Turn New GitHub Secret Alerts Into Faster IP Risk Checks
When a secret alert lands, quickly check whether its associated IP is linked to a proxy, VPN, or TOR exit node.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
IP2Proxy: Get Proxy Detection
Tool to detect if an IP is a proxy, VPN, or TOR exit node. Use when verifying anonymizing services.
Why this helps
Security alerts create urgent context switching when the founder has to investigate IP risk manually.
- Adds proxy and anonymizer context to secret alerts
- Reduces manual security lookups
- Creates a consistent first response
Setup
Build it in a few focused steps.
- 1Connect GitHub and Ip2location to Notis once through the portal.
- 2Create an automation in the portal or ask Notis to create one in plain language.
- 3Tell Notis: When a new GitHub secret scanning alert includes an IP, check it with IP2Proxy and report the result with the alert link.
- 4Select the new secret scanning alert trigger and choose where Notis should report runs.
Questions about this workflow
What does the workflow check?
It checks whether the IP associated with a new secret scanning alert appears to be a proxy, VPN, or TOR exit node.
Can I test it safely?
Yes. Trigger one real alert in a test repository and review the run report.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Ip2location. A trigger fires from one place; an action lands in another.
GitHub triggers
Ip2location actions
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Bulk IP Geolocation
Tool to retrieve geolocation information for multiple IP addresses in bulk. Use when you need batch processing of up to 1000 IPs per request.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Check IP2Location API Credits
Tool to check remaining IP2Location API credits. Use after setting up authentication to monitor usage.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
IP2WHOIS Hosted Domains Lookup
Tool to retrieve hosted domains for a given IP address. Use when you need to list domains hosted on an IP.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
IP2Location Get IP Geolocation
Tool to retrieve geolocation data for an IP address. Use when detailed IP location info is needed.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
IP2Proxy: Get Proxy Detection
Tool to detect if an IP is a proxy, VPN, or TOR exit node. Use when verifying anonymizing services.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
IP2Location Distance Calculator
Tool to calculate distance between two IPs. Use when geographic separation between two IP addresses is needed.
New Repository Collaborator Added
Triggers when a new collaborator is added to a GitHub repository. Monitors the full list of collaborators on a repository and fires an event for each newly added collaborator. The payload includes the collaborator's GitHub username, account ID, profile URL, avatar URL, permission flags (pull, triage, push, maintain, admin), and assigned role name.
IP2WHOIS Domain WHOIS Lookup
Tool to retrieve WHOIS information for a domain. Use when you need domain registration details.
Commit Event
Triggered when a new commit is pushed to a repository.
IP2Location List IPs
Tool to list a curated set of test IPv4 and IPv6 addresses. Use when sample IPs are needed for IP2Location or IP2Proxy lookups during development or testing.
Connect any two apps with Notis in the middle.
Not just GitHub and Ip2location. Any combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7 days free trial with 20$ free usage included.
No card. Works with personal or business Ip2location.