stripe-php icon indicating copy to clipboard operation
stripe-php copied to clipboard

Please consider removal of custom ca-cert included within codebase.

Open danmarsden opened this issue 5 years ago • 2 comments

It's generally considered bad practice to include your own version of the ca-cert bundle. Can you please look at removing this from your codebase? I can see how it might be "convenient" but it means that when performing a security review, we need to check to make sure your version of the ca-certs haven't been compromised.

danmarsden avatar Jul 14 '20 22:07 danmarsden

@danmarsden Thanks for the report! We'll look into this and see if it's something we could deprecate in the future!

remi-stripe avatar Jul 14 '20 23:07 remi-stripe