Skip to content
Notis

Create a focused response to secret alerts

Keep the response narrow, visible, and tied to the right account information.

Trigger

New Secret Scanning Alert Detected

Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.

Action

Read account

Tool to retrieve details for a specific account. use after obtaining valid user and account guids to fetch up-to-date account information.

Why this helps

A secret alert can scatter attention across code, credentials, and operations without one clear response checkpoint.

  • Creates a predictable response moment
  • Brings account information into the alert workflow
  • Helps reduce fragmented incident handling

Setup

Build it in a few focused steps.

  • 1Connect GitHub and Mx technologies to Notis once in the portal.
  • 2Create the automation in the portal or ask Notis to set it up conversationally.
  • 3Use this instruction: “When a new secret scanning alert is detected, retrieve the details for my selected Mx account and summarize the alert and account context.”
  • 4Choose the secret-scanning trigger, select a reporting channel, and test with a controlled real example.

Questions about this workflow

Should this replace credential rotation?

No. It provides context; follow your normal security response process for rotating or revoking credentials.

Can I include token validity?

Yes. Ask Notis to include the validity status from the GitHub alert.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link GitHub to Mx technologies. A trigger fires from one place; an action lands in another.

GitHub triggers

Mx technologies actions

New Workflow Artifact Created

Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.

TriggerPolling

Cancel Partner Account

Tool to cancel (disable) a client account under a partner account. this maps to mx platform api: put /users/{guid} with body {"user": {"is disabled": true, "metadata": "..."}}.

ActionInstant

Branch Changed

Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.

TriggerPolling

Create account

Tool to create a manual account for a given user. use when you need to add an external or test account to a user record.

ActionInstant

New Branch Created

Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.

TriggerPolling

Retrieve Audience API Credentials

Tool to retrieve audience api credentials. use when obtaining client id and client secret for audience service authentication before generating an access token. credentials must be created in the partner dashboard (partner administrator → authentication → audience api key). the tool prefers explicitly provided values, then falls back to environment variables.

ActionInstant

Check Run Status / Conclusion Changed

Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.

TriggerPolling

Create member

Tool to create a member and start aggregating specified financial products. use after confirming user guid and gathering connection credentials or oauth details.

ActionInstant

Check Suite Status / Conclusion Changed

Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.

TriggerPolling

Create Partner Account

Tool to create a new client account under a partner account. use when provisioning a new constant contact client after obtaining api key and jwt authorization.

ActionInstant

New Code Scanning Alert Created

Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.

TriggerPolling

Create Partner Account User SSO

Tool to create a new partner account user with single sign-on enabled. use when adding an sso user under a partner client account with 'sso for all users' enabled.

ActionInstant

New Repository Collaborator Added

Triggers when a new collaborator is added to a GitHub repository. Monitors the full list of collaborators on a repository and fires an event for each newly added collaborator. The payload includes the collaborator's GitHub username, account ID, profile URL, avatar URL, permission flags (pull, triage, push, maintain, admin), and assigned role name.

TriggerPolling

Fetch rewards

Tool to initiate rewards aggregation for a specific member. use after connecting the member to trigger an async rewards job.

ActionInstant

Commit Event

Triggered when a new commit is pushed to a repository.

TriggerInstant

Get configurable widget URL

Tool to retrieve a configurable widget url for a user. use after determining the user guid.

ActionInstant

Connect any two apps with Notis in the middle.

Not just GitHub and Mx technologies. Any combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7 days free trial with 20$ free usage included.
No card. Works with personal or business Mx technologies.