Automated Veracode Weekly Vulnerability Scorecard
Every Monday, WebRun opens Veracode, reviews open findings across your scanned applications, exports them to a Google Sheet grouped by severity and age, and emails the security lead a scorecard so nothing critical sits unreviewed for another week.
How do I get a weekly summary of open Veracode findings?
WebRun reviews open Veracode findings every Monday across your scanned applications, exports them to a Google Sheet grouped by severity and how long each has been open, and emails the security lead a scorecard highlighting anything high severity open more than two weeks, so nothing critical sits unreviewed between scans.
- Open findings get a weekly review instead of sitting unseen between scans
- High severity items open more than two weeks are called out automatically
- The security lead gets a scorecard without pulling the report by hand
Built for Application security teams · security leads · engineering managers · compliance teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
web.analysiscenter.veracode.com/loginin a real browser with your saved login - no setup, no API keys. -
1
Veracode - review open findings
- Open Veracode and review open findings across scanned applications
- Group findings by severity: very high, high, medium, and low
- Note how many days each very high and high finding has been open
Done when Every open finding is grouped by severity with its age in days.
-
2
Google Sheets - export findings by severity
WebRun opens Google Sheets to export findings by severity. - Open the Veracode Findings Tracker sheet
- Add or update a row per finding with its application, severity, and days open
- Highlight any very high or high severity finding open more than 14 days
Done when The sheet reflects this week's full findings list with age highlighted.
-
3
Gmail - email the security scorecard
WebRun opens Gmail to email the security scorecard. - Draft and send a weekly scorecard email to the security lead
- Summarize the count of findings by severity and call out anything open more than 14 days
- Link to the full Google Sheet
Done when The security lead has this week's scorecard in their inbox.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will WebRun fix or dismiss any findings?
No. It only reads and reports on open findings. Triaging, fixing, or marking a finding as mitigated stays a decision for your security and engineering teams.
How does it flag urgency?
It groups findings by Veracode's own severity rating and separately highlights any very high or high severity item that has been open more than 14 days.
Does the email go outside the company?
No. The scorecard email goes only to your internal security lead, never to a customer or outside party.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.