Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root


1 badge earned


Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!


Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.


Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!


Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups

What’s the scope of permissions which Jira has access to in GitHub?

The permission scope suggests that code and metadata is read to synchronise development information to Jira. However when we've tested this out we're only seeing metadata being read from GitHub.

If the app was compromised, could it in theory exfiltrate all of our code from GitHub to a malicious actor or is it just metadata that is read from GitHub?

What we saw was that the information shared between Github and Jira is effectively links to commits. So in Jira you can see an individual commit, the commit comment, an indication of the scale of the change (lines added and deleted) and the names of the individual files that are changed. No code is shared or displayed in Jira.

0 answers

Suggest an answer

Log in or Sign up to answer

Atlassian Community Events