n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts
n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts
Regular price
£54.99
Regular price
£54.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts
Regular price
£54.99
Regular price
£54.99
Sale price
Unit price
/
per
Detect Compromised GitHub Dependencies Fast — Get Slack Alerts with an AI Response Plan
This n8n workflow spots newly published GitHub malware and critical security advisories across your repositories’ dependency graphs—then sends a Slack alert with a Google Gemini-generated incident response plan so you know exactly what to do next.
What this workflow does
- Runs hourly and creates its own n8n Data Table on the first run to remember what it has already reported.
- Fetches advisories from the GitHub Advisory Database published in the last 7 days.
- Scans every repository dependency graph (SBOM) by listing your GitHub repositories and downloading each one’s dependencies across ecosystems including npm, PyPI, Maven, NuGet, Go, RubyGems, Composer, Rust, and more.
- Checks affected version ranges so alerts trigger only when your installed dependency versions truly match the vulnerable ranges.
- Avoids duplicate alerts by skipping anything already reported, while still re-checking recent advisories each run to catch packages installed later.
- Generates an AI response plan with Google Gemini for each new advisory: what happened, what to do now, and how to verify whether you were compromised.
- Sends incident alerts to Slack, logs each incident to the Data Table, and can open GitHub issues in private repositories.
Use cases
- Stay ahead of supply-chain attacks by monitoring GitHub dependency advisories within an hour.
- Help security and engineering teams triage vulnerable npm or PyPI libraries without manual version hunting.
- Give SaaS operators a repeatable workflow for dependency risk assessment and response planning.
Technical details
- Integrations: GitHub (Fetch/List Repositories using a GitHub personal access token), Slack (alerts), Google Gemini (response plan generation).
- n8n nodes/logic: if, set, code, limit, slack, filter.
- GitHub credentials: classic token with repo scope, or fine-grained with Contents: read + Metadata: read (and Issues: write if you want issue creation).
