Skip to content

spec-kit

v0.11.7 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai copilot development engineering prd spec
+1 more
spec-driven

Affected surfaces

deps rce_ssrf

Summary

AI summary

Updates chore, scripts, and fix across a mixed release.

Full changelog

Install

uv tool install specify-cli --from git+https://github.com/github/[email protected]
specify init my-project

What's Changed

  • chore: bump version to 0.11.7
  • feat(extensions): verify catalog archive sha256 before install (#3080)
  • fix(workflows): validate requires keys and reject phantom permissions gate (#3079)
  • fix(scripts): use case-sensitive match for acronym retention in PS branch names (#3130)
  • feat(integrations): add omp support (#3107)
  • fix: render valid TOML when a command body contains backslashes (#3135)
  • harden: reject shell=True in run_command (#3132)
  • docs: add monorepo guide (#3084)
  • fix(scripts): send check-prerequisites.ps1 errors to stderr (#3123)
  • fix: write Codex dev skills as files (#2988)
  • chore: release 0.11.6, begin 0.11.7.dev0 development (#3121)

Security Fixes

  • Reject shell=True in run_command to prevent injection vulnerabilities (harden: reject shell=True in run_command #3132)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spec-kit

Get notified when new releases ship.

Sign up free

About spec-kit

All releases →

Related context

Earlier breaking changes

  • v0.10.0 Legacy AI flags (--ai, --ai-commands-dir, --ai-skills) removed.
  • v0.10.0 Git extension is now opt-in; --no-git flag removed.

Beta — feedback welcome: [email protected]