Cover image for project: NEXUS Bugcrowd IN PROGRESS

Technical summary

NEXUS plugin integrating Bugcrowd for bug bounty: submissions are ingested via HMAC-SHA256-digest webhooks (X-Bugcrowd-Digest) and become tasks with severity-derived priority (P1=4 → P4=1); a program → project map routes each submission, NEXUS comments sync back to the submission and the Intelligence Hub enriches tasks with severity, state and Bugcrowd link — with automatic migration from legacy identities (bugcrowdnd/bugcrowd-company) to the canonical bugcrowd slug.

Executed scope

  • Identity: canonical slug bugcrowd (folder plugins/bugcrowd/); legacy_slugs: [bugcrowdnd, bugcrowd-company]; canonical bugcrowd_* actions with bugcrowdnd_* aliases kept for legacy integrations; fastr /bugcrowd (canonical) + /bugcrowdnd (legacy alias).
  • Backend backend.php (1071 lines): bugcrowd_get_config()/bugcrowd_save_config() in DB::getConfig('plugin.bugcrowd') with webhook_secret, access_key, secret_key, public_base_url, default_project ('Geral'), program_map (program_code/UUID → NEXUS project), sync_comments, comment_visibility (everyone|bugcrowd_and_customer), enrich_tasks, auto_close_on_closed, api_version (2025-01-01).
  • Automatic migration (bugcrowd_migrate_legacy()): idempotent — migrates config from plugin.bugcrowd-company/plugin.bugcrowd into plugin.bugcrowd; promotes tables bugcrowd_company_submissions/bugcrowd_submissions/bugcrowdnd_submissions → bugcrowd_submissions (RENAME + INSERT IGNORE) and the matching webhook log; validates SQL identifiers and compatible columns before migrating.
  • Webhook: bugcrowd_verify_signature() validates X-Bugcrowd-Digest = HMAC-SHA256(secret, raw_body + timestamp) via hash_equals; events submission.created, submission.updated, comments and ping/test; public URL public_base_url + /api.php?action=bugcrowd_webhook; full audit in bugcrowd_webhook_log.
  • Severity → priority: bugcrowd_severity_to_priority() — P1/Critical=4, P2/High=3, P3/Medium=2, P4/others=1; auto_close_on_closed marks the task done (closed/resolved/informational) and triaged/unresolved/new becomes in_progress.
  • Task create/update: submission.created creates a task ([Bugcrowd] <id> — <title>, markdown description with ID/program/event/title/severity/state/VRT) + API enrich; submission.updated updates priority/status and comments the changes diff.
  • NEXUS → Bugcrowd comment sync: bugcrowd_on_comment_created (filter comment_created) POSTs /submissions/{id}/comments with body_markdown + visibility_scope; ignores system/status/status_change/attachment comments and bugcrowd/system authors (anti-loop).
  • Program → project map: bugcrowd_resolve_project() (code|id|name → project; default_project fallback).
  • API client: bugcrowd_api_request() (cURL) with Accept: application/vnd.bugcrowd+json, Authorization: Token <access_key>:<secret_key>, Bugcrowd-Version and 25s timeout (8s connect); base api.bugcrowd.com.
  • Intelligence Hub: bugcrowd enricher (['url','domain','_task'], priority 38) — _task: signal sid · P{sev} · {state} with scores P1=90/P2=75/P3=55/P4=30; url/domain on *.bugcrowd.com hosts → linked/unlinked (extracts /submissions/{id}).
  • Lookup/refresh: bugcrowd_lookup (submission_id or URL → local link + fresh API) and bugcrowd_refresh (GET /submissions/{id} → create/update with manual.refresh event).
  • API: 9 actions via PluginManager::registerApiAction (bugcrowd_webhook, bugcrowd_settings/_save, bugcrowd_stats, bugcrowd_links, bugcrowd_test, bugcrowd_lookup, bugcrowd_refresh, bugcrowd_post_comment) — public webhook + digest; others session + CSRF.
  • Own i18n: lang.json (226 lines, pt_BR/en_US) via nexusRegisterPluginI18n + nx_load_dictionary (window.t / __()).
  • Alpine.js UI (tab.php, 389 lines, orange-600 theme): Webhook OK/API OK badges, 4 KPI cards (Linked/Events today/Webhook/API Token), Submissions tab (ID, program, severity, state, task link) + Config tab (webhook URL with copy + secret, Public Base URL, NEXUS project picker, Access/Secret Key, Bugcrowd-Version, Test API, dynamic program→project map rows, sync/enrich/auto-close toggles, comment visibility, "How to get the API Key" guide).
  • Tables: bugcrowd_submissions (PK submission_id, UNIQUE task_id, indexes program_code/updated_at) and bugcrowd_webhook_log (event_type, submission_id, ok, message; indexes created_at/submission_id).
  • No cronjob.json — event-driven plugin (webhooks), no continuous polling (Bugcrowd API limits ~60 req/min).

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (config in admin_configs; bugcrowd_submissions + bugcrowd_webhook_log)
  • Alpine.js + Tailwind CSS (premium light, orange ring)
  • NEXUS plugin system (PluginManager)
  • cURL → Bugcrowd API (Token auth + HMAC-SHA256 webhooks)

Operational tags

  • Bugcrowd
  • Bug Bounty
  • Security
  • Webhooks
  • REST API
  • Intelligence Hub

Operational outcome

  • Closed bugcrowd → NEXUS loop: submissions ingested via webhook (HMAC-SHA256 digest verified) become backlog tasks with correct priority; closed/resolved state marks the task done.
  • Bidirectional comment sync: NEXUS comments become comments on the Bugcrowd submission (configurable visibility) with no loop from Bugcrowd authors.
  • Per-program routing: each submission lands in the mapped NEXUS project (program code/UUID), falling back to the default project.
  • Contextual Intelligence Hub: linked tasks show severity, score, state and submission link; app.bugcrowd.com/submissions/* URLs are detected as references.
  • Full audit trail: every delivery and event is logged (bugcrowd_webhook_log).
  • Transparent migration: legacy installs (bugcrowdnd/bugcrowd-company) are idempotently migrated to the canonical bugcrowd slug, with aliases kept.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin integrating Bugcrowd for bug bounty: submissions ingested via HMAC-SHA256 webhooks (X-Bugcrowd-Digest) become tasks with severity-based priority, with program→project mapping, bidirectional comment sync, Intelligence Hub enrichment and automatic legacy migration.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.