Skip to content

Conversation

@kiblik
Copy link
Contributor

@kiblik kiblik commented Oct 14, 2025

TBD

renovate bot and others added 30 commits September 5, 2025 09:12
…github/workflows/release-3-master-into-dev.yml) (DefectDojo#13112)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* add about_deduplication png

* update changelog 2.50

* update changelog 2.50

---------

Co-authored-by: Paul Osinski <[email protected]>
* semgrep pro: parse sast finding

* update docs
* 🐛 Implement Wazuh v4.8

* update unittests

* update

* fix

* fix

* fix

* update unittests

* update

* fix unittest

* review
* **Summary:**

- Add extraInitContainers to celery+django deployments.
- Add extraEnv to all deployments
- Remove existing volume logic in favor of agnostic extraVolumes and extraVolumeMounts
- Fix optional secret mounts + reference
- Update bitnami chart reference (OCI)
- Bump up redis chart

* chore: add livenessProbe entries for celery

* fix: reference to removed field

* fix: conflict

* chore: add reference to upstream chart

* fix: missing default values from upstream chart used in templates

* chore: rephrase

* feat: allow deploy secret as regular non-hooked resources

* fix: review

* chore: restore Chart.lock

* chore: update chart.lock

* chore: wrap services url

* fix: PR review suggestions

* chore: mount extraVolumes in initContainers too

* chore: move external db values to separate fields, add release notes

* Update docs/content/en/open_source/upgrading/2.50.md

Co-authored-by: kiblik <[email protected]>

* chore: bump chart version and remove bitnami dependency comment from RN

* chore: move release notes to 2.51

* chore: restore 2.50.md

---------

Co-authored-by: kiblik <[email protected]>
* Ruff: Add PLW

* update
* 🐛 Fix finding_group view

* ruff

* finding group view: add basic UI tests

---------

Co-authored-by: Valentijn Scholten <[email protected]>
Release: Merge release into master from: release/2.50.1
….50.1-2.51.0-dev

Release: Merge back 2.50.1 into dev from: master-into-dev/2.50.1-2.51.0-dev
…x/2.50.1-2.51.0-dev

Release: Merge back 2.50.1 into bugfix from: master-into-bugfix/2.50.1-2.51.0-dev
Bumps [psycopg[c]](https://github.com/psycopg/psycopg) from 3.2.9 to 3.2.10.
- [Changelog](https://github.com/psycopg/psycopg/blob/master/docs/news.rst)
- [Commits](psycopg/psycopg@3.2.9...3.2.10)

---
updated-dependencies:
- dependency-name: psycopg[c]
  dependency-version: 3.2.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.40.24 to 1.40.25.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.40.24...1.40.25)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.40.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…/release-x-manual-helm-chart.yml) (DefectDojo#13131)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…ctDojo#13130)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
… v2.3.3 (.github/workflows/release-x-manual-helm-chart.yml) (DefectDojo#13128)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
)

Bumps [datatables.net](https://github.com/DataTables/Dist-DataTables) from 2.3.3 to 2.3.4.
- [Release notes](https://github.com/DataTables/Dist-DataTables/releases)
- [Commits](DataTables/Dist-DataTables@2.3.3...2.3.4)

---
updated-dependencies:
- dependency-name: datatables.net
  dependency-version: 2.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ocker-compose.yml) (DefectDojo#13141)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.1.3 to 7.1.5.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v7.1.5/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 7.1.5
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…fectDojo#13144)

Bumps [datatables.net-buttons-bs](https://github.com/DataTables/Dist-DataTables-Buttons-Bootstrap) from 3.2.4 to 3.2.5.
- [Release notes](https://github.com/DataTables/Dist-DataTables-Buttons-Bootstrap/releases)
- [Commits](DataTables/Dist-DataTables-Buttons-Bootstrap@3.2.4...3.2.5)

---
updated-dependencies:
- dependency-name: datatables.net-buttons-bs
  dependency-version: 3.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@github-actions github-actions bot added docker New Migration Adding a new migration file. Take care when merging. settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 docs unittests integration_tests ui parser helm conflicts-detected labels Oct 14, 2025
@github-actions
Copy link
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

@valentijnscholten
Copy link
Member

Could you consider rebasing instead of merging?

It looks like it would be a clean rebase:

valentijn@PF5B0KN2:~/dd.old$ git rebase upstream/master
warning: skipped previously applied commit 67de2951dc
warning: skipped previously applied commit 821771bc92
warning: skipped previously applied commit 7f726a87ca
warning: skipped previously applied commit 96dc379e9e
....
warning: skipped previously applied commit 309fea0ef3
warning: skipped previously applied commit 64aebced0c
warning: skipped previously applied commit e67f5b5179
hint: use --reapply-cherry-picks to include skipped commits
hint: Disable this message with "git config advice.skippedCherryPicks false"
Successfully rebased and updated detached HEAD.
valentijn@PF5B0KN2:~/dd.old$ cd helm/
valentijn@PF5B0KN2:~/dd.old/helm$ ls -l
total 4
drwxrwxrwx 4 valentijn valentijn 4096 Oct 15 17:22 defectdojo
valentijn@PF5B0KN2:~/dd.old/helm$ cd defectdojo/
valentijn@PF5B0KN2:~/dd.old/helm/defectdojo$ ls -l
total 124
-rw-r--r-- 1 valentijn valentijn   365 Oct 15 17:22 Chart.lock
-rw-r--r-- 1 valentijn valentijn  1360 Oct 15 17:22 Chart.yaml
-rw-r--r-- 1 valentijn valentijn 30717 Oct 15 17:22 README.md
-rw-r--r-- 1 valentijn valentijn 18339 Oct 15 17:22 README.md.gotmpl
drwxrwxrwx 2 valentijn valentijn  4096 Dec 19  2022 charts
drwxrwxrwx 3 valentijn valentijn  4096 Oct 15 17:22 templates
-rw-r--r-- 1 valentijn valentijn 36197 Oct 15 17:22 values.schema.json
-rw-r--r-- 1 valentijn valentijn 17740 Oct 15 17:22 values.yaml
valentijn@PF5B0KN2:~/dd.old/helm/defectdojo$ less Chart.yaml
valentijn@PF5B0KN2:~/dd.old/helm/defectdojo$

Chart.yaml

apiVersion: v2
appVersion: "2.51.1"
description: A Helm chart for Kubernetes to install DefectDojo
name: defectdojo
version: 1.7.1
icon: https://defectdojo.com/hubfs/DefectDojo_favicon.png
maintainers:
  - name: madchap
    email: [email protected]
    url: https://github.com/DefectDojo/django-DefectDojo
dependencies:
  - name: postgresql
    version: ~16.7.0
    repository: "oci://us-docker.pkg.dev/os-public-container-registry/defectdojo"
    condition: postgresql.enabled
  - name: redis
    version: ~19.6.4
    repository: "oci://us-docker.pkg.dev/os-public-container-registry/defectdojo"
    condition: redis.enabled
annotations:
  # For correct syntax, check https://artifacthub.io/docs/topics/annotations/helm/
  # This is example for "artifacthub.io/changes"
  # artifacthub.io/changes: |
  #   - kind: added
  #     description: Cool feature
  #   - kind: fixed
  #     description: Minor bug
  #   - kind: changed
  #     description: Broken feature
  #   - kind: removed
  #     description: Old bug
  #   - kind: deprecated
  #     description: Not-needed feature
  #   - kind: security
  #     description: Critical bug
  artifacthub.io/prerelease: "false"
  artifacthub.io/changes: |
    - kind: added
      description: Add support for automountServiceAccountToken
    - kind: changed
      description: Bump DefectDojo to 2.51.1

git log

commit 76d65f80dc5d87eb107c50c38070c12116eb8161 (HEAD)
Author: DefectDojo release bot <[email protected]>
Date:   Wed Oct 15 05:11:00 2025 +0000

    Update index.yaml - nightly-dev

commit 05cf4363cbb1834a74877c9ce0e7132f8b4ce5d5
Author: DefectDojo release bot <[email protected]>
Date:   Tue Oct 14 16:23:58 2025 +0000

    Update index.yaml - 2.51.1

commit b2eadc38b51a84557a3f8b7efeff07e5b0e225e5
Author: DefectDojo release bot <[email protected]>
Date:   Tue Oct 14 06:14:44 2025 +0000

    Update index.yaml

commit 5d1329579c5937f7563cd426e1c06e8c7d60fdc6
Author: DefectDojo release bot <[email protected]>
Date:   Tue Oct 14 06:00:33 2025 +0000

    Update index.yaml

commit 958cdfb21277f31324a889433ae5cfebcab8143b
Author: DefectDojo release bot <[email protected]>
Date:   Tue Oct 14 05:53:39 2025 +0000

    Update index.yaml

commit a6ffd58e797dbbea3a4437f11d85fc11cd1c52e6
Author: DefectDojo release bot <[email protected]>
Date:   Tue Oct 14 05:46:17 2025 +0000

    Update index.yaml

commit 6100be8d73136d483e9889b424220b5ef61d3842
Author: DefectDojo release bot <[email protected]>
Date:   Tue Oct 14 05:38:58 2025 +0000

    Update index.yaml

I do think someone with write access would have to do the rebase and push to the helm-charts branch.

Copy link
Contributor

@Maffooch Maffooch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Happy to help here with write access if needed. Not really sure what to do on this one though

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

apiv2 conflicts-detected docker docs helm integration_tests New Migration Adding a new migration file. Take care when merging. parser settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui unittests