Jira

Connect Jira Cloud to create one issue per finding and keep its state in sync with LaunchSafe both ways.

Edit on GitHub

Connect

Owners and admins connect Jira Cloud under Integrations, through Atlassian's own sign-in. LaunchSafe asks for read:jira-work, write:jira-work and offline_access. If your Atlassian account reaches several Jira sites, you choose the site. Then choose the Jira project. Issues are created as Bug when the project has that type, and otherwise as Task.

Issues from findings

On a finding, choose Create Jira issue. A finding gets at most one issue per Jira connection. The issue carries the title, severity, proof, location, what could happen, how to fix it and a link back. Evidence is never sent to Jira. For a finding in a restricted project, LaunchSafe asks first, because everyone who can see that Jira project will see the issue.

Kept in sync

  • LaunchSafe to Jira. A finding fixed or verified moves the issue to done with a comment. A finding found again moves it back. An accepted risk or false positive adds a comment.
  • Jira to LaunchSafe. LaunchSafe reads linked issues about every five minutes. Moving an issue to done queues a retest. It does not close the finding. Only a retest that finds it fixed does.

Not available

Priority and field mapping, default labels or assignees, bulk creation and attachments are not available.

Disconnect

Disconnecting deletes LaunchSafe's grant. Atlassian has no way to revoke it from our side, so also remove the app in your Atlassian account settings. Existing issues stay, marked as no longer synced.

On this page