#samccn-sri

1 messages ยท Page 1 of 1 (latest)

vestal moon
#

@warped void no, that's impossible and it wouldn't make sense in this case.

#

we control Stripe.js, it comes from our servers, we change it regularly, sometimes dozens of times per day, so SRI can't work

warped void
#

yeah i get that the library is updated daily - is there a way to pin the version?

vestal moon
#

no there isn't, we don't want anyone to use an old version, if you tried the calls woudl immediately all fail

#

you have to always use the latest version for both security and PCI reasons

warped void
#

is there any way to get informed about library updates?

vestal moon
#

there is not no. You have to understand that we control and deploy code constantly, you have no way to control the version. We're a pretty large financial company and we test Stripe.js thoroughly, there's no reason to need to pin to a specific version

warped void
#

they ding you a lot of points for not using SRI

#

guess theres nothing that can be done though

vestal moon
#

yeah unfortunately nothing can be done

warped void
#

ok thanks for your time

vestal moon
#

Sure, sorry I couldn't help more ๐Ÿ˜ฆ

warped void
#

no worries, not your fault ๐Ÿ™‚