diff --git a/README.md b/README.md index 68e48d3..02df044 100644 --- a/README.md +++ b/README.md @@ -22,8 +22,13 @@ This template demonstrates: - **Multi-Runtime Support**: Targets .NET 8, 9, and 10 - **Comprehensive CI/CD**: GitHub Actions workflows with quality checks, builds, and integration tests +- **Linting Enforcement**: markdownlint, cspell, and yamllint enforced on every CI run +- **Continuous Compliance**: Compliance evidence generated automatically on every CI run, following + the [Continuous Compliance][link-continuous-compliance] methodology +- **SonarCloud Integration**: Quality gate and security analysis on every build - **Documentation Generation**: Automated build notes, user guide, code quality reports, requirements, justifications, and trace matrix +- **Requirements Traceability**: Requirements linked to passing tests with auto-generated trace matrix ## Installation @@ -132,3 +137,4 @@ By contributing to this project, you agree that your contributions will be licen [link-security]: https://sonarcloud.io/dashboard?id=demaconsulting_TemplateDotNetTool [link-nuget]: https://www.nuget.org/packages/DemaConsulting.TemplateDotNetTool [link-guide]: https://github.com/demaconsulting/TemplateDotNetTool/blob/main/docs/guide/guide.md +[link-continuous-compliance]: https://github.com/demaconsulting/ContinuousCompliance diff --git a/docs/guide/guide.md b/docs/guide/guide.md index 034054f..4abb284 100644 --- a/docs/guide/guide.md +++ b/docs/guide/guide.md @@ -14,6 +14,20 @@ This user guide covers: - Command-line options reference - Practical examples for various scenarios +# Continuous Compliance + +This template follows the [Continuous Compliance][continuous-compliance] methodology, which ensures +compliance evidence is generated automatically on every CI run. + +## Key Practices + +- **Requirements Traceability**: Every requirement is linked to passing tests, and a trace matrix is + auto-generated on each release +- **Linting Enforcement**: markdownlint, cspell, and yamllint are enforced before any build proceeds +- **Automated Audit Documentation**: Each release ships with generated requirements, justifications, + trace matrix, and quality reports +- **CodeQL and SonarCloud**: Security and quality analysis runs on every build + # Installation Install the tool globally using the .NET CLI: @@ -143,3 +157,6 @@ templatetool --validate --results validation-results.trx ```bash templatetool --silent --log tool-output.log ``` + + +[continuous-compliance]: https://github.com/demaconsulting/ContinuousCompliance