# Detect compromised GitHub dependencies with Gemini and Slack alerts

> Quick overview Know within an hour when a hijacked or malicious npm, PyPI or other open-source package lands in any of your GitHub repositories. This workflow checks new GitHub malware and critical advisories against every repository's dependency graph and sends a Slack alert with an AI response plan. How it works 1. Runs every hour and creates its own n8n Data Table on the first run to remember what it already reported. 2. Pulls the malware and critical advisories published in the last 7 days from the GitHub Advisory Database. 3. Lists your repositories and downloads each one's dependency graph (SBOM), covering npm, PyPI, Maven, NuGet, Go, RubyGems, Composer, Rust and more. 4. Compares every dependency version with the affected version ranges, so you are only alerted about versions that are really affected. 5. Skips anything already reported, so each problem is alerted once, and re-checks recent advisories on every run to catch packages installed later. 6. Google Gemini writes an inci

- **Domain**: `n8n-workflow-20529.n8n.io`
- **Provider**: n8n.io (https://n8n.io)
- **Kind**: workflow
- **Live-responds (last probe)**: None
- **Signed card**: False
- **Streaming**: False
- **Quality score**: 40%

## URLs
- Agent card: https://n8n.io/workflows/20529
- Page (HTML): https://agenstry.com/agents/n8n-workflow-20529.n8n.io
- Documentation: https://n8n.io/workflows/20529
