Skip to content
Notis

Review domains named in code scanning alerts

Turn a code scanning alert that names a domain into a quick DNSFilter threat check, with the finding still available for follow-up.

Trigger

New Code Scanning Alert Created

Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.

Action

Suggest Domain Threat

Tool to suggest a fqdn as a potential threat. use after identifying a suspicious domain to verify its threat categorization.

Why this helps

Security findings can be easy to lose in a busy issue queue, especially when checking a related domain requires another manual lookup.

  • Give domain related findings an immediate threat lookup.
  • Keep attention on actionable alerts instead of repeating manual checks.
  • Use the GitHub alert as the starting point for review.

Setup

Build it in a few focused steps.

  • 1Connect GitHub and DNSFilter once in the Notis portal.
  • 2Create an automation in Automations, New Automation, and name it for code alert review.
  • 3In one instruction, ask Notis to request a DNSFilter threat suggestion for any domain in each new code scanning alert.
  • 4Pick the new code scanning alert trigger, then select a report channel.
  • 5Test with one real alert that includes a domain.

Questions about this workflow

Does this analyze every alert field?

Notis can work with information returned in the alert. A domain must be present in the alert details for DNSFilter to check it.

Can this change DNSFilter filtering policies?

No. The listed action suggests a domain threat classification and does not update filtering policies.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link GitHub to Dnsfilter. A trigger fires from one place; an action lands in another.

GitHub triggers

Dnsfilter actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Create IP Address

Tool to create a new ip address in dnsfilter. use after confirming the target network id exists.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get Application Category

Tool to get basic information of a specific application category. use when you need details for a given application category id.

ActionInstant

New Workflow Artifact Created

Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.

TriggerPolling

Get Billing Information

Tool to retrieve basic billing information for an organization. use when you need to obtain billing details for reporting or automation tasks.

ActionInstant

Branch Changed

Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.

TriggerPolling

Get Category

Tool to get basic information of a specific category. use when you need to retrieve details for a category by its id.

ActionInstant

New Branch Created

Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.

TriggerPolling

Get IP Address

Tool to get basic information of the specified ip address. use when you need to fetch metadata for a particular ip after authentication.

ActionInstant

Check Run Status / Conclusion Changed

Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.

TriggerPolling

List All Categories

Tool to list all categories including internal categories. use when you need the complete set of filtering categories.

ActionInstant

Check Suite Status / Conclusion Changed

Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.

TriggerPolling

List All IP Addresses

Tool to list all user-associated ip addresses. use when you need a comprehensive list of all ip address entries in your organization.

ActionInstant

New Code Scanning Alert Created

Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.

TriggerPolling

List All MAC Addresses

Tool to list all mac addresses with basic information. use when you need to retrieve all mac address entries in your organization.

ActionInstant

Connect any two apps with Notis in the middle.

GitHub and Dnsfilter, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Dnsfilter.