Skip to content

[Preset]: Update Security Governance to v0.7.1 #4901

Description

@hindermath

Preset ID

security-governance

Preset Name

Security Governance

Version

0.7.1

Description

Adds secure coding, memory-safe-language guidance, security-gate and supply-chain evidence, and scoped GDPR, NIS2, CRA, EU AI Act, and DORA screening to Spec Kit.

Author

Thorsten Hindermann

Repository URL

https://github.com/hindermath/spec-kit-preset-security-governance

Download URL

https://github.com/hindermath/spec-kit-preset-security-governance/archive/refs/tags/v0.7.1.zip

Documentation URL

https://github.com/hindermath/spec-kit-preset-security-governance/blob/v0.7.1/README.md

License

MIT

Required Spec Kit Version

=0.8.0

Required Extensions (optional)

None

Templates Provided

  • security-governance-model-routing — agent-neutral routing contract
  • constitution-template — appended secure-development principles
  • spec-template — appended applicability and evidence requirements
  • plan-template — appended security planning checks
  • tasks-template — appended explicit security tasks
  • security-agent-guidance-addendum-template — agent guidance
  • msl-applicability-template — memory-safe-language applicability
  • standard-applicability-template — standards applicability matrix
  • security-checklist-template — security review checklist
  • secure-coding-language-rules-template — language-specific secure coding
  • dependency-audit-template — dependency/CVE evidence
  • asvs-verification-template — scoped ASVS verification
  • supply-chain-evidence-template — SBOM/AI-SBOM/VEX/provenance evidence
  • cra-applicability-template — CRA scope and conformity-assessment record
  • regulatory-applicability-template — regulatory screening
  • gdpr-applicability-template — GDPR role-bound evidence
  • ai-act-applicability-template — EU AI Act role-bound evidence
  • nis2-applicability-template — NIS2 role-bound evidence
  • dora-applicability-template — DORA role-bound evidence

Commands Provided

  • speckit.specify — wraps Specify with security governance
  • speckit.plan — wraps Plan with security governance
  • speckit.tasks — wraps Tasks with security governance

Number of Scripts (optional)

0

Tags

security, governance, ssdf, sbom, regulatory

Key Features

  • Update the existing catalog entry from 0.6.2 to 0.7.1, preserving the preset ID and priority 10.
  • Includes v0.7.0's portable GDPR, EU AI Act, NIS2, and DORA evidence records and aligned CRA scope/duty/reporting fields.
  • Separates sample product, development tooling, and operating organisation; direct legal and contractual duties are distinct, unknown roles stay Open, and educational purpose is not a blanket exemption.
  • Retains language-specific secure coding, memory-safe-language guidance, audit-ready exact-head/security-gate evidence, ASVS and supply-chain applicability.
  • v0.7.1 supplies a directly parseable exact-release one-line installation command and LF/CRLF/negative-command regression coverage; normative templates and wrapper behavior are unchanged from v0.7.0.
  • Evidence templates do not grant legal compliance, product acceptance, risk acceptance, certification, or execution authority.

Testing Checklist

  • Preset installs successfully via specify preset add
  • Template resolution works correctly after installation
  • Documentation is complete and accurate
  • Tested on at least one real project

Submission Requirements

  • Valid preset.yml manifest included
  • Linked README (Documentation URL) explains how to use this preset and includes a valid specify preset add ... command using the exact download URL
  • LICENSE file included
  • GitHub release created with version tag
  • Preset ID follows naming conventions (lowercase-with-hyphens)

Immutable package and validation evidence

SHA-256 of the exact Download URL:

c85a4b924e741a3981dc369adc6233b6f323013fb1d46735555038d322cda18a

Activity

  1. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    cc @github/spec-kit-maintainers — new catalog submission for review.

  2. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    Pull request created: #4903

    Generated by Add Community Preset from Issue Submission · copilot · gpt52codex · 3.99 AIC · ⌖ 0.752 AIC · ⊞ 26.7K

  3. mnriem commented on Oct 9, 2026

    @mnriem
    Collaborator

    Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions