Turn a secret alert into a clear, formal response
A new secret scanning alert can start a prepared letter to your designated security contacts, with Notis keeping the response tied to the GitHub event.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Send Letter
Tool to send a letter via u.s. mail with specified recipient, sender, and pdf. use after confirming recipient and document details. example: send letter(to name='john doe', to address='123 main st, ...', file url='https://...')
Why this helps
Security alerts need timely follow-up, and a separate mailing task can be easy to miss while responding to the issue.
- Put formal notification in the same flow as alert handling.
- Use a response document and contacts you have already approved.
- Keep a run report for later follow-up.
Setup
Build it in a few focused steps.
- 1Connect GitHub and Docupost once in the Notis portal.
- 2Create an automation in Automations, New Automation, and name the security notification.
- 3In one instruction, tell Notis how to use the alert details and your approved PDF, and specify the security contacts and their mailing addresses.
- 4Pick the GitHub New Secret Scanning Alert Detected trigger, then choose where run reports should go.
- 5Test with one real example and confirm the recipient and PDF details before sending.
Questions about this workflow
Does the alert include mailing addresses?
No. Provide the intended contacts and their mailing addresses in your instruction or an available trusted source.
Can Notis write the incident response letter?
Notis can use available alert details to help prepare content, but Send Letter requires a PDF. Supply an approved PDF URL or a defined process to create one.
Does every alert need to result in a letter?
Describe the conditions for sending in your instruction. The workflow should send only when the needed recipient and document details are available.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Docupost. A trigger fires from one place; an action lands in another.
GitHub triggers
Docupost actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Send Letter
Tool to send a letter via u.s. mail with specified recipient, sender, and pdf. use after confirming recipient and document details. example: send letter(to name='john doe', to address='123 main st, ...', file url='https://...')
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Send Postcard
Tool to send a postcard via u.s. mail with specified recipient, sender, and front/back images. use after confirming recipient addresses and design urls. example: send postcard(to name='john doe', ..., front image='https://...', back image='https://...')
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Connect any two apps with Notis in the middle.
GitHub and Docupost, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Docupost.