Per SLSA Dependency Track: dependencies. Requirements include (a) Software Bill of Materials (SBOM) + (b) dependency verification + provenance + (c) vulnerability scanning + (d) license + malicious package screening + (e) reproducible dependency resolution.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.