All templates

Automated Semgrep Critical Finding Escalation

Every morning, WebRun opens Semgrep, checks scan results across every monitored project for newly introduced high or critical severity findings, posts the full list to Telegram naming the rule and affected file, and texts the security lead through Twilio when a finding is rated critical so the most dangerous issues get looked at the same day they're found.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Semgrep check for newly introduced high severity findings
2 Telegram post the findings to the team
3 Twilio text security on critical ones
In short

How do I escalate critical Semgrep findings the day they're found?

WebRun checks Semgrep every morning for newly introduced high or critical severity findings across every monitored project. It posts the full list to Telegram naming the rule and file, and texts the security lead through Twilio for anything critical, so the most dangerous issues get looked at the same day they're found.

  • Critical findings reach security the same day they're introduced
  • Every high severity finding is visible in Telegram, not just critical ones
  • Nothing dangerous waits for the next manual scan review

Built for application security teams · DevSecOps · security engineers · platform teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens semgrep.dev/login in a real browser with your saved login - no setup, no API keys.

  2. 1
    Semgrep - check for newly introduced high severity findings
    • Open Semgrep and check scan results across every monitored project for findings introduced since yesterday
    • Capture the rule, affected file, and severity for each
    • Separate out anything rated critical

    Done when Every newly introduced high or critical finding is listed with its rule and file.

  3. 2
    Telegram - post the findings to the team
    telegram.org
    WebRun in Telegram: post the findings to the team
    WebRun opens Telegram to post the findings to the team.
    • Post the full list of new findings to the security channel
    • Show the rule and affected file for each
    • Note which ones are also being texted to the security lead

    Done when The security channel has today's list of new high and critical findings.

  4. 3
    Twilio - text security on critical ones
    twilio.com
    WebRun in Twilio: text security on critical ones
    WebRun opens Twilio to text security on critical ones.
    • Text the security lead only for findings rated critical
    • Name the rule and affected file
    • Skip the text for high severity findings. Those stay in Telegram only

    Done when The security lead has a text for every critical finding.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
semgrep.dev/login
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Finding escalation · Telegram
OutputWhat each run produces - A Telegram list of new high and critical Semgrep findings, with a Twilio text to security for critical ones.
Alert
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it fix the flagged code?

No. WebRun only reports what Semgrep finds. Fixing the flagged code is always done by an engineer.

Does it run its own scan rules?

No. It reads the scan results your team's existing Semgrep rules already produce. WebRun does not add or change rules.

Why text only for critical findings?

So the security lead's phone is reserved for what needs same day attention. High severity findings still post to Telegram for full visibility.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.