Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Has anyone had any experience deploying SourceTree in a secure environment? (eg. DOD, DHA)

Jamaine
July 12, 2023

Has anyone had any experience deploying SourceTree in a secure environment? (eg. DOD, DHA).  If so, what was your experience?  Did the security patches impact the application's ability to function?

1 answer

0 votes
LynnG
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 11, 2026

I haven't personally deployed SourceTree in a DoD/DHA environment, but I did find that this exact question was asked in the Atlassian Community and, at least in the publicly visible thread, there were no answers describing real-world deployment experience. [community....assian.com]

A few observations that may help:

  • SourceTree does have a history of published security advisories and vulnerability fixes, so organizations with strict patching requirements often need to keep the client updated and validate new releases before rollout. [confluence...assian.com], [app.opencve.io]

  • Whether security hardening impacts functionality is usually less about SourceTree itself and more about the environment's controls:

    • Application whitelisting
    • Proxy/SSL inspection
    • Smart card/PKI authentication
    • Restrictions on credential stores
    • Endpoint protection products that monitor Git operations
  • In highly secured environments, many teams end up using SourceTree primarily as a GUI on top of an approved Git installation. If SourceTree encounters issues, it's useful to verify whether the equivalent Git operation works from the command line first.

If you're evaluating SourceTree for a DoD/DHA deployment, I'd be interested in:

  • Is the environment NIPR, SIPR, or another enclave?
  • Are you using Bitbucket Data Center, GitLab, GitHub Enterprise, or Azure DevOps?
  • What specific security controls (STIGs, AppLocker, HBSS/Trellix, WDAC, PKI-only auth, etc.) are mandated?

Those details would make it easier to identify common compatibility concerns.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events