Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Static version of pay.js for PCI compliance #316

Open
Kevin-McCormick-eStar opened this issue Nov 5, 2024 · 2 comments
Open

Static version of pay.js for PCI compliance #316

Kevin-McCormick-eStar opened this issue Nov 5, 2024 · 2 comments
Labels
enhancement New feature or request

Comments

@Kevin-McCormick-eStar
Copy link

Is your feature request related to a problem? Please describe.
PCI v4 mandates more stringent integrity checks on scripts being loaded into payment pages

Describe the solution you'd like
A static version of pay.js that can be either hosted locally, or on a cors enabled cdn allowing for SRI checks

Additional context
This was mentioned in this issue as a comment

@Kevin-McCormick-eStar Kevin-McCormick-eStar added the enhancement New feature or request label Nov 5, 2024
@dmengelt
Copy link
Member

Hi @Kevin-McCormick-eStar We are aware of the PCI v4 requirements. Will update this issue once we have more clarity...

@tristan-littlepay
Copy link

I want to escalate this. The new requirement - verifying the integrity of all scripts - is mandatory by the end of March. Can you @dmengelt give us an update on the process and potential solution? Other helpful measurements would be to publish a list of valid SRI hashes and versions or even a changelog of the pay.js library.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants