Cover image for project: Nexus Aikido Integration IN PROGRESS

Technical summary

NEXUS plugin (Security category) that integrates the Aikido REST API: while functions live in the Inngest app, the NEXUS plugin here consumes the Aikido API (OAuth2 client_credentials) to list open issue groups (/open-issue-groups), map which already have a NEXUS task (SELECT ... FROM tasks WHERE title = ?) and import them as tasks with priority derived from severity. It follows the principle that the workflow/CI is the source of truth — Aikido is the source, NEXUS is the sink that materializes issues into the backlog.

Executed scope

  • backend.php backend (376 lines): aikido_get_config()/aikido_save_config() in DB::getConfig('plugin.aikido.config') with client_id, client_secret, region (eu/us/me, default eu), default_project (validated via project_find_by_name); no dedicated tables (config + history in admin_configs).
  • OAuth2 (aikido_get_auth_token): Authorization: Basic base64(client_id:client_secret), grant_type=client_credentials — 3 token endpoints per region.
  • REST (aikido_call_api): Bearer <token>, base /api/public/v1 (3 regions), 15s timeout, CURLOPT_SSL_VERIFYPEER=true.
  • aikido_test_connection: GET /workspace → workspace name + plan.
  • aikido_fetch_issues: GET /open-issue-groups?per_page=100 → issue groups with an nx_task flag (task already exists).
  • aikido_import_issue: GET /issues/groups/{id} (fallback /issues/{id}), title [Aikido] Vulnerabilidade: … (duplicate match), severity → priority: critical=4 / high=3 / medium=2 / others=1; rich description (rule, type, score, file, package, CVE, locations, lines, commit, "💡 How to fix"); task_create on the default project; back-link via POST /task_tracking/linkTaskToIssueGroup (best-effort).
  • aikido_cron_check: soft-cron with 1h throttle (plugin.aikido.last_cron.ts), imports up to 3 critical/high without a task; stores {ts, at, imported, fetch_ok}.
  • API: 5 actions via PluginManager::registerApiAction — aikido_get_config, aikido_save_config, aikido_test_connection, aikido_fetch_issues, aikido_import_issue (session/Bearer + CSRF).
  • Alpine.js UI (tab.php 397 lines + modals.php 314 lines): "Aikido Security" header with workspace badge, 5 filterable stat cards (Total/Critical/High/Medium/Imported), search + type filter (sast/open_source/cloud/surface_monitoring/leaked_secret/iac), 7-column table (vuln, type, severity+score, repo/domain, NEXUS status, action), toast feedback, config/help modals.
  • cors.php: origins app.aikido.dev/api.aikido.dev on the api endpoint — consumed by NEXUS CORS.
  • cronjob.json + cli.php: job aikido_import (tick) and CLI for on-demand runs.

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (config/history in admin_configs; tasks in core tasks)
  • Alpine.js + Tailwind CSS (premium light)
  • NEXUS plugin system (PluginManager)
  • cURL → Aikido public API (OAuth2 + Bearer)

Operational tags

  • Aikido
  • Security
  • Vulnerabilities
  • SAST
  • SCA
  • DevOps

Operational outcome

  • Closed issues→tasks pipeline: Aikido open issue groups become NEXUS backlog tasks with correct priority (critical=4, high=3, medium=2) — surfacing what matters.
  • Deduplication by title ([Aikido] Vulnerabilidade: …) prevents duplicate tasks; the bidirectional link (NEXUS→Aikido) tracks status in the Aikido app.
  • Automatic sync via cronjob (≤3 critical/high per hour, 1h throttle) + CLI for on-demand — no manual action.
  • Secret safety: OAuth2 client_credentials, HTTPS enforced (CURLOPT_SSL_VERIFYPEER), and the task↔issue link is best-effort (exposes only what Aikido allows).
  • NEXUS CORS integration: declares cors.php for app.aikido.dev/api.aikido.dev, applicable with one click via the CORS plugin.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that integrates the Aikido REST API for vulnerability lookup and issue-to-task import — with OAuth2 client_credentials, open issue groups, severity→priority and periodic sync (cron/CLI).

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.