View Your Qualys Report

The plugin generates report for the container image in the build.

To view the report, perform the following steps:

  1. In a build, click the job which includes Qualys plugin
  2. Navigate to 'Qualys Image Scan Result', to see vulnerability details for the container image.

    The reports shows vulnerabilities data in multiple tabs.

    • Build Summary shows the criteria against which vulnerabilities are evaluated. These criteria are the configured failure conditions. A criteria is violated when vulnerabilities found in the scan matches one or more values set in the failure conditions for the criteria.

      Sample Build Summary view

      azuredevops_report  

    • Image Statistics provides a dashboard view of your security posture.

      Sample Image Statistics view

      azuredevops_report1

    • Vulnerabilities shows a list of detected QIDs.
    • Installed Software shows software detected on the container image.
    • Layers shows a list of layers the image is made of.