Publishing checklist

Mapped to Spec Kit’s extensions/EXTENSION-PUBLISHING-GUIDE.md and the Extension Submission issue template.

🔗Before tagging

Guide requirementWhere it is satisfied
extension.yml with valid id, semver, description under 100 characters, public repository URL, 2–5 lowercase tagsextension.yml; enforced by tests/test_manifest.py
README.md with overview, installation, configuration, usage, troubleshooting, contributingREADME.md
LICENSE (permissive) and CHANGELOG.mdboth at the root
Command files exist for every declared commandcommands/; enforced by tests
Config template with documented options and defaultsconfig-template.yml, config.defaults in the manifest
No hardcoded secrets, validated inputs, trusted dependenciesPyYAML only; jsonschema optional; $ARGUMENTS never reaches a shell
Version bumped on every content changeRelease workflow refuses a tag whose version differs from the manifest

🔗Release

  1. Bump extension.version in extension.yml, update CHANGELOG.md, and update version and download_url in catalog.json (the test suite checks they agree).

  2. Tag and push:

    git tag v0.2.0 && git push origin v0.2.0
  3. The Release workflow runs the tests, builds threatspec-v0.2.0.zip, smoke-installs it with the Spec Kit CLI, and publishes a GitHub Release whose notes include the archive’s SHA-256.

  4. Verify the two install paths the guide expects:

    specify extension add threatspec --from https://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/v0.2.0.zip
    specify extension add --dev /path/to/spec-kit-threatspec

🔗Submit to the community catalog

File an issue with the Extension Submission template. Do not open a pull request against catalog.community.json. Field values:

FieldValue
Extension IDthreatspec
Extension NameThreatSpec — Threat Modeling & Security Traceability
Versionfrom extension.yml
DescriptionSTRIDE and AI/ML threat modeling with threat-to-test traceability and security convergence
Authorhupe1980
Repository URLhttps://github.com/hupe1980/spec-kit-threatspec
Download URLhttps://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/vX.Y.Z.zip
LicenseMIT
Documentation URLhttps://hupe1980.github.io/spec-kit-threatspec/
Changelog URLhttps://github.com/hupe1980/spec-kit-threatspec/blob/main/CHANGELOG.md
Required Spec Kit Version>=1.0.0
Required ToolsPython 3 with PyYAML, or uv
Number of Commands3
Number of Hooks7
Tagssecurity, threat-modeling, llm, agentic, traceability
Key FeaturesOTM-compatible threat-model.yaml; SR-### requirements published into spec.md; deterministic checks C1–C12 with SARIF output; evidence-based convergence with append-only verification history; profiles for STRIDE, OWASP LLM Top 10 2026, OWASP Agentic Top 10 2026
Testing checklistinstalls from the download URL (release workflow smoke test); commands executed on real projects; docs complete; no known vulnerabilities (see ThreatSpec’s own threat model)

The community catalog is discovery-only. Users either copy the entry into a catalog they trust or use the --from URL. The ready-made entry in catalog.json at the repository root is what a maintainer would paste.

🔗Self-hosted catalog

catalog.json is also a complete installable catalog. Teams can register it and install by name:

specify extension catalog add https://raw.githubusercontent.com/hupe1980/spec-kit-threatspec/main/catalog.json --name threatspec --install-allowed
specify extension add threatspec

Spec Kit ≥ 1.0.7 requires tag-pinned download URLs in catalogs, which is why download_url names a release tag rather than main.

Edit this page on GitHub