{"product_id":"github-npm-cve-alerts-to-slack-with-apify-n8n-workflow","title":"GitHub NPM CVE Alerts to Slack with Apify (n8n Workflow)","description":"\u003ch3\u003eGet Emergency Slack Alerts for NPM Vulnerabilities—Automatically\u003c\/h3\u003e\n\u003cp\u003eThis \u003cstrong\u003en8n workflow\u003c\/strong\u003e pulls your \u003cstrong\u003epackage.json\u003c\/strong\u003e from \u003cstrong\u003eGitHub\u003c\/strong\u003e, scans dependencies with the \u003cstrong\u003eApify NPM CVE Monitor\u003c\/strong\u003e, and posts an \u003cstrong\u003eemergency alert to Slack\u003c\/strong\u003e only when \u003cstrong\u003ehigh\/critical vulnerabilities\u003c\/strong\u003e (or suspicious dependency patterns) are detected.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns on a schedule:\u003c\/strong\u003e Executes every \u003cstrong\u003eMonday at 9am\u003c\/strong\u003e via an n8n Schedule trigger.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eFetches your latest package.json from GitHub:\u003c\/strong\u003e Uses the GitHub \u003cem\u003eContents API\u003c\/em\u003e (via HTTP Request) to retrieve \u003ccode\u003epackage.json\u003c\/code\u003e from your repository.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eScans with Apify NPM CVE Monitor:\u003c\/strong\u003e Sends the package.json content to the \u003cstrong\u003eApify\u003c\/strong\u003e actor to check for \u003cstrong\u003emedium-and-above vulnerabilities\u003c\/strong\u003e and \u003cstrong\u003esuspicious dependency patterns\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eOrganizes scan results:\u003c\/strong\u003e Groups findings into \u003cstrong\u003ecritical\u003c\/strong\u003e, \u003cstrong\u003ehigh\u003c\/strong\u003e, \u003cstrong\u003emedium\u003c\/strong\u003e, and \u003cstrong\u003esuspicious\u003c\/strong\u003e buckets.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAlerts only when it matters:\u003c\/strong\u003e If no \u003cstrong\u003ecritical or high\u003c\/strong\u003e issues are found, the workflow stops and \u003cstrong\u003edoes not spam Slack\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSends a detailed Slack message:\u003c\/strong\u003e Formats per-package CVE details and includes \u003cstrong\u003esuggested fixes\u003c\/strong\u003e in the emergency alert, then posts to your configured \u003cstrong\u003eSlack\u003c\/strong\u003e channel.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSaaS security monitoring:\u003c\/strong\u003e Catch dependency vulnerabilities in your Node.js projects before they become incidents.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRelease hygiene:\u003c\/strong\u003e Ensure newly declared dependencies remain free of high-risk CVEs.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAutomation engineering:\u003c\/strong\u003e Centralize GitHub + Apify vulnerability scanning and deliver actionable alerts to Slack.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details (nodes \u0026amp; integrations)\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSchedule Trigger\u003c\/strong\u003e (runs Mondays at 9am)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHTTP Request\u003c\/strong\u003e to GitHub Contents API (requires GitHub token read access)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHTTP Request\u003c\/strong\u003e to \u003cstrong\u003eApify\u003c\/strong\u003e (requires Apify API token)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCode\u003c\/strong\u003e for grouping\/results handling\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eif\u003c\/strong\u003e node to stop when no critical\/high findings exist\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSlack\u003c\/strong\u003e node to post the emergency alert (configured with Slack OAuth2)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSticky Note\u003c\/strong\u003e for workflow guidance\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eBest for:\u003c\/strong\u003e n8n users, automation engineers, and SaaS operators who want reliable \u003cstrong\u003eGitHub-to-Apify-to-Slack\u003c\/strong\u003e security alerts for NPM dependencies.\u003c\/p\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45938285641907,"sku":"N8N-18948","price":11.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/QQK1yzSmD0pCjY-HJAzKY_PDhzS6dz.png?v=1788341230","url":"https:\/\/buyflowscripts.com\/products\/github-npm-cve-alerts-to-slack-with-apify-n8n-workflow","provider":"N8N Commerce","version":"1.0","type":"link"}