The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How does your team vet new add-ons?

Cat Quinn
September 6, 2022

Hello! I am trying to standardize the process for vetting and reviewing new add-ons for Jira Software, JSM and Confluence so that we are only using what is necessary without having too many add-ons to manage. Do you have any advice for best practices on how to handle this? 

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Brant Schroeder
Community Champion
January 21, 2023

@Cat Quinn 

We have a test instance where we allow our users to install and validate apps.  We then have the following criteria that we rate the apps on.  We weight the different criteria to meet our instances need.  

  1. Justification for marketplace product, how they tested the app, examples of their testing - Submitted by the users after they test and validate in our test instance.
  2. Cost of the app and how will it be funded.
  3. How well the application is documented and link to documentation.
  4. Is it part of the bug bounty program.
  5. How many reviews does it have and overall review rating.
  6. How many installs does it have.
  7. How long has it been around.

I would suggest thinking about what will serve you the best.  In the past I have had units I worked with also do a security review as part of the process to ensure that the app meets certain criteria.

Hope this helps. 

TAGS
AUG Leaders

Atlassian Community Events