{"repo":"w3c/secure-payment-confirmation","summary":{"retrieved":"2026-05-16T07:46:11Z","triageViolations":7,"urgentViolations":0,"soonViolations":0,"agendaViolations":0,"needsEditsViolations":0,"needTriage":0,"urgent":0,"soon":0,"agenda":0,"needsEdits":0,"other":27},"triage":[{"number":273,"url":"https://github.com/w3c/secure-payment-confirmation/issues/273","title":"\"payment\" WebAuthn extension does not report successful registration","author":"stephenmcgruer","createdAt":"2024-08-23T18:42:28Z","labels":["WebAuthn liaison"],"sloTimeUsed":"P630DT13H3M43S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":288,"url":"https://github.com/w3c/secure-payment-confirmation/issues/288","title":"Specify storage type hint for browser bound keys","author":"pejic","createdAt":"2025-04-08T15:34:03Z","labels":[],"sloTimeUsed":"P402DT16H12M8S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":307,"url":"https://github.com/w3c/secure-payment-confirmation/issues/307","title":"Spec: Fetch images with the context of the PaymentRequest","author":"pejic","createdAt":"2025-07-15T19:13:49Z","labels":["Spec detail (for editor)"],"sloTimeUsed":"P304DT12H32M22S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":0,"numLabels":1},"outOfSlo":true},{"number":309,"url":"https://github.com/w3c/secure-payment-confirmation/issues/309","title":"Non-normative UX guidelines for implementors and integrators","author":"stephenmcgruer","createdAt":"2025-07-23T16:28:26Z","labels":["documentation"],"sloTimeUsed":"P296DT15H17M45S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":3,"numLabels":1},"outOfSlo":true},{"number":312,"url":"https://github.com/w3c/secure-payment-confirmation/issues/312","title":"Seeking input on prioritization of increased support for authenticators that can be used with SPC","author":"ianbjacobs","createdAt":"2025-08-14T15:13:22Z","labels":[],"sloTimeUsed":"P274DT16H32M49S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true},{"number":325,"url":"https://github.com/w3c/secure-payment-confirmation/pull/325","title":"Update from api.csswg.org/bikeshed to spec-generator","author":"kfranqueiro","createdAt":"2026-03-19T18:06:22Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"P57DT13H39M49S","whichSlo":"triage","stats":{"numTimelineItems":1,"numComments":1,"numLabels":0},"outOfSlo":true},{"number":328,"url":"https://github.com/w3c/secure-payment-confirmation/issues/328","title":"[Spec] SPC is overly restrictive on what constitutes \"third party\"","author":"stephenmcgruer","createdAt":"2026-05-08T13:27:18Z","labels":[],"sloTimeUsed":"P7DT18H18M53S","whichSlo":"triage","stats":{"numTimelineItems":0,"numComments":0,"numLabels":0},"outOfSlo":true}],"urgent":[],"soon":[],"agenda":[],"needsEdits":[],"other":[{"number":12,"url":"https://github.com/w3c/secure-payment-confirmation/issues/12","title":"Supporting roaming authenticators","author":"jcjones","createdAt":"2020-07-30T00:19:17Z","labels":["security-needs-resolution","after-v1","WebAuthn liaison"],"milestone":{"url":"https://github.com/w3c/secure-payment-confirmation/milestone/3","title":"GA"},"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":5,"numLabels":3}},{"number":34,"url":"https://github.com/w3c/secure-payment-confirmation/issues/34","title":"Suggestion to enable Frictionless Flows","author":"Goosth","createdAt":"2020-10-28T09:43:37Z","labels":["after-v1","Payments use case"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":4,"numComments":12,"numLabels":2}},{"number":124,"url":"https://github.com/w3c/secure-payment-confirmation/issues/124","title":"How do RPs determine when to enroll the user?","author":"ianbjacobs","createdAt":"2021-09-02T16:22:03Z","labels":["after-v1","WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":8,"numLabels":2}},{"number":157,"url":"https://github.com/w3c/secure-payment-confirmation/issues/157","title":"Consider separating the SPC powers of Third Party invocation and Payment display","author":"Goosth","createdAt":"2021-11-08T08:01:58Z","labels":["privacy-tracker"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":5,"numComments":13,"numLabels":1}},{"number":187,"url":"https://github.com/w3c/secure-payment-confirmation/issues/187","title":"Improving understanding of who is authenticating for whom","author":"ianbjacobs","createdAt":"2022-05-03T21:03:27Z","labels":["after-v1","WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":7,"numLabels":2}},{"number":253,"url":"https://github.com/w3c/secure-payment-confirmation/issues/253","title":"Add Support for Cross-Device Authentication","author":"tblachowicz","createdAt":"2023-07-03T11:46:14Z","labels":["after-v1","WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":2,"numLabels":2}},{"number":260,"url":"https://github.com/w3c/secure-payment-confirmation/issues/260","title":"How will new passkey providers impact SPC","author":"ve7jtb","createdAt":"2023-09-28T14:57:55Z","labels":["after-v1","WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":2,"numLabels":2}},{"number":266,"url":"https://github.com/w3c/secure-payment-confirmation/issues/266","title":"Document End-User Guide","author":"maltfield","createdAt":"2024-01-11T08:17:49Z","labels":["documentation"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":3,"numComments":7,"numLabels":1}},{"number":269,"url":"https://github.com/w3c/secure-payment-confirmation/issues/269","title":"Limitations for showing transaction data","author":"kseybold","createdAt":"2024-04-09T07:33:02Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":274,"url":"https://github.com/w3c/secure-payment-confirmation/issues/274","title":"Proposal: Remove `showOptOut` from SPC","author":"stephenmcgruer","createdAt":"2024-08-23T18:57:33Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":276,"url":"https://github.com/w3c/secure-payment-confirmation/issues/276","title":"Could cards be authenticators for SPC (or WebAuthn)?","author":"ianbjacobs","createdAt":"2024-10-03T16:27:59Z","labels":["after-v1","Payments use case"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":2,"numComments":4,"numLabels":2}},{"number":278,"url":"https://github.com/w3c/secure-payment-confirmation/issues/278","title":"Backup of the payment bit should be defined in SPC spec","author":"timcappalli","createdAt":"2024-11-25T15:26:12Z","labels":["WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":3,"numLabels":1}},{"number":287,"url":"https://github.com/w3c/secure-payment-confirmation/issues/287","title":"Ameliorate the need for re-authentication upon re-creating BBKs","author":"pejic","createdAt":"2025-04-01T15:42:22Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":12,"numLabels":0}},{"number":290,"url":"https://github.com/w3c/secure-payment-confirmation/issues/290","title":"Regarding support for BBK feature detection","author":"ianbjacobs","createdAt":"2025-04-28T13:15:52Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":299,"url":"https://github.com/w3c/secure-payment-confirmation/issues/299","title":"Should SPC be limited to passkeys with the payment bit set?","author":"ianbjacobs","createdAt":"2025-05-22T16:43:26Z","labels":["WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":4,"numLabels":1}},{"number":300,"url":"https://github.com/w3c/secure-payment-confirmation/issues/300","title":"URL handling for icons/logos should only allow `https`, `http`, and `data` URLs","author":"stephenmcgruer","createdAt":"2025-05-26T14:39:48Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":306,"url":"https://github.com/w3c/secure-payment-confirmation/issues/306","title":"Proposal: Leveraging FIDO User Verification Index (UVI) as a Cross-Browser PSD2 \"Possession Factor\" for Passkeys","author":"JeanDim","createdAt":"2025-07-07T07:15:25Z","labels":["WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":3,"numLabels":1}},{"number":310,"url":"https://github.com/w3c/secure-payment-confirmation/issues/310","title":"Support for multiple RPs in the Payment Request API for SPC","author":"fahads9","createdAt":"2025-07-30T16:48:12Z","labels":["WebAuthn liaison"],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":1,"numComments":5,"numLabels":1}},{"number":313,"url":"https://github.com/w3c/secure-payment-confirmation/issues/313","title":"Proposal: Extending Payment Confirmation experience to include line items","author":"vthub","createdAt":"2025-08-14T22:26:11Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":6,"numLabels":0}},{"number":315,"url":"https://github.com/w3c/secure-payment-confirmation/issues/315","title":"Double-authentication problem when BBK not available","author":"tblachowicz","createdAt":"2025-10-06T13:30:04Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":317,"url":"https://github.com/w3c/secure-payment-confirmation/issues/317","title":"Double authentication in Click To Pay checkout","author":"tblachowicz","createdAt":"2025-11-20T16:19:08Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":319,"url":"https://github.com/w3c/secure-payment-confirmation/issues/319","title":"Support for immediate mediation for friction-less payment with SPC (in 1PC)","author":"tblachowicz","createdAt":"2026-01-08T14:17:11Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":4,"numLabels":0}},{"number":321,"url":"https://github.com/w3c/secure-payment-confirmation/issues/321","title":"Gap between BBK requirements and specification","author":"John-Earnshaw","createdAt":"2026-03-03T09:58:37Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":5,"numLabels":0}},{"number":326,"url":"https://github.com/w3c/secure-payment-confirmation/issues/326","title":"[Security] SPC should disallow extensions that expose private relying party sign in data","author":"nsatragno","createdAt":"2026-03-30T14:41:50Z","labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":0,"numComments":1,"numLabels":0}},{"number":262,"url":"https://github.com/w3c/secure-payment-confirmation/pull/262","title":"Update Github changelog link","author":"rockymeza","createdAt":"2023-10-19T15:50:33Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":4,"numComments":4,"numLabels":0}},{"number":263,"url":"https://github.com/w3c/secure-payment-confirmation/pull/263","title":"Editorial: small cleanup of examples","author":"marcoscaceres","createdAt":"2023-11-22T23:07:10Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":8,"numComments":8,"numLabels":0}},{"number":327,"url":"https://github.com/w3c/secure-payment-confirmation/pull/327","title":"Create allowlist for webauthn extensions accessed via SPC","author":"stephenmcgruer","createdAt":"2026-05-05T13:26:32Z","pull_request":{"draft":false},"labels":[],"sloTimeUsed":"PT0S","whichSlo":"none","stats":{"numTimelineItems":22,"numComments":22,"numLabels":0}}]}