OSPS-DO-05 Document Security Update Scope and Duration (maturity level 3). Requirement: When the project has made a release, the project documentation MUST provide a descriptive statement when releases or versions will no longer receive security updates. Objective of the control: Communicate when the project maintainers will no longer fix defects or security vulnerabilities. Recommendation: In order to communicate the scope and duration of support for security fixes, the project should have a SUPPORT.md or other documentation explaining the project's policy for security updates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.