Why is there no feature/option to receive security related threat advisories or alerts?
Atlassian is a huge corporation... do you not want your customers to know immediately when a new security alert is issued?
Welcome to the community.
I see your point, but as Cloud is a SaaS product, you pay to have security issues mitigated by the Service Provider ASAP.
To put it bluntly, this should not be a customers concern, as this is handled by the company n the price for the Service.
Further @Gabriela - LeanZero is right on the options there are, as theses are for self-installed products only
Hi @Blaine Blodgette, it exists, it lives outside the product. Atlassian's advisory publishing policy commits to posting each advisory on the Trust Center page at the same time as the fix ships, and critical ones also go to the Alerts mailing list for that product. You opt in at my.atlassian.com/email under Tech Alerts. Your Primary Technical Contact is on that list by default, which is usually why nobody else on the team ever sees one land.
Check which deployment you're on first though. That policy is written for self-managed products, and the KB behind it carries a Data Center Only notice. On Cloud I could not find an equivalent subscription, so there the Trust Center advisories page is what you watch.
https://www.atlassian.com/trust/security/advisory-publishing-policy
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I need to walk back the second half of that. The Trust Center advisories page only carries Data Center and Server advisories, and your post is tagged cloud, so nothing for your site will ever land there. Wrong pointer from me.
There's no feature, and Atlassian says so on its own page. It asks "Is there a Security Bulletin for Cloud customers?" and answers "No, the Security Bulletin is for server and DC products only. We are able to seamlessly patch Cloud vulnerabilities without any action required on the part of the customer."
So there's nothing to subscribe to because there's nothing for you to install. What you get in its place is a committed fix window. The Security Bug Fix Policy puts cloud products under Accelerated Resolution Objectives, critical fixed in 10 days, high in 28.
The Tech Alerts list I mentioned is real, but the KB behind it is Data Center only, so it won't cover your site either.
https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html
https://www.atlassian.com/trust/security/bug-fix-policy
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.