Implement branch protection + code review + repository governance per OpenSSF Scorecard checks Branch-Protection + Code-Review + Maintained. Branch protection must (a) require pull requests + (b) require reviewers (typically 1 minimum + 2 for high-impact branches) + (c) require status checks to pass + (d) require up-to-date branches + (e) restrict force pushes + (f) restrict deletion + (g) include administrators per Scorecard scoring. Code Review on Changes must verify (a) PRs have approving review from required reviewers + (b) review is by collaborator with write access + (c) self-merge restrictions where appropriate. Maintained Project assesses (a) recent commits + (b) release cadence + (c) issue triage activity + (d) project is not archived + with documented sustainability practice. Integrate with broader Software Development Lifecycle governance + with documented exception management + change record + audit trail.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.