Hello,
Our company is looking to integrate our GitHub repositories and are looking for an addon to accomplish this. We started with the free app but had several security concerns with the app listed below. So we are asking the community if anyone knows of an app they would recommend that addresses these concerns.
- Once enabled the default app becomes available on all projects within the company. We can limit the app by controlling what projects contain the custom field connected to the app. But ideally we would rather be able to select specific projects to have the addon.
- There is no option to disable smart commits, which means someone without access to a Jira project could potentially transition issues via commit messages in GitHub.
- : Any user can create a branch from the Jira Development panel, even if they don’t have access to the corresponding GitHub repository or don’t exist in GitHub.
- We want to link only certain repositories to specific Jira projects. The free Atlassian plugin links all repositories to all projects. Meaning anyone could get access to a repository they shouldn't be involved in.
Any recommendations/advice are appreciated.