Release Notes

Version 1.2.0

September 29, 2026

Identity Provider Authentication Support

We have added support for IDP (Identity Provider) authentication in the Qualys TotalAppSec Finding Connector application. This authentication type requires a Client ID, Client Secret, and Token URL from your identity provider. Scope and Audience are optional.

For more details, see Configure Plugin for Build Pipelines Projects.

Work Item Type Support

AzureDevops TAS Finding Coonector now supports creating Bug (default) and Task work items in AzureDevOps.

For more details, see Configure Plugin for Build Pipelines Projects.

Version 1.1.0

May 16, 2026

OIDC Authentication Support

With this release, we have added support for OIDC authentication in the Qualys TotalAppSec Finding Connector application.  You can authenticate using one of the following methods, based on your organization’s security policies and access configuration:

  • Basic Authentication using a username and password
  • OIDC Authentication using a client ID and client secret

To use OIDC authentication, you must create a user-level client. For detailed steps, refer to Set up Token-based Authentication from UI.

For more details, see Configure Plugin for Build Pipelines Projects.

Support for Required Fields for Fixed State Findings

Earlier, while updating a work item, Fixed State Findings failed when Azure DevOps had mandatory custom rules enabled. With this release, a new text box is available while updating a ticket, similar to the configuration used during ticket creation. You can update work items with the required fields for updating Fixed State Findings. This lets you pass JSON input for mandatory or custom rules defined in Azure DevOps, ensuring updates succeed even when mandatory fields are enforced. 

Support for Required Fields for Fixed State Findings Earlier, while.

For more details

Version 1.0.2

February 05, 2026

Support for Custom and System Fields

This release introduces support for mapping and passing additional fields to downstream Azure DevOps work items. Both custom and predefined Azure DevOps system fields can now be configured for ticket creation. A new configuration option in the plugin UI accepts field values in JSON format, enabling greater flexibility in defining work item data.

The connector processes the provided JSON input and maps key-value pairs directly to corresponding Azure DevOps fields. Field mapping requires the Azure DevOps field reference name as the JSON key and the desired value as the input.

Example JSON configuration

{
  "Custom.BugFoundIn": "Sprint1",
  "custom.Efforts": 3,
  "Microsoft.VSTS.TCM.ReproSteps": "NA"
}

For more details, refer to Configure Plugin for Build Pipelines Projects.

Version 1.0.1

November 25, 2025

Support for Additional Pipeline Types

In the release, we have added support for 'Release pipelines' and 'YAML pipelines', in addition to existing Build pipeline support. This enables expanded compatibility across various CI/CD workflows.

For more details about Configuration, refer to Configure Plugin.

Updated Work Item Issue Type  

The connector will now create remediation tickets as 'Bug' work items instead of 'Task', ensuring better alignment with vulnerability and defect tracking workflows. Severity-based prioritization remains supported, and status transitions continue to work across all Azure DevOps process models, including CMMI, Scrum, and Agile.

Version 1.0.0

August 28, 2025

We are introducing a new TotalAppSec extension that integrates Qualys TotalAppSec (TAS) with Azure DevOps. This extension automatically creates and updates work items in Azure DevOps for TAS findings, enabling security and development teams to collaborate within their existing workflows.

Each work item includes key details such as finding ID, QID, severity, category, source, vulnerability information, application context, finding score, and results. These fields provide the necessary context to prioritize, investigate, and remediate issues efficiently.

This integration reduces manual effort by automating ticket creation, ensures up-to-date visibility of vulnerabilities, and helps teams align remediation activities with sprints and releases.

The extension supports cloud-based Azure DevOps environments and provides a reliable, one-way flow of data from TotalAppSec to Azure DevOps, with TotalAppSec serving as the single source of truth for vulnerability data.