# GitHub dependabot alert notifications on your phone > Get a push notification when Dependabot finds a vulnerable dependency, with priority based on the severity. - Company: GitHub (https://www.justpush.io/recipes/github) - Event: `dependabot_alert` (Dependabot alerts) - Tags: Developer tools, Security - Install: https://studio.justpush.io/recipes/github/dependabot-alert - Web page: https://www.justpush.io/recipes/github/dependabot-alert ## Setup 1. Click Install in Studio and sign in. The recipe is added to your account and you get a personal webhook URL. 2. In your repository (or organization), go to Settings > Webhooks and click Add webhook. 3. Paste your webhook URL (shown in Studio after install) as the Payload URL and set Content type to application/json. 4. Enter a secret and copy the same secret into JustPush. 5. Choose Let me select individual events, tick Dependabot alerts, and save. GitHub sends a ping right away. 6. Tick **Dependabot alerts** in the webhook's events (Dependabot alerts must be enabled for the repository). New alerts and reintroduced ones push; dismissals and fixes don't. 7. GitHub signs every delivery with your secret (`X-Hub-Signature-256`), and JustPush checks it, so requests that don't come from GitHub are rejected. ## Code Studio calls `handleRequest(request)` with the incoming webhook (`{ method, headers, body, query, raw }`) and sends the message object it returns. Returning `null` sends nothing. ```js // GitHub โ†’ dependabot_alert (dependabot alert) // Get a push notification when Dependabot finds a vulnerable dependency, with priority based on the severity. // Docs: https://docs.github.com/en/webhooks/webhook-events-and-payloads#dependabot_alert // Advisory severity โ†’ push priority. const SEVERITIES = { critical: 2, high: 1, medium: 0, low: -1 } // Header names can arrive in any case. function header(request, name) { const headers = request.headers || {} const key = Object.keys(headers).find((k) => k.toLowerCase() === name) const value = key ? headers[key] : null return Array.isArray(value) ? value[0] : value } // Only link to real http(s) URLs. function link(url, cta) { return typeof url === "string" && /^https?:\/\//.test(url) ? [{ cta, url }] : [] } function handleRequest(request) { const body = request.body && typeof request.body === "object" ? request.body : {} const event = header(request, "x-github-event") // Saving the webhook makes GitHub send a ping; confirm the connection quietly. if (event === "ping" || (body.zen && body.hook_id)) { return { title: "๐Ÿ”” GitHub connected", message: `Webhook for ${body.repository?.full_name ?? body.organization?.login ?? "your account"} is working`, topic: "GitHub", priority: -1, } } // Guard: only dependabot_alert events. The header decides when it's there; the payload's // shape is the fallback (for example in Studio's Test runner). if (event ? event !== "dependabot_alert" : !(body.alert?.security_advisory)) { console.log(`Ignoring GitHub "${event ?? "unknown"}" event`) return null } const repo = body.repository?.full_name ?? "a repository" const alert = body.alert // New alerts, and ones that came back after being fixed. if (!["created", "reintroduced"].includes(body.action) || !alert) { console.log(`Skipping Dependabot alert action "${body.action}"`) return null } const severity = String(alert.security_advisory?.severity ?? alert.security_vulnerability?.severity ?? "").toLowerCase() const pkg = alert.dependency?.package?.name ?? alert.security_vulnerability?.package?.name ?? "a dependency" const fixed = alert.security_vulnerability?.first_patched_version?.identifier const again = body.action === "reintroduced" ? " (again)" : "" return { title: `๐Ÿ›ก๏ธ ${severity ? severity.charAt(0).toUpperCase() + severity.slice(1) + " v" : "V"}ulnerability in ${pkg}${again}`, message: (alert.security_advisory?.summary ?? "Security advisory") + ` ยท ${repo}` + (fixed ? ` ยท fixed in ${fixed}` : ""), topic: "GitHub", priority: Object.prototype.hasOwnProperty.call(SEVERITIES, severity) ? SEVERITIES[severity] : 0, buttons: link(alert.html_url, "View alert"), } } ``` ## GitHub dependabot_alert webhook payload (sample) ```json { "alert": { "state": "open", "number": 7, "html_url": "https://github.com/acme/web/security/dependabot/7", "dependency": { "scope": "runtime", "package": { "name": "lodash", "ecosystem": "npm" }, "manifest_path": "package-lock.json" }, "security_advisory": { "ghsa_id": "GHSA-35jh-r3h4-6jhm", "summary": "Command injection in lodash", "severity": "high" }, "security_vulnerability": { "package": { "name": "lodash", "ecosystem": "npm" }, "severity": "high", "first_patched_version": { "identifier": "4.17.21" }, "vulnerable_version_range": "< 4.17.21" } }, "action": "created", "sender": { "login": "dependabot[bot]" }, "repository": { "full_name": "acme/web" } } ``` ## Signature check GitHub signs every webhook with an HMAC-SHA256 hash of the request body in the X-Hub-Signature-256 header, made with the secret you set on the webhook. JustPush checks it before the code runs. ## FAQ ### Does this work on iPhone and Android? Yes. Install the JustPush app from the App Store or Google Play and sign in. Every phone signed in to your account gets the notification. ### Do I need to write code? No. Install the recipe in Studio, paste your webhook URL into GitHub and you are done. The code is there if you want to change the text, the sound or the buttons. ### Can I change what the notification says? Yes. After install the recipe's code is yours. Edit it in Studio and test it against the sample payload before you save. ### What does it cost? JustPush is free for 30 days. After that it's $19.99 a year, or $39.99 once. There is no extra charge for recipes.