Build images using minimal base layers, remove development tools and shells where possible, and configure non root users. Treat the Dockerfile or equivalent build specification as code that is reviewed and version controlled.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.