Recently our Security team have found multiple vulnerabilities in some Add-Ons I was interested in for both Jira Software and Jira Service Management. Minimal things like Pen Tests were not even available.
This is becoming an issue, as I am looking for various add-ons and they keep failing Security. So that got me wondering, how come Atlassian approves them into their Marketplace and yet these add-ons have major security vulnerabilities.
What does Atlassian check for in regards to Security before approving ANY add-on to it's Marketplace?
I hope someone from Atlassian can answer that so i can put some Security compliance process behind that in our org.
Thanks!
Hi @Meytal BM ,
Indeed, app security is an issue. Apps on the marketplace are not thoroughly tested by Atlassian.
However some apps have a security badge: https://developer.atlassian.com/platform/marketplace/marketplace-security-bug-bounty-program/ . In order to get the badge you need to participate in a paid bug bounty program.
These apps are tested by pen testers. If you are security minded, just choose from those apps.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.