Observe
Passively record scripts and selected security-impacting headers from one authorised staging or demo checkout.
GitHub-native · release-scoped · client-owned
Record browser-observed checkout scripts and selected security-impacting headers, compare them with an approved baseline, and preserve the result inside the caller’s own GitHub workflow.
Release evidence—not PCI certification, penetration testing, production monitoring, alerting, or blocking.
v0.3.1Evidence remains in the agency or client repository.
The release record a source diff cannot provide
Source and QA records remain useful, but they do not necessarily preserve the exact browser-served script and selected-header state delivered during a release. This adds that narrow evidence layer without pretending to be continuous security monitoring.
Passively record scripts and selected security-impacting headers from one authorised staging or demo checkout.
Compare the browser observation with a previously reviewed baseline and approval records.
Return PASS or REVIEW_REQUIRED without labelling every difference malicious or insecure.
Keep the passport, comparison, snapshot and readable report inside the caller’s GitHub workflow.
Tight data boundary
Passive GET navigation only. No form submission. Script contents are fingerprinted; complete script bodies are not retained.
Founding agency offer
The Action remains free to self-install. Paid work covers scoped configuration, controlled acceptance, evidence verification, and handover.
One agency-owned staging or demo workflow, delivered in three business days.
Move the accepted evidence workflow into the agreed client implementation.
Best fit
Especially Magento / Adobe Commerce, custom BigCommerce checkout, Salesforce Commerce Cloud, WooCommerce customisation, and custom React or Next.js checkout flows.
Not a fit
Not for third-party checkout scanning, PCI certification, penetration testing, vulnerability assessment, or replacement of continuous monitoring.
Clear boundaries
No. It provides release-scoped evidence that may support change-management and evidence processes. It does not by itself satisfy PCI DSS Requirements 6.4.3 or 11.6.1, and it is not a QSA assessment.
No. It complements—but does not replace—CSP, script governance, runtime monitoring, alerting, or blocking controls.
A Git diff describes source changes. The passport records what a controlled browser observed, the baseline comparison, approval status, and GitHub workflow provenance.
No checkout submission is required. Evidence excludes cardholder data, credentials, cookies, form values, query values, response bodies, and complete script bodies.
Request the one-page agency scope
Send only non-sensitive architecture and staging details. Never email credentials, private URLs, customer data, or card data.