taco-nextjs

The web frontend for the TACO platform, served at portal.taco-sec.com.

The web frontend for the TACO platform, served at portal.taco-sec.com.

Overview

PropertyValue
LanguageTypeScript
FrameworkNext.js 16, React 19
Port3000
ExposedVia HAProxy at portal.taco-sec.com
Dependenciestaco-api, taco-support-bot
Repositorytacosec/taco-nextjs

Tech Stack

  • Next.js 16 with React 19
  • Tailwind CSS 4 for styling
  • Recharts 3 for data visualization (charts, trends)
  • Lucide React for icons
  • jsPDF + jspdf-autotable for PDF report generation
  • xlsx for Excel export
  • boneyard-js for UI component patterns
  • class-variance-authority + clsx + tailwind-merge for conditional styling

Architecture

taco-nextjs is a server-side rendered Next.js application that acts as the primary user interface. It communicates with taco-api over the internal Docker network (http://taco-api:8090) and with the Discord support bot (http://taco-support-bot:3100).

All API calls are proxied through Next.js server-side routes to avoid exposing the internal API directly to browsers.

Environment Variables

VariableRequiredDefaultDescription
API_URLYes--Internal URL of taco-api (e.g., http://taco-api:8090)
DISCORD_BOT_URLNo--Internal URL of taco-support-bot
SUPPORT_WEBHOOK_SECRETNo--Shared secret for support bot communication
DISCORD_SUPPORT_WEBHOOK_URLNo--Discord webhook URL for support messages

Key Features

  • Dashboard with vulnerability statistics and trend charts
  • Project management (create, configure, invite members)
  • SBOM viewer with component lists and diff views
  • Findings browser with severity filtering, triage workflows, and CVE detail pages
  • Secret detection results viewer
  • Risk configuration per project
  • Alert configuration (Slack, email, webhook, PagerDuty)
  • Subscription management with billing (Stripe)
  • PDF and Excel export of reports
  • OAuth login (GitHub, Google) and email/password authentication
  • On-demand scan requests and image scan requests

Build & Deploy

The application is built as a static export (next build) and served by Nginx on port 3000 inside the Docker container.