Skip to content
Notis

Review IP geography metadata from GitHub

Keep the policy explicit and the conclusion limited to returned metadata.

Trigger

New Issue Created

Triggers when a new issue is created in a GitHub repository. Pull requests are automatically excluded -- only true issues produce events. Results can be filtered by labels, assignee, creator, and mentioned user. The payload includes the issue number, title, body, state, labels, assignees, comment count, creator details, timestamps, and direct links to the issue on GitHub.

Action

Search IPs

Tool to search IP addresses via SecurityTrails DSL. Use when you need to filter IPs with custom DSL queries.

Why this helps

Geography questions consume attention when the policy and evidence are not stated together.

  • Uses a stated policy.
  • Reports only returned geography fields.
  • Avoids legal or ownership claims.

Setup

Build it in a few focused steps.

  • 1Connect GitHub and SecurityTrails once.
  • 2Ask Notis to run the supported DSL query and compare returned geography fields with the issue policy.
  • 3Choose the new-issue trigger and report channel, then test with one policy example.

Questions about this workflow

What if geography is not returned?

The workflow reports that the policy review cannot be determined from the available fields.

Is this a legal compliance decision?

No. It is a metadata comparison against the policy supplied by the user.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link GitHub to Securitytrails. A trigger fires from one place; an action lands in another.

GitHub triggers

Securitytrails actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Bulk Static Asset Rules

Tool to bulk add or remove static asset rules for a project. Use when performing batch updates (up to 1000 rules total) asynchronously; verify changes via the Get Static Assets endpoint.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get Company Associated IPs

Tool to retrieve IPs associated with a company domain. Use when you need to find all IP addresses linked to an organization's domain name.

ActionInstant

New Workflow Artifact Created

Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.

TriggerPolling

Get Domain

Tool to retrieve current data about a given domain, including DNS record statistics. Use when you need to fetch detailed domain insights after determining the target hostname.

ActionInstant

Branch Changed

Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.

TriggerPolling

Get Domain SSL

Tool to fetch current and historical SSL certificate details for a hostname. Use when you need to retrieve SSL data after identifying the domain.

ActionInstant

New Branch Created

Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.

TriggerPolling

IP Search Statistics

Tool to fetch summary statistics for an IP DSL query. Use when you need metrics for IP search queries.

ActionInstant

Check Run Status / Conclusion Changed

Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.

TriggerPolling

List ASI Projects

Tool to list ASI projects available to the account. Use when you need project IDs for subsequent ASI operations.

ActionInstant

Check Suite Status / Conclusion Changed

Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.

TriggerPolling

Ping

Tool to test authentication and connectivity with the SecurityTrails API. Use after configuring API key.

ActionInstant

New Code Scanning Alert Created

Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.

TriggerPolling

Scroll Results

Tool to continue scrolling through DSL search results. Use after receiving a scroll_id from a prior search to fetch the next batch of data.

ActionInstant

Connect any two apps with Notis in the middle.

GitHub and Securitytrails, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Securitytrails.