{"product_id":"n8n-dependency-risk-triage-github-osv-to-slack-digest","title":"n8n Dependency Risk Triage: GitHub + OSV to Slack Digest","description":"\u003ch3\u003en8n Dependency Risk Triage: GitHub + OSV to Slack Digest\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eStay ahead of vulnerable and stale dependencies.\u003c\/strong\u003e This n8n workflow scans your listed GitHub repositories every Monday, cross-checks JavaScript and Python dependency health with \u003cstrong\u003enpm\/PyPI\u003c\/strong\u003e and vulnerability data from \u003cstrong\u003eOSV\u003c\/strong\u003e, ranks the highest-risk packages, and delivers a single \u003cstrong\u003eSlack\u003c\/strong\u003e digest—automatically creating a \u003cstrong\u003eGitHub issue\u003c\/strong\u003e when replacements are needed.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWeekly GitHub dependency inventory:\u003c\/strong\u003e Runs every Monday morning, reads \u003ccode\u003epackage.json\u003c\/code\u003e and a configured Python manifest (e.g., \u003ccode\u003epyproject.toml\u003c\/code\u003e or \u003ccode\u003erequirements.txt\u003c\/code\u003e) from each listed GitHub repository, and extracts dependency names and versions (normalizing version ranges to bare numbers).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRelease and maintenance signals:\u003c\/strong\u003e Looks up each dependency in \u003cstrong\u003enpm\u003c\/strong\u003e or \u003cstrong\u003ePyPI\u003c\/strong\u003e to capture the latest version, last release date, deprecation\/yank status, and basic maintenance indicators.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eVulnerability verification with OSV:\u003c\/strong\u003e Queries \u003cstrong\u003eOSV\u003c\/strong\u003e for advisories affecting the specific dependency version, filters out findings that are already fixed, and flags advisories with no fix available.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRisk scoring and verdict:\u003c\/strong\u003e Calculates a risk score and a clear verdict (\u003cem\u003ereplace\/upgrade\/watch\/fine\u003c\/em\u003e) based on staleness, deprecation, severity, and fix availability, then builds a ranked shortlist.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eActionable Slack output + GitHub follow-up:\u003c\/strong\u003e Uses an \u003cstrong\u003eOpenAI-compatible chat model\u003c\/strong\u003e to generate one actionable sentence per shortlisted package, \u003cstrong\u003eupserts\u003c\/strong\u003e results into an \u003cstrong\u003en8n Data Table\u003c\/strong\u003e, posts a single Slack summary, and creates one GitHub issue when any packages are marked for replacement.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eWeekly security hygiene for SaaS teams maintaining both \u003cstrong\u003eNode.js\u003c\/strong\u003e and \u003cstrong\u003ePython\u003c\/strong\u003e services.\u003c\/li\u003e\n  \u003cli\u003eDependency risk visibility for automation engineers who want fewer alerts and more prioritized actions.\u003c\/li\u003e\n  \u003cli\u003eHands-off triage: digest to Slack, then GitHub issue creation only when replacements are required.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e \u003cstrong\u003eGitHub\u003c\/strong\u003e (read repositories + open issues), \u003cstrong\u003eSlack\u003c\/strong\u003e (single digest message).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWorkflow nodes:\u003c\/strong\u003e if, set, code, no op, merge, slack.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eExternal checks:\u003c\/strong\u003e npm\/PyPI lookup for release health and \u003cstrong\u003eOSV\u003c\/strong\u003e for vulnerability advisories.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAI assistance:\u003c\/strong\u003e OpenAI-compatible chat model for one actionable sentence per risky package.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eSetup (high level)\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eAdd a \u003cstrong\u003eGitHub credential\u003c\/strong\u003e with access to the repositories you want to scan and the repository where issues should be created.\u003c\/li\u003e\n  \u003cli\u003eAdd a \u003cstrong\u003eSlack credential\u003c\/strong\u003e (cr) and configure the destination for the weekly digest.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45938306613427,"sku":"N8N-18934","price":50.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/aGk_xlEckeVR111m2ctCB_CgCWGzwG.png?v=1788341557","url":"https:\/\/buyflowscripts.com\/products\/n8n-dependency-risk-triage-github-osv-to-slack-digest","provider":"N8N Commerce","version":"1.0","type":"link"}