Skip to content

[Preset]: Update Security Governance to v0.6.2 #4039

Description

@hindermath

Preset ID

security-governance

Preset Name

Security Governance

Version

0.6.2

Description

Adds memory-safe-language and secure-coding governance, exact-head security evidence, ASVS, supply-chain transparency, EU regulatory screening, and provider-neutral model routing.

Author

Thorsten Hindermann

Repository URL

https://github.com/hindermath/spec-kit-preset-security-governance

Download URL

https://github.com/hindermath/spec-kit-preset-security-governance/archive/refs/tags/v0.6.2.zip

Documentation URL

https://github.com/hindermath/spec-kit-preset-security-governance/blob/v0.6.2/README.md

License

MIT

Required Spec Kit Version

=0.8.0

Required Extensions (optional)

None

Templates Provided

  • security-governance-model-routing (model-routing.json) — agent-neutral command-to-role routing contract
  • constitution-template — secure-development governance principles
  • spec-template — security applicability and evidence requirements
  • plan-template — secure-development planning checks
  • tasks-template — explicit security and supply-chain tasks
  • security-agent-guidance-addendum-template — standalone security agent guidance
  • msl-applicability-template — memory-safe-language applicability record
  • standard-applicability-template — audit-ready standards applicability matrix
  • security-checklist-template — security review checklist with CWE Top 25 and language-specific sections
  • secure-coding-language-rules-template — secure-coding rules for the supported language profiles
  • dependency-audit-template — dependency and CVE review record
  • asvs-verification-template — ASVS verification with explicit Level 1/2/3 selection
  • supply-chain-evidence-template — SBOM, AI-SBOM, VEX, SLSA, and OpenSSF Scorecard evidence
  • cra-applicability-template — EU Cyber Resilience Act applicability and conformity assessment
  • regulatory-applicability-template — NIS2, CRA, EU AI Act, and DORA applicability screening

Commands Provided

  • speckit.specify — wraps Specify with security-governance checks
  • speckit.plan — wraps Plan with security-governance checks
  • speckit.tasks — wraps Tasks with security-governance checks

Number of Scripts (optional)

0

Tags

security, governance, secure-coding, supply-chain, model-routing

Key Features

  • Updates the currently cataloged v0.6.1 entry to the exact v0.6.2 release.
  • Publishes a provider-neutral model-routing.json contract so Spec Kit commands declare workload roles while concrete model selections remain machine-local.
  • Preserves the existing security behavior; the v0.6.2 functional addition is the composable model-routing contract.
  • Retains memory-safe-language preference, language-specific secure-coding profiles, exact-head and security-gate evidence, provider-failure classification, ASVS verification, and supply-chain evidence for SBOM, AI-SBOM, VEX, SLSA, and OpenSSF Scorecard.
  • Retains applicability screening for NIS2, CRA, the EU AI Act, and DORA.
  • The tagged archive was re-tested with Spec Kit 0.12.8: installation succeeded, all 15 templates and three commands were recognized, and security-governance-model-routing resolved to the published model-routing.json.
  • The same release participates in the validated twelve-preset model-routing composition across the managed repository fleet; field evidence is available at https://github.com/hindermath/home-baseline/blob/main/docs/field-validation/model-routing-fleet-2026-08-09.md.

Testing Checklist

  • Preset installs successfully via specify preset add
  • Template resolution works correctly after installation
  • Documentation is complete and accurate
  • Tested on at least one real project

Submission Requirements

  • Valid preset.yml manifest included
  • Linked README (Documentation URL) explains how to use this preset and includes a valid specify preset add ... command using the exact Download URL
  • LICENSE file included
  • GitHub release created with version tag
  • Preset ID follows naming conventions

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions