Per OWASP ASVS V10: protect against malicious code. Requirements include (a) integrate static + dynamic + interactive application security testing in CI/CD pipeline + (b) maintain dependency inventory + SBOM + scan for vulnerabilities + license issues + malicious packages + (c) verify package provenance + signing + (d) implement code signing for application code + scripts + container images + (e) protect against supply chain attacks via dependency confusion + typosquatting + repository compromise + (f) implement runtime application self-protection (RASP) + similar runtime protections where appropriate.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.