Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
10000 commits
Select commit Hold shift + click to select a range
79f057f
Bump markdown from 3.7 to 3.8 (#12233)
Apr 14, 2025
348c996
chore(deps): update actions/setup-node action from v4.3.0 to v4.4.0 (…
Apr 14, 2025
c7c5132
Bump django-crispy-forms from 2.3 to 2.4 (#12235)
Apr 14, 2025
8356f81
Bump pillow from 11.1.0 to 11.2.1 (#12234)
Apr 14, 2025
d46dfdb
Merge pull request #12240 from DefectDojo/master-into-bugfix/2.45.1-2…
Apr 14, 2025
f2ee11e
Fixing ruff
Apr 14, 2025
ed2b172
Merge pull request #12239 from DefectDojo/master-into-dev/2.45.1-2.46…
Apr 14, 2025
64131e3
Bump boto3 from 1.37.33 to 1.37.34 (#12245)
Apr 15, 2025
423d98d
Bump html2text from 2024.2.26 to 2025.4.15 (#12246)
Apr 15, 2025
ed03b4f
Update how-to-write-a-parser.md (#12210)
Apr 15, 2025
d902fbb
Deprecation notification about async import (#12244)
Apr 15, 2025
0b5354e
Tag: Update allowed characters for a unified format (#12194)
Apr 16, 2025
d2a32bf
Update dependency vite from 6.2.6 to v6.3.0 (docs/package.json) (#12252)
Apr 16, 2025
539a7b2
SLA Calculations 2/2: Simplify logic (#11924)
Apr 16, 2025
50a0c43
Bump boto3 from 1.37.34 to 1.37.35 (#12257)
Apr 17, 2025
cfd640f
Update dependency vite from 6.3.0 to v6.3.1 (docs/package.json) (#12255)
Apr 17, 2025
744cce5
Update gcr.io/cloudsql-docker/gce-proxy Docker tag from 1.37.6 to v1.…
Apr 17, 2025
bd59489
:tada: Add Amazon Linux Security Center aadvisory to vulnid (#12242)
Apr 17, 2025
c5f921d
:tada: Implement Fortify Webinspect new report format (#12155)
Apr 17, 2025
8f7936e
Update base.html (#12228)
Apr 17, 2025
810d93c
Bump boto3 from 1.37.35 to 1.37.36 (#12262)
Apr 18, 2025
c0c434e
[docs] Changelog, Jira reorg, Wiz Connector docs, Import reorg (#12250)
Apr 18, 2025
41d5929
Bump ruff from 0.11.5 to 0.11.6 (#12263)
Apr 18, 2025
841df51
Update dependency vite from 6.3.1 to v6.3.2 (docs/package.json) (#12260)
Apr 18, 2025
78a8bfc
Update versions in application files
Apr 22, 2025
8e7cc01
Merge pull request #12286 from DefectDojo/release/2.45.2
Apr 22, 2025
ffad037
Update versions in application files
Apr 22, 2025
18613df
Update versions in application files
Apr 22, 2025
3ae4570
Merge branch 'dev' into master-into-dev/2.45.2-2.46.0-dev
Apr 22, 2025
ae199cb
Merge pull request #12288 from DefectDojo/master-into-bugfix/2.45.2-2…
Apr 22, 2025
842d72d
Fix Ruff
Apr 22, 2025
df090cb
Merge pull request #12287 from DefectDojo/master-into-dev/2.45.2-2.46…
Apr 22, 2025
219ae02
Update softprops/action-gh-release action from v2.2.1 to v2.2.2 (.git…
Apr 22, 2025
a6cb5a5
Update stefanzweifel/git-auto-commit-action action from v5.1.0 to v5.…
Apr 22, 2025
227eaa5
Bump boto3 from 1.37.36 to 1.37.38 (#12290)
Apr 22, 2025
f55c623
Update wording about async import removal in 2.46.md (#12256)
Apr 22, 2025
a0c4895
:bug: Differentiate between slackware and siemens vulnid (#12251)
Apr 22, 2025
c8a50b0
[docs] Add Example Cases to docs (#12265)
Apr 22, 2025
fcfb39c
Parser docstrings (#12253)
Apr 22, 2025
ff2a37b
Update Wiz parser documentation - Standard & SCA imports (#12259)
Apr 22, 2025
2c21a46
Update Node.js from v22.14.0 to v22.15.0 (docs/package.json) (#12296)
Apr 23, 2025
020b476
Bump lxml from 5.3.2 to 5.4.0 (#12297)
Apr 23, 2025
0dd2dd1
Bump boto3 from 1.37.38 to 1.38.0 (#12298)
Apr 23, 2025
4ffaac9
Update redis Docker tag from 7.2.5 to v7.2.7 (docker-compose.yml) (#1…
Apr 23, 2025
ee50912
Reimport: Special statuses should be respected from reports (#12291)
Apr 24, 2025
2296f09
Update dependency node from 22.14.0 to v22.15.0 (.github/workflows/va…
Apr 24, 2025
6d412dd
saml: provide link to saml-tracer browser add-on (#12274)
Apr 24, 2025
f763df3
tenable: check mandatory columns before importing (#12273)
Apr 24, 2025
84383b2
2.45.2 pro changelog (#12292)
Apr 24, 2025
b413437
sla: parse finding.date implicitly (#12301)
Apr 24, 2025
76c63d3
Fortify: Handle suppressed findings as false positives (#12293)
Apr 24, 2025
214543d
Update dependency vite from 6.3.2 to v6.3.3 (docs/package.json) (#12305)
Apr 24, 2025
db484e4
Update actions/setup-python action from v5.5.0 to v5.6.0 (.github/wor…
Apr 24, 2025
0bd100f
Bump boto3 from 1.38.0 to 1.38.1 (#12308)
Apr 24, 2025
d3d5ca8
Update docker/build-push-action action from v6.15.0 to v6.16.0 (.gith…
Apr 24, 2025
3e16c41
Update actions/download-artifact action from v4.2.1 to v4.3.0 (.githu…
Apr 24, 2025
205692e
Add Cyberwatch Galeax Parser (#12105)
Apr 25, 2025
3fb7829
Update redis Docker tag from 7.2.7 to v7.2.8 (docker-compose.yml) (#1…
Apr 25, 2025
5e44090
Bump boto3 from 1.38.1 to 1.38.2 (#12318)
Apr 25, 2025
63d468c
Bump ruff from 0.11.6 to 0.11.7 (#12317)
Apr 25, 2025
04ebea4
Bump social-auth-core from 4.5.6 to 4.6.0 (#12316)
Apr 25, 2025
5bf2349
[docs] add Pro Finding Enhancements documentation (#12310)
Apr 25, 2025
a6b411a
Remove non-working DD_SLA_BUSINESS_DAYS feature to avoid confusion (#…
Apr 26, 2025
a53fcef
Quotes (#12226)
Apr 26, 2025
48a7a73
Implement Albibaba Linux vulnids (#12304)
Apr 26, 2025
0bab9ec
Update versions in application files
Apr 28, 2025
477583e
Merge pull request #12324 from DefectDojo/release/2.45.3
Apr 28, 2025
72b373a
Update versions in application files
Apr 28, 2025
6fa16dd
Update versions in application files
Apr 28, 2025
26e6f44
Merge branch 'dev' into master-into-dev/2.45.3-2.46.0-dev
Apr 28, 2025
499e4ee
Merge pull request #12326 from DefectDojo/master-into-bugfix/2.45.3-2…
Apr 28, 2025
c0a1e1c
Fixing linter issues
Apr 28, 2025
23d98ee
Fixing keyword space
Apr 28, 2025
617881b
Bump openapitools/openapi-generator-cli from v7.12.0 to v7.13.0 (#12322)
Apr 28, 2025
827bfc2
Bump nginx from 1.27.4-alpine3.21 to 1.27.5-alpine3.21 (#12323)
Apr 28, 2025
0b732f0
Merge pull request #12325 from DefectDojo/master-into-dev/2.45.3-2.46…
Apr 28, 2025
ceee1cf
Update nginx/nginx-prometheus-exporter Docker tag from 1.4.1 to v1.4.…
Apr 28, 2025
2f60528
Update verbose name + help text for JIRA username and password fields…
Apr 28, 2025
6d3bf89
Bump social-auth-core from 4.6.0 to 4.6.1 (#12340)
Apr 29, 2025
e262c35
chore(deps): update manusa/actions-setup-minikube action from v2.13.1…
Apr 29, 2025
9febeb6
Bump pdfmake from 0.2.18 to 0.2.19 in /components (#12335)
Apr 29, 2025
b9512d4
Bump boto3 from 1.38.2 to 1.38.4 (#12336)
Apr 29, 2025
b071600
Bump celery from 5.5.1 to 5.5.2 (#12337)
Apr 29, 2025
25cd3e5
Bump django-auditlog from 3.0.0 to 3.1.2 (#12338)
Apr 29, 2025
a39ff49
Bump django-debug-toolbar from 5.1.0 to 5.2.0 (#12339)
Apr 29, 2025
3c9e7ff
most recent note: show date/author (#12329)
Apr 29, 2025
c15e604
fix(api): Enable to set `recommendation` and `decision` in `risk_acce…
Apr 29, 2025
51c70e8
Jira webhook comment duplicate patch (#12333)
Apr 29, 2025
d9b49c5
[docs] add Tags article (#12294)
Apr 29, 2025
8ee4d2d
Bump humanize from 4.12.2 to 4.12.3 (#12353)
Apr 30, 2025
5a07275
Bump boto3 from 1.38.4 to 1.38.5 (#12352)
Apr 30, 2025
df81430
chore(deps): update dependency vite from 6.3.3 to v6.3.4 (docs/packag…
Apr 30, 2025
09acb3a
False Positive Status: Update docs (#12332)
Apr 30, 2025
9636c1e
Generic Parser: Support Test Type Meta (#12348)
Apr 30, 2025
600e574
tenable nessus: parse all fields, except cwe (#12247)
Apr 30, 2025
38700b5
Enhance OSV Parser to Include Mitigation Information with Fixed Packa…
Apr 30, 2025
339874b
releases: publish nightly builds of dev (#12137)
Apr 30, 2025
f5b9039
Bump psycopg[c] from 3.2.6 to 3.2.7 (#12360)
May 1, 2025
c8d1d3a
Bump boto3 from 1.38.5 to 1.38.6 (#12359)
May 1, 2025
ac19d38
Bump drf-spectacular-sidecar from 2025.4.1 to 2025.5.1 (#12358)
May 1, 2025
67940a9
Urllib3 upgrade + Rerecord JIra responses (#12355)
May 1, 2025
5635f69
view_endpoint: fix error (#12343)
May 1, 2025
5fcc9e4
Add input validation (branch to release num) for the release gha (#12…
May 1, 2025
19ed7f7
Focus Indicator Disappears While Tabbing - DefectDojo Accessibility i…
May 1, 2025
dfa5304
fix(GHA): Avoid some actions in forks (#12354)
May 2, 2025
2bf8cd6
Bump ruff from 0.11.7 to 0.11.8 (#12367)
May 2, 2025
6601929
update changelog 2.45.3 (#12364)
May 2, 2025
32b1bdd
Bump boto3 from 1.38.6 to 1.38.7 (#12366)
May 2, 2025
5610328
[docs] sso maintenance (#12356)
May 2, 2025
cede5fa
Merge branch 'dev' into bugfix
May 5, 2025
941b258
Fixing linter issues PTH123
May 5, 2025
8ff6f7d
Fixing urllib version
May 5, 2025
e21bfbb
Merge pull request #12385 from DefectDojo/bugfix
May 5, 2025
fba830a
Update versions in application files
May 5, 2025
05a92af
Merge pull request #12386 from DefectDojo/release/2.46.0
May 5, 2025
7de17c4
Update versions in application files
May 5, 2025
40e03f9
Update versions in application files
May 5, 2025
466fc0b
Release: Merge back 2.46.0 into dev from: master-into-dev/2.46.0-2.47…
May 5, 2025
11ab9b4
Merge pull request #12387 from DefectDojo/master-into-bugfix/2.46.0-2…
May 5, 2025
b583fda
Bump boto3 from 1.38.7 to 1.38.8 (#12383)
May 5, 2025
8c88056
Bump cryptography from 44.0.2 to 44.0.3 (#12382)
May 5, 2025
2f2db2d
chore(deps): update dependency vite from 6.3.4 to v6.3.5 (docs/packag…
May 5, 2025
7ffc077
Session timeout notification 2 (#12225)
May 5, 2025
bcc2181
chore(deps): update mikefarah/yq action from v4.45.1 to v4.45.2 (.git…
May 5, 2025
6b2419b
ui: fix "retrieve my username" typo (#12368)
May 6, 2025
be2429b
Minor Semgrep connector docs tweaks (#12373)
May 6, 2025
e2c5b12
Ruff: Add PLR1730 and PLR2044 (#12380)
May 6, 2025
10155ce
jira push: log inactive/verified message to debug (#12376)
May 6, 2025
5514679
Bump boto3 from 1.38.8 to 1.38.9 (#12390)
May 7, 2025
662fbb0
helm chart publisher: use proper ref for checkout (#12392)
May 7, 2025
1db84c8
tags: prevent validation from removing tags (#12400)
May 7, 2025
37df1f1
Update versions in application files
May 7, 2025
1b6e43b
Release: Merge release into master from: release/2.46.1 (#12402)
May 7, 2025
ea4392f
Update versions in application files
May 7, 2025
3ab3539
Update versions in application files
May 7, 2025
e0457ad
Merge branch 'dev' into master-into-dev/2.46.1-2.47.0-dev
May 7, 2025
792ab61
Merge pull request #12403 from DefectDojo/master-into-dev/2.46.1-2.47…
May 7, 2025
96a7cb4
Merge pull request #12404 from DefectDojo/master-into-bugfix/2.46.1-2…
May 7, 2025
0f32654
Bump boto3 from 1.38.9 to 1.38.10 (#12395)
May 7, 2025
9be3f22
Merge pull request #12412 from DefectDojo/dependabot/pip/dev/boto3-1.…
May 8, 2025
6710ef4
Bump boto3 from 1.38.11 to 1.38.12 (#12423)
May 9, 2025
af25a7d
Bump pdfmake from 0.2.19 to 0.2.20 in /components (#12422)
May 9, 2025
02ee92d
chore(deps): update helm release postgresql from 16.6.7 to ~16.7.0 (h…
May 9, 2025
1884ada
Removed Asynchronous Imort from performance.md (#12410)
May 9, 2025
a403927
Update Burp Enterprise HTML Parser Documentation (#12407)
May 9, 2025
bbda765
fix(nighly): Avoid forks (#12396)
May 9, 2025
c4c6fc3
anchorectl: add format check (#12375)
May 9, 2025
ff2871e
feat(helm): Drop support for postgresql-ha (#12319)
May 9, 2025
1fddb39
chore(deps): update postgres docker tag from 17.4 to v17.5 (docker-co…
May 9, 2025
4243bb5
chore(deps): update mikefarah/yq action from v4.45.2 to v4.45.3 (.git…
May 9, 2025
bec9e0d
Managed Files: Sanitized file name before downloading (#12406)
May 9, 2025
b3d2c96
Ruff: Add and autofix PERF403 (#12371)
May 9, 2025
f9ccf79
[docs] Pro dashboards and metrics (#12416)
May 12, 2025
f9656c1
[docs] Add FAQ + minor maintenance changes (#12417)
May 12, 2025
c43cd15
Update versions in application files
May 12, 2025
924c2c8
Merge pull request #12431 from DefectDojo/release/2.46.2
May 12, 2025
8814849
Update versions in application files
May 12, 2025
715e7f6
Update versions in application files
May 12, 2025
5aca9d9
Merge branch 'dev' into master-into-dev/2.46.2-2.47.0-dev
May 12, 2025
05a74d5
Merge pull request #12433 from DefectDojo/master-into-bugfix/2.46.2-2…
May 12, 2025
16d7cc4
Merge pull request #12432 from DefectDojo/master-into-dev/2.46.2-2.47…
May 12, 2025
3b52d08
Bump django-dbbackup from 4.2.1 to 4.3.0 (#12430)
May 12, 2025
a1ba6ea
Bump boto3 from 1.38.12 to 1.38.13 (#12429)
May 12, 2025
8d5d856
Bump psycopg[c] from 3.2.7 to 3.2.8 (#12428)
May 12, 2025
4ecdfea
Bump ruff from 0.11.8 to 0.11.9 (#12427)
May 12, 2025
73ba1db
chore(deps): update mikefarah/yq action from v4.45.3 to v4.45.4 (.git…
May 12, 2025
9b5af77
Bump boto3 from 1.38.13 to 1.38.15 (#12443)
May 14, 2025
28083c8
Bump psycopg[c] from 3.2.8 to 3.2.9 (#12444)
May 14, 2025
54ae24f
Ruff: Add and autofix PERF401 (#12370)
May 15, 2025
28215da
chore(deps): update docker/build-push-action action from v6.16.0 to v…
May 15, 2025
2b829bf
Bump boto3 from 1.38.15 to 1.38.16 (#12453)
May 15, 2025
e2121f1
Bump sqlalchemy from 2.0.40 to 2.0.41 (#12452)
May 15, 2025
adc5fed
chore(deps): update node.js from v22.15.0 to v22.15.1 (docs/package.j…
May 15, 2025
bae01df
defender: fix no vulnerabilities check (#12448)
May 15, 2025
bc62293
UI Pagination: Reduce the options to more reasonable numbers (#12439)
May 15, 2025
241015a
docs: Add non-parser Test Types to product hierarchy documentation (#…
May 15, 2025
741e239
Tags: Add support for comma separation for multipart forms (import/re…
May 15, 2025
ccf049f
excel export: enhance handling of finding groups, better logging (#12…
May 15, 2025
4c180c0
Bump ruff from 0.11.9 to 0.11.10 (#12461)
May 16, 2025
66b30da
Bump boto3 from 1.38.16 to 1.38.17 (#12460)
May 16, 2025
18644d6
Ruff: Add PLC0206 (#12426)
May 16, 2025
129fddf
cvssv3: backport tests (#12457)
May 16, 2025
156f46d
easymde: enable native spell checker (#12377)
May 16, 2025
cfa7b97
fix(deps): update dependency @tabler/icons from 3.31.0 to v3.33.0 (do…
May 18, 2025
4f83b84
docs maintenance (#12455)
May 19, 2025
ec9ede1
Replace Review Bot with Centralized Action (#12451)
May 19, 2025
0abb385
Update versions in application files
May 19, 2025
5cd9876
Merge pull request #12481 from DefectDojo/release/2.46.3
May 19, 2025
41cce1e
Update versions in application files
May 19, 2025
bf1bfe8
Update versions in application files
May 19, 2025
778342a
Merge branch 'dev' into master-into-dev/2.46.3-2.47.0-dev
May 19, 2025
43b20c8
Merge pull request #12482 from DefectDojo/master-into-bugfix/2.46.3-2…
May 19, 2025
76306ab
Merge pull request #12483 from DefectDojo/master-into-dev/2.46.3-2.47…
May 19, 2025
c70ced7
Bump boto3 from 1.38.17 to 1.38.18 (#12477)
May 19, 2025
3a76f3d
Bump pyopenssl from 25.0.0 to 25.1.0 (#12479)
May 19, 2025
6beedb3
Celery Logging: Respect CELERY_LOG_LEVEL (#12464)
May 20, 2025
017fcce
Bump boto3 from 1.38.18 to 1.38.19 (#12486)
May 20, 2025
2cbfbfc
feat(helm): allow to use an external serviceAccount (#12441)
May 20, 2025
9d1ba17
Update contributors in README.md (#12485)
May 20, 2025
3e8f041
:bug: fix missing CWE in HCL Appscan (#12469)
May 21, 2025
541ce46
Bump django-polymorphic from 3.1.0 to 4.1.0 (#12488)
May 21, 2025
409af5f
Bump boto3 from 1.38.19 to 1.38.20 (#12489)
May 21, 2025
35b590e
add changelog for 2.46.0-3 (#12484)
May 22, 2025
c4dbe4f
bugfix cyberwatch parser (#12480)
May 22, 2025
7fa55fc
Alibaba Cloud Linux 3 Security Advisory (#12465)
May 22, 2025
5a57c1f
Add new "evaluations" format support to Anchorectl parser (#12425)
May 22, 2025
13e35cf
Updated Nexpose XML (Rapid7) Parser Documentation (#12409)
May 22, 2025
c4daf99
Checkmarx one doc update (#12408)
May 22, 2025
98e7431
Bump boto3 from 1.38.20 to 1.38.21 (#12492)
May 22, 2025
05dc721
legacy reimport: make matching on title case-insensitive (#12487)
May 22, 2025
4e3c6f4
ms defender: do not cache parsed findings (#12493)
May 22, 2025
7c29ecf
chore(deps): update node.js from v22.15.1 to v22.16.0 (docs/package.j…
May 23, 2025
b35d46f
unique_id_from_tool: clarify values and usage (#12463)
May 23, 2025
24ac437
Store fingerprint from bearer in unique_id_from_tool (#12346)
May 23, 2025
45db41d
Forced-contrast mode adjustments for better accessibility (#12342)
May 23, 2025
ae8fca0
Bump ruff from 0.11.10 to 0.11.11 (#12498)
May 23, 2025
01d7295
Bump boto3 from 1.38.21 to 1.38.22 (#12497)
May 23, 2025
0197647
Include CVSS score in finding when using OpenVAS csv parser (#12472)
May 23, 2025
c736634
fixed margin panel-footer issue in detailed metrics (#12494)
May 23, 2025
7a0bdb1
Implement ALEA vulnid (#12500)
May 25, 2025
77a1610
fix: add CVSSv4 support to auditjs parser and improve error handling …
May 25, 2025
d8d9211
Update Support Messaging (#12495)
May 27, 2025
4e646aa
Update versions in application files
May 27, 2025
6b30c45
Merge pull request #12515 from DefectDojo/release/2.46.4
May 27, 2025
359c492
Update versions in application files
May 27, 2025
8ff82af
Update versions in application files
May 27, 2025
cd686f1
Merge branch 'dev' into master-into-dev/2.46.4-2.47.0-dev
May 27, 2025
08c5f4a
Merge pull request #12516 from DefectDojo/master-into-bugfix/2.46.4-2…
May 27, 2025
101c776
Fixing linter issue (#12519)
May 27, 2025
38653f2
Bump boto3 from 1.38.22 to 1.38.23 (#12506)
May 27, 2025
e69d6bb
Merge pull request #12517 from DefectDojo/master-into-dev/2.46.4-2.47…
May 27, 2025
daeaa43
Bump cryptography from 44.0.3 to 45.0.3 (#12505)
May 27, 2025
1f04a4f
check for existing issue inside celery task (#12508)
May 28, 2025
b8d55e5
Bump boto3 from 1.38.23 to 1.38.24 (#12522)
May 28, 2025
ec2e5fd
chore(deps): update docker/build-push-action action from v6.17.0 to v…
May 28, 2025
69d0d57
fix gap between component header and filter body (#12503)
May 29, 2025
33559eb
Escape javascript breaking on backlash or special characters in findi…
May 29, 2025
4c53398
Bump vulners from 2.3.6 to 2.3.7 (#12526)
May 29, 2025
5f3e862
Bump boto3 from 1.38.24 to 1.38.25 (#12527)
May 29, 2025
2f27ebe
Implement ELA vulnid (#12510)
May 29, 2025
9d99c62
remove google sheets leftovers (#12509)
May 29, 2025
7c4bef4
Fix helm chart for nightly-dev builds (#12504)
May 29, 2025
fcf9878
Bump ruff from 0.11.11 to 0.11.12 (#12532)
May 30, 2025
9225090
:recycle: Remove async import (#12042)
Jun 2, 2025
d720d38
Dojo Meta: Migrate to `filterset_class` + Add case Insensitive filter…
Jun 2, 2025
4ca3098
Product Announcements: Add messages to relevant features (#12525)
Jun 2, 2025
446088d
Merge pull request #12541 from DefectDojo/bugfix
Jun 2, 2025
bc61e4c
Update versions in application files
Jun 2, 2025
fe38beb
Merge pull request #12542 from DefectDojo/release/2.47.0
Jun 2, 2025
05a47cb
Add .whitesource configuration file
Jun 4, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
3 changes: 3 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
.git
.gitignore
*.md
72 changes: 72 additions & 0 deletions .dryrunsecurity.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
---
sensitiveCodepaths:
- 'dojo/object/urls.py'
- 'dojo/object/views.py'
- 'dojo/announcement/*.py'
- 'dojo/api_v2/*.py'
- 'dojo/api_v2/**/*.py'
- 'dojo/authorization/*.py'
- 'dojo/db_migrations/*.py'
- 'dojo/endpoint/*.py'
- 'dojo/engagement/*.py'
- 'dojo/finding/*.py'
- 'dojo/finding_group/*.py'
- 'dojo/group/*.py'
- 'dojo/importers/*.py'
- 'dojo/importers/**/*.py'
- 'dojo/jira_link/*.py'
- 'dojo/metrics/*.py'
- 'dojo/note_type/*.py'
- 'dojo/notes/*.py'
- 'dojo/product/*.py'
- 'dojo/product_type/*.py'
- 'dojo/reports/*.py'
- 'dojo/risk_acceptance/*.py'
- 'dojo/search/*.py'
- 'dojo/templates/*.html'
- 'dojo/templates/**/*.html'
- 'dojo/templatetags/*.py'
- 'dojo/test/*.py'
- 'dojo/tool_config/*.py'
- 'dojo/tool_product/*.py'
- 'dojo/tool_type/*.py'
- 'dojo/user/*.py'
- 'dojo/apps.py'
- 'dojo/celery.py'
- 'dojo/context_processors.py'
- 'dojo/decorators.py'
- 'dojo/filters.py'
- 'dojo/forms.py'
- 'dojo/middleware.py'
- 'dojo/models.py'
- 'dojo/okta.py'
- 'dojo/pipeline.py'
- 'dojo/remote_user.py'
- 'dojo/tasks.py'
- 'dojo/urls.py'
- 'dojo/utils.py'
- 'dojo/views.py'
- 'dojo/wsgi.py'
- 'docker/environments/*.env'
- 'docker/extra_settings'
- 'docker/entrypoint-celery-beat.sh'
- 'docker/entrypoint-celery-worker.sh'
- 'docker/entrypoint-initializer.sh'
- 'docker/entrypoint-first-boot.sh'
- 'docker/entrypoint-nginx.sh'
- 'docker/entrypoint-uwsgi.sh'
- 'docker/wait-for-it.sh'
allowedAuthors:
usernames:
- mtesauro
- devGregA
- cneill
- Maffooch
- blakeaowens
- kiblik
- dsever
- dogboat
- hblankenship
- valentijnscholten
notificationList:
- '@mtesauro'
19 changes: 19 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Any kind of package updates only need 2 approvals,
# So let's add three folks here
requirements.txt @cneill @mtesauro @Maffooch
# Any dockerfile or compose changes will need to be viewed by
# these people
Dockerfile.* @mtesauro @Maffooch
docker-compose.* @mtesauro @Maffooch
/docker/ @mtesauro @Maffooch
# Documentation changes
/docs/content/ @paulOsinski @valentijnscholten @Maffooch
# Kubernetes should be reviewed by reviewed first by those that know it
/helm/ @cneill @kiblik @Maffooch
# Anything UI related needs to be checked out by those with the eye for it
/dojo/static/ @blakeaowens @Maffooch
/dojo/templates/ @blakeaowens @Maffooch
# Any model changes should be closely looked at
/dojo/models.py @Maffooch
# All other code changes should be reviewed by someone
* @Maffooch @mtesauro
49 changes: 49 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: Bug report
about: Create a report to help us improve
title: ''
labels: bug
assignees: ''

---
**Slack us first!**
The easiest and fastest way to help you is via Slack. There's a free and easy signup to join our #defectdojo channel in the OWASP Slack workspace: [Get Access.](https://owasp.org/slack/invite)
If you're confident you've found a bug, or are allergic to Slack, you can submit an issue anyway.

**Be informative**
Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev version and try again.

**Bug description**
A clear and concise description of what the bug is. For errors include at least the exact error message you are seeing (including traceback).

**Steps to reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Deployment method** *(select with an `X`)*
- [ ] Docker Compose
- [ ] Kubernetes
- [ ] GoDojo

**Environment information**
- Operating System: [e.g. Ubuntu 18.04]
- Docker Compose or Helm version (Output of `docker compose version` or `helm version`)
- DefectDojo version (see footer) or commit message: [use `git show -s --format="[%ci] %h: %s [%d]"`]

**Logs**
Use `docker compose logs` (or similar, depending on your deployment method) to get the logs and add the relevant sections here showing the error occurring (if applicable).

**Sample scan files**
If applicable, add sample scan files to help reproduce your problem.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Additional context** (optional)
Add any other context about the problem here.
26 changes: 26 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
name: Feature request
about: Suggest an idea for DefectDojo
title: ''
labels: enhancement
assignees: ''

---
## :warning: Note on feature completeness :warning:

We are narrowing the scope of acceptable enhancements to DefectDojo. Learn more here:
https://github.com/DefectDojo/django-DefectDojo/blob/master/readme-docs/CONTRIBUTING.md

**Is your feature request related to a problem? Please describe**
A clear and concise description of what the problem is.
Ex: I'm always frustrated when [...]

**Describe the solution you'd like**
A clear and concise description of what you want to happen.
Ex: As a < role >, I want < some goal > so that < some reason >.

**Describe alternatives you've considered**
A clear and concise description of any alternative solutions or features you have considered.

**Additional context**
Add any other context, screenshots, sketch, code snippet, etc. about the feature request here.
14 changes: 14 additions & 0 deletions .github/ISSUE_TEMPLATE/importer_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
name: New importer request
about: Request a new importer (scanner) for DefectDojo
title: ''
labels: Import Scans
assignees: ''

---

**Scanner Name**
Name of the scanner, brief description of the scanner and link.

**Sample File**
Please attach a sample file and the format of the file (xml, json, csv).
16 changes: 16 additions & 0 deletions .github/ISSUE_TEMPLATE/security_issue.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
name: Security issue
about: Report a security issue
title: Please submit via our security reporting program, not GitHub
labels: security
assignees: ''

---

**DefectDojo security reporting program**

If you believe you have found a **security issue** in DefectDojo, please review the [disclosure policy](../../readme-docs/SECURITY.md) and submit your finding via our security reporting program.

Please, do not submit **security issues** via GitHub directly.

Thank you for helping keep DefectDojo and our users safe!
49 changes: 49 additions & 0 deletions .github/ISSUE_TEMPLATE/support_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
---
name: Support Request
about: If you need support or are running into some trouble
title: ''
labels: support
assignees: ''

---
**Slack us first!**
The easiest and fastest way to help you is via Slack. There's a free and easy signup to join our #defectdojo channel in the OWASP Slack workspace: [Get Access.](https://owasp.org/slack/invite)
If you're confident you've found a bug, or are allergic to Slack, you can submit an issue anyway.

**Be informative**
Please enter as much information as possible, otherwise we can't provide support. If possible upgrade to the latest release or dev branch and try again.

**Problem description**
A clear and concise description of what the problem is. For errors include at least the exact error message you are seeing (including traceback).

**Steps to reproduce**
Steps to reproduce the behavior:
1. Go to '...'
2. Click on '....'
3. Scroll down to '....'
4. See error

**Expected behavior**
A clear and concise description of what you expected to happen.

**Deployment method** *(select with an `X`)*
- [ ] Docker Compose
- [ ] Kubernetes
- [ ] GoDojo

**Environment information**
- Operating System: [e.g. Ubuntu 18.04]
- Docker Compose or Helm version (Output of `docker compose version` or `helm version`)
- DefectDojo version (see footer) or commit message: [use `git show -s --format="[%ci] %h: %s [%d]"`]

**Logs**
Use `docker compose logs` (or similar, depending on your deployment method) to get the logs and add the relevant sections here showing the error occurring (if applicable).

**Sample scan files**
If applicable, add sample scan files to help reproduce your problem.

**Screenshots**
If applicable, add screenshots to help explain your problem.

**Additional context** (optional)
Add any other context about the problem here.
71 changes: 71 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
version: 2
updates:
- package-ecosystem: pip
directory: "/"
schedule:
interval: daily
open-pull-requests-limit: 10
target-branch: dev
ignore:
- dependency-name: whitenoise
versions:
- ">= 5.a"
- "< 6"
- package-ecosystem: npm
directory: "/components"
schedule:
interval: daily
open-pull-requests-limit: 10
target-branch: dev
ignore:
- dependency-name: bootstrap
versions:
- ">= 4.a"
- "< 5"
- dependency-name: bootstrap-social
versions:
- ">= 5.a"
- "< 6"
- dependency-name: bootswatch
versions:
- ">= 4.a"
- "< 5"
- dependency-name: chosen
versions:
- ">= 1.a"
- "< 2"
- dependency-name: drmonty-datatables-responsive
versions:
- ">= 2.a"
- "< 3"
- dependency-name: flot
versions:
- ">= 2.a"
- "< 3"
- dependency-name: flot
versions:
- ">= 3.a"
- "< 4"
- dependency-name: flot
versions:
- ">= 4.a"
- "< 5"
- dependency-name: fullcalendar
versions:
- ">= 5.a"
- "< 6"
- dependency-name: startbootstrap-sb-admin-2
versions:
- ">= 3.a"
- "< 4"
- dependency-name: startbootstrap-sb-admin-2
versions:
- ">= 4.a"
- "< 5"
- package-ecosystem: docker
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 10
target-branch: dev

67 changes: 67 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
docs:
- changed-files:
- any-glob-to-any-file:
- docs/**/*
- readme-docs/**/*

docker:
- changed-files:
- any-glob-to-any-file:
- docker/**/*
- docker**
- Docker*

helm:
- changed-files:
- any-glob-to-any-file:
- helm/defectdojo/*
- helm/defectdojo/**/*

"New Migration":
- changed-files:
- any-glob-to-any-file:
- dojo/db_migrations/*

unittests:
- changed-files:
- any-glob-to-any-file:
- unittests/**/*

integration_tests:
- changed-files:
- any-glob-to-any-file:
- tests/**/*

settings_changes:
- changed-files:
- any-glob-to-any-file:
- dojo/settings/settings.dist.py

apiv2:
- changed-files:
- any-glob-to-any-file:
- dojo/api_v2/**/*

ui:
- changed-files:
- any-glob-to-any-file:
- dojo/static/**/*
- dojo/templates/**/*
- dojo/templatetags/**/*

parser:
- changed-files:
- any-glob-to-any-file:
- dojo/tools/**/*

localization:
- changed-files:
- any-glob-to-any-file:
- dojo/locale/*
- dojo/locale/**/*

lint:
- changed-files:
- any-glob-to-any-file:
- ruff.toml
Loading