Nostr developers release ngit CI to challenge GitHub
- Open-source developers launched ngit CI to run automated builds over decentralized Nostr relays.
- Formstr integrated Mailstr PGP encryption to let Nostr apps email external providers like ProtonMail.
- Gittr 1.0 stabilized NIP-34 code collaboration with recoverable drafts and encrypted repo secrets.
GitHub's control over software pipelines is starting to fracture.
Host Max detailed the launch of ngit version 3 and ngit CI on Nostr Compass. The update introduces private repositories powered by Grasp servers, using NIP-42 authentication to enforce whitelist access. Developers can sync multi-device code, manage pull requests, and run continuous integration directly over Nostr relays. To solve the compute bottleneck, the runner establishes a marketplace where developers rent out idle server capacity for automated build checks.
Execution pipelines expanded rapidly in follow-up releases. Gittr reached its 1.0.0 milestone, establishing production stability for NIP-34 code collaboration protocols. Git Workshop added recoverable local drafts to protect against network drops, while the NGIT CI package introduced container execution, signed workflows, and encrypted repository secrets tied to maintainer signatures. For teams maintaining hybrid setups, bridging tools now post cryptographic build proof back to Nostr while running builds on GitHub.
Protocol interoperability extended beyond code repositories into standard productivity tools. Formstr co-founder Form announced on Nostr Compass that his team is embedding Mailstr across its application suite. By wrapping messages in PGP end-to-end encryption, Nostr clients can deliver invites and notifications directly to traditional email providers like ProtonMail without requiring external users to hold a Nostr key.
Web publishing is undergoing a parallel shift toward local execution. The release of nsite-clay introduced client-side editing for Nostr-hosted websites using Blossom relays for asset storage. Site owners authenticate with cryptographic keys, edit page code directly in the browser, and publish updated root manifests without maintaining traditional backend servers or complex deployment pipelines.
Infrastructure expansion has not come without security stumbles. Messaging and payments client Linky issued an urgent patch, version 26.9.17, after discovering that user seed phrases intended for password managers were transmitted to central servers. Host Max warned long-time users to review their setups as the patch hardened seed storage and cut off Android cloud backups.
Decentralized development tools are moving from experimental proofs to working infrastructure.