Configure Plugin for Build Pipelines Projects
You can use the Qualys TotalAppSec Finding Connector extension as a pre-deployment task in your project pipeline.
After installing the Qualys TotalAppSec Finding Connector, you can see this plugin as a task in your pipeline.
Before adding the plugin, you need to create the Classic Build Pipeline. For more details, refer to How to Create Classic Build Pipeline.
How to Create a Classic Build Pipeline
To create a Classic Build Pipeline, perform the following steps:
Step 1: Enable the Classic Build Pipeline Option
By default, YAML pipelines are favored, and the Classic editor may be disabled.
To enable the classic editor:
-
Go to Organization Settings in Azure DevOps.
-
Navigate to Pipelines > Settings.
-
Ensure the Disable creation of classic build pipeline option is turned off (that means classic pipelines are not disabled)
The Use the classic editor field is displayed when creating a new pipeline.
Step 2: Create a Classic Build Pipeline
Once the feature is enabled, follow these steps:
-
In your project, go to Pipelines and select New Pipeline.
-
Choose Use the classic editor to create a pipeline without YAML.
-
Select your source (for example, Azure Repos Git), repository, and branch.
-
Choose a template or start with an Empty job.
Add Plugin
To add a plugin, perform the following steps:
- Under your agent job in the Tasks tab, click
Add, and search for Qualys TotalAppSec Finding Connector. - To add the plugin as a task in the build pipeline, click Add.
After you click Add, the task gets added below the Agent Job.
Configure Plugin
To configure the plugin, perform the following steps:
- Below the Agent Job, click the task that you want to configure.

-
Enter the Display name.
-
Select the work item type (Bug or Task).
-
Then, configure the TAS service endpoint.
To connect with TAS APIs, you need to configure the service endpoint using a Qualys account and, if necessary, a proxy on your Azure DevOps instance for the organization where the Qualys TotalAppSec Finding Connector is installed.
To create work items through the API, you will need a Personal Access Token (PAT) to securely authenticate your access to Azure DevOps.
To configure service endpoints, perform the following steps:
- Go to the TAS service/server endpoint field and click New.
-
In the New service connection window, enter the Qualys Gateway URL where your Qualys TAS account resides. For more information, refer to Qualys Platform Identification page.
-
Enter your account credentials to authenticate with the TAS API server.
The Qualys application supports the following authentication methods for connecting to your Qualys account:
- OIDC (OpenID Connect)
- Basic Authentication.
- IDP (Identity Provider) Authentication.
You can choose any of these methods based on your organization’s security policies and access setup.
Configure OIDC Authentication
Use this method if your Qualys environment is configured for OpenID Connect with Client ID and Client Secret.
API authentication is supported using Qualys-managed tokens via a user-level client. To create a user-level client, see Set up Token-based Authentication from UI.
Provide the details in the following required fields:
-
Set Authentication Type to OIDC.
-
Client ID: Enter the Client ID received from your Qualys OIDC configuration.
-
Client Secret: Enter the corresponding Client Secret.
Basic Authentication
Use this method if your Qualys setup uses a standard Username and Password.
Provide details in the following required fields:
-
Set the Authentication Type to BasicAuth.
-
Username: Enter Qualys username used for API access.
-
Password: Enter the password for the above username.
IDP Authentication
Use this method if your organization authenticates through an external Identity Provider (IDP).
Provide details in the following fields:
-
Set the Authentication Type to IDP.
-
Client ID: Enter the Client ID issued by your identity provider.
-
Client Secret: Enter the corresponding Client Secret.
-
Token URL: Enter your identity provider’s token endpoint URL.
-
Scope (optional): Enter the scope value required by your identity provider, if applicable.
-
Audience (optional): Enter the audience value required by your identity provider, if applicable.
The plugin logs the token-received and disconnection events for each run. If your identity provider returns an error response - for example, an invalid token, an issuer or audience mismatch, or an unsupported scope - the error is logged in the pipeline output, the same as with the other authentication methods.
IDP authentication is currently supported only for the Qualys US1 platform in production. Support for additional platforms is planned.
-
Provide Azure DevOps Personal Access Token (PAT) with the required permissions of Read, Write, and Manage work items.
-
Provide a Service connection name to the new connection.
-
You can use this service connection to all pipelines in the same project by selecting the Security checkbox.
-
Click Save.
Once added, the TAS service endpoint is listed in the TAS service/server endpoint' drop-down field.
If your Azure DevOps instance does not have direct Internet access and requires a proxy, click Use Proxy Settings check box, and enter the proxy server information.
- Go to the TAS service/server endpoint field and click New.
-
Configure the required filters:
-
If you want to create work items only for specific application findings, you can configure the Application IDs as a comma-separated list. If no Application ID is configured, work items will be created for all application findings.
Azure DevOps does not allow duplicate work items for the same finding within the same organization.
-
If you want to create work items for specific severity levels, you can select the desired levels. If you do not select a severity level, work items are created for all detected severity levels.
-
If you want to create work items for specific vulnerability categories, you can select the desired categories. If you do not select any category, work items are created for all detected vulnerabilities.
-
If you want to create work items for a specific source, you select a finding type. If you select Qualys, you create work items only for Qualys findings. If you select 'Other', you can include findings from other sources, such as Burp or Bugcrowd. If you do not select a finding type, the system creates work items for all finding types.
-
If you select the Create/Sync tickets for ignored Detections checkbox, then work items are created for all findings. If you do not select it, work items are created only for findings that are not marked as ignored.
-
-
Configure Default Values for Custom and System Fields.
If you have any required fields in your Azure DevOps instance, you can add them using JSON. Field mapping requires the Azure DevOps field reference name as the JSON key and the desired value as the input.Example JSON configuration
{ "Custom.BugFoundIn": "Sprint1", "custom.Efforts": 3, "Microsoft.VSTS.TCM.ReproSteps": "NA" }- You can configure a custom field using its reference names, as shown in the example below:
{"Custom.BugFoundIn":"Sprint1"} - To configure system fields, you must use the correct field reference name. You can retrieve the reference names for system fields by running the following API call:
API Call
GET https://dev.azure.com/{Organization}/{Project}/_apis/wit/workitemtypes/Bug/fields?api-version=7.1Ex. "Microsoft.VSTS.TCM.ReproSteps":"NA"You must configure required field values for both ticket creation and ticket update operations.
- You can configure a custom field using its reference names, as shown in the example below:
-
Add Field Configuration for Ticket Updation for Fixed State Findings. You can update work items with the required fields for Fixed State Findings using JSON input.
This step applies only if the required fields are defined in the process rules during ticket transition.
For example, if you set a rule as follows.
- When a work item state is not To Do: Assigned To is a required field.
- When a work item state changes to Closed: Resolved Reason is a required field.
In such cases, you must configure the required fields for ticket updates in the Field Configuration for Ticket Updation section.
Example JSON Configuration for Ticket Update
{ "Microsoft.VSTS.Common.ResolvedReason": "Fixed", "System.AssignedTo": "[email protected]" } -
Click Save and queue.