Quick Overview
This workflow runs daily to scan GitHub Actions workflow files across a GitHub org or user, flags supply-chain risk patterns and unpinned actions, uses Google Gemini to review new or changed workflows, and posts instant alerts plus a daily security digest to Slack while tracking results in an n8n Data Table.
How it works
- Runs every day at 7:00 AM on a schedule.
- Creates (if missing) and loads an n8n Data Table baseline of previously scanned workflow files and their last known SHAs.
- Uses the GitHub REST and Contents APIs to list repositories, enumerate
.github/workflows files, and keep only YAML workflow files.
- Compares each workflow file’s current SHA to the stored inventory to process only new or changed files and keep previous results for unchanged files.
- Downloads changed workflow files, performs rule-based checks for common GitHub Actions attack patterns, and uses GitHub GraphQL to resolve commit SHAs for unpinned
uses: references to provide ready-to-paste pinning suggestions.
- Sends the highest-risk changed workflows (up to the configured limit) to Google Gemini for a structured security verdict and posts an immediate Slack alert when the verdict is malicious/suspicious or rule checks include critical findings.
- Upserts scan results back into the Data Table, has Google Gemini generate a short daily digest from the scan statistics, posts the digest to Slack, and optionally creates GitHub issues for serious findings in private repositories.
Setup
- Add a GitHub credential (personal access token) with Contents/Metadata read access (and Issues write access if you enable issue creation) and select it for the GitHub and GitHub HTTP Request steps.
- Add a Google Gemini API key credential and connect it to both Gemini chat model steps used for file review and for the daily digest.
- Add a Slack credential and set the target channel (default
#security-alerts) for the instant alert and daily digest messages.
- Update the Settings values (at least
github_owner and owner_type, plus any optional filters and limits like repo_name_filter, max_repositories, and max_ai_reviews).
- Run the workflow once to create/populate the
gha_security_inventory Data Table baseline, then activate it to scan automatically on the schedule.