{"id":19601294,"url":"https://github.com/lukasz-zimnoch/dexly","last_synced_at":"2026-05-12T22:39:16.635Z","repository":{"id":218155232,"uuid":"322021495","full_name":"lukasz-zimnoch/dexly","owner":"lukasz-zimnoch","description":"Playground crypto trading bot leveraging the cloud-native architecture and modern DevOps toolset.","archived":false,"fork":false,"pushed_at":"2021-06-29T09:33:05.000Z","size":366,"stargazers_count":2,"open_issues_count":0,"forks_count":1,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-08-03T00:08:50.012Z","etag":null,"topics":["ci-cd","cloud-native","cryptocurrency","devops","go","google-cloud-platform","microservices","terraform"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/lukasz-zimnoch.png","metadata":{"files":{"readme":"README.adoc","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-12-16T15:20:38.000Z","updated_at":"2023-06-22T13:59:24.000Z","dependencies_parsed_at":null,"dependency_job_id":"5cd71f52-be6e-471b-9a30-cc2c3a6b10f4","html_url":"https://github.com/lukasz-zimnoch/dexly","commit_stats":null,"previous_names":["lukasz-zimnoch/dexly"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/lukasz-zimnoch/dexly","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lukasz-zimnoch%2Fdexly","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lukasz-zimnoch%2Fdexly/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lukasz-zimnoch%2Fdexly/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lukasz-zimnoch%2Fdexly/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/lukasz-zimnoch","download_url":"https://codeload.github.com/lukasz-zimnoch/dexly/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lukasz-zimnoch%2Fdexly/sbom","scorecard":{"id":604117,"data":{"date":"2025-08-11","repo":{"name":"github.com/lukasz-zimnoch/dexly","commit":"06efdfc77c74b9f7372327b291da3a67c8fa4b67"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.9,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/trading.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":0,"reason":"license file not detected","details":["Warn: project does not have a license file"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trading.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trading.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trading.yaml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trading.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trading.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trading.yaml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trading.yaml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/trading.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trading.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trading.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/lukasz-zimnoch/dexly/trading.yaml/master?enable=pin","Warn: containerImage not pinned by hash: trading/Dockerfile:1","Warn: containerImage not pinned by hash: trading/Dockerfile:17: pin your Docker image by updating alpine:3.13 to alpine:3.13@sha256:469b6e04ee185740477efa44ed5bdd64a07bbdd6c7e5f5d169e540889597b911","Info:   0 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":8,"reason":"2 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2024-2605 / GHSA-m7wr-2xf7-cm9p","Warn: Project is vulnerable to: GO-2024-2606 / GHSA-mrww-27vc-gghv"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T01:11:13.529Z","repository_id":218155232,"created_at":"2025-08-21T01:11:13.529Z","updated_at":"2025-08-21T01:11:13.529Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32960295,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-12T09:19:52.626Z","status":"ssl_error","status_checked_at":"2026-05-12T09:17:33.438Z","response_time":102,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ci-cd","cloud-native","cryptocurrency","devops","go","google-cloud-platform","microservices","terraform"],"created_at":"2024-11-11T09:17:56.404Z","updated_at":"2026-05-12T22:39:16.614Z","avatar_url":"https://github.com/lukasz-zimnoch.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":":toc: macro\n\n= Dexly\n\nCryptocurrency trading bot.\n\ntoc::[]\n\n== Cloud infrastructure\n\nThis project contains the configuration of Google Cloud Platform infrastructure\nneeded to run all components in a seamless way.\n\n=== Prerequisites\n\nTo configure the infrastructure on GCP, you will need to:\n\n1. Configure your https://cloud.google.com[account] and\n   https://cloud.google.com/resource-manager/docs/creating-managing-projects[project].\n2. Create a https://cloud.google.com/iam/docs/creating-managing-service-accounts[service account]\n   for Terraform. For simplicity, give it the project's owner role and generate an\n   https://cloud.google.com/iam/docs/creating-managing-service-account-keys[account key].\n   Download the account key and keep it safe, somewhere on your local machine.\n3. Install https://www.terraform.io/[Terraform] (at least 0.15.1) on your\n   local machine.\n\n=== Create infrastructure components\n\nFirst, set the `GOOGLE_CREDENTIALS` environment variable to point to your\nservice account key path, by doing:\n```\nexport GOOGLE_CREDENTIALS=\u003cservice-account-key\u003e\n```\n\nThen, you need to perform an one-off initialization of the remote state bucket.\nMove to the `infrastructure/terraform/remote-state` directory and invoke:\n```\nterraform init \u0026\u0026 terraform apply\n```\n\nA Google Cloud bucket will be created. Terraform will use it to store its state.\nYou can now start creating all cloud resources by moving to the\n`infrastructure/terraform` directory and invoking:\n```\nterraform init \u0026\u0026 terraform apply\n```\n\nOnce the process terminates, all cloud resources should be up and running.\nPlease note the outputs as they may be needed in further steps.\n\n=== Destroy infrastructure components\n\nYou can quickly destroy all cloud resources by doing:\n```\nterraform destroy\n```\nRemember about setting the service account key path via the `GOOGLE_CREDENTIALS`\nvariable.\n\n== Continuous integration\n\nThis project uses GitHub Actions as continuous integration runner. Each service\ncontains its workflow definition defined in the `.github/workflows` directory.\n\nEach workflow consists of several jobs:\n\n- `build` which builds the microservice code. This job is performed on all pushes\n  and pull requests.\n- `test` which performs unit and integration tests. This job is performed on all\n  pushes and pull requests.\n- `publish` which builds the Docker image and publishes it to the registry. This\n  job is performed *only* on pushes to the master branch. It also updates the\n  image digest in the Kubernetes manifest and commits that change.\n\nThe above jobs need several secrets to be defined in the repository settings:\n\n- `DOCKER_REGISTRY_URL` which should point to the registry URL.\n- `DOCKER_REPOSITORY_ID` which should contain the image repository name.\n- `DOCKER_REGISTRY_KEY` which should contain the registry key in JSON format.\n\n== Continuous deployment\n\nRegarding continuous deployment, several crucial components are configured\nas part of the infrastructure described in \u003c\u003cCloud infrastructure\u003e\u003e section.\nThose components are:\n\n- GCR which serves as target repository for images built during the `publish`\n  job described in \u003c\u003cContinuous integration\u003e\u003e section.\n- GKE cluster used as environment for containerized services.\n- ArgoCD which is a GitOps delivery tool for Kubernetes\n\nThose parts work together to continuously deploy services as soon as new\ncode lands on master. Everything starts once the `publish` job pushes the new\nimage to GCR and commits the image digest change made in the service manifest.\nArgoCD observes the cluster state and compares it against the source Git\nrepository, as defined in the `infrastructure/helm/argo-applications` chart.\nIn case of divergence (e.g. new image digest is used), ArgoCD makes efforts\nto move the cluster to the desired state. This way microservices are deployed\nin a fully-automated and continuous way.\n\n// TODO: Complete readme.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flukasz-zimnoch%2Fdexly","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Flukasz-zimnoch%2Fdexly","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flukasz-zimnoch%2Fdexly/lists"}