Skip to product information

n8n Security Audit Workflow: API Audit vs GitHub Advisories

n8n Security Audit Workflow: API Audit vs GitHub Advisories

 (200+Reviews)
Regular price £58.99
Regular price £58.99 Sale price
SAVE Sold out
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Security Audit Workflow: API Audit vs GitHub Advisories

n8n Security Audit Workflow: API Audit vs GitHub Advisories

Regular price £58.99
Regular price £58.99 Sale price
SAVE Sold out

Stay ahead of n8n security issues with an automated daily audit + GitHub advisory matching

This n8n Security Audit Workflow runs every morning to check your instance’s built-in security audit, compare it against n8n GitHub Security Advisories (with branch-aware patch detection), and email you a scored risk report and fix plan via SMTP when new risks appear.

What this workflow does

  • Schedules daily at 07:00 (or runs manually for testing) and loads instance-specific settings like N8N_URL and an optional version override.
  • Calls your instance’s built-in security endpoint: /api/v1/audit, using the X-N8N-API-KEY header, to retrieve your audit report.
  • Fetches the official stable n8n versions list from api.n8n.io to help determine your effective version when the audit doesn’t report missing updates.
  • Pulls published security advisories for n8n-io/n8n from the GitHub Security Advisories API.
  • Analyzes results to detect your effective version, flag advisories that affect it (including backport-aware patch matching), surface audit findings (including issues related to disabled nodes policy), and compute a risk score, grade, trend, and ordered fix plan.
  • Sends a plain-text email report via SMTP when there are new urgent issues, when checks are SKIPPED (never a “fake all-clear”), on the weekly digest day, or whenever testing/always-send is enabled.

Use cases

  • SaaS operators who want consistent n8n vulnerability monitoring without manual review.
  • Automation engineers needing a clear “what to fix first” plan after security advisories are published.
  • Teams managing multiple environments where effective version detection and advisory matching reduce guesswork.

Technical details

  • Nodes/logic used: Manual Trigger, HTTP Request, If, Code, Email Send, Sticky Note.
  • Integrations: HTTP to your n8n /api/v1/audit endpoint; X-N8N-API-KEY via HTTP Header Auth; GitHub Security Advisories API for n8n-io/n8n; versions list from api.n8n.io; email via SMTP.

Setup

  • Create an n8n API key with Instance operations scope and configure HTTP Header Auth to send X-N8N-API-KEY to N8N_URL.
  • Set N8N_URL in the Config step.
View full details