A vendor that finds or receives a vulnerability in another vendor's product should report it to that vendor as a reporter would, and vendors sharing components should exchange reports so each can handle its own products; ISO/IEC 30111 8 lists the cases (an underlying OS or hardware issue, a flawed specification or algorithm, common development practices, common libraries, unmaintained components).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.