Skip to main content
Forge scans Bitbucket Cloud repositories for AI application code, configuration, tools, and deployment evidence. Findings retain their workspace, repository, revision, and file provenance for review in Inventory.

Coverage

Detection

Forge suppresses weak uncorroborated matches and assigns evidence quality and confidence to each accepted observation. Secret references may be detected; secret values are not collected.

Scan contract

Connection

Setup

  1. Open Settings → Integrations → Bitbucket and save the workspace, base URL, authentication mode, and token. Supply the username when using bitbucket_api_token.
  2. Leave the repository list empty to enumerate repositories visible to the token, or provide an explicit allowlist.
  3. Run a sync. Forge records success, observationCount, canonicalInventoryCount, and blockers for each repository.
Changing the base URL after a credential has been saved requires token rotation. Production endpoints must use HTTPS and cannot contain credentials, query strings, fragments, or path traversal.

Boundaries

Bitbucket scanning establishes code and configuration evidence, not live execution. Runtime user identity, prompt and response content, tool calls, and policy decisions require endpoint, gateway, or cloud telemetry.