qualys/Qualys GitHub actions for Web Application Scanning

The Qualys GitHub Actions for Web Application Scanning allows DevOps teams to build application vulnerability scans into their existing CI/CD processes. By integrating web application scans in this manner, application security testing is accomplished earlier in the SDLC to catch and eliminate security flaws.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Dec 5, 2025
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: qualys/github-action-qwas@ade3ed7dd931cebf9c40245f7270ca336f328d7b # v1.2.1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
QUALYS_USERNAMEQualys Usernameyes
QUALYS_PASSWORDQualys Passwordyes
API_SERVERAPI Server URLyes
SCAN_NAMEScan Nameyes
SCAN_TYPEScan Typeyes
WEBAPP_IDWebapp IDyes
AUTH_RECORDAuthentication Recordno
AUTH_RECORD_IDAuthentication Record IDno
OPTION_PROFILEOption Profileno
OPTION_PROFILE_IDOption Profile IDno
CANCEL_OPTIONCancel Optionno
CANCEL_HOURSCancel Hoursno
SEVERITY_CHECKSeverity Checkno
SEVERITY_LEVELSeverity Levelno
EXCLUDEExcludeno
FAIL_ON_SCAN_ERRORFail on Scan Errorno
WAIT_FOR_RESULTWait for Resultno
INTERVALIntervalno
TIMEOUTTimeoutno
FILE_TYPEFile format to download artifactno

no outputs