Balam Security Platform
  • TypeScript 55%
  • Go 44.1%
  • Shell 0.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
James Luther 52b1c2c409
All checks were successful
security-scan / security-scan (push) Successful in 1m15s
test / web (push) Successful in 2m22s
codecov/project 34.78% (No base report)
codecov/patch Patch coverage: N/A (not in PR context)
test / go (push) Successful in 5m5s
test / coverage-badge (push) Successful in 3m36s
Merge pull request 'chore(deps): update dependency @tanstack/react-query to v5.104.0' (#39) from renovate/tanstack-query-monorepo into main
Reviewed-on: #39
2026-09-29 15:53:58 +00:00
.forgejo/workflows fix: bump pinned forgejo-workflows renovate.yml to Node 24 fix 2026-09-11 18:06:03 -05:00
api fix: quote OpenAPI summaries containing ?param= inside flow mappings 2026-09-06 11:30:37 -05:00
cmd/server fix: harden Jira issue keys, add container healthcheck, bump vitest 2026-09-19 11:35:06 -05:00
deploy fix: harden Jira issue keys, add container healthcheck, bump vitest 2026-09-19 11:35:06 -05:00
internal fix broken endpoints, add Team management, and improve finding traceability 2026-09-22 20:30:38 -05:00
scripts fix: address final review findings for coverage tracking 2026-09-08 09:58:26 -05:00
web chore(deps): update dependency @tanstack/react-query to v5.104.0 2026-09-26 04:03:12 +00:00
.dockerignore Initial commit 2026-06-29 14:29:06 -05:00
.gitignore fix: address final review findings for coverage tracking 2026-09-08 09:58:26 -05:00
.ojoignore fix: address Balam-triaged vulnerabilities, harden Jira/cookies/k8s/docker 2026-09-08 21:42:05 +00:00
AGENTS.md Initial commit 2026-06-29 14:29:06 -05:00
DESIGN.md Add search/filter handlers, deletion search UX cleanup, and design docs 2026-08-14 11:39:34 -05:00
go.mod fix: address Balam-triaged vulnerabilities, harden Jira/cookies/k8s/docker 2026-09-08 21:42:05 +00:00
go.sum fix: address Balam-triaged vulnerabilities, harden Jira/cookies/k8s/docker 2026-09-08 21:42:05 +00:00
Makefile feat: add Go coverage reporting and wiki history to balam CI 2026-09-07 15:39:15 -05:00
PRODUCT.md Add search/filter handlers, deletion search UX cleanup, and design docs 2026-08-14 11:39:34 -05:00
README.md Update README.md 2026-09-06 17:13:54 +00:00
renovate.json ci: add Renovate for automated dependency updates 2026-09-06 12:55:50 -05:00
STATUS.md fix broken endpoints, add Team management, and improve finding traceability 2026-09-22 20:30:38 -05:00
TODO.md OIDC updates for errors 2026-08-15 13:24:37 -05:00

Balam

Buy Me a Coffee

Self-hosted vulnerability management with a DefectDojo-style API and a modern UI. Go API · PostgreSQL · React/TypeScript frontend.

Features

  • Multi-tenant — every record is isolated by organization; RBAC roles owner > admin > writer > reader.
  • Auth — Argon2id passwords with account lockout, short-lived JWT access tokens, rotating refresh tokens (stored hashed), personal API tokens, and UI-configurable OIDC SSO (PKCE + state + nonce).
  • Resources — product types, products, engagements, tests, findings, endpoints, tags (DefectDojo parity).
  • Scan import — Trivy, Semgrep, and generic SARIF reports, with hash-based finding deduplication.
  • Integrations — Jira and Linear issue creation with status sync-back, Slack notifications. Credentials are encrypted at rest (AES-256-GCM).
  • Security baseline — security headers, rate limiting, audit logging, tenant-scoped data access, secrets never serialized to API clients.

Quick start (local)

# Requires Go 1.24+ and a PostgreSQL instance.
export BALAM_DATABASE_URL="postgres://balam:balam@localhost:5432/balam?sslmode=disable"
export BALAM_JWT_SECRET="$(openssl rand -base64 32)"
make run

On first start the server migrates the schema and bootstraps a default organization plus an admin user (BALAM_BOOTSTRAP_EMAIL / BALAM_BOOTSTRAP_PASSWORD, default [email protected] / admin). Change the admin password immediately in production.

The API is served at /api/v2; interactive docs at /api/v2/oa3/swagger-ui/.

Docker Compose

docker compose -f deploy/docker/docker-compose.yml up --build

Configuration

All configuration is via BALAM_* environment variables:

Variable Default Purpose
BALAM_ENV development production enables HSTS and quiet logs
BALAM_HTTP_ADDR :8080 Listen address
BALAM_DATABASE_URL local postgres DSN PostgreSQL connection
BALAM_JWT_SECRET dev placeholder Required. Signs JWTs and derives the secret-encryption key
BALAM_ACCESS_TOKEN_TTL 15m Access token lifetime
BALAM_REFRESH_TOKEN_TTL 720h Refresh token lifetime
BALAM_PUBLIC_URL http://localhost:8080 Used for OIDC redirect URIs
BALAM_CORS_ORIGINS localhost dev origins Comma-separated allowed origins
BALAM_BOOTSTRAP_EMAIL / _PASSWORD / _ORG admin defaults First-run seed

Development

make build   # compile the server
make test    # run all tests (crypto, parsers, auth, tenant isolation)
make vet     # static analysis

Source of truth for validation is the CLI (go build ./..., go vet ./..., go test ./...). Tests use in-memory SQLite; production runs on PostgreSQL.

Layout

cmd/server          entrypoint (config, migrate, bootstrap, serve)
internal/config     env-driven configuration
internal/models     GORM domain models (OrgScoped tenant boundary)
internal/crypto     Argon2id, AES-256-GCM SecretBox, token hashing
internal/database   connect, AutoMigrate, bootstrap seed
internal/auth       JWT, refresh rotation, API tokens, RBAC, OIDC
internal/api        chi router + middleware + handlers
internal/parsers    scanner import framework (Trivy/Semgrep/SARIF)
internal/integrations  Jira/Linear/Slack + status sync worker
api/openapi.yaml    OpenAPI 3 spec (served via Swagger UI)
web/                React + TypeScript + Vite frontend
deploy/             Docker and Kubernetes manifests

License

GPL-2.0