Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
10000 commits
Select commit Hold shift + click to select a range
7436cf7
chore(deps): update dependency renovatebot/renovate from 41.165.5 to …
renovate[bot] Oct 31, 2025
39e3b9c
chore(deps): update dependency django-debug-toolbar from 6.0.0 to v6.…
renovate[bot] Oct 31, 2025
554b531
chore(deps): update dependency renovatebot/renovate from 41.165.7 to …
renovate[bot] Oct 31, 2025
4fda41e
docker compose: switch to Valkey as message broker (#13331)
valentijnscholten Oct 31, 2025
1ba1122
Fix recipient handling in create_notification method (#13548)
dorkdiaries9 Oct 31, 2025
a8869de
chore(deps): bump ruff from 0.14.2 to 0.14.3 (#13577)
dependabot[bot] Oct 31, 2025
e1eef7c
chore(deps): bump boto3 from 1.40.62 to 1.40.63 (#13579)
dependabot[bot] Oct 31, 2025
a260967
:tada: Add mal vulnid (#13588)
manuel-sommer Nov 3, 2025
ca0fc56
:bug: fix similiar findings severity color (#13586)
manuel-sommer Nov 3, 2025
1f90ab7
fix(CycloneDXJSONParser): handle missing severity field by defaulting…
Maffooch Nov 3, 2025
d1e0dca
[docs] Prioritization Engine adjustments (#13581)
paulOsinski Nov 3, 2025
9fb0dae
:bug: Robustify create_user to handle None value (#13572)
manuel-sommer Nov 3, 2025
1271649
Merge branch 'dev' into bugfix
Maffooch Nov 3, 2025
88361c9
Changing to supported k8s version for minikube
rossops Nov 3, 2025
40dca35
Merge pull request #13601 from DefectDojo/bugfix
rossops Nov 3, 2025
4b6ddca
Update versions in application files
Nov 3, 2025
8f98d4e
Merge branch 'master' into release/2.52.0
rossops Nov 3, 2025
8bc3738
Merge pull request #13602 from DefectDojo/release/2.52.0
rossops Nov 3, 2025
ec606a3
Update versions in application files
Nov 3, 2025
10dd753
Update versions in application files
Nov 3, 2025
fb49ecd
Merge pull request #13606 from DefectDojo/master-into-bugfix/2.52.0-2…
rossops Nov 3, 2025
bd689fe
Merge pull request #13605 from DefectDojo/master-into-dev/2.52.0-2.53…
rossops Nov 3, 2025
0dc5a5b
chore(deps): update dependency renovatebot/renovate from 41.168.0 to …
renovate[bot] Nov 3, 2025
22afcfc
chore(deps): update mccutchen/go-httpbin docker tag from 2.18.3 to v2…
renovate[bot] Nov 3, 2025
99b9567
chore(deps): update dependency renovatebot/renovate from 41.168.6 to …
renovate[bot] Nov 3, 2025
9007e4d
chore(deps): bump drf-spectacular from 0.28.0 to 0.29.0 (#13600)
dependabot[bot] Nov 4, 2025
87a46ae
chore(deps): bump openapitools/openapi-generator-cli (#13599)
dependabot[bot] Nov 4, 2025
503399f
chore(deps): bump nginx from 1.29.2-alpine3.22 to 1.29.3-alpine3.22 (…
dependabot[bot] Nov 4, 2025
d049730
chore(deps): bump markdown from 3.9 to 3.10 (#13609)
dependabot[bot] Nov 4, 2025
0b705d6
chore(deps): bump boto3 from 1.40.63 to 1.40.65 (#13610)
dependabot[bot] Nov 4, 2025
71ae67d
chore(deps): update dependency renovatebot/renovate from 41.169.2 to …
renovate[bot] Nov 4, 2025
b2036f0
chore(deps): update dependency kubernetes/kubernetes from v1.34.0 to …
renovate[bot] Nov 4, 2025
3c28fb5
chore(deps): update dependency vite from 7.1.11 to v7.1.12 (docs/pack…
renovate[bot] Nov 4, 2025
723d6ee
:tada: implement n0s1 scanner #13564 (#13580)
manuel-sommer Nov 4, 2025
d303fea
chore(deps): update dependency renovatebot/renovate from 41.169.4 to …
renovate[bot] Nov 4, 2025
1d68128
:bug: Catch AuthTokenError in middleware (#13608)
manuel-sommer Nov 5, 2025
817a31f
feat(renovate): Update renovate only weekly (#13611)
kiblik Nov 5, 2025
00f0993
:bug: calender: Fix incorrect end dates for engagements and tests (#1…
manuel-sommer Nov 5, 2025
3052ac3
:tada: Advance reimport to update fix_available field #12633 (#12922)
manuel-sommer Nov 5, 2025
f689f84
Make Finding Group Push to Jira Push Push to Duplicate Issues (#13573)
Jino-T Nov 5, 2025
b99e169
[docs] moving Parser Docs to new index (#13528)
paulOsinski Nov 5, 2025
4d869b4
chore(deps): bump django from 5.1.13 to 5.1.14 (#13631)
dependabot[bot] Nov 5, 2025
789cf11
chore(deps): update helm/chart-testing-action action from v2.7.0 to v…
renovate[bot] Nov 6, 2025
10ccf52
chore(deps): bump boto3 from 1.40.65 to 1.40.66 (#13626)
dependabot[bot] Nov 6, 2025
0354619
chore(deps): update dependency vite from 7.1.12 to v7.2.1 (docs/packa…
renovate[bot] Nov 6, 2025
bc493c4
chore(deps): update dependency renovatebot/renovate from 41.170.0 to …
renovate[bot] Nov 6, 2025
0024aa2
fix(deps): update dependency @docsearch/js from 4.2.0 to v4.3.1 (docs…
renovate[bot] Nov 6, 2025
e7fed9b
fix(deps): update dependency @docsearch/css from 4.2.0 to v4.3.1 (doc…
renovate[bot] Nov 6, 2025
253772b
:bug: fix TestForms date validation (#13624)
manuel-sommer Nov 6, 2025
d1d9676
feat(renovate): track oldest maintained k8s (#13545)
kiblik Nov 6, 2025
66b7334
fix(helm/dependabot/renovate): Fix broken automatic update (#13520, #…
kiblik Nov 6, 2025
2f9a5aa
Adding SOCIAL_AUTH_REDIRECT_IS_HTTPS, to enable use of HTTPS protocol…
marcelhorner Nov 6, 2025
83834f0
SLA Calculations: Remove product grade calculation and consolidate ta…
Maffooch Nov 7, 2025
d4e7513
:bug: fix nancy file format update #12860 (#13634)
manuel-sommer Nov 7, 2025
60e2cb3
chore(deps): update dependency renovatebot/renovate from 41.173.0 to …
renovate[bot] Nov 7, 2025
24eb308
fix(tags): improve tag handling in DefaultImporter and add tests for …
Maffooch Nov 7, 2025
d34047e
fix(tags): enhance tag handling in DefaultReImporter and add tests fo…
Maffooch Nov 7, 2025
e2dbca5
fix(helm): Fix PVC templating after #13210 (#13619)
kiblik Nov 7, 2025
213d1e7
add SLA pro documentation
Nov 7, 2025
005104c
reweight in menu
Nov 7, 2025
336946e
fix screenshot
Nov 7, 2025
b388a01
chore(deps): bump ruff from 0.14.3 to 0.14.4 (#13645)
dependabot[bot] Nov 9, 2025
9137d79
chore(deps): bump boto3 from 1.40.66 to 1.40.68 (#13644)
dependabot[bot] Nov 9, 2025
4104958
chore(deps): update dependency vite from 7.2.1 to v7.2.2 (docs/packag…
renovate[bot] Nov 9, 2025
37069a5
chore(deps): bump asteval from 1.0.6 to 1.0.7 (#13646)
dependabot[bot] Nov 9, 2025
717b846
chore(deps): bump django-dbbackup from 5.0.0 to 5.0.1 (#13643)
dependabot[bot] Nov 9, 2025
b1ff550
chore(deps): bump django-crispy-forms from 2.4 to 2.5 (#13642)
dependabot[bot] Nov 9, 2025
071f098
:lipstick: Nancy parser: generate tool link (#13633)
manuel-sommer Nov 9, 2025
2b54bbb
:tada: Make social auth exceptions configurable (#13596)
manuel-sommer Nov 10, 2025
0bc088c
Merge pull request #13652 from paulOsinski/sla-docs
rossops Nov 10, 2025
0523665
Merge branch 'bugfix' into importing-tags
rossops Nov 10, 2025
d519cf7
Merge pull request #13650 from DefectDojo/importing-tags
rossops Nov 10, 2025
f4d4c41
Update versions in application files
Nov 10, 2025
b9836f2
Merge pull request #13664 from DefectDojo/release/2.52.1
rossops Nov 10, 2025
8daba95
Update versions in application files
Nov 10, 2025
c58f90e
Update versions in application files
Nov 10, 2025
1622df3
Merge pull request #13669 from DefectDojo/master-into-bugfix/2.52.1-2…
rossops Nov 10, 2025
5bf54c2
Merge branch 'dev' into master-into-dev/2.52.1-2.53.0-dev
Maffooch Nov 10, 2025
cf2a8b1
:bug: harden jfrog xray unified file parsing #13628 (#13632)
manuel-sommer Nov 10, 2025
f6cac49
Restore n0s1 Scanner documentation in supported tools
Maffooch Nov 10, 2025
ac9c159
Merge pull request #13667 from DefectDojo/master-into-dev/2.52.1-2.53…
rossops Nov 10, 2025
bcb9488
chore(deps): bump boto3 from 1.40.68 to 1.40.69 (#13661)
dependabot[bot] Nov 10, 2025
a78cbeb
chore(deps): update softprops/action-gh-release action from v2.4.1 to…
renovate[bot] Nov 10, 2025
0f3040d
Update dependency renovatebot/renovate from 42.0.3 to v42.5.0 (.githu…
renovate[bot] Nov 10, 2025
d56960d
fix(deps): update dependency @docsearch/css from 4.3.1 to v4.3.2 (doc…
renovate[bot] Nov 10, 2025
c484229
feat(renovate): track oldest maintained k8s (#13670)
kiblik Nov 12, 2025
f44d5a4
Update dependency node from 24.11.0 to v24.11.1 (.github/workflows/va…
renovate[bot] Nov 12, 2025
517c14c
:lipstick: beautify drheader jsonfiles (#13672)
manuel-sommer Nov 12, 2025
c7432c1
:tada: Advance ibm app parser with fix_available (#13663)
manuel-sommer Nov 12, 2025
3396e7b
:tada: add Dawnscanner fix_available field. (#13660)
manuel-sommer Nov 12, 2025
186befb
:bug: fix nancy severity calculation #13656 (#13657)
manuel-sommer Nov 12, 2025
99a1d7e
:bug: fix debug mode in logging #13659 (#13662)
manuel-sommer Nov 12, 2025
fc6aba9
Update dependency kubernetes/kubernetes from v1.34.1 to v1.34.2 (.git…
renovate[bot] Nov 13, 2025
0e46041
chore(deps): bump boto3 from 1.40.69 to 1.40.71 (#13692)
dependabot[bot] Nov 13, 2025
b345e64
chore(deps): bump vulners from 3.1.1 to 3.1.2 (#13691)
dependabot[bot] Nov 13, 2025
2a8eaed
fix(deps): update dependency @docsearch/js from 4.3.1 to v4.3.2 (docs…
renovate[bot] Nov 13, 2025
139741d
Update dependency gohugoio/hugo from v0.152.1 to v0.152.2 (.github/wo…
renovate[bot] Nov 13, 2025
0ff017f
:tada: implement new threatmapper file format #13639 (#13655)
manuel-sommer Nov 13, 2025
573e263
:tada: Add VA vulnid (#13675)
manuel-sommer Nov 13, 2025
038cf16
:tada: Add Kubeaudit fix_available field (#13684)
manuel-sommer Nov 13, 2025
b097ced
feat(helm): Relocate docs/schema hints
kiblik Nov 13, 2025
856aa7a
feat(renovate): Wait 2 days to use latest k8s (#13694)
kiblik Nov 13, 2025
2171863
fix(helm/renovate/dependabot): Commit changes & fix condition format …
kiblik Nov 13, 2025
bea1002
chore(deps): bump boto3 from 1.40.71 to 1.40.72 (#13697)
dependabot[bot] Nov 13, 2025
ed83097
reimport: support pro hash method (#13680)
valentijnscholten Nov 13, 2025
3ce29cb
:bug: fix DD_EDITABLE_MITIGATED_DATA close finding internal server er…
manuel-sommer Nov 14, 2025
769231d
:bug: add user mention notifications in note creation for Engagement,…
Maffooch Nov 14, 2025
19dc283
log a line when custom hash method is used (#13679)
valentijnscholten Nov 14, 2025
44ebefb
:tada: Add pwn sast fix_available field (#13702)
manuel-sommer Nov 14, 2025
68f6639
Deduplicate findings in batches (#13491)
valentijnscholten Nov 14, 2025
6e55879
docs: update SonarQube API pull details (#13689)
sNiXx Nov 14, 2025
3fb802b
Qualys parser add CVEs to vulnerability ids for xml files
Jino-T Nov 14, 2025
c8b521a
Add CVE assertions to Qualys parser tests for vulnerability IDs
Maffooch Nov 14, 2025
348a345
chore(deps): bump boto3 from 1.40.72 to 1.40.73 (#13706)
dependabot[bot] Nov 15, 2025
5e9f1ae
fix(helm): merge extraAnnotations with init job annotations (#13677)
qlimenoque Nov 15, 2025
67801cf
chore(deps): update postgres docker tag from 18.0 to v18.1 (docker-co…
renovate[bot] Nov 15, 2025
2593926
:bug: fix finding closed with a provided mitigated date #13699 (#13700)
manuel-sommer Nov 17, 2025
9a319ce
:arrow_up: Bump ruff from 0.14.4 to 0.14.5 (#13708)
manuel-sommer Nov 17, 2025
3d3427b
[docs] typo fixes (#13709)
paulOsinski Nov 17, 2025
b5a7f9e
Refactor CVE extraction in parse_finding to use list comprehensions f…
Maffooch Nov 17, 2025
82cbdb7
Update postgres:18.1-alpine Docker digest from 18.1 to 18.1-alpine (d…
renovate[bot] Nov 17, 2025
461a885
Update dependency renovatebot/renovate from 42.5.0 to v42.5.4 (.githu…
renovate[bot] Nov 17, 2025
9d83ea6
Merge pull request #13698 from kiblik/helm_hit_help
rossops Nov 17, 2025
3096b0a
Merge pull request #13710 from Jino-T/qualys-fix
rossops Nov 17, 2025
c1387b7
Update versions in application files
Nov 17, 2025
69536d9
Merge pull request #13718 from DefectDojo/release/2.52.2
rossops Nov 17, 2025
aa5a758
Update versions in application files
Nov 17, 2025
ed37199
Update versions in application files
Nov 17, 2025
6f0897a
Merge branch 'dev' into master-into-dev/2.52.2-2.53.0-dev
Maffooch Nov 17, 2025
5b610e4
Merge pull request #13720 from DefectDojo/master-into-bugfix/2.52.2-2…
rossops Nov 17, 2025
8a7ff18
Merge pull request #13721 from DefectDojo/master-into-dev/2.52.2-2.53…
rossops Nov 17, 2025
f6e2657
Update dependency kubernetes from v1.31.13 to v1.32.10 (.github/workf…
renovate[bot] Nov 17, 2025
1d7dcb8
chore(deps): update dependency renovatebot/renovate from 42.5.4 to v4…
renovate[bot] Nov 18, 2025
36af07a
chore(deps): bump boto3 from 1.40.73 to 1.40.74 (#13715)
dependabot[bot] Nov 18, 2025
e931c60
chore(deps): bump datatables.net from 2.3.4 to 2.3.5 in /components (…
dependabot[bot] Nov 18, 2025
374553e
chore(deps): update actions/checkout action from v5.0.0 to v5.0.1 (.g…
renovate[bot] Nov 18, 2025
b6a87cc
chore(deps): bump boto3 from 1.40.74 to 1.40.75 (#13731)
dependabot[bot] Nov 18, 2025
df5430c
feat(renovate): Do not split updates for renovate (#13723)
kiblik Nov 18, 2025
b58fc33
fix(helm): Missing annotation for "master-into-..." (#13722)
kiblik Nov 18, 2025
820f74c
:bug: fix create questionnaire with empty survey (#13728)
manuel-sommer Nov 19, 2025
50450e1
Add notification when finding is created via the API (#13732)
Juu Nov 19, 2025
8bee0b6
:tada: implement certfr vulnid (#13730)
manuel-sommer Nov 19, 2025
21bf1a7
Feat: Add HPA & PDB Helm Chart Support #13391 (#13512)
carlosmt86 Nov 20, 2025
a85bbba
add apollo script (#13734)
paulOsinski Nov 20, 2025
e7f9026
chore(deps): bump redis from 7.0.1 to 7.1.0 (#13742)
dependabot[bot] Nov 20, 2025
cb57c63
chore(deps): bump boto3 from 1.40.75 to 1.41.0 (#13743)
dependabot[bot] Nov 20, 2025
56acdae
Update dependency vite from 7.2.2 to v7.2.4 (docs/package.json) (#13741)
renovate[bot] Nov 20, 2025
bd0fa81
Update dependency yamale from 6.0.0 to v6.1.0 (.github/workflows/test…
renovate[bot] Nov 20, 2025
5a97ed6
Update actions/checkout action from v5.0.1 to v6 (.github/workflows/v…
renovate[bot] Nov 20, 2025
ccca584
[docs] update jira language (#13749)
paulOsinski Nov 21, 2025
4505bdb
:lipstick: restructure github vulnerability reports (#13745)
manuel-sommer Nov 21, 2025
7e7ecd3
:tada: implement zora vulnerabilty parser (#13744)
manuel-sommer Nov 21, 2025
bd81e6e
:bug: fix severity order of trivy (#13736)
manuel-sommer Nov 21, 2025
b5569c0
Add boto3 dependency to dependabot configuration (#13733)
Maffooch Nov 21, 2025
ffc03a9
Add OpenReports import support (#13562)
mfyll Nov 21, 2025
1e9777b
system settings caching optimization + test cases (#13739)
valentijnscholten Nov 21, 2025
7ddbd5f
Add choice fields for business criticality, platform, lifecycle, and …
Maffooch Nov 21, 2025
3a2f66a
Change log level from info to debug for Watson indexing (#13748)
Maffooch Nov 21, 2025
2655ae4
Add path filter for docs in gh-pages workflow
Maffooch Nov 22, 2025
e037f89
chore(deps): bump boto3 from 1.41.0 to 1.41.1 (#13753)
dependabot[bot] Nov 22, 2025
9eb305f
fix: enable uwsgi EXTRA_ARGS passthrough
Bump-Action Nov 22, 2025
f506013
Merge branch 'dev' into uwsgi-extra-args
Bump-Action Nov 22, 2025
10b2c39
Merge pull request #13755 from DefectDojo/Maffooch-patch-3
rossops Nov 24, 2025
f1e363f
Update versions in application files
Nov 24, 2025
59841b4
Merge pull request #13768 from DefectDojo/release/2.52.3
rossops Nov 24, 2025
4aa8010
Update versions in application files
Nov 24, 2025
303c254
Update versions in application files
Nov 24, 2025
c7b813f
Merge branch 'dev' into master-into-dev/2.52.3-2.53.0-dev
Maffooch Nov 24, 2025
9fd9073
Merge pull request #13771 from DefectDojo/master-into-bugfix/2.52.3-2…
rossops Nov 24, 2025
b994e48
Merge pull request #13770 from DefectDojo/master-into-dev/2.52.3-2.53…
rossops Nov 24, 2025
0952a2e
docs: Update number of concurrent connections for uWSGI (#13752)
NoaFayn Nov 25, 2025
7781201
Update dependency renovatebot/renovate from 42.13.3 to v42.21.0 (.git…
renovate[bot] Nov 25, 2025
e274d29
Unit Testing: Do no run in debug mode in order to reduce logging (#13…
Maffooch Nov 26, 2025
678bc65
Update peter-evans/create-pull-request action from v7.0.8 to v7.0.9 (…
renovate[bot] Nov 26, 2025
8917680
:tada: Add 'fix_available' field to zora parser (#13760)
manuel-sommer Nov 26, 2025
75423ff
Update gcr.io/cloudsql-docker/gce-proxy Docker tag from 1.37.9 to v1.…
renovate[bot] Nov 26, 2025
feff19f
chore(deps): bump ruff from 0.14.5 to 0.14.6 (#13763)
dependabot[bot] Nov 26, 2025
ec9ebb3
chore(deps): bump psycopg[c] from 3.2.12 to 3.2.13 (#13764)
dependabot[bot] Nov 26, 2025
11f8310
chore(deps): bump packageurl-python from 0.17.5 to 0.17.6 (#13773)
dependabot[bot] Nov 26, 2025
6fc83be
Update actions/setup-python action from v6.0.0 to v6.1.0 (.github/wor…
renovate[bot] Nov 26, 2025
a0d2ec6
chore(deps): bump boto3 from 1.41.1 to 1.41.4 (#13778)
dependabot[bot] Nov 26, 2025
a5dc944
Update nginx/nginx-prometheus-exporter Docker tag from 1.4.2 to v1.5.…
renovate[bot] Nov 26, 2025
c4e1e02
feat(helm): Use Valkey (#13408)
kiblik Nov 27, 2025
840edf5
fix: rename EXTRA_ARGS to DD_UWSGI_EXTRA_ARGS
Bump-Action Nov 28, 2025
13ab477
Update dependency prettier from 3.6.2 to v3.7.2 (docs/package.json) (…
renovate[bot] Nov 29, 2025
b5eaa75
chore(deps): bump boto3 from 1.41.4 to 1.41.5 (#13782)
dependabot[bot] Nov 29, 2025
c69eb0e
fix(helm): Avoid forbidden chars in annotation (#13772)
kiblik Nov 29, 2025
02a69ef
Remove left over log statement
valentijnscholten Nov 29, 2025
ef3e19d
JIRA: add retries/rate limit support
valentijnscholten Nov 29, 2025
78eb819
Update dependency renovatebot/renovate from 42.21.0 to v42.27.0 (.git…
renovate[bot] Dec 1, 2025
59c6692
Merge pull request #13786 from valentijnscholten/jira-rate-limiting
rossops Dec 1, 2025
9f3d23b
Merge pull request #13756 from Bump-Action/uwsgi-extra-args
rossops Dec 1, 2025
76daa0a
Merge pull request #13784 from DefectDojo/valentijnscholten-patch-3
rossops Dec 1, 2025
83c54b1
Merge branch 'dev' into bugfix
Maffooch Dec 1, 2025
0fa482c
Merge pull request #13801 from DefectDojo/bugfix
rossops Dec 1, 2025
d3d64db
Update versions in application files
Dec 1, 2025
ba85cab
Merge pull request #13802 from DefectDojo/release/2.53.0
rossops Dec 1, 2025
9ccf58e
Update dependency prettier from 3.7.2 to v3.7.3 (docs/package.json) (…
renovate[bot] Dec 1, 2025
532720e
Update versions in application files
Dec 1, 2025
61b8b75
Update versions in application files
Dec 1, 2025
62ab7ab
Merge branch 'dev' into master-into-dev/2.53.0-2.54.0-dev
rossops Dec 1, 2025
a88bdee
fix: Enable AND logic for Tag filtering in Findings (#13789)
PoojasPatel013 Dec 1, 2025
6f7f691
Merge pull request #13804 from DefectDojo/master-into-dev/2.53.0-2.54…
rossops Dec 1, 2025
5017b11
Merge pull request #13803 from DefectDojo/master-into-bugfix/2.53.0-2…
rossops Dec 1, 2025
d3cefdf
chore(deps): update dependency vite from 7.2.4 to v7.2.6 (docs/packag…
renovate[bot] Dec 3, 2025
7ec2943
chore(deps): update softprops/action-gh-release action from v2.4.2 to…
renovate[bot] Dec 3, 2025
ef7ca97
chore(deps): bump celery from 5.5.3 to 5.6.0 (#13794)
dependabot[bot] Dec 3, 2025
e2cf157
chore(deps): bump django-pghistory from 3.8.3 to 3.9.0 (#13795)
dependabot[bot] Dec 3, 2025
0adb904
chore(deps): bump drf-spectacular-sidecar from 2025.10.1 to 2025.12.1…
dependabot[bot] Dec 3, 2025
b9ec210
chore(deps): bump psycopg[c] from 3.2.13 to 3.3.0 (#13798)
dependabot[bot] Dec 3, 2025
6712a07
fix(helm): Drop djnago.mediaPersistentVolume.fsGroup
kiblik Dec 3, 2025
c30909b
chore(deps): update actions/checkout action from v6.0.0 to v6.0.1 (.g…
renovate[bot] Dec 3, 2025
52d0a30
[docs] "about us" section maintenance (#13783)
paulOsinski Dec 4, 2025
eb9c690
:tada: Add 'fix_available' field to legitify (#13791)
manuel-sommer Dec 5, 2025
ec1842b
:lipstick: restructure whispers reports (#13790)
manuel-sommer Dec 5, 2025
32e4e0f
fix(parsers): DeprecationWarning: Testing an element's truth ...
kiblik Dec 5, 2025
1d4df38
fix(node_modules): Avoid staticfiles.W004
kiblik Dec 5, 2025
01afaf5
fix(unittest): avoid ResourceWarning: unclosed file
kiblik Dec 5, 2025
38950fe
:arrow_up: Bump ruff from 0.14.6 to 0.14.8 (#13799)
manuel-sommer Dec 5, 2025
edbc453
chore(deps): update actions/stale action from v10.1.0 to v10.1.1 (.gi…
renovate[bot] Dec 5, 2025
67e40d1
chore(deps): update dependency prettier from 3.7.3 to v3.7.4 (docs/pa…
renovate[bot] Dec 5, 2025
d1eed3c
chore(deps): update actions/setup-node action from v6.0.0 to v6.1.0 (…
renovate[bot] Dec 5, 2025
5455c4a
chore(deps): bump psycopg[c] from 3.3.0 to 3.3.1 (#13812)
dependabot[bot] Dec 5, 2025
e1af6ec
chore(deps): update dependency vcrpy from 7.0.0 to v8 (requirements-d…
renovate[bot] Dec 5, 2025
ed9a56a
chore(deps): update postgres:18.1-alpine docker digest from 18.1 to 1…
renovate[bot] Dec 5, 2025
755e91e
fix(GHA): Correction of #13722
kiblik Dec 5, 2025
98e8b6e
chore(deps): bump django from 5.1.14 to 5.1.15 (#13814)
dependabot[bot] Dec 6, 2025
3323973
chore(deps): update peter-evans/create-pull-request action from v7.0.…
renovate[bot] Dec 6, 2025
3a5f124
chore(deps): update valkey/valkey:7.2.11-alpine docker digest from 7.…
renovate[bot] Dec 6, 2025
3a4a6fd
chore(deps): bump django-polymorphic from 4.1.0 to 4.2.0 (#13824)
dependabot[bot] Dec 6, 2025
e7ebeef
chore(deps): bump urllib3 from 2.5.0 to 2.6.0 (#13834)
dependabot[bot] Dec 8, 2025
4b6ff8b
Merge pull request #13813 from kiblik/helm_drop_djnago.mediaPersisten…
rossops Dec 8, 2025
4799f38
Merge pull request #13828 from kiblik/xml_DeprecationWarning
rossops Dec 8, 2025
1ab501e
Merge pull request #13829 from kiblik/fix_staticfiles.W004
rossops Dec 8, 2025
176d5e8
Merge pull request #13830 from kiblik/ResourceWarning_unclosed_file
rossops Dec 8, 2025
032f22f
Merge pull request #13833 from kiblik/helm_fix_13722
rossops Dec 8, 2025
fa0df51
finding list: disable audowith to ix too wide column (#13835)
valentijnscholten Dec 8, 2025
b8f5e53
:bug: Remove unselected parsers from filters and test types (#13767)
manuel-sommer Dec 8, 2025
f01d0c2
perf: Use lazy loading for Product_Tab to improve edit finding perfor…
Vincent-Ngobeh Dec 8, 2025
256ca26
fix: Add null check for engagement in permission validation for Risk …
Maffooch Dec 8, 2025
87ff93a
Update versions in application files
Dec 8, 2025
6618b2b
docs: Add Pro vs OSS comparison for cross-product risk acceptances (#…
skywalke34 Dec 8, 2025
93f0f4d
Merge pull request #13843 from DefectDojo/release/2.53.1
rossops Dec 8, 2025
b1eb46f
Update versions in application files
Dec 8, 2025
a9479b2
Merge branch 'dev' into master-into-dev/2.53.1-2.54.0-dev
rossops Dec 8, 2025
471f9c0
Merge pull request #13846 from DefectDojo/master-into-dev/2.53.1-2.54…
rossops Dec 8, 2025
31fa8d7
chore(deps): bump psycopg[c] from 3.3.1 to 3.3.2 (#13839)
dependabot[bot] Dec 9, 2025
c59ec25
chore(deps): update dependency vite from 7.2.6 to v7.2.7 (docs/packag…
renovate[bot] Dec 9, 2025
0ace59c
chore(deps): update dependency renovatebot/renovate from 42.27.0 to v…
renovate[bot] Dec 9, 2025
e54840e
Move Risk Acceptance from Engagement to Product level
kiblik Nov 21, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
3 changes: 3 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
.git
.gitignore
*.md
72 changes: 72 additions & 0 deletions .dryrunsecurity.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
---
sensitiveCodepaths:
- 'dojo/object/urls.py'
- 'dojo/object/views.py'
- 'dojo/announcement/*.py'
- 'dojo/api_v2/*.py'
- 'dojo/api_v2/**/*.py'
- 'dojo/authorization/*.py'
- 'dojo/db_migrations/*.py'
- 'dojo/endpoint/*.py'
- 'dojo/engagement/*.py'
- 'dojo/finding/*.py'
- 'dojo/finding_group/*.py'
- 'dojo/group/*.py'
- 'dojo/importers/*.py'
- 'dojo/importers/**/*.py'
- 'dojo/jira_link/*.py'
- 'dojo/metrics/*.py'
- 'dojo/note_type/*.py'
- 'dojo/notes/*.py'
- 'dojo/product/*.py'
- 'dojo/product_type/*.py'
- 'dojo/reports/*.py'
- 'dojo/risk_acceptance/*.py'
- 'dojo/search/*.py'
- 'dojo/templates/*.html'
- 'dojo/templates/**/*.html'
- 'dojo/templatetags/*.py'
- 'dojo/test/*.py'
- 'dojo/tool_config/*.py'
- 'dojo/tool_product/*.py'
- 'dojo/tool_type/*.py'
- 'dojo/user/*.py'
- 'dojo/apps.py'
- 'dojo/celery.py'
- 'dojo/context_processors.py'
- 'dojo/decorators.py'
- 'dojo/filters.py'
- 'dojo/forms.py'
- 'dojo/middleware.py'
- 'dojo/models.py'
- 'dojo/okta.py'
- 'dojo/pipeline.py'
- 'dojo/remote_user.py'
- 'dojo/tasks.py'
- 'dojo/urls.py'
- 'dojo/utils.py'
- 'dojo/views.py'
- 'dojo/wsgi.py'
- 'docker/environments/*.env'
- 'docker/extra_settings'
- 'docker/entrypoint-celery-beat.sh'
- 'docker/entrypoint-celery-worker.sh'
- 'docker/entrypoint-initializer.sh'
- 'docker/entrypoint-first-boot.sh'
- 'docker/entrypoint-nginx.sh'
- 'docker/entrypoint-uwsgi.sh'
- 'docker/wait-for-it.sh'
allowedAuthors:
usernames:
- mtesauro
- devGregA
- cneill
- Maffooch
- blakeaowens
- kiblik
- dsever
- dogboat
- hblankenship
- valentijnscholten
notificationList:
- '@mtesauro'
19 changes: 19 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Any kind of package updates only need 2 approvals,
# So let's add three folks here
requirements.txt @cneill @mtesauro @Maffooch
# Any dockerfile or compose changes will need to be viewed by
# these people
Dockerfile.* @mtesauro @Maffooch
docker-compose.* @mtesauro @Maffooch
/docker/ @mtesauro @Maffooch
# Documentation changes
/docs/content/ @paulOsinski @valentijnscholten @Maffooch
# Kubernetes should be reviewed by reviewed first by those that know it
/helm/ @cneill @kiblik @Maffooch
# Anything UI related needs to be checked out by those with the eye for it
/dojo/static/ @blakeaowens @Maffooch
/dojo/templates/ @blakeaowens @Maffooch
# Any model changes should be closely looked at
/dojo/models.py @Maffooch
# All other code changes should be reviewed by someone
* @Maffooch @mtesauro
49 changes: 49 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: Bug report
about: Create a report to help us improve
title: ''
labels: bug
assignees: ''

---
**Slack us first!**
The easiest and fastest way to help you is via Slack. There's a free and easy signup to join our #defectdojo channel in the OWASP Slack workspace: [Get Access.](https://owasp.org/slack/invite)
If you're confident you've found a bug, or are allergic to Slack, you can submit an issue anyway.

**Be informative**
Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev version and try again.

**Bug description**
A clear and concise description of what the bug is. For errors include at least the exact error message you are seeing (including traceback).

**Steps to reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Deployment method** *(select with an `X`)*
- [ ] Docker Compose
- [ ] Kubernetes
- [ ] GoDojo

**Environment information**
- Operating System: [e.g. Ubuntu 18.04]
- Docker Compose or Helm version (Output of `docker compose version` or `helm version`)
- DefectDojo version (see footer) or commit message: [use `git show -s --format="[%ci] %h: %s [%d]"`]

**Logs**
Use `docker compose logs` (or similar, depending on your deployment method) to get the logs and add the relevant sections here showing the error occurring (if applicable).

**Sample scan files**
If applicable, add sample scan files to help reproduce your problem.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Additional context** (optional)
Add any other context about the problem here.
26 changes: 26 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
name: Feature request
about: Suggest an idea for DefectDojo
title: ''
labels: enhancement
assignees: ''

---
## :warning: Note on feature completeness :warning:

We are narrowing the scope of acceptable enhancements to DefectDojo. Learn more here:
https://github.com/DefectDojo/django-DefectDojo/blob/master/readme-docs/CONTRIBUTING.md

**Is your feature request related to a problem? Please describe**
A clear and concise description of what the problem is.
Ex: I'm always frustrated when [...]

**Describe the solution you'd like**
A clear and concise description of what you want to happen.
Ex: As a < role >, I want < some goal > so that < some reason >.

**Describe alternatives you've considered**
A clear and concise description of any alternative solutions or features you have considered.

**Additional context**
Add any other context, screenshots, sketch, code snippet, etc. about the feature request here.
14 changes: 14 additions & 0 deletions .github/ISSUE_TEMPLATE/importer_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
name: New importer request
about: Request a new importer (scanner) for DefectDojo
title: ''
labels: Import Scans
assignees: ''

---

**Scanner Name**
Name of the scanner, brief description of the scanner and link.

**Sample File**
Please attach a sample file and the format of the file (xml, json, csv).
16 changes: 16 additions & 0 deletions .github/ISSUE_TEMPLATE/security_issue.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
name: Security issue
about: Report a security issue
title: Please submit via our security reporting program, not GitHub
labels: security
assignees: ''

---

**DefectDojo security reporting program**

If you believe you have found a **security issue** in DefectDojo, please review the [disclosure policy](../../readme-docs/SECURITY.md) and submit your finding via our security reporting program.

Please, do not submit **security issues** via GitHub directly.

Thank you for helping keep DefectDojo and our users safe!
49 changes: 49 additions & 0 deletions .github/ISSUE_TEMPLATE/support_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: Support Request
about: If you need support or are running into some trouble
title: ''
labels: support
assignees: ''

---
**Slack us first!**
The easiest and fastest way to help you is via Slack. There's a free and easy signup to join our #defectdojo channel in the OWASP Slack workspace: [Get Access.](https://owasp.org/slack/invite)
If you're confident you've found a bug, or are allergic to Slack, you can submit an issue anyway.

**Be informative**
Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev branch and try again.

**Problem description**
A clear and concise description of what the problem is. For errors include at least the exact error message you are seeing (including traceback).

**Steps to reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Deployment method** *(select with an `X`)*
- [ ] Docker Compose
- [ ] Kubernetes
- [ ] GoDojo

**Environment information**
- Operating System: [e.g. Ubuntu 18.04]
- Docker Compose or Helm version (Output of `docker compose version` or `helm version`)
- DefectDojo version (see footer) or commit message: [use `git show -s --format="[%ci] %h: %s [%d]"`]

**Logs**
Use `docker compose logs` (or similar, depending on your deployment method) to get the logs and add the relevant sections here showing the error occurring (if applicable).

**Sample scan files**
If applicable, add sample scan files to help reproduce your problem.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Additional context** (optional)
Add any other context about the problem here.
73 changes: 73 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
version: 2
updates:
- package-ecosystem: pip
directory: "/"
schedule:
interval: daily
open-pull-requests-limit: 10
target-branch: dev
ignore:
- dependency-name: whitenoise
versions:
- ">= 5.a"
- "< 6"
- dependency-name: boto3
update-types: ["version-update:semver-minor"]
- package-ecosystem: npm
directory: "/components"
schedule:
interval: daily
open-pull-requests-limit: 10
target-branch: dev
ignore:
- dependency-name: bootstrap
versions:
- ">= 4.a"
- "< 5"
- dependency-name: bootstrap-social
versions:
- ">= 5.a"
- "< 6"
- dependency-name: bootswatch
versions:
- ">= 4.a"
- "< 5"
- dependency-name: chosen
versions:
- ">= 1.a"
- "< 2"
- dependency-name: drmonty-datatables-responsive
versions:
- ">= 2.a"
- "< 3"
- dependency-name: flot
versions:
- ">= 2.a"
- "< 3"
- dependency-name: flot
versions:
- ">= 3.a"
- "< 4"
- dependency-name: flot
versions:
- ">= 4.a"
- "< 5"
- dependency-name: fullcalendar
versions:
- ">= 5.a"
- "< 6"
- dependency-name: startbootstrap-sb-admin-2
versions:
- ">= 3.a"
- "< 4"
- dependency-name: startbootstrap-sb-admin-2
versions:
- ">= 4.a"
- "< 5"
- package-ecosystem: docker
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 10
target-branch: dev

67 changes: 67 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
docs:
- changed-files:
- any-glob-to-any-file:
- docs/**/*
- readme-docs/**/*

docker:
- changed-files:
- any-glob-to-any-file:
- docker/**/*
- docker**
- Docker*

helm:
- changed-files:
- any-glob-to-any-file:
- helm/defectdojo/*
- helm/defectdojo/**/*

"New Migration":
- changed-files:
- any-glob-to-any-file:
- dojo/db_migrations/*

unittests:
- changed-files:
- any-glob-to-any-file:
- unittests/**/*

integration_tests:
- changed-files:
- any-glob-to-any-file:
- tests/**/*

settings_changes:
- changed-files:
- any-glob-to-any-file:
- dojo/settings/settings.dist.py

apiv2:
- changed-files:
- any-glob-to-any-file:
- dojo/api_v2/**/*

ui:
- changed-files:
- any-glob-to-any-file:
- dojo/static/**/*
- dojo/templates/**/*
- dojo/templatetags/**/*

parser:
- changed-files:
- any-glob-to-any-file:
- dojo/tools/**/*

localization:
- changed-files:
- any-glob-to-any-file:
- dojo/locale/*
- dojo/locale/**/*

lint:
- changed-files:
- any-glob-to-any-file:
- ruff.toml
Loading