Skip to content
Kodvalley

Open source

Our code on GitHub and GitLab

We publish tools, packages and examples from our engineering and security work, and run client projects on the same Git platforms.

GitHub kodvalley

Public repositories, packages and examples, with issues and pull requests open to everyone.

  • Laravel and Filament packages
  • Security tooling and scripts
  • GitHub Actions workflows
  • Code examples from our articles
GitLab kodvalley

Client delivery, private registries and CI/CD pipelines, including self managed GitLab for clients who need it.

  • Private client repositories
  • GitLab CI/CD pipelines
  • Container and package registries
  • Self managed GitLab setup

What we publish

Useful parts of our daily work

When something we build could help others, we clean it up, document it and release it.

Packages

Reusable Laravel, PHP and JavaScript packages with tests and documentation.

Security tools

Scripts and checklists from our penetration tests and hardening projects.

Infrastructure

Server setup, deployment and monitoring scripts for Linux environments.

Templates

Starter projects and UI components that follow our own coding standards.

Client projects

A Git workflow you can audit

Every client project lives in a repository you can access, on GitHub or GitLab.

  1. Branches

    Each feature and fix is developed on its own branch.

  2. Merge requests

    Changes are reviewed by a second engineer before they are merged.

  3. Automated checks

    Tests, linting and builds run on every push.

  4. Security scans

    Dependency and secret scanning catch issues before release.

  5. Deployment

    Releases are tagged and deployed by the pipeline, with a rollback path.

Principles

How we handle open source

Clear licences
Every public repository states its licence, usually MIT.
Responsible disclosure
Security issues are reported privately and fixed before details are published.
Your code stays yours
Client code is never published without written permission.
Contributions welcome
Issues and pull requests are reviewed by the team that wrote the code.