github DefectDojo/django-DefectDojo 3.1.301
3.1.301 🌈

4 hours ago

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 3.1.300

  • fix(dedupe): re-point chained duplicates before deleting excess ones (backport of #15364) @Maffooch (#15383)
  • fix(finding): carry locations across a finding merge @Maffooch (#15379)
  • Harden metadata API object authorization @svader0 (#15380)
  • docs(jira): document enabling the Jira integration in System Settings @Maffooch (#15381)
  • docs(sso): document the attribute-mapping editors and OIDC group mapping @Maffooch (#15373)
  • [docs] maintenance @paulOsinski (#15371)
  • Apply the member-management check on every serializer exposing the field @svader0 (#15375)
  • docs: add Pro changelog entry for 3.1.300 @Maffooch (#15369)
  • Restrict JIRA finding-mapping project field to authorized projects @svader0 (#15355)
  • Docs: clarify that the Jira webhook secret authenticates incoming requests @svader0 (#15368)
  • Restrict bulk update target finding group to authorized groups @svader0 (#15356)

🚀 API features and enhancements

  • fix(api): return a validation error instead of 500 when environment is omitted @devGregA (#15367)

🐛 Bug Fixes

  • fix(risk_acceptance): stop the expiration job aborting on an unattached risk acceptance @Maffooch (#15376)

🖌 Updates in UI

  • Harden finding and engagement UI actions to require POST @svader0 (#15372)

🧰 Maintenance

Don't miss a new django-DefectDojo release

NewReleases is sending notifications on new releases.