Disable unverified commercial and mint rails - #2
Merged
Merged
Conversation
…on USDC-on-Base payments
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
bshelby88
force-pushed
the
remove-stripe
branch
from
August 26, 2026 14:42
50812df to
86550df
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
This follow-up repairs the third independent blocker while keeping all commercial and mint rails fail-closed.
collection.jsonto usehttps://royalruby.iocanonical image/external URLs.animation_urlvalues (the referenced videos are not in the deployable repository), all Unlockable descriptions/traits, open-edition/holder-benefit copy, and royalty/treasury placeholders.dist.disttests for every one of the 11 metadata files.npm run build+dist, emits exact-commitdeployment-provenance.json, adds an expected-commit health gate, and adds GitHub quality gates for PRs and every push to canonical production branchmaster.Strict TDD evidence
distcases, Vercel build pinning, and provenance.https://royalruby.coin item 1 failed the exact per-file test, then the clean file was restored and the full suite rerun.Verification for exact head
67b49565d570564314334b433efa112d1e7afc3dnpm test— 67 passed across 4 filesnpm run build— production artifact emitted todist; 11 metadata JSON files parse successfullynpm audit --audit-level=high— 0 vulnerabilitiesEXPECTED_COMMIT=67b49565d570564314334b433efa112d1e7afc3d— 14/14 passed, including provenancedistmetadata truth scans — cleangit diff --checkand added-line static security scan — clean09c8501dd4550e5b4ae4acbfbe7676882c50aced; latest exact-head Vercel/CI checks are pendingProduction truth / remaining gap
Source-first inspection found no prior GitHub workflow. Vercel Git integration has historically deployed
masterto Production, so reviewed merge tomasterremains the canonical production path; this PR does not introduce a second deployer. Current production is still the oldmasterSHA372a85c11919972c2cac8b51dc0703ef6ef9506c, returns staleroyalruby.cometadata in the landing page, and returns 404 for/deployment-provenance.json. That gap cannot close until this PR is independently approved and merged, after which the Vercel integration must deploy the mergedmasterSHA and the provenance health check can verify it exactly.No merge, production deployment, payment, mint, publish, account change, or duplicate-project deletion was performed. The duplicate
royal-ruby-pr2Vercel project was not mutated manually.