Cover image for project: Nexus Security Gate IN PROGRESS

Technical summary

NEXUS DevSecOps plugin that runs security scans at pre-commit and pre-push, before code reaches GitHub. Its CLI installs hooks, runs scanners and uploads authenticated results to the panel, which enforces blocking policies, creates tasks, and maintains inventory, metrics and automation for local or registered repositories.

Executed scope

  • plugin.json — v1.0.0, DevSecOps category, protected: false (non-core), lucide shield-check icon with icon_bg #ecfdf5, own icon.svg (shield + check) and style: design.css.
  • Registrations: registerTab("nexus-security-gate", "Security Gate", "shield-check", tab.php, "DevSecOps") and registerDoc(...).
  • 23 API actions (plugin.php, via PluginManager::registerApiAction) — gate_status (mode/tools/last_scan/metrics), gate_requirements (tools check), gate_settings/gate_settings_save (config + rotate_token), gate_install_hooks (pre-commit/pre-push scripts + env_example + steps), gate_bootstrap (one-liner + script + notes), gate_bootstrap_sh (raw script for curl | bash, public with token), gate_cli_raw (raw CLI, public with token), gate_repos_browse/discover/save/scan/auto_tick (local host repos), gate_install_tools (host scanners, profile/tools), gate_upload (CLI upload, public with X-Gate-Token), gate_register (repo registration by the CLI, public with token), gate_registered/save/scan (inventory), gate_metrics, gate_scans (paginated), gate_fastr/gate_fastr_suggest (slash /gate).
  • Database: gate_install() on load — CREATE TABLE IF NOT EXISTS gate_scan_results (id PK, repo_name, branch, commit_sha, scanner, findings_json, severity counts, blocked, upload_source, project, created_at; repo/created/blocked/scanner indexes).
  • Config: security_gate_settings in DB config — enabled, upload_token, block_on_critical, block_on_high, auto_create_tasks, default_project, min_severity_for_task, repos_root, watched_repos, auto_scan, repos_max_depth, registered_repos, tool_profile.
  • Upload: gate_upload — own token (X-Gate-Token/body), project resolution (mapping → upload → default NEXUS), counts derived from findings, block by block_on_critical/block_on_high, block_reasons (up to 12), auto-tasks (CRITICAL/HIGH), repo registered in the inventory.
  • Tasks: gate_create_tasks — [Gate][SEV] scanner — rule, min_severity_for_task, max 5/scan, priority 4 critical / 3 high, blocked-scan fallback without detailed findings.
  • CLI: cli/nexus-gate (bash) — --status/--install/--commit/--push; NEXUS_GATE_URL/TOKEN/PROJECT/BLOCK_CRITICAL/BLOCK_HIGH/BIN_DIR env; TTY progress bar; PATH with uploads/security-gate/bin + ~/.local/share/nexus-gate/bin; cli/install.sh (symlink in ~/.local/bin).
  • Hooks: hooks/pre-commit + hooks/pre-push (templates) and dynamic generation in gate_install_hooks() (absolute path, example env).
  • Bootstrap: gate_bootstrap_sh (one-liner with token, curl | bash) — CLI + ~/.config/nexus-gate/env + hooks in the repo; --with-tools installs jq+gitleaks; gate_cli_raw serves the CLI; shared-hosting notes.
  • Host tools: gate_install_tools — essential/normal/complete profiles (mirroring nexus-security.yml), static binaries in uploads/security-gate/bin (persistent, .gitignore), gate_tool_catalog() (15 tools with bin/role/phase/tier/workflow), gate_install_via_uv() for Python (embedded CPython), tarball downloads + GitHub latest tag.
  • Local repos: gate_repos_discover (.git under root, depth 1-6, allowed paths NEXUS tree//var/www//home//opt//srv), gate_repos_scan (runs nexus-gate --push), gate_repos_auto_tick (auto-scan).
  • CLI inventory: gate_register_repo (cap 200, mark_scan), gate_registered_list/save/scan — project mapping in the dashboard.
  • Metrics: gate_metrics_data — scans last hour/day/7d, blocked 7d, block_rate_7d, 7d findings (C/H/M/L).
  • Auth: gate_upload/gate_bootstrap_sh/gate_cli_raw/gate_register in the api.php auth bypass whitelist (lines 58-60) — public with their own token; the remaining actions require session/Bearer.
  • Alpine.js UI (tab.php ~42 KB): 5 tabs — Overview, Repos, Scans, Install, Config; install-missing button; scans table with blocked/C/H/M/L chips; copyable one-liner with token.

Stack and tools

  • PHP 8 (no framework) + MySQL 8 (gate_scan_results — DDL on load)
  • Alpine.js + Tailwind CSS
  • Bash (nexus-gate CLI, hooks, install.sh, bootstrap)
  • Git Hooks (pre-commit / pre-push)
  • Scanners: gitleaks, semgrep, trivy, trufflehog, grype, syft, osv-scanner, shellcheck, hadolint, checkov, bandit, nuclei (host-installable by profile)
  • NEXUS plugin system (PluginManager::registerTab/registerDoc/registerApiAction) + Fast Responses (fastr.json)

Operational tags

  • Security Gate
  • Shift Left
  • Secrets
  • SAST
  • SCA
  • Pre-commit
  • Pre-push
  • NEXUS Plugin
  • DevSecOps

Operational result

  • Real Shift Security Left: the code is scanned before GitHub — pre-commit stops secrets (gitleaks) and pre-push stops secrets + SAST (semgrep) + SCA (trivy), blocking commit/push on CRITICAL (and HIGH if configured).
  • One-command install: curl | bash one-liner with token installs the CLI, writes env and puts the hooks in the repo — the developer needs no VPS; the upload goes over HTTPS to NEXUS.
  • Authenticated upload with its own token (X-Gate-Token), auto-resolved project (mapping → upload → default) and automatic task creation [Gate][SEV] scanner — rule with minimum-severity gating.
  • 5-tab dashboard: overview (mode/tools/last scan), local host repos (.git discovery, watched, auto-scan), scans (paginated history with blocked and C/H/M/L counts), scanner installation by profile (essential/normal/complete) and config (block rules, token with rotate).
  • Operational metrics: scans/hour/day/7d, 7d block rate and 7d findings by severity — visible in /gate and the dashboard.
  • No conflict with Security Scanner: Gate is the pre-push layer (local hooks, gate_*); Scanner is the post-push layer (CI/import, security_*).

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Shift-Left security gate implementing automated pre-commit and pre-push hooks. Prevents exposed secrets (Gitleaks/TruffleHog), code vulnerabilities (Semgrep), and vulnerable dependencies (Trivy) before code reaches remote repositories, reporting real-time metrics to the NEXUS dashboard.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.