OSPS-BR-04 Publish Change Log With Release (maturity levels 2, 3). Requirement: When an official release is created, that release MUST contain a descriptive log of functional and security modifications. Objective of the control: Provide transparency and accountability for changes made to the project's software releases in such a way that users can understand the modifications and improvements included in each release. Recommendation: Ensure that all releases include a descriptive change log. It is recommended to ensure that the change log is human-readable and includes details beyond commit messages, such as descriptions of the security impact or relevance to different use cases. To ensure machine readability, place the content under a markdown header such as "## Changelog".
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.