Security policy: Sprint Scope Search for Jira
Provider: WorkAlong.
Reporting a vulnerability
- Use the support portal with category Security. It's our only reporting channel, and security reports go to the top of the queue. We reply by email to the address you give. (Machine-readable: /.well-known/security.txt.)
- Include the steps to reproduce, the affected function or page, and the impact.
- We acknowledge reports within 2 business days and keep you updated until the issue is resolved.
- We fix confirmed issues within the timelines that Atlassian's Marketplace security policies set for each severity.
- Please don't test against Jira sites you don't own, and don't access or change other customers' data.
- We have no paid bug bounty program at this time. We're happy to credit reporters on request.
Supported versions
Only the latest version deployed to the Atlassian Marketplace is supported. Forge upgrades customers automatically, so fixes reach every site without action from admins.
Security design
- Runs on Atlassian: all compute and storage are on Atlassian Forge. The app has no servers, no remote endpoints and no egress (the manifest declares no external permissions).
- Least privilege: read scopes plus one write scope (
write:issue.property:jira) for the app's ownwlSprintScopeindex property, which holds sprint ids only. - User-facing code runs as the user: the Sprint scope page uses
asUser(), so Jira enforces the viewer's issue and board permissions. The report also checks that the viewer can see the sprint before it returns catalog data. - Background work runs as the app (
asApp()): indexing, sprint catalog and the first sync. The UI can start the first sync only once, and only with an active license. - JQL functions return only numeric-id property queries. Jira then applies the searching user's permissions to the results.
- Input validation: sprint ids, page cursors, story-point field ids and project keys are validated in resolvers. JQL arguments are length-capped and never put into JQL text.
- Logs: numeric ids, function names, timings and HTTP status codes only. Jira response bodies and query strings aren't logged.
- Licensing: paid features check the Marketplace license. Cached JQL results are revoked when the license is inactive.