Release Notes
Version 1.2.0
September 29, 2026
Identity Provider Authentication Support
We have added support for IDP (Identity Provider) authentication in the Qualys TotalAppSec Finding Connector application. This authentication type requires a Client ID, Client Secret, and Token URL from your identity provider. Scope and Audience are optional.
For more details, see Configure Plugin for Build Pipelines Projects.
Work Item Type Support
AzureDevops TAS Finding Coonector now supports creating Bug (default) and Task work items in AzureDevOps.
For more details, see Configure Plugin for Build Pipelines Projects.
Version 1.1.0
May 16, 2026
OIDC Authentication Support
With this release, we have added support for OIDC authentication in the Qualys TotalAppSec Finding Connector application. You can authenticate using one of the following methods, based on your organization’s security policies and access configuration:
- Basic Authentication using a username and password
- OIDC Authentication using a client ID and client secret
To use OIDC authentication, you must create a user-level client. For detailed steps, refer to Set up Token-based Authentication from UI.
For more details, see Configure Plugin for Build Pipelines Projects.
Support for Required Fields for Fixed State Findings
Earlier, while updating a work item, Fixed State Findings failed when Azure DevOps had mandatory custom rules enabled. With this release, a new text box is available while updating a ticket, similar to the configuration used during ticket creation. You can update work items with the required fields for updating Fixed State Findings. This lets you pass JSON input for mandatory or custom rules defined in Azure DevOps, ensuring updates succeed even when mandatory fields are enforced.

For more details
Version 1.0.2
February 05, 2026
Support for Custom and System Fields
This release introduces support for mapping and passing additional fields to downstream Azure DevOps work items. Both custom and predefined Azure DevOps system fields can now be configured for ticket creation. A new configuration option in the plugin UI accepts field values in JSON format, enabling greater flexibility in defining work item data.

The connector processes the provided JSON input and maps key-value pairs directly to corresponding Azure DevOps fields. Field mapping requires the Azure DevOps field reference name as the JSON key and the desired value as the input.
Example JSON configuration
{
"Custom.BugFoundIn": "Sprint1",
"custom.Efforts": 3,
"Microsoft.VSTS.TCM.ReproSteps": "NA"
}
For more details, refer to Configure Plugin for Build Pipelines Projects.
Version 1.0.1
November 25, 2025
Support for Additional Pipeline Types
In the release, we have added support for 'Release pipelines' and 'YAML pipelines', in addition to existing Build pipeline support. This enables expanded compatibility across various CI/CD workflows.
For more details about Configuration, refer to Configure Plugin.
Updated Work Item Issue Type
The connector will now create remediation tickets as 'Bug' work items instead of 'Task', ensuring better alignment with vulnerability and defect tracking workflows. Severity-based prioritization remains supported, and status transitions continue to work across all Azure DevOps process models, including CMMI, Scrum, and Agile.
Version 1.0.0
August 28, 2025
We are introducing a new TotalAppSec extension that integrates Qualys TotalAppSec (TAS) with Azure DevOps. This extension automatically creates and updates work items in Azure DevOps for TAS findings, enabling security and development teams to collaborate within their existing workflows.
Each work item includes key details such as finding ID, QID, severity, category, source, vulnerability information, application context, finding score, and results. These fields provide the necessary context to prioritize, investigate, and remediate issues efficiently.
This integration reduces manual effort by automating ticket creation, ensures up-to-date visibility of vulnerabilities, and helps teams align remediation activities with sprints and releases.
The extension supports cloud-based Azure DevOps environments and provides a reliable, one-way flow of data from TotalAppSec to Azure DevOps, with TotalAppSec serving as the single source of truth for vulnerability data.