistake (if possible)
Expand Down
43 changes: 39 additions & 4 deletions meetings/template.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,46 @@
# nth Meeting of TC39-TG3 - YYYY-MM-DD

<!-- DST below -->

<!--
| | |
| -----------: | --------------- |
| US / Central | 12:00 Wednesday |
| UTC | 17:00 Wednesday |
| China | 01:00 Thursday |
-->

<!-- not DST below -->

<!--
| | |
| -----------: | --------------- |
| US / Central | 12:00 Wednesday |
| UTC | 18:00 Wednesday |
| China | 02:00 Thursday |
-->

Meeting link: [join zoom meeting](https://us02web.zoom.us/j/81143085896?pwd=TUE3WGgrdEZmNFZJc0g4QzBHUWczdz09)

## Folks

| Name | GH Username | TLA | Affiliation |
| --------- | --------------- | --- | ------------ |
| Full Name | @githubUsername | FNE | organization |
| | | | |
> [!NOTE]
> Add a ✅ to the `Present` column in the table below, and add anyone missing. Also add to [the template](../template.md) and [GitHub team](https://github.com/orgs/tc39/teams/tg3) if the individual is a regular attendee.
| Present | Name | GH Username | TLA | Affiliation |
| ------- | ---------------- | --------------- | --- | ----------- |
| | Chip Morningstar | @FUDCo | CM | Agoric |
| | Chris de Almeida | @ctcpip | CDA | IBM |
| | Daniel Veditz | @dveditz | DPV | Mozilla |
| | Jack Works | @Jack-Works | JWK | Sujitech |
| | Jordan Harband | @ljharb | JHD | HeroDevs |
| | Kris Kowal | @kriskowal | KKL | Agoric |
| | Mark Miller | @erights | MM | Agoric |
| | Mathieu Hofman | @mhofman | MHN | Agoric |
| | Michael Ficarra | @michaelficarra | MF | F5 |
| | Peter Hoddie | @phoddie | PHE | Moddable |
| | Richard Gibson | @gibson042 | RGN | Agoric |
| | | | | |

## Agenda

Expand Down

0 comments on commit 0898fbb

Please sign in to comment.