A high-performance, secure, static cybersecurity leaderboard and automated tracker for CyLab Security Academy / PicoCTF challenges. Features a 3D wireframe interactive scene, custom vector podium chalices, live operator search, tactile Web Audio feedback, and automated stats aggregation.
- Weighted Fair Scoring System:
EASY= 1 PTMEDIUM= 3 PTSHARD= 6 PTS
- 3D Perspective Scene:
- Interactive WebGL/Canvas wireframe globe with orbital rings and mouse parallax.
- Perspective floor grid and geometric tesseract visuals.
- Top 3 Podium Chalices:
- Custom multi-gradient vector chalices for Gold (#1), Silver (#2), and Bronze (#3) with 3D tilt.
- Operator HUD & Drawer:
- Click on any operator to open an inspect drawer with challenge breakdown and academy standing.
- Live Search & Filter:
- Instant client-side search with match counter and keyboard navigation.
- Hardened Architecture:
- Strict Content Security Policy (CSP), anti-MIME sniffing, no-referrer privacy, and DOM-safe encoding.
- Zero sensitive backend endpoints exposed to the browser.
- Automated Hourly Updates:
- GitHub Actions runs every hour or instantly when
roster.txtis updated.
- GitHub Actions runs every hour or instantly when
├── index.html # Main leaderboard frontend
├── styles.css # Cyber dark-mode stylesheet & 3D animations
├── script.js # Web Audio, 3D particles, and client-side rendering
├── ehax-wordmark.png # Transparent brand wordmark
├── logo.png # Brand asset
├── leaderboard.json # Live scored leaderboard data snapshot
├── roster.txt # List of participant usernames (one per line)
├── fetch_stats.py # Automated stats scraper & weighted points engine
├── requirements.txt # Python dependencies
├── vercel.json # Production security headers and route guards
├── .vercelignore # Prevents deployment of backend scripts & roster
├── .github/
│ └── workflows/
│ └── update_leaderboard.yml # Automated CI/CD update workflow
└── README.md # Documentation
The repository is configured to automatically fetch challenge stats and update leaderboard.json:
- Every Hour: On a scheduled cron (
0 * * * *). - On Roster Changes: Automatically triggers whenever usernames are added or removed in
roster.txt. - Manual Trigger: Can be run anytime via the "Run workflow" button in the GitHub Actions tab.
- Navigate to your repository on GitHub:
https://github.com/E-HAX/PicoTracker. - Click Settings (top tab) → Actions (left sidebar) → General.
- Scroll down to Workflow permissions:
- Select Read and write permissions.
- Check Allow GitHub Actions to create and approve pull requests.
- Click Save.
Note: If you only use roster.txt, you can skip this step! The script automatically falls back to roster.txt.
- Go to Settings → Secrets and variables → Actions.
- Click New repository secret.
- Name:
GOOGLE_SHEETS_CREDENTIALS - Value: Paste your Google Service Account JSON key.
- (Optional) Name:
GOOGLE_SHEET_ID, Value: Your spreadsheet ID. - Click Add secret.
- Go to the Actions tab on GitHub.
- Under "All workflows", click Update Leaderboard.
- Click the Run workflow dropdown on the right → Click Run workflow.
- The workflow will execute, scrape the latest solves, calculate weighted points, and commit the updated
leaderboard.json.
To run the static leaderboard locally:
# Start a local HTTP server
python3 -m http.server 8080Open http://localhost:8080 in your browser.
To manually refresh stats from the command line:
pip install -r requirements.txt
python fetch_stats.pyThe site is production-ready for deployment on Vercel:
- Connect the
E-HAX/PicoTrackerrepository to Vercel. - Framework Preset: Other.
- Root Directory:
./. - The bundled
vercel.jsonapplies strict security headers (nosniff,DENY,no-referrer, strict CSP) and blocks direct public access to backend scripts (fetch_stats.py,roster.txt).