Security Advisory: Changes to how apps are installed by URL
We're changing how to install Bitbucket Cloud apps using the URL of an app descriptor from an unknown source. Going forward, to install apps from unknown sources you will need to enable development mode in your Bitbucket settings.
To install apps by URL:
Enable development mode.
Navigate to the workspace. Select your profile avatar, then the name of the workspace from the Recent workspaces list or select All workspaces to display an entire list from which to select.
Select the Settings cog on the top navigation bar.
Select Workspace settings from the Settings dropdown menu.
Select Installed apps under Apps and features on the left side menu.
Select Enable development mode.
Select Install app from URL.
Paste the URL of the app descriptor, select Install.
Who is impacted by this change?
Bitbucket Cloud app vendors who currently install the apps by URL, usually while testing an app they maintain.
Bitbucket Cloud users with custom or private apps that are not from the Bitbucket Marketplace.
Was this helpful?