{"id":20078036,"url":"https://github.com/cn-src/wechat-pay","last_synced_at":"2025-08-19T13:19:09.221Z","repository":{"id":57715959,"uuid":"123258731","full_name":"cn-src/wechat-pay","owner":"cn-src","description":"微信支付-简单易用","archived":false,"fork":false,"pushed_at":"2019-07-02T04:12:56.000Z","size":10524,"stargazers_count":7,"open_issues_count":0,"forks_count":6,"subscribers_count":4,"default_branch":"master","last_synced_at":"2025-05-22T22:05:39.741Z","etag":null,"topics":["spring-boot","wechat","wechatpay"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cn-src.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2018-02-28T09:04:36.000Z","updated_at":"2022-04-30T14:06:49.000Z","dependencies_parsed_at":"2022-09-12T10:41:55.195Z","dependency_job_id":null,"html_url":"https://github.com/cn-src/wechat-pay","commit_stats":null,"previous_names":[],"tags_count":4,"template":false,"template_full_name":null,"purl":"pkg:github/cn-src/wechat-pay","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cn-src%2Fwechat-pay","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cn-src%2Fwechat-pay/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cn-src%2Fwechat-pay/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cn-src%2Fwechat-pay/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cn-src","download_url":"https://codeload.github.com/cn-src/wechat-pay/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cn-src%2Fwechat-pay/sbom","scorecard":{"id":294521,"data":{"date":"2025-08-11","repo":{"name":"github.com/cn-src/wechat-pay","commit":"d6e904d7c286b897b21ab0773ab8eada1be77fb1"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.6,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: samples/wiremock/wiremock-standalone-2.14.0.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Vulnerabilities","score":0,"reason":"10 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-7r82-7xv7-xcpj","Warn: Project is vulnerable to: GHSA-6xx3-rg99-gc3p","Warn: Project is vulnerable to: GHSA-8xfc-gm6g-vgpv","Warn: Project is vulnerable to: GHSA-hr8g-6v94-x4m9","Warn: Project is vulnerable to: GHSA-v435-xc8x-wvr9","Warn: Project is vulnerable to: GHSA-wjxj-5m7g-mg7q","Warn: Project is vulnerable to: GHSA-7v6m-28jr-rg84","Warn: Project is vulnerable to: GHSA-m8p2-495h-ccmh","Warn: Project is vulnerable to: GHSA-rmrm-75hp-phr2","Warn: Project is vulnerable to: GHSA-x83m-pf6f-pf9g"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T19:08:23.208Z","repository_id":57715959,"created_at":"2025-08-17T19:08:23.208Z","updated_at":"2025-08-17T19:08:23.208Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":271159363,"owners_count":24709251,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-19T02:00:09.176Z","response_time":63,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["spring-boot","wechat","wechatpay"],"created_at":"2024-11-13T15:12:31.757Z","updated_at":"2025-08-19T13:19:09.199Z","avatar_url":"https://github.com/cn-src.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![Maven Central](https://img.shields.io/maven-central/v/cn.javaer.wechat/wechat-pay.svg)](https://search.maven.org/search?q=g:cn.javaer.wechat)\n[![Build Status](https://travis-ci.org/cn-src/wechat-pay.svg?branch=master)](https://travis-ci.org/cn-src/wechat-pay)\n\n# wechat-pay\n微信支付-简单易用\n\n# 使用说明\n1. 参数名已尽可能保持与官方文档一致，因此可直接参照官方文档说明使用\n2. 提供了最小化参数集的接口，无需关心过多的参数\n3. 兼容微信支付API变动带来的未知响应字段以及枚举值\n5. 使用 spring 事件机制封装了微信支付通知，以简化使用方式\n6. wiremock 是一个 web mock server, 感兴趣的可以去官网了解 http://wiremock.org/, 配置中可配置微信 API 的 basePath, 所以你可以使用 wiremock 构建一个完全的仿真环境\n\n# 使用前提\n1. 申请微信公众号以及微信商户号\n2. 获取到 公众号 ID(appid), 商户号(mchId)\n3. 登录商户号设置：【账户中心】-【API安全】, 设置 API 秘钥(mchKey)，下载 API 证书(退款需要)\n4. 登录商户号设置：【产品中心】-【开发配置】, 配置支付目录\n5. 登录商户号设置：【交易中心】-【退款配置】, 配置通知 url(推荐样例: http://your_host/public/wechat/pay/refund_notify)\n6. 如果你处于开发测试阶段，可能需要一个内网穿透工具以及ICP备案域名，推荐使用: https://natapp.cn/\n7. samples 目录下有相关使用样例，类似 `System.getenv(\"wechat.pay.appId\")` 的参数获取是为了从 jvm 系统变量中获取私密配置信息，你可以根据相关的开发工具等从外部配置好即可无需修改样例代码运行样例了，对于使用 IDEA 开发工具的推荐插件 https://github.com/Ashald/EnvFile 从外部配置私密信息\n\n# maven 坐标\n```xml\n\u003cdependency\u003e\n    \u003cgroupId\u003ecn.javaer.wechat\u003c/groupId\u003e\n    \u003cartifactId\u003ewechat-pay\u003c/artifactId\u003e\n    \u003cversion\u003eLATEST\u003c/version\u003e\n\u003c/dependency\u003e\n\n\u003cdependency\u003e\n    \u003cgroupId\u003ecn.javaer.wechat\u003c/groupId\u003e\n    \u003cartifactId\u003ewechat-spring-boot-starter-pay\u003c/artifactId\u003e\n    \u003cversion\u003eLATEST\u003c/version\u003e\n\u003c/dependency\u003e\n```\n\n# 常规使用\n\n1. 启动接收结果通知的 web 服务, 测试下可运行 run-wiremock.sh 启动模拟服务器，用于接收结果通知以及响应.\n2. 使用样例\n\n```java\nWeChatPayConfigurator configurator = new WeChatPayConfigurator();\nconfigurator.setAppId(\"\");\nconfigurator.setMchId(\"\");\nconfigurator.setMchKey(\"\");\nconfigurator.setPaymentNotifyUrl(\"http://your_host/public/wechat/pay/payment_notify\");\nconfigurator.setCertificatePath(\"\");\n\nWeChatPayService weChatPayService = new WeChatPayService(configurator);\n// weChatPayService 调用相关方法\n```\n\n# spring \u0026 spring boot 集成\n\n* 【spring集成】配置 `WeChatPayController`, `WeChatPayServiceFactoryBean`, 可参照 wechat-spring-boot-starter-pay 中的自动配置.\n* 【spring boot 集成】配置\n```\nwechat.pay.appId=\nwechat.pay.mchId=\nwechat.pay.mchKey=\nwechat.pay.paymentNotifyUrl=http://your_host/public/wechat/pay/payment_notify\nwechat.pay.certificatePath=\n```\n* 使用样例\n\n```java\n// 调用接口\n@Autowired\nprivate WeChatPayService weChatPayService\n```\n\n```java\n// 接收结果通知\n@Component\npublic class SamplePayEvent {\n\n    /**\n     * 付款结果通知.\n     *\n     * @param event PaymentNotifyEvent\n     */\n    @EventListener\n    public void paymentNotifyEvent(final PaymentNotifyEvent event) {\n        System.out.println(event);\n    }\n\n    /**\n     * 退款结果通知.\n     *\n     * @param event RefundNotifyEvent\n     */\n    @EventListener\n    public void refundNotifyEvent(final RefundNotifyEvent event) {\n        System.out.println(event);\n    }\n}\n\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcn-src%2Fwechat-pay","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcn-src%2Fwechat-pay","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcn-src%2Fwechat-pay/lists"}