Quick overview
Every six hours, this checks the software libraries your products use against public lists of security holes that hackers are actively using right now. For each real match it opens a Jira ticket with the EU Cyber Resilience Act reporting deadlines.
How it works
- Every six hours the workflow starts and reads your settings: which GitHub repositories are your products, and how strict the deadlines are.
- It downloads two official lists of security holes that are being exploited right now: one from the US agency CISA and one from the EU agency ENISA. If either list fails to load, it stops instead of wrongly saying you are safe.
- For each product repository, it asks GitHub for the full list of libraries and the exact versions it uses.
- It asks the free OSV database which known security problems affect those exact versions.
- It keeps only the problems that are also on the 'actively exploited' lists. A library with an old, unexploited issue does not create noise.
- For each new match it opens one Jira ticket with the 24-hour, 72-hour and final-report deadlines. It never creates duplicates, and if a deadline passes on an open ticket it adds a comment and a label.
- If a repository cannot be read (wrong name, no access, or dependency list switched off), it opens a ticket saying so, so a blind spot is never mistaken for 'all clear'.
Setup
- Connect your GitHub account in n8n, and in each product repository turn on the dependency graph (Settings > Code security) so GitHub can list its libraries.
- Connect your Jira Cloud account, then open the 'Open A Jira Ticket' step and choose the project and issue type where the tickets should go.
- Open 'Reporting Policy' and list your product repositories as owner/name, separated by commas. The default deadlines follow the CRA (24 hours, 72 hours, 14 days); change them only if your legal team says so.
Requirements
- A GitHub account that can read your product repositories, and a Jira Cloud account. The vulnerability lists and OSV are free and need no account.
Customization
- Change how often it runs, the ticket label, or the deadline times in 'Reporting Policy'.
Additional info
This starts the reporting clock and keeps track of it; a person still decides whether a finding must be reported. A ticket you close is never reopened. The final-report deadline is only flagged once a fixed version exists.