THE LINUX FOUNDATION PROJECTS
Blog

Announcing the Node.js AI Security Engineer in Residence

Written by Kylie Wagar-Dirks, OpenJS Foundation

The OpenJS Foundation’s mission is to support the healthy growth of JavaScript and web technologies. Today, we’re proud to announce a new engagement that directly advances that mission: a funded AI Security Engineer in Residence in partnership with NodeSource for the Node.js ecosystem, made possible through a grant from Alpha-Omega.

Why This Matters Now

New AI-powered security tools are rapidly accelerating the discovery of vulnerabilities in open source software. Major projects across the JavaScript ecosystem have already received — and acted on — credible vulnerability reports surfaced by these new tools.

At the same time, many maintainers are reporting a sharp rise in low-quality, AI-generated vulnerability reports that waste time and bury legitimate issues. For a sprawling ecosystem like Node.js — spanning core libraries, hundreds of OpenJS-governed projects, and millions of npm packages — this is an urgent operational problem.

The OpenJS Foundation is addressing both sides of this challenge by funding a dedicated AI Security Engineer in Residence for the Node.js ecosystem.

Meet Ulises Gascón

We’re thrilled to announce that Ulises Gascón from NodeSource has been selected for this role.

Ulises is already doing most of this work. He serves as the primary CVE coordinator for the OpenJS Foundation CNA — covering Express, Lodash, Fastify, Webpack, Multer, Multiparty, Undici, and more. He’s an active Node.js Releaser, an Express and Lodash TSC member, and the de-facto first call for coordinated disclosures across the OpenJS ecosystem. He delivered the prior OpenJS Security Engineer engagement funded by Alpha-Omega in 2025, and he has already built and deployed AI-assisted patch review workflows in production.

This grant formalizes and scales work Ulises is already doing — with no ramp-up time required.

In Ulises’ own words:

👋

Some of you may know me from the Node.js release team, or from coordinating security disclosures across OpenJS projects over the past couple of years.

JavaScript security has been a constant thread through my career — from maintaining security workflows for Express and Lodash to building the CVE coordination infrastructure that the OpenJS CNA runs on today. Over the last year, I’ve been quietly building an AI-assisted triage and patch review system that now runs against real ecosystem advisories every week.

This grant lets me do that work properly: with the bandwidth to scale it, share it, and make it useful to maintainers across the ecosystem — not just the projects I personally maintain.

If you’re a maintainer who’s been overwhelmed by the recent surge in vulnerability reports, or if you’re working on supply-chain security for a high-criticality JS project, I want to hear from you.

You can find me on GitHub and LinkedIn.

What This Work Will Cover

Ulises will focus on three overlapping problems: high-volume AI-generated report intake, AI-assisted patch quality review, and supply-chain incident response.

  • AI-assisted patch review as a quality gate. Every non-trivial security patch will go through a blind multi-AI review alongside human review. This process is already running in production today.
  • Editorial criteria for recurring report classes. Ulises will document the patterns that show up repeatedly — prototype pollution via copied req.body, deep-recursion DoS on user input, trust-proxy assumption misuses — so that each recurring class gets a consistent, documented answer. This reduces maintainer burden and reporter friction over time.
  • Open source skill and prompt library. The AI-assisted triage operating system Ulises has built — 16+ skills covering acknowledgment, triage, patch review, CVE reservation, publication, release, and announcement — will be open sourced and contributed to the Alpha-Omega virtual team, where peer engineers in other ecosystems can adopt and adapt it.
  • Rapid response and supply-chain incident support. Ulises will continue as the de-facto first call for OpenJS coordinated disclosures, with formalized on-call expectations. He’ll also act as a trusted advisor for high-criticality JS maintainers facing supply-chain compromise — covering assessment, disclosure coordination, short-term mitigation, communication, and post-mortem. This scope is intentionally cross-ecosystem, because supply-chain events don’t respect org boundaries.
  • AI tooling enablement for existing security teams. OpenJS-ecosystem security teams (Express, Fastify, Lodash, Node.js core, and others) will receive onboarding support to adopt AI-assisted workflows where it makes sense — building on the mentorship work from Alpha-Omega 2025, refocused on AI uplift.
  • Cross-ecosystem contribution. Ulises will participate in the Alpha-Omega virtual team: sharing lessons learned, contributing prompts and playbooks, and surfacing Node.js-specific patterns that are useful to other ecosystems.

About Alpha-Omega

Alpha-Omega is an OpenSSF project that improves the security of open source software by working with maintainers to proactively find and fix vulnerabilities. This engagement is part of Alpha-Omega’s broader investment in ecosystem-level security capacity across the open source world.

We’re grateful to Alpha-Omega for making this work possible, and we look forward to sharing updates as the engagement progresses.

About the Author

Kylie is a Senior Marketing Manager at the Linux Foundation focused on open source technologies, developer communities, and content strategy. She helps projects and foundations grow awareness, engagement, and contributor participation through storytelling, events, and community programs.