Passing criterion release_notes_vulns (MUST; group Change Control, Release notes). Criterion text: The release notes MUST identify every publicly known run-time vulnerability fixed in this release that already had a CVE assignment or similar when the release was created. This criterion may be marked as not applicable (N/A) if users typically cannot practically update the software themselves (e.g., as is often true for kernel updates). This criterion applies only to the project results, not to its dependencies. If there are no release notes or there have been no publicly known vulnerabilities, choose N/A.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.