GitHub dependabot alert notifications on your phone.

Get a push notification when Dependabot finds a vulnerable dependency, with priority based on the severity.

dependabot_alertDeveloper toolsSecurity Signature verified
How it works

Three steps to your first push

STEP 01

Install the recipe

One click in Studio gives you a personal webhook URL.

STEP 02

Paste your URL into GitHub

Add it as a webhook for Dependabot alerts.

STEP 03

Get a push on your phone

With the text, sound and buttons from the recipe.

Setup

How to set up the GitHub dependabot alerts webhook

  1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL.
  2. In your repository (or organization), go to Settings > Webhooks and click Add webhook.
  3. Paste your webhook URL as the Payload URL and set Content type to application/json.https://••••••••/•••••••• your personal URL, shown after install
  4. Enter a secret and copy the same secret into JustPush.
  5. Choose Let me select individual events, tick Dependabot alerts, and save. GitHub sends a ping right away.
  6. Tick **Dependabot alerts** in the webhook's events (Dependabot alerts must be enabled for the repository). New alerts and reintroduced ones push; dismissals and fixes don't.
  7. GitHub signs every delivery with your secret (`X-Hub-Signature-256`), and JustPush checks it, so requests that don't come from GitHub are rejected.
The code

What runs when the webhook arrives

Studio calls handleRequest(request) with the incoming webhook and sends the message it returns. It's yours after install; change anything.

transform.js
1// GitHub → dependabot_alert (dependabot alert)
2// Get a push notification when Dependabot finds a vulnerable dependency, with priority based on the severity.
3// Docs: https://docs.github.com/en/webhooks/webhook-events-and-payloads#dependabot_alert
4
5// Advisory severity → push priority.
6const SEVERITIES = { critical: 2, high: 1, medium: 0, low: -1 }
7
8// Header names can arrive in any case.
9function header(request, name) {
10 const headers = request.headers || {}
11 const key = Object.keys(headers).find((k) => k.toLowerCase() === name)
12 const value = key ? headers[key] : null
13 return Array.isArray(value) ? value[0] : value
14}
15
16// Only link to real http(s) URLs.
17function link(url, cta) {
18 return typeof url === "string" && /^https?:\/\//.test(url) ? [{ cta, url }] : []
19}
20
21function handleRequest(request) {
22 const body = request.body && typeof request.body === "object" ? request.body : {}
23 const event = header(request, "x-github-event")
24
25 // Saving the webhook makes GitHub send a ping; confirm the connection quietly.
26 if (event === "ping" || (body.zen && body.hook_id)) {
27 return {
28 title: "🔔 GitHub connected",
29 message: `Webhook for ${body.repository?.full_name ?? body.organization?.login ?? "your account"} is working`,
30 topic: "GitHub",
31 priority: -1,
32 }
33 }
34
35 // Guard: only dependabot_alert events. The header decides when it's there; the payload's
36 // shape is the fallback (for example in Studio's Test runner).
37 if (event ? event !== "dependabot_alert" : !(body.alert?.security_advisory)) {
38 console.log(`Ignoring GitHub "${event ?? "unknown"}" event`)
39 return null
40 }
41
42 const repo = body.repository?.full_name ?? "a repository"
43 const alert = body.alert
44
45 // New alerts, and ones that came back after being fixed.
46 if (!["created", "reintroduced"].includes(body.action) || !alert) {
47 console.log(`Skipping Dependabot alert action "${body.action}"`)
48 return null
49 }
50
51 const severity = String(alert.security_advisory?.severity ?? alert.security_vulnerability?.severity ?? "").toLowerCase()
52 const pkg = alert.dependency?.package?.name ?? alert.security_vulnerability?.package?.name ?? "a dependency"
53 const fixed = alert.security_vulnerability?.first_patched_version?.identifier
54 const again = body.action === "reintroduced" ? " (again)" : ""
55
56 return {
57 title: `🛡️ ${severity ? severity.charAt(0).toUpperCase() + severity.slice(1) + " v" : "V"}ulnerability in ${pkg}${again}`,
58 message:
59 (alert.security_advisory?.summary ?? "Security advisory") +
60 ` · ${repo}` +
61 (fixed ? ` · fixed in ${fixed}` : ""),
62 topic: "GitHub",
63 priority: Object.prototype.hasOwnProperty.call(SEVERITIES, severity) ? SEVERITIES[severity] : 0,
64 buttons: link(alert.html_url, "View alert"),
65 }
66}
Payload

The GitHub dependabot_alert webhook

This is what GitHub sends to your URL for dependabot alerts. It is a sample, trimmed to the fields recipes use.

dependabot_alert · sample.json
1{
2 "alert": {
3 "state": "open",
4 "number": 7,
5 "html_url": "https://github.com/acme/web/security/dependabot/7",
6 "dependency": {
7 "scope": "runtime",
8 "package": {
9 "name": "lodash",
10 "ecosystem": "npm"
11 },
12 "manifest_path": "package-lock.json"
13 },
14 "security_advisory": {
15 "ghsa_id": "GHSA-35jh-r3h4-6jhm",
16 "summary": "Command injection in lodash",
17 "severity": "high"
18 },
19 "security_vulnerability": {
20 "package": {
21 "name": "lodash",
22 "ecosystem": "npm"
23 },
24 "severity": "high",
25 "first_patched_version": {
26 "identifier": "4.17.21"
27 },
28 "vulnerable_version_range": "< 4.17.21"
29 }
30 },
31 "action": "created",
32 "sender": {
33 "login": "dependabot[bot]"
34 },
35 "repository": {
36 "full_name": "acme/web"
37 }
38}
Security

How the GitHub signature is verified

X-Hub-Signature-256

GitHub signs every webhook with an HMAC-SHA256 hash of the request body in the X-Hub-Signature-256 header, made with the secret you set on the webhook. Add the secret to the recipe in Studio and JustPush checks every request before your code runs, so requests that don't come from GitHub never reach your phone.

FAQ

GitHub dependabot alert notifications: questions

Does this work on iPhone and Android?

Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification.

Do I need to write code?

No. Install the recipe in Studio, paste your webhook URL into GitHub and you are done. The code is there if you want to change the text, the sound or the buttons.

Can I change what the notification says?

Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save.

What does it cost?

JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.

Ready when you are

GitHub on your phone in two minutes.

Install the recipe, paste one URL, done. Free for 30 days, no credit card required.