Skip to content

[Preset]: Add Secure Development Assurance Governance v0.1.3 #4455

Description

@hindermath

Preset ID

secure-development-assurance-governance

Preset Name

Secure Development Assurance Governance

Version

0.1.3

Description

Validates project-owned secure-development manifests, hashes, checklists, reviews, risks, closure, and image-impact evidence without granting human approvals or certifications.

Author

Thorsten Hindermann

Repository URL

https://github.com/hindermath/spec-kit-preset-secure-development-assurance-governance

Download URL

https://github.com/hindermath/spec-kit-preset-secure-development-assurance-governance/archive/refs/tags/v0.1.3.zip

Documentation URL

https://github.com/hindermath/spec-kit-preset-secure-development-assurance-governance/blob/v0.1.3/README.md

License

MIT

Required Spec Kit Version

=0.8.3

Required Extensions (optional)

None

Templates Provided

  • secure-development-evidence-contract.md — portable evidence and decision-boundary contract

Commands Provided

  • speckit.secure-development-status.md — read-only inspection of a secure-development evidence directory
  • speckit.secure-development-review.md — validation of one named gate with authority-bounded review evidence

Number of Scripts (optional)

2

Tags

security, governance, assurance, evidence, cross-platform

Key Features

  • Validates separately bound baseline, delta, closure, and image-impact gates.
  • Checks versions, normalized hashes, twelve unique checklists, review metadata, accepted risks, and image-impact fields.
  • Keeps technical validation independent from pilot authorization, project acceptance, product or sandbox release, fleet release, and certification.
  • Provides matching Bash and PowerShell validators with read-only status behavior and fail-closed exit semantics.
  • The v0.1.2 baseline passed native Linux, macOS, and Windows package tests and serial RL-SE and GSDB field tests in TinyCalc; this historical evidence is not a new v0.1.3 field-test acceptance.

Testing Checklist

  • Preset installs successfully via specify preset add
  • Template resolution works correctly after installation
  • Documentation is complete and accurate
  • Tested on at least one real project

Submission Requirements

  • Valid preset.yml manifest included
  • Linked README (Documentation URL) explains how to use this preset and includes a valid specify preset add ... command (preferably specify preset add --from <download-url> using the exact download URL)
  • LICENSE file included
  • GitHub release created with version tag
  • Preset ID follows naming conventions (lowercase-with-hyphens)

Scope Boundary

The field-test outcome is ReleaseAccepted for preset v0.1.2 and its evidence contract only. It does not approve TinyCalc findings, human decisions, product or sandbox release, certification, fleet rollout, or selection of Level-2 repositories.

v0.1.3 Update

Updated this existing submission to the published v0.1.3 pre-release:
https://github.com/hindermath/spec-kit-preset-secure-development-assurance-governance/releases/tag/v0.1.3

  • Requires an exact, unique dated context ID and rejects ambiguous context selection.
  • Binds evidence ID and operating mode to the review request.
  • Requires optional acceptedRisks to be an array when present, addressing divergent Bash/PowerShell handling.
  • Addresses two defects reproduced in absdd-image-sandbox PR Resuming / Loading an existing session #57.

The testing checklist above records the previously submitted v0.1.2 baseline evidence. The earlier ReleaseAccepted outcome remains explicitly scoped to v0.1.2; this update does not assert a new v0.1.3 field-test acceptance or any human approval, certification, or rollout authorization.

Documentation Impact: UpdateRequired. Owner: Thorsten Hindermann. The upstream submission is the canonical source for the submitted version and its download/documentation links; updated for catalog maintainers and preset consumers. Reevaluate on the next release or maintainer feedback.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions