Skip to content
Notis

Check npm advisories when a dependency concern is commented

A comment that flags a package can trigger an advisory check, so the concern gets an answer to work from instead of becoming another open loop.

Trigger

Comment Created

Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.

Action

Query Bulk Security Advisories

Tool to bulk query security advisories for multiple npm packages. Use when you need to check vulnerability information for multiple packages and versions at once.

Why this helps

Dependency concerns raised in discussion can disappear beneath newer comments before anyone checks the package.

  • Give a package concern a concrete follow-up.
  • Reduce the chance that a comment remains unanswered.
  • Keep the result tied to the discussion that raised it.

Setup

Build it in a few focused steps.

  • 1Connect Notion and Npm to Notis once in the portal and ensure the Notion connection can read comments.
  • 2Create an automation in the portal or ask Notis to check package concerns raised in Notion comments.
  • 3In one instruction, ask Notis to identify an exact package and version in a new comment, query npm advisories, and report the findings.
  • 4Choose the Notion Comment Created trigger and a channel for run reports.
  • 5Test by adding a comment to a real project page with an exact package and version.

Questions about this workflow

Does the Notion connection need extra access?

Yes. Comment events require the Read comments capability, and a connection authorized before that capability was enabled may need re-authorization.

What if the comment does not include a version?

The report can note that the version is missing; include exact package details in the comment for a useful check.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Notion to Npm. A trigger fires from one place; an action lands in another.

Notion triggers

Npm actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Delete User Token (Legacy)

Tool to delete a user authentication token using the legacy endpoint. Use when you need to revoke or remove a specific token from the npm registry.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get All Packages Download Count Point

Get total npm registry download statistics for all packages for a specified time period. Returns aggregate download counts across the entire npm registry with start/end dates. Supports preset periods (last-day, last-week, last-month, last-year) or custom date ranges (YYYY-MM-DD:YYYY-MM-DD).

ActionInstant

All Page Events

Triggers when any Notion page is created or updated across the workspace.

TriggerPolling

Get NPM Download Counts Point

Get npm package download statistics for a specified time period. Returns total download counts with start/end dates for single packages, scoped packages, or bulk queries (up to 128 packages). Supports preset periods (last-day, last-week, last-month, last-year) or custom date ranges (YYYY-MM-DD:YYYY-MM-DD).

ActionInstant

Comment Created

Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.

TriggerInstant

Get NPM Package Download Counts Over Date Range

Tool to get download counts for an npm package over a specified date range. Use when you need historical daily download data.

ActionInstant

New Comment

Triggers when a new comment is added to a specified Notion block or page.

TriggerPolling

Get All NPM Packages Download Counts by Period

Tool to get daily download counts for all npm packages over a specified period. Use when you need aggregate download statistics across the entire npm registry.

ActionInstant

Database Created

Triggers when a new Notion database (the container) is created. A database is the post-2025-09-03 container that holds one or more data sources. This trigger fires for the container's creation event (`database.created`), distinct from `NOTION_DATASOURCE_CREATED` which fires when a new data source is added to an existing database. Most customers calling Notion's `POST /v1/databases` (the legacy API) or creating a database via the Notion UI will see this event. Adding a new data source to an existing database fires `data_source.created` instead — use `NOTION_DATASOURCE_CREATED` for that. Notion's payload puts `entity.type: "block"` (the container is a `child_database` block in the content tree) and `entity.id` is the database id.

TriggerInstant

Get Registry Changes Feed

Tool to get a stream of registry changes for replication purposes. Returns CouchDB-style change feed for following registry updates.

ActionInstant

Data Source Created

Triggers when a new Notion data source is created. Fires workspace-wide. The payload's `data.parent` carries the data source's tree parent (typically the teamspace) for downstream filtering. A single template-based database creation can fire multiple `data_source.created` events at once — one per data source the template instantiates.

TriggerInstant

Get NPM Registry Meta

Retrieves npm registry metadata via meta endpoints. Use 'ping' to verify registry connectivity or 'whoami' to get the authenticated username.

ActionInstant

Data Source Schema Updated

Triggers when a Notion data source's schema is updated. Fires on column add / remove / rename. Payload includes `data.updated_properties: [{id, name, action}]` so consumers can discriminate the kind of change downstream. Optional `data_source_id` filter scopes to schema changes on a single data source. When omitted, fires for any schema change in the workspace the integration has access to. Note: adding a column also fires `page.properties_updated` once per existing row in the data source. Customers wanting a single structural-change signal should use this trigger.

TriggerInstant

Get NPM Package Version Downloads (Last 7 Days)

Tool to get download counts for specific versions of a package over the last 7 days. Use when you need to understand which versions are most popular.

ActionInstant

Connect any two apps with Notis in the middle.

Notion and Npm, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Npm.