I have been asked to evaluate a new plug-in for our Bitbucket Server instance, in a sensitive environment. One of the criteria for this evaluation is to review security details.
In the Marketplace, I can see that the vendor has completed a security self-assessment, but I was not able to find the results for that plug-in, only a description of the self-assessment program.
I was looking at "Code-Owners for Bitbucket Server".