Upgrade authority
Deployment and program-upgrade operations remain an external operational trust boundary for the Devnet release.
The frozen release manifest identifies the source and binary deployed under the official Devnet Program ID. A matching artifact identity establishes which reviewed release was validated; it does not by itself make the deployed program immutable.
Solana program deployment/upgrade operations remain an external trust boundary. The release evidence does not claim that upgrade authority has been permanently revoked or that deployment governance is trustless. Integrators should verify the deployed program identity and any upgrade-authority state through their own canonical Devnet tooling before relying on a deployment.
An upgrade could change program behavior, so a future deployment should be treated as a new release identity with new source/binary provenance, review, validation and public documentation. Do not infer a future program's behavior from the current manifest alone.
This operational caveat is distinct from the single-party Groth16 setup assumption and the centralized hosted relayer. See Current release, Validation evidence and Known limitations.