Hi, does anyone know if Trello (Cloud SaaS) uses any of the React componants?
support are useless. All I get back is that I chose the wrong catagory and that they can't forward my request onto the right one.
thanks,
Michael.
Hi @Michael C
Official form Atlassian no, but there are options provided via users in the development community.
See this post; https://community.developer.atlassian.com/t/react-trello-client-is-released/31773
Thank you for the answer. Not sure how to get anything official. I'm conducting an audit of all our Saas providers and so far Atlassian have been the worst for support.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Howdy @Michael C
It's nice to want to know such information about what Trello is built with 'behind the scenes', but can I offer a perspective from Atlassian's point of view?
Atlassian are under no obligation to disclose you or anyone else what Trello is built with or how it works, that's private, commercially sensitive information. All they are legally required to do is disclose information regarding their policies and processes, and their compliance with various security and privacy standards.
With regard your 'audit', if it did eventuate that Trello used React for the UI, why would your organisation care? Personally, I wouldn't be at all surprised if they did use React for the UI... but so what? Does the use of React present some sort of ethical conflict or security compromise that your organisation is not willing to accept and you'll have to stop using Trello because of that?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Not strictly true. As they holding my data. From the latter half of your comment, I would suggest you research into what the React library is, what CVE-2025-55182 (React2Shell) is and why a business would audit their suppliers as per ISO27001 to ensure that they upholding their commitment to providing a safe and secure environment that protects their clients data.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Ah, so you don't actually want to know if Trello uses React, what you actually want to know is if Atlassian have taken action to ensure their systems are not affected by a particular security vulnerability.
Well, since they haven't specifically mentioned that security vulnerability in their December Security Advisory Bulletin, and they haven't listed that security vulnerability and the action they took via their Vulnerability Disclosure Portal, then, in my humble opinion, that leaves two possibilities:
1) Even though Atlassian have a huge number of staff working to constantly monitor security advisories then take action to update and keep their systems secure and in compliance with the vast number of internationally recognised security compliance standards they adhere to, this one security vulnerability has somehow escaped their attention, or
2) They are well aware of that security vulnerability and, if they were affected, have already taken action to mitigate it and will let everyone know about that in a coming security bulletin, the same as they've done for more than a decade, rather than respond to individual audit requests or attestations on specific vulnerabilities.
Well, I sure hope you get to the bottom of this conundrum.
Good luck!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.