EM ANDAMENTO
Resumo técnico
Gerenciador DevSecOps para GitHub com OAuth App (anti-CSRF). Backend modular: client (config/token/repos), workflows (Actions, Secrets libsodium, Dependabot com detecção 23 ecossistemas), commits (diffs/revert), PRs (AI Code Review/merge), releases (SemVer notes), security (Dependabot+Secret Scanning, commit audit com risk score, Health Scorecard), purger (scanner 8 regex, git-filter-repo/BFG), sync (cronjob auto-sync PRs e CVEs no Kanban). Interface Alpine.js 8 abas, Marked.js, i18n, 3 slash commands Fastr.
Escopo executado
plugin.php(320 linhas): aba "GitHub Manager" em "Development" com íconegithub, doc, modal de configuração, 20+ ações de API (github_get_config, github_save_config, github_revoke_token, github_disconnect, github_callback, github_user, github_list_repos, github_commits, github_commit_detail, github_diff, github_revert_commit, github_get_prs, github_pr_detail, github_create_pr, github_merge_pr, github_review_pr, github_actions, github_create_workflow_dispatch, github_secrets, github_set_secret, github_set_variable, github_install_dependabot, github_releases, github_create_release, github_tags, github_security_alerts, github_health_score, github_ai_analyze, github_purge_secrets, github_sync_all).backend.php(24 linhas): master controller que carrega 8 módulos de/includes/.includes/client.php(295 linhas):github_get_config,github_save_config,github_api_request(HTTP client com curl, HTTPS enforcement, 15s timeout, API version 2022-11-28),github_api_get/github_api_call(authenticated helpers),github_get_auth_url(OAuth authorize URL com state CSRF),github_exchange_code(code→token exchange + profile fetch + persist),github_list_repos(até100 repos com permissions.push, cache em DB),github_validate_token(validação via /user endpoint).includes/workflows.php(578 linhas):github_encrypt_secret(sodium_crypto_box_seal),github_set_repo_variable/github_set_scan_profile_remote(Actions variables → secrets fallback),github_put_repo_secret(PUT encrypted secret),github_push_security_workflow(commit/update .github/workflows/nexus-security.yml),github_detect_dependabot_ecosystems(23 markers de lockfiles/manifests: composer, npm, pip, gomod, bundler, cargo, mix, pub, maven, gradle),github_build_dependabot_yaml,github_install_repo_dependabot(auto-detect + commit dependabot.yml),github_is_nexus_source_repo(protection check),github_setup_repo(full setup: secrets + workflow + dependabot + scan profile),github_generate_workflow_yaml,github_delete_workflow,github_get_workflow_runs/github_rerun_workflow.includes/commits.php(183 linhas):github_get_branches,github_get_commits(paginado, com author filter),github_get_commit_details(file diffs, stats, verification),github_compare_commits,github_revert_commit.includes/prs.php(214 linhas):github_get_prs(open/closed/all com permission notice),github_get_pr_details(PR + files changed),github_ai_review_pr(prompt enterprise OWASP/NIST, sensitive file detection, 5-section report),github_merge_pr(merge/squash/rebase).includes/releases.php(144 linhas):github_get_releases(releases + tags),github_generate_release_notes(SemVer classification: feat/fix/sec/breaking),github_create_release.includes/security.php(352 linhas):github_get_security_alerts(Dependabot alerts + Secret Scanning alerts, contadores por severidade),github_ai_analyze_commits(DevSecOps audit engine: categorização feat/fix/sec/refactor/docs, risk score 10-95, conventional commits %, verified %, relatório 6 seções markdown),github_get_repo_health(5 checks ponderados: README, LICENSE, SECURITY.md, Dependabot, Branch Protection → scorecard 0-100).includes/purger.php(205 linhas):github_create_task_from_git,github_scan_sensitive_files(8 regex: .env, SSH keys, .pem/.pfx, cloud credentials JSON, wp-config, npmrc/pypirc, .htpasswd, SQL dumps),github_purge_file_from_branch(delete via GitHub API com commit message [SECURITY EXPUNGE]),github_get_history_purge_script(gera scripts bash para git-filter-repo e BFG Repo-Cleaner).includes/sync.php(264 linhas):github_get_nexus_projects,github_get_repo_mappings/github_save_repo_mappings(repo→NEXUS project mapping),github_auto_sync_all_repos(cronjob worker: sync Dependabot PRs + Security Alerts para Kanban, cria tasks com ref signatures para deduplicação),github_create_task_direct.views/script.php(926 linhas): Alpine.js plugin controllergitManagerPlugin(), state completo (repos, branches, commits, PRs, workflows, releases, security, health, tasks, mappings, purge), 25+ métodos async (apiCall, fetchRepos, fetchBranches, fetchCommits, viewCommitDetails, fetchPRs, openPRDetails, openAIReviewPR, submitMergePR, fetchWorkflowRuns, rerunWorkflow, fetchReleases, submitCreateRelease, fetchRepoHealth, installDependabot, analyzeWithAI, confirmRevert, saveConfig, disconnectAccount, scanSensitiveFiles, openPurgeModal, submitPurgeFile, triggerDevSecOpsSync), renderMarkdown com Marked.js + fallback custom, formatDiffPatch com syntax highlighting.views/subtabs/(8 arquivos): commits.php, prs.php, actions.php, releases.php, security.php, health.php, ai.php, config.php.views/modals/(7 arquivos): diff-modal.php, pr-modal.php, ai-review.php, pr-merge.php, release-modal.php, task-modal.php, purge-modal.php.tab.php(329 linhas): master view que inclui CSS de markdown body styles (tabelas, headings, blockquotes), incluimarked.min.jsCDN, carrega subtabs e modais, rendering do header com avatar do usuário GitHub.modals.php(500+ linhas): modal de configuração OAuth (Client ID/Secret, callback URL, disconnect/reconnect), guia GitHub App (6 passos visuais).lang.json(22K): i18n PT/EN/ES extenso para todas as features, abas, modais, mensagens de erro e configurações.fastr.json(2.8K): slash commands/github(abrir GitHub Manager),/git-commits(ver commits),/git-ai(análise IA),/git-health(health score),/git-prs(listar PRs),/git-release(gerar release).cronjob.json: jobgithub_manager_dependabot_sync— auto-sync Dependabot & CVEs para Kanban (frequência configurável).doc.md(157 linhas): guia passo a passo de configuração do GitHub App (14 etapas, PT).icon.svg: ícone GitHub (Octocat).
Andamento no GitHub (issues)
Painel em tempo real com as issues mais recentes do repositório.
live feed
abrir issues no githubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Resultados reais
Plugin DevSecOps completo para o GitHub: OAuth App com anti-CSRF, repositórios, commits com diff, Pull Requests com Code Review por IA, CI/CD (GitHub Actions), Releases SemVer com geração de notes, Dependabot installer, alertas de vulnerabilidade, Health Scorecard com 10 dimensões, scanner de arquivos sensíveis, expurgo de histórico git (git-filter-repo/BFG) e cronjob de sincronização automática de PRs e CVEs no Kanban do NEXUS — tudo em uma interface slate com 8 abas e i18n completo.
Arquitetura e organização
- PHP 8
- MySQL 8
- OAuth 2.0
- libsodium
- Alpine.js
- Marked.js
- i18n
- GitHub REST API v2022-11-28
Execução e operação
O projeto segue fluxo reprodutível de execução com validação técnica em ambiente de produção/similar.
Screenshots
Falar sobre este projeto
Aplique este modelo no seu ambiente e acelere a entrega com consistência técnica.
