View Your Qualys Report

The plugin generates a report for the container image in the build.

To view the report, perform the following steps:

  1. In a build, click the job, which includes the Qualys plugin.
  2. Navigate to 'Qualys Image Scan Result', to see vulnerability details for the container image.

    The reports show vulnerability data in multiple tabs.

    • The build summary shows the criteria against which vulnerabilities are evaluated. These criteria are the configured failure conditions. A criterion is violated when vulnerabilities found in the scan match one or more values set in the failure conditions for that criteria.

      Sample Build Summary view

      azuredevops_report

    • Image Statistics provides a dashboard view of your security posture.

      Sample Image Statistics view

      azuredevops_report1

    • Vulnerabilities show a list of detected QIDs.
    • Installed Software shows software detected on the container image.
    • Layers show a list of layers the image is made of.