In order to proactively identify and address unresolved security risks in DC Marketplace apps to safeguard the Atlassian ecosystem and its customers, Atlassian is continuously scanning not just the latest app versions, but also those compatible with current and previous Long Term Support (LTS) versions of Atlassian Data Center products. This initiative not only safeguards the Atlassian ecosystem and its customers but also sets a high standard for security in the software industry.
| Targeted Version | Description |
|---|---|
| Latest | Most recent Data Center version of the app available on the Atlassian Marketplace |
| Current LTS | Latest app version that is compatible with the latest available LTS version of the Atlassian Data Center product offering |
| Previous LTS | Latest app version that supports the LTS version immediately preceding the current LTS version of the Atlassian Data Center product offering |
This approach ensures that vulnerabilities in older, yet supported, app versions are detected and addressed, not just those in the latest releases.
App version scans utilize a multi-layered security approach:
Findings are filed as tickets in the Atlassian Marketplace Security (AMS) Jira project, categorized by scanner type and severity. In addition, we will differentiate findings associated with different Targeted versions via the App Product Compatibility field. There are three possible values for the field:
latestAppVersion - Finding is associated with the latest semantic version of the app available on the Atlassian MarketplacecurrentLTS - Finding is associated with the latest app version that supports the current LTS version of the associated Atlassian Data Center product offeringpreviousLTS - Finding is associated with the latest app version that supports the previous LTS version of the associated Atlassian Data Center product offering| Targeted Version | Value in App Product Compatibility field in AMS |
|---|---|
| Latest | latestAppVersion |
| Current LTS | currentLTS |
| Previous LTS | previousLTS |
We are trying to continuously optimize our processes, if you feel that there’s a mistake in the version(s) of your app being scanned, please reach out to our support executive by transitioning the AMS finding with the associated version to Atlassian Input Requested and we will take a look
The logic to identify the Current and Previous LTS Versions is as below:
e. g. If you want these values for Jira, you can head over to the LTS releases page and check the latest available LTS version, which would be 11.3 at the time of writing as the current LTS version, and the LTS version immediately preceding 11.3, which would be 10.3 at the time of writing as the previous LTS version.
All the existing AMS findings associated with previously identified current LTS version will be marked Patched, and new tickets will be created with previousLTS value in the App Product Compatibility field. All the existing AMS findings associated with previously identified previous LTS version will automatically be marked as Patched.
Apps cannot opt out at this time.
App version scans are designed to be non-intrusive (unless otherwise mentioned). In the event the scanning somehow disrupts app functionality, please submit a request for support on our service desk.
Rate this page: