Triage actively exploited GitHub SBOM vulnerabilities with OSV and Jira

Go to Workflow
0 views
Built by Melbin Francis Melbin Francis
Created on October 01, 2026

Description

Quick overview
Every six hours, this checks the software libraries your products use against public lists of security holes that hackers are actively using right now. For each real match it opens a Jira ticket with the EU Cyber Resilience Act reporting deadlines.

How it works
Every six hours the workflow starts and reads your settings: which GitHub repositories are your products, and how strict the deadlines are.
It downloads two official lists of security holes that are being exploited right now: one from the US agency CISA and one from the EU agency ENISA. If either list fails to load, it stops instead of wrongly saying you are safe.
For each product repository, it asks GitHub for the full list of libraries and the exact versions it uses.
It asks the free OSV database which known security problems affect those exact versions.
It keeps only the problems that are also on the 'actively exploited' lists. A library with an old, unexploited issue does not create noise.
For each new match it opens one Jira ticket with the 24-hour, 72-hour and final-report deadlines. It never creates duplicates, and if a deadline passes on an open ticket it adds a comment and a label.
If a repository cannot be read (wrong name, no access, or dependency list switched off), it opens a ticket saying so, so a blind spot is never mistaken for 'all clear'.

Setup
Connect your GitHub account in n8n, and in each product repository turn on the dependency graph (Settings > Code security) so GitHub can list its libraries.
Connect your Jira Cloud account, then open the 'Open A Jira Ticket' step and choose the project and issue type where the tickets should go.
Open 'Reporting Policy' and list your product repositories as owner/name, separated by commas. The default deadlines follow the CRA (24 hours, 72 hours, 14 days); change them only if your legal team says so.

Requirements
A GitHub account that can read your product repositories, and a Jira Cloud account. The vulnerability lists and OSV are free and need no account.

Customization
Change how often it runs, the ticket label, or the deadline times in 'Reporting Policy'.

Additional info
This starts the reporting clock and keeps track of it; a person still decides whether a finding must be reported. A ticket you close is never reopened. The final-report deadline is only flagged once a fixed version exists.

Nodes Used (4)

Code
n8n-nodes-base.code
GitHub
n8n-nodes-base.github
HTTP Request
n8n-nodes-base.httpRequest
Jira Software
n8n-nodes-base.jira