Problem
We have an option for Jira and Confluence to add some HTTP security header and Bamboo still does not have that option.
Content-Security-Policy
X-XSS-Protection
X-Frame-Options
X-Content-Type-Option
Referrer-Policy
Feature-Policy
Confluente servlet app
Jira clickjacking plugin
Suggestion
- Create a plugin/app with a simple servlet (or install the referred app).
- Have Bamboo instances with app pre-installed.