Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Bitbucket Pipelines Security

Arielle Adams January 10, 2019

Trying to determine if our team should use pipelines for manual deployment but I can't seem to find information on security measures used. What protocol is used to send scripts?

1 answer

0 votes
Philip Hodder
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 4, 2019

Hi Arielle,

The Bitbucket Pipelines team takes security extremely seriously. As we are well aware of the degree of trust our users are placing in using our infrastructure and the impact a security incident could have.

Some high level details:

  1. All of our networking uses HTTPS, including the sending of scripts.
  2. Environment Variables that are marked as secured are stored as encrypted values, and are masked from build logs.
  3. Pipelines builds run on shared infrastructure, inside Docker containers with user namespace remapping enabled.
  4. Bitbucket Pipelines (and other Atlassian products) also has a bug bounty programme for security researchers to report any vulnerabilities they find, before malicious actors can exploit them. 
  5. We also have a published list of security practices we follow at Atlassian, including the Bitbucket Cloud and Bitbucket Pipelines teams.

If you have any other questions, feel free to ask.

Thanks,

Phil

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events