-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Release: Merge back 2.52.1 into dev from: master-into-dev/2.52.1-2.53.0-dev #13667
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
….53.0-dev Release: Merge back 2.52.0 into bugfix from: master-into-bugfix/2.52.0-2.53.0-dev
Signed-off-by: kiblik <5609770+kiblik@users.noreply.github.com>
* update package & package-lock * rename directories for hugo 0.152.1 * update other stuff * replace favicons * update faq * move the files into new index * fix links * add sidebar nav to new index * Update test_parsers.py docs path * update node_modules path * revert breaking commit * update test_parsers.py --------- Co-authored-by: Paul Osinski <paul.m.osinski@gmail.com>
Bumps [django](https://github.com/django/django) from 5.1.13 to 5.1.14. - [Commits](django/django@5.1.13...5.1.14) --- updated-dependencies: - dependency-name: django dependency-version: 5.1.14 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…sk handlers (#13630) * Add custom SLA calculation method to Finding model * Refactor SLA expiration date update methods for async processing and improve system settings checks * Update async SLA expiration date update to filter by product ID * Update helpers.py Co-authored-by: valentijnscholten <valentijnscholten@gmail.com> --------- Co-authored-by: valentijnscholten <valentijnscholten@gmail.com>
…r additional tags
* fix(helm): Typo in description of digests Signed-off-by: kiblik <5609770+kiblik@users.noreply.github.com> * fix(helm): Fix PVC templating after #13210 Signed-off-by: kiblik <5609770+kiblik@users.noreply.github.com> --------- Signed-off-by: kiblik <5609770+kiblik@users.noreply.github.com>
* 🎉 Make social auth exceptions configurable * update * fix * update * udpate
[docs] SLAs for Pro
Improve tag handling in importers and add tests for tag imports
Release: Merge release into master from: release/2.52.1
|
This pull request has conflicts, please resolve those before we can evaluate the pull request. |
|
This pull request changes the Renovate bot configuration to delay its own updates to a weekly schedule, which increases the window (up to a week) during which the repository could be exposed to newly discovered vulnerabilities in a high-privilege supply-chain tool. Because Renovate has historically had severe issues (e.g., token leakage and command injection), this delayed patching raises security risk even if the change is marked non-blocking.
Delayed Security Patching for Supply Chain Tool in
|
| Vulnerability | Delayed Security Patching for Supply Chain Tool |
|---|---|
| Description | The configuration for the Renovate bot is changed to delay its own updates to a weekly schedule. Renovate is a critical supply chain tool with privileged access to repository data. Delaying its updates creates a window of up to a week where the repository is exposed to any newly discovered and patched vulnerabilities in Renovate itself. Past vulnerabilities in Renovate have included serious issues like token leakage and arbitrary command injection, highlighting the risk of delayed patching. |
django-DefectDojo/.github/renovate.json
Lines 29 to 32 in f6cac49
| "schedule": ["* * * * 0"] | |
| }], | |
| "customDatasources": { | |
| "endoflife-oldest-maintained": { |
All finding details can be found in the DryRun Security Dashboard.
|
Conflicts have been resolved. A maintainer will review the pull request shortly. |
Release triggered by
rossops