The Appknox Security Scan Plugin allows you to perform Appknox security scan on your mobile application binary. The APK/IPA built from your CI pipeline will be uploaded to Appknox platform which performs static scan and the build will be errored according to the chosen risk threshold, minimum health score, or KnoxIQ exploit likelihood.
Sign up on Appknox.
Generate a personal access token from Developer Settings
Select credentials options from Manage Jenkins -> Credentials:
Store Appknox Access Token as Global Credential:
Select Kind as "Secret Text" and store the Appknox Access Token with desired "ID" and "Description":
Add job name and select Freestyle project:
Add Appknox Plugin from build step:
Select Access Token from the dropdown:
Ensure the Access Token matches with the Access Token given while configuring Appknox Access Token in the credentials.
Add other details in the Appknox Plugin Configuration:
Add Pipeline name and select Pipeline project:
Add Appknox Plugin Stage:
Ensure the Appknox Access Token ID matches with the ID given while configuring Appknox Access Token in the credentials.
stages {
stage('Appknox Scan') {
steps {
script {
appKnoxScanner(
credentialsId: 'your-appknox-access-token-ID', // Specify the Appknox Access Token ID that was set when storing the token in Jenkins credentials.
filePath: FILE_PATH,
thresholdType: 'RISK', // 'RISK', 'HEALTH_SCORE', or 'EXPLOIT_LIKELIHOOD' -- pick exactly one, with the matching threshold field below
riskThreshold: params.RISK_THRESHOLD, // required when thresholdType is 'RISK'
// healthScoreThreshold: params.HEALTH_SCORE_THRESHOLD, // required when thresholdType is 'HEALTH_SCORE' instead
// exploitLikelihoodThreshold: params.EXPLOIT_LIKELIHOOD_THRESHOLD, // required when thresholdType is 'EXPLOIT_LIKELIHOOD' instead -- automatically requests KnoxIQ triage regardless of triggerKnoxiq below
region: params.REGION,
generatePdfReport: params.GENERATE_PDF, // set to true to download a password-protected PDF report
triggerKnoxiq: params.TRIGGER_KNOXIQ // set to true to request KnoxIQ triage during upload
)
}
}
}
}
| Key | Value |
|---|---|
credentialsId |
Personal appknox access token ID |
filePath |
Specify the build file name or path for the mobile application binary to upload, E.g. app-debug.apk, app/build/apk/app-debug.apk |
thresholdType |
Which threshold to enforce — pick exactly one. Accepted values: RISK, HEALTH_SCORE, EXPLOIT_LIKELIHOOD |
riskThreshold |
Risk threshold value for which the CI should fail. Required when thresholdType is RISK. Accepted values: CRITICAL, HIGH, MEDIUM & LOW Default: LOW |
healthScoreThreshold |
Minimum health score (0-100) the scanned app must meet for the CI to pass. Required when thresholdType is HEALTH_SCORE. |
exploitLikelihoodThreshold |
Minimum KnoxIQ exploit-likelihood level for which the CI should fail, based on real-world exploitability rather than raw CVSS severity. Required when thresholdType is EXPLOIT_LIKELIHOOD. Automatically requests KnoxIQ triage during upload regardless of triggerKnoxiq — this gate only works against triaged results. Accepted values: LOW, MEDIUM, HIGH |
region |
Specify the Appknox region. Accepted values: global, uae, saudi Default: global |
generatePdfReport |
(Optional) Download a PDF VAPT report after the scan. The report is password-protected. Accepted values: true, false Default: false |
triggerKnoxiq |
(Optional) Request KnoxIQ triage for this build during upload; results are reflected by the CI check. Forced on automatically when thresholdType is EXPLOIT_LIKELIHOOD. Accepted values: true, false Default: false |
pipeline {
agent any
parameters {
choice(name: 'RISK_THRESHOLD', choices: ['LOW', 'MEDIUM', 'HIGH', 'CRITICAL'], description: 'Risk Threshold')
choice(name: 'REGION', choices: ['global', 'uae', 'saudi'], description: 'Appknox Region')
booleanParam(name: 'GENERATE_PDF', defaultValue: false, description: 'Download PDF report')
booleanParam(name: 'TRIGGER_KNOXIQ', defaultValue: false, description: 'Request KnoxIQ triage during upload')
}
stages {
stage('Checkout') {
steps {
git 'https://github.com/yourgithub/reponame'
}
}
stage('Build App') {
steps {
// Build the app using your build tool. Example uses Gradle.
script {
sh './gradlew build'
FILE_PATH = "app/build/outputs/apk/debug/app-debug.apk"
}
}
}
stage('Appknox Scan') {
steps {
script {
appKnoxScanner(
credentialsId: 'your-appknox-access-token-ID', // Specify the Appknox Access Token ID that was set when storing the token in Jenkins credentials.
filePath: FILE_PATH,
thresholdType: 'RISK',
riskThreshold: params.RISK_THRESHOLD,
region: params.REGION,
generatePdfReport: params.GENERATE_PDF, // set to true to download a password-protected PDF report
triggerKnoxiq: params.TRIGGER_KNOXIQ // set to true to request KnoxIQ triage during upload
)
}
}
}
}
}
pipeline {
agent any
parameters {
string(name: 'HEALTH_SCORE_THRESHOLD', defaultValue: '70', description: 'Minimum Health Score (0-100)')
choice(name: 'REGION', choices: ['global', 'uae', 'saudi'], description: 'Appknox Region')
booleanParam(name: 'GENERATE_PDF', defaultValue: false, description: 'Download PDF report')
booleanParam(name: 'TRIGGER_KNOXIQ', defaultValue: false, description: 'Request KnoxIQ triage during upload')
}
stages {
stage('Checkout') {
steps {
git 'https://github.com/yourgithub/reponame'
}
}
stage('Build App') {
steps {
// Build the app using your build tool. Example uses Gradle.
script {
sh './gradlew build'
FILE_PATH = "app/build/outputs/apk/debug/app-debug.apk"
}
}
}
stage('Appknox Scan') {
steps {
script {
appKnoxScanner(
credentialsId: 'your-appknox-access-token-ID', // Specify the Appknox Access Token ID that was set when storing the token in Jenkins credentials.
filePath: FILE_PATH,
thresholdType: 'HEALTH_SCORE',
healthScoreThreshold: params.HEALTH_SCORE_THRESHOLD,
region: params.REGION,
generatePdfReport: params.GENERATE_PDF, // set to true to download a password-protected PDF report
triggerKnoxiq: params.TRIGGER_KNOXIQ // set to true to request KnoxIQ triage during upload
)
}
}
}
}
}
pipeline {
agent any
parameters {
choice(name: 'EXPLOIT_LIKELIHOOD_THRESHOLD', choices: ['LOW', 'MEDIUM', 'HIGH'], description: 'Minimum Exploit Likelihood')
choice(name: 'REGION', choices: ['global', 'uae', 'saudi'], description: 'Appknox Region')
booleanParam(name: 'GENERATE_PDF', defaultValue: false, description: 'Download PDF report')
}
stages {
stage('Checkout') {
steps {
git 'https://github.com/yourgithub/reponame'
}
}
stage('Build App') {
steps {
// Build the app using your build tool. Example uses Gradle.
script {
sh './gradlew build'
FILE_PATH = "app/build/outputs/apk/debug/app-debug.apk"
}
}
}
stage('Appknox Scan') {
steps {
script {
appKnoxScanner(
credentialsId: 'your-appknox-access-token-ID', // Specify the Appknox Access Token ID that was set when storing the token in Jenkins credentials.
filePath: FILE_PATH,
thresholdType: 'EXPLOIT_LIKELIHOOD',
exploitLikelihoodThreshold: params.EXPLOIT_LIKELIHOOD_THRESHOLD,
region: params.REGION,
generatePdfReport: params.GENERATE_PDF // set to true to download a password-protected PDF report
// triggerKnoxiq is not set here -- it's forced on automatically for this threshold type
)
}
}
}
}
}
Note: exploitLikelihoodThreshold gates on KnoxIQ's real-world exploitability assessment instead of raw CVSS risk. It requires KnoxIQ triage to complete for the uploaded file, so --knoxiq is always passed on upload when this threshold type is selected -- the triggerKnoxiq input is ignored (and disabled in the classic UI) in this mode. If KnoxIQ triage is unavailable or does not complete in time, the CLI falls back to a risk check at LOW -- any Low-or-higher finding fails the build, regardless of which Exploit Likelihood level was configured. See the console output for which gate actually ran.








