diff --git a/src/content/blog/2026-09-09-joining-the-openjs-cna-security-break.md b/src/content/blog/2026-09-09-joining-the-openjs-cna-security-break.md new file mode 100644 index 0000000000..e48dc83891 --- /dev/null +++ b/src/content/blog/2026-09-09-joining-the-openjs-cna-security-break.md @@ -0,0 +1,26 @@ +--- +title: 'Express is joining the OpenJS CNA coordinated break' +description: The Express security team is pausing from September 17 to October 6, 2026, alongside the OpenJS Foundation CNA. +tags: ['security'] +authors: + - name: Express Security Team + github: expressjs +--- + +The [OpenJS Foundation CNA](https://cna.openjsf.org/) is taking a [coordinated break from September 17 to October 6, 2026](https://openjsf.org/blog), and setting a good example for the community while doing it. The Express security team is joining the pause for the same window. Their post explains the reasoning, and it matches what we see in the Express ecosystem firsthand. + +## What this means for Express + +From September 17 to October 6, 2026: + +- Triage, patch development, advisory validation, CVE assignment, and security releases are paused. +- Channels stay open, so you can still file reports, but please do not expect a response until we return on **October 7**. +- Where possible, please hold non urgent reports until after the break, and keep following coordinated disclosure. + +**Emergency exception:** if a vulnerability is being actively exploited, or poses immediate and serious risk, we will still respond. Reach out in the **#express** channel on the [OpenJS Foundation Slack](https://slack-invite.openjsf.org/), keep the first message high level, and mark it urgent. + +We will be back on **October 7, 2026**. Thank you for following coordinated disclosure. + +To the maintainers who build on Express, and to the wider community: we hope you find your own moments to rest and recharge too. + +The Express Security Team