All templates

Automated Jenkins Plugin Security Audits

Every Monday, WebRun opens jenkins.io, reads the security advisories and release news published there, matches them against the plugin list and controller version your team runs, posts the risks to Slack ranked by severity, and drafts a Gmail brief for the next maintenance window.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Jenkins read advisories and release news
2 Slack post the ranked risks
3 Gmail draft the maintenance brief
In short

How do I review Jenkins plugin security warnings before a maintenance window?

Every Monday WebRun opens jenkins.io, reads the security advisories and release news published there, and matches them against the plugins and controller version your team runs. It posts the risks to Slack and drafts a Gmail brief for your maintenance window, so security warnings do not sit for months.

  • Advisories are matched to your plugin list every Monday, not once a year
  • The maintenance window opens with a ranked list and a reason for each update
  • Nothing is installed or restarted without an engineer doing it

Built for build engineers · DevOps teams · platform engineers · release managers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.jenkins.io in a real browser with your saved login - no setup, no API keys.

  2. 1
    Jenkins - read advisories and release news
    jenkins.io
    WebRun in Jenkins: read advisories and release news
    WebRun opens Jenkins to read advisories and release news.
    • Open jenkins.io and read the security advisories published since the previous run
    • Read the current release information for the controller line your team follows
    • Match each advisory against the plugin list you gave WebRun for your controller
    • Record the affected plugin, the severity stated in the advisory, and the version that resolves it

    Done when Every advisory touching a plugin you run is captured with its severity and its fixed version.

  3. 2
    Slack - post the ranked risks
    slack.com
    WebRun in Slack: post the ranked risks
    WebRun opens Slack to post the ranked risks.
    • Post the week's findings to your build channel with the highest severity first
    • Show for each plugin the version you run, the version that resolves the advisory, and what the advisory says it affects
    • Call out separately whether the controller version itself has moved
    • Stay quiet in weeks with no advisory touching your plugin list

    Done when The build channel has this week's ranked list of plugins worth updating.

  4. 3
    Gmail - draft the maintenance brief
    gmail.com
    WebRun in Gmail: draft the maintenance brief
    WebRun opens Gmail to draft the maintenance brief.
    • Compose a maintenance window brief listing each plugin to update, its target version, and the reason
    • Add the jobs your team flagged as most likely to be affected by each update
    • Leave the brief in Drafts. WebRun never emails the team and never touches your controller or its plugins

    Done when A maintenance brief is waiting in Gmail drafts for the build engineer to review and send.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.jenkins.io
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Update audit · Slack
OutputWhat each run produces - A weekly ranked list of plugins with advisories, the version that resolves each one, and a drafted brief for the next maintenance window.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it install a plugin update?

No. WebRun reads published advisories and reports them. Updating a plugin, restarting a controller, or upgrading a version stays with your build engineer, and shell commands are blocked by the policy.

Will it email the team on its own?

No. The maintenance brief is left unsent in Gmail drafts. You read it, adjust the plan, and send it when the window is agreed.

How does it know which plugins I run?

You give WebRun your plugin list and controller version once, and every run matches new advisories against it, so the Slack post only names plugins you actually have.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.