Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Unsupported Atlassian apps

Mark Wheeler
Contributor
April 6, 2020

Hi there

I recently asked my company security team for permission to install "Who's Looking" and "My Reminders for Jira" which are both for Jira Cloud and both are by Atlassian Labs.

https://marketplace.atlassian.com/apps/1211596/whos-looking-for-jira-cloud

https://marketplace.atlassian.com/apps/1212778/my-reminders-for-jira?hosting=cloud&tab=overview

My request was not approved by our security team because the apps do not have formal support from the vendor.

The below forum post explains what Unsupported means but I don't understand why Atlassian Labs don't support their own apps.

https://community.atlassian.com/t5/Marketplace-Apps-Integrations/Unsupported-App/qaq-p/1268364

Are there plans to make Who's Looking and My Reminders for Jira apps supported as they look really useful.

Alternatively, can anyone help convince my security team that unsupported Atlassian Labs apps are secure and pose minimal risk to my organisation, well at least no more risk than Jira itself?

Thanks

Mark

1 answer

1 accepted

3 votes
Answer accepted
JimmyVanAU
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
April 7, 2020

Hi Mark,

I should start by saying that I don't work for Atlassian and these are my views.

It's unlikely that current Atlassian Labs apps will move to be supported. Often these products are the output of Atlassian's ShipIt days. Teams will get together to build something quickly to solve one small problem. In some cases, they're good enough to ship, as you've seen with the two apps you've listed. Supporting apps long term takes time, effort and resources, something that Atlassian have not yet deemed important for some things. As apps move to different platforms (apps will be moving to Atlassian Forge, for reasons of security, data sovereignty among others), refactoring and migrating will consume resources on their otherwise full roadmaps. For other Atlassian apps in the middle of their radar, e.g. Portfolio for Jira, the team will throw significant resources to ensure new features are being rolled out, and ensure support staff are versed on the latest developments.

Depending on what your security team are looking for, there may a number of avenues. I can think of two for now.

Does your security team have a policy on open source software? If the source code is published, is this acceptable? The security team can have a look under the hood here - https://bitbucket.org/atlassian/whoslooking-connect/src/master/ - and perform an audit themselves. I don't have a publicly accessible link for My Reminders.

For My Reminders, there is a commercial alternative which is supported - Reminders for Jira . That said it's developed by a third party, and this vendor will need to be appropriately vetted (in particular, security teams seem to raise eyebrows that the developers are Russian, and that may pose more risk).

Hope that helps!

Suggest an answer

Log in or Sign up to answer
TAGS
atlassian, team '25 europe, atlassian event, barcelona 2025, jira, confluence, atlassian intelligence, rovo, ai-powered collaboration, developer tools, agile teams, digital transformation, teamwork solutions, atlassian conference, product announcements

🌆 Team '25 Europe registration is now open!

Join the largest European gathering of the Atlassian Community and reimagine what’s possible when great teams and transformative technology come together. Plus, grab your Super Fan ticket now and save over €1,000 on your pass before prices rise on 3 June.

Register now
AUG Leaders

Atlassian Community Events