IN PROGRESS
Technical summary
NEXUS plugin that centralizes post-push findings from scanners, SBOM, Dependency-Track, domains and CI/CD repositories. Imports normalize evidence, deduplicate or reopen tasks and feed Compliance Hub; the panel also correlates CVEs, manages scan profiles and workflows, and sends critical alerts.
Executed scope
plugin.json— v1.3.0, NEXUS category, lucideshield-alerticon withicon_bg #fff1f2, ownicon.svg(scan magnifier) andstyle: design.css.- Registrations:
registerTab("security", "Security Scanner", "shield-alert", tab.php, "NEXUS"),registerDoc(...),registerModal("security-modals", modals.php)andregisterJs("nexus-security-scanner", "/plugins/nexus-security-scanner/assets/security.js"). - 37 API actions (
plugin.php, viaPluginManager::registerApiAction) — 14 imports (security_import_trivy|grype|semgrep|codeql|mobsf|qark|nuclei|wordfence|gitleaks|zap|composer|npm|sbom|dtrack), SBOM (security_sbom_list/get), DTrack (security_dtrack_sync/dashboard/save_config), CVE (security_cve_details), domains (security_scan_domain|save_domain|get_domains|delete_domain), repos (security_save_repo|get_repos|delete_repo), profiles (security_get_scan_profiles|set_scan_profile), workflows (security_get_workflow_statuses|trigger_workflow), CI health (security_get_ci_health|inspect_repo_ci|sync_repo_workflow|install_repo_dependabot|sync_outdated_workflows), alerts (security_notify_critical). - Persistence: no own tables — findings become NEXUS tasks (
security_manage_task: title dedupe, reopen of done/cancelled,project_resolve_for_task) and evidence inplugin.compliance.ci_evidence; domains inplugin.security.domains, repos inplugin.security.repos, SBOM inplugin.security.sbom, DTrack inplugin.security.dtrack(DB config). - Imports:
security_process_trivy_scan(37-249),grype(249-405),semgrep(405-632),codeql(632-843),mobsf(893-1106),qark(1106-1262),nuclei(1262-1442),wordfence(1820-1965),gitleaks(1965-2126),zap(2126-2280),composer(2280-2398),npm(2398-2532),sbom(3924-4092),dtrack(4303-4495) — each normalizes upload/body, resolves the project and creates/reopens tasks. - Compliance:
security_import_with_compliance→security_finding_to_controls(MITRE + NIST/ISO map per scanner) →security_record_compliance_evidence(Hub evidence; SBOM creates no per-package task). - SBOM:
security_process_sbom_scan— CycloneDX preferred/SPDX fallback, purl → ecosystem, per-repo inventory inplugin.security.sbom;security_sbom_list/get(detail + packages by?repo=owner/name). - Dependency-Track: local Docker stack (API
127.0.0.1:9080, UI 9081;bootstrap-api-key.sh→plugin.security.dtrack); NEW_VULNERABILITY/POLICY webhook →[DTrack] CVE — pkgtasks;security_dtrack_sync(CI evidence); dashboard with stats/syncs/alerts/masked config. - CodeQL: dual visibility —
codeql-action/upload-sarif@v3to GitHub Security Tab +security_import_codeqlcreates/updates[CodeQL] …tasks. - Mobile:
nexus-mobile-scan.ymlworkflow (detectjob with path filter — Manifest/Gradle Android/iOS/artifact) → only then MobSF/QARK (no APK/IPA or non-mobile repo → skipped). DocsMOBSF.md/QARK.md. - GitHub OAuth: GitHub plugin authorizes repos/workflows; callbacks by
SITE_URL(labhttp://127.0.0.1:8088;LOCAL_DEV_F_IA.mddocs). - Domains:
security_audit_domain— headers/SSL/CORS;/trivy <domain|IP>slash via fastr.json (security_scan_domain). - Intel:
security_scanner_intel_enrich(priority 46,cvetype) — local correlation with tasks/findings (no external API in the hub). - Alerts:
security_notify_critical—notify_security_critical(email, dashboard, Discord/Slack, optional Novu); used by thenotify-criticaljob. - CI health:
security_get_ci_health/inspect_repo_ci— compares remote workflow vs local template (action pins, template version/fingerprint), workflow sync, Dependabot, billing block detection. - Alpine.js UI (
tab.php116 KB): 4 sub-tabs (Domains, CI/CD Repositories, SBOM, Dependency-Track), per-scanner import selector, metric cards and premium toolbar.
Stack and tools
- PHP 8 (no framework) + MySQL 8 (NEXUS tasks + DB config — no plugin tables)
- Alpine.js + Tailwind CSS (
tab.php) + modals (modals.php) + registered JS (assets/security.js) - GitHub Actions (
nexus-security.yml— per-scanner import jobs +notify-critical;nexus-mobile-scan.yml— MobSF/QARK) - GitHub API (GitHub plugin OAuth) — workflows, CI health, Dependabot
- Scanners: Trivy, Grype, Semgrep, CodeQL, Nuclei, Wordfence, Gitleaks, ZAP, Composer, npm, Syft (SBOM), MobSF, QARK
- Dependency-Track (local Docker) + Compliance Hub (NIST/ISO evidence) + Intelligence Hub (CVE enricher)
Operational tags
- Security Scanner
- Trivy
- SBOM
- Dependency-Track
- MobSF
- QARK
- CodeQL
- Domains
- NEXUS Plugin
Operational result
- 14 scanner imports with normalization, per-repo project auto-mapping and conversion into NEXUS tasks with title dedupe (reopens
done/cancelledwhen the vulnerability resurfaces). - Automatic compliance evidence: each import appends MITRE + NIST/ISO controls to the Compliance Hub (
plugin.compliance.ci_evidence) — no MITRE task flood per finding. - SBOM (CycloneDX/SPDX) inventoried per repository with purl → ecosystem; Dependency-Track receives the SBOM via CI and the continuous webhook creates/reopens
[DTrack] CVE — pkgtasks. - CodeQL with dual visibility: results in the GitHub Security Tab and as
[CodeQL]tasks in NEXUS; mobile via MobSF/QARK with path filter (only mobile repos/artifacts are scanned). - CVEs cited in tasks/comments are correlated with local findings by the Intelligence Hub enricher — severity by open tasks, no external call.
- Domains audited (headers/SSL/CORS) via the
/trivyslash; CI health compares workflows with the template (pins/version) and syncs, plus Dependabot installation. - CRITICAL alerts from CI (
notify-criticaljob) by email/dashboard/Discord/Slack/Novu. - Complementary to Security Gate: Scanner is the post-push layer (CI/import,
security_*); Gate is the pre-push layer (local hooks,gate_*).
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Comprehensive post-push security and DevSecOps orchestrator for GitHub repositories. Consolidates multi-scanner findings (Trivy, Grype, Semgrep, CodeQL, MobSF, Nuclei, Gitleaks, OWASP ZAP), manages SBOM inventories with Syft, integrates continuous CVE monitoring via Dependency-Track, and audits domain surfaces and CI/CD.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- GitHub Actions
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.