Preset ID
security-governance
Preset Name
Security Governance
Version
0.7.1
Description
Adds secure coding, memory-safe-language guidance, security-gate and supply-chain evidence, and scoped GDPR, NIS2, CRA, EU AI Act, and DORA screening to Spec Kit.
Author
Thorsten Hindermann
Repository URL
https://github.com/hindermath/spec-kit-preset-security-governance
Download URL
https://github.com/hindermath/spec-kit-preset-security-governance/archive/refs/tags/v0.7.1.zip
Documentation URL
https://github.com/hindermath/spec-kit-preset-security-governance/blob/v0.7.1/README.md
License
MIT
Required Spec Kit Version
=0.8.0
Required Extensions (optional)
None
Templates Provided
- security-governance-model-routing — agent-neutral routing contract
- constitution-template — appended secure-development principles
- spec-template — appended applicability and evidence requirements
- plan-template — appended security planning checks
- tasks-template — appended explicit security tasks
- security-agent-guidance-addendum-template — agent guidance
- msl-applicability-template — memory-safe-language applicability
- standard-applicability-template — standards applicability matrix
- security-checklist-template — security review checklist
- secure-coding-language-rules-template — language-specific secure coding
- dependency-audit-template — dependency/CVE evidence
- asvs-verification-template — scoped ASVS verification
- supply-chain-evidence-template — SBOM/AI-SBOM/VEX/provenance evidence
- cra-applicability-template — CRA scope and conformity-assessment record
- regulatory-applicability-template — regulatory screening
- gdpr-applicability-template — GDPR role-bound evidence
- ai-act-applicability-template — EU AI Act role-bound evidence
- nis2-applicability-template — NIS2 role-bound evidence
- dora-applicability-template — DORA role-bound evidence
Commands Provided
- speckit.specify — wraps Specify with security governance
- speckit.plan — wraps Plan with security governance
- speckit.tasks — wraps Tasks with security governance
Number of Scripts (optional)
0
Tags
security, governance, ssdf, sbom, regulatory
Key Features
- Update the existing catalog entry from 0.6.2 to 0.7.1, preserving the preset ID and priority 10.
- Includes v0.7.0's portable GDPR, EU AI Act, NIS2, and DORA evidence records and aligned CRA scope/duty/reporting fields.
- Separates sample product, development tooling, and operating organisation; direct legal and contractual duties are distinct, unknown roles stay Open, and educational purpose is not a blanket exemption.
- Retains language-specific secure coding, memory-safe-language guidance, audit-ready exact-head/security-gate evidence, ASVS and supply-chain applicability.
- v0.7.1 supplies a directly parseable exact-release one-line installation command and LF/CRLF/negative-command regression coverage; normative templates and wrapper behavior are unchanged from v0.7.0.
- Evidence templates do not grant legal compliance, product acceptance, risk acceptance, certification, or execution authority.
Testing Checklist
Submission Requirements
Immutable package and validation evidence
SHA-256 of the exact Download URL:
c85a4b924e741a3981dc369adc6233b6f323013fb1d46735555038d322cda18a
Preset ID
security-governance
Preset Name
Security Governance
Version
0.7.1
Description
Adds secure coding, memory-safe-language guidance, security-gate and supply-chain evidence, and scoped GDPR, NIS2, CRA, EU AI Act, and DORA screening to Spec Kit.
Author
Thorsten Hindermann
Repository URL
https://github.com/hindermath/spec-kit-preset-security-governance
Download URL
https://github.com/hindermath/spec-kit-preset-security-governance/archive/refs/tags/v0.7.1.zip
Documentation URL
https://github.com/hindermath/spec-kit-preset-security-governance/blob/v0.7.1/README.md
License
MIT
Required Spec Kit Version
Required Extensions (optional)
None
Templates Provided
Commands Provided
Number of Scripts (optional)
0
Tags
security, governance, ssdf, sbom, regulatory
Key Features
Testing Checklist
specify preset addSubmission Requirements
preset.ymlmanifest includedspecify preset add ...command using the exact download URLImmutable package and validation evidence
SHA-256 of the exact Download URL:
c85a4b924e741a3981dc369adc6233b6f323013fb1d46735555038d322cda18a775b3e43c2e5349a14a1fb10e8c77b0af5c0d86f.7204bccbdf3565d4dd22424c7fa7a15c6a6e0eb3; identical tested/released tree:b2ad2b805af2e3437d17ee9fa70f5d2dc098dfbb.