Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.