|
| 1 | +# 1.2 (2026-03-10) |
| 2 | + |
| 3 | +## Added |
| 4 | + |
| 5 | +- **DocEngine CLI** (`c5dec docengine report|presentation -n <name> [-d <dest>]`): `create_docengine_template()` in the SSDLC module copies and customizes report/presentation templates with variable substitution, overwrite protection, Quarto dependency check, and `REPORT_TEMPLATE_PATH` / `PRESENTATION_TEMPLATE_PATH` constants in `c5settings.py` |
| 6 | +- **DocEngine enhancements**: `c5dec_config_v2.yml` and `custom_vars_v2.py` pre-render script with automatic LaTeX conversion, support for string/list/dict changelog entry formats, and LaTeX escaping for special characters; Quarto presentation template (`c5dec/assets/presentation/`) with Reveal.js and PowerPoint output, ALab branding, and modular slide organization |
| 7 | +- **`docEngine.Dockerfile`**: dedicated DocEngine dev container (Quarto, TeX Live, Kryptor, Cryptomator CLI); separate `.devcontainer/c5dec-dev/` for the lightweight C5-DEC dev container |
| 8 | +- **CRA compliance module** (`c5dec/core/cra.py`, EU Regulation 2024/2847 Tier 1): YAML requirements database (35+ Annex I items), Doorstop-integrated checklist with pass/fail/na verdicts and Excel export, CRA Technical Documentation template (Annex VII, seven chapters), EU Declaration of Conformity generator (Annex V); `cra` CLI command (`create`, `verify`, `export`); feature flags and `c5settings.py` constants; test suite `tests/cra_checklist_test.py` (16 methods); user manual `docs/manual/cra.md` |
| 9 | +- **SBOM lifecycle management module** (`c5dec/core/sbom.py`): Syft-based generation (CycloneDX/SPDX), parsing, validation, version diff, Doorstop traceability, and `auto_verify_sbom_requirement()` for CRA `cra_ii_1_1`; `sbom` CLI command (`generate`, `import`, `diff`, `validate`); test suite `tests/sbom_test.py` (25+ methods); user manual `docs/manual/sbom.md` |
| 10 | +- **Native Python cryptography module** (`c5dec/core/cryptography.py`): SHA-256 file integrity, GnuPG signing/encryption, Shamir's Secret Sharing over GF(2^127−1), NaCl Ed25519 digital signatures; `c5dec crypto` CLI command with 11 subcommands (`hash`, `verify-hash`, `sign`, `verify-sig`, `encrypt`, `decrypt`, `shamir-split`, `shamir-recover`, `nacl-keygen`, `nacl-sign`, `nacl-verify`) |
| 11 | +- **CPSSA as a multi-subsystem package** (`c5dec/core/cpssa/`): `create_threat_model()` generating Threagile-compatible YAML from Doorstop SRS/ARC artefacts with auto-discovery of architecture folders; `generate_cpssa_report()` for STRIDE-based Markdown reports; Threagile field-mapping subsystem (`threagile-mappings.yml`, `threagile-schema.json`); sidecar YAML support (`threat-actors.yml`, `assumptions.yml`); `generate_fair_input_template()` and `run_quantitative_risk_analysis()` with `--fair-params` YAML override and PERT distribution support; water-treatment worked example (`c5dec/core/cpssa/examples/water-treatment/`) |
| 12 | +- **SpecEngine tools**: `c5graph.py` — interactive Cytoscape.js traceability graph producing a self-contained `specs-graph.html` (dagre layout, expand/collapse, color-coded coverage, offline asset inlining); `prune_bad_links.py` — removes Doorstop links with mismatched target prefix or links on root documents; `doorstop_yml_to_md.py` — migration script converting Doorstop items from pure YAML to Markdown with YAML frontmatter; `c5mermaid.py` — Mermaid diagram pre-processor that scans Doorstop `.md` item files for fenced ` ```mermaid ``` ` blocks, renders each to SVG (or PNG) via the Mermaid CLI (`mmdc`), stores the result in the item's `assets/` directory, and replaces the fenced block with an HTML comment preserving the original source plus a Markdown image reference; transformation is one-way and idempotent (content-hash-based filenames, `c5-mermaid-source` sentinel); supports `render` (default) and `undo` actions, `--dry-run`, and `--format svg|png`; integrated into `publish.sh` (render before publish, undo after); all support `--dry-run`; "Traceability Graph" entry added to `index.html` via `c5publish.py`; automatic item ID linkification in published HTML (`linkify_html_file()` / `_linkify_item_ids()`); per-column filter inputs in `c5browser.py`; section titles in `c5traceability.py` nav bar; `docs/specs/SpecEngine/README.md` and `c5traceability_config_example.yaml` added |
| 13 | +- **Specs**: 19 new SRS items; 5 new TCS test cases; grouping items added to `swd/`, `mrs/`, and `arc/`; headings added to all TRP items; SWD-002 updated with full C5-DEC CAD class diagram in Mermaid; SWD-003 updated with Mermaid architecture overview diagram |
| 14 | +- **Documentation**: user manuals `docs/manual/isms.md`, `docs/manual/README.md`; updated `cpssa.md`, `cryptography.md`, `ssdlc.md` |
| 15 | +- **Project template** (`c5dec/assets/templates/project/`) synchronized with current toolchain: containers, SpecEngine toolkit, DocEngine assets, refreshed `pyproject.toml` and `poetry.lock` |
| 16 | +- `SECURITY.md` detailing supported versions, responsible disclosure process, response timeline, scope definition |
| 17 | +- `CONTRIBUTING.md` explaining how to set up the development environment, submit changes, and follow project conventions |
| 18 | +- **Mermaid resize support** in `c5mermaid.py`: `--width` and `--height` flags passed to `mmdc` for SVG/PNG output dimensions |
| 19 | +- TCS and TRP Doorstop document templates added to the project template (`c5dec/assets/templates/project/docs/specs/`); test case and test report spec documents consolidated |
| 20 | +- **Common Criteria knowledge base**: completed CC KB (new CC pages) and revisions covering CC:2022 |
| 21 | + |
| 22 | +## Fixed |
| 23 | + |
| 24 | +- TeX rendering issue in DocEngine templates and `cli new` command (malformed `\usepackage` argument in `_quarto.yml`) |
| 25 | +- Broken Doorstop link format in 14 SWD items (`ARC003`/`ARC004` → `ARC-003`/`ARC-004`) |
| 26 | +- Orphaned TCS-001–TCS-007 with empty `links: []`; all now carry SRS traceability links |
| 27 | +- 14 SRS items with placeholder (TBD) text replaced with complete procedural descriptions |
| 28 | +- Missing MRS upward traceability links in ARC-003 (MRS-013, MRS-024, MRS-025, MRS-046, MRS-047) and ARC-004 (MRS-040, MRS-041, MRS-044, MRS-060) |
| 29 | +- HTML output path in `c5traceability.py` and `c5browser.py` resolved relative to script dir instead of specs dir; corrected to `SCRIPT_DIR.parent / "docs" / "publish"` |
| 30 | +- Typos in SRS items |
| 31 | + |
| 32 | +## Modified |
| 33 | + |
| 34 | +- `dev.Dockerfile` and `docEngine.Dockerfile` extended with Node.js 20.x, Chromium, and Mermaid CLI (`mmdc`) for Mermaid diagram rendering in the SpecEngine pipeline |
| 35 | +- `dev.Dockerfile` stripped of DocEngine dependencies (Quarto, TeX Live, fonts, cryptographic tools); `.devcontainer/devcontainer.json` updated to use `docEngine.Dockerfile` |
| 36 | +- `c5dec crypto` CLI upgraded from stub to full implementation dispatching to the native cryptography module |
| 37 | +- `c5dec cpssa` CLI extended with `fair-input` and `risk-analysis` subcommands |
| 38 | +- `c5traceability.py`: generalized to YAML-configurable, project-agnostic Doorstop traceability analyser; added `--config`, `--discover`, `--discover-write` flags and auto-discovery of document hierarchy from `.doorstop.yml` files |
| 39 | +- `c5browser.py`: extended to support both `.md` (Markdown frontmatter) and `.yml` (pure YAML) Doorstop item formats; document type list auto-discovered at runtime; numeric field detection for proper column sorting |
| 40 | +- All 246 Doorstop item files in `arc`, `mrs`, `srs`, `swd`, `tra`, `trb`, `tst` converted from pure YAML to Markdown with YAML frontmatter; `.doorstop.yml` configs updated to `itemformat: markdown` |
| 41 | +- ARC item files renamed to hyphenated format (`ARC001.yml` → `ARC-001.yml`); SWD items likewise (`SWD001.yml`–`SWD014.yml` → `SWD-001.yml`–`SWD-014.yml`) |
| 42 | +- PlantUML schematics relocated to `docs/specs/swd/assets/PlantUML/`; obsolete `classes.puml` and `subsystems.puml` removed |
| 43 | +- SpecEngine folder renamed from `docs/specs/c5dec-SpecEngine/` to `docs/specs/SpecEngine/`; `publish.sh` updated with linkification step, `c5graph.py` generation, and Mermaid render/undo steps |
| 44 | +- `c5publish.py` tooling-reports block moved to `<body>` top with "Traceability Graph" link added |
| 45 | +- DocEngine pre-render script updated from `custom_vars.py` to `custom_vars_v2.py`; default approval signatures set to placeholder (`"---"`) |
| 46 | +- **Docker security hardening**: non-root user, dropped Linux capabilities, `--no-install-recommends`, and package pinning applied to `Dockerfile`, `dev.Dockerfile`, and `docEngine.Dockerfile`; `.dockerignore` added to limit build context |
| 47 | +- **Unit test coverage significantly extended**: new test files for CLI (`cli_test.py`, 298 lines), ISMS (`isms_test.py`, 268 lines), SSDLC (`ssdlc_test.py`, 251 lines), Transformer (`transformer_test.py`, 176 lines), CPSSA (`cpssa_test.py`, 1175 lines), and cryptography (`cryptography_test.py`, 380 lines); existing CCT test files improved |
| 48 | +- Mermaid SVGs pre-rendered for SWD-002 and SWD-003; stored in `docs/specs/swd/assets/` |
| 49 | +- README, `docs/manual/README.md`, `docs/specs/README.md` |
| 50 | + |
| 51 | +## Removed |
| 52 | + |
| 53 | +- DocEngine-specific dependencies from `dev.Dockerfile` (moved to `docEngine.Dockerfile`) |
| 54 | +- `c5traceability_v2.py`; merged into `c5traceability.py` |
| 55 | +- Stale Doorstop Bootstrap CSS/JS assets from `docs/assets/doorstop/`; replaced by CDN references |
| 56 | +- `docs/manual/overview.md`; content merged into `docs/manual/start.md` |
| 57 | + |
| 58 | + |
1 | 59 | # 1.1 (2025-05-12) |
2 | 60 |
|
3 | 61 | ## Added |
|
0 commit comments