Skip to main content

ship-spec productionalize

Production readiness analysis across security, SOC 2, code quality, dependencies, testing, and configuration.

ship-spec productionalize --cloud-ok
ship-spec productionalize "B2B SaaS handling PII" --enable-scans --cloud-ok
ship-spec productionalize --categories security,testing --cloud-ok

Options:

FlagDescriptionDefault
--enable-scansRun Semgrep, Gitleaks, Trivyfalse
--categories <list>Filter categories (csv)All
--reindexForce full codebase re-indexfalse
--no-streamWait for completionfalse
--checkpointEnable session persistencefalse
--thread-id <id>Resume checkpointed session-
--no-savePrint to stdout onlyfalse
--keep-outputs <n>Retention limit10
--cloud-okConsent to cloud usageRequired
--local-onlyUse local models onlyfalse

Analysis categories:

  • Core: security, soc2, code-quality, dependencies, testing, configuration
  • Dynamic (auto-detected): container-security, infrastructure-as-code, ci-cd

Workflow:

  1. Gather signals (stack, CI, testing, Docker, IaC)
  2. Researcher (web search for compliance standards)
  3. Scanner (SAST tools if enabled)
  4. Planner (creates subtasks per category)
  5. Workers (parallel analysis)
  6. Aggregator (Markdown report)
  7. Prompt Generator (agent-ready remediation tasks)

Outputs: .ship-spec/outputs/

  • report-<timestamp>.md
  • task-prompts-<timestamp>.md (agent-ready remediation tasks)
  • latest-report.md and latest-task-prompts.md symlinks