{"product_id":"n8n-workflow-detect-compromised-github-dependencies-with-gemini-slack-alerts","title":"n8n Workflow: Detect Compromised GitHub Dependencies with Gemini + Slack Alerts","description":"\u003ch3\u003eDetect Compromised GitHub Dependencies Fast — Get Slack Alerts with an AI Response Plan\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow spots newly published GitHub malware and critical security advisories across your repositories’ dependency graphs—then sends a \u003cstrong\u003eSlack\u003c\/strong\u003e alert with a \u003cstrong\u003eGoogle Gemini\u003c\/strong\u003e-generated incident response plan so you know exactly what to do next.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns hourly\u003c\/strong\u003e and creates its own n8n \u003cstrong\u003eData Table\u003c\/strong\u003e on the first run to remember what it has already reported.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eFetches advisories\u003c\/strong\u003e from the \u003cstrong\u003eGitHub Advisory Database\u003c\/strong\u003e published in the last \u003cstrong\u003e7 days\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eScans every repository dependency graph\u003c\/strong\u003e (SBOM) by listing your \u003cstrong\u003eGitHub repositories\u003c\/strong\u003e and downloading each one’s dependencies across ecosystems including \u003cstrong\u003enpm, PyPI, Maven, NuGet, Go, RubyGems, Composer, Rust\u003c\/strong\u003e, and more.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eChecks affected version ranges\u003c\/strong\u003e so alerts trigger only when your installed dependency versions truly match the vulnerable ranges.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAvoids duplicate alerts\u003c\/strong\u003e by skipping anything already reported, while still re-checking recent advisories each run to catch packages installed later.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eGenerates an AI response plan\u003c\/strong\u003e with \u003cstrong\u003eGoogle Gemini\u003c\/strong\u003e for each new advisory: what happened, what to do now, and how to verify whether you were compromised.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSends incident alerts to Slack\u003c\/strong\u003e, logs each incident to the Data Table, and can \u003cstrong\u003eopen GitHub issues in private repositories\u003c\/strong\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eStay ahead of supply-chain attacks by monitoring \u003cstrong\u003eGitHub\u003c\/strong\u003e dependency advisories within an hour.\u003c\/li\u003e\n  \u003cli\u003eHelp security and engineering teams triage vulnerable \u003cstrong\u003enpm\u003c\/strong\u003e or \u003cstrong\u003ePyPI\u003c\/strong\u003e libraries without manual version hunting.\u003c\/li\u003e\n  \u003cli\u003eGive SaaS operators a repeatable workflow for dependency risk assessment and response planning.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e \u003cstrong\u003eGitHub\u003c\/strong\u003e (Fetch\/List Repositories using a GitHub personal access token), \u003cstrong\u003eSlack\u003c\/strong\u003e (alerts), \u003cstrong\u003eGoogle Gemini\u003c\/strong\u003e (response plan generation).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes\/logic:\u003c\/strong\u003e \u003cem\u003eif, set, code, limit, slack, filter\u003c\/em\u003e.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eGitHub credentials:\u003c\/strong\u003e classic token with \u003cem\u003erepo\u003c\/em\u003e scope, or fine-grained with \u003cem\u003eContents: read\u003c\/em\u003e + \u003cem\u003eMetadata: read\u003c\/em\u003e (and \u003cem\u003eIssues: write\u003c\/em\u003e if you want issue creation).\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46192860397747,"sku":"N8N-20529","price":54.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/NYCa5ek-_pJ-0tdYaAF_o_8k7nO2gz.png?v=1791537592","url":"https:\/\/buyflowscripts.com\/products\/n8n-workflow-detect-compromised-github-dependencies-with-gemini-slack-alerts","provider":"N8N Commerce","version":"1.0","type":"link"}