# Detect GitHub Actions supply-chain risks with Gemini and Slack

> Quick Overview This workflow runs daily to scan GitHub Actions workflow files across a GitHub org or user, flags supply-chain risk patterns and unpinned actions, uses Google Gemini to review new or changed workflows, and posts instant alerts plus a daily security digest to Slack while tracking results in an n8n Data Table. How it works 1. Runs every day at 7:00 AM on a schedule. 2. Creates (if missing) and loads an n8n Data Table baseline of previously scanned workflow files and their last known SHAs. 3. Uses the GitHub REST and Contents APIs to list repositories, enumerate .github/workflows files, and keep only YAML workflow files. 4. Compares each workflow file’s current SHA to the stored inventory to process only new or changed files and keep previous results for unchanged files. 5. Downloads changed workflow files, performs rule-based checks for common GitHub Actions attack patterns, and uses GitHub GraphQL to resolve commit SHAs for unpinned uses: references to provide ready-to-pa

- **Domain**: `n8n-workflow-20291.n8n.io`
- **Provider**: n8n.io (https://n8n.io)
- **Kind**: workflow
- **Live-responds (last probe)**: None
- **Signed card**: False
- **Streaming**: False
- **Quality score**: 40%

## URLs
- Agent card: https://n8n.io/workflows/20291
- Page (HTML): https://agenstry.com/agents/n8n-workflow-20291.n8n.io
- Documentation: https://n8n.io/workflows/20291
