This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
copilot
development
engineering
prd
spec
+1 more
spec-driven
Affected surfaces
deps
rce_ssrf
Summary
AI summaryUpdates chore, scripts, and fix across a mixed release.
Full changelog
Install
uv tool install specify-cli --from git+https://github.com/github/[email protected]
specify init my-project
What's Changed
- chore: bump version to 0.11.7
- feat(extensions): verify catalog archive sha256 before install (#3080)
- fix(workflows): validate requires keys and reject phantom permissions gate (#3079)
- fix(scripts): use case-sensitive match for acronym retention in PS branch names (#3130)
- feat(integrations): add omp support (#3107)
- fix: render valid TOML when a command body contains backslashes (#3135)
- harden: reject shell=True in run_command (#3132)
- docs: add monorepo guide (#3084)
- fix(scripts): send check-prerequisites.ps1 errors to stderr (#3123)
- fix: write Codex dev skills as files (#2988)
- chore: release 0.11.6, begin 0.11.7.dev0 development (#3121)
Security Fixes
- Reject shell=True in run_command to prevent injection vulnerabilities (harden: reject shell=True in run_command #3132)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About spec-kit
All releases →Beta — feedback welcome: [email protected]