Releases: DefectDojo/django-DefectDojo
Release list
3.2.0 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.0
- fix(dedupe): repair four split deduplication registrations @devGregA (#15479)
- fix(govulncheck): sort symbol/location sets so hash_code is stable @devGregA (#15483)
- docs(agents): milestone every new PR at creation, from milestones that already exist @Maffooch (#15485)
- docs(navigation): document the reorganized Pro Settings menu and the All Settings page @devGregA (#15478)
- fix(awssecurityhub): sort resource IDs so hash_code is stable @devGregA (#15481)
- docs(rules-engine): document Rules Engine 2.0 @blakeaowens (#15484)
- docs(notes): document markdown, editing and history in notes @blakeaowens (#15477)
- docs(pro): several optional features are now always on, and one is support-enabled @devGregA (#15480)
- docs(triage): document reachability scoring @devGregA (#15476)
- feat(parsers): add composer audit, pnpm audit, dotnet vulnerable packages and mix_audit parsers @devGregA (#15475)
- docs(compliance): document the CMMC partial-credit column @devGregA (#15474)
- docs(onprem): add hardware sizing guidance for self-hosted Pro @rossops (#15459)
- Harden authorization on the make-finding-a-template action @svader0 (#15463)
- Harden authorization on finding-template apply/read views @svader0 (#15471)
- Harden source-code link construction in create_bleached_link @svader0 (#15470)
- feat(parsers): add 30 command-line security tool parsers (SAST, IaC, host hardening, web/network discovery, malware) @devGregA (#15465)
- docs(onprem): publish the Helm install and upgrade guides @devGregA (#15466)
- docs(onprem): add the Docker Compose installation guide @devGregA (#15469)
- docs(onprem): document what to back up in a self-hosted deployment @devGregA (#15461)
- docs(onprem): make the self-hosting page a real landing page @devGregA (#15464)
- docs: correct the Threat Intelligence floor to describe Priority, not just the Risk band @devGregA (#15462)
- docs(onprem): add guidance for expanding upload storage on Compose @devGregA (#15458)
- docs(onprem): document the upload size limits for large scan files @devGregA (#15456)
- docs(onprem): add air-gapped install guide for self-hosted Pro @devGregA (#15455)
- docs(onprem): add OpenShift deployment guide for self-hosted Pro @devGregA (#15457)
- docs: peer review claiming, per-person assignment and the My Work queue @devGregA (#15395)
- docs(pro): FIPS 140-3 mode — enabling, verifying, and behaviour differences @devGregA (#15370)
- docs(compliance): Federal Compliance section (FedRAMP POA&M, ConMon, CMMC, control coverage) @devGregA (#15453)
- Harden user account management authorization @svader0 (#15454)
- Scope the report endpoint prefetch to the requesting user's findings @svader0 (#15435)
- feat(parsers): SPDX, CSAF 2.0 and OpenVEX interchange-format parsers @devGregA (#15414)
- docs(pro): document Diagnostics, Authorization Connectors, and menu badges @Maffooch (#15433)
- fix(generic parser): ignore non-numeric values in numeric JSON fields @Maffooch (#15442)
- Scope endpoint and host view findings to the requesting user @svader0 (#15441)
- Scope API scan configuration tool selection to authorized tool configurations @svader0 (#15445)
- fix(importers): keep the reimport target test when a report declares no tests @Maffooch (#15446)
- fix(search): render result panes, open the right tab, survive bad input @Maffooch (#15448)
- Align id-keyed questionnaire routes with engagement permissions @svader0 (#15449)
- docs: Threat Intelligence page (DefectDojo Pro) @devGregA (#15450)
- Scope the product endpoint report to the requested product @svader0 (#15451)
- docs(onprem): document migrating from open source to self-hosted Pro @devGregA (#15452)
- fix(dedupe): stable original across scan orders via content-ordered finding creation @Maffooch (#15222)
- fix(importers): skip child rows buffered for a finding deleted mid-batch @Maffooch (#15428)
- fix(finding): clear M2M through rows inside each chunk's delete transaction @Maffooch (#15434)
- fix: support new Popeye report sections format @kocaemre (#15432)
- fix: replace bare except with specific exception types @lxcxjxhx (#15430)
- 🎉 add bell security advisory @manuel-sommer (#15429)
- fix(importers): stop the write-back re-creating a deleted import target @Maffooch (#15427)
- perf(migration): drop O(n^2) inheritance query from endpoint-to-locations migration, make re-runs converge @Maffooch (#15425)
- feat(vuln-id): per-vulnerability KEV/EPSS enrichment columns on the Vulnerability entity @Maffooch (#15426)
- chore(deps): update gcr.io/cloudsql-docker/gce-proxy docker tag from 1.38.1 to v1.38.2 (helm/defectdojo/values.yaml) @renovate (#15393)
- Add pro audit logs documentation @dangoelz (#15419)
- feat(vuln-id): normalize Vulnerability_Id into a Vulnerability entity + ordered references (entity-only cutover) @Maffooch (#15331)
- chore(deps): update dependency renovatebot/renovate from 43.263.3 to v43.288.0 (.github/workflows/renovate.yaml) @renovate (#15279)
- chore(deps): update actions/setup-python action from v6.3.0 to v7 (.github/workflows/test-helm-chart.yml) @renovate (#15335)
- chore(deps): update losisin/helm-values-schema-json-action digest from v3.1.0 to v3 (.github/workflows/test-helm-chart.yml) @renovate (#15389)
- chore(deps): update dependency kubernetes from 1.34.9 to v1.34.10 (.github/workflows/k8s-tests.yml) - autoclosed @renovate (#15390)
- chore(deps): update release-drafter/release-drafter action from v7.6.0 to v7.7.0 (.github/workflows/release-drafter.yml) @renovate (#15417)
- chore(deps): update actions/stale action from v10.4.0 to v11 (.github/workflows/close-stale.yml) @renovate (#15418)
- docs: add Pro changelog entries for 3.1.301 and 3.1.302 @Maffooch (#15423)
- fix(findings): clear review state when a finding is closed or reopened @devGregA (#15394)
- add additional scanner protocols to whitelist @paulOsinski (#15416)
- chore(deps): bump python-gitlab from 8.4.0 to 8.5.0 @dependabot (#15401)
- chore(deps): update valkey docker tag from 0.24.4 to v0.24.6 (helm/defectdojo/chart.yaml) @renovate (#15396)
- update fortify parsers to parse cwe @paulOsinski (#15409)
- ci: make ruff a hard gate for the unit-tests workflow chain @Maffooch (#15410)
- fix(reimport): skip close-old candidates whose finding row was deleted mid-reimport @Maffooch (#15408)
- fix(jfrog): stable reimport identity for JFrog Xray API Summary Artifact Scan @devGregA (#15412)
- fix(jira): stop assuming push_to_jira returns a tuple @Maffooch (#15411)
- fix(api): return 409 instead of 500 on a unique-constraint violation @Maffooch (#15407)
- chore(deps): update dependency kubernetes/kubernetes from v1.35.6 to v1.35.7 (.github/workflows/k8s-tests.yml) @renovate (#15392)
- Apply login rate limiter to the API token auth endpoint @svader0 (#15415)
- chore(deps): update docker/login-action action from v4.4.0 to v4.6.0 (.github/workflows/release-x-manual-tag-as-latest.yml) @renovate (#15397)
- chore(deps): bump ruff from 0.15.22 to 0.16.0 @dependabot (#15399)
- chore(deps): bump vulners from 3.2.0 to 4.0.0 @dependabot (#15400)
- chore(deps): bump gitpython from 3.1.54 to 3.1.57 @dependabot (#15403)
- chore(deps): update mccutchen/go-httpbin docker tag from 2.24.0 to v2.25.0 (docker-compose.override.integration_tests.yml) @renovate (#15406)
- fix: add missing return after exception in GitHub issue handlers @lxcxjxhx (#15391)
- maintenance: add a branch guard for the bugfix/dev/master release lines @Maffooch (#15388)
- Seed the search language facet from the authorized queryset @svader0 (#15387)
- refactor(reimport): extract get_original_findings as an override point; guard debug renders @devGregA (#15398)
- docs(connectors): Intigriti connector reference @devGregA (#15286)
- docs(connectors): HCL AppScan connector reference @devGregA (#15312)
- docs(connectors): document the YesWeHack connector @devGregA (#15288)
- docs: Checkmarx One connector — branch handling + Track Scanned Branches @devGregA (#15358)
- docs(connectors): Harbor setup @devGregA (#15272)
- docs(connectors): MobSF connector reference @devGregA (#15330)
- docs(connectors): Lacework / FortiCNAPP connector reference @devGregA (#15339)
- docs(connectors): Socket.dev connector reference @devGregA (#15340)
- docs(connectors): Bright Security connector reference @devGregA (#15341)
- docs(connectors): Fortify connector reference @devGregA (#15329)
- docs(connectors): Escape connector reference @devGregA (#15342)
- docs(connectors): Deepfence ThreatMapper connector reference @devGregA (#15337)
- docs(integrations): Opsgenie integrator reference @devGregA (#15277)
- docs(integrations): add ServiceNow SecOps / Vulnerability Response integrator @devGregA (#15278)
- docs(connectors): Fairwinds Insights connector reference @devGregA (#15343)
- fix(dedupe): re-point chained duplicates before deleting excess ones (backport of #15364) @Maffooch (#15383)
- fix(risk_acceptance): stop the expiration job aborting on an unattached risk acceptance @Maffooch (#15376)
- fix(finding): carry locations across a finding merge @Maffooch (#15379)
- Harden metadata API object authorization @svader0 (#15380)
- docs(jira): document enabling the Jira integration in System Settings @Maffooch (#15381)
- docs(sso): document the attribute-mapping editors and OIDC group mapping @Maffooch (#15373)
- [docs] maintenance @paulOsinski (#15371)
- docs: Global Locations deduplication (Pro) + comparison with Global Component @Maffooch (#15348)
- deprecate: API-based pull parsers, Tool Type/Configuration, and dbbackup (3.2.0 → 3.5.0 EOL) @Maffooch (#15353)
- Apply the member-management check on ev...
3.1.305 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.303
- docs(compliance): Federal Compliance section (FedRAMP POA&M, ConMon, CMMC, control coverage) @devGregA (#15453)
- Harden user account management authorization @svader0 (#15454)
- Scope the report endpoint prefetch to the requesting user's findings @svader0 (#15435)
- Scope endpoint and host view findings to the requesting user @svader0 (#15441)
- Scope API scan configuration tool selection to authorized tool configurations @svader0 (#15445)
- Align id-keyed questionnaire routes with engagement permissions @svader0 (#15449)
- docs: Threat Intelligence page (DefectDojo Pro) @devGregA (#15450)
- Scope the product endpoint report to the requested product @svader0 (#15451)
- docs(onprem): document migrating from open source to self-hosted Pro @devGregA (#15452)
🐛 Bug Fixes
- fix(generic parser): ignore non-numeric values in numeric JSON fields @Maffooch (#15442)
- fix(importers): keep the reimport target test when a report declares no tests @Maffooch (#15446)
🖌 Updates in UI
3.1.303 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.302
- fix: support new Popeye report sections format @kocaemre (#15432)
- perf(migration): drop O(n^2) inheritance query from endpoint-to-locations migration, make re-runs converge @Maffooch (#15425)
- Add pro audit logs documentation @dangoelz (#15419)
- docs: add Pro changelog entries for 3.1.301 and 3.1.302 @Maffooch (#15423)
🚩 Changes to settings.dist.py / local_settings.py
- 🎉 add bell security advisory @manuel-sommer (#15429)
🐛 Bug Fixes
3.1.302 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.301
- fix(findings): clear review state when a finding is closed or reopened @devGregA (#15394)
- add additional scanner protocols to whitelist @paulOsinski (#15416)
- update fortify parsers to parse cwe @paulOsinski (#15409)
- ci: make ruff a hard gate for the unit-tests workflow chain @Maffooch (#15410)
- Apply login rate limiter to the API token auth endpoint @svader0 (#15415)
- fix: add missing return after exception in GitHub issue handlers @lxcxjxhx (#15391)
- Seed the search language facet from the authorized queryset @svader0 (#15387)
- refactor(reimport): extract get_original_findings as an override point; guard debug renders @devGregA (#15398)
- docs(connectors): Intigriti connector reference @devGregA (#15286)
- docs(connectors): HCL AppScan connector reference @devGregA (#15312)
- docs(connectors): document the YesWeHack connector @devGregA (#15288)
- docs: Checkmarx One connector — branch handling + Track Scanned Branches @devGregA (#15358)
- docs(connectors): Harbor setup @devGregA (#15272)
- docs(connectors): MobSF connector reference @devGregA (#15330)
- docs(connectors): Lacework / FortiCNAPP connector reference @devGregA (#15339)
- docs(connectors): Socket.dev connector reference @devGregA (#15340)
- docs(connectors): Bright Security connector reference @devGregA (#15341)
- docs(connectors): Fortify connector reference @devGregA (#15329)
- docs(connectors): Escape connector reference @devGregA (#15342)
- docs(connectors): Deepfence ThreatMapper connector reference @devGregA (#15337)
- docs(integrations): add ServiceNow SecOps / Vulnerability Response integrator @devGregA (#15278)
- docs(connectors): Fairwinds Insights connector reference @devGregA (#15343)
🚩 Changes to settings.dist.py / local_settings.py
🚀 API features and enhancements
🐛 Bug Fixes
- fix(reimport): skip close-old candidates whose finding row was deleted mid-reimport @Maffooch (#15408)
- fix(jira): stop assuming push_to_jira returns a tuple @Maffooch (#15411)
- fix(api): return 409 instead of 500 on a unique-constraint violation @Maffooch (#15407)
🧰 Maintenance
3.1.301 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.300
- fix(dedupe): re-point chained duplicates before deleting excess ones (backport of #15364) @Maffooch (#15383)
- fix(finding): carry locations across a finding merge @Maffooch (#15379)
- Harden metadata API object authorization @svader0 (#15380)
- docs(jira): document enabling the Jira integration in System Settings @Maffooch (#15381)
- docs(sso): document the attribute-mapping editors and OIDC group mapping @Maffooch (#15373)
- [docs] maintenance @paulOsinski (#15371)
- Apply the member-management check on every serializer exposing the field @svader0 (#15375)
- docs: add Pro changelog entry for 3.1.300 @Maffooch (#15369)
- Restrict JIRA finding-mapping project field to authorized projects @svader0 (#15355)
- Docs: clarify that the Jira webhook secret authenticates incoming requests @svader0 (#15368)
- Restrict bulk update target finding group to authorized groups @svader0 (#15356)
🚀 API features and enhancements
🐛 Bug Fixes
- fix(risk_acceptance): stop the expiration job aborting on an unattached risk acceptance @Maffooch (#15376)
🖌 Updates in UI
🧰 Maintenance
- chore(deps): bump postcss from 8.5.15 to 8.5.23 in /docs @dependabot[bot] (#15352)
- chore(deps): bump gitpython from 3.1.52 to 3.1.54 @dependabot[bot] (#15351)
3.1.300 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.200
- docs(feature-flags): correct Organization / Asset relabeling controls @blakeaowens (#15360)
- docs: JFrog Xray connector — Artifact-Level Records mode + hierarchy behavior @devGregA (#15347)
- docs(rbac): document Custom RBAC Roles @blakeaowens (#15359)
- Extend user serializer validation to identity and permission fields @devGregA (#15191)
- docs(connectors): GitHub asset connector reference @devGregA (#15291)
- docs(connectors): NeuVector connector reference @devGregA (#15338)
- docs(sensei): document Bitbucket, Azure DevOps, and GitHub Enterprise connections @Maffooch (#15349)
- 🐛 fix kics severity mapping #15345 @manuel-sommer (#15350)
- docs(connectors): Black Duck connector reference @devGregA (#15269)
- perf(migration): batch endpoint tags and restore inheritance @AKSHATSPAR (#15311)
- add pro findings documentation @dangoelz (#15333)
- docs(connectors): Quay (Clair) connector reference @devGregA (#15284)
- Make notes read-only on the test create serializer @svader0 (#15334)
- create fortify parser V2 - prefer true line @paulOsinski (#15228)
- product type updates and tests @svader0 (#15307)
- fix(docker): install PostgreSQL 18 client so dbbackup works @valentijnscholten (#15306)
- docs(connectors): Acunetix 360 connector reference @devGregA (#15267)
- docs(connectors): Sysdig Secure connector reference @devGregA (#15271)
- docs(connectors): document Bugcrowd, ServiceNow CMDB, and Linear @Maffooch (#15336)
- docs(connectors): runZero asset connector reference @devGregA (#15287)
- docs(connectors): add Intruder connector reference @devGregA (#15285)
- docs(connectors): add Kubescape connector reference @devGregA (#15283)
- docs(connectors): Sonatype IQ setup @devGregA (#15268)
- Restrict configuration permission assignment to superusers in the user API @svader0 (#15296)
- docs(servicenow): refresh Pro ServiceNow Integrator guide (OAuth, close fields, push filters) @devGregA (#15298)
- docs: add Pro changelog entry for 3.1.200 @Maffooch (#15299)
- docs(sensei): Sensei documentation chapter (GitHub and GitLab) @Maffooch (#15308)
- july 17 docs maintenance @paulOsinski (#15276)
🚩 Database migration
🚀 API features and enhancements
- fix(api): don't scope serializer querysets by AnonymousUser during schema generation @Maffooch (#15344)
- Scope location and endpoint reference writes to authorized products @svader0 (#15300)
🖌 Updates in UI
- fix: render report summary charts after the table-of-contents rebuild @stevewallone (#15195)
- fix(ui): style OS promo banner dismiss button in classic UI @Maffooch (#15332)
🧰 Maintenance
- chore(deps): bump gitpython from 3.1.50 to 3.1.52 @dependabot[bot] (#15324)
- chore(deps): bump setuptools from 82.0.1 to 83.0.0 @dependabot[bot] (#15325)
3.1.200 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.101
- docs(features): document Feature Flags page and correct feature enablement @blakeaowens (#15289)
- docs(connectors): Endor Labs connector reference @devGregA (#15281)
- docs(connectors): add Cobalt.io and Nuclei tool references @devGregA (#15280)
- docs(connectors): Prowler connector reference @devGregA (#15282)
- docs(connectors): OpenVAS / Greenbone connector reference @devGregA (#15273)
- docs(connectors): Edgescan setup @devGregA (#15270)
- docs(connectors): Rapid7 InsightAppSec connector reference @devGregA (#15265)
- fix(generic parser): prevent nested list when cve and vulnerability_ids are both present @narvadanami (#15212)
- chore(ci): migrate release-drafter to
whenand build OAS from the release tag @Maffooch (#15264) - docs: add Pro changelog entry for 3.1.101 @Maffooch (#15263)
🚩 Changes to settings.dist.py / local_settings.py
3.1.101 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.100
- fix(shell): silence the shell model auto-import banner (docker + manual runs) @Maffooch (#15234)
- docs: add PagerDuty to the Pro Integrations tool reference @devGregA (#15210)
- fix(forms): avoid DB access at import time in Import/ReImport forms @Maffooch (#15233)
- docs: use "DefectDojo, Inc." consistently in company name references @devGregA (#15242)
- add OS Findings documentation @dangoelz (#15235)
- docs: redesign documentation site UI @devGregA (#15214)
- docs: add Zendesk to the Pro Integrations tool reference @devGregA (#15215)
- docs: add ServiceDesk Plus to the Pro Integrations tool reference @devGregA (#15217)
- docs: add Pro changelog entry for 3.1.100 @Maffooch (#15237)
🚩 Changes to settings.dist.py / local_settings.py
- feat(search): add DD_WATSON_SEARCH_ENABLED toggle to gate watson indexing @blakeaowens (#15236)
🧰 Maintenance
- chore(deps): bump django from 5.2.14 to 5.2.15 @dependabot[bot] (#15230)
3.1.100 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.1.0
- docs: Asset Connectors — concept + Azure DevOps / Bitbucket / GitLab / JSM Assets setup @devGregA (#15153)
- docs(jira): Jira integrator guide — custom fields, ticket templates, test render @Maffooch (#15226)
- docs(connectors): Microsoft Defender for Cloud connector reference @devGregA (#15197)
- docs(connectors): add GitHub Advanced Security, Qualys, Rapid7 InsightVM, Veracode references @devGregA (#15198)
- docs(connectors): Cloudflare, Contrast, GitGuardian, Google Cloud SCC, HackerOne, Shodan setup @devGregA (#15199)
- Docs: Docker Scout connector reference @devGregA (#15203)
- Group-IB ASM connector docs @Maffooch (#15208)
- docs: add Shortcut to the Pro Integrations tool reference @devGregA (#15209)
- docs: add upgrade guide for DefectDojo Pro on-premise (Helm) deployments @devGregA (#15189)
- docs: add Bitbucket to the Pro Integrations pages @devGregA (#15207)
- docs: add Freshservice Pro integration reference @devGregA (#15221)
- docs: add Backstage Pro connector reference @devGregA (#15223)
- Docs: Wazuh connector reference @devGregA (#15201)
- Docs: Censys connector reference @devGregA (#15202)
- docs(connectors): add CrowdStrike Falcon connector reference @Maffooch (#15206)
- Docs: Have I Been Pwned connector reference @devGregA (#15200)
- docs: Microsoft Defender connector setup guide @devGregA (#15156)
- docs: add copy-to-clipboard to Report Builder LLM prompt and API blocks @skywalke34 (#15216)
- docs: add Similar Findings pages for Open Source and Pro @Maffooch (#15190)
- fix(notifications): deliver @mention notifications and match full usernames @blakeaowens (#15196)
- fix(auditlog): make pghistory context JSON-safe before Celery dispatch @Maffooch (#15204)
- fix(risk_acceptance): reinstate findings when expiration date updated via API @Jino-T (#15147)
- refactor(locations): consistent object lookups in endpoint views @devGregA (#15173)
- Align questionnaire relink routes with questionnaire permissions @devGregA (#15192)
- Authorize the location foreign key on location reference writes @devGregA (#15193)
- Modify CODEOWNERS for code review assignments @Maffooch (#15205)
- fix(importers): stop doubling the (scan_type) suffix in dynamic Test Type names @Maffooch (#15149)
- fix(watson): only intermediate-flush the global search context singleton @valentijnscholten (#15187)
- fix(importers): dispatch post-processing with per-finding push_to_jira @valentijnscholten (#15186)
- perf(importers): fetch only needed columns in close_old_findings @valentijnscholten (#15185)
- Product updates and tests @dogboat (#15170)
- Expose effective dedupe matching policy on the Test API (2/3) @devGregA (#15151)
- fix(checkmarx_one): handle explicit null scanner sections in filtered reports @stevewallone (#15159)
- docs: add Pro changelog entries for 3.1.0 @Maffooch (#15166)
- docs: SSO user local-login fallback for open source @Maffooch (#15167)
🚩 Changes to settings.dist.py / local_settings.py
- feat(search): FTS + trigram GIN indexes for global search @blakeaowens (#15220)
🚩 Database migration
- Update migration dependency for global search FTS trigram indexes @Maffooch (#15227)
- feat(search): FTS + trigram GIN indexes for global search @blakeaowens (#15220)
- Jira: support fields on close/reopen transitions @devGregA (#15213)
🚀 API features and enhancements
🖌 Updates in UI
3.1.0 🌈
Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.0.0
- Bugfix: make jfrog xray impact paths deterministic @paulOsinski (#15094)
- fix: guard legacy endpoint access in Make Template / Merge Findings under V3_FEATURE_LOCATIONS @stevewallone (#15139)
- fix: relabel finding Asset-tag (AND) filter to v3 Asset vocabulary @stevewallone (#15136)
- chore: remove legacy Slack PR reminder bot workflow @Maffooch (#15109)
- Update sample data @github-actions (#15117)
- fix(mass_model_updater): read tracked fields via attribute access for skip_unchanged @valentijnscholten (#15114)
- docs: migrate OSS asset-modelling pages to v3 Asset/Organization terminology + refresh screenshots @stevewallone (#15113)
- docs: DefectDojo Pro Customizable Dashboards (dashboard_v2) @skywalke34 (#15111)
- chore: replace archived upload-release-asset with gh release upload @Maffooch (#15110)
- docs: add Pro changelog entries for 3.0.200 @Maffooch (#15105)
- docs: split Attaching Files into OS and Pro guides with screenshots @Maffooch (#15104)
- Include analysis.detail from Dependency Track FPF in finding description @webdevred (#14931)
- fix(tags): keep user-set tags when creating a finding under product tag inheritance @valentijnscholten (#15097)
- fix(govulncheck): reject SARIF reports with a clear error pointing to the SARIF scan type @valentijnscholten (#15087)
- June18 docs @paulOsinski (#15093)
- feat(jira): support multiple components in project settings (SC-13173) @Maffooch (#15039)
- fix(rbac): resolve product-scoped users for the engagement Testing Lead selector @valentijnscholten (#15063)
- authorized users improvements @valentijnscholten (#15065)
- Fix SARIF parser: unwrap BlackDuck nested fingerprint dict values @Jino-T (#15080)
- Fix typo in README about demo environment @mo7921 (#15060)
- docs: add Pro changelog entries for 3.0.1, 3.0.2, 3.0.100 @Maffooch (#15059)
- add organization and product type articles @dangoelz (#14961)
- Fix Xygeni parser deduplicating repeated SAST/Secrets findings in the same file @lmrb-1968 (#15003)
- Fixing gha for new versioning scheme @rossops (#15052)
- Stabilize flaky notification-webhook integration test @Maffooch (#15043)
- docs: add DefectDojo Pro Report Builder guides (UI, API, LLM) @skywalke34 (#15008)
- fix(trivy): prevent import crash on legacy reports with missing Class field @stevewallone (#15006)
- test(perf): always run both v2 and v3 importer perf cases @valentijnscholten (#15042)
- feat(cargo-audit): parse CVSS vectors and derive severity (SC-13140) @Maffooch (#15041)
- perf(importers): batch Vulnerability_Id inserts @valentijnscholten (#14966)
- fix(findings): resolve single-location filter against Location model @skywalke34 (#15023)
- [docs] june wk 1 maintenance @paulOsinski (#14963)
🚩 Changes to settings.dist.py / local_settings.py
- feat: allow import/reimport to wait for deduplication to complete @valentijnscholten (#15007)
- feat: allow disabling and dismissing the open source message banner @devGregA (#15089)
- perf(dedupe): skip unchanged rows, VALUES fast-write, prefetch vulnerability_ids @valentijnscholten (#15046)
- Fix Xygeni SAST/Secrets deduplication: key on uniqueHash, not issueId @lmrb-1968 (#15061)
- Add Garak (NVIDIA LLM vulnerability scanner) parser @Dashtid (#15013)
- feat(govulncheck): add Govulncheck Scanner V2 parser @valentijnscholten (#15045)
- feat(parsers): add PICUS Breach and Attack Simulation CSV parser @skywalke34 (#14984)
- perf(importers): batch BurpRawRequestResponse inserts + re-enable perf tests @valentijnscholten (#14969)
- Added global required fields notice for WCAG H90 compliance @sym9 (#14962)
🚩 Database migration
- feat: allow import/reimport to wait for deduplication to complete @valentijnscholten (#15007)
- feat: allow disabling and dismissing the open source message banner @devGregA (#15089)
- perf(finding): add sla_expiration_date index for global finding list @rossops (#15103)
- perf(jira,product): fix finding-group push N+1 and add case-insensitive product-name index @Maffooch (#15122)
- Renumber #15058 migration and move release notes to 3.1.x @Maffooch (#15108)
- Modernize Tool Config credential encryption to AES-256-GCM @Maffooch (#15058)
- Ree/perf indexes @rossops (#15095)
- Add partial indexes for authorized finding-list queries @rossops (#15064)
- perf(migrations): bulk backfill in 0268 release_authorization_to_pro @Maffooch (#15044)
- fix(findings): normalize blank components to NULL (SC-13073) @Maffooch (#15038)
🚀 API features and enhancements
- feat: allow import/reimport to wait for deduplication to complete @valentijnscholten (#15007)
- perf(finding-api): drop blanket DISTINCT from FindingViewSet list @rossops (#15096)
- refactor(reorg): extract every type of class into modules [10/10] @valentijnscholten (#14987)
- Prefetcher updates @dogboat (#14964)
- Endpoint_Status updates @dogboat (#15012)
- Refactor and enhance API permissions @dogboat (#15034)
- fix: prevent 500 on org/product delete with deprecated endpoints, and point new-UI banner at 3.3.0 @Maffooch (#15024)
🐛 Bug Fixes
- fix(filters): don't auto-open the filter panel when only sorting a column @skywalke34 (#15082)
🖌 Updates in UI
- feat: allow import/reimport to wait for deduplication to complete @valentijnscholten (#15007)
- Fix: right-aligned dropdown menus overflow off the right edge of the page @stevewallone (#15137)
- feat(ui): animate collapse panels in the new UI @ksitton58 (#15116)
- feat(ui): smooth and tidy the filter category accordion in the new UI @ksitton58 (#15106)
- feat: allow disabling and dismissing the open source message banner @devGregA (#15089)
- PDF Report: Show vulnerability IDs @samiat4911 (#15115)
- fix(ui): stop client/server sort flash on asset & finding-group lists @skywalke34 (#15084)
- fix(filters): don't auto-open the filter panel when only sorting a column @skywalke34 (#15082)
- fix(metrics): prevent 500 on Critical Asset Metrics page when no critical products exist @valentijnscholten (#15057)
- refactor(ui): use design tokens instead of hardcoded colors on new lo… @ksitton58 (#14998)
- fix(ui): use brand color tokens instead of hardcoded hex in new UI @ksitton58 (#14999)
- fix(ui): add missing "solid" keyword to disclaimer border in new UI @ksitton58 (#15001)
- feat(ui): fold Finding Groups under Findings in the sidebar @ksitton58 (#15040)
- perf(importers): batch BurpRawRequestResponse inserts + re-enable perf tests @valentijnscholten (#14969)
- Added global required fields notice for WCAG H90 compliance @sym9 (#14962)
🧰 Maintenance
- Update dependency kubernetes/kubernetes from v1.35.4 to v1.35.6 (.github/workflows/k8s-tests.yml) @renovate (#14892)
- chore(deps): update stefanzweifel/git-auto-commit-action action from v7.1.0 to v7.2.0 (.github/workflows/release-3-master-into-dev.yml) @renovate (#15130)
- Update actions/checkout action from v6.0.3 to v7 (.github/workflows/validate_docs_build.yml) @renovate (#15132)
- chore(deps-dev): bump @tailwindcss/cli from 4.3.1 to 4.3.2 in /components @dependabot (#15131)
- chore(deps): update docker/build-push-action action from v7.2.0 to v7.3.0 (.github/workflows/release-x-manual-docker-containers.yml) @renovate (#15138)
- chore(deps-dev): bump tailwindcss from 4.3.1 to 4.3.2 in /components @dependabot (#15129)
- chore(deps): bump ruff from 0.15.19 to 0.15.20 @dependabot (#15128)
- chore(deps): bump humanize from 4.15.0 to 4.16.0 @dependabot (#15127)
- chore(deps): bump django-permissions-policy from 4.31.0 to 4.32.0 @dependabot (#15126)
- Update dependency kubernetes from 1.33.13 to v1.34.9 (.github/workflows/k8s-tests.yml) @renovate (#15121)
- Update gcr.io/cloudsql-docker/gce-proxy Docker tag from 1.38.0 to v1.38.1 (helm/defectdojo/values.yaml) @renovate (#15119)
- chore(deps): update actions/cache action from v6.0.0 to v6.1.0 (.github/workflows/validate_docs_build.yml) @renovate (#15120)
- Update python:3.14.6-slim-trixie Docker digest from 3.14.6 to 3.14.6-slim-trixie (Dockerfile.integration-tests-debian) @renovate (#15118)
- chore(deps): update dependency renovatebot/renovate from 43.240.0 to v43.248.0 (.github/workflows/renovate.yaml) @renovate (#15099)
- chore(deps): bump python-gitlab from 8.3.0 to 8.4.0 @dependabot (#14956)
- chore(deps): update release-drafter/release-drafter action from v7.3.1 to v7.5.1 (.github/workflows/release-drafter.yml) @renovate (#15083)
- chore(deps): update actions/cache action from v5.0.5 to v6 (.github/workflows/validate_docs_build.yml) @renovate (#15085)
- chore(deps): update openapitools/openapi-generator-cli docker tag from v7.22.0 to v7.23.0 (dockerfile.integration-tests-debian) @renovate (#15079)
- chore(deps): update mccutchen/go-httpbin docker tag from 2.18.3 to v2.23.1 (docker-compose.override.integration_tests.yml) @renovate (#15078)
- chore(deps): update dependency node from 24.16.0 to v24.18.0 (.github/workflows/validate_docs_build.yml) @renovate (#15077)
- chore(deps): update actions/setup-python action from v6.2.0 to v6.3.0 (.github/workflows/test-helm-chart.yml) @renovate (#15076)
- chore(deps): bump pdfmake from 0.3.10 to 0.3.11 in /components @dependabot (#15075)
- chore(deps): bump redis from 8.0.0 to 8.0.1 @dependabot (#15074)
- chore(deps): bump django-environ from 0.13.0 to 0.14.0 @dependabot (#15073)
- chore(deps): bump ruff from 0.15.16 to 0.15.19 @dependabot (#15072)
- chore(deps-dev): bump django-debug-toolbar from 6.3.0 to 7.0.0 @dependabot (#15071)
- chore(deps): update softprops/action-gh-release action from v3.0.0 to v3.0.1 (.github/workflows/release-x-manual-helm-chart.yml) @renovate (#15070)
- chore(deps): u...