Operate static analysis + fuzzing + testing per OpenSSF Scorecard checks SAST + Fuzzing + CI-Tests. Static Analysis SAST must (a) run SAST on every PR + (b) detect common security vulnerabilities (injection + authentication + authorisation + crypto + secrets + supply chain) + (c) integrate with code review gating + (d) align with broader SDLC security testing. Fuzzing must (a) operate fuzzing on appropriate components (parsers + network protocols + cryptographic routines + complex input handlers) + (b) integrate with OSS-Fuzz or equivalent + (c) maintain corpus + regression tracking + (d) coordinate fuzzing-found vulnerabilities with VDP + remediation. Test coverage must (a) measure test coverage + (b) maintain coverage thresholds for security-critical code + (c) treat coverage gaps in security boundaries as remediation priorities.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.