{"product_id":"n8n-workflow-triage-github-sbom-vulns-with-osv-jira","title":"n8n Workflow: Triage GitHub SBOM Vulns with OSV \u0026 Jira","description":"\u003ch3\u003eStay ahead of actively exploited GitHub SBOM vulnerabilities—automatically\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow checks your \u003cstrong\u003eGitHub dependency versions\u003c\/strong\u003e against \u003cstrong\u003eactively exploited\u003c\/strong\u003e vulnerability lists from \u003cstrong\u003eCISA\u003c\/strong\u003e and \u003cstrong\u003eENISA\u003c\/strong\u003e. When there’s a real match, it \u003cstrong\u003eopens Jira tickets\u003c\/strong\u003e with the reporting deadlines required by the \u003cstrong\u003eEU Cyber Resilience Act\u003c\/strong\u003e—without duplicates.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns every six hours\u003c\/strong\u003e to triage vulnerabilities for the software libraries your products use.\u003c\/li\u003e\n  \u003cli\u003eReads your configuration: which `GitHub repositories` belong to your products and how strict you want the \u003cstrong\u003edeadlines\u003c\/strong\u003e handling to be.\u003c\/li\u003e\n  \u003cli\u003eDownloads two official “actively exploited” lists—\u003cstrong\u003eCISA (US)\u003c\/strong\u003e and \u003cstrong\u003eENISA (EU)\u003c\/strong\u003e. If either list fails to load, the workflow \u003cstrong\u003estops\u003c\/strong\u003e to avoid a false sense of safety.\u003c\/li\u003e\n  \u003cli\u003eFor each product repository, requests the \u003cstrong\u003efull dependency list\u003c\/strong\u003e and the \u003cstrong\u003eexact versions\u003c\/strong\u003e used.\u003c\/li\u003e\n  \u003cli\u003eQueries the \u003cstrong\u003efree OSV database\u003c\/strong\u003e to find which known security problems affect those exact versions.\u003c\/li\u003e\n  \u003cli\u003eKeeps \u003cstrong\u003eonly\u003c\/strong\u003e the issues that also appear on the actively exploited lists—reducing noise from old, unexploited findings.\u003c\/li\u003e\n  \u003cli\u003eCreates \u003cstrong\u003eone Jira ticket\u003c\/strong\u003e per new match, including the \u003cstrong\u003e24-hour\u003c\/strong\u003e, \u003cstrong\u003e72-hour\u003c\/strong\u003e, and \u003cstrong\u003efinal-report\u003c\/strong\u003e deadlines.\u003c\/li\u003e\n  \u003cli\u003eIf a deadline passes on an open Jira ticket, it adds a \u003cstrong\u003ecomment\u003c\/strong\u003e and applies a \u003cstrong\u003elabel\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eIf a repository cannot be read (wrong name, missing access, or dependency graph disabled), it opens a Jira ticket stating the issue—so blind spots aren’t mistaken for “all clear.”\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS and platform teams monitoring multiple product repositories for \u003cstrong\u003eactively exploited\u003c\/strong\u003e SBOM\/GitHub dependency risks.\u003c\/li\u003e\n  \u003cli\u003eSecurity owners using n8n to automate \u003cstrong\u003eEU Cyber Resilience Act\u003c\/strong\u003e triage reporting workflows in Jira.\u003c\/li\u003e\n  \u003cli\u003eAutomation engineers reducing vulnerability alert fatigue by filtering for issues that are currently exploited in the wild.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003en8n workflow includes nodes\/tools: \u003cstrong\u003eif\u003c\/strong\u003e, \u003cstrong\u003eset\u003c\/strong\u003e, \u003cstrong\u003ecode\u003c\/strong\u003e, \u003cstrong\u003egithub\u003c\/strong\u003e, and \u003cstrong\u003ejira\u003c\/strong\u003e (with \u003cstrong\u003emerge\u003c\/strong\u003e for data handling).\u003c\/li\u003e\n  \u003cli\u003eIntegrations: \u003cstrong\u003eGitHub\u003c\/strong\u003e dependency graph, \u003cstrong\u003eOSV\u003c\/strong\u003e (free vulnerability lookup), \u003cstrong\u003eCISA\u003c\/strong\u003e, \u003cstrong\u003eENISA\u003c\/strong\u003e, and \u003cstrong\u003eJira\u003c\/strong\u003e.\u003c\/li\u003e\n  \u003cli\u003eDesigned to avoid duplicates and to flag missing repository access as a Jira ticket.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46154004431027,"sku":"N8N-20293","price":5.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/cmz52jw9awhcILsULkkyh_QMnzoomc.png?v=1790932559","url":"https:\/\/buyflowscripts.com\/products\/n8n-workflow-triage-github-sbom-vulns-with-osv-jira","provider":"N8N Commerce","version":"1.0","type":"link"}