taco-nextjs
The web frontend for the TACO platform, served at portal.taco-sec.com.
The web frontend for the TACO platform, served at portal.taco-sec.com.
Overview
| Property | Value |
|---|---|
| Language | TypeScript |
| Framework | Next.js 16, React 19 |
| Port | 3000 |
| Exposed | Via HAProxy at portal.taco-sec.com |
| Dependencies | taco-api, taco-support-bot |
| Repository | tacosec/taco-nextjs |
Tech Stack
- Next.js 16 with React 19
- Tailwind CSS 4 for styling
- Recharts 3 for data visualization (charts, trends)
- Lucide React for icons
- jsPDF + jspdf-autotable for PDF report generation
- xlsx for Excel export
- boneyard-js for UI component patterns
- class-variance-authority + clsx + tailwind-merge for conditional styling
Architecture
taco-nextjs is a server-side rendered Next.js application that acts as the primary user interface. It communicates with taco-api over the internal Docker network (http://taco-api:8090) and with the Discord support bot (http://taco-support-bot:3100).
All API calls are proxied through Next.js server-side routes to avoid exposing the internal API directly to browsers.
Environment Variables
| Variable | Required | Default | Description |
|---|---|---|---|
API_URL | Yes | -- | Internal URL of taco-api (e.g., http://taco-api:8090) |
DISCORD_BOT_URL | No | -- | Internal URL of taco-support-bot |
SUPPORT_WEBHOOK_SECRET | No | -- | Shared secret for support bot communication |
DISCORD_SUPPORT_WEBHOOK_URL | No | -- | Discord webhook URL for support messages |
Key Features
- Dashboard with vulnerability statistics and trend charts
- Project management (create, configure, invite members)
- SBOM viewer with component lists and diff views
- Findings browser with severity filtering, triage workflows, and CVE detail pages
- Secret detection results viewer
- Risk configuration per project
- Alert configuration (Slack, email, webhook, PagerDuty)
- Subscription management with billing (Stripe)
- PDF and Excel export of reports
- OAuth login (GitHub, Google) and email/password authentication
- On-demand scan requests and image scan requests
Build & Deploy
The application is built as a static export (next build) and served by Nginx on port 3000 inside the Docker container.