Qualys IaC Security with Jenkins - Release Notes
Release 2.0.3
August 2, 2026
Added support for Identity Provider (IDP) Authentication in Jenkins IAC plugin
The Jenkins IAC plugin now supports Identity Provider (IDP) authentication. You can now select IDP as the authentication type when you configure the plugin.

When you select this IDP as an authentication type, the plugin displays the following fields:
|
Field |
Mandatory/Optional |
|---|---|
|
Token URL |
Mandatory |
|
Client ID |
Mandatory |
|
Client Secret |
Mandatory |
|
Audience |
Optional |
|
Scope |
Optional |
The plugin also provides enhanced authentication logging. The console output now shows the selected authentication type and reports errors returned by your Identity Provider or QAS, making it easier to troubleshoot authentication failures.
Before you use IDP authentication, your Support team must configure your QAS environment for your Identity Provider. Authentication requests fail until this setup is complete.
For more details, see Configure Identity Provider (IDP) Authentication.
Release 2.0.2
May 26, 2026
With this release, the supported Java version is upgraded to v21.
Release 2.0.0
January 29th, 2026
OpenID Connect (OIDC) Authentication Support
This release introduces OpenID Connect (OAuth) support, providing enhanced authentication and improved security integration. API authentication is supported using Qualys-managed tokens via a user-level client.
To create a user-level client, see Set up Token-based Authentication from UI.
For more details, see Configure Environment Variables.
Multiple IaC Scan Configurations
You can now configure multiple IaC scan setups in Jenkins global settings. Each configuration can have a custom name, platform URL, and authentication details, and can be selected at the job level for greater flexibility and reuse.
Jenkins UI-Based Scan Reporting
IaC scan results are now displayed directly in the Jenkins job UI. Users can configure severity-based failure criteria (High, Medium, Low), allowing jobs to fail automatically when defined thresholds are met.