Preset ID
architecture-governance
Preset Name
Architecture Governance
Version
0.6.2
Description
Adds secure architecture, STRIDE/CAPEC threat models, arc42, S-ADRs, Zero Trust, SAMM, C3A/C5 cloud assurance, and audit-ready evidence to Spec Kit.
Author
Thorsten Hindermann
Repository URL
https://github.com/hindermath/spec-kit-preset-architecture-governance
Download URL
https://github.com/hindermath/spec-kit-preset-architecture-governance/archive/refs/tags/v0.6.2.zip
Documentation URL
https://github.com/hindermath/spec-kit-preset-architecture-governance/blob/v0.6.2/README.md
License
MIT
Required Spec Kit Version
=0.8.0
Required Extensions (optional)
None
Templates Provided
- architecture-governance-model-routing
- constitution-template
- spec-template
- plan-template
- tasks-template
- architecture-agent-guidance-addendum-template
- threat-model-template
- adr-template
- arc42-security-template
- security-quality-scenarios-template
- zero-trust-applicability-template
- samm-assessment-template
- cloud-autonomy-applicability-template
- c3a-criteria-catalog
- cloud-compliance-assurance-template
Commands Provided
- speckit.specify
- speckit.plan
- speckit.tasks
Number of Scripts (optional)
0
Tags
architecture, governance, threat-modeling, c3a, c5
Key Features
- Update the existing catalog entry from v0.5.2 to v0.6.2; preserve preset ID and priority 20. This is not a new preset.
- Secure architecture: STRIDE/CIA/CAPEC threat modeling, security ADRs, arc42 cross-cutting concepts, quality scenarios, Zero Trust applicability and SAMM assessment.
- Includes the v0.6.0 BSI C3A/C5 cloud-assurance additions, with a source-bound C3A criterion catalog and distinct C5 Type 1/Type 2 evidence semantics.
- Includes v0.6.1 privacy/data-flow, AI-tool-boundary and resilience/recovery/exit architecture integration. Regulatory applicability remains project-owned; Security Governance records or equivalent evidence can be referenced without a hard preset dependency.
- v0.6.2 itself only corrects the release installation documentation, shortens manifest metadata and adds regression coverage. Architecture templates, command wrappers, model routing and normative cloud/regulatory content are unchanged from v0.6.1.
- No automatic legal applicability, product acceptance, provider attestation, C5, conformity or certification claims.
Testing Checklist
Submission Requirements
Immutable package and validation evidence
- Stable v0.6.2 release and validation notes, including source-inventory SPDX SBOM.
- SHA-256 of the exact Download URL above:
ebea0ede13e6d72b8d65ae56b08ae28e07b3814aca3f8e9563b6590d0c88a082.
- Source PR #9: tested head
84c7457d9a5aa4e20b013daa578517d7b65d2e59, merge/tag commit 017e91a24a685e23f176e98c07c9ac8d81487cbb; identical source tree 68b2fed8f12b1d52ab38bc2651af79f38865925c.
- All three native platform checks passed: macOS, Linux and Windows. Six contract tests cover the cloud catalog, boundaries, manifest/wrappers and exact one-line installation, including LF/CRLF and negative regression cases.
- Exact tag-archive installation was verified in a disposable copy of Home Baseline's tracked
.specify project context at b11f86ed40de7d5bce6ac3d768f47b33d34dfa8b, replacing Architecture only inside that temporary copy. Preset list confirms v0.6.2 at priority 20; both cloud-autonomy-applicability-template and cloud-compliance-assurance-template resolve to this version. The live project and runtime were not changed.
- The README installation command is a single line and uses the exact submitted URL. The tag ZIP and attached release ZIP have identical extracted source trees; their distinct container hashes are documented in the release notes.
- Existing v0.6.1 tag and archive remain unchanged; its tag ZIP SHA-256 is
9ea0721e9475e4e955c4b71214adcc96b117ef97f977115446128bd157ed05c6.
- This submission is separate from central source-lock, Home Runtime, pilot and fleet rollout changes. No such rollout is claimed.
Preset ID
architecture-governance
Preset Name
Architecture Governance
Version
0.6.2
Description
Adds secure architecture, STRIDE/CAPEC threat models, arc42, S-ADRs, Zero Trust, SAMM, C3A/C5 cloud assurance, and audit-ready evidence to Spec Kit.
Author
Thorsten Hindermann
Repository URL
https://github.com/hindermath/spec-kit-preset-architecture-governance
Download URL
https://github.com/hindermath/spec-kit-preset-architecture-governance/archive/refs/tags/v0.6.2.zip
Documentation URL
https://github.com/hindermath/spec-kit-preset-architecture-governance/blob/v0.6.2/README.md
License
MIT
Required Spec Kit Version
Required Extensions (optional)
None
Templates Provided
Commands Provided
Number of Scripts (optional)
0
Tags
architecture, governance, threat-modeling, c3a, c5
Key Features
Testing Checklist
specify preset addSubmission Requirements
preset.ymlmanifest includedspecify preset add --fromcommand using the exact Download URLImmutable package and validation evidence
ebea0ede13e6d72b8d65ae56b08ae28e07b3814aca3f8e9563b6590d0c88a082.84c7457d9a5aa4e20b013daa578517d7b65d2e59, merge/tag commit017e91a24a685e23f176e98c07c9ac8d81487cbb; identical source tree68b2fed8f12b1d52ab38bc2651af79f38865925c..specifyproject context atb11f86ed40de7d5bce6ac3d768f47b33d34dfa8b, replacing Architecture only inside that temporary copy. Preset list confirms v0.6.2 at priority 20; bothcloud-autonomy-applicability-templateandcloud-compliance-assurance-templateresolve to this version. The live project and runtime were not changed.9ea0721e9475e4e955c4b71214adcc96b117ef97f977115446128bd157ed05c6.