Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Security guidelines for Jira Add-Ons Marketplace

Meytal BM
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 17, 2021

Recently our Security team have found multiple vulnerabilities in some Add-Ons I was interested in for both Jira Software and Jira Service Management. Minimal things like Pen Tests were not even available.

This is becoming an issue, as I am looking for various add-ons and they keep failing Security. So that got me wondering, how come Atlassian approves them into their Marketplace and yet these add-ons have major security vulnerabilities.

What does Atlassian check for in regards to Security before approving ANY add-on to it's Marketplace?

I hope someone from Atlassian can answer that so i can put some Security compliance process behind that in our org.
Thanks!

2 answers

0 votes
marc -Collabello--Phase Locked-
Community Champion
November 17, 2021

Hi @Meytal BM ,

Indeed, app security is an issue.  Apps on the marketplace are not thoroughly tested by Atlassian.

However some apps have a security badge: https://developer.atlassian.com/platform/marketplace/marketplace-security-bug-bounty-program/ .  In order to get the badge you need to participate in a paid bug bounty program.

These apps are tested by pen testers.  If you are security minded, just choose from those apps.

0 votes
Brant Schroeder
Community Champion
November 17, 2021

@Meytal BM I believe this is  what you are looking for https://www.atlassian.com/trust/marketplace

Suggest an answer

Log in or Sign up to answer