Cover image for project: Nexus GitHub Integration IN PROGRESS

Technical summary

Integration plugin that connects NEXUS to GitHub through OAuth with state protection and safe client-secret handling. Repository setup writes NEXUS secrets with libsodium, publishes the security workflow, configures Dependabot and the scan profile, and registers the project for use by Security Scanner.

Executed scope

  • 8 API actions via PluginManager::registerApiAction — github_get_config (masked client_secret), github_save_config (never overwrites the secret with the mask), github_auth (CSRF state + repo,workflow scope), github_callback (code→token exchange + profile, auth bypass in api.php), github_disconnect, github_list_repos, github_setup_repo, github_get_connection_status (token validation with token_invalid flag).
  • github_api_request() — cURL wrapper with forced HTTPS, per-endpoint headers (api.github.com → Accept: application/vnd.github+json + X-GitHub-Api-Version: 2022-11-28, User-Agent: NEXUS-Task-Dashboard), 15s timeout and GET/POST/PUT/PATCH/DELETE support.
  • CI/CD secrets: github_encrypt_secret() with sodium_crypto_box_seal (repo public key + key_id) writing NEXUS_TOKEN and NEXUS_API_URL via github_put_repo_secret (PUT on /actions/secrets/{name}); github_nexus_public_url() resolves the public URL (SITE_URL resolved at bootstrap or the NEXUS_PUBLIC_URL env).
  • Security workflow: github_push_security_workflow() sends .github/workflows/nexus-security.yml with base64 + sha (create/update) and commit ci: sync NEXUS security scanner workflow; github_generate_workflow_yaml() reads the host template at .github/workflows/nexus-security.yml (source of truth) with an inline fallback.
  • Dependabot: github_detect_dependabot_ecosystems() maps 23 lockfile/manifest markers (composer, npm, pip, gomod, bundler, cargo, mix, pub, maven, gradle), skips vendor|node_modules|dist|build and always monitors github-actions; github_build_dependabot_yaml() generates .github/dependabot.yml (weekly, Monday, 5 PR limit, dependencies labels).
  • Remote scan profile: github_set_scan_profile_remote() prefers the Actions variable (NEXUS_SCAN_PROFILE) and falls back to a secret when the token/app cannot write variables ("Resource not accessible by integration"); integrates with security_resolve_repo_scan_profile() from the nexus-security-scanner.
  • Repository registration: github_setup_repo() upserts plugin.security.repos (URL + NEXUS project resolved via project_find_by_name() in projects.php) — a direct cross-link with the nexus-security-scanner plugin.
  • Protection: github_delete_workflow() refuses to remove the workflow from the NEXUS source repo (detected by probing plugins/nexus-security-scanner/plugin.php), preserving the template.
  • Alpine.js UI: modals.php (289 lines — connection status with avatar, invalid-token warning with Reconnect button, copyable callback URL, 7-step inline guide) + docs.php (245 lines — 10-step carousel with zoomable screenshots) + doc.md (14-step GitHub App guide).
  • cors.php: origins https://github.com and https://api.github.com, GET/POST/PUT methods and X-Hub-Signature-256 header (GitHub webhooks call the NEXUS API).

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (config persisted via DB::getConfig/setConfig in plugin.github.config and plugin.security.repos)
  • cURL (GitHub REST API, OAuth endpoints)
  • libsodium (sodium_crypto_box_seal for secrets)
  • GitHub REST API (v2022-11-28) + GitHub OAuth App
  • GitHub Actions (security workflow) + Dependabot
  • Alpine.js + Tailwind CSS

Operational tags

  • Integrations
  • GitHub
  • OAuth
  • CI/CD
  • GitHub Actions
  • Secrets
  • Dependabot
  • Plugin NEXUS

Operational outcome

  • OAuth connection with minimal scopes (repo, workflow) and permanent tokens (expiration unchecked on the GitHub App), with invalid/expired token detection and guided reconnection from the panel.
  • One-click repository setup: libsodium-encrypted CI/CD secrets, security workflow committed to the repo, nexus-security-scanner registration and Dependabot installed with no manual intervention.
  • Link with the nexus-security-scanner (plugin.security.repos + NEXUS_SCAN_PROFILE) — repositories start reporting scans to the NEXUS API via NEXUS_TOKEN/NEXUS_API_URL.
  • Defense in depth: anti-CSRF state in OAuth, forced HTTPS on every call, masked secret in the frontend, per-repository public key and protection of the template source repository.
  • Dependabot with automatic ecosystem detection (including github-actions pins) keeps dependencies monitored without manual YAML configuration.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin (Integrations category) that connects the panel to GitHub via OAuth App: links repositories, encrypts CI/CD secrets with libsodium and automates the GitHub Actions security workflow with Dependabot in one click.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.