Security Scanning Practices

Our dependency, application, and Atlassian ecosystem scanning practices.

Security Scanning with Snyk

We use Snyk to scan the following:

  • Our deployment Docker images
  • Application frontend dependencies
  • Backend dependencies used for the Server & DC edition of our products

Snyk.io

Atlassian Data Center Approval

Atlassian requires us to scan all of our backend dependencies using their own scanner to renew the certification of our apps for Atlassian Data Center every year. You can read more about it in Atlassian's Data Center SAST scanner documentation.

Ecoscanner by Atlassian

The Ecoscanner platform is a platform used for performing security checks against all Marketplace cloud apps on an ongoing basis. This will help Atlassian continuously monitor Marketplace cloud apps for common security vulnerabilities and improve the overall security posture of our ecosystem.

Atlassian Ecoscanner