The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Has anyone had any experience deploying SourceTree in a secure environment? (eg. DOD, DHA)

Jamaine
July 12, 2023

Has anyone had any experience deploying SourceTree in a secure environment? (eg. DOD, DHA).  If so, what was your experience?  Did the security patches impact the application's ability to function?

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
LynnG
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
August 11, 2026

I haven't personally deployed SourceTree in a DoD/DHA environment, but I did find that this exact question was asked in the Atlassian Community and, at least in the publicly visible thread, there were no answers describing real-world deployment experience. [community....assian.com]

A few observations that may help:

  • SourceTree does have a history of published security advisories and vulnerability fixes, so organizations with strict patching requirements often need to keep the client updated and validate new releases before rollout. [confluence...assian.com], [app.opencve.io]

  • Whether security hardening impacts functionality is usually less about SourceTree itself and more about the environment's controls:

    • Application whitelisting
    • Proxy/SSL inspection
    • Smart card/PKI authentication
    • Restrictions on credential stores
    • Endpoint protection products that monitor Git operations
  • In highly secured environments, many teams end up using SourceTree primarily as a GUI on top of an approved Git installation. If SourceTree encounters issues, it's useful to verify whether the equivalent Git operation works from the command line first.

If you're evaluating SourceTree for a DoD/DHA deployment, I'd be interested in:

  • Is the environment NIPR, SIPR, or another enclave?
  • Are you using Bitbucket Data Center, GitLab, GitHub Enterprise, or Azure DevOps?
  • What specific security controls (STIGs, AppLocker, HBSS/Trellix, WDAC, PKI-only auth, etc.) are mandated?

Those details would make it easier to identify common compatibility concerns.

TAGS
AUG Leaders

Atlassian Community Events