Verify domains from code scanning alerts
Give a security alert an immediate mail-domain signal without opening another tool during incident triage.
Trigger
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Action
Verify Domain
Tool to verify the validity and configuration of a domain. use when you need to confirm the domain's mx records and catch-all behavior.
Why this helps
A small configuration clue can be lost while a founder is juggling a security alert and delivery work.
- Adds fast investigation context
- Reduces tool hopping
- Supports focused triage
Setup
Build it in a few focused steps.
- 1Connect GitHub and Bouncer in the Notis portal.
- 2Create a new automation.
- 3Tell Notis to verify any relevant domain referenced by a new code scanning alert.
- 4Choose New Code Scanning Alert Created and a reporting channel.
- 5Test the prompt with a representative alert.
Questions about this workflow
Does this replace security remediation?
No. It adds domain verification context to the alert workflow.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Bouncer. A trigger fires from one place; an action lands in another.
GitHub triggers
Bouncer actions
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Check Toxicity List Job Status
Tool to check the status of a specific toxicity list job. use after creating a toxicity list job to poll its status until completion.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Create Batch Request
Tool to initiate a batch email verification request. use when you have multiple emails to verify in one api call. returns a batch id and initial status.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Create Toxicity List Job
Tool to create a toxicity analysis job for a list of email addresses. use when you need to batch-process toxicity checks for multiple emails at once.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Delete batch request
Tool to delete a batch verification request. use when you need to remove all associated emails and results for a specific batch after confirming that the batch data is no longer required.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Delete Toxicity List Job
Tool to delete a specific toxicity list job. use when you need to remove a completed or unwanted toxicity analysis job after confirming its id.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Finish Batch
Tool to mark a batch verification process as finished. use after batch processing completes to stop further verifications and reclaim unused credits.
New Repository Collaborator Added
Triggers when a new collaborator is added to a GitHub repository. Monitors the full list of collaborators on a repository and fires an event for each newly added collaborator. The payload includes the collaborator's GitHub username, account ID, profile URL, avatar URL, permission flags (pull, triage, push, maintain, admin), and assigned role name.
Get Batch Results
Tool to retrieve the results of a batch verification process. use after submitting a batch to fetch all processed email verification outcomes.
Commit Event
Triggered when a new commit is pushed to a repository.
Verify Domain
Tool to verify the validity and configuration of a domain. use when you need to confirm the domain's mx records and catch-all behavior.
Connect any two apps with Notis in the middle.
Not just GitHub and Bouncer. Any combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7 days free trial with 20$ free usage included.
No card. Works with personal or business Bouncer.