Turn security alerts into owned, documented decisions
A new vulnerability alert should produce a clear decision trail, not another notification to mentally hold.
Trigger
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Action
Create Document
Tool to create a new document for signature. use after finalizing document details and signer list.
Why this helps
Security alerts can be acknowledged informally while remediation ownership and risk acceptance remain unclear.
- Creates a formal record for security decisions.
- Reduces the chance of alerts being silently deferred.
- Makes severity and remediation context easy to review.
- Supports clearer handoffs between technical and business owners.
Setup
Build it in a few focused steps.
- 1Connect GitHub and Eversign once through the portal.
- 2Create an automation: “When a new GitHub code scanning alert is created, create an Eversign security acknowledgement request containing the alert severity, rule, location, and remediation owner.”
- 3Choose the New Code Scanning Alert Created trigger and set the severity filters you need.
- 4Select a reporting channel and test with a low-risk alert.
Questions about this workflow
Can alerts be filtered by severity?
Yes. The GitHub trigger supports severity and scanning-tool filters.
Is this a replacement for remediation?
No. It documents acknowledgement and ownership so remediation is less likely to be forgotten.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Eversign. A trigger fires from one place; an action lands in another.
GitHub triggers
Eversign actions
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Get Document Audit Log
Tool to retrieve the audit log for a document. use after obtaining the document hash to view its full event history.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Create Document
Tool to create a new document for signature. use after finalizing document details and signer list.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Create Template
Tool to create a new template. use when you need to programmatically set up reusable document templates after confirming your business settings.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Delete Document or Template
Tool to delete a document or template by its hash. use when you need to permanently remove a document or template.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Get Bulk Jobs List
Tool to retrieve a list of bulk jobs for a business. use when you need to view or paginate existing bulk jobs.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
List Businesses
Tool to retrieve a list of businesses associated with your account. use when you need to fetch all businesses available to the authenticated user.
New Repository Collaborator Added
Triggers when a new collaborator is added to a GitHub repository. Monitors the full list of collaborators on a repository and fires an event for each newly added collaborator. The payload includes the collaborator's GitHub username, account ID, profile URL, avatar URL, permission flags (pull, triage, push, maintain, admin), and assigned role name.
List Documents
Tool to list documents for a business. use when you need to retrieve documents with optional filters after setting business id in query params.
Commit Event
Triggered when a new commit is pushed to a repository.
List Templates
Tool to list templates for a business with optional pagination. use when you need to retrieve a paginated list of templates.
Connect any two apps with Notis in the middle.
Not just GitHub and Eversign. Any combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7 days free trial with 20$ free usage included.
No card. Works with personal or business Eversign.