Planning Poker for Jira
Security
Reporting a vulnerability
We take security seriously. If you believe you have found a security vulnerability in Planning Poker for Jira, please report it to us responsibly by emailing:
Security contact
Kee Ling Xuan — lingxuan.kee@yycadvisors.com
Subject line: [SECURITY] Planning Poker for Jira
Please include as much of the following as possible to help us reproduce and validate the issue:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue (proof-of-concept or exploit code if available).
- The Jira site or environment where you observed the issue.
- Any relevant screenshots, logs, or request/response captures.
Our commitment to you
- Acknowledgement: We will acknowledge receipt of your report within 3 business days.
- Assessment: We will assess the severity and validity of the report within 10 business days of acknowledgement.
- Updates: We will keep you informed of our progress and expected remediation timeline.
- Fix: We aim to release a fix for confirmed vulnerabilities within 30 days for critical issues and 90 days for other severities, depending on complexity.
- Credit: We will acknowledge your contribution in our release notes if you wish, once the issue is resolved and publicly disclosed.
Responsible disclosure guidelines
We ask that you:
- Give us a reasonable amount of time to investigate and remediate before any public disclosure.
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Do not perform denial-of-service attacks or automated scanning against production systems.
- Do not exploit the vulnerability beyond what is necessary to demonstrate the issue.
We will not take legal action against security researchers who discover and report vulnerabilities in good faith following these guidelines.
Scope
This policy covers:
- The Planning Poker for Jira Forge app distributed on the Atlassian Marketplace (app ID
682030c7-b762-4a52-8862-d253bc616a15).
Vulnerabilities in the underlying Atlassian Forge platform or Jira Cloud itself should be reported directly to Atlassian at atlassian.com/trust/security.