Automated Snyk Scan Coverage Audits
Every Monday, WebRun opens Snyk, walks each organization and its integrations, lists every project and target with its last tested date, works out which repositories were never imported and which have gone stale, posts the coverage gaps to Microsoft Teams, and emails the security owner the same list.
How do I find repositories that Snyk is not scanning?
WebRun audits your Snyk coverage every Monday. It walks each organization, lists every project and target with its last tested date, and works out which repositories were never imported and which have gone stale. It posts the gaps to Microsoft Teams and emails the security owner the same list.
- Unscanned repositories surface every Monday, not at audit time
- Stale projects are measured against a freshness window you set
- Coverage gaps land in the security channel with clear ownership
Built for security engineers · AppSec teams · platform engineering · engineering managers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
app.snyk.io/loginin a real browser with your saved login - no setup, no API keys. -
1
Snyk - list projects and last tested dates
WebRun opens Snyk to list projects and last tested dates. - Open Snyk and step through each organization in turn
- List every project and target with its integration source and last tested date
- Compare the connected integrations against the repositories you expect to see covered
- Split the result into two groups: never imported, and not tested inside your freshness window
Done when Every organization has been walked and both coverage gap lists are built.
-
2
Microsoft Teams - post the coverage gaps
WebRun opens Microsoft Teams to post the coverage gaps. - Post the gap list to your security channel
- Put repositories with no Snyk coverage at all first
- Follow with stale projects, showing how many days since the last test
- Keep the counts by organization so ownership is obvious
Done when The security channel has this week's coverage gaps ranked by risk.
-
3
Gmail - send the owner the list
WebRun opens Gmail to send the owner the list. - Email the same list to the security owner for the record
- Lead with the number of unscanned repositories and the number gone stale
- Send only inside your team. Any note to an auditor or customer is left as a draft for a human to approve
Done when The security owner has the week's coverage list in writing.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it import repositories on its own?
No. WebRun reports the gaps and stops there. Importing a repository into Snyk, changing an integration, or altering a project stays a human decision, because it changes what your scans and licence usage cover.
Does it email anyone outside the team?
No. The list goes to your security owner internally. If an auditor or customer needs the same summary, WebRun leaves it as a Gmail draft for a human to check and send.
How does it decide a project is stale?
By the freshness window you set, for example not tested in fourteen days. WebRun reads each project's last tested date in Snyk and measures against that window every Monday.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.