All templates

Automated Mend Critical Vulnerability Text Alerts

Every morning, WebRun opens Mend, reviews new findings from the latest dependency scans, texts the security lead the moment a new critical severity vulnerability shows up, and saves the full finding, including the affected package and fixed version, to Google Drive for the remediation record.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Mend check for new findings
2 Twilio text the security lead
3 Google Drive archive the finding detail
In short

How do I get alerted immediately to a new critical Mend finding?

WebRun checks Mend every morning for new critical severity findings from your dependency scans, texting the security lead the affected package and whether a fixed version exists the moment one is found. It also saves the full finding detail to Google Drive, so a critical vulnerability gets immediate attention and a complete record for remediation.

  • A new critical finding reaches the security lead within minutes of the scan
  • Every finding has a saved record with the fixed version noted
  • Lower severity findings stay recorded without adding alert noise

Built for Application security teams · security leads · engineering managers · compliance-focused teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens saas.mend.io/login in a real browser with your saved login - no setup, no API keys.

  2. 1
    Mend - check for new findings
    • Open Mend and review findings from the latest dependency scans
    • Filter for new findings rated critical severity
    • Note the affected package, the vulnerable version, and the fixed version if available

    Done when Every new critical severity finding is identified with its package and fixed version.

  3. 2
    Twilio - text the security lead
    twilio.com
    WebRun in Twilio: text the security lead
    WebRun opens Twilio to text the security lead.
    • Send a text to the security lead for each new critical finding
    • Include the affected package, the project, and whether a fixed version exists
    • Keep the message to a single line

    Done when The security lead has been texted about every new critical severity finding.

  4. 3
    Google Drive - archive the finding detail
    drive.google.com
    WebRun in Google Drive: archive the finding detail
    WebRun opens Google Drive to archive the finding detail.
    • Open the Mend Findings Records folder in Google Drive
    • Save the full finding detail including the vulnerable and fixed version
    • Name the file with the package name and the date found

    Done when A saved record exists in Google Drive for every new critical finding.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
saas.mend.io/login
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Critical vulnerability alert · Twilio SMS
OutputWhat each run produces - A text to the security lead for each new critical severity finding and a saved detail record in Google Drive.
Alert
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will WebRun upgrade the vulnerable dependency itself?

No. It only detects and reports the finding. Upgrading the dependency, testing the change, and merging it stays with your engineering team.

Why only critical severity by text?

Critical findings need the fastest possible attention, so they get a direct text. Lower severity findings are still recorded but do not interrupt the security lead immediately.

Does the text include the exploit details?

No, just the affected package, project, and whether a fix is available. Full technical detail is saved to the Google Drive record instead of sent by text.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.