n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira
n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira
Regular price
£5.99
Regular price
£5.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Workflow: Triage GitHub SBOM Vulns with OSV & Jira
Regular price
£5.99
Regular price
£5.99
Sale price
Unit price
/
per
Stay ahead of actively exploited GitHub SBOM vulnerabilities—automatically
This n8n workflow checks your GitHub dependency versions against actively exploited vulnerability lists from CISA and ENISA. When there’s a real match, it opens Jira tickets with the reporting deadlines required by the EU Cyber Resilience Act—without duplicates.
What this workflow does
- Runs every six hours to triage vulnerabilities for the software libraries your products use.
- Reads your configuration: which `GitHub repositories` belong to your products and how strict you want the deadlines handling to be.
- Downloads two official “actively exploited” lists—CISA (US) and ENISA (EU). If either list fails to load, the workflow stops to avoid a false sense of safety.
- For each product repository, requests the full dependency list and the exact versions used.
- Queries the free OSV database to find which known security problems affect those exact versions.
- Keeps only the issues that also appear on the actively exploited lists—reducing noise from old, unexploited findings.
- Creates one Jira ticket per new match, including the 24-hour, 72-hour, and final-report deadlines.
- If a deadline passes on an open Jira ticket, it adds a comment and applies a label.
- If a repository cannot be read (wrong name, missing access, or dependency graph disabled), it opens a Jira ticket stating the issue—so blind spots aren’t mistaken for “all clear.”
Use cases
- SaaS and platform teams monitoring multiple product repositories for actively exploited SBOM/GitHub dependency risks.
- Security owners using n8n to automate EU Cyber Resilience Act triage reporting workflows in Jira.
- Automation engineers reducing vulnerability alert fatigue by filtering for issues that are currently exploited in the wild.
Technical details
- n8n workflow includes nodes/tools: if, set, code, github, and jira (with merge for data handling).
- Integrations: GitHub dependency graph, OSV (free vulnerability lookup), CISA, ENISA, and Jira.
- Designed to avoid duplicates and to flag missing repository access as a Jira ticket.
