Releases: catch-exchange/catch-contracts
Release list
Catch Family V1 — ten-family source record
Public source record for all ten already-launched Catch Family V1 markets on Robinhood Chain (4663).
Added
- cNVDA, cEWY, cSGOV, cSLV, cETH, cPONS, cSPCX and cTSLA deployment identities alongside cGOLD and cSPY: all seven family components, launch provenance, pool IDs and recorded runtime hashes.
- Per-address source-publication evidence checked on 7 September 2026: 71 exact Sourcify creation/runtime matches (shared factory plus 70 family contracts).
- Separate evidence for the seven shared code depots: Blockscout partial source matches and independently checked exact payloads. Their Sourcify jobs returned bytecode_length_mismatch because depot runtime is stored component creation code, not the nominal Solidity runtime. They are not counted among the 71 exact Sourcify matches.
- Strict evidence schemas, provider/identity regression checks and clarified documentation.
Unchanged
All 36 Solidity source files, eight compiler inputs, ABIs and the build manifest are unchanged from source-v1.0.1. No deployed contract, economic rule, market admission, key, launch transaction or prior source tag was changed by this release. No private operator material is included.
Checks
- 88-file publication allowlist; 11 publication-tooling tests passed.
- All eight targets reproduced with exact Solidity 0.8.26 inputs.
- Full public-history and working-directory Gitleaks scans passed.
- Independent read-only publication review and all three required PR/main CI checks passed.
Source correspondence is not an independent security audit, guaranteed liquidity or external router approval. Blockscout badges were not individually rechecked for all 71 exact Sourcify records. See docs/VERIFICATION.md and verification/source-status.json for scope and per-address links.
Catch Family V1 — review and testing record
Documentation-only source publication for the existing Robinhood cGOLD and cSPY families. Adds cross-session AI-assisted Pashov/EthSkills review history with candidate boundaries, remediation/design dispositions, fresh bounded regression evidence (40 Solidity tests including six stateful invariants, plus 10 simulator tests), and one approved Catch illustration. No commissioned audit or framework-author endorsement is claimed. Exact production sources, ABIs, compiler inputs and deployment identities are unchanged from source-v1.0.0. All required publication, reproducible compilation and full-history secret-scan CI checks passed. No deployment or transaction occurred.
Maintainer-authorized privacy correction — 7 September 2026
The commit metadata for this release was corrected to use the maintainer's GitHub noreply email. This is a narrowly scoped exception to the normal no-retagging policy: the replacement commit is af223e9e13e276d1aed842a498771f79128c7449 and its Git file-tree ID is eca52907474c8c52afda16fc1b83843015a8e6dc. Every tracked file is byte-for-byte identical to the original publication; no source, ABI, compiler input, deployment identity or test evidence changed. All three required CI checks passed on the replacement commit before the refs were updated. The old GitHub commit signature was not carried over; the replacement commit is unsigned. Branch protections were restored immediately after the leased ref update.
The original commit may remain accessible through GitHub's retained objects or pull-request records and existing clones. This correction does not claim those copies have been erased.
Catch Family V1 — public source 1.0.0
First source-only publication of the deployed Catch Family V1 contract closure for Robinhood Chain (4663), covering the shared factory and the cGOLD/cSPY family components. Includes architecture and custody documentation, public deployment identities, 36 exact Solidity sources, eight ABIs, exact compiler inputs, licences, and reproducible-build tooling.
Verification: all eight creation-code/runtime-template outputs, ABIs and immutable layouts reproduced locally and in GitHub CI. Publication integrity and six tooling tests passed. Files and complete public history were secret-scanned; the only scanner exception is a documented exact PoolKey.sol source checksum, independently verified by the integrity check.
No private development history, production credentials, unpublished launch bundles, signatures or future-family launch configurations are included. This publication changes no deployed contract and does not imply an independent audit, fresh chain/runtime comparison, or router allowlisting. See docs/VERIFICATION.md for evidence limits and SECURITY.md for private vulnerability reporting.