Qualys IaC Security with GitLab- Release Notes
Release 2.1.3
September 21, 2026
Added support for Identity Provider Authentication
The GitLab IaC integration now supports Identity Provider (IDP) authentication. You can now set AUTH_TYPE to IDP when you configure the pipeline environment variables.
When you use IDP as the authentication type, the following variables are used:
|
Variable |
Mandatory/Optional |
|---|---|
|
TOKEN_URL |
Mandatory |
|
QULAYS_CLIENTID |
Mandatory |
|
QULAYS_CLIENTSECRET |
Mandatory |
|
AUDIENCE |
Optional |
|
SCOPE |
Optional |
The pipeline log provides clear visibility into the authentication process, including detailed messages from your Identity Provider or QAS - covering scope, audience, and configuration details - so you can quickly verify your setup and resolve any issues.
Before you use IDP authentication, your Support team must configure your QAS environment for your Identity Provider. Authentication requests fail until this setup is complete.
For more details, see Configure Environment Variables.
Release 2.1.2
April 28th, 2026
OpenID Connect Authentication Support
This release introduces OpenID Connect (OAuth) support, providing enhanced authentication and improved security integration. API authentication is supported using Qualys-managed tokens via a user-level client.
To create a user-level client, see Set up Token-based Authentication from UI.
For more details about configuration, see Configure Environment Variables.