Per SLSA Source Track: source integrity. Requirements include (a) branch protection + signed commits + (b) code review + two-person review for changes + (c) source repository security + (d) developer identity + access controls + (e) audit log of changes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.