IN PROGRESS
Technical summary
NEXUS plugin (Security category) that integrates the Aikido REST API: while functions live in the Inngest app, the NEXUS plugin here consumes the Aikido API (OAuth2 client_credentials) to list open issue groups (/open-issue-groups), map which already have a NEXUS task (SELECT ... FROM tasks WHERE title = ?) and import them as tasks with priority derived from severity. It follows the principle that the workflow/CI is the source of truth — Aikido is the source, NEXUS is the sink that materializes issues into the backlog.
Executed scope
backend.phpbackend (376 lines):aikido_get_config()/aikido_save_config()inDB::getConfig('plugin.aikido.config')withclient_id,client_secret,region(eu/us/me, default eu),default_project(validated viaproject_find_by_name); no dedicated tables (config + history inadmin_configs).- OAuth2 (
aikido_get_auth_token):Authorization: Basic base64(client_id:client_secret),grant_type=client_credentials— 3 token endpoints per region. - REST (
aikido_call_api):Bearer <token>, base/api/public/v1(3 regions), 15s timeout,CURLOPT_SSL_VERIFYPEER=true. aikido_test_connection:GET /workspace→ workspace name + plan.aikido_fetch_issues:GET /open-issue-groups?per_page=100→ issue groups with annx_taskflag (task already exists).aikido_import_issue:GET /issues/groups/{id}(fallback/issues/{id}), title[Aikido] Vulnerabilidade: …(duplicate match), severity → priority: critical=4 / high=3 / medium=2 / others=1; rich description (rule, type, score, file, package, CVE, locations, lines, commit, "💡 How to fix");task_createon the default project; back-link viaPOST /task_tracking/linkTaskToIssueGroup(best-effort).aikido_cron_check: soft-cron with 1h throttle (plugin.aikido.last_cron.ts), imports up to 3critical/highwithout a task; stores{ts, at, imported, fetch_ok}.- API: 5 actions via
PluginManager::registerApiAction—aikido_get_config,aikido_save_config,aikido_test_connection,aikido_fetch_issues,aikido_import_issue(session/Bearer + CSRF). - Alpine.js UI (
tab.php397 lines +modals.php314 lines): "Aikido Security" header with workspace badge, 5 filterable stat cards (Total/Critical/High/Medium/Imported), search + type filter (sast/open_source/cloud/surface_monitoring/leaked_secret/iac), 7-column table (vuln, type, severity+score, repo/domain, NEXUS status, action), toast feedback, config/help modals. cors.php: originsapp.aikido.dev/api.aikido.devon the api endpoint — consumed by NEXUS CORS.cronjob.json+cli.php: jobaikido_import(tick) and CLI for on-demand runs.
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (config/history in
admin_configs; tasks in coretasks) - Alpine.js + Tailwind CSS (premium light)
- NEXUS plugin system (
PluginManager) - cURL → Aikido public API (OAuth2 + Bearer)
Operational tags
- Aikido
- Security
- Vulnerabilities
- SAST
- SCA
- DevOps
Operational outcome
- Closed issues→tasks pipeline: Aikido open issue groups become NEXUS backlog tasks with correct priority (critical=4, high=3, medium=2) — surfacing what matters.
- Deduplication by title (
[Aikido] Vulnerabilidade: …) prevents duplicate tasks; the bidirectional link (NEXUS→Aikido) tracks status in the Aikido app. - Automatic sync via cronjob (≤3 critical/high per hour, 1h throttle) + CLI for on-demand — no manual action.
- Secret safety: OAuth2 client_credentials, HTTPS enforced (
CURLOPT_SSL_VERIFYPEER), and the task↔issue link is best-effort (exposes only what Aikido allows). - NEXUS CORS integration: declares
cors.phpforapp.aikido.dev/api.aikido.dev, applicable with one click via the CORS plugin.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that integrates the Aikido REST API for vulnerability lookup and issue-to-task import — with OAuth2 client_credentials, open issue groups, severity→priority and periodic sync (cron/CLI).
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.