Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 2.41.0
- Fix image ref on README.md @paulOsinski (#11491)
- Docs maintenance - v2.41.4 @paulOsinski (#11484)
- Update JIRA for Finding Group When Risk Acceptance Expires @hblankenship (#11401)
- Add pro release notes for 2.41.4 @paulOsinski (#11483)
- update changelog, add changelog link to navbar @paulOsinski (#11465)
- Add EPSS score and percentile to generic csv parser @hblankenship (#11449)
- bump ruff to 0.8.1 @manuel-sommer (#11350)
- 2.41.1: docs maintenance @paulOsinski (#11413)
- fix typo in docs @manuel-sommer (#11387)
- Notifications: Convert to classes @Maffooch (#11296)
- [docs] Pro Docs release notes - 2.41.2 @paulOsinski (#11420)
- fix(helm): Unpin old HELM version @kiblik (#11363)
- Add uwsgi vars to docker-compose.yml @optimistic5 (#11186)
- fix(setEnv): remove debug from list @kiblik (#11374)
- feat(GHA): Add SHA pinning @kiblik (#11364)
- [docs] rename case-sensitive refs so that site builds correctly @paulOsinski (#11403)
- [docs] Pro Docs release notes - 2.41.1 @paulOsinski (#11402)
- [docs] add reo to script header @paulOsinski (#11396)
- Docs maintenance: remove external images, article QA + updates @paulOsinski (#11376)
- feat(parser: generic): Allow epss_* parameters @kiblik (#11293)
- Hotfix filenames @paulOsinski (#11368)
- fix(ruff): Fix RUF039 for v0.8.0 @kiblik (#11326)
- Update 2.36.md to fix typo's in version number @valentijnscholten (#11319)
- Ruff: Enable and fix RUF010 @kiblik (#11331)
- Ruff: Enable and fix RUF027 @kiblik (#11332)
- update Pro changelog 2.41.0 @paulOsinski (#11367)
- Request Review Notification Update to Usernames @hblankenship (#11295)
- Add a filter for Findings for Has Any JIRA (grouped or single) @hblankenship (#11313)
🚩 Changes to settings.dist.py
/ local_settings.py
- 🎉 Add CGA vulnid @manuel-sommer (#11441)
- Add Horusec Scan to Hashcode settings. @hblankenship (#11418)
- Qualys Hacker Guardian: Set Dedupe Config @Maffooch (#11442)
- fix(oauth2): google oauth2 whitelisting. @JGodin-C2C (#11372)
- 🐛 fix RHS deduplication @manuel-sommer (#11385)
- Settings SHA: The Removal @Maffooch (#11299)
- Add DTSA to vulnid @manuel-sommer (#11302)
- Add GLSA gentoo vulnid @manuel-sommer (#9813)
🚀 API features and enhancements
- Add Ordering to Test_Import API Endpoint @hblankenship (#11448)
- Allow None Option for Active/Verified on Import/Reimport to Mirror UI Options @hblankenship (#11447)
- Request/Response API CRUD Endpoints @hblankenship (#11365)
- Disallow multiple single-use notes on a single object @hblankenship (#11306)
- dissallow already linked issue @hblankenship (#11298)
🖌 Updates in UI
- Ruff: Add and fix S110 (+ merge all S1 rules) @kiblik (#11256)
- Add Filters to the Products under View Product Type @hblankenship (#11321)
- Update Reported Finding Severity by Month on the dashboard to be by month instead of day. @hblankenship (#11304)
- Add GLSA gentoo vulnid @manuel-sommer (#9813)
🧰 Maintenance
- Update dependency vite from 6.0.6 to v6.0.7 (docs/package.json) @renovate (#11494)
- Bump boto3 from 1.35.90 to 1.35.91 @dependabot (#11496)
- Bump python-gitlab from 5.2.0 to 5.3.0 @dependabot (#11475)
- Bump boto3 from 1.35.88 to 1.35.90 @dependabot (#11476)
- Bump boto3 from 1.35.87 to 1.35.88 @dependabot (#11473)
- Bump boto3 from 1.35.85 to 1.35.87 @dependabot (#11466)
- chore(deps): update dependency vite from 6.0.5 to v6.0.6 (docs/package.json) @renovate (#11471)
- Bump pdfmake from 0.2.16 to 0.2.17 in /components @dependabot (#11457)
- chore(deps): update dependency vite from 6.0.4 to v6.0.5 (docs/package.json) @renovate (#11445)
- Bump boto3 from 1.35.84 to 1.35.85 @dependabot (#11443)
- chore(deps): update dependency vite from 6.0.3 to v6.0.4 (docs/package.json) @renovate (#11439)
- Bump boto3 from 1.35.83 to 1.35.84 @dependabot (#11440)
- Bump python-gitlab from 5.1.0 to 5.2.0 @dependabot (#11438)
- Bump boto3 from 1.35.82 to 1.35.83 @dependabot (#11437)
- chore(deps): update actions/upload-artifact action from v4.4.3 to v4.5.0 (.github/workflows/fetch-oas.yml) @renovate (#11436)
- Bump boto3 from 1.35.81 to 1.35.82 @dependabot (#11434)
- Bump pycurl from 7.45.3 to 7.45.4 @dependabot (#11417)
- Bump nanoid from 3.3.7 to 3.3.8 in /docs @dependabot (#11421)
- Bump pdfmake from 0.2.15 to 0.2.16 in /components @dependabot (#11428)
- chore(deps): update docker/setup-buildx-action action from v3.7.1 to v3.8.0 (.github/workflows/release-x-manual-docker-containers.yml) @renovate (#11427)
- Bump vobject from 0.9.8 to 0.9.9 @dependabot (#11426)
- Bump boto3 from 1.35.78 to 1.35.81 @dependabot (#11425)
- fix(deps): update dependency @tabler/icons from 3.24.0 to v3.26.0 (docs/package.json) @renovate (#11423)
- chore(deps): update helm release postgresql from 16.2.5 to ~16.3.0 (helm/defectdojo/chart.yaml) @renovate (#11406)
- chore(deps): update mikefarah/yq action from v4.44.5 to v4.44.6 (.github/workflows/release-x-manual-helm-chart.yml) @renovate (#11409)
- chore(deps): update softprops/action-gh-release action from v2.1.0 to v2.2.0 (.github/workflows/release-x-manual-helm-chart.yml) @renovate (#11412)
- chore(deps): update gcr.io/cloudsql-docker/gce-proxy docker tag from 1.37.2 to v1.37.3 (helm/defectdojo/values.yaml) @renovate (#11411)
- chore(deps): update actions/cache action from v4.1.2 to v4.2.0 (.github/workflows/gh-pages.yml) @renovate (#11410)
- Bump boto3 from 1.35.76 to 1.35.78 @dependabot (#11407)
- Bump nginx from
5acf10c
to4152318
@dependabot (#11391) - chore(deps): update postgres:17.2-alpine docker digest from 17.2 to 17.2-alpine (docker-compose.yml) @renovate (#11397)
- Bump boto3 from 1.35.73 to 1.35.76 @dependabot (#11377)
- chore(deps): update dependency vite from 6.0.2 to v6.0.3 (docs/package.json) @renovate (#11380)
- chore(deps): update actions/configure-pages action from v4 to v5 (.github/workflows/gh-pages.yml) @renovate (#11329)
- fix(deps): update dependency @tabler/icons from 3.23.0 to v3.24.0 (docs/package.json) @renovate (#11360)
- chore(deps): update nginx/nginx-prometheus-exporter docker tag from 1.3.0 to v1.4.0 (helm/defectdojo/values.yaml) @renovate (#11373)
- chore(deps): update dependency prettier from 3.4.1 to v3.4.2 (docs/package.json) @renovate (#11370)
- Bump redis from 5.2.0 to 5.2.1 @dependabot (#11381)
- Bump django from 5.1.3 to 5.1.4 @dependabot (#11378)
- Bump drf-spectacular from 0.27.2 to 0.28.0 @dependabot (#11352)
- Bump boto3 from 1.35.71 to 1.35.73 @dependabot (#11362)
- Bump nginx from 1.27.2-alpine to 1.27.3-alpine @dependabot (#11355)
- Bump drf-spectacular-sidecar from 2024.11.1 to 2024.12.1 @dependabot (#11354)
- chore(deps): update dependency vite from 6.0.1 to v6.0.2 (docs/package.json) @renovate (#11351)