As titled, here are some basic questions that we need to clarify: 1) are all @nodejs/tsc members automatic members of the security team? 2) how do we rotate out members of @nodejs/security that are no longer active? should they serve terms, similar to what the TSC might get? 3) how do we avoid discriminating against one security company with another? It seems they would all want to be part of this.