IN PROGRESS
Technical summary
NEXUS plugin that centralizes post-push findings from scanners, SBOM, Dependency-Track, domains and CI/CD repositories. Imports normalize evidence, deduplicate or reopen tasks and feed Compliance Hub; the panel also correlates CVEs, manages scan profiles and workflows, and sends critical alerts.
Executed scope
plugin.json— v1.3.0, NEXUS category, lucideshield-alerticon withicon_bg #fff1f2, ownicon.svg(scan magnifier) andstyle: design.css.- Registrations:
registerTab("security", "Security Scanner", "shield-alert", tab.php, "NEXUS"),registerDoc(...),registerModal("security-modals", modals.php)andregisterJs("nexus-security-scanner", "/plugins/nexus-security-scanner/assets/security.js"). - 37 API actions (
plugin.php, viaPluginManager::registerApiAction) — 14 imports (security_import_trivy|grype|semgrep|codeql|mobsf|qark|nuclei|wordfence|gitleaks|zap|composer|npm|sbom|dtrack), SBOM (security_sbom_list/get), DTrack (security_dtrack_sync/dashboard/save_config), CVE (security_cve_details), domains (security_scan_domain|save_domain|get_domains|delete_domain), repos (security_save_repo|get_repos|delete_repo), profiles (security_get_scan_profiles|set_scan_profile), workflows (security_get_workflow_statuses|trigger_workflow), CI health (security_get_ci_health|inspect_repo_ci|sync_repo_workflow|install_repo_dependabot|sync_outdated_workflows), alerts (security_notify_critical). - Persistence: no own tables — findings become NEXUS tasks (
security_manage_task: title dedupe, reopen of done/cancelled,project_resolve_for_task) and evidence inplugin.compliance.ci_evidence; domains inplugin.security.domains, repos inplugin.security.repos, SBOM inplugin.security.sbom, DTrack inplugin.security.dtrack(DB config). - Imports:
security_process_trivy_scan(37-249),grype(249-405),semgrep(405-632),codeql(632-843),mobsf(893-1106),qark(1106-1262),nuclei(1262-1442),wordfence(1820-1965),gitleaks(1965-2126),zap(2126-2280),composer(2280-2398),npm(2398-2532),sbom(3924-4092),dtrack(4303-4495) — each normalizes upload/body, resolves the project and creates/reopens tasks. - Compliance:
security_import_with_compliance→security_finding_to_controls(MITRE + NIST/ISO map per scanner) →security_record_compliance_evidence(Hub evidence; SBOM creates no per-package task). - SBOM:
security_process_sbom_scan— CycloneDX preferred/SPDX fallback, purl → ecosystem, per-repo inventory inplugin.security.sbom;security_sbom_list/get(detail + packages by?repo=owner/name). - Dependency-Track: local Docker stack (API
127.0.0.1:9080, UI 9081;bootstrap-api-key.sh→plugin.security.dtrack); NEW_VULNERABILITY/POLICY webhook →[DTrack] CVE — pkgtasks;security_dtrack_sync(CI evidence); dashboard with stats/syncs/alerts/masked config. - CodeQL: dual visibility —
codeql-action/upload-sarif@v3to GitHub Security Tab +security_import_codeqlcreates/updates[CodeQL] …tasks. - Mobile:
nexus-mobile-scan.ymlworkflow (detectjob with path filter — Manifest/Gradle Android/iOS/artifact) → only then MobSF/QARK (no APK/IPA or non-mobile repo → skipped). DocsMOBSF.md/QARK.md. - GitHub OAuth: GitHub plugin authorizes repos/workflows; callbacks by
SITE_URL(labhttp://127.0.0.1:8088;LOCAL_DEV_F_IA.mddocs). - Domains:
security_audit_domain— headers/SSL/CORS;/trivy <domain|IP>slash via fastr.json (security_scan_domain). - Intel:
security_scanner_intel_enrich(priority 46,cvetype) — local correlation with tasks/findings (no external API in the hub). - Alerts:
security_notify_critical—notify_security_critical(email, dashboard, Discord/Slack, optional Novu); used by thenotify-criticaljob. - CI health:
security_get_ci_health/inspect_repo_ci— compares remote workflow vs local template (action pins, template version/fingerprint), workflow sync, Dependabot, billing block detection. - Alpine.js UI (
tab.php116 KB): 4 sub-tabs (Domains, CI/CD Repositories, SBOM, Dependency-Track), per-scanner import selector, metric cards and premium toolbar.
Stack and tools
- PHP 8 (no framework) + MySQL 8 (NEXUS tasks + DB config — no plugin tables)
- Alpine.js + Tailwind CSS (
tab.php) + modals (modals.php) + registered JS (assets/security.js) - GitHub Actions (
nexus-security.yml— per-scanner import jobs +notify-critical;nexus-mobile-scan.yml— MobSF/QARK) - GitHub API (GitHub plugin OAuth) — workflows, CI health, Dependabot
- Scanners: Trivy, Grype, Semgrep, CodeQL, Nuclei, Wordfence, Gitleaks, ZAP, Composer, npm, Syft (SBOM), MobSF, QARK
- Dependency-Track (local Docker) + Compliance Hub (NIST/ISO evidence) + Intelligence Hub (CVE enricher)
Operational tags
- Security Scanner
- Trivy
- SBOM
- Dependency-Track
- MobSF
- QARK
- CodeQL
- Domains
- NEXUS Plugin
Operational result
- 14 scanner imports with normalization, per-repo project auto-mapping and conversion into NEXUS tasks with title dedupe (reopens
done/cancelledwhen the vulnerability resurfaces). - Automatic compliance evidence: each import appends MITRE + NIST/ISO controls to the Compliance Hub (
plugin.compliance.ci_evidence) — no MITRE task flood per finding. - SBOM (CycloneDX/SPDX) inventoried per repository with purl → ecosystem; Dependency-Track receives the SBOM via CI and the continuous webhook creates/reopens
[DTrack] CVE — pkgtasks. - CodeQL with dual visibility: results in the GitHub Security Tab and as
[CodeQL]tasks in NEXUS; mobile via MobSF/QARK with path filter (only mobile repos/artifacts are scanned). - CVEs cited in tasks/comments are correlated with local findings by the Intelligence Hub enricher — severity by open tasks, no external call.
- Domains audited (headers/SSL/CORS) via the
/trivyslash; CI health compares workflows with the template (pins/version) and syncs, plus Dependabot installation. - CRITICAL alerts from CI (
notify-criticaljob) by email/dashboard/Discord/Slack/Novu. - Complementary to Security Gate: Scanner is the post-push layer (CI/import,
security_*); Gate is the pre-push layer (local hooks,gate_*).
GitHub progress (issues)
Latest repository issues, updated in real time.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin (v1.3.0) that centralizes scanner findings (Trivy, Grype, Semgrep, CodeQL, Nuclei, Wordfence, Gitleaks, ZAP, Composer, npm, MobSF, QARK), SBOM inventory (Syft CycloneDX/SPDX), Dependency-Track (continuous CVE webhook), domain auditing, CI/CD repos and CRITICAL alerts — turning everything into NEXUS tasks with cross evidence in the Compliance Hub.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- GitHub Actions
- Plugin NEXUS
Execution and operations
Execution in Docker/production environment, with validation and evidence documentation.
Screenshots
Talk about this project
Interested in adapting this project for your context? Get in touch.