IN PROGRESS
Technical summary
NEXUS DevSecOps plugin that runs security scans at pre-commit and pre-push, before code reaches GitHub. Its CLI installs hooks, runs scanners and uploads authenticated results to the panel, which enforces blocking policies, creates tasks, and maintains inventory, metrics and automation for local or registered repositories.
Executed scope
plugin.json— v1.0.0, DevSecOps category,protected: false(non-core), lucideshield-checkicon withicon_bg #ecfdf5, ownicon.svg(shield + check) andstyle: design.css.- Registrations:
registerTab("nexus-security-gate", "Security Gate", "shield-check", tab.php, "DevSecOps")andregisterDoc(...). - 23 API actions (
plugin.php, viaPluginManager::registerApiAction) —gate_status(mode/tools/last_scan/metrics),gate_requirements(tools check),gate_settings/gate_settings_save(config + rotate_token),gate_install_hooks(pre-commit/pre-push scripts + env_example + steps),gate_bootstrap(one-liner + script + notes),gate_bootstrap_sh(raw script forcurl | bash, public with token),gate_cli_raw(raw CLI, public with token),gate_repos_browse/discover/save/scan/auto_tick(local host repos),gate_install_tools(host scanners,profile/tools),gate_upload(CLI upload, public withX-Gate-Token),gate_register(repo registration by the CLI, public with token),gate_registered/save/scan(inventory),gate_metrics,gate_scans(paginated),gate_fastr/gate_fastr_suggest(slash/gate). - Database:
gate_install()on load — CREATE TABLE IF NOT EXISTSgate_scan_results(id PK, repo_name, branch, commit_sha, scanner, findings_json, severity counts, blocked, upload_source, project, created_at; repo/created/blocked/scanner indexes). - Config:
security_gate_settingsin DB config — enabled, upload_token, block_on_critical, block_on_high, auto_create_tasks, default_project, min_severity_for_task, repos_root, watched_repos, auto_scan, repos_max_depth, registered_repos, tool_profile. - Upload:
gate_upload— own token (X-Gate-Token/body), project resolution (mapping → upload → default NEXUS), counts derived from findings, block byblock_on_critical/block_on_high,block_reasons(up to 12), auto-tasks (CRITICAL/HIGH), repo registered in the inventory. - Tasks:
gate_create_tasks—[Gate][SEV] scanner — rule, min_severity_for_task, max 5/scan, priority 4 critical / 3 high, blocked-scan fallback without detailed findings. - CLI:
cli/nexus-gate(bash) —--status/--install/--commit/--push;NEXUS_GATE_URL/TOKEN/PROJECT/BLOCK_CRITICAL/BLOCK_HIGH/BIN_DIRenv; TTY progress bar; PATH withuploads/security-gate/bin+~/.local/share/nexus-gate/bin;cli/install.sh(symlink in~/.local/bin). - Hooks:
hooks/pre-commit+hooks/pre-push(templates) and dynamic generation ingate_install_hooks()(absolute path, example env). - Bootstrap:
gate_bootstrap_sh(one-liner with token,curl | bash) — CLI +~/.config/nexus-gate/env+ hooks in the repo;--with-toolsinstalls jq+gitleaks;gate_cli_rawserves the CLI; shared-hosting notes. - Host tools:
gate_install_tools— essential/normal/complete profiles (mirroringnexus-security.yml), static binaries inuploads/security-gate/bin(persistent,.gitignore),gate_tool_catalog()(15 tools with bin/role/phase/tier/workflow),gate_install_via_uv()for Python (embedded CPython), tarball downloads + GitHub latest tag. - Local repos:
gate_repos_discover(.gitunder root, depth 1-6, allowed paths NEXUS tree//var/www//home//opt//srv),gate_repos_scan(runsnexus-gate --push),gate_repos_auto_tick(auto-scan). - CLI inventory:
gate_register_repo(cap 200,mark_scan),gate_registered_list/save/scan— project mapping in the dashboard. - Metrics:
gate_metrics_data— scans last hour/day/7d, blocked 7d, block_rate_7d, 7d findings (C/H/M/L). - Auth:
gate_upload/gate_bootstrap_sh/gate_cli_raw/gate_registerin theapi.phpauth bypass whitelist (lines 58-60) — public with their own token; the remaining actions require session/Bearer. - Alpine.js UI (
tab.php~42 KB): 5 tabs — Overview, Repos, Scans, Install, Config; install-missing button; scans table with blocked/C/H/M/L chips; copyable one-liner with token.
Stack and tools
- PHP 8 (no framework) + MySQL 8 (
gate_scan_results— DDL on load) - Alpine.js + Tailwind CSS
- Bash (
nexus-gateCLI, hooks, install.sh, bootstrap) - Git Hooks (pre-commit / pre-push)
- Scanners: gitleaks, semgrep, trivy, trufflehog, grype, syft, osv-scanner, shellcheck, hadolint, checkov, bandit, nuclei (host-installable by profile)
- NEXUS plugin system (
PluginManager::registerTab/registerDoc/registerApiAction) + Fast Responses (fastr.json)
Operational tags
- Security Gate
- Shift Left
- Secrets
- SAST
- SCA
- Pre-commit
- Pre-push
- NEXUS Plugin
- DevSecOps
Operational result
- Real Shift Security Left: the code is scanned before GitHub —
pre-commitstops secrets (gitleaks) andpre-pushstops secrets + SAST (semgrep) + SCA (trivy), blocking commit/push on CRITICAL (and HIGH if configured). - One-command install:
curl | bashone-liner with token installs the CLI, writes env and puts the hooks in the repo — the developer needs no VPS; the upload goes over HTTPS to NEXUS. - Authenticated upload with its own token (
X-Gate-Token), auto-resolved project (mapping → upload → default) and automatic task creation[Gate][SEV] scanner — rulewith minimum-severity gating. - 5-tab dashboard: overview (mode/tools/last scan), local host repos (
.gitdiscovery, watched, auto-scan), scans (paginated history with blocked and C/H/M/L counts), scanner installation by profile (essential/normal/complete) and config (block rules, token with rotate). - Operational metrics: scans/hour/day/7d, 7d block rate and 7d findings by severity — visible in
/gateand the dashboard. - No conflict with Security Scanner: Gate is the pre-push layer (local hooks,
gate_*); Scanner is the post-push layer (CI/import,security_*).
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Shift-Left security gate implementing automated pre-commit and pre-push hooks. Prevents exposed secrets (Gitleaks/TruffleHog), code vulnerabilities (Semgrep), and vulnerable dependencies (Trivy) before code reaches remote repositories, reporting real-time metrics to the NEXUS dashboard.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- Bash
- Plugin NEXUS
- Git Hooks
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.