{"product_id":"n8n-security-audit-workflow-api-audit-vs-github-advisories","title":"n8n Security Audit Workflow: API Audit vs GitHub Advisories","description":"\u003ch3\u003eStay ahead of n8n security issues with an automated daily audit + GitHub advisory matching\u003c\/h3\u003e\n\u003cp\u003eThis n8n Security Audit Workflow runs every morning to check your instance’s built-in security audit, compare it against \u003cstrong\u003en8n GitHub Security Advisories\u003c\/strong\u003e (with branch-aware patch detection), and email you a scored risk report and fix plan via \u003cstrong\u003eSMTP\u003c\/strong\u003e when new risks appear.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSchedules daily\u003c\/strong\u003e at \u003cstrong\u003e07:00\u003c\/strong\u003e (or runs manually for testing) and loads instance-specific settings like \u003cstrong\u003eN8N_URL\u003c\/strong\u003e and an optional version override.\u003c\/li\u003e\n  \u003cli\u003eCalls your instance’s built-in security endpoint: \u003cstrong\u003e\/api\/v1\/audit\u003c\/strong\u003e, using the \u003cstrong\u003eX-N8N-API-KEY\u003c\/strong\u003e header, to retrieve your audit report.\u003c\/li\u003e\n  \u003cli\u003eFetches the \u003cstrong\u003eofficial stable n8n versions list\u003c\/strong\u003e from \u003cstrong\u003eapi.n8n.io\u003c\/strong\u003e to help determine your effective version when the audit doesn’t report missing updates.\u003c\/li\u003e\n  \u003cli\u003ePulls published security advisories for \u003cstrong\u003en8n-io\/n8n\u003c\/strong\u003e from the \u003cstrong\u003eGitHub Security Advisories API\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eAnalyzes results to detect your effective version, flag advisories that affect it (including \u003cstrong\u003ebackport-aware patch matching\u003c\/strong\u003e), surface audit findings (including issues related to \u003cstrong\u003edisabled nodes\u003c\/strong\u003e policy), and compute a \u003cstrong\u003erisk score\u003c\/strong\u003e, grade, trend, and \u003cstrong\u003eordered fix plan\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eSends a plain-text email report via \u003cstrong\u003eSMTP\u003c\/strong\u003e when there are new urgent issues, when checks are \u003cstrong\u003eSKIPPED\u003c\/strong\u003e (never a “fake all-clear”), on the weekly digest day, or whenever testing\/always-send is enabled.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS operators who want consistent \u003cstrong\u003en8n vulnerability monitoring\u003c\/strong\u003e without manual review.\u003c\/li\u003e\n  \u003cli\u003eAutomation engineers needing a clear “what to fix first” plan after security advisories are published.\u003c\/li\u003e\n  \u003cli\u003eTeams managing multiple environments where effective version detection and advisory matching reduce guesswork.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eNodes\/logic used:\u003c\/strong\u003e Manual Trigger, HTTP Request, If, Code, Email Send, Sticky Note.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e HTTP to your n8n \u003ccode\u003e\/api\/v1\/audit\u003c\/code\u003e endpoint; \u003ccode\u003eX-N8N-API-KEY\u003c\/code\u003e via HTTP Header Auth; GitHub Security Advisories API for \u003cem\u003en8n-io\/n8n\u003c\/em\u003e; versions list from \u003cstrong\u003eapi.n8n.io\u003c\/strong\u003e; email via \u003cstrong\u003eSMTP\u003c\/strong\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eSetup\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eCreate an n8n API key with \u003cstrong\u003eInstance operations\u003c\/strong\u003e scope and configure HTTP Header Auth to send \u003cstrong\u003eX-N8N-API-KEY\u003c\/strong\u003e to \u003cstrong\u003eN8N_URL\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eSet \u003cstrong\u003eN8N_URL\u003c\/strong\u003e in the Config step.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46164184957107,"sku":"N8N-20506","price":58.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/84yxNTyuhDNsRpjwkqqjM_IXMGnD7o.png?v=1791277715","url":"https:\/\/buyflowscripts.com\/products\/n8n-security-audit-workflow-api-audit-vs-github-advisories","provider":"N8N Commerce","version":"1.0","type":"link"}