IN PROGRESS
Technical summary
Integration plugin that connects NEXUS to GitHub through OAuth with state protection and safe client-secret handling. Repository setup writes NEXUS secrets with libsodium, publishes the security workflow, configures Dependabot and the scan profile, and registers the project for use by Security Scanner.
Executed scope
- 8 API actions via
PluginManager::registerApiAction—github_get_config(masked client_secret),github_save_config(never overwrites the secret with the mask),github_auth(CSRF state +repo,workflowscope),github_callback(code→token exchange + profile, auth bypass inapi.php),github_disconnect,github_list_repos,github_setup_repo,github_get_connection_status(token validation withtoken_invalidflag). github_api_request()— cURL wrapper with forced HTTPS, per-endpoint headers (api.github.com →Accept: application/vnd.github+json+X-GitHub-Api-Version: 2022-11-28,User-Agent: NEXUS-Task-Dashboard), 15s timeout and GET/POST/PUT/PATCH/DELETE support.- CI/CD secrets:
github_encrypt_secret()withsodium_crypto_box_seal(repo public key +key_id) writingNEXUS_TOKENandNEXUS_API_URLviagithub_put_repo_secret(PUT on/actions/secrets/{name});github_nexus_public_url()resolves the public URL (SITE_URLresolved at bootstrap or theNEXUS_PUBLIC_URLenv). - Security workflow:
github_push_security_workflow()sends.github/workflows/nexus-security.ymlwith base64 + sha (create/update) and commitci: sync NEXUS security scanner workflow;github_generate_workflow_yaml()reads the host template at.github/workflows/nexus-security.yml(source of truth) with an inline fallback. - Dependabot:
github_detect_dependabot_ecosystems()maps 23 lockfile/manifest markers (composer, npm, pip, gomod, bundler, cargo, mix, pub, maven, gradle), skipsvendor|node_modules|dist|buildand always monitorsgithub-actions;github_build_dependabot_yaml()generates.github/dependabot.yml(weekly, Monday, 5 PR limit,dependencieslabels). - Remote scan profile:
github_set_scan_profile_remote()prefers the Actions variable (NEXUS_SCAN_PROFILE) and falls back to a secret when the token/app cannot write variables ("Resource not accessible by integration"); integrates withsecurity_resolve_repo_scan_profile()from the nexus-security-scanner. - Repository registration:
github_setup_repo()upsertsplugin.security.repos(URL + NEXUS project resolved viaproject_find_by_name()inprojects.php) — a direct cross-link with the nexus-security-scanner plugin. - Protection:
github_delete_workflow()refuses to remove the workflow from the NEXUS source repo (detected by probingplugins/nexus-security-scanner/plugin.php), preserving the template. - Alpine.js UI:
modals.php(289 lines — connection status with avatar, invalid-token warning with Reconnect button, copyable callback URL, 7-step inline guide) +docs.php(245 lines — 10-step carousel with zoomable screenshots) +doc.md(14-step GitHub App guide). cors.php: originshttps://github.comandhttps://api.github.com, GET/POST/PUT methods andX-Hub-Signature-256header (GitHub webhooks call the NEXUS API).
Stack and tooling
- PHP 8 (no framework)
- MySQL 8 (config persisted via
DB::getConfig/setConfiginplugin.github.configandplugin.security.repos) - cURL (GitHub REST API, OAuth endpoints)
- libsodium (
sodium_crypto_box_sealfor secrets) - GitHub REST API (v2022-11-28) + GitHub OAuth App
- GitHub Actions (security workflow) + Dependabot
- Alpine.js + Tailwind CSS
Operational tags
- Integrations
- GitHub
- OAuth
- CI/CD
- GitHub Actions
- Secrets
- Dependabot
- Plugin NEXUS
Operational outcome
- OAuth connection with minimal scopes (
repo,workflow) and permanent tokens (expiration unchecked on the GitHub App), with invalid/expired token detection and guided reconnection from the panel. - One-click repository setup: libsodium-encrypted CI/CD secrets, security workflow committed to the repo, nexus-security-scanner registration and Dependabot installed with no manual intervention.
- Link with the nexus-security-scanner (plugin.security.repos + NEXUS_SCAN_PROFILE) — repositories start reporting scans to the NEXUS API via NEXUS_TOKEN/NEXUS_API_URL.
- Defense in depth: anti-CSRF
statein OAuth, forced HTTPS on every call, masked secret in the frontend, per-repository public key and protection of the template source repository. - Dependabot with automatic ecosystem detection (including
github-actionspins) keeps dependencies monitored without manual YAML configuration.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin (Integrations category) that connects the panel to GitHub via OAuth App: links repositories, encrypts CI/CD secrets with libsodium and automates the GitHub Actions security workflow with Dependabot in one click.
Architecture and organization
- PHP 8
- MySQL 8
- cURL
- libsodium
- Alpine.js
- Tailwind CSS
- GitHub REST API
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.