All templates

Automated JFrog Artifact Security Scorecard

Every Monday, WebRun opens JFrog, compiles the current Xray vulnerability count by severity for every monitored repository, logs the numbers as a new row in Airtable so the trend builds over time, and updates a Notion security dashboard page so anyone can see which repository is carrying the most risk at a glance.

Runs on WebRun · Strict Lockdown policy
Every Monday at 8:00 AM WebRunorchestrates each step
1 JFrog compile the week's Xray vulnerability counts
2 Airtable log the numbers to a tracker
3 Notion update the security dashboard
In short

How do I track artifact security risk across my JFrog repositories?

WebRun compiles JFrog Xray's vulnerability counts by severity for every monitored repository every Monday, logging the numbers to an Airtable tracker so the trend builds over time. It updates a Notion security dashboard page, so the repository carrying the most risk is visible at a glance instead of buried in individual scan reports.

  • The riskiest repository is visible at a glance every Monday
  • Vulnerability trends are tracked automatically week over week
  • Security dashboards stay current without a manual pull from Xray

Built for DevSecOps · platform engineers · security teams · release engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens jfrog.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    JFrog - compile the week's Xray vulnerability counts
    jfrog.com
    WebRun in JFrog: compile the week's Xray vulnerability counts
    WebRun opens JFrog to compile the week's Xray vulnerability counts.
    • Open JFrog and check Xray's current vulnerability count by severity for every monitored repository
    • Record the count of critical and high severity findings specifically
    • Compare this week's counts against last week's

    Done when Every monitored repository has this week's vulnerability counts by severity.

  3. 2
    Airtable - log the numbers to a tracker
    airtable.com
    WebRun in Airtable: log the numbers to a tracker
    WebRun opens Airtable to log the numbers to a tracker.
    • Log this week's vulnerability counts as a new row per repository
    • Flag any repository whose critical or high count increased
    • Keep prior weeks in place so the trend is visible

    Done when This week's numbers are logged as a new row for every repository.

  4. 3
    Notion - update the security dashboard
    notion.so
    WebRun in Notion: update the security dashboard
    WebRun opens Notion to update the security dashboard.
    • Update the security dashboard page with the current vulnerability counts per repository
    • Highlight repositories flagged for an increase
    • Keep the page as the current at a glance summary

    Done when The Notion page reflects this week's vulnerability counts for every repository.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
jfrog.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Artifact security scorecard · Notion
OutputWhat each run produces - A weekly artifact vulnerability scorecard by repository and severity, logged to Airtable and shown in Notion.
Scorecard
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it remove or replace a vulnerable artifact?

No. WebRun only reads the vulnerability counts Xray already calculates. Removing or replacing an artifact is always done by your engineers.

Does it scan the artifacts itself?

No. It reads the scan results JFrog Xray already produces. WebRun does not run its own scans.

Can I see which repository is trending worse over time?

Yes. Every week's counts are added as a new row in the same Airtable tracker, so a repository trending worse stands out over a few weeks.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.