Address OWASP Top 10 A06 Vulnerable and Outdated Components per OWASP Top 10:2025. Vulnerable and Outdated Components arises from using libraries + frameworks + runtimes + operating systems + containers + and other components with known vulnerabilities + end-of-life status + unsupported versions + or unauthorised modifications. Mitigations include (a) maintain inventory of components + dependencies + including transitive + (b) maintain Software Bill of Materials (SBOM) + (c) scan for known vulnerabilities + license issues + (d) verify component provenance + signing + (e) maintain patching + update programme with priority + tracking + (f) implement third-party script + tag management for client-side dependencies + (g) implement secure dependency lifecycle including secure update + retirement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.