Automated Checkmarx Critical Finding Alerts
Every morning, WebRun opens Checkmarx, checks the latest scan results across every monitored project for newly introduced critical or high severity findings, saves the full scan report to a Google Drive folder for the security team's records, and posts an alert to Slack naming the project and finding so nothing critical waits until the next manual review.
How do I get alerted about critical Checkmarx findings right away?
WebRun checks Checkmarx every morning for newly introduced critical or high severity findings across every monitored project. It saves the full scan report to Google Drive for the security team's records, and posts a Slack alert naming the project and finding, so nothing critical waits until the next manual review.
- Critical findings reach the security channel the same morning they're scanned
- Every scan report is archived automatically for later reference
- Nothing critical waits for the next manual review cycle
Built for application security teams · security engineers · DevSecOps · platform teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
checkmarx.comin a real browser with your saved login - no setup, no API keys. -
1
Checkmarx - find newly introduced critical findings
- Open Checkmarx and check the latest scan results for every monitored project
- Capture the finding type, severity, and affected file for anything newly introduced
- Separate out anything rated critical or high
Done when Every newly introduced critical or high finding is listed with its project and file.
-
2
Google Drive - save the full scan report
WebRun opens Google Drive to save the full scan report. - Save the full scan report to the security team's Drive folder
- Name the file with the project and scan date
- Keep a running folder so scan history is easy to review
Done when Every newly scanned project has its report saved to Drive.
-
3
Slack - alert the security channel
WebRun opens Slack to alert the security channel. - Post an alert to the security channel naming the project, finding, and severity
- Group critical findings first
- Link the saved report in Drive
Done when The security channel has an alert for every newly introduced critical or high finding.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it fix the vulnerable code?
No. WebRun only reports what Checkmarx finds. Fixing the vulnerable code is always done by an engineer.
Does it run the scan itself?
No. It reads the scan results Checkmarx already produces. WebRun does not trigger its own scans.
What's saved in the Drive report?
The full scan report for the project, kept for the security team's records even after the Slack alert scrolls by.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.