github DefectDojo/django-DefectDojo 2.13.0
2.13.0 🌈

latest releases: 2.38.4, 2.38.3, 2.38.2...
2 years ago

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 2.12.0

🚩 Changes to settings.dist.py / local_settings.py

  • API-Swagger(drf-yasg): fix docExpansion @kiblik (#6625)
  • Fix Okta OAuth2 API URL @rc-mattschwager (#6606)
  • Remove legacy authorization for changing configuration @StefanFl (#6446)
  • Add file upload extension allow list, Force authorization to download file @Maffooch (#6564)
  • Implement PWN SAST Parser for importing pwn_sast driver source code scanning results into DefectDojo. @ninp0 (#6561)
  • StackHawk HawkScan Parser Config Tweak @Bwvolleyball (#6571)

🚩 Database migration

🚩 Security

  • Add file upload extension allow list, Force authorization to download file @Maffooch (#6564)

πŸš€ General features and enhancements

  • Add the merged findings as bulletpoints in the note @coheigea (#6531)
  • Add file upload extension allow list, Force authorization to download file @Maffooch (#6564)
  • Set the finding date for Acunetix360 from FirstSeenDate @coheigea (#6460)
  • Don't wrap lines when parsing Acunetix @coheigea (#6532)

πŸš€ API features and enhancements

  • Deduplication for Engagement only when auto_create_context = True @37b (#6562)
  • Fix format strings used in exceptions @p-l- (#6593)
  • Remove legacy authorization for changing configuration @StefanFl (#6446)

πŸ› Bug Fixes

  • Correct wording on copy text, add more places to copy @Maffooch (#6614)
  • SonarQube API: process hotspot rules without riskDescription and fixRecommendations @StefanFl (#6530)
  • Simplify saving of vulnerability ids @StefanFl (#6535)

🧰 Maintenance

πŸ–Œ Updates in UI

Don't miss a new django-DefectDojo release

NewReleases is sending notifications on new releases.