Cover image for project: GitHub Manager IN PROGRESS

Technical summary

DevSecOps manager for GitHub with OAuth App (anti-CSRF). Modular backend: client (config/token/repos), workflows (Actions, libsodium Secrets, Dependabot with 23 ecosystem markers), commits (diffs/revert), PRs (AI Code Review/merge), releases (SemVer notes), security (Dependabot+Secret Scanning, commit audit with risk score, Health Scorecard), purger (8-regex sensitive file scanner, git-filter-repo/BFG), sync (cronjob auto-sync PRs and CVEs into Kanban). Alpine.js 8-tab interface, Marked.js, i18n, 3 Fastr slash commands.

Executed scope

  • plugin.php (320 lines): "GitHub Manager" tab under "Development" with github icon, doc, configuration modal, 20+ API actions (github_get_config, github_save_config, github_revoke_token, github_disconnect, github_callback, github_user, github_list_repos, github_commits, github_commit_detail, github_diff, github_revert_commit, github_get_prs, github_pr_detail, github_create_pr, github_merge_pr, github_review_pr, github_actions, github_create_workflow_dispatch, github_secrets, github_set_secret, github_set_variable, github_install_dependabot, github_releases, github_create_release, github_tags, github_security_alerts, github_health_score, github_ai_analyze, github_purge_secrets, github_sync_all).
  • backend.php (24 lines): master controller loading 8 modules from /includes/.
  • includes/client.php (295 lines): github_get_config, github_save_config, github_api_request (HTTP client with curl, HTTPS enforcement, 15s timeout, API version 2022-11-28), github_api_get/github_api_call (authenticated helpers), github_get_auth_url (OAuth authorize URL with CSRF state), github_exchange_code (code→token exchange + profile fetch + persist), github_list_repos (up to100 repos with permissions.push, DB cache), github_validate_token (validation via /user endpoint).
  • includes/workflows.php (578 lines): github_encrypt_secret (sodium_crypto_box_seal), github_set_repo_variable/github_set_scan_profile_remote (Actions variables → secrets fallback), github_put_repo_secret (PUT encrypted secret), github_push_security_workflow (commit/update .github/workflows/nexus-security.yml), github_detect_dependabot_ecosystems (23 lockfile/manifest markers: composer, npm, pip, gomod, bundler, cargo, mix, pub, maven, gradle), github_build_dependabot_yaml, github_install_repo_dependabot (auto-detect + commit dependabot.yml), github_is_nexus_source_repo (protection check), github_setup_repo (full setup: secrets + workflow + dependabot + scan profile), github_generate_workflow_yaml, github_delete_workflow, github_get_workflow_runs/github_rerun_workflow.
  • includes/commits.php (183 lines): github_get_branches, github_get_commits (paginated, author filter), github_get_commit_details (file diffs, stats, verification), github_compare_commits, github_revert_commit.
  • includes/prs.php (214 lines): github_get_prs (open/closed/all with permission notice), github_get_pr_details (PR + files changed), github_ai_review_pr (enterprise OWASP/NIST prompt, sensitive file detection, 5-section report), github_merge_pr (merge/squash/rebase).
  • includes/releases.php (144 lines): github_get_releases (releases + tags), github_generate_release_notes (SemVer classification: feat/fix/sec/breaking), github_create_release.
  • includes/security.php (352 lines): github_get_security_alerts (Dependabot + Secret Scanning alerts, severity counters), github_ai_analyze_commits (DevSecOps audit engine: feat/fix/sec/refactor/docs categorization, risk score 10-95, conventional commits %, verified %, 6-section markdown report), github_get_repo_health (5 weighted checks: README, LICENSE, SECURITY.md, Dependabot, Branch Protection → scorecard 0-100).
  • includes/purger.php (205 lines): github_create_task_from_git, github_scan_sensitive_files (8 regex: .env, SSH keys, .pem/.pfx, cloud credentials JSON, wp-config, npmrc/pypirc, .htpasswd, SQL dumps), github_purge_file_from_branch (delete via GitHub API with [SECURITY EXPUNGE] commit message), github_get_history_purge_script (generates bash scripts for git-filter-repo and BFG Repo-Cleaner).
  • includes/sync.php (264 lines): github_get_nexus_projects, github_get_repo_mappings/github_save_repo_mappings (repo→NEXUS project mapping), github_auto_sync_all_repos (cronjob worker: sync Dependabot PRs + Security Alerts to Kanban, creates tasks with ref signatures for deduplication), github_create_task_direct.
  • views/script.php (926 lines): Alpine.js plugin controller gitManagerPlugin(), full state (repos, branches, commits, PRs, workflows, releases, security, health, tasks, mappings, purge), 25+ async methods (apiCall, fetchRepos, fetchBranches, fetchCommits, viewCommitDetails, fetchPRs, openPRDetails, openAIReviewPR, submitMergePR, fetchWorkflowRuns, rerunWorkflow, fetchReleases, submitCreateRelease, fetchRepoHealth, installDependabot, analyzeWithAI, confirmRevert, saveConfig, disconnectAccount, scanSensitiveFiles, openPurgeModal, submitPurgeFile, triggerDevSecOpsSync), renderMarkdown with Marked.js + custom fallback, formatDiffPatch with syntax highlighting.
  • views/subtabs/ (8 files): commits.php, prs.php, actions.php, releases.php, security.php, health.php, ai.php, config.php.
  • views/modals/ (7 files): diff-modal.php, pr-modal.php, ai-review.php, pr-merge.php, release-modal.php, task-modal.php, purge-modal.php.
  • tab.php (329 lines): master view including markdown body CSS styles (tables, headings, blockquotes), includes marked.min.js CDN, loads subtabs and modals, GitHub user avatar header rendering.
  • modals.php (500+ lines): OAuth configuration modal (Client ID/Secret, callback URL, disconnect/reconnect), GitHub App guide (6 visual steps).
  • lang.json (22K): PT/EN/ES i18n for all features, tabs, modals, error messages and configurations.
  • fastr.json (2.8K): slash commands /github (open GitHub Manager), /git-commits (view commits), /git-ai (AI analysis), /git-health (health score), /git-prs (list PRs), /git-release (generate release).
  • cronjob.json: github_manager_dependabot_sync job — auto-sync Dependabot & CVEs to Kanban (configurable frequency).
  • doc.md (157 lines): step-by-step GitHub App configuration guide (14 steps, PT).
  • icon.svg: GitHub brand icon (Octocat).

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Full-featured DevSecOps plugin for GitHub: OAuth App with anti-CSRF, repository management, commits with diffs, Pull Requests with AI Code Review, CI/CD (GitHub Actions), SemVer Releases with notes generation, Dependabot installer, vulnerability alerts, 10-dimension Health Scorecard, sensitive file scanner, git history purger (git-filter-repo/BFG) and automated cronjob for syncing PRs and CVEs into the NEXUS Kanban — all in a slate 8-tab UI with full i18n.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.