{"product_id":"n8n-workflow-scan-git-ci-logs-for-secret-leaks-whatsapp-alerts","title":"n8n Workflow: Scan Git \u0026 CI Logs for Secret Leaks + WhatsApp Alerts","description":"\u003ch3\u003eAutomatically find secret leaks in Git \u0026amp; CI logs—and alert the right people on WhatsApp\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow scans your \u003cstrong\u003eGitHub commits\u003c\/strong\u003e and \u003cstrong\u003eCI\/CD pipeline logs\u003c\/strong\u003e for leaked credentials, verifies suspicious findings against \u003cstrong\u003eGitHub\u003c\/strong\u003e and \u003cstrong\u003eStripe\u003c\/strong\u003e when possible, and sends \u003cstrong\u003eWhatsApp alerts\u003c\/strong\u003e with a remediation checklist—then re-verifies after confirmation to confirm whether the secret is still active.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns on schedule (every 6 hours)\u003c\/strong\u003e or on-demand via a manual trigger.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCollects evidence:\u003c\/strong\u003e fetches the latest commit list from your configured \u003cstrong\u003eGitHub repository\u003c\/strong\u003e, then pulls \u003cstrong\u003eCI\/CD logs\u003c\/strong\u003e from your configured CI API endpoint.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDetects secrets:\u003c\/strong\u003e scans log and commit text for common secret patterns (e.g., \u003cstrong\u003eAWS keys\u003c\/strong\u003e, \u003cstrong\u003eGitHub tokens\u003c\/strong\u003e, \u003cstrong\u003eStripe keys\u003c\/strong\u003e, and \u003cstrong\u003ehigh-entropy strings\u003c\/strong\u003e), masks matches, and deduplicates findings.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRoutes findings by category:\u003c\/strong\u003e suspected credentials are verified via provider API calls (GitHub \u003cstrong\u003e\/user\u003c\/strong\u003e and Stripe \u003cstrong\u003e\/v1\/account\u003c\/strong\u003e where applicable); high-entropy matches that can’t be validated are marked for manual review.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eScores risk \u0026amp; severity:\u003c\/strong\u003e generates a risk score using secret type, source (repo vs CI), confidence, and whether the credential appears still valid.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWhatsApp notification + remediation loop:\u003c\/strong\u003e sends WhatsApp alerts based on severity. For critical\/high findings, it waits for an external remediation confirmation webhook, pauses for a grace period, then \u003cstrong\u003ere-verifies\u003c\/strong\u003e and sends a resolution or escalation message.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eProactively detect accidental token exposure in GitHub commits and CI logs.\u003c\/li\u003e\n  \u003cli\u003eReduce time-to-response by sending incident-ready WhatsApp alerts with concrete remediation steps.\u003c\/li\u003e\n  \u003cli\u003eVerify whether leaked credentials (GitHub\/Stripe) remain valid after teams claim they’ve rotated them.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes \/ building blocks:\u003c\/strong\u003e if, set, code, wait, switch, WhatsApp\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e GitHub (commit retrieval + API verification via \u003cem\u003e\/user\u003c\/em\u003e), CI\/CD log API endpoint, Stripe verification via \u003cem\u003e\/v1\/account\u003c\/em\u003e\n\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCore logic:\u003c\/strong\u003e secret pattern scanning, masking, deduplication, risk scoring, WhatsApp messaging, confirmation webhook, wait\/grace period, and re-verification.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45869878247603,"sku":"N8N-18452","price":27.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/Vd8QineNVordxE98TzptT_wiaHzpg5.png?v=1787130140","url":"https:\/\/buyflowscripts.com\/products\/n8n-workflow-scan-git-ci-logs-for-secret-leaks-whatsapp-alerts","provider":"N8N Commerce","version":"1.0","type":"link"}