Features

Qualys CI/CD Security Integration provides comprehensive security scanning capabilities for your build pipelines.

Container Vulnerability Scanning

Scan Docker/OCI container images for known vulnerabilities:

Software Composition Analysis (SCA)

Scan source code repositories for vulnerable dependencies:

Secrets Detection

Identify hardcoded secrets before they reach production:

SBOM Generation

Generate Software Bill of Materials for compliance and inventory:

Policy Enforcement

Threshold-Based Gating

Configure maximum allowed vulnerabilities per severity:

Cloud Policy Evaluation

Use centralized Qualys platform policies:

Reporting and Integration

SARIF Reports

Issue/Work Item Creation

Native Security Dashboards

Platform-Specific Features

Feature GitHub GitLab Jenkins Azure DevOps
Container Scan Yes Yes Yes Yes
Code Scan (SCA) Yes Yes Yes Yes
Secrets Detection Yes Yes Yes Yes
SBOM Generation Code only No Yes Yes
Malware Detection No Yes Yes No
Rootfs Scanning No No Yes No
Offline Scanning No No Yes Yes
Issue Creation GitHub - Jira Work Items
Dual Backends No No Yes No

Next Steps