Fix-merged-but-not-deployed gap
Frax Finance's assessment for RD-F-140 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No confirmed instance of a merged fix not deployed. The opposite direction is the concern (F139): deployed changes not in verified source. No public reports of a PR-merged-but-not-deployed-to-production gap found.
Sources #
- GitHubFraxFinance/frax-solidity | GitHubGitHub FraxFinance/frax-solidity and frax-governance — no public reports of undeployed merged fixretrieved 2026-05-17
Methodology #
Determine whether a known vulnerability has a PR merged in the repo but the fix has not been included in the deployed bytecode.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol frax factor RD-F-140 score green collected_at 2026-05-16 20:44:31