Cover image for project: NEXUS GitHub Security IN PROGRESS

Technical summary

NEXUS plugin that centralizes post-push findings from security scanners, SBOM, Dependency-Track, domains, and CI/CD repositories. Imports normalize evidence, deduplicate or reopen tasks, and feed the Compliance Hub; the dashboard also correlates CVEs, manages scan profiles and workflows, and triggers critical alerts.

Executed scope

  • plugin.json — v1.2.0, category DevSecOps, lucide icon shield-alert, dedicated icon.svg and repository sr00t3d/nexus-github-security.
  • Registrations: registerTab("github-security", "GitHub Security", "shield-alert", tab.php, "Security"), registerDoc(...), registerModal("security-modals", modals.php) and registerJs("github-security", "/plugins/github-security/assets/nexus-security-scanner.js").
  • 37 API actions: 14 imports (Trivy, Grype, Semgrep, CodeQL, MobSF, QARK, Nuclei, Wordfence, Gitleaks, ZAP, Composer, NPM, SBOM, Dependency-Track), SBOM inventory, DTrack synchronization, CVE correlation, domain audits, and CI/CD workflow health.
  • Persistence: NEXUS task deduplication and evidence recording in Compliance Hub, with local domain, repository, SBOM, and DTrack configurations.
  • Mobile and CodeQL integrations: MobSF/QARK dual-mode scans for mobile packages and CodeQL SARIF uploads to GitHub Security Tab.
  • Alpine.js UI: 4 sub-tabs (Domains, CI/CD Repositories, SBOM, Dependency-Track), scanner import selector, metric cards, and responsive controls.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Comprehensive post-push security and DevSecOps orchestrator for GitHub repositories. Consolidates findings from multiple scanners (Trivy, Grype, Semgrep, CodeQL, MobSF, Nuclei, Gitleaks, OWASP ZAP), manages SBOM inventories with Syft, integrates continuous CVE monitoring via Dependency-Track, and audits domain surfaces and CI/CD.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.