upwind-code

Upwind Code Expands Enterprise Coverage to Azure DevOps and Bitbucket Cloud

Danilo Michelucci September 14, 2026

Modern development organizations rarely keep all their code in one place. Teams may use different version control platforms because of acquisitions, business-unit preferences, regional requirements, or existing development workflows. But when code is spread across multiple providers, application security coverage can become fragmented too.

Today, Upwind Code adds support for Azure DevOps and Bitbucket Cloud. Together with existing support for GitHub and GitLab, Upwind now connects to every major version control provider, helping enterprises secure code across their organization without forcing developers to change how they work.

Your Code Doesn’t Live in One Place

When version control is fragmented, security tools often are too. One provider may have strong scanning coverage while another relies on a separate tool or is not scanned at all. Repositories without clear ownership can quietly fall outside established security processes, creating blind spots between teams and platforms.

code-01-scaled

Supporting every major provider is more than checking an integration box. It gives security teams a consistent view of code risk across the business, wherever that code is hosted.

Coverage Across Major Version Control Providers

Upwind for Azure DevOps

Upwind connects to Azure DevOps at the organization level through Microsoft Entra ID, aligning with the identity model Microsoft-based development teams already use.

With the integration, teams can:

  • Connect multiple Azure DevOps organizations through a centralized setup.
  • Include future organizations and projects as they are created.
  • View findings in the Upwind console and directly on pull requests.
  • Begin repository discovery without changing existing CI/CD pipelines.

This approach makes it easier for enterprises to extend security coverage across large and evolving Azure DevOps environments without managing every repository individually.

Upwind for Bitbucket Cloud

Upwind connects to Bitbucket Cloud at the workspace level, allowing security coverage to follow the workspace rather than depend on individual repository connections.

Teams can:

  • Discover projects and repositories across a connected workspace.
  • Automatically include new repositories as they appear.
  • Avoid repeated per-repository authorization.
  • Surface findings on pull requests within developers’ existing review workflows.

For fast-moving teams, this helps prevent new repositories from becoming new blind spots.

code-02-scaled

Consistent Coverage Wherever Your Code Lives

Adding more providers only matters if teams receive a consistent security experience across them. Upwind Code brings supported software supply chain and infrastructure-as-code scanning into one place, with findings evaluated and presented through the same platform experience.

Security teams can connect broadly, then choose which organizations and repositories to scan from the Organizations & Repositories page. Access and scan scope remain separate, giving teams centralized visibility while preserving precise control over where scanning runs.

Developers also receive feedback in the pull request workflows they already use. That means security can move closer to the point where code changes happen, helping teams address issues earlier without introducing another disconnected process.

Most importantly, Upwind connects code findings with runtime context. Instead of prioritizing a vulnerable dependency based only on where its repository is hosted, teams can focus on the questions that determine real risk: Is the affected code loaded? Is the workload exposed? Is it reachable in the running environment?

Whether a finding comes from Bitbucket, Azure DevOps, GitHub, or GitLab, it can be evaluated through the same risk-based lens. The version control provider no longer has to be a variable in the prioritization process.

Available Now

Azure DevOps and Bitbucket Cloud support is available now alongside GitHub and GitLab. Teams using other version control providers can also report scan results to Upwind through the API.

To get started, open Components → Integrations in the Upwind console and connect your version control environment.

Code
Contents

Further Reading

upwind-code

Upwind Code Expands Enterprise Coverage to Azure DevOps and Bitbucket Cloud

Modern development organizations rarely keep all their code in one place. Teams may use different version control platforms because of acquisitions, business-unit preferences, regional requirements, or existing development workflows. But when code is spread across multiple providers, application security coverage can become fragmented too. Today, Upwind Code adds support for Azure DevOps and Bitbucket Cloud.…
Blue-agent

Upwind Blue Agent – Increasing the Scope and tooling to a new level of incident response

Cloud attacks do not stay within the boundaries of a single security tool. An intrusion can begin with an API request, execute a process inside a Kubernetes workload, modify a file, contact an external host, use a cloud identity, and change cluster state, all as part of the same incident. But the evidence needed to…
Upwind-Sentinel

Upwind for Microsoft Sentinel – Available on Marketplace and Security Store

Security teams should not have to switch between tools to understand what is happening across their cloud environments. That’s why we’re excited to announce that the Upwind solution for Microsoft Sentinel is now available through the Microsoft Marketplace and the Microsoft Security Store. The integration brings Upwind security data directly into Microsoft Sentinel, helping security…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS