Qualys CI/CD Security Integration

Welcome to the Qualys CI/CD Security Integration documentation. This guide provides comprehensive information on integrating Qualys container and code security scanning into your CI/CD pipelines.

Shift security left by scanning container images and source code for vulnerabilities during your build process. Identify issues before they reach production with policy-based gating and automated issue tracking.

Supported Platforms

GitHub Actions

Two reusable actions for container and code scanning with SARIF upload and GitHub Issues integration.

View Documentation → | Source

GitLab CI

Native CI component with GitLab Security Dashboard integration for container scanning.

View Documentation → | Source

Jenkins

Full-featured plugin with dual scanner backends (QScanner and CICD Sensor) and Jira integration.

View Documentation → | Source

Azure DevOps

Pipeline extension with container and code scanning tasks, SARIF publishing, and work item creation.

View Documentation → | Source

Key Features

Get Started