Imagem de capa do projeto: GitHub Manager EM ANDAMENTO

Resumo técnico

Gerenciador DevSecOps para GitHub com OAuth App (anti-CSRF). Backend modular: client (config/token/repos), workflows (Actions, Secrets libsodium, Dependabot com detecção 23 ecossistemas), commits (diffs/revert), PRs (AI Code Review/merge), releases (SemVer notes), security (Dependabot+Secret Scanning, commit audit com risk score, Health Scorecard), purger (scanner 8 regex, git-filter-repo/BFG), sync (cronjob auto-sync PRs e CVEs no Kanban). Interface Alpine.js 8 abas, Marked.js, i18n, 3 slash commands Fastr.

Escopo executado

  • plugin.php (320 linhas): aba "GitHub Manager" em "Development" com ícone github, doc, modal de configuração, 20+ ações de API (github_get_config, github_save_config, github_revoke_token, github_disconnect, github_callback, github_user, github_list_repos, github_commits, github_commit_detail, github_diff, github_revert_commit, github_get_prs, github_pr_detail, github_create_pr, github_merge_pr, github_review_pr, github_actions, github_create_workflow_dispatch, github_secrets, github_set_secret, github_set_variable, github_install_dependabot, github_releases, github_create_release, github_tags, github_security_alerts, github_health_score, github_ai_analyze, github_purge_secrets, github_sync_all).
  • backend.php (24 linhas): master controller que carrega 8 módulos de /includes/.
  • includes/client.php (295 linhas): github_get_config, github_save_config, github_api_request (HTTP client com curl, HTTPS enforcement, 15s timeout, API version 2022-11-28), github_api_get/github_api_call (authenticated helpers), github_get_auth_url (OAuth authorize URL com state CSRF), github_exchange_code (code→token exchange + profile fetch + persist), github_list_repos (até100 repos com permissions.push, cache em DB), github_validate_token (validação via /user endpoint).
  • includes/workflows.php (578 linhas): github_encrypt_secret (sodium_crypto_box_seal), github_set_repo_variable/github_set_scan_profile_remote (Actions variables → secrets fallback), github_put_repo_secret (PUT encrypted secret), github_push_security_workflow (commit/update .github/workflows/nexus-security.yml), github_detect_dependabot_ecosystems (23 markers de lockfiles/manifests: composer, npm, pip, gomod, bundler, cargo, mix, pub, maven, gradle), github_build_dependabot_yaml, github_install_repo_dependabot (auto-detect + commit dependabot.yml), github_is_nexus_source_repo (protection check), github_setup_repo (full setup: secrets + workflow + dependabot + scan profile), github_generate_workflow_yaml, github_delete_workflow, github_get_workflow_runs/github_rerun_workflow.
  • includes/commits.php (183 linhas): github_get_branches, github_get_commits (paginado, com author filter), github_get_commit_details (file diffs, stats, verification), github_compare_commits, github_revert_commit.
  • includes/prs.php (214 linhas): github_get_prs (open/closed/all com permission notice), github_get_pr_details (PR + files changed), github_ai_review_pr (prompt enterprise OWASP/NIST, sensitive file detection, 5-section report), github_merge_pr (merge/squash/rebase).
  • includes/releases.php (144 linhas): github_get_releases (releases + tags), github_generate_release_notes (SemVer classification: feat/fix/sec/breaking), github_create_release.
  • includes/security.php (352 linhas): github_get_security_alerts (Dependabot alerts + Secret Scanning alerts, contadores por severidade), github_ai_analyze_commits (DevSecOps audit engine: categorização feat/fix/sec/refactor/docs, risk score 10-95, conventional commits %, verified %, relatório 6 seções markdown), github_get_repo_health (5 checks ponderados: README, LICENSE, SECURITY.md, Dependabot, Branch Protection → scorecard 0-100).
  • includes/purger.php (205 linhas): github_create_task_from_git, github_scan_sensitive_files (8 regex: .env, SSH keys, .pem/.pfx, cloud credentials JSON, wp-config, npmrc/pypirc, .htpasswd, SQL dumps), github_purge_file_from_branch (delete via GitHub API com commit message [SECURITY EXPUNGE]), github_get_history_purge_script (gera scripts bash para git-filter-repo e BFG Repo-Cleaner).
  • includes/sync.php (264 linhas): github_get_nexus_projects, github_get_repo_mappings/github_save_repo_mappings (repo→NEXUS project mapping), github_auto_sync_all_repos (cronjob worker: sync Dependabot PRs + Security Alerts para Kanban, cria tasks com ref signatures para deduplicação), github_create_task_direct.
  • views/script.php (926 linhas): Alpine.js plugin controller gitManagerPlugin(), state completo (repos, branches, commits, PRs, workflows, releases, security, health, tasks, mappings, purge), 25+ métodos async (apiCall, fetchRepos, fetchBranches, fetchCommits, viewCommitDetails, fetchPRs, openPRDetails, openAIReviewPR, submitMergePR, fetchWorkflowRuns, rerunWorkflow, fetchReleases, submitCreateRelease, fetchRepoHealth, installDependabot, analyzeWithAI, confirmRevert, saveConfig, disconnectAccount, scanSensitiveFiles, openPurgeModal, submitPurgeFile, triggerDevSecOpsSync), renderMarkdown com Marked.js + fallback custom, formatDiffPatch com syntax highlighting.
  • views/subtabs/ (8 arquivos): commits.php, prs.php, actions.php, releases.php, security.php, health.php, ai.php, config.php.
  • views/modals/ (7 arquivos): diff-modal.php, pr-modal.php, ai-review.php, pr-merge.php, release-modal.php, task-modal.php, purge-modal.php.
  • tab.php (329 linhas): master view que inclui CSS de markdown body styles (tabelas, headings, blockquotes), inclui marked.min.js CDN, carrega subtabs e modais, rendering do header com avatar do usuário GitHub.
  • modals.php (500+ linhas): modal de configuração OAuth (Client ID/Secret, callback URL, disconnect/reconnect), guia GitHub App (6 passos visuais).
  • lang.json (22K): i18n PT/EN/ES extenso para todas as features, abas, modais, mensagens de erro e configurações.
  • fastr.json (2.8K): slash commands /github (abrir GitHub Manager), /git-commits (ver commits), /git-ai (análise IA), /git-health (health score), /git-prs (listar PRs), /git-release (gerar release).
  • cronjob.json: job github_manager_dependabot_sync — auto-sync Dependabot & CVEs para Kanban (frequência configurável).
  • doc.md (157 linhas): guia passo a passo de configuração do GitHub App (14 etapas, PT).
  • icon.svg: ícone GitHub (Octocat).

Andamento no GitHub (issues)

Painel em tempo real com as issues mais recentes do repositório.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Resultados reais

Plugin DevSecOps completo para o GitHub: OAuth App com anti-CSRF, repositórios, commits com diff, Pull Requests com Code Review por IA, CI/CD (GitHub Actions), Releases SemVer com geração de notes, Dependabot installer, alertas de vulnerabilidade, Health Scorecard com 10 dimensões, scanner de arquivos sensíveis, expurgo de histórico git (git-filter-repo/BFG) e cronjob de sincronização automática de PRs e CVEs no Kanban do NEXUS — tudo em uma interface slate com 8 abas e i18n completo.

Arquitetura e organização

Execução e operação

O projeto segue fluxo reprodutível de execução com validação técnica em ambiente de produção/similar.

Screenshots

Falar sobre este projeto

Aplique este modelo no seu ambiente e acelere a entrega com consistência técnica.