All templates

Automated Checkmarx Open Source License Review

Every Monday, WebRun opens Checkmarx, reads the open source packages found in each project with the license attached to them, compares the list to last week to find what is new, sends the restrictive ones to Telegram, and drafts a summary email for legal in Gmail.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Checkmarx read package licenses
2 Telegram flag restrictive licenses
3 Gmail draft the note for legal
In short

How do I review the open source licenses in my codebase every week?

WebRun opens Checkmarx every Monday and reads the open source packages in each project with the license attached to each one, comparing against last week to find what is new. It sends restrictive licenses to Telegram and drafts a summary for legal in Gmail, so a licensing problem is raised before a customer's review finds it.

  • New licenses are named the week they enter the codebase
  • Legal hears about a restrictive package before a customer audit
  • Packages are grouped by license so one decision covers many

Built for engineering managers · security teams · legal counsel · platform teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens checkmarx.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Checkmarx - read package licenses
    checkmarx.com
    WebRun in Checkmarx: read package licenses
    WebRun opens Checkmarx to read package licenses.
    • Open Checkmarx and list the projects you asked WebRun to review
    • Read the latest scan results for open source packages in each project
    • Record the package, version, and the license attached to it
    • Compare against last week's list to separate the newly introduced packages

    Done when Every reviewed project has a current package and license list with the new entries marked.

  3. 2
    Telegram - flag restrictive licenses
    telegram.org
    WebRun in Telegram: flag restrictive licenses
    WebRun opens Telegram to flag restrictive licenses.
    • Send the packages whose license sits on your restricted list
    • Name the project, the package, the version, and the license for each
    • Include a count of new packages added this week even when none are restrictive

    Done when The engineering channel has this week's restrictive license list.

  4. 3
    Gmail - draft the note for legal
    gmail.com
    WebRun in Gmail: draft the note for legal
    WebRun opens Gmail to draft the note for legal.
    • Draft an email to your legal contact listing the new licenses from this week
    • Group the packages by license so one decision covers several dependencies
    • Note which project and which team introduced each package
    • Leave the email in Drafts so an engineer confirms it before legal sees it

    Done when A license summary is drafted in Gmail for legal review.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
checkmarx.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
License review · Telegram
OutputWhat each run produces - A weekly list of open source packages by license, marking which are new this week and which sit on your restricted list.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it email legal without me?

No. The summary is drafted in Gmail and left unsent. An engineer reads it first, because a license question sent to legal with the wrong project attached costs everyone a week.

Does it change any scan or policy in Checkmarx?

No. WebRun reads existing scan results only. It never starts a scan, edits a policy, or marks a finding, so your Checkmarx configuration is untouched.

How does it decide a license is restrictive?

From the list you give it. Name the licenses your legal team wants to hear about, such as strong copyleft ones, and WebRun flags only those, leaving permissive licenses in the weekly count.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.