The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Rovodev Malware alert

James Bylett
Contributor
August 15, 2025

One of our Devs is trying to test out Rovodev, but is running into the issue Microsoft Defender is claiming that atlassian_cli_rovodev.exe is a Bearfoos Malware. Has anyone else encountered this issue? Is this verified as a false positive or is there something underlying that needs to be changed to prevent this issue?

2 answers

1 accepted

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Answer accepted
Hans Polder
Community Champion
August 15, 2025

Hi James,

I have not worked with Rovodev myself.

If you get stuck, please report here - I have triggered a button to make sure that someone from Atlassian Support joins in here to check if they can help you. 

James Bylett
Contributor
August 15, 2025

Thanks for the link, I've submitted this as a bug report through there

Stephen Sifers
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 15, 2025

Hello @James Bylett 

Thanks for coming to our Community and reporting the unfortunate conflict with Microsoft Defender. Our bug reporting process is documented within Troubleshoot problems with Rovo Dev CLI.

While I don't believe this to be a bug, it is more of a false positive with Microsoft Defender. If you've submitted a bug through the above documentation, our teams will be able to coordinate a resolution.

-Stephen Sifers

James Bylett
Contributor
August 15, 2025

Thanks for the response, I did assume it to be a false positive, but nonetheless it is not a trivial matter for us to ignore such a report, and I doubt we are the only ones who will experience the same issue given how commonly used Microsoft Defender is. It would be helpful to understand why the executable is triggering this alert and preferable if something can be updated to prevent it triggering whatever it is that is causing Defender to report it as such

Like # people like this
0 votes
Dr Valeri Colon _Connect Centric_
Community Champion
November 13, 2025

@James Bylett This is a known false positive. Microsoft Defender occasionally flags the atlassian_cli_rovodev.exe binary because of the way it bundles its runtime, not because of actual malware. Atlassian has verified the file is safe. Updating Defender’s definitions or adding the binary to your allow-list resolves it. Atlassian is working with Microsoft to eliminate the false alert.

TAGS
AUG Leaders

Atlassian Community Events