At Atlassian, one of our goals is to make sure customers can trust our software is safe and secure. That is why every Data Center product at Atlassian is subject to a third-party dependencies security scan for known vulnerabilities. It’s critical to address vulnerabilities as soon as possible to ensure our customers can continuously trust the Atlassian Ecosystem. This way we’ll be able to detect potential issues early enough to reduce any risks for our customers.
Over the course of years we’ve seen the evolution of mechanisms used in Atlassian Data Center Engineering to discover security vulnerabilities. There are security scanners, Bug Bounty Program, and more. Customers rely on Atlassian software and trust us with their data every day.
Atlassian Data Center products are part of a thriving Ecosystem and the vast majority of deployments host multiple Data Center apps. The security of such a complex setup depends on the security of each of its components.
We want to share our experience in this area and help partners align with Atlassian Security Standards.
What is changing?
We’re proceeding with the extension of the Data Center app approval process and introducing a third-party security scanner for all Data Center apps.
Since November 2022 all apps submitted for Data Center app approval have to be free from critical- and high-severity security vulnerabilities in third-party dependencies. Learn more about the technical aspects of the security scan process.
Starting from July 2023, we’ll start tracking Data Center app vulnerabilities in the Atlassian Marketplace Security Jira project. Atlassian Marketplace Security (AMS) is our one-stop-shop for vulnerability management, where partners can go to review all their vulnerabilities, statuses, due dates, sources, and severities. All issues in AMS describe the vulnerability in detail, and all questions about an issue can be addressed in the comments of the issue. Learn more about AMS.
What do I need to do?
Please review our Security Bug Fix Policy for Marketplace apps that outlines Atlassian’s security expectations of developers who host apps on the Atlassian Marketplace, specifically regarding security vulnerabilities.
We’ll also reach out to partners who own apps with the highest number of detected vulnerabilities. We want to ensure that we create enough room for you to discuss and act on the security scanner results.
Last but not least, please ensure that the security contact in your partner profile is up to date and that you follow Vulnerability review practices for Atlassian marketplace partners. It’s important to complete those steps before the rollout of the security scanner integration with the Atlassian Marketplace Security Jira project.
Thank you for taking this seriously. Please review the technical aspect of dependency scanning and consider including it into the CI/CD pipeline of your Data Center app.
Please note that our team will also communicate this information via ECOHELP tickets. If you have any questions or concerns, please don’t hesitate to reach out to us through the ECOHELP tickets.