Put promotion on hold when credentials are exposed
A secret alert should trigger containment, not another item to remember.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Delete Advertising Campaign
Deletes a ToneDen advertising campaign by ID using DELETE /advertising/campaigns/{campaignID}.
Why this helps
Credential exposure can demand immediate attention, but active ads may continue running unnoticed during the response.
- Reduces promotion during an active security incident
- Creates an immediate containment step
- Removes reliance on memory during stressful work
Setup
Build it in a few focused steps.
- 1Connect GitHub and ToneDen to Notis once through the portal.
- 2Create the automation in the portal or ask Notis to create it conversationally.
- 3Use this instruction: When GitHub detects a new secret scanning alert, delete the related ToneDen campaign and report the campaign ID, alert, and action taken.
- 4Pick the secret scanning alert trigger and choose an urgent run-report channel.
- 5Test with a non-production campaign and a controlled alert scenario.
Questions about this workflow
Can I restrict this to active tokens?
Yes. Describe the secret validity or repository conditions that should qualify.
What if there is no matching campaign?
Ask Notis to report the alert and confirm that no campaign was found.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Toneden. A trigger fires from one place; an action lands in another.
GitHub triggers
Toneden actions
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Create Advertising Campaign
Tool to create a ToneDen advertising campaign on Facebook or Google platforms. Use when you need to launch a new ad campaign with specified budget, targeting, and creatives.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Create Attachment
Tool to create an attachment. Use when you need to programmatically create a social unlock or contest attachment after gathering all required parameters.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Create ToneDen Link
Tool to create a ToneDen link. Use when you have the target_type and, if needed, the services array. Supports creation of links for music, podcast, livestream, event, tour, biglink, fundraiser, smartlink, and custom types.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Delete Advertising Campaign
Deletes a ToneDen advertising campaign by ID using DELETE /advertising/campaigns/{campaignID}.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Delete ToneDen Link
Deletes a ToneDen link by ID using DELETE /links/{linkID}.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Delete ToneDen Playbook Campaign
Deletes a ToneDen playbook campaign by ID using DELETE /playbooks/campaigns/{campaignID}.
New Repository Collaborator Added
Triggers when a new collaborator is added to a GitHub repository. Monitors the full list of collaborators on a repository and fires an event for each newly added collaborator. The payload includes the collaborator's GitHub username, account ID, profile URL, avatar URL, permission flags (pull, triage, push, maintain, admin), and assigned role name.
Expand ToneDen Link Template
Tool to expand a ToneDen link template. Use when you need to retrieve the full template link with your tracking pixels and optional service links. Provide a URL to generate platform services for music or podcast content.
Commit Event
Triggered when a new commit is pushed to a repository.
Get Advertising Campaign
Retrieve a specific advertising campaign by its ID using ToneDen's API. Endpoint: GET /advertising/campaigns/{campaignID} Notes: - This endpoint does not require a userID in the path per official docs. - Some accounts may not have advertising access; in such cases, non-2xx responses are still returned here for observability instead of raising, so the caller can inspect the error object.
Connect any two apps with Notis in the middle.
Not just GitHub and Toneden. Any combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7 days free trial with 20$ free usage included.
No card. Works with personal or business Toneden.