Skip to content

[client-side security] expand PCI DSS compliance page - #33199

Open
ngayerie wants to merge 3 commits into
productionfrom
dee-3623-client-side-pci-dss
Open

[client-side security] expand PCI DSS compliance page#33199
ngayerie wants to merge 3 commits into
productionfrom
dee-3623-client-side-pci-dss

Conversation

@ngayerie

@ngayerie ngayerie commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Expands the client-side security PCI DSS documentation to meet requirements 6.4.3 and 11.6.1 introduced in PCI DSS v4.0.

DEE-3623

Changes

  • /client-side-security/reference/pci-dss/: expanded from a one-paragraph stub to a full requirements mapping table for PCI DSS v4.0 req 6.4.3 (payment page script management) and 11.6.1 (tamper detection), with setup steps and cross-links to the SSL PCI DSS guide and Cloudflare Trust Hub

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 3, 2026

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://dee-3623-client-side-pci-dss.previews.developers.cloudflare.com (commit 3d11432)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://d818febf.previews.developers.cloudflare.com 3d11432 2026-09-05T10:02:44.804Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://8ac1f200.previews.developers.cloudflare.com 8a9fa14 2026-09-04T12:33:40.117Z Visit the dashboard ↗
  • Build: Failed ❌

View logs ↗
4a60052 2026-09-04T11:35:40.943Z View logs ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://ded2abb7.previews.developers.cloudflare.com 4890173 2026-09-03T06:59:52.323Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://a43b313d.previews.developers.cloudflare.com ae77ed7 2026-09-03T06:37:42.410Z Visit the dashboard ↗

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

This pull request requires reviews from CODEOWNERS as it changes files that match the following patterns:

Pattern Owners
/src/content/docs/client-side-security/ @cloudflare/appsec-reviewers, @xmflsct, @danielegm, @cloudflare/product-owners

@ngayerie
ngayerie marked this pull request as ready for review September 3, 2026 06:32
@ngayerie
ngayerie requested review from a team, danielegm and xmflsct as code owners September 3, 2026 06:32
@cloudflare-docs-bot

cloudflare-docs-bot Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Review

✅ No issues found in commit 3d11432.

Code Review

This code review is in beta and may not always be helpful — use your judgment.

No code review issues found.

Conventions

No convention issues found.

Style Guide Review

No style-guide issues found.

Commands

Only codeowners can run commands. Post a comment with the command to trigger it.

Command Description
/review Runs a review now. Incremental if a prior review exists, full if not.
/full-review Re-reviews the entire PR diff from scratch, ignoring incremental history. Useful after a rebase, when you want a fresh review, or if the bot gets out of sync and reports issues that no longer exist.
/ignore-review-limit Permanently lifts the 2-review automatic limit for this PR. Future pushes will trigger reviews as normal.
/disable-auto-review Stops automatic reviews from triggering on future pushes to this PR. Codeowners can still run /review or /full-review manually.
/rebase Rebases the PR branch against production. On conflict, attempts to resolve automatically using AI. Stops with an explanation if confidence is not high enough.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

@ngayerie
ngayerie force-pushed the dee-3623-client-side-pci-dss branch from 4890173 to 4a60052 Compare September 4, 2026 11:34
DEE-3623

- Replace overclaiming "HTTP security headers and payment page content"
  with "monitored client-side resources on payment pages"
- Replace "Alerts fire when scripts, connections, or cookies...change"
  with "Alerts can identify changes to monitored client-side resources"
- Removes undocumented header/cookie-change alerting claim
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants