It must state the type of technical security support offered and the end date of the support period during which users can expect vulnerabilities to be handled and security updates to be received.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.