All templates

Automated Checkmarx Scan Coverage Reports

Every Monday, WebRun signs in to Checkmarx, checks when each project last completed a scan and whether recent scans failed, posts a coverage report to Microsoft Teams naming the gaps and their owners, and texts you through Twilio when a project you marked critical has no recent successful scan.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 Checkmarx check scan coverage per project
2 Microsoft Teams post the coverage report
3 Twilio text you about uncovered critical apps
In short

How do I check which projects are missing security scans each week?

WebRun signs in to Checkmarx every Monday, reads the last scan date and result for every project, and sorts them into scanned, failing and never scanned in the window. It posts the coverage report to Microsoft Teams with owners tagged, and texts security leads through Twilio when a critical project is uncovered.

  • A repo that dropped out of scanning is found within a week
  • Failing scans get an owner instead of sitting in a queue
  • Critical apps with no coverage reach a lead by text, not by email

Built for application security teams · DevSecOps engineers · engineering managers · compliance leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens checkmarx.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Checkmarx - check scan coverage per project
    checkmarx.com
    WebRun in Checkmarx: check scan coverage per project
    WebRun opens Checkmarx to check scan coverage per project.
    • Sign in to Checkmarx and list every project in scope
    • For each project read the date and result of the most recent scan
    • Separate projects into scanned successfully this week, scanned but failed or errored, and not scanned at all in the window you set

    Done when Every project has a coverage status and a last successful scan date.

  3. 2
    Microsoft Teams - post the coverage report
    microsoft.com
    WebRun in Microsoft Teams: post the coverage report
    WebRun opens Microsoft Teams to post the coverage report.
    • Post the coverage report to your security channel in Microsoft Teams
    • Lead with projects that have no successful scan in the window, then projects whose scans are failing
    • Tag the owning team on each gap and give the last successful scan date so the age of the gap is obvious

    Done when The security channel has this week's coverage report with owners tagged.

  4. 3
    Twilio - text you about uncovered critical apps
    twilio.com
    WebRun in Twilio: text you about uncovered critical apps
    WebRun opens Twilio to text you about uncovered critical apps.
    • Send a text through Twilio only when a project on your critical list has no successful scan in the window
    • Name the project, the last successful scan date and the owning team
    • Send to the security leads on your recipient list and nobody else

    Done when Security leads have been texted about any uncovered critical project.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
checkmarx.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Scan coverage report · Microsoft Teams
OutputWhat each run produces - A weekly Checkmarx coverage report listing projects with no recent successful scan, projects whose scans are failing, and the owner of each gap.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it start scans or change scan settings?

No. WebRun reads scan history and reports on it. It never triggers a scan, never edits a project configuration, and never changes a policy. Running a scan stays a deliberate action by your team.

Does the report include vulnerability details?

No. This workflow is about coverage, not findings. It reports which projects were scanned, which failed and which were skipped. It does not copy vulnerability details out of Checkmarx into a chat channel.

Who receives the text message?

Only the security leads on the recipient list you configure, and only when a project you marked critical has no recent successful scan. Quiet weeks send no text at all.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.