Security for Bitbucket
Run security audits for committed API keys, passwords, and more. Protect your dev workflow against accidental credential leaks.
-
Overview
-
Scanning Every Push with the Soteri - Scan Commits Security Hook
-
The Global Dashboard: Viewing Bitbucket's Overall Security Status
-
Project-level Dashboard
-
Repository-level Dashboard
-
Branch Scan Report
-
Exporting a Security Scan Report for External Use
-
Hiding false positives, revoked credentials, etc.
-
Allow-listing Detected Secrets
-
Enabling and Disabling Global Detection Rules
-
Defining Global Custom Detection Rules
-
Granting App Access to Additional Users and Groups
-
Customizing the hook messages
-
Defining Repository-Level Detection Rules
- How to bypass the pre-receive hook for a single commit?
- How to trigger a full Bitbucket rescan?
- Enabling debug logging
- How to get notified when a large scan completes?
- What do I do if a security scan finds a secret?
- Scan Performance Tuning
- Mitigating Trojan Source attacks
- Viewing Audited Events
- Known Incompatibilities
-
REST API for Scripting and Automation
-
REST API for Mass Scanning
-
Built-In Scanning Rules
-
Example Scan Findings Detected
Security for Bitbucket