Review domains named in code scanning alerts
Turn a code scanning alert that names a domain into a quick DNSFilter threat check, with the finding still available for follow-up.
Trigger
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Action
Suggest Domain Threat
Tool to suggest a fqdn as a potential threat. use after identifying a suspicious domain to verify its threat categorization.
Why this helps
Security findings can be easy to lose in a busy issue queue, especially when checking a related domain requires another manual lookup.
- Give domain related findings an immediate threat lookup.
- Keep attention on actionable alerts instead of repeating manual checks.
- Use the GitHub alert as the starting point for review.
Setup
Build it in a few focused steps.
- 1Connect GitHub and DNSFilter once in the Notis portal.
- 2Create an automation in Automations, New Automation, and name it for code alert review.
- 3In one instruction, ask Notis to request a DNSFilter threat suggestion for any domain in each new code scanning alert.
- 4Pick the new code scanning alert trigger, then select a report channel.
- 5Test with one real alert that includes a domain.
Questions about this workflow
Does this analyze every alert field?
Notis can work with information returned in the alert. A domain must be present in the alert details for DNSFilter to check it.
Can this change DNSFilter filtering policies?
No. The listed action suggests a domain threat classification and does not update filtering policies.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Dnsfilter. A trigger fires from one place; an action lands in another.
GitHub triggers
Dnsfilter actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Create IP Address
Tool to create a new ip address in dnsfilter. use after confirming the target network id exists.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get Application Category
Tool to get basic information of a specific application category. use when you need details for a given application category id.
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Get Billing Information
Tool to retrieve basic billing information for an organization. use when you need to obtain billing details for reporting or automation tasks.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Get Category
Tool to get basic information of a specific category. use when you need to retrieve details for a category by its id.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Get IP Address
Tool to get basic information of the specified ip address. use when you need to fetch metadata for a particular ip after authentication.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
List All Categories
Tool to list all categories including internal categories. use when you need the complete set of filtering categories.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
List All IP Addresses
Tool to list all user-associated ip addresses. use when you need a comprehensive list of all ip address entries in your organization.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
List All MAC Addresses
Tool to list all mac addresses with basic information. use when you need to retrieve all mac address entries in your organization.
Connect any two apps with Notis in the middle.
GitHub and Dnsfilter, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Dnsfilter.