Ngit launches native CI on Nostr to rival GitHub
- Ngit version 3 and Ngit CI bring native automated testing and private repositories to Nostr.
- Gittr 1.0 and micro VM runners allow developers to host and test code outside GitHub.
- Mailstr adds PGP encryption, letting Nostr applications email external providers like ProtonMail.
GitHub's chokehold on software infrastructure is slipping. On Nostr Compass, host Max detailed how the launch of Ngit CI version 0.1 brings automated continuous integration natively onto the Nostr protocol.
Code hosting without testing was always half a solution. The rollout of Ngit version 3 introduced private repositories to Grasp servers using NIP-42 authentication for whitelist access. Developers can now run internal code syncing, manage issues, and trigger containerized testing pipelines before publishing open-source releases to relays.
"Automated testing was long the primary barrier holding developers back on GitHub."
- Max, Nostr Compass
The technical architecture relies on micro VMs and signed workflow coordination. According to Max on Nostr Compass, Ngit CI version 0.1.1 establishes an open compute marketplace where idle server operators can rent execution capacity directly to open-source projects. For teams unwilling to migrate fully, dedicated bridging tools now post cryptographic Nostr proof events for builds completed on legacy GitHub runners.
The broader developer stack on Nostr is settling into production readiness. Gittr published its version 1.0.0 release, bringing NIP-34 code collaboration into stable operation, while Git Workshop version 4.1.0 added offline recoverable pull request drafts. Together, these releases replace central code repositories with signed protocol events distributed across relay networks.
Protocol independence is spilling over from code repos into general productivity. Formstr co-founder Form announced on Nostr Compass that Mailstr PGP encryption is being integrated across Formstr Drive and Calendar applications. The integration allows Nostr users to send encrypted guest invitations and notifications directly to traditional inbox providers like ProtonMail without requiring recipient public keys.
Yet rapid client development brings acute operational risks. Max highlighted a severe vulnerability in Linky version 26.9.17, where user recovery seeds intended for local password managers were inadvertently transmitted to company servers. Linky released an urgent patch disabling cloud backups and hardening local storage, proving that client UI complexity remains decentralized software's weakest attack surface.
"The slip highlights the persistent risk of wrapping non-custodial crypto and identity tools in complex client-side user interfaces."
- Max, Nostr Compass
Sovereign development tools no longer require compromise. With native testing, encrypted repositories, and open compute markets now online, the migration away from centralized code hubs has shifted from theory to working code.
Source Intelligence
- Deep dive into what was said in the episodes
Nostr Compass Podcast #40 • Oct 1
- The Formstr team integrated Mailstr into its calendar application to send guest invitations without external email accounts. Infinity x2 details Mailstr's new PGP support, enabling end-to-end encrypted communication directly with external providers like Proton Mail.
- Max details a severe vulnerability in Linky version 26.9.17 where saving a recovery seed to a password manager inadvertently leaked credentials to Linky's servers. The update disables Android backups and hardens key storage to prevent data leakage.
- Nostr's decentralized Git ecosystem achieved several milestones, including Gittr’s stable version 1.0.0 release. Git Workshop version 4.1.0 introduced local recoverable drafts that survive browser restarts, and NGIT CI version 0.1.1 released a continuous integration client featuring micro VM execution.
Also discussed on this episode: (8)
Nostr (8)
- Max highlights major updates to Marmot-based applications. MDK version 0.10.0 moves username display and logic into the library core to simplify frontend implementations, while Myco version 0.7.0 introduces full support for single-file NIP-5D napplets over localized mesh networks.
- LibreNostr version 0.5.17 optimizes outbox model efficiency by querying NIP-65 write relays directly and delaying interaction counts until notes enter the viewport. Additionally, Nostr Relay improved its Redis database performance across multiple concurrent relay processes.
- Postr version 1.1.1 introduced local speech-to-text dictation, and Voca version 1.2.0 added debug logging via anonymous NIP-17 DMs. Concurrently, routstrd version 0.4.10, the decentralized AI inference marketplace, updated its CLI with endpoint nicknames and scheduled refresh controls.
- A flurry of Nostr Improvement Proposals includes NIP-CD for executing slash commands, and NIP-90's addition of expiration tags to Data Vending Machine heartbeats. NIP-F5 proposes a permissioned FIPS transport window for web apps to request origin-bound database access.
- The Marmot group messaging specification clarified its key package flow, declaring that read-only NIP-65 entries cannot be key package destinations. A new moderation proposal introduces kind 1,984 encrypted group reports, allowing administrators to delete messages using kind 4,891 events.
- The Nostr Wallet Connect protocol merged updates for payment lookups, enabling transactions to be searched by hash or invoice while adding draft BOLT12 payment records. A client-initiated connection proposal allows clients to generate secrets and negotiate permissions over HTTP.
- Max explains NIP-23 replaceable kind 30,023 events, which allow long articles to be edited over time using a stable D tag identifier. This standard fully renders markdown, strictly forbids HTML, and relies on NIP-22 comments for handling replies.
- NIP-92 standardizes imeta tags in Nostr events to optimize media loading times and user experiences. These tags borrow fields from NIP-94, such as dimensions for layout blocking, blur hashes for instant visual previews, and fallback Blossom server URLs.
Nostr Compass Podcast #39 • Oct 1
- Max highlights the version 3 release of ngit, which introduces private repositories to its Grasp servers. The system uses NIP-42 authentication to restrict repository data access to whitelisted public keys.
- Max highlights the release of ngit CI version 0.1, a continuous integration system running natively over Nostr. This architecture enables self-hosted runner owners to sell idle compute capacity on an open marketplace.
Also discussed on this episode: (7)
Nostr (7)
- Max details nsite-clay, a tool that allows users to edit Nostr-native static websites directly from their browsers. The tool saves code updates to Blossom and publishes a new root manifest event to Nostr relays.
- Max reports that Nostr clients Amethyst, Grimoire, and Pollerama implemented NIP-A3 payment targets. This protocol extension allows creators to set a fundraising goal in satoshis and track funding progress percentages.
- Nostr clients are adopting Blossom fallback and mirroring schemes. Max explains that these mechanisms route uploads to secondary servers during outages and duplicate blobs across multiple servers to ensure long-term data preservation.
- Specification updates in the NIPs repository clarify filter rules and application data security. Max notes that NIP-01 now defines the limit zero filter, while NIP-78 recommends requiring NIP-42 authentication to restrict application data access.
- Max introduces NIP-AC, a proposal for open WebRTC signaling using ephemeral Nostr kinds for connection handshakes. Relays must broadcast these kind 30600 events to active peers but are prohibited from storing them.
- Max analyzes NIP-21, which standardizes native Nostr URI schemes like npubs and nevents to enable deep linking across OS applications. The standard explicitly excludes private keys to prevent accidental credential leakage.
- Max outlines NIP-27, which details how clients should parse NIP-21 URIs inside event content to display human-readable names. Implementing clients are advised to append corresponding tags to the event to trigger notifications.
