IN PROGRESS
Technical summary
DevSecOps manager for GitHub with OAuth App (anti-CSRF). Modular backend: client (config/token/repos), workflows (Actions, libsodium Secrets, Dependabot with 23 ecosystem markers), commits (diffs/revert), PRs (AI Code Review/merge), releases (SemVer notes), security (Dependabot+Secret Scanning, commit audit with risk score, Health Scorecard), purger (8-regex sensitive file scanner, git-filter-repo/BFG), sync (cronjob auto-sync PRs and CVEs into Kanban). Alpine.js 8-tab interface, Marked.js, i18n, 3 Fastr slash commands.
Executed scope
plugin.php(320 lines): "GitHub Manager" tab under "Development" withgithubicon, doc, configuration modal, 20+ API actions (github_get_config, github_save_config, github_revoke_token, github_disconnect, github_callback, github_user, github_list_repos, github_commits, github_commit_detail, github_diff, github_revert_commit, github_get_prs, github_pr_detail, github_create_pr, github_merge_pr, github_review_pr, github_actions, github_create_workflow_dispatch, github_secrets, github_set_secret, github_set_variable, github_install_dependabot, github_releases, github_create_release, github_tags, github_security_alerts, github_health_score, github_ai_analyze, github_purge_secrets, github_sync_all).backend.php(24 lines): master controller loading 8 modules from/includes/.includes/client.php(295 lines):github_get_config,github_save_config,github_api_request(HTTP client with curl, HTTPS enforcement, 15s timeout, API version 2022-11-28),github_api_get/github_api_call(authenticated helpers),github_get_auth_url(OAuth authorize URL with CSRF state),github_exchange_code(code→token exchange + profile fetch + persist),github_list_repos(up to100 repos with permissions.push, DB cache),github_validate_token(validation via /user endpoint).includes/workflows.php(578 lines):github_encrypt_secret(sodium_crypto_box_seal),github_set_repo_variable/github_set_scan_profile_remote(Actions variables → secrets fallback),github_put_repo_secret(PUT encrypted secret),github_push_security_workflow(commit/update .github/workflows/nexus-security.yml),github_detect_dependabot_ecosystems(23 lockfile/manifest markers: composer, npm, pip, gomod, bundler, cargo, mix, pub, maven, gradle),github_build_dependabot_yaml,github_install_repo_dependabot(auto-detect + commit dependabot.yml),github_is_nexus_source_repo(protection check),github_setup_repo(full setup: secrets + workflow + dependabot + scan profile),github_generate_workflow_yaml,github_delete_workflow,github_get_workflow_runs/github_rerun_workflow.includes/commits.php(183 lines):github_get_branches,github_get_commits(paginated, author filter),github_get_commit_details(file diffs, stats, verification),github_compare_commits,github_revert_commit.includes/prs.php(214 lines):github_get_prs(open/closed/all with permission notice),github_get_pr_details(PR + files changed),github_ai_review_pr(enterprise OWASP/NIST prompt, sensitive file detection, 5-section report),github_merge_pr(merge/squash/rebase).includes/releases.php(144 lines):github_get_releases(releases + tags),github_generate_release_notes(SemVer classification: feat/fix/sec/breaking),github_create_release.includes/security.php(352 lines):github_get_security_alerts(Dependabot + Secret Scanning alerts, severity counters),github_ai_analyze_commits(DevSecOps audit engine: feat/fix/sec/refactor/docs categorization, risk score 10-95, conventional commits %, verified %, 6-section markdown report),github_get_repo_health(5 weighted checks: README, LICENSE, SECURITY.md, Dependabot, Branch Protection → scorecard 0-100).includes/purger.php(205 lines):github_create_task_from_git,github_scan_sensitive_files(8 regex: .env, SSH keys, .pem/.pfx, cloud credentials JSON, wp-config, npmrc/pypirc, .htpasswd, SQL dumps),github_purge_file_from_branch(delete via GitHub API with [SECURITY EXPUNGE] commit message),github_get_history_purge_script(generates bash scripts for git-filter-repo and BFG Repo-Cleaner).includes/sync.php(264 lines):github_get_nexus_projects,github_get_repo_mappings/github_save_repo_mappings(repo→NEXUS project mapping),github_auto_sync_all_repos(cronjob worker: sync Dependabot PRs + Security Alerts to Kanban, creates tasks with ref signatures for deduplication),github_create_task_direct.views/script.php(926 lines): Alpine.js plugin controllergitManagerPlugin(), full state (repos, branches, commits, PRs, workflows, releases, security, health, tasks, mappings, purge), 25+ async methods (apiCall, fetchRepos, fetchBranches, fetchCommits, viewCommitDetails, fetchPRs, openPRDetails, openAIReviewPR, submitMergePR, fetchWorkflowRuns, rerunWorkflow, fetchReleases, submitCreateRelease, fetchRepoHealth, installDependabot, analyzeWithAI, confirmRevert, saveConfig, disconnectAccount, scanSensitiveFiles, openPurgeModal, submitPurgeFile, triggerDevSecOpsSync), renderMarkdown with Marked.js + custom fallback, formatDiffPatch with syntax highlighting.views/subtabs/(8 files): commits.php, prs.php, actions.php, releases.php, security.php, health.php, ai.php, config.php.views/modals/(7 files): diff-modal.php, pr-modal.php, ai-review.php, pr-merge.php, release-modal.php, task-modal.php, purge-modal.php.tab.php(329 lines): master view including markdown body CSS styles (tables, headings, blockquotes), includesmarked.min.jsCDN, loads subtabs and modals, GitHub user avatar header rendering.modals.php(500+ lines): OAuth configuration modal (Client ID/Secret, callback URL, disconnect/reconnect), GitHub App guide (6 visual steps).lang.json(22K): PT/EN/ES i18n for all features, tabs, modals, error messages and configurations.fastr.json(2.8K): slash commands/github(open GitHub Manager),/git-commits(view commits),/git-ai(AI analysis),/git-health(health score),/git-prs(list PRs),/git-release(generate release).cronjob.json:github_manager_dependabot_syncjob — auto-sync Dependabot & CVEs to Kanban (configurable frequency).doc.md(157 lines): step-by-step GitHub App configuration guide (14 steps, PT).icon.svg: GitHub brand icon (Octocat).
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Full-featured DevSecOps plugin for GitHub: OAuth App with anti-CSRF, repository management, commits with diffs, Pull Requests with AI Code Review, CI/CD (GitHub Actions), SemVer Releases with notes generation, Dependabot installer, vulnerability alerts, 10-dimension Health Scorecard, sensitive file scanner, git history purger (git-filter-repo/BFG) and automated cronjob for syncing PRs and CVEs into the NEXUS Kanban — all in a slate 8-tab UI with full i18n.
Architecture and organization
- PHP 8
- MySQL 8
- OAuth 2.0
- libsodium
- Alpine.js
- Marked.js
- i18n
- GitHub REST API v2022-11-28
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.
