Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
10000 commits
Select commit Hold shift + click to select a range
79a292b
chore(deps): update actions/github-script action from v7.1.0 to v8 (.…
renovate[bot] Sep 5, 2025
45030d5
allow qualys hacker guardian parser to parse larger csv files (#13120)
Jino-T Sep 5, 2025
8ec84b4
Update changelog 2.50 (#13121)
paulOsinski Sep 5, 2025
7eee818
semgrep pro parser (#12848)
valentijnscholten Sep 5, 2025
8e949da
:bug: Implement Wazuh v4.8 (#12739)
manuel-sommer Sep 5, 2025
7d3b999
:tada: Add fix_available information to jfrog (#13115)
manuel-sommer Sep 5, 2025
25e532e
:tada: Add fix_available information to jfrog xray unified parser #12…
manuel-sommer Sep 5, 2025
43434d6
feat: improve Helm chart (#12691)
fernandezcuesta Sep 5, 2025
18330a9
ruff (#13122)
valentijnscholten Sep 5, 2025
d41ceaf
Ruff: Add PLW (#13104)
manuel-sommer Sep 5, 2025
5ada3e3
:bug: Fix finding_group view (#13119)
manuel-sommer Sep 5, 2025
aeb7c4a
fix default order to finding_groups
LeoOMaia Sep 6, 2025
433208a
Merge pull request #13127 from LeoOMaia/default-findinggroup
rossops Sep 8, 2025
f72cb99
Update versions in application files
Sep 8, 2025
580681e
Merge pull request #13135 from DefectDojo/release/2.50.1
rossops Sep 8, 2025
69e22de
Update versions in application files
Sep 8, 2025
fc4c132
Update versions in application files
Sep 8, 2025
bc7bf32
Merge branch 'dev' into master-into-dev/2.50.1-2.51.0-dev
rossops Sep 8, 2025
f42df63
Merge pull request #13138 from DefectDojo/master-into-dev/2.50.1-2.51…
rossops Sep 8, 2025
6a9bf1a
Merge pull request #13137 from DefectDojo/master-into-bugfix/2.50.1-2…
rossops Sep 8, 2025
7295fa8
Bump psycopg[c] from 3.2.9 to 3.2.10 (#13133)
dependabot[bot] Sep 8, 2025
3fb18e0
Bump boto3 from 1.40.24 to 1.40.25 (#13132)
dependabot[bot] Sep 8, 2025
09966bd
Update mikefarah/yq action from v4.47.1 to v4.47.2 (.github/workflows…
renovate[bot] Sep 8, 2025
8665da5
Update dependency vite from 7.1.4 to v7.1.5 (docs/package.json) (#13130)
renovate[bot] Sep 8, 2025
14f227c
chore(deps): update softprops/action-gh-release action from v2.3.2 to…
renovate[bot] Sep 8, 2025
3d37175
Bump datatables.net from 2.3.3 to 2.3.4 in /components (#13145)
dependabot[bot] Sep 10, 2025
83d80ce
Update postgres:17.6-alpine Docker digest from 17.6 to 17.6-alpine (d…
renovate[bot] Sep 10, 2025
228d0d5
Bump vite from 7.1.3 to 7.1.5 in /docs (#13147)
dependabot[bot] Sep 10, 2025
830e120
Bump datatables.net-buttons-bs from 3.2.4 to 3.2.5 in /components (#1…
dependabot[bot] Sep 10, 2025
40b7418
:tada: Add OXAS-ADV- vulnid (#13129)
manuel-sommer Sep 10, 2025
74e28c3
docker: remove dev dependencies from release images (#13095)
valentijnscholten Sep 10, 2025
e464cbe
Allow enabling Django Debug Toolbar via env variable (#12921)
valentijnscholten Sep 10, 2025
4400959
Rename duplicate 'Dashboard' to 'Finding Groups' (#13140)
testaccount90009 Sep 10, 2025
d8afc96
Bump boto3 from 1.40.25 to 1.40.27 (#13149)
dependabot[bot] Sep 10, 2025
c52c5bc
feat(docker): Use Python 3.12 in docker images (#10473)
kiblik Sep 10, 2025
1336ba5
fix(helm): uwsgi tuning (#13146)
kiblik Sep 11, 2025
35bc518
Update to Django 5.1.12 (#13148)
valentijnscholten Sep 11, 2025
976f72c
feat(social): Add SOCIAL_AUTH_OIDC_LOGIN_BUTTON_TEXT (#13150)
kiblik Sep 11, 2025
00ac181
add new opensource page (#13151)
paulOsinski Sep 12, 2025
33f8beb
chore(deps): update dependency django-test-migrations from 1.4.0 to v…
renovate[bot] Sep 12, 2025
2fe00d6
:tada: Add fix_available information to mend #12633 (#13142)
manuel-sommer Sep 12, 2025
e42f2cb
fix(helm): Drop bitnami repo reference (#13125)
kiblik Sep 12, 2025
58e87a9
Bump ruff from 0.12.12 to 0.13.0 (#13159)
dependabot[bot] Sep 12, 2025
8fb9fd7
fortify fpr_parser: allow optional fields to be optional (#13160)
fopina Sep 12, 2025
3ab9c06
:tada: Add fix_available information to wpscan #12633 (#13153)
manuel-sommer Sep 12, 2025
cbdf895
Ruff: Add PLC0415 (#13156)
manuel-sommer Sep 12, 2025
f156277
:tada: Add fix_available information to jfrogondemand #12633 (#13124)
manuel-sommer Sep 12, 2025
a998a9b
Generic parser update (#13139)
mykhailo-sindieiev Sep 12, 2025
9acaab2
Github Vulnerability Parser: Update docs to generate correct schema
Maffooch Sep 12, 2025
19d708a
update pro changelog 2.50.1
Sep 12, 2025
3ccf079
add None check
valentijnscholten Sep 12, 2025
6d104d3
Bump boto3 from 1.40.27 to 1.40.29 (#13164)
dependabot[bot] Sep 13, 2025
299a018
Ruff: Add PLC1901 (#13157)
manuel-sommer Sep 13, 2025
0a2ff28
Merge pull request #13168 from valentijnscholten/jira-keep-in-sync-safe
rossops Sep 15, 2025
676aa93
Merge pull request #13167 from paulOsinski/changelog
rossops Sep 15, 2025
d1592dd
Merge pull request #13166 from DefectDojo/Maffooch-patch-5
rossops Sep 15, 2025
790fdfa
Update versions in application files
Sep 15, 2025
8a72a83
Merge branch 'master' into release/2.50.2
rossops Sep 15, 2025
68821a8
Merge pull request #13173 from DefectDojo/release/2.50.2
rossops Sep 15, 2025
bbe2ed1
Update versions in application files
Sep 15, 2025
45adce5
Update versions in application files
Sep 15, 2025
34e8ae2
Merge branch 'dev' into master-into-dev/2.50.2-2.51.0-dev
rossops Sep 15, 2025
186f047
Merge pull request #13174 from DefectDojo/master-into-dev/2.50.2-2.51…
rossops Sep 15, 2025
05ca7ab
Merge pull request #13175 from DefectDojo/master-into-bugfix/2.50.2-2…
rossops Sep 15, 2025
6441938
Bump boto3 from 1.40.29 to 1.40.30 (#13172)
dependabot[bot] Sep 15, 2025
47c3cf4
Bump pyopenssl from 25.1.0 to 25.2.0 (#13171)
dependabot[bot] Sep 15, 2025
1a80117
product grade: only update product if grade has changed (#13123)
valentijnscholten Sep 15, 2025
d1d007a
Ruff: Add PLC0415 to dojo/models (#13165)
manuel-sommer Sep 15, 2025
fa958b8
feat(helm): Improve docs, add schema (#12984)
kiblik Sep 16, 2025
3cd24d1
watson: perform async index updates (#13152)
valentijnscholten Sep 16, 2025
f10d793
fix(deps): update dependency @docsearch/js from 3.9.0 to v4 (docs/pac…
renovate[bot] Sep 16, 2025
57069ba
Fix naive datetime warnings/errors (#13170)
valentijnscholten Sep 17, 2025
873c5c2
fix(deps): update dependency @docsearch/css from 3.9.0 to v4 (docs/pa…
renovate[bot] Sep 17, 2025
281696e
fix(deps): update dependency @tabler/icons from 3.34.1 to v3.35.0 (do…
renovate[bot] Sep 17, 2025
6ffb967
:arrow_up: Bump boto3 from 1.40.30 to 1.40.31 (#13185)
dependabot[bot] Sep 17, 2025
a75cea3
:arrow_up: Bump boto3 from 1.40.31 to 1.40.32 (#13203)
dependabot[bot] Sep 17, 2025
270ab86
Update actions/checkout action from v4.2.2 to v5 (.github/workflows/t…
renovate[bot] Sep 17, 2025
09eb62d
chore(deps): update losisin/helm-values-schema-json-action action fro…
renovate[bot] Sep 17, 2025
937dec7
chore(deps): update azure/setup-helm action from v4.3.0 to v4.3.1 (.g…
renovate[bot] Sep 17, 2025
373eff1
debugtoolbar: fix for requirements-dev.txt (#13183)
valentijnscholten Sep 17, 2025
c45aa56
NN vulnid (#13180)
manuel-sommer Sep 17, 2025
5dfc4bd
:arrow_up: Bump pyopenssl from 25.2.0 to 25.3.0 (#13202)
dependabot[bot] Sep 18, 2025
324684e
fix(helm): Set correct icon link (#13195)
kiblik Sep 18, 2025
d9b6176
:arrow_up: Bump boto3 from 1.40.32 to 1.40.33 (#13213)
dependabot[bot] Sep 18, 2025
8004997
:arrow_up: Bump cryptography from 45.0.7 to 46.0.1 (#13204)
dependabot[bot] Sep 18, 2025
cb01b7d
:lipstick: Update Wazuh v4.8 (#13184)
manuel-sommer Sep 19, 2025
25a32cc
feat(helm): Trigger update of Helm docs when version is changed (#13191)
kiblik Sep 19, 2025
9159e3d
feat(helm): Better explanation for failing GHA (#13198)
kiblik Sep 19, 2025
cf62d26
fix(helm): Empty string values propagated as strings (not as null) (#…
kiblik Sep 19, 2025
8a1992c
:tada: Add fix_available information to blackduck component risk #126…
manuel-sommer Sep 19, 2025
9acc3ce
dockerfiles: drop wheels from layers (#13209)
fopina Sep 19, 2025
72806a7
make close_old_findings tooltip clearer when service is not set / emp…
fopina Sep 19, 2025
01d052f
:arrow_up: Bump boto3 from 1.40.33 to 1.40.34 (#13221)
dependabot[bot] Sep 19, 2025
f5d8ea5
Unit Tests: Ignore deprecation Warning from BlackDuck pypi package (#…
Maffooch Sep 19, 2025
76cff59
:arrow_up: Bump ruff to 0.13.1 (#13223)
manuel-sommer Sep 19, 2025
ab4315d
Ruff: Add PLC1901 to dojo/models (#13178)
manuel-sommer Sep 19, 2025
f75d375
bulk edit: update under_review flag (#13179)
valentijnscholten Sep 19, 2025
fdd5a66
chore(deps): update dependency vite from 7.1.5 to v7.1.6 (docs/packag…
renovate[bot] Sep 19, 2025
887d426
Tags: Remove duplicates in edit forms
Maffooch Sep 19, 2025
9ca1c58
Correcting ruff
Maffooch Sep 19, 2025
1d1b84e
[docs] changelog 2.50.2, minor changes (#13226)
paulOsinski Sep 20, 2025
797bd24
feat(helm): Add ArtifactHub Linter (#13199)
kiblik Sep 20, 2025
0b53add
Merge pull request #13228 from DefectDojo/duplicate-tag-patch
rossops Sep 22, 2025
f69c5a0
Update versions in application files
Sep 22, 2025
15141de
Merge pull request #13238 from DefectDojo/release/2.50.3
rossops Sep 22, 2025
07fb8ab
Update versions in application files
Sep 22, 2025
9976826
Update versions in application files
Sep 22, 2025
4cbb405
Merge branch 'dev' into master-into-dev/2.50.2-2.51.0-dev
rossops Sep 22, 2025
bb35fe8
Update query count in tests
Maffooch Sep 22, 2025
7ef8d6a
Merge pull request #13239 from DefectDojo/master-into-bugfix/2.50.2-2…
rossops Sep 22, 2025
09acc8f
Merge pull request #13240 from DefectDojo/master-into-dev/2.50.2-2.51…
rossops Sep 22, 2025
bda56b4
fix(helm): Update annotations during releasing (#13197)
kiblik Sep 23, 2025
9e9ce38
fix(helm): apiVersion overrides not needed in tests (#13207)
kiblik Sep 23, 2025
d8a461d
fix(deps): update dependency @docsearch/js from 4.0.1 to v4.1.0 (docs…
renovate[bot] Sep 23, 2025
6a4eb92
:arrow_up: Bump lxml from 6.0.1 to 6.0.2 (#13235)
dependabot[bot] Sep 23, 2025
02638f6
chore(deps): update dependency vite from 7.1.6 to v7.1.7 (docs/packag…
renovate[bot] Sep 23, 2025
ea05d71
k8s-tests: bump k8s and minukube (#13231)
valentijnscholten Sep 23, 2025
9fb8846
drop django-tagging as dependency (#13216)
fopina Sep 23, 2025
8db0425
fix(deps): update dependency @docsearch/css from 4.0.1 to v4.1.0 (doc…
renovate[bot] Sep 23, 2025
e9eee8b
:arrow_up: Bump boto3 from 1.40.34 to 1.40.36 (#13246)
dependabot[bot] Sep 23, 2025
4f188db
debug toolbar: disable by default (#13227)
valentijnscholten Sep 23, 2025
afcb3e5
make sonarqube hotspots sync work (#13206)
dshafranskiy-r7 Sep 23, 2025
2fc8bef
:tada: Add fix_available information to blackduck binary analysis par…
manuel-sommer Sep 23, 2025
6919a69
Ruff: Add SIM115 (#13219)
manuel-sommer Sep 23, 2025
bc0900f
feat(helm): Make API test more verbose (#13208)
kiblik Sep 23, 2025
fd2bf22
do not build/start unused services in unit test docker compose files …
fopina Sep 23, 2025
9ce8e87
Update postgres:17.6-alpine Docker digest from 17.6 to 17.6-alpine (d…
renovate[bot] Sep 24, 2025
2175461
:arrow_up: Bump boto3 from 1.40.36 to 1.40.37 (#13253)
dependabot[bot] Sep 24, 2025
c593ace
chore(deps): update actions/cache action from v4.2.4 to v4.3.0 (.gith…
renovate[bot] Sep 24, 2025
287a06a
chore(deps): update node.js from v22.19.0 to v22.20.0 (docs/package.j…
renovate[bot] Sep 24, 2025
169c1fc
Refactor warning handling for blackduck import (#13229)
Maffooch Sep 24, 2025
169e9d3
jira webhook: add comment detection test (#13232)
valentijnscholten Sep 24, 2025
7c0f3f0
Added line number field for SonarQube Scan and SonarQube Scan Detaile…
Sep 24, 2025
c3e4c8b
feat(helm): Add docs for more variables (#13224)
kiblik Sep 25, 2025
ccef941
:arrow_up: Bump pycurl from 7.45.6 to 7.45.7 (#13258)
dependabot[bot] Sep 26, 2025
698ea66
:arrow_up: Bump pyyaml from 6.0.2 to 6.0.3 (#13264)
dependabot[bot] Sep 26, 2025
699e3b1
OpenVAS parser improvments (#13214)
jostaub Sep 26, 2025
649f866
chore(deps): update dependency node from 22.19.0 to v22.20.0 (.github…
renovate[bot] Sep 26, 2025
e296b78
:arrow_up: Bump ruff to 0.13.2 (#13267)
manuel-sommer Sep 26, 2025
9bf7a32
Revert "Bump django-tagulous from 2.1.0 to 2.1.1" and "Tags: Remove d…
fopina Sep 26, 2025
8a47310
:arrow_up: Bump boto3 from 1.40.37 to 1.40.39 (#13265)
dependabot[bot] Sep 26, 2025
043aee4
update changelog 2.50.3
Sep 26, 2025
0ef0eb2
Added branch_tag to jira epic description
Sep 26, 2025
7bc1835
Fixing ruff linter issue
Sep 26, 2025
80ec10d
product grade logging fix (#13268)
valentijnscholten Sep 26, 2025
14d7e91
Merge branch 'DefectDojo:bugfix' into bugfix
Jino-T Sep 26, 2025
0638fdd
Added protection for type mismatch
Sep 26, 2025
df70797
Merge pull request #13270 from Jino-T/bugfix-jira-epic-branch-name
rossops Sep 29, 2025
4d6b44d
Merge pull request #13269 from paulOsinski/bugfix
rossops Sep 29, 2025
cf9fc09
Merge pull request #13256 from Jino-T/bugfix
rossops Sep 29, 2025
3480313
Update versions in application files
Sep 29, 2025
4527392
Merge pull request #13275 from DefectDojo/release/2.50.4
rossops Sep 29, 2025
862f43b
Update versions in application files
Sep 29, 2025
2477d69
Update versions in application files
Sep 29, 2025
b527bf7
Merge branch 'dev' into master-into-dev/2.50.4-2.51.0-dev
rossops Sep 29, 2025
30db93f
Fixing merge error
rossops Sep 29, 2025
832a0f1
Merge pull request #13277 from DefectDojo/master-into-bugfix/2.50.4-2…
rossops Sep 29, 2025
460ec82
Setting k8s version back since .1 isnt supported in minikube
rossops Sep 29, 2025
dc761aa
Merge pull request #13276 from DefectDojo/master-into-dev/2.50.4-2.51…
rossops Sep 29, 2025
8940cc8
Bug Fix: improve Kiuwan SCA parser to support multi component finding…
mwager Sep 29, 2025
a2a52f1
:bug: Fix tenable CWE #13245 (#13252)
manuel-sommer Sep 29, 2025
2fc71eb
close finding: sync api and ui behaviour (#13230)
valentijnscholten Sep 29, 2025
57690b9
Import history optimize (#13182)
valentijnscholten Sep 29, 2025
13253f5
feat(finding list): Add planned_remediation_version (#13261)
kiblik Sep 29, 2025
927e261
Reduce and optimize number of product grading calls using a `Chord` (…
valentijnscholten Sep 29, 2025
598220a
chore(deps): update postgres docker tag from 17.6 to v18 (docker-comp…
renovate[bot] Sep 30, 2025
58fddff
:arrow_up: Bump boto3 from 1.40.39 to 1.40.41 (#13283)
dependabot[bot] Sep 30, 2025
6ef4443
chore(deps): update postgres:18.0-alpine docker digest from 18.0 to 1…
renovate[bot] Sep 30, 2025
ea162af
:arrow_up: Bump openapitools/openapi-generator-cli (#13279)
dependabot[bot] Sep 30, 2025
66b03b3
:arrow_up: Bump python-gitlab from 6.3.0 to 6.4.0 (#13278)
dependabot[bot] Sep 30, 2025
3081970
Update docker/login-action action from v3.5.0 to v3.6.0 (.github/work…
renovate[bot] Sep 30, 2025
82b5e9b
:arrow_up: Bump cryptography from 46.0.1 to 46.0.2 (#13290)
dependabot[bot] Oct 1, 2025
5fc6f3b
:arrow_up: Bump drf-spectacular-sidecar from 2025.9.1 to 2025.10.1 (#…
dependabot[bot] Oct 1, 2025
81435f7
:arrow_up: Bump boto3 from 1.40.41 to 1.40.42 (#13288)
dependabot[bot] Oct 1, 2025
c48d541
Add AWS security bulletins to vulnid (#13272)
manuel-sommer Oct 1, 2025
b8eee86
requested review: add data to notification title (#13284)
valentijnscholten Oct 2, 2025
fc44e8b
Update postgres:18.0-alpine Docker digest from 18.0 to 18.0-alpine (d…
renovate[bot] Oct 2, 2025
46f95fc
GitHub Secrets Detection Report Parser (#13286)
Logicmn Oct 2, 2025
62b53d6
Introduce text labels for v3 (#13155)
dogboat Oct 2, 2025
42b518c
Update dependency vite from 7.1.7 to v7.1.8 (docs/package.json) (#13294)
renovate[bot] Oct 2, 2025
ad3b6b7
:arrow_up: Bump boto3 from 1.40.42 to 1.40.43 (#13295)
dependabot[bot] Oct 2, 2025
22d7ece
Similar Findings: Restrict to Product Scope (#13271)
Maffooch Oct 2, 2025
fb85784
Snyk Issue Api Scan "sca" import implementation (#13263)
dshafranskiy-r7 Oct 3, 2025
6142157
Update postgres:18.0-alpine Docker digest from 18.0 to 18.0-alpine (d…
renovate[bot] Oct 3, 2025
d900ef2
performance optimization: add tags in bulk (#13285)
valentijnscholten Oct 3, 2025
7082611
Update dependency vite from 7.1.8 to v7.1.9 (docs/package.json) (#13306)
renovate[bot] Oct 3, 2025
81f3a17
Update close-stale.yml (#13298)
valentijnscholten Oct 3, 2025
40569ba
Auditlog: Add django-pghistory as audit log (optional for now) (#13169)
valentijnscholten Oct 3, 2025
43fe726
:arrow_up: Bump boto3 from 1.40.43 to 1.40.44 (#13308)
dependabot[bot] Oct 3, 2025
3a0cd3c
Update softprops/action-gh-release action from v2.3.3 to v2.3.4 (.git…
renovate[bot] Oct 3, 2025
983f501
Update actions/stale action from v10.0.0 to v10.1.0 (.github/workflow…
renovate[bot] Oct 3, 2025
5881505
Add CVSS details extraction to AWS Inspector2 parser (#13305)
Maffooch Oct 3, 2025
319ea6e
changelog oct 3 (#13315)
paulOsinski Oct 3, 2025
8e400a2
ui import: allow providing test title (#13299)
valentijnscholten Oct 4, 2025
df93de2
search results: enable bulk adding of tags and notes (#13297)
valentijnscholten Oct 4, 2025
77d6bdd
findings list: support ordering by more fields (#13300)
valentijnscholten Oct 4, 2025
7de7ec3
make SOCIAL_AUTH_USERNAME_IS_FULL_EMAIL configurable (#13301)
valentijnscholten Oct 4, 2025
89ac05a
enhance/normalize EDITABLE_MITIGATED_DATA handling (#13303)
valentijnscholten Oct 4, 2025
924ba7f
finding api: fix hash_code for vulnerability_ids (#13304)
valentijnscholten Oct 4, 2025
75d9bb2
twistlock: defend against compliances being null (#13318)
valentijnscholten Oct 4, 2025
5199554
update default audit log type to use django-auditlog
Maffooch Oct 4, 2025
62d52f8
Update redis Docker tag from 7.2.10 to v7.2.11 (docker-compose.yml) (…
renovate[bot] Oct 4, 2025
fad261f
Merge branch 'dev' into audit-log-default
rossops Oct 6, 2025
2ab6c8b
Merge pull request #13321 from DefectDojo/audit-log-default
rossops Oct 6, 2025
6e613d1
upgrade notes: explain performance improvements 2.51 (#13287)
valentijnscholten Oct 6, 2025
b1a5cba
Refactor vulnerability ID and endpoint retrieval in Finding model (#1…
Maffooch Oct 6, 2025
4a80d28
Merge branch 'dev' into bugfix
rossops Oct 6, 2025
4b695cb
Merge pull request #13348 from DefectDojo/bugfix
rossops Oct 6, 2025
add9b4e
Update versions in application files
Oct 6, 2025
f3e1ffb
Updating helm docs
rossops Oct 6, 2025
9dc11ff
order alerts explicitly (#13314)
valentijnscholten Oct 6, 2025
1b338e2
Merge pull request #13350 from DefectDojo/release/2.51.0
rossops Oct 6, 2025
209010d
Update versions in application files
Oct 6, 2025
f9b0961
Merge branch 'bugfix' into master-into-bugfix/2.51.0-2.52.0-dev
rossops Oct 6, 2025
96fa917
Merge pull request #13354 from DefectDojo/master-into-bugfix/2.51.0-2…
rossops Oct 6, 2025
9d2e906
fix(gha): Run Release-Nightly only once a day (#13329)
kiblik Oct 7, 2025
5e7fe2a
Bump django from 5.1.12 to 5.1.13 (#13353)
dependabot[bot] Oct 7, 2025
7d8b3f9
fix: handle broken endpoints when <startURL> includes a port number i…
Irfan-Mohd Oct 7, 2025
12ea082
fix:broken endpoint error in acunetix XML parser with unittests
Irfan-Mohd Oct 7, 2025
51447c7
all unittests clear for broken endpoint in Acunetix parser
Irfan-Mohd Oct 7, 2025
aba31c7
Fix: resolve ruff linting errors
Irfan-Mohd Oct 7, 2025
004f492
Fix: resolve ruff linting errors
Irfan-Mohd Oct 7, 2025
6eba956
Fix: resolve ruff linting errors
Irfan-Mohd Oct 7, 2025
f548051
Fix: resolve ruff linting errors
Irfan-Mohd Oct 7, 2025
4460758
feat(helm): Add support for automountServiceAccountToken
kiblik Oct 8, 2025
f809828
pghistory_backfill: avoid prefetching - dry-run working
valentijnscholten Oct 8, 2025
a02c4e3
JIRA instance config: improve error handling on open/close status ids…
valentijnscholten Oct 8, 2025
9ba01e3
skip duplicates: remove obsolete references (#13327)
valentijnscholten Oct 8, 2025
e13a95c
watson middleware: skip logging if no instances updated (#13363)
valentijnscholten Oct 8, 2025
b503b8b
finalize
valentijnscholten Oct 8, 2025
3eb4e36
feat(helm): Make release commits more verbose (#13367)
kiblik Oct 9, 2025
f4b53ca
feat(gha): Help Renovate + Dependabot to update HELM docs (#13366)
kiblik Oct 10, 2025
3fca6c1
feat(helm): Hint for correct "artifacthub.io/changes" syntax (#13397)
kiblik Oct 11, 2025
9437ce3
add new test
valentijnscholten Oct 7, 2025
1fef56d
supporting changes
valentijnscholten Oct 7, 2025
4a43381
progress
valentijnscholten Oct 7, 2025
df65888
progress new samples
valentijnscholten Oct 7, 2025
2dfe5cf
somewhat working
valentijnscholten Oct 7, 2025
5c1bee5
cleanup
valentijnscholten Oct 7, 2025
64e120b
update tests
valentijnscholten Oct 11, 2025
2eb45b8
capture dedupe performance
valentijnscholten Oct 12, 2025
45e4931
add backfill using copy
valentijnscholten Oct 12, 2025
39b51a1
add backfill using insert with select from
valentijnscholten Oct 12, 2025
659e136
Merge pull request #13375 from kiblik/helm_automountServiceAccountToken
rossops Oct 14, 2025
d4caea5
Merge pull request #13372 from valentijnscholten/dedupe-importers-uni…
rossops Oct 14, 2025
dbb4950
Merge pull request #13371 from Irfan-Mohd/fix/acunetix-broken-endpoint
rossops Oct 14, 2025
2ae7490
Merge pull request #13383 from valentijnscholten/pghistory-backfill-i…
rossops Oct 14, 2025
a1737ee
Update versions in application files
Oct 14, 2025
cba7d81
Merge pull request #13421 from DefectDojo/release/2.51.1
rossops Oct 14, 2025
0be43c8
fix(helm): replace current helm-charts
kiblik Oct 14, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
3 changes: 3 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
.git
.gitignore
*.md
72 changes: 72 additions & 0 deletions .dryrunsecurity.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
---
sensitiveCodepaths:
- 'dojo/object/urls.py'
- 'dojo/object/views.py'
- 'dojo/announcement/*.py'
- 'dojo/api_v2/*.py'
- 'dojo/api_v2/**/*.py'
- 'dojo/authorization/*.py'
- 'dojo/db_migrations/*.py'
- 'dojo/endpoint/*.py'
- 'dojo/engagement/*.py'
- 'dojo/finding/*.py'
- 'dojo/finding_group/*.py'
- 'dojo/group/*.py'
- 'dojo/importers/*.py'
- 'dojo/importers/**/*.py'
- 'dojo/jira_link/*.py'
- 'dojo/metrics/*.py'
- 'dojo/note_type/*.py'
- 'dojo/notes/*.py'
- 'dojo/product/*.py'
- 'dojo/product_type/*.py'
- 'dojo/reports/*.py'
- 'dojo/risk_acceptance/*.py'
- 'dojo/search/*.py'
- 'dojo/templates/*.html'
- 'dojo/templates/**/*.html'
- 'dojo/templatetags/*.py'
- 'dojo/test/*.py'
- 'dojo/tool_config/*.py'
- 'dojo/tool_product/*.py'
- 'dojo/tool_type/*.py'
- 'dojo/user/*.py'
- 'dojo/apps.py'
- 'dojo/celery.py'
- 'dojo/context_processors.py'
- 'dojo/decorators.py'
- 'dojo/filters.py'
- 'dojo/forms.py'
- 'dojo/middleware.py'
- 'dojo/models.py'
- 'dojo/okta.py'
- 'dojo/pipeline.py'
- 'dojo/remote_user.py'
- 'dojo/tasks.py'
- 'dojo/urls.py'
- 'dojo/utils.py'
- 'dojo/views.py'
- 'dojo/wsgi.py'
- 'docker/environments/*.env'
- 'docker/extra_settings'
- 'docker/entrypoint-celery-beat.sh'
- 'docker/entrypoint-celery-worker.sh'
- 'docker/entrypoint-initializer.sh'
- 'docker/entrypoint-first-boot.sh'
- 'docker/entrypoint-nginx.sh'
- 'docker/entrypoint-uwsgi.sh'
- 'docker/wait-for-it.sh'
allowedAuthors:
usernames:
- mtesauro
- devGregA
- cneill
- Maffooch
- blakeaowens
- kiblik
- dsever
- dogboat
- hblankenship
- valentijnscholten
notificationList:
- '@mtesauro'
19 changes: 19 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Any kind of package updates only need 2 approvals,
# So let's add three folks here
requirements.txt @cneill @mtesauro @Maffooch
# Any dockerfile or compose changes will need to be viewed by
# these people
Dockerfile.* @mtesauro @Maffooch
docker-compose.* @mtesauro @Maffooch
/docker/ @mtesauro @Maffooch
# Documentation changes
/docs/content/ @paulOsinski @valentijnscholten @Maffooch
# Kubernetes should be reviewed by reviewed first by those that know it
/helm/ @cneill @kiblik @Maffooch
# Anything UI related needs to be checked out by those with the eye for it
/dojo/static/ @blakeaowens @Maffooch
/dojo/templates/ @blakeaowens @Maffooch
# Any model changes should be closely looked at
/dojo/models.py @Maffooch
# All other code changes should be reviewed by someone
* @Maffooch @mtesauro
49 changes: 49 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: Bug report
about: Create a report to help us improve
title: ''
labels: bug
assignees: ''

---
**Slack us first!**
The easiest and fastest way to help you is via Slack. There's a free and easy signup to join our #defectdojo channel in the OWASP Slack workspace: [Get Access.](https://owasp.org/slack/invite)
If you're confident you've found a bug, or are allergic to Slack, you can submit an issue anyway.

**Be informative**
Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev version and try again.

**Bug description**
A clear and concise description of what the bug is. For errors include at least the exact error message you are seeing (including traceback).

**Steps to reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Deployment method** *(select with an `X`)*
- [ ] Docker Compose
- [ ] Kubernetes
- [ ] GoDojo

**Environment information**
- Operating System: [e.g. Ubuntu 18.04]
- Docker Compose or Helm version (Output of `docker compose version` or `helm version`)
- DefectDojo version (see footer) or commit message: [use `git show -s --format="[%ci] %h: %s [%d]"`]

**Logs**
Use `docker compose logs` (or similar, depending on your deployment method) to get the logs and add the relevant sections here showing the error occurring (if applicable).

**Sample scan files**
If applicable, add sample scan files to help reproduce your problem.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Additional context** (optional)
Add any other context about the problem here.
26 changes: 26 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
name: Feature request
about: Suggest an idea for DefectDojo
title: ''
labels: enhancement
assignees: ''

---
## :warning: Note on feature completeness :warning:

We are narrowing the scope of acceptable enhancements to DefectDojo. Learn more here:
https://github.com/DefectDojo/django-DefectDojo/blob/master/readme-docs/CONTRIBUTING.md

**Is your feature request related to a problem? Please describe**
A clear and concise description of what the problem is.
Ex: I'm always frustrated when [...]

**Describe the solution you'd like**
A clear and concise description of what you want to happen.
Ex: As a < role >, I want < some goal > so that < some reason >.

**Describe alternatives you've considered**
A clear and concise description of any alternative solutions or features you have considered.

**Additional context**
Add any other context, screenshots, sketch, code snippet, etc. about the feature request here.
14 changes: 14 additions & 0 deletions .github/ISSUE_TEMPLATE/importer_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
name: New importer request
about: Request a new importer (scanner) for DefectDojo
title: ''
labels: Import Scans
assignees: ''

---

**Scanner Name**
Name of the scanner, brief description of the scanner and link.

**Sample File**
Please attach a sample file and the format of the file (xml, json, csv).
16 changes: 16 additions & 0 deletions .github/ISSUE_TEMPLATE/security_issue.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
name: Security issue
about: Report a security issue
title: Please submit via our security reporting program, not GitHub
labels: security
assignees: ''

---

**DefectDojo security reporting program**

If you believe you have found a **security issue** in DefectDojo, please review the [disclosure policy](../../readme-docs/SECURITY.md) and submit your finding via our security reporting program.

Please, do not submit **security issues** via GitHub directly.

Thank you for helping keep DefectDojo and our users safe!
49 changes: 49 additions & 0 deletions .github/ISSUE_TEMPLATE/support_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: Support Request
about: If you need support or are running into some trouble
title: ''
labels: support
assignees: ''

---
**Slack us first!**
The easiest and fastest way to help you is via Slack. There's a free and easy signup to join our #defectdojo channel in the OWASP Slack workspace: [Get Access.](https://owasp.org/slack/invite)
If you're confident you've found a bug, or are allergic to Slack, you can submit an issue anyway.

**Be informative**
Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev branch and try again.

**Problem description**
A clear and concise description of what the problem is. For errors include at least the exact error message you are seeing (including traceback).

**Steps to reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Deployment method** *(select with an `X`)*
- [ ] Docker Compose
- [ ] Kubernetes
- [ ] GoDojo

**Environment information**
- Operating System: [e.g. Ubuntu 18.04]
- Docker Compose or Helm version (Output of `docker compose version` or `helm version`)
- DefectDojo version (see footer) or commit message: [use `git show -s --format="[%ci] %h: %s [%d]"`]

**Logs**
Use `docker compose logs` (or similar, depending on your deployment method) to get the logs and add the relevant sections here showing the error occurring (if applicable).

**Sample scan files**
If applicable, add sample scan files to help reproduce your problem.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Additional context** (optional)
Add any other context about the problem here.
71 changes: 71 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
version: 2
updates:
- package-ecosystem: pip
directory: "/"
schedule:
interval: daily
open-pull-requests-limit: 10
target-branch: dev
ignore:
- dependency-name: whitenoise
versions:
- ">= 5.a"
- "< 6"
- package-ecosystem: npm
directory: "/components"
schedule:
interval: daily
open-pull-requests-limit: 10
target-branch: dev
ignore:
- dependency-name: bootstrap
versions:
- ">= 4.a"
- "< 5"
- dependency-name: bootstrap-social
versions:
- ">= 5.a"
- "< 6"
- dependency-name: bootswatch
versions:
- ">= 4.a"
- "< 5"
- dependency-name: chosen
versions:
- ">= 1.a"
- "< 2"
- dependency-name: drmonty-datatables-responsive
versions:
- ">= 2.a"
- "< 3"
- dependency-name: flot
versions:
- ">= 2.a"
- "< 3"
- dependency-name: flot
versions:
- ">= 3.a"
- "< 4"
- dependency-name: flot
versions:
- ">= 4.a"
- "< 5"
- dependency-name: fullcalendar
versions:
- ">= 5.a"
- "< 6"
- dependency-name: startbootstrap-sb-admin-2
versions:
- ">= 3.a"
- "< 4"
- dependency-name: startbootstrap-sb-admin-2
versions:
- ">= 4.a"
- "< 5"
- package-ecosystem: docker
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 10
target-branch: dev

67 changes: 67 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
docs:
- changed-files:
- any-glob-to-any-file:
- docs/**/*
- readme-docs/**/*

docker:
- changed-files:
- any-glob-to-any-file:
- docker/**/*
- docker**
- Docker*

helm:
- changed-files:
- any-glob-to-any-file:
- helm/defectdojo/*
- helm/defectdojo/**/*

"New Migration":
- changed-files:
- any-glob-to-any-file:
- dojo/db_migrations/*

unittests:
- changed-files:
- any-glob-to-any-file:
- unittests/**/*

integration_tests:
- changed-files:
- any-glob-to-any-file:
- tests/**/*

settings_changes:
- changed-files:
- any-glob-to-any-file:
- dojo/settings/settings.dist.py

apiv2:
- changed-files:
- any-glob-to-any-file:
- dojo/api_v2/**/*

ui:
- changed-files:
- any-glob-to-any-file:
- dojo/static/**/*
- dojo/templates/**/*
- dojo/templatetags/**/*

parser:
- changed-files:
- any-glob-to-any-file:
- dojo/tools/**/*

localization:
- changed-files:
- any-glob-to-any-file:
- dojo/locale/*
- dojo/locale/**/*

lint:
- changed-files:
- any-glob-to-any-file:
- ruff.toml
Loading