github DefectDojo/django-DefectDojo 3.2.400
3.2.400 🌈

3 hours ago

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 3.2.300

  • docs: finish the N.0 feature naming migration and repair the mangled relabel copy @blakeaowens (#15829)
  • fix(url): parse a bare (unbracketed) IPv6 host @Maffooch (#15824)
  • docs(correlation): Root Cause asset/organization columns, filters, and drill-in @Maffooch (#15827)
  • docs: clarify Prioritization Engine semantics, threshold recommendations, and Risk-based SLA behavior @paulOsinski (#15823)
  • docs(sensei): note AI agent skill scanning @Maffooch (#15822)
  • docs(navigation): document searching the sidebar menu @blakeaowens (#15816)
  • docs(rules_engine_2): KEV and exploit evidence condition fields @blakeaowens (#15815)
  • backport(importers): make bulk_new_finding_writes functional on 3.2.x @devGregA (#15770)
  • fix(api): return a boolean from endpoint_status mitigated under V3 Locations @svader0 (#15811)
  • docs(mcp): state that active_* summary counts ignore verified status @Jino-T (#15793)
  • Align authorization queryset filters with the object-level permission check @svader0 (#15783)
  • fix(jira): gate the legacy endpoints block in the classic issue templates @svader0 (#15810)
  • Apply the global template gate to the add-from-template listing @svader0 (#15781)
  • Validate the request body on a finding metadata PUT @svader0 (#15785)
  • fix(reimporter): drain the last partial batch however the loop ended @devGregA (#15762)
  • docs(pro): engagement checklists in the Pro UI @blakeaowens (#15814)
  • Add Pro+OS Environments documentation (plus other docs updates) @dangoelz (#15765)
  • docs(sensei): document inline repo association and the locate-the-file fix flow @Maffooch (#15794)
  • docs(rules_engine_2): document the SLA configuration and Risk Priority asset actions @svader0 (#15788)
  • Scope engagement related-object choices to the caller's authorized queryset @svader0 (#15792)
  • Scope endpoint list filters to the requesting product's references @svader0 (#15760)
  • Validate the Jira epic action body and reject reserved dispatch kwargs @svader0 (#15782)
  • add RSS feed to changelog @paulOsinski (#15812)
  • docs(pro): custom fields on the create and edit forms @blakeaowens (#15789)
  • changelog @paulOsinski (#15790)

🚩 Database migration

  • fix(findings): store review-request notes public so reviewers can read them @blakeaowens (#15818)

🚀 API features and enhancements

  • fix(api): answer 410 rather than 500 when a v2 route reaches a deprecated Endpoint @svader0 (#15809)

🐛 Bug Fixes

  • fix(auth): don't 500 on SAML single-logout when session user is gone @Maffooch (#15820)

🖌 Updates in UI

  • Scope Location tag reads to the caller's own products @svader0 (#15784)

Don't miss a new django-DefectDojo release

NewReleases is sending notifications on new releases.