ENGINEERING
Route GitLab dependency-bump MRs through CVE-aware review
When a merge request changes a lockfile or manifest, it extracts the changed dependencies, checks them for known vulnerabilities.
How it runs
The automated pipeline, trigger to output.
- TriggerGitLab merge request openedGitLab
- LogicDetect lockfile or manifest changes
- ActionExtract changed packages and query CVE advisoriesHTTP webhook
- LogicBranch on whether a vulnerable version is introduced
- OutputLabel, route to security pool, and comment CVEsGitLab
What it does
Gives dependency changes their own security lane. When an MR edits a lockfile or package manifest, the flow diffs which packages and versions changed, looks each up against vulnerability advisories, and decides routing on the result. Bumps that pull in a flagged version get the security label, the reviewer pool, and a comment listing the specific CVEs so the reviewer knows exactly what to check.
When to use it
Use it when automated dependency PRs (or manual bumps) are frequent and you don't want every one of them to consume a security reviewer — only the ones that actually introduce known-vulnerable versions.
How it works
- 1A GitLab webhook fires on merge request open.
- 2A logic step checks whether the MR touches a lockfile or manifest; unrelated MRs exit.
- 3The flow extracts changed package names and versions from the diff and queries advisory data over HTTP.
- 4If any package matches a known vulnerability, it labels the MR, assigns the security pool, and comments the advisory details.
- 5Clean dependency bumps get an auto-approve-eligible label and pass through to the default pool.
Set it up
What you configure once, before turning it on.
- 1Connect GitLabRepos, MRs, pipelines, registry.
- 2Connect HTTP webhookTrigger any URL on agent actions.
- 3Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 4Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 5Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Engineering workflows
Gate breaking API PRs behind downstream consumer acknowledgement
When a PR introduces a breaking contract change, comments the impact summary back on the PR, applies a blocking label.
Publish a versioned API changelog to Confluence on each release tag
On a new semver release tag, gathers the contract changes since the last release and writes a clean.
Agent reviews model-license fit and suggests compliant swaps on the PR
When a PR adds a Hugging Face model, an agent reads the model card and license, judges fit against your commercial-use policy.
Upgrade Impact Router to Module Code Owners
Maps a dependency-bump PR's affected modules to their CODEOWNERS, then DMs each owner on Slack with only the changelog slice that touches code they own.
Re-Voice IVR Prompts on Phone-Tree Config Merge
When a phone-tree config change merges in GitHub, regenerates the ElevenLabs audio for any prompt whose script changed in the diff and opens a follow-up PR adding the new audio…
Upstream Release to Notion Upgrade Brief
When a watched package publishes a new release, fetches the release notes, maps them to the internal modules that depend on it.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
