Jira integration known limitations

  • Public preview

These limits apply to XBOW Integration for Jira.

Installation

  • Jira Cloud only.
  • The app does not support Jira Server or Jira Data Center.
  • One active mapping per Jira install.
  • Each install needs its own XBOW organization ID and XBOW API token.

Data flow

  • XBOW remains the source of truth for finding details and vulnerability lifecycle state.
  • Jira status changes write only to XBOW external workflow metadata.
  • The app links one Jira work item to one XBOW finding.

Mapping

  • Required Jira fields must pass Check Fields before saving.
  • The app creates work items in one Jira project and issue type per mapping.
  • The app does not handle multi-project routing. Use Jira Automation if you want to copy, move, or create related work items in other Jira projects after the app creates the primary work item.
  • Unsupported required fields block saving, unless Jira has a default value for them.
  • Test custom Jira workflows before relying on bidirectional writeback.

Events and retry

  • The Events view stores the most recent 100 event records per installation.
  • Do not use the Events view as long-term audit history.
  • There is no backfill or scheduled reconciliation job.
  • Retry appears only when the app has enough stored context.

Three narrower recovery paths do exist:

  • An administrator can retry eligible failures from the Events view.
  • A Jira update can restore a missing link from the Jira issue property.
  • A later XBOW finding event can repair missing XBOW ticket metadata for a finding that is already linked.

Content

  • The app does not sync attachments.
  • The app does not generate PDFs.
  • The app does not sync Jira comments back to XBOW.
  • XBOW finding updates do not edit an existing Jira work item after creation.

Token lifecycle

  • The app validates and stores an XBOW API token for each Jira installation.
  • Token revocation happens in XBOW.

Was this helpful?