Skip to content

Configure Mend Bolt for GitHub - #1

Open
mend-bolt-for-github[bot] wants to merge 10000 commits into
masterfrom
whitesource/configure
Open

Configure Mend Bolt for GitHub#1
mend-bolt-for-github[bot] wants to merge 10000 commits into
masterfrom
whitesource/configure

Conversation

@mend-bolt-for-github

Copy link
Copy Markdown

Welcome to Mend Bolt for GitHub (formerly WhiteSource). This is an onboarding PR to help you understand and configure settings before Mend starts scanning your repository for security vulnerabilities.

🚦 Mend Bolt for GitHub will start scanning your repository only once you merge this Pull Request. To disable Mend Bolt for GitHub, simply close this Pull Request.


What to Expect

This PR contains a '.whitesource' configuration file which can be customized to your needs. If no changes were applied to this file, Mend Bolt for GitHub will use the default configuration.

Before merging this PR, Make sure the Issues tab is enabled. Once you merge this PR, Mend Bolt for GitHub will scan your repository and create a GitHub Issue for every vulnerability detected in your repository.

If you do not want a GitHub Issue to be created for each detected vulnerability, you can edit the '.whitesource' file and set the 'minSeverityLevel' parameter to 'NONE'.


❓ Got questions? Check out Mend Bolt for GitHub docs.
If you need any further assistance then you can also request help here.

dependabot Bot and others added 30 commits April 14, 2025 10:13
Bumps [markdown](https://github.com/Python-Markdown/markdown) from 3.7 to 3.8.
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.7...3.8)

---
updated-dependencies:
- dependency-name: markdown
  dependency-version: '3.8'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….github/workflows/validate_docs_build.yml) (DefectDojo#12229)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [django-crispy-forms](https://github.com/django-crispy-forms/django-crispy-forms) from 2.3 to 2.4.
- [Release notes](https://github.com/django-crispy-forms/django-crispy-forms/releases)
- [Changelog](https://github.com/django-crispy-forms/django-crispy-forms/blob/main/CHANGELOG.md)
- [Commits](django-crispy-forms/django-crispy-forms@2.3...2.4)

---
updated-dependencies:
- dependency-name: django-crispy-forms
  dependency-version: '2.4'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pillow](https://github.com/python-pillow/Pillow) from 11.1.0 to 11.2.1.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@11.1.0...11.2.1)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 11.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…x/2.45.1-2.46.0-dev

Release: Merge back 2.45.1 into bugfix from: master-into-bugfix/2.45.1-2.46.0-dev
….45.1-2.46.0-dev

Release: Merge back 2.45.1 into dev from: master-into-dev/2.45.1-2.46.0-dev
Bumps [boto3](https://github.com/boto/boto3) from 1.37.33 to 1.37.34.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.33...1.37.34)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.37.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [html2text](https://github.com/Alir3z4/html2text) from 2024.2.26 to 2025.4.15.
- [Release notes](https://github.com/Alir3z4/html2text/releases)
- [Changelog](https://github.com/Alir3z4/html2text/blob/master/ChangeLog.rst)
- [Commits](Alir3z4/html2text@2024.2.26...2025.4.15)

---
updated-dependencies:
- dependency-name: html2text
  dependency-version: 2025.4.15
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Update how-to-write-a-parser.md

- it is 4 methods that have to be added not 3 (see the numbered list 1..4 )
- the location of the doc for a new parser is now in: `docs/content/en/connecting_your_tools/parsers/<file/api>/`

* Update how-to-write-a-parser.md 2

- update the import page documentation

* Update docs/content/en/open_source/contributing/how-to-write-a-parser.md

---------

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* Implement migration

* Remove lower case requirement

* Create common validator

* UI: Apply validator

* API: Apply validator

* Add release notes

* Add unit tests

* Fixing ruff

* Fix some migration updates

* Applying feedback

* Silly copy/paste
…ctDojo#12252)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* sla calc: add unit tests

* sla calc: add unit tests

* sla calc: add unit tests

* linting

* sla: simplify

* sla config: cleanup

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <76979297+blakeaowens@users.noreply.github.com>

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <76979297+blakeaowens@users.noreply.github.com>

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <76979297+blakeaowens@users.noreply.github.com>

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <76979297+blakeaowens@users.noreply.github.com>

---------

Co-authored-by: Blake Owens <76979297+blakeaowens@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.34 to 1.37.35.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.34...1.37.35)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.37.35
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ctDojo#12255)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…37.7 (helm/defectdojo/values.yaml) (DefectDojo#12254)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* 🎉 Implement Fortify Webinspect new report format

* update

* fix

* update

* update

* update

* update

* update

* update according to comment

* docs update

* fix
Bumps [boto3](https://github.com/boto/boto3) from 1.37.35 to 1.37.36.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.35...1.37.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.37.36
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tDojo#12250)

* merge all jira articles into single article

* reweight articles

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

* add wiz documentation

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: valentijnscholten <valentijnscholten@gmail.com>

* update Pro features docs

* reorganize support docs

* rework import documentation for OS context

* update changelog 2.45.1

* fix broken links

---------

Co-authored-by: Paul Osinski <paul.m.osinski@gmail.com>
Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>
Co-authored-by: valentijnscholten <valentijnscholten@gmail.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.11.5 to 0.11.6.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.11.5...0.11.6)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.11.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ctDojo#12260)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Release: Merge release into master from: release/2.45.2
…x/2.45.2-2.46.0-dev

Release: Merge back 2.45.2 into bugfix from: master-into-bugfix/2.45.2-2.46.0-dev
Maffooch and others added 29 commits May 27, 2025 08:13
* Update Support Messaging

* Revert CSS change

* Update wording

* Silly type :face_palm:
Release: Merge release into master from: release/2.46.4
…x/2.46.4-2.47.0-dev

Release: Merge back 2.46.4 into bugfix from: master-into-bugfix/2.46.4-2.47.0-dev
Bumps [boto3](https://github.com/boto/boto3) from 1.38.22 to 1.38.23.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.38.22...1.38.23)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.38.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….46.4-2.47.0-dev

Release: Merge back 2.46.4 into dev from: master-into-dev/2.46.4-2.47.0-dev
Bumps [cryptography](https://github.com/pyca/cryptography) from 44.0.3 to 45.0.3.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@44.0.3...45.0.3)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 45.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.38.23 to 1.38.24.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.38.23...1.38.24)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.38.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…6.18.0 (.github/workflows/release-x-manual-docker-containers.yml) (DefectDojo#12518)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…ng title (DefectDojo#12514)

* Escape javascript breaking on backlash or special characters in finding titel

* Ruff formatting and W605 ignore

* Fix escape character issue with \

* Remove ruff noqa comments.

* Fix ruff failure on w291
Bumps vulners from 2.3.6 to 2.3.7.

---
updated-dependencies:
- dependency-name: vulners
  dependency-version: 2.3.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.38.24 to 1.38.25.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.38.24...1.38.25)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.38.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* nightly-dev-fix-helm-chart-version-detection

* fix release number input

* make helm chart work
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.11.11 to 0.11.12.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.11.11...0.11.12)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.11.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* ♻️ Deprecate async import

* simplify

* update

* fix unittest

* add docs

* update
DefectDojo#12528)

* Dojo Meta: Migrate to `filterset_class` + Add case Insensitive filters

* Update query name
…12525)

* Product Announcements: Add messages to relevant features

* Specify exactly where the error is modified

* Correcting ruff

* Ruff can be dangerous?
Release: Merge release into master from: release/2.47.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.