Clean up obsolete Zeplin annotations after secret alerts
Prevent old credential references from lingering in design handoff notes after they need attention.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Delete Screen Annotation
Tool to delete a screen annotation in Zeplin. Use when you need to remove a specific annotation from a Zeplin screen given its IDs.
Why this helps
Retired credentials can remain mentioned in annotations long after the code alert is resolved.
- Reduces stale sensitive references
- Keeps handoff notes current
Setup
Build it in a few focused steps.
- 1Connect GitHub and Zeplin to Notis.
- 2Create a new automation in the portal.
- 3Tell Notis to remove only a confirmed obsolete annotation related to a secret alert.
- 4Select New Secret Scanning Alert Detected and a reporting channel.
- 5Test with a safe, non-sensitive example before relying on it.
Questions about this workflow
Will it delete annotations without context?
No. Make the confirmation conditions explicit in the plain-language prompt.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Zeplin. A trigger fires from one place; an action lands in another.
GitHub triggers
Zeplin actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Start OAuth authorization (PKCE)
Tool to start OAuth 2.0 authorization code flow for Zeplin apps. Use when initiating user authorization; call before exchanging the code.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
List Project Connected Components
Tool to list connected components in a Zeplin project. Use when you have the project_id and need to retrieve connected components in a specific project.
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
List Project Colors
Tool to list colors in a Zeplin project. Use when you need to fetch defined color tokens at the project level after obtaining the project ID.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Update Project Color
Tool to update a color in a Zeplin project. Use when you need to modify RGBA channels or source ID of an existing color after confirming the project and color IDs.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Get Zeplin Project by ID
Tool to get a Zeplin project by ID. Use when you need detailed info about a specific project after confirming its project_id.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Invite Project Member
Tool to invite a user to a Zeplin project. Use when you need to add a member by email or username to a project after obtaining the project ID.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
List Project Text Styles
Tool to list text styles in a Zeplin project. Use when you need to fetch typography tokens defined at the project level after obtaining the project ID.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Update Project Text Style
Tool to update a text style in a Zeplin project. Use when you need to modify typography settings of an existing text style after confirming the project and text style IDs.
Connect any two apps with Notis in the middle.
GitHub and Zeplin, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Zeplin.