Detect GitHub Actions Supply-Chain Risks with Gemini & Slack
Detect GitHub Actions Supply-Chain Risks with Gemini & Slack
Regular price
£45.99
Regular price
£45.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
Detect GitHub Actions Supply-Chain Risks with Gemini & Slack
Regular price
£45.99
Regular price
£45.99
Sale price
Unit price
/
per
Detect GitHub Actions supply-chain risks and get instant Slack alerts—automatically
This n8n workflow scans your GitHub Actions workflows every day, detects supply-chain risk patterns (including unpinned uses: references), uses Google Gemini to generate a structured security verdict for high-risk changes, and posts both instant alerts and a daily digest to Slack. Results are tracked in an n8n Data Table so only new or modified workflows are rechecked.
What this workflow does
- Runs on a schedule: executes daily at 7:00 AM.
- Builds/loads a baseline: creates an n8n Data Table (if missing) to store previously scanned workflow files and their last known SHAs.
-
Discovers workflow files: uses GitHub REST and Contents APIs to list repositories, enumerate
.github/workflowsfiles, and keep only YAML workflow files. - Scans only what changed: compares the current workflow file SHA with the stored inventory to process only new or changed files.
- Checks for common attack patterns: downloads changed workflows and runs rule-based supply-chain risk checks for GitHub Actions threats.
-
Pinpoint unpinned actions: uses GitHub GraphQL to resolve commit SHAs for unpinned
uses:references, producing ready-to-paste pinning suggestions. - Gemini verdict + Slack response: sends the highest-risk changed workflows (up to a configured limit) to Google Gemini and posts an immediate Slack alert when findings are malicious/suspicious or critical.
- Stores results + posts a digest: upserts scan results back into the Data Table and posts a short daily security digest to Slack; it can also optionally create GitHub issues for serious findings (private repos mentioned).
Use cases
- Catch risky pull-request changes that introduce unpinned third-party GitHub Actions.
- Continuously monitor an organization’s
.github/workflowsfor supply-chain attack patterns. - Provide security and operations teams with daily visibility and instant incident-style alerts in Slack.
Technical details
- Integrations: GitHub REST + Contents APIs, GitHub GraphQL, Google Gemini, Slack.
-
n8n nodes referenced:
if,set,code,limit,merge,slack. - Tracking: n8n Data Table stores workflow inventory and scan outcomes for efficient incremental scanning.
