Security Advisory: Changes to how apps are installed by URL

We're changing how to install Bitbucket Cloud apps using the URL of an app descriptor from an unknown source. Going forward, to install apps from unknown sources you will need to enable development mode in your Bitbucket settings.

To install apps by URL:

  1. Enable development mode.

    1. Navigate to the workspace. Click your profile avatar > click the name of the workspace from the Recent workspaces list or click All workspaces to display an entire list from which to select.

    2. Click the Settings cog on the top navigation bar.

    3. Click Workspace settings from the Settings dropdown menu.

    4. Click Installed apps under Apps and features on the left side menu.

    5. Check Enable development mode.

  2. Click Install app from URL.

  3. Paste the URL of the app descriptor, click Install.

Who is impacted by this change?

  • Bitbucket Cloud app vendors who currently install the apps by URL, usually while testing an app they maintain.

  • Bitbucket Cloud users with custom or private apps that are not from the Bitbucket Marketplace. 

Additional Help