Put outreach on hold when credentials may be exposed
Make the urgent security response easier to protect and prioritize.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Pause Campaign
Tool to pause a campaign. Use when you need to temporarily stop sending prospects until resumed.
Why this helps
A possible credential exposure creates immediate risk, yet active campaigns may continue unless someone manually pauses them.
- Stops outbound activity during a sensitive incident.
- Reduces the number of decisions required under pressure.
- Helps prevent poorly timed messages while access is investigated.
Setup
Build it in a few focused steps.
- 1Connect GitHub and Woodpecker co to Notis once through the portal.
- 2Create an automation in the portal or ask Notis to pause the specified Woodpecker campaigns when a secret scanning alert is detected.
- 3Choose the new secret scanning alert trigger and select a channel for run reports.
- 4Test with a dedicated test campaign and document the expected pause behavior.
Questions about this workflow
Can this target only active secrets?
Yes. Use the GitHub alert filters and specify the token validity conditions in the instruction.
Does it resolve the security alert?
No. It only pauses outreach so you can focus on remediation in GitHub.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Woodpecker co. A trigger fires from one place; an action lands in another.
GitHub triggers
Woodpecker co actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Add prospects to a campaign (v1)
Tool to add one or multiple prospects to a campaign. Use when you need to import prospects into a campaign's contact list.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Campaign Step
Tool to delete a non-initial campaign step that hasn't processed any prospects. Use when the campaign is in DRAFT or EDITED status and the step is unused.
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Get Prospects in Campaigns (v1)
Tool to retrieve prospects enrolled in specified campaigns. Use when you need to list prospects for given campaign IDs.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
List Available Webhook Events
Tool to list all webhook event names supported by Woodpecker. Use before subscribing to ensure valid 'event' values (static catalog from docs).
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
List Campaigns V1
Tool to list campaigns. Use when you need to fetch campaigns with optional status or ID filters.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Pause Campaign
Tool to pause a campaign. Use when you need to temporarily stop sending prospects until resumed.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Run Campaign
Tool to run a campaign and set its status to RUNNING. Use when you want to activate a configured campaign after final review.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Stop Campaign
Tool to stop a campaign. Use when you need to halt prospect contacts by setting campaign status to STOPPED.
Connect any two apps with Notis in the middle.
GitHub and Woodpecker co, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Woodpecker co.