Skip to product information

n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira

n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira

 (200+Reviews)
Regular price £5.99
Regular price £5.99 Sale price
SAVE Sold out
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira

n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira

Regular price £5.99
Regular price £5.99 Sale price
SAVE Sold out

Stay ahead of actively exploited GitHub SBOM vulnerabilities—automatically

This n8n workflow checks your GitHub dependency versions against actively exploited vulnerability lists from CISA and ENISA. When there’s a real match, it opens Jira tickets with the reporting deadlines required by the EU Cyber Resilience Act—without duplicates.

What this workflow does

  • Runs every six hours to triage vulnerabilities for the software libraries your products use.
  • Reads your configuration: which `GitHub repositories` belong to your products and how strict you want the deadlines handling to be.
  • Downloads two official “actively exploited” lists—CISA (US) and ENISA (EU). If either list fails to load, the workflow stops to avoid a false sense of safety.
  • For each product repository, requests the full dependency list and the exact versions used.
  • Queries the free OSV database to find which known security problems affect those exact versions.
  • Keeps only the issues that also appear on the actively exploited lists—reducing noise from old, unexploited findings.
  • Creates one Jira ticket per new match, including the 24-hour, 72-hour, and final-report deadlines.
  • If a deadline passes on an open Jira ticket, it adds a comment and applies a label.
  • If a repository cannot be read (wrong name, missing access, or dependency graph disabled), it opens a Jira ticket stating the issue—so blind spots aren’t mistaken for “all clear.”

Use cases

  • SaaS and platform teams monitoring multiple product repositories for actively exploited SBOM/GitHub dependency risks.
  • Security owners using n8n to automate EU Cyber Resilience Act triage reporting workflows in Jira.
  • Automation engineers reducing vulnerability alert fatigue by filtering for issues that are currently exploited in the wild.

Technical details

  • n8n workflow includes nodes/tools: if, set, code, github, and jira (with merge for data handling).
  • Integrations: GitHub dependency graph, OSV (free vulnerability lookup), CISA, ENISA, and Jira.
  • Designed to avoid duplicates and to flag missing repository access as a Jira ticket.
View full details