Price:

Nostr deploys decentralized testing engines to challenge GitHub

Oct 2, 2026Summary from 1 podcast.
  • Ngit launches native Nostr continuous integration to compete with GitHub repos.
  • Mailstr adds PGP encryption to send Nostr messages to ProtonMail inboxes.
  • Linky patches a flaw that leaked seed phrases to centralized server backends.

Nostr is expanding into core developer infrastructure.

Developers are launching decentralized continuous integration systems directly over Nostr relays to replace centralized platforms like GitHub. On Nostr Compass, host Max outlined how ngit version 3 introduced private code repositories using NIP-42 authentication on Grasp servers, letting engineering teams restrict access via public key whitelists. The protocol now runs ngit CI version 0.1, establishing an open compute marketplace where node operators rent idle server capacity to execute automated software test suites.

Code collaboration protocols reached production stability with the release of Gittr 1.0. Max explained on Nostr Compass that NIP-34 tooling now supports recoverable offline drafts for pull requests and code reviews through Git Workshop 4.1.0. Updated NGIT CI runners handle containerized execution, signed workflow coordination, and encrypted repository secrets tied directly to maintainer cryptographic signatures.

For engineering groups maintaining hybrid setups, build bridges now transmit cryptographic execution proofs from GitHub back to Nostr relays. The shift comes two weeks after Napster leveraged Nostr relays for peer discovery, extending the protocol's scope from ephemeral file sharing to full-stack developer tooling.

The protocol's reach is also expanding beyond git repositories into secure communication hubs. Through PGP integration in Mailstr and Nail protocols, Nostr clients can now send end-to-end encrypted emails directly to traditional providers like ProtonMail. Formstr co-founder Form announced on Nostr Compass that the team is embedding Mailstr across its productivity suite, enabling users to send calendar invitations to external email addresses without leaving Nostr.

Web publishing workflows are eliminating traditional server management alongside code repositories. Max highlighted nsite-clay on Nostr Compass, a client-side tool allowing site owners to edit static web pages directly in the browser. Updated assets are uploaded to Blossom storage servers before publishing a signed root manifest event to relays, removing the need for dedicated build pipelines or WordPress-style backend servers.

Rapid infrastructure expansion, however, carries client-side security risks. Max reported on Nostr Compass that messaging and payments app Linky released version 26.9.17 to patch a severe credential flaw. The application had accidentally transmitted wallet recovery seeds to central servers when users saved backup phrases to password managers, prompting emergency updates to disable cloud backups and harden local key storage.

Decentralized developer tools are dismantling traditional platform lock-in.

Source Intelligence

- Deep dive into what was said in the episodes

Nostr Compass Podcast #40 • Oct 1

  • The Formstr team integrated Mailstr into its calendar application to send guest invitations without external email accounts. Infinity x2 details Mailstr's new PGP support, enabling end-to-end encrypted communication directly with external providers like Proton Mail.
  • Max details a severe vulnerability in Linky version 26.9.17 where saving a recovery seed to a password manager inadvertently leaked credentials to Linky's servers. The update disables Android backups and hardens key storage to prevent data leakage.
  • Nostr's decentralized Git ecosystem achieved several milestones, including Gittr’s stable version 1.0.0 release. Git Workshop version 4.1.0 introduced local recoverable drafts that survive browser restarts, and NGIT CI version 0.1.1 released a continuous integration client featuring micro VM execution.
Also discussed on this episode: (8)

Nostr (8)

  • Max highlights major updates to Marmot-based applications. MDK version 0.10.0 moves username display and logic into the library core to simplify frontend implementations, while Myco version 0.7.0 introduces full support for single-file NIP-5D napplets over localized mesh networks.
  • LibreNostr version 0.5.17 optimizes outbox model efficiency by querying NIP-65 write relays directly and delaying interaction counts until notes enter the viewport. Additionally, Nostr Relay improved its Redis database performance across multiple concurrent relay processes.
  • Postr version 1.1.1 introduced local speech-to-text dictation, and Voca version 1.2.0 added debug logging via anonymous NIP-17 DMs. Concurrently, routstrd version 0.4.10, the decentralized AI inference marketplace, updated its CLI with endpoint nicknames and scheduled refresh controls.
  • A flurry of Nostr Improvement Proposals includes NIP-CD for executing slash commands, and NIP-90's addition of expiration tags to Data Vending Machine heartbeats. NIP-F5 proposes a permissioned FIPS transport window for web apps to request origin-bound database access.
  • The Marmot group messaging specification clarified its key package flow, declaring that read-only NIP-65 entries cannot be key package destinations. A new moderation proposal introduces kind 1,984 encrypted group reports, allowing administrators to delete messages using kind 4,891 events.
  • The Nostr Wallet Connect protocol merged updates for payment lookups, enabling transactions to be searched by hash or invoice while adding draft BOLT12 payment records. A client-initiated connection proposal allows clients to generate secrets and negotiate permissions over HTTP.
  • Max explains NIP-23 replaceable kind 30,023 events, which allow long articles to be edited over time using a stable D tag identifier. This standard fully renders markdown, strictly forbids HTML, and relies on NIP-22 comments for handling replies.
  • NIP-92 standardizes imeta tags in Nostr events to optimize media loading times and user experiences. These tags borrow fields from NIP-94, such as dimensions for layout blocking, blur hashes for instant visual previews, and fallback Blossom server URLs.

Nostr Compass Podcast #39 • Oct 1

  • Max highlights the version 3 release of ngit, which introduces private repositories to its Grasp servers. The system uses NIP-42 authentication to restrict repository data access to whitelisted public keys.
  • Max highlights the release of ngit CI version 0.1, a continuous integration system running natively over Nostr. This architecture enables self-hosted runner owners to sell idle compute capacity on an open marketplace.
  • Max details nsite-clay, a tool that allows users to edit Nostr-native static websites directly from their browsers. The tool saves code updates to Blossom and publishes a new root manifest event to Nostr relays.
Also discussed on this episode: (6)

Nostr (6)

  • Max reports that Nostr clients Amethyst, Grimoire, and Pollerama implemented NIP-A3 payment targets. This protocol extension allows creators to set a fundraising goal in satoshis and track funding progress percentages.
  • Nostr clients are adopting Blossom fallback and mirroring schemes. Max explains that these mechanisms route uploads to secondary servers during outages and duplicate blobs across multiple servers to ensure long-term data preservation.
  • Specification updates in the NIPs repository clarify filter rules and application data security. Max notes that NIP-01 now defines the limit zero filter, while NIP-78 recommends requiring NIP-42 authentication to restrict application data access.
  • Max introduces NIP-AC, a proposal for open WebRTC signaling using ephemeral Nostr kinds for connection handshakes. Relays must broadcast these kind 30600 events to active peers but are prohibited from storing them.
  • Max analyzes NIP-21, which standardizes native Nostr URI schemes like npubs and nevents to enable deep linking across OS applications. The standard explicitly excludes private keys to prevent accidental credential leakage.
  • Max outlines NIP-27, which details how clients should parse NIP-21 URIs inside event content to display human-readable names. Implementing clients are advised to append corresponding tags to the event to trigger notifications.