Skip to content

Bitbucket

The Bitbucket integration connects Bitbucket Cloud to Oneleet and syncs your workspaces, repositories, and users as assets. Self-managed Bitbucket Data Center isn’t supported.

After you connect, you can add your Bitbucket repositories to Code Security. Dependency Scanning runs on the repositories you add there. Not every Code Security feature is available for Bitbucket; see Git provider support.

  • Workspaces: every workspace the connected Bitbucket account belongs to
  • Repositories: the repositories in each of those workspaces, with their default branch and branch names
  • Users: the members of each workspace, with their permission in that workspace. Someone who belongs to several workspaces appears as one user account.

Oneleet uses the synced users for detected accounts and access reviews.

Oneleet has no monitors that check Bitbucket workspaces, repositories, or users directly, so a repository that’s synced but not added to Code Security isn’t checked by any monitor. When you add a Bitbucket repository to Code Security, it falls under the monitors that check git repositories for code security scanning, dependency scanning, and software bills of materials, when applicable to your active compliance programs.

To set up the Bitbucket integration, navigate to Integrations > Add integration > Bitbucket.

Oneleet uses OAuth to connect to the Bitbucket API. Click the Connect button to start the OAuth authorization flow.

The OAuth flow requests these Bitbucket scopes:

  • account
  • project
  • repository
  1. Click Connect on the integration setup form
  2. You will be redirected to Bitbucket to authorize Oneleet
  3. Grant the requested permissions
  4. Bitbucket will redirect you back to Oneleet

You don’t choose a workspace during setup. Oneleet syncs all the workspaces your Bitbucket account belongs to, so connect with an account that’s a member of every workspace you want in Oneleet.