Skip to content

[preset] Add Secure Development Assurance Governance preset - #4513

Merged
KSchlobohm merged 3 commits into
mainfrom
add-secure-development-assurance-governance-preset-ebcad89abe97311b
Sep 10, 2026
Merged

[preset] Add Secure Development Assurance Governance preset#4513
KSchlobohm merged 3 commits into
mainfrom
add-secure-development-assurance-governance-preset-ebcad89abe97311b

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Add the new secure-development-assurance-governance v0.1.3 community preset submitted by @hindermath.

Updated:

  • presets/catalog.community.json with the alphabetically ordered preset entry and current catalog timestamp.
  • docs/community/presets.md with the alphabetically ordered community preset table row.

Validation passed for the preset ID, semver version, public repository, preset.yml, LICENSE, documentation README, exact specify preset add --from command, release tag, and required issue checklists.

Closes #4455

cc @hindermath

Generated by 🎨 Add Community Preset from Issue Submission for issue #4455 · 80.7 AIC · ⌖ 9.43 AIC · ⊞ 30.1K ·

Add secure-development-assurance-governance preset submitted by @hindermath to:

- presets/catalog.community.json (alphabetical order)

- docs/community/presets.md community presets table

Closes #4455

Assisted-by: GitHub Copilot (model: gpt-5.2-codex, autonomous)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@KSchlobohm
KSchlobohm marked this pull request as ready for review September 10, 2026 15:29
@KSchlobohm
KSchlobohm requested a review from mnriem as a code owner September 10, 2026 15:29
Copilot AI balanced review requested due to automatic review settings September 10, 2026 15:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The only remaining comment is a non-blocking documentation nit.

Pull request overview

Adds the secure-development-assurance-governance v0.1.3 community preset.

Changes:

  • Registers the preset in presets/catalog.community.json.
  • Documents it in docs/community/presets.md.
File summaries
File Summary
presets/catalog.community.json Added the preset catalog entry and timestamp.
docs/community/presets.md Added the community preset documentation row; a non-blocking prerequisite note remains.
Review details

Suppressed comments (1)

docs/community/presets.md:35

  • This preset's bundled Bash and PowerShell validators require .specify/presets/security-governance/preset.yml at version >=0.6.1; with in the Requires column, users following the catalog are not told about a prerequisite and a fresh install will fail validation. Please list security-governance >=0.6.1 here, as the table already does for the parallel governance preset.
| Secure Development Assurance Governance | Validates project-owned secure-development manifests, hashes, checklists, reviews, risks, closure, and image-impact evidence without granting human approvals or certifications. | 1 template, 2 commands, 2 scripts | — | [spec-kit-preset-secure-development-assurance-governance](https://github.com/hindermath/spec-kit-preset-secure-development-assurance-governance) |
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@KSchlobohm KSchlobohm self-assigned this Sep 10, 2026
Comment thread docs/community/presets.md

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Update the documentation’s Requires cell to to match the catalog.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread docs/community/presets.md Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The documentation omits the required security-governance >=0.6.1 dependency.

Review details

Suppressed comments (1)

docs/community/presets.md:35

  • This hides a real prerequisite: the published v0.1.3 README requires security-governance >=0.6.1, and both bundled validators fail when .specify/presets/security-governance/preset.yml is absent. Please advertise that required preset in the Requires column; otherwise users following the catalog will install a preset that cannot validate in a fresh project.
| Secure Development Assurance Governance | Validates project-owned secure-development manifests, hashes, checklists, reviews, risks, closure, and image-impact evidence without granting human approvals or certifications. | 1 template, 2 commands, 2 scripts | — | [spec-kit-preset-secure-development-assurance-governance](https://github.com/hindermath/spec-kit-preset-secure-development-assurance-governance) |
  • Files reviewed: 2/2 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@KSchlobohm

Copy link
Copy Markdown
Contributor

Noted the runtime prerequisite and the Copilot reviewer's concern. The shipped validators intentionally fail closed unless the separately installed security-governance preset is at least 0.6.1.

However, this catalog’s requires metadata and the table’s Requires column currently model extensions only; security-governance is a preset, and Spec Kit does not yet support declarative preset-to-preset dependencies.

We should therefore retain - here to match the supported schema and submission metadata.

@KSchlobohm
KSchlobohm merged commit 7cb2c7d into main Sep 10, 2026
17 checks passed
@KSchlobohm
KSchlobohm deleted the add-secure-development-assurance-governance-preset-ebcad89abe97311b branch September 10, 2026 17:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Preset]: Add Secure Development Assurance Governance v0.1.3

2 participants