devops:securityInfoProvider module is now generally available
- Announced
- APIs
- adopting-forge-from-connect, forge-core-platform
- Severity
- info, set by
reef/atlassian-rule-v1 - Source
- https://developer.atlassian.com/changelog/#CHANGE-3371
The devops:securityInfoProvider module has moved from preview to general availability. Your Forge app can now send security information (such as vulnerabilities and security containers) to Jira and surface it in the development panel of Jira Software issues.
Known limitation: Currently, Forge apps using the devops:securityInfoProvider module require a Connect key. This means apps using this module cannot be listed as new apps on the Atlassian Marketplace - only existing Connect-based security provider apps migrating to Forge are unaffected by this restriction.
We're actively tracking this limitation in https://jira.atlassian.com/browse/ECO-1602 and will update this page when it's resolved.
Get started
See the https://developer.atlassian.com/platform/forge/manifest-reference/modules/jira-software-security-info/ for the full manifest schema and property details.
For a step-by-step guide, check out the https://developer.atlassian.com/platform/forge/security/.
The text above is Atlassian's. reef added the severity, the dates it could read from the text, and the endpoints and scopes named in code.