Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
1552 results
plat:linux-aarch64

Pgp

@hivemq/pgp · v2026.09.11.1789122858

ASCII-armored OpenPGP private key operations via the local gpg binary — inspect, extend expiry, sign-and-verify, upload to keyserver. Runs each invocation against an ephemeral GNUPGHOME so the host keyring is never touched. Auto-detects raw armored or base64-encoded armored key material on import (works around vault providers that strip newlines from multi-line field values).

upd Sep 16109 pullsD50/100

Oci/image/patch

@hivemq/oci/image/patch · v2026.09.11.1789122855

Take a single base OCI image identifier and emit its security-patched counterpart under the HiveMQ naming convention (<registry>/<namespace>/<flattened>:<tag>-hivemq-patched-<date>). A pure logic model (`plan` generates the security-upgrade Dockerfile + derives the re-homed target; `verify` asserts the expected fixed package versions) plus a bundled workflow that orchestrates a container CLI wrapper around it: plan, build the multi-arch image, verify the expected versions on every platform of it, then push. Two workflow variants ship: the Apple @hivemq/container engine (self-hosted macOS) and @hivemq/docker (standard Linux/GitHub-hosted runners). Motivated by PLT-941 (openssl CVE-2026-45447): own the patch cadence instead of waiting on upstream base rebuilds. Registry credentials are injected from a swamp vault at run time and never persisted in a committed instance.

upd Sep 1643 pullsD50/100

Github/merge

@hivemq/github/merge · v2026.08.27.1787839768

GitHub pull-request and file-commit operations. Octokit-backed PR creation, merging, and fan-out across repos, plus gh-CLI-backed commitFile (branch creation + single-file commit) and openPullRequest (PR opening from an existing head→base pair) for one-shot file updates without a local checkout or token. dryRun supported on commitFile and openPullRequest.

upd Sep 1627 pullsD50/100

Docker

@hivemq/docker · v2026.09.11.1789122852

Thin swamp wrapper around the `docker` CLI. Image-lifecycle subset: `build` (single-platform, locally runnable), `run`, `buildInspectPlatforms` (build each arch single-arch with `buildx --load` + run an inspection command, capturing all output in one `inspected` resource — the verify-before-push primitive), `login`, and `buildx build --push` (multi-arch build + push). Each method mirrors a `docker` subcommand so workflows can drive the build/run/publish lifecycle without bespoke shell steps.

upd Sep 165 pullsD50/100

Base Images

@hivemq/base-images · v2026.09.11.1789122846

A declared fleet of base OCI images we keep security-patched. The whole job — what to patch (`source` = registry/repository/tag), how (`patch`, default: apply all pending security updates), where to publish (`destination` = repository/tag under a run-time `registry`), and what to assert (`expect`, optional version floor) — lives in the model instance's `globalArguments.images`, so a single `swamp model method run <instance> patch --input registry=<registry[/namespace]>` builds, verifies, and pushes every image. The destination registry is the `registry` arg (or `globalArguments.registry`), so one instance retargets to a different registry per run. No workflow. Verify is foreknowledge-free (asserts no security updates remain pending on every platform), which fits a scheduled cadence; an optional per-image `expect` adds a version floor. Composes the pure logic of @hivemq/oci/image/patch and the buildx wrapper of @hivemq/docker; it is the only one of the three that drives buildx. Motivated by PLT-941 (openssl CVE-2026-45447): own the patch cadence instead of waiting on upstream base rebuilds.

upd Sep 16109 pullsD50/100

Azure

@dougschaefer/azure · v2026.09.15.1

Azure infrastructure management via az CLI — 43 model types covering compute, networking, data, security, RBAC, Azure Policy, Defender for Cloud, Entra directory, monitoring, DNS, DevOps, Azure AI Foundry (accounts, model deployments, projects, quota), AI Search, Cosmos DB, PostgreSQL Flexible Server, Static Web Apps, Service Bus, Event Grid, Recovery Services, Log Analytics, subscription-wide topology with Mermaid diagrams and cost estimation, actual-spend cost analysis and waste auditing via Cost Management/Resource Graph/Advisor, and the Azure AI Vision Face REST API for identity-aware room services.

upd Sep 1658 pullsA100/100

Git

@swamp/git · v2026.09.15.1

Git repository operations for swamp workflows. Wraps the git CLI

upd Sep 16957 pullsA100/100

Aws Sm

@swamp/aws-sm · v2026.09.15.0

Read, write, and delete secrets stored in AWS Secrets Manager, with support

upd Sep 15738 pullsA100/100

Typesafe Ai

@swamp/typesafe-ai · v2026.09.15.1

Ask TypeSafe's System One models (Jev) typed questions from swamp and

upd Sep 152 pullsA100/100

Reolink

@mgreten/reolink · v2026.09.15.1

Observe and directly synchronize local Reolink camera clocks.

upd Sep 150 pullsB85/100

Snyk/projects

@webframp/snyk/projects · v2026.09.15.1

Snyk Projects — project listing, attributes, relationships, and target management

upd Sep 151 pullsA100/100

Datadog/security Signals

@webframp/datadog/security-signals · v2026.09.15.1

Datadog Security Signals — signal search, triage, and archiving

upd Sep 151 pullsA100/100

Datadog/events

@webframp/datadog/events · v2026.09.15.1

Datadog Events — event search and submission

upd Sep 152 pullsA100/100

Org Simulation

@webframp/org-simulation · v2026.09.15.1

Agent-guided organization design simulation model inspired by the Curious

upd Sep 152 pullsA100/100

Anydoc Ingest

@webframp/anydoc-ingest · v2026.09.15.1

Document-to-knowledge ingestion pipeline powered by Firecrawl's anydoc.

upd Sep 152 pullsA100/100

Datadog/security Rules

@webframp/datadog/security-rules · v2026.09.15.1

Datadog Security Rules — detection rule CRUD and management

upd Sep 151 pullsA100/100

Operator Briefing

@webframp/operator-briefing · v2026.09.15.1

Unified daily operator briefing report. A workflow-scope report over the

upd Sep 1521 pullsA100/100

Ddd Guidance

@webframp/ddd-guidance · v2026.09.15.1

Guides teams through applying Domain-Driven Design to existing projects.

upd Sep 1535 pullsA100/100

Datadog/on Call

@webframp/datadog/on-call · v2026.09.15.1

Datadog On-Call — on-call schedules, escalation policies, and routing

upd Sep 151 pullsA100/100

Threat Model

@webframp/threat-model · v2026.09.15.1

Agile threat modeling as an agent-guided concept model.

upd Sep 1511 pullsA100/100

Datadog/dora

@webframp/datadog/dora · v2026.09.15.1

Datadog DORA Metrics — deployment frequency, lead time, MTTR, and change failure rate

upd Sep 151 pullsA100/100

Datadog/monitors

@webframp/datadog/monitors · v2026.09.15.1

Datadog Monitors — monitor definitions, muting, status, and downtime management

upd Sep 152 pullsA100/100

Datadog/metrics

@webframp/datadog/metrics · v2026.09.15.1

Datadog Metrics — metric queries, submissions, tag configurations, and metadata

upd Sep 155 pullsA100/100

Datadog/downtimes

@webframp/datadog/downtimes · v2026.09.15.1

Datadog Downtimes — scheduled downtime management for monitors

upd Sep 151 pullsA100/100