React to secret alerts before the next release
A secret alert needs a fast, concrete response. Notis can add a targeted DeployHQ exclusion while keeping you informed about what changed.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Create Excluded File
Tool to add a new excluded file to a project. Use when you need to exclude specific files or patterns from deployment to prevent them from being deployed to servers.
Why this helps
Security alerts compete with everything else on a founder's plate, increasing the chance that a risky path remains in the deployment configuration.
- Adds a deployment barrier for qualifying secret-related paths.
- Provides an immediate report of the protective action.
- Reduces the chance of silently carrying a risky file into release.
Setup
Build it in a few focused steps.
- 1Connect GitHub and DeployHQ to Notis once through the portal.
- 2Create the automation in Automations or ask Notis to set it up in plain language.
- 3Tell Notis to add a targeted DeployHQ excluded-file rule for a qualifying new secret alert and report the result.
- 4Select the secret-scanning trigger, choose the run-report channel, and test with a non-sensitive example.
Questions about this workflow
Does this revoke the secret?
No. It adds a DeployHQ exclusion; secret rotation should follow your security process.
Can the prompt limit the action by secret type?
Yes. Specify which alert types or validity states should qualify.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to DeployHQ. A trigger fires from one place; an action lands in another.
GitHub triggers
DeployHQ actions
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Delete Command
Tool to delete a command from a specified project. Use when you need to remove an SSH command from a project's configuration.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Delete Project
Tool to delete a project from DeployHQ. Use when you need to permanently remove a project by its permalink or identifier.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Delete Build Cache File
Tool to delete an existing build cache file from a project. Use when you need to remove a cached build artifact from the project's build cache storage.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Delete Excluded File Rule
Tool to delete an existing excluded file rule from a project. Use when you need to remove an excluded file pattern from deployment configuration.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Delete Server Group
Tool to delete a server group from a project using the DeployHQ API. Use when you need to remove a server group from deployment configuration.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Delete Template
Tool to delete a template by its unique permalink. Use when you need to permanently remove a template from DeployHQ.
New Repository Collaborator Added
Triggers when a new collaborator is added to a GitHub repository. Monitors the full list of collaborators on a repository and fires an event for each newly added collaborator. The payload includes the collaborator's GitHub username, account ID, profile URL, avatar URL, permission flags (pull, triage, push, maintain, admin), and assigned role name.
Get Projects
Tool to retrieve all projects from DeployHQ account. Use when you need to list all available projects and their configurations.
Commit Event
Triggered when a new commit is pushed to a repository.
Get Project
Tool to view an existing project in DeployHQ. Use when you need to retrieve details about a specific project by its permalink or identifier.
Connect any two apps with Notis in the middle.
Not just GitHub and DeployHQ. Any combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7 days free trial with 20$ free usage included.
No card. Works with personal or business DeployHQ.