Webhook icon
Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Gate Deployments on npm Audit Counts

Pre-deploy npm audit gate that fails on critical vulnerabilities and alerts Slack.

Categories
CloudInfrastructureinfrastructure

A lockfile nobody audits is a liability with a README. This blueprint clones the repo, installs with npm ci, runs npm audit --omit=dev --json, and gates the deploy on critical counts. The nightly schedule ships disabled to catch fresh CVEs.

How it works

  1. run_audit (io.kestra.plugin.scripts.shell.Commands on the Node image) clones, npm ci, then npm audit --omit=dev --json; counts come out via the ::{"outputs": ...}:: protocol.
  2. check_gate (io.kestra.plugin.core.flow.If) branches: breach -> alert_breach; pass -> log_clean.
  3. The errors block alerts on audit failure.
  4. Triggers: a Webhook plus a disabled nightly Schedule.

What you get

  • A deploy gate backed by real counts.
  • Alerts that state the breach size.
  • A trend in the execution history.

Who it's for

  • Teams whose CI never runs npm audit.
  • Security champions chasing prod dependency exposure.

Why orchestrate this with Kestra

npm audit prints a table; the flow makes it a decision with a webhook entry point, a branch, and history. The next step (fail the deploy, open an issue, bump the dep) is one task away.

Prerequisites

  • Docker available on the Kestra Worker.
  • Repo readable from the Worker with a committed lockfile.
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for breach and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set repo_url and max_critical.
  3. Run once and read vuln_counts.
  4. Wire the npm-audit webhook into your deploy pipeline.

How to extend

  • Fail the execution on breach for a hard gate.
  • Include dev dependencies by dropping --omit=dev.
  • Diff counts week-over-week via KV.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.