Cover image for project: Nexus Security Scanner IN PROGRESS

Technical summary

NEXUS plugin that centralizes post-push findings from scanners, SBOM, Dependency-Track, domains and CI/CD repositories. Imports normalize evidence, deduplicate or reopen tasks and feed Compliance Hub; the panel also correlates CVEs, manages scan profiles and workflows, and sends critical alerts.

Executed scope

  • plugin.json — v1.3.0, NEXUS category, lucide shield-alert icon with icon_bg #fff1f2, own icon.svg (scan magnifier) and style: design.css.
  • Registrations: registerTab("security", "Security Scanner", "shield-alert", tab.php, "NEXUS"), registerDoc(...), registerModal("security-modals", modals.php) and registerJs("nexus-security-scanner", "/plugins/nexus-security-scanner/assets/security.js").
  • 37 API actions (plugin.php, via PluginManager::registerApiAction) — 14 imports (security_import_trivy|grype|semgrep|codeql|mobsf|qark|nuclei|wordfence|gitleaks|zap|composer|npm|sbom|dtrack), SBOM (security_sbom_list/get), DTrack (security_dtrack_sync/dashboard/save_config), CVE (security_cve_details), domains (security_scan_domain|save_domain|get_domains|delete_domain), repos (security_save_repo|get_repos|delete_repo), profiles (security_get_scan_profiles|set_scan_profile), workflows (security_get_workflow_statuses|trigger_workflow), CI health (security_get_ci_health|inspect_repo_ci|sync_repo_workflow|install_repo_dependabot|sync_outdated_workflows), alerts (security_notify_critical).
  • Persistence: no own tables — findings become NEXUS tasks (security_manage_task: title dedupe, reopen of done/cancelled, project_resolve_for_task) and evidence in plugin.compliance.ci_evidence; domains in plugin.security.domains, repos in plugin.security.repos, SBOM in plugin.security.sbom, DTrack in plugin.security.dtrack (DB config).
  • Imports: security_process_trivy_scan (37-249), grype (249-405), semgrep (405-632), codeql (632-843), mobsf (893-1106), qark (1106-1262), nuclei (1262-1442), wordfence (1820-1965), gitleaks (1965-2126), zap (2126-2280), composer (2280-2398), npm (2398-2532), sbom (3924-4092), dtrack (4303-4495) — each normalizes upload/body, resolves the project and creates/reopens tasks.
  • Compliance: security_import_with_compliance → security_finding_to_controls (MITRE + NIST/ISO map per scanner) → security_record_compliance_evidence (Hub evidence; SBOM creates no per-package task).
  • SBOM: security_process_sbom_scan — CycloneDX preferred/SPDX fallback, purl → ecosystem, per-repo inventory in plugin.security.sbom; security_sbom_list/get (detail + packages by ?repo=owner/name).
  • Dependency-Track: local Docker stack (API 127.0.0.1:9080, UI 9081; bootstrap-api-key.sh → plugin.security.dtrack); NEW_VULNERABILITY/POLICY webhook → [DTrack] CVE — pkg tasks; security_dtrack_sync (CI evidence); dashboard with stats/syncs/alerts/masked config.
  • CodeQL: dual visibility — codeql-action/upload-sarif@v3 to GitHub Security Tab + security_import_codeql creates/updates [CodeQL] … tasks.
  • Mobile: nexus-mobile-scan.yml workflow (detect job with path filter — Manifest/Gradle Android/iOS/artifact) → only then MobSF/QARK (no APK/IPA or non-mobile repo → skipped). Docs MOBSF.md/QARK.md.
  • GitHub OAuth: GitHub plugin authorizes repos/workflows; callbacks by SITE_URL (lab http://127.0.0.1:8088; LOCAL_DEV_F_IA.md docs).
  • Domains: security_audit_domain — headers/SSL/CORS; /trivy <domain|IP> slash via fastr.json (security_scan_domain).
  • Intel: security_scanner_intel_enrich (priority 46, cve type) — local correlation with tasks/findings (no external API in the hub).
  • Alerts: security_notify_critical — notify_security_critical (email, dashboard, Discord/Slack, optional Novu); used by the notify-critical job.
  • CI health: security_get_ci_health/inspect_repo_ci — compares remote workflow vs local template (action pins, template version/fingerprint), workflow sync, Dependabot, billing block detection.
  • Alpine.js UI (tab.php 116 KB): 4 sub-tabs (Domains, CI/CD Repositories, SBOM, Dependency-Track), per-scanner import selector, metric cards and premium toolbar.

Stack and tools

  • PHP 8 (no framework) + MySQL 8 (NEXUS tasks + DB config — no plugin tables)
  • Alpine.js + Tailwind CSS (tab.php) + modals (modals.php) + registered JS (assets/security.js)
  • GitHub Actions (nexus-security.yml — per-scanner import jobs + notify-critical; nexus-mobile-scan.yml — MobSF/QARK)
  • GitHub API (GitHub plugin OAuth) — workflows, CI health, Dependabot
  • Scanners: Trivy, Grype, Semgrep, CodeQL, Nuclei, Wordfence, Gitleaks, ZAP, Composer, npm, Syft (SBOM), MobSF, QARK
  • Dependency-Track (local Docker) + Compliance Hub (NIST/ISO evidence) + Intelligence Hub (CVE enricher)

Operational tags

  • Security Scanner
  • Trivy
  • SBOM
  • Dependency-Track
  • MobSF
  • QARK
  • CodeQL
  • Domains
  • NEXUS Plugin

Operational result

  • 14 scanner imports with normalization, per-repo project auto-mapping and conversion into NEXUS tasks with title dedupe (reopens done/cancelled when the vulnerability resurfaces).
  • Automatic compliance evidence: each import appends MITRE + NIST/ISO controls to the Compliance Hub (plugin.compliance.ci_evidence) — no MITRE task flood per finding.
  • SBOM (CycloneDX/SPDX) inventoried per repository with purl → ecosystem; Dependency-Track receives the SBOM via CI and the continuous webhook creates/reopens [DTrack] CVE — pkg tasks.
  • CodeQL with dual visibility: results in the GitHub Security Tab and as [CodeQL] tasks in NEXUS; mobile via MobSF/QARK with path filter (only mobile repos/artifacts are scanned).
  • CVEs cited in tasks/comments are correlated with local findings by the Intelligence Hub enricher — severity by open tasks, no external call.
  • Domains audited (headers/SSL/CORS) via the /trivy slash; CI health compares workflows with the template (pins/version) and syncs, plus Dependabot installation.
  • CRITICAL alerts from CI (notify-critical job) by email/dashboard/Discord/Slack/Novu.
  • Complementary to Security Gate: Scanner is the post-push layer (CI/import, security_*); Gate is the pre-push layer (local hooks, gate_*).

GitHub progress (issues)

Latest repository issues, updated in real time.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin (v1.3.0) that centralizes scanner findings (Trivy, Grype, Semgrep, CodeQL, Nuclei, Wordfence, Gitleaks, ZAP, Composer, npm, MobSF, QARK), SBOM inventory (Syft CycloneDX/SPDX), Dependency-Track (continuous CVE webhook), domain auditing, CI/CD repos and CRITICAL alerts — turning everything into NEXUS tasks with cross evidence in the Compliance Hub.

Architecture and organization

Execution and operations

Execution in Docker/production environment, with validation and evidence documentation.

Screenshots

Talk about this project

Interested in adapting this project for your context? Get in touch.