Deployed bytecode matches signed release tag
Venus Protocol's assessment for RD-F-136 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Bytecode-to-signed-release-tag matching not performed within budget. Changelog present (data cache: changelog_present=true). 48+ audits exist. Full bytecode match deferred to code-security-analyst (RD-F-001 scope).
Sources #
- GitHubVenus Protocol GitHub — changelog present; last commit 2026-04-27Data cache changelog_present=trueretrieved 2026-04-28
Methodology #
Determine whether the deployed runtime bytecode corresponds to a signed git tag in the protocol's repository.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol venus factor RD-F-136 score gray collected_at 2026-04-28 18:30:49