#samccn-sri
1 messages ยท Page 1 of 1 (latest)
@warped void no, that's impossible and it wouldn't make sense in this case.
we control Stripe.js, it comes from our servers, we change it regularly, sometimes dozens of times per day, so SRI can't work
yeah i get that the library is updated daily - is there a way to pin the version?
no there isn't, we don't want anyone to use an old version, if you tried the calls woudl immediately all fail
you have to always use the latest version for both security and PCI reasons
is there any way to get informed about library updates?
there is not no. You have to understand that we control and deploy code constantly, you have no way to control the version. We're a pretty large financial company and we test Stripe.js thoroughly, there's no reason to need to pin to a specific version
yeah i get it... just that a particular client is hellbent on us having a high mozilla observatory security score https://observatory.mozilla.org/
they ding you a lot of points for not using SRI
guess theres nothing that can be done though
yeah unfortunately nothing can be done
ok thanks for your time
Sure, sorry I couldn't help more ๐ฆ
no worries, not your fault ๐