github DefectDojo/django-DefectDojo 3.1.305
3.1.305 🌈

5 hours ago

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 3.1.303

  • docs(compliance): Federal Compliance section (FedRAMP POA&M, ConMon, CMMC, control coverage) @devGregA (#15453)
  • Harden user account management authorization @svader0 (#15454)
  • Scope the report endpoint prefetch to the requesting user's findings @svader0 (#15435)
  • Scope endpoint and host view findings to the requesting user @svader0 (#15441)
  • Scope API scan configuration tool selection to authorized tool configurations @svader0 (#15445)
  • Align id-keyed questionnaire routes with engagement permissions @svader0 (#15449)
  • docs: Threat Intelligence page (DefectDojo Pro) @devGregA (#15450)
  • Scope the product endpoint report to the requested product @svader0 (#15451)
  • docs(onprem): document migrating from open source to self-hosted Pro @devGregA (#15452)

🐛 Bug Fixes

  • fix(generic parser): ignore non-numeric values in numeric JSON fields @Maffooch (#15442)
  • fix(importers): keep the reimport target test when a report declares no tests @Maffooch (#15446)

🖌 Updates in UI

  • fix(search): render result panes, open the right tab, survive bad input @Maffooch (#15448)

Don't miss a new django-DefectDojo release

NewReleases is sending notifications on new releases.