All templates

Automated Checkmarx Critical Finding Alerts

Every morning, WebRun opens Checkmarx, checks the latest scan results across every monitored project for newly introduced critical or high severity findings, saves the full scan report to a Google Drive folder for the security team's records, and posts an alert to Slack naming the project and finding so nothing critical waits until the next manual review.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Checkmarx find newly introduced critical findings
2 Google Drive save the full scan report
3 Slack alert the security channel
In short

How do I get alerted about critical Checkmarx findings right away?

WebRun checks Checkmarx every morning for newly introduced critical or high severity findings across every monitored project. It saves the full scan report to Google Drive for the security team's records, and posts a Slack alert naming the project and finding, so nothing critical waits until the next manual review.

  • Critical findings reach the security channel the same morning they're scanned
  • Every scan report is archived automatically for later reference
  • Nothing critical waits for the next manual review cycle

Built for application security teams · security engineers · DevSecOps · platform teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens checkmarx.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Checkmarx - find newly introduced critical findings
    • Open Checkmarx and check the latest scan results for every monitored project
    • Capture the finding type, severity, and affected file for anything newly introduced
    • Separate out anything rated critical or high

    Done when Every newly introduced critical or high finding is listed with its project and file.

  3. 2
    Google Drive - save the full scan report
    drive.google.com
    WebRun in Google Drive: save the full scan report
    WebRun opens Google Drive to save the full scan report.
    • Save the full scan report to the security team's Drive folder
    • Name the file with the project and scan date
    • Keep a running folder so scan history is easy to review

    Done when Every newly scanned project has its report saved to Drive.

  4. 3
    Slack - alert the security channel
    slack.com
    WebRun in Slack: alert the security channel
    WebRun opens Slack to alert the security channel.
    • Post an alert to the security channel naming the project, finding, and severity
    • Group critical findings first
    • Link the saved report in Drive

    Done when The security channel has an alert for every newly introduced critical or high finding.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
checkmarx.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Critical finding alert · Slack
OutputWhat each run produces - A saved scan report and a Slack alert for every newly introduced critical or high severity Checkmarx finding.
Alert
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it fix the vulnerable code?

No. WebRun only reports what Checkmarx finds. Fixing the vulnerable code is always done by an engineer.

Does it run the scan itself?

No. It reads the scan results Checkmarx already produces. WebRun does not trigger its own scans.

What's saved in the Drive report?

The full scan report for the project, kept for the security team's records even after the Slack alert scrolls by.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.