Skip to product information

n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts

n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts

 (200+Reviews)
Regular price £54.99
Regular price £54.99 Sale price
SAVE Sold out
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts

n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts

Regular price £54.99
Regular price £54.99 Sale price
SAVE Sold out

Detect Compromised GitHub Dependencies Fast — Get Slack Alerts with an AI Response Plan

This n8n workflow spots newly published GitHub malware and critical security advisories across your repositories’ dependency graphs—then sends a Slack alert with a Google Gemini-generated incident response plan so you know exactly what to do next.

What this workflow does

  • Runs hourly and creates its own n8n Data Table on the first run to remember what it has already reported.
  • Fetches advisories from the GitHub Advisory Database published in the last 7 days.
  • Scans every repository dependency graph (SBOM) by listing your GitHub repositories and downloading each one’s dependencies across ecosystems including npm, PyPI, Maven, NuGet, Go, RubyGems, Composer, Rust, and more.
  • Checks affected version ranges so alerts trigger only when your installed dependency versions truly match the vulnerable ranges.
  • Avoids duplicate alerts by skipping anything already reported, while still re-checking recent advisories each run to catch packages installed later.
  • Generates an AI response plan with Google Gemini for each new advisory: what happened, what to do now, and how to verify whether you were compromised.
  • Sends incident alerts to Slack, logs each incident to the Data Table, and can open GitHub issues in private repositories.

Use cases

  • Stay ahead of supply-chain attacks by monitoring GitHub dependency advisories within an hour.
  • Help security and engineering teams triage vulnerable npm or PyPI libraries without manual version hunting.
  • Give SaaS operators a repeatable workflow for dependency risk assessment and response planning.

Technical details

  • Integrations: GitHub (Fetch/List Repositories using a GitHub personal access token), Slack (alerts), Google Gemini (response plan generation).
  • n8n nodes/logic: if, set, code, limit, slack, filter.
  • GitHub credentials: classic token with repo scope, or fine-grained with Contents: read + Metadata: read (and Issues: write if you want issue creation).
View full details