Operate dependency management per OpenSSF Scorecard checks Dependency-Update-Tool + Pinned-Dependencies + Vulnerabilities. Dependency Update Tool Active must (a) verify Dependabot + Renovate + or equivalent is configured + (b) maintains dependency update PRs + (c) integrates with CI for verification. Pinned Dependencies must (a) pin dependencies to specific versions or commit SHAs rather than tag references for actions + container images + scripts + packages + (b) verify pinning across workflow files + Dockerfiles + scripts + package manifests. Vulnerabilities Free of Known Critical Issues must (a) scan dependencies + container images + transitive deps against vulnerability databases (OSV + CVE + GHSA + npm advisory + PyPA + similar) + (b) maintain remediation within SLA aligned with severity + (c) align with broader vulnerability management programme. Maintain SBOM Generation and Publication per SCORE-19 with CycloneDX or SPDX format + signed + published per release.
This control maps to 75 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.