n8n Security Audit Workflow: API Audit vs GitHub Advisories
n8n Security Audit Workflow: API Audit vs GitHub Advisories
Regular price
£58.99
Regular price
£58.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Security Audit Workflow: API Audit vs GitHub Advisories
Regular price
£58.99
Regular price
£58.99
Sale price
Unit price
/
per
Stay ahead of n8n security issues with an automated daily audit + GitHub advisory matching
This n8n Security Audit Workflow runs every morning to check your instance’s built-in security audit, compare it against n8n GitHub Security Advisories (with branch-aware patch detection), and email you a scored risk report and fix plan via SMTP when new risks appear.
What this workflow does
- Schedules daily at 07:00 (or runs manually for testing) and loads instance-specific settings like N8N_URL and an optional version override.
- Calls your instance’s built-in security endpoint: /api/v1/audit, using the X-N8N-API-KEY header, to retrieve your audit report.
- Fetches the official stable n8n versions list from api.n8n.io to help determine your effective version when the audit doesn’t report missing updates.
- Pulls published security advisories for n8n-io/n8n from the GitHub Security Advisories API.
- Analyzes results to detect your effective version, flag advisories that affect it (including backport-aware patch matching), surface audit findings (including issues related to disabled nodes policy), and compute a risk score, grade, trend, and ordered fix plan.
- Sends a plain-text email report via SMTP when there are new urgent issues, when checks are SKIPPED (never a “fake all-clear”), on the weekly digest day, or whenever testing/always-send is enabled.
Use cases
- SaaS operators who want consistent n8n vulnerability monitoring without manual review.
- Automation engineers needing a clear “what to fix first” plan after security advisories are published.
- Teams managing multiple environments where effective version detection and advisory matching reduce guesswork.
Technical details
- Nodes/logic used: Manual Trigger, HTTP Request, If, Code, Email Send, Sticky Note.
-
Integrations: HTTP to your n8n
/api/v1/auditendpoint;X-N8N-API-KEYvia HTTP Header Auth; GitHub Security Advisories API for n8n-io/n8n; versions list from api.n8n.io; email via SMTP.
Setup
- Create an n8n API key with Instance operations scope and configure HTTP Header Auth to send X-N8N-API-KEY to N8N_URL.
- Set N8N_URL in the Config step.
