New to Kestra?
Use blueprints to kickstart your first workflows.
Weekly npm outdated audit that highlights major-version dependency risk and posts a digest to Slack.
Dependabot sends a PR per package; nobody reads sixty of them. A weekly digest of what actually has a major bump pending is the signal you can act on. This blueprint clones your repo, runs npm outdated in a throwaway Node container, splits the results into major versus minor/patch drift, and posts the majors to Slack.
npm_outdated (io.kestra.plugin.scripts.shell.Commands on Docker) clones the repo, runs npm outdated --json in the subdirectory, and emits total, majors, and the first 10 major-bump details via the ::{"outputs": ...}:: protocol.check_majors (io.kestra.plugin.core.flow.If) branches: majors pending → post_digest lists the count and total to Slack; otherwise log_fresh records the green week.errors block alerts Slack when the clone or npm call fails.Schedule (disabled by default) plus a Webhook for post-merge checks.dependency_summary JSON output for dashboards.npm outdated prints a table nobody reads. The flow turns it into a weekly, branched, alerted digest — and the next step (open a tracking issue, pin a Dependabot schedule, gate releases) is one task away.
SLACK_WEBHOOK_URL: webhook for the digest and failure alerts.repo_url and subdirectory (e.g. ui).dependency_summary.weekly_digest.npm audit --json parsing for vulnerability counts.ForEach.dependency_summary in KV and alert only on growth.