State is derived on every read, never recorded: the executable is dumped from each program's ProgramData account on devnet, trimmed and hashed, then compared against the compiled artifact on every matching release in cfx-solana-program-library. This reproduces solana-verify get-executable-hash, and reports what is on chain rather than what a deploy claimed — so it stays correct while programs are still deployed from a laptop.
Rows are expected to read Unmatched at launch. Release artifacts were overwritten in place behind static tags for four months, so for most programs no surviving release still carries the bytes that were deployed from it. That is the drift this page exists to make visible, not a fault in the reading.