Ngit CI launches peer compute to replace GitHub builds
- Ngit CI brings automated testing and private code repositories to Nostr.
- Mailstr adds PGP encryption to deliver Nostr messages to standard email inboxes.
- Default app relays and client key leaks reveal persistent infrastructure weak spots.
Software development on Nostr lost its last centralized dependency.
Developers building on Nostr have long faced a major friction point: while code storage could live on relays via NIP-34, continuous integration and build testing still relied on GitHub. With the release of ngit version 3 and ngit CI, host Max explained on Nostr Compass Podcast #39 that developer workflows can now run end-to-end without touching Microsoft servers. Grasp servers now enforce private repositories using NIP-42 authentication, while the new CI runner operates an open compute marketplace where developers can rent idle server capacity for micro-VM test runs.
The push to replace legacy productivity tools extends beyond code hosting into routine business messaging. Mailstr integrated PGP end-to-end encryption into its protocol, enabling Nostr applications to send encrypted messages directly to standard email providers like Proton Mail. On Nostr Compass Podcast #40, Formstr co-founder Form announced that guest invitations for calendar events and file sharing now route directly into external inboxes. Users no longer need to ensure their contacts hold a Nostr public key before sending sensitive communications.
Simultaneously, encrypted group communications crossed a crucial maturity threshold. The release of Marmot DevKit 0.10.4 delivered cross-language interoperability across Rust, C#, and Kotlin codebases. As detailed on Nostr Compass Podcast #41, clients like White Noise, Scramble, and Amethyst can now coordinate encrypted group chats, conduct polls using NIP-88, and process admin deletions without relying on central relay coordination servers.
Yet rapid expansion at the application layer continues to collide with client-side security risks. A critical flaw in Nostr client Linky exposed recovery seeds directly to the company's central servers whenever users attempted to export credentials to password managers. Host Max urged users on Nostr Compass Podcast #40 to take immediate precautions while highlighting Linky's version 26.9.17 emergency patch, which explicitly hardens seed saving paths and disables Android cloud backups to prevent hardware key leakage.
Beyond client software bugs, protocol structural integrity remains threatened by user reliance on default hosted relays. Apps like Primal, Damus, and Ditto onboard millions of users, but standard configurations route traffic through a handful of centralized relay clusters. Developer Sam introduced RelayKit on Nostr Compass Podcast #41 to counter this consolidation, bundling personal relays, Blossom media hosting, and local testing environments into single-command deployments for virtual private servers.
These infrastructure tools are steadily hardening remote node management and browser-based publishing. Nsite-clay now lets site owners edit static web pages directly inside the browser and publish signed manifest events to Blossom servers without running a backend. On the system level, FIPS-initramfs embeds a peer-to-peer mesh daemon into unencrypted Linux boot partitions, allowing operators to deliver LUKS disk decryption keys over firewalled networks without static public IPs.
Protocol sovereignty depends entirely on who controls the relays.
Source Intelligence
- Deep dive into what was said in the episodes
Nostr Compass Podcast #40 • Oct 1
- Max highlights major updates to Marmot-based applications. MDK version 0.10.0 moves username display and logic into the library core to simplify frontend implementations, while Myco version 0.7.0 introduces full support for single-file NIP-5D napplets over localized mesh networks.
- The Formstr team integrated Mailstr into its calendar application to send guest invitations without external email accounts. Infinity x2 details Mailstr's new PGP support, enabling end-to-end encrypted communication directly with external providers like Proton Mail.
- Max details a severe vulnerability in Linky version 26.9.17 where saving a recovery seed to a password manager inadvertently leaked credentials to Linky's servers. The update disables Android backups and hardens key storage to prevent data leakage.
- Nostr's decentralized Git ecosystem achieved several milestones, including Gittr’s stable version 1.0.0 release. Git Workshop version 4.1.0 introduced local recoverable drafts that survive browser restarts, and NGIT CI version 0.1.1 released a continuous integration client featuring micro VM execution.
- The Marmot group messaging specification clarified its key package flow, declaring that read-only NIP-65 entries cannot be key package destinations. A new moderation proposal introduces kind 1,984 encrypted group reports, allowing administrators to delete messages using kind 4,891 events.
Also discussed on this episode: (6)
Nostr (6)
- LibreNostr version 0.5.17 optimizes outbox model efficiency by querying NIP-65 write relays directly and delaying interaction counts until notes enter the viewport. Additionally, Nostr Relay improved its Redis database performance across multiple concurrent relay processes.
- Postr version 1.1.1 introduced local speech-to-text dictation, and Voca version 1.2.0 added debug logging via anonymous NIP-17 DMs. Concurrently, routstrd version 0.4.10, the decentralized AI inference marketplace, updated its CLI with endpoint nicknames and scheduled refresh controls.
- A flurry of Nostr Improvement Proposals includes NIP-CD for executing slash commands, and NIP-90's addition of expiration tags to Data Vending Machine heartbeats. NIP-F5 proposes a permissioned FIPS transport window for web apps to request origin-bound database access.
- The Nostr Wallet Connect protocol merged updates for payment lookups, enabling transactions to be searched by hash or invoice while adding draft BOLT12 payment records. A client-initiated connection proposal allows clients to generate secrets and negotiate permissions over HTTP.
- Max explains NIP-23 replaceable kind 30,023 events, which allow long articles to be edited over time using a stable D tag identifier. This standard fully renders markdown, strictly forbids HTML, and relies on NIP-22 comments for handling replies.
- NIP-92 standardizes imeta tags in Nostr events to optimize media loading times and user experiences. These tags borrow fields from NIP-94, such as dimensions for layout blocking, blur hashes for instant visual previews, and fallback Blossom server URLs.
Nostr Compass Podcast #39 • Oct 1
- Max highlights the version 3 release of ngit, which introduces private repositories to its Grasp servers. The system uses NIP-42 authentication to restrict repository data access to whitelisted public keys.
- Max highlights the release of ngit CI version 0.1, a continuous integration system running natively over Nostr. This architecture enables self-hosted runner owners to sell idle compute capacity on an open marketplace.
- Max details nsite-clay, a tool that allows users to edit Nostr-native static websites directly from their browsers. The tool saves code updates to Blossom and publishes a new root manifest event to Nostr relays.
Also discussed on this episode: (6)
Nostr (6)
- Max reports that Nostr clients Amethyst, Grimoire, and Pollerama implemented NIP-A3 payment targets. This protocol extension allows creators to set a fundraising goal in satoshis and track funding progress percentages.
- Nostr clients are adopting Blossom fallback and mirroring schemes. Max explains that these mechanisms route uploads to secondary servers during outages and duplicate blobs across multiple servers to ensure long-term data preservation.
- Specification updates in the NIPs repository clarify filter rules and application data security. Max notes that NIP-01 now defines the limit zero filter, while NIP-78 recommends requiring NIP-42 authentication to restrict application data access.
- Max introduces NIP-AC, a proposal for open WebRTC signaling using ephemeral Nostr kinds for connection handshakes. Relays must broadcast these kind 30600 events to active peers but are prohibited from storing them.
- Max analyzes NIP-21, which standardizes native Nostr URI schemes like npubs and nevents to enable deep linking across OS applications. The standard explicitly excludes private keys to prevent accidental credential leakage.
- Max outlines NIP-27, which details how clients should parse NIP-21 URIs inside event content to display human-readable names. Implementing clients are advised to append corresponding tags to the event to trigger notifications.
Nostr Compass Podcast #41 • Oct 1
- Sam designed RelayKit to simplify running self-hosted Nostr infrastructure on cheap virtual private servers. It acts as an easy-to-use hosting stack and provides developers with a local, modular testing environment to avoid polluting the main network.
- The Marmot Protocol ecosystem achieved multi-client interoperability across distinct codebases, including White Noise in Rust, Scramble in C#, and Amethyst in Kotlin. The Marmot DevKit version 0.10.4 update also resolved a critical bug that caused repeated automatic attachment downloads.
Also discussed on this episode: (10)
Privacy (2)
- Max highlights FIPS-initramfs, a tool that lets users remotely decrypt Linux disks behind firewalls on boot. It hosts a tiny daemon in an unencrypted partition, listening for a whitelisted public key over the FIPS mesh network without requiring a public IP.
- Amber version 6.6.5 improves local security by encrypting application backups with dedicated keys derived from the user's account key. This prevents applications with remembered NIP-44 decryption permissions from reading raw backup payloads.
Nostr (8)
- The Nostr Web of Trust SDK version 1.0.2 introduced a new graph engine that batches up to 100 authors per relay request and compresses edge data using delta encoding. This toolkit helps applications efficiently crawl, store, and query the Nostr follow graph.
- Nostr Mail client version 0.16.0 introduced per-recipient delivery controls, allowing senders to mix SMTP email and Nostr delivery in a single thread. The update also mandates that every user account establish and maintain an active relay list.
- NIP-30 standardizes custom emojis on Nostr using kind 30,030 parameterized replaceable events. These events store alphanumeric shortcodes mapped to external image or GIF links, which clients can cache locally to render reactions efficiently.
- NIP-71 establishes dedicated event types for video content, assigning kind 21 for horizontal videos and kind 22 for portrait videos. The spec relies on mandatory i-meta tags to define media types, URLs, file hashes, and resolutions.
- Amethyst version 1.16.0 added support for BOLT12 lightning offers in its profile payment and Zap Picker interfaces. The client also integrated Deck3, a 3D mesh format utilizing kind 11333 for avatars and kind 3330 for mesh shards.
- The proposed NWC13 specification introduces a get budget permission for Nostr Wallet Connect. This allows connected applications to query spending limits and remaining allowances without granting them visibility into the user's total wallet balance.
- Citrine version 3.2.0 optimized its performance as an Android-based Nostr relay by streaming matching events in batches. The update limits aggregator fan-out to 200 relays and bounds caches to prevent high-volume queries from exhausting memory.
- Nostream merged relay monitoring updates based on NIP-66 and introduced an adaptive proof-of-work mechanism. This mechanism dynamically reduces the proof-of-work requirements for clients with high-ranking web of trust scores.
