Give new code scanning alerts a report your team can act on
A new code scanning alert contains concrete findings. Notis can use the alert details in a Carbone template to create a readable report for your review and follow-up.
Trigger
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Action
Generate Carbone Report
Tool to generate a carbone report from a template and json data. use when you need to render documents in various formats.
Why this helps
Security findings can be easy to postpone when their context is buried in the repository scanner, especially when a founder must turn each alert into a shareable handoff.
- Carry the alert number, rule details, tool, state, severity, and latest finding location into a report.
- Give security follow-up a consistent document format without rewriting scanner details.
- Use the configured repository, reference, tool, state, or severity filters to keep the workflow focused.
Setup
Build it in a few focused steps.
- 1Connect GitHub and Carbone to Notis once, and prepare a Carbone template for security findings.
- 2Create the automation through the portal or in conversation, with one plain-language instruction describing which new code scanning alerts should produce a report.
- 3Choose the new code scanning alert trigger and any available alert filters; select a channel for Notis run reports.
- 4Test with a real alert and verify the generated report includes the finding details your review process needs.
Questions about this workflow
What alert information can the report use?
The trigger payload includes the alert number, rule details, scanning tool, state, severity, and location of the most recent instance.
Can this close or resolve the alert?
No. This workflow generates a Carbone report from a new alert; it does not change the GitHub alert's state.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Carbone. A trigger fires from one place; an action lands in another.
GitHub triggers
Carbone actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Delete Carbone Template
Tool to delete a template from the carbone server. use after confirming you have the correct template id.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Download Template
Tool to download a template from carbone by template id. use when you need to retrieve the original template file.
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Generate Carbone Report
Tool to generate a carbone report from a template and json data. use when you need to render documents in various formats.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Generate Template ID
Tool to generate a unique template id for a new template. use when you need the template identifier before uploading.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Get Carbone Server Status
Tool to retrieve the current status and health of the carbone server. use before generating reports to ensure the service is operational.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Set Carbone API Version
Tool to set the carbone api version to be used for subsequent requests. use before rendering or managing templates to ensure correct version is applied.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Upload a template
Tool to upload a template to the carbone server. use when you need to add or replace a template by providing its content.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Connect any two apps with Notis in the middle.
GitHub and Carbone, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Carbone.