defirisk.co
rubric v1.7.0

Deployed bytecode reproducibility

Sanctum's assessment for RD-F-145 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Sanctum supports solana-verify reproducible builds. The unstake-program toolchain is pinned (solana 1.17.6 / ellipsislabs/solana Docker image). inf-1.5 has a tagged release. However, no explicit public solana-verify check output confirming the inf-1.5 V2 deployed bytecode matches the tagged release was found in public evidence.

Sources #

Methodology #

Determine whether anyone can independently reproduce the deployed bytecode from the repo and declared build toolchain.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sanctum factor RD-F-145 score yellow collected_at 2026-05-04 18:49:23