{"product_id":"detect-github-actions-supply-chain-risks-with-gemini-slack","title":"Detect GitHub Actions Supply-Chain Risks with Gemini \u0026 Slack","description":"\u003ch3\u003eDetect GitHub Actions supply-chain risks and get instant Slack alerts—automatically\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow scans your GitHub Actions workflows every day, detects supply-chain risk patterns (including unpinned \u003ccode\u003euses:\u003c\/code\u003e references), uses Google Gemini to generate a structured security verdict for high-risk changes, and posts both instant alerts and a daily digest to Slack. Results are tracked in an n8n Data Table so only new or modified workflows are rechecked.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns on a schedule\u003c\/strong\u003e: executes daily at \u003cstrong\u003e7:00 AM\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eBuilds\/loads a baseline\u003c\/strong\u003e: creates an n8n Data Table (if missing) to store previously scanned workflow files and their last known SHAs.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDiscovers workflow files\u003c\/strong\u003e: uses GitHub REST and Contents APIs to list repositories, enumerate \u003ccode\u003e.github\/workflows\u003c\/code\u003e files, and keep only YAML workflow files.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eScans only what changed\u003c\/strong\u003e: compares the current workflow file SHA with the stored inventory to process only \u003cem\u003enew or changed\u003c\/em\u003e files.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eChecks for common attack patterns\u003c\/strong\u003e: downloads changed workflows and runs rule-based supply-chain risk checks for GitHub Actions threats.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePinpoint unpinned actions\u003c\/strong\u003e: uses GitHub GraphQL to resolve commit SHAs for unpinned \u003ccode\u003euses:\u003c\/code\u003e references, producing ready-to-paste pinning suggestions.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eGemini verdict + Slack response\u003c\/strong\u003e: sends the highest-risk changed workflows (up to a configured limit) to \u003cstrong\u003eGoogle Gemini\u003c\/strong\u003e and posts an immediate Slack alert when findings are malicious\/suspicious or critical.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eStores results + posts a digest\u003c\/strong\u003e: upserts scan results back into the Data Table and posts a short daily security digest to Slack; it can also optionally create GitHub issues for serious findings (private repos mentioned).\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eCatch risky pull-request changes that introduce unpinned third-party GitHub Actions.\u003c\/li\u003e\n  \u003cli\u003eContinuously monitor an organization’s \u003ccode\u003e.github\/workflows\u003c\/code\u003e for supply-chain attack patterns.\u003c\/li\u003e\n  \u003cli\u003eProvide security and operations teams with daily visibility and instant incident-style alerts in Slack.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations\u003c\/strong\u003e: GitHub REST + Contents APIs, GitHub GraphQL, Google Gemini, Slack.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes referenced\u003c\/strong\u003e: \u003ccode\u003eif\u003c\/code\u003e, \u003ccode\u003eset\u003c\/code\u003e, \u003ccode\u003ecode\u003c\/code\u003e, \u003ccode\u003elimit\u003c\/code\u003e, \u003ccode\u003emerge\u003c\/code\u003e, \u003ccode\u003eslack\u003c\/code\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTracking\u003c\/strong\u003e: n8n Data Table stores workflow inventory and scan outcomes for efficient incremental scanning.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46154009673907,"sku":"N8N-20291","price":45.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/QE6SuZIDOuebu15sOXEwr_Ar7DdVwg.png?v=1790932616","url":"https:\/\/buyflowscripts.com\/products\/detect-github-actions-supply-chain-risks-with-gemini-slack","provider":"N8N Commerce","version":"1.0","type":"link"}