Deployed bytecode matches signed release tag
Compound V3 (Comet)'s assessment for RD-F-136 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Compound uses deployAndUpgradeTo pattern — each governance proposal triggers CometFactory to deploy a new implementation. No GPG-signed GitHub release tags found corresponding to April 2026 upgrades. GitHub last commit: 2025-12-19; on-chain upgrades continued through April 2026. One-to-one repo tag to deployed bytecode not practically achievable with this architecture. Gray because absence of signed tags is architectural, not evidence of mismatch.
Sources #
- GitHubhttps://github.com/compound-finance/cometretrieved 2026-04-28
- https://etherscan.io/address/0xc3d688B66703497DAA19211EEdff47f25384cdc3retrieved 2026-04-28
Methodology #
Determine whether the deployed runtime bytecode corresponds to a signed git tag in the protocol's repository.
See the full factor methodology and distribution across all protocols →