Silver criterion version_tags_signed (SUGGESTED; group Security, Secure release). Criterion text: It is SUGGESTED that in the version control system, each important version tag (a tag that is part of a major release, minor release, or fixes publicly noted vulnerabilities) be cryptographically signed and verifiable as described in signed_releases.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.