%PDF- <> %âãÏÓ endobj 2 0 obj <> endobj 3 0 obj <>/ExtGState<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/Annots[ 28 0 R 29 0 R] /MediaBox[ 0 0 595.5 842.25] /Contents 4 0 R/Group<>/Tabs/S>> endobj ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµùÕ5sLOšuY>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<> endobj 2 0 obj<>endobj 2 0 obj<>es 3 0 R>> endobj 2 0 obj<> ox[ 0.000000 0.000000 609.600000 935.600000]/Fi endobj 3 0 obj<> endobj 7 1 obj<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI]>>/Subtype/Form>> stream
# Security Steward Onboarding/OffBoarding ## Onboarding * Confirm the new steward agrees to keep all private information confidential to the project and not to use/disclose to their employer. * Add them to the security-stewards team in the GitHub nodejs-private organization. * Add them to the [public website team](https://github.com/orgs/nodejs/teams/website). * Ensure they have 2FA enabled in H1. * Add them to the standard team in H1 using this [page](https://hackerone.com/nodejs/team_members). * Add them as managers of the [nodejs-sec](https://groups.google.com/g/nodejs-sec/members) mailing list. ## Offboarding * Remove them from security-stewards team in the GitHub nodejs-private organization. * Remove them from public website team * Unless they have access for another reason, remove them from the standard team in H1 using this [page](https://hackerone.com/nodejs/team_members). * Downgrade their account to regular member in the [nodejs-sec](https://groups.google.com/g/nodejs-sec/members) mailing list.