Ooh, this reminds me that I saw a file being included straight from github.com on flyporter.com (Canadian regional airline)<p>Actually, extremely weirdly, they didn't include the "actual" file (the raw version of it) but ... they included the github page in the <script> tag...??<p>Go through a checkout on flyporter.com (use dates > Aug 31st as they're resuming service then) and you'll see<p>`<script src="<a href="https://github.com/furf/jquery-ui-touch-punch/blob/master/jquery.ui.touch-punch.js"></script>`" rel="nofollow">https://github.com/furf/jquery-ui-touch-punch/blob/master/jq...</a><p>in the source code which makes no sense (try that URL in your browser!)<p>I contacted everyone I could find on LinkedIn who's working as CTO/CIO/etc. there, AND emailed them but never heard back. (this was 9 months ago... the issue is still there)<p>Isn't this how the British Airways checkout ended up being hacked?