github DefectDojo/django-DefectDojo 3.3.0
3.3.0 🌈

2 hours ago

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 3.2.400

  • test(integration): wait for DataTables before clicking engagement links to fix a stale-element flake @blakeaowens (#15882)
  • fix(unittests): pin the rate-limit window in test_api_token_auth_is_rate_limited @blakeaowens (#15883)
  • docs(shell): sidebar rail (collapse, flyouts, unified Global Search, badge icons) @blakeaowens (#15871)
  • fix(unittests): stop leaking a crum current-user override across tests @blakeaowens (#15880)
  • docs(mcp): document tag filtering on the findings tools @Maffooch (#15877)
  • docs: document the /api/v2/ Custom Fields API and stop pointing automation at /api/vue @Maffooch (#15876)
  • Pin outbound connections to an already-checked address @svader0 (#15835)
  • fix(fortify): only flag suppressed FPR findings as false_p (reimport closing all findings) @BrunoTerres (#15839)
  • docs(engagements): explain the locked Asset field and its copy button @Jino-T (#15873)
  • fix(product): defer list count annotations @kocaemre (#15447)
  • docs(connectors): JFrog artifact mode scopes nested child images to their own latest build @paulOsinski (#15868)
  • fix(login): render login page when the Site row for SITE_ID is missing @Maffooch (#15843)
  • fix(parser): make xeol severity parsing deterministic without wall clock @P6-36-216 (#15813)
  • Remove the redundant table-wide file cleanup from the manage-files view @svader0 (#15836)
  • docs: match the Pro UI's renamed buttons and Email labels @blakeaowens (#15870)
  • feat(api-v3): let a downstream distribution supply the assets router's write schemas @valentijnscholten (#15826)
  • docs(feature-flags): restart tag clears after a restart; mark data migrations complete @Maffooch (#15872)
  • docs(connectors): location inventory from asset connectors @svader0 (#15838)
  • refactor(importers): one existence lookup for findings deleted mid-import @valentijnscholten (#15825)
  • Set finding mitigation from Dependency Track affected version ranges @webdevred (#15366)
  • refactor(importers): extract the import-history write into an overridable hook @Maffooch (#15866)
  • update changelog @paulOsinski (#15844)
  • fix(parsers): drop unique ids that repeat within a report (SARIF family, Generic JSON) @devGregA (#15817)
  • docs(connectors): explain the two wiz data classes and the import filter @svader0 (#15791)
  • docs(assets): document the Bulk Edit action on the All Assets list @paulOsinski (#15787)
  • docs(organizations): the type-scoped grants UI @devGregA (#15764)
  • docs: 3.3.x upgrade notes for the three deduplication identity changes @devGregA (#15761)
  • docs(connectors): Wiz imports without Projects via a tenant-level Record @svader0 (#15752)
  • docs(connectors): document GitHub issue import on the GHAS connector @devGregA (#15755)
  • docs: Fix typos @9alexx3 (#15747)
  • docs: asset exposure and deployment context @devGregA (#15679)
  • docs: notifications follow every organization membership @devGregA (#15628)
  • docs(connectors): document the data-visibility warnings @svader0 (#15634)
  • docs(notifications): document the Connector Health Warning notification @svader0 (#15646)
  • docs(organizations): roles scoped to an organization type @devGregA (#15673)
  • docs(connectors): note that Location is pre-filled for single-host tools @svader0 (#15714)
  • docs(federal): document PAIN-keyed FedRAMP VDR remediation deadlines @devGregA (#15719)
  • docs(rules-engine-2): document the missing-scan trigger @devGregA (#15731)
  • docs(psirt): Feed Rules, the no-SBOM matching path, and advisory-to-case @devGregA (#15735)
  • docs(rules-engine-2): document exploit-evidence, reachability and asset-exposure condition fields @devGregA (#15713)
  • fix: Add CISA KEV date parsing for Anchore Grype parser @Kasyap7 (#15730)
  • docs(psirt): who can use PSIRT, and why the permission beats the role @devGregA (#15741)
  • docs(assets): how to reach Asset Versions and per-version claims in the UI @devGregA (#15670)
  • docs(asset-hierarchy): relationship types, and direct vs indirect vulnerabilities @devGregA (#15672)
  • docs: where to find Asset types and aliases in the UI (asset model Phase 4) @devGregA (#15645)
  • refactor(dedupe): one definition of the location prefetch @valentijnscholten (#15520)
  • fix(dedupe): order locations/endpoints inside hash_code, and catch set-order leaks in parsers @valentijnscholten (#15513)
  • refactor(importers): track reimport finding buckets by id, not instance @valentijnscholten (#15600)
  • refactor(importers): extract persist_new_findings as a bulk-write seam @valentijnscholten (#15599)
  • docs: asset kinds and per-source asset aliases @devGregA (#15633)
  • docs: asset versions, BOM snapshots, and per-version SBOM/VEX export @devGregA (#15629)
  • fix(ci): drop duplicated db-snapshot steps that make dev's unit test suite unrunnable @devGregA (#15614)
  • refactor(reimporter): a seam for deferring the new-finding write @devGregA (#15621)
  • docs: organization types + non-exclusive membership @devGregA (#15619)
  • refactor(importers): reconcile a finding's child rows before the finding is written @devGregA (#15620)
  • refactor(locations): let locations be recorded before the finding is written @devGregA (#15597)
  • docs(sensei): add the Sensei Advisor page @devGregA (#15594)
  • feat(locations): make the endpoint->location migration resumable and memory-bounded @devGregA (#15590)
  • perf(locations): clean and stringify each URL location once per import @devGregA (#15588)
  • docs(connectors): a connector's field mappings can be customised per scan type @devGregA (#15579)
  • docs(universal parser): document editing field mappings from the UI @devGregA (#15583)
  • docs: the sidebar page now covers the whole menu, not just Settings @devGregA (#15591)
  • docs: Exporting SBOMs and VEX (Pro) @devGregA (#15584)
  • docs(psirt): PSIRT module documentation @devGregA (#15555)
  • docs: DISA STIG checklist import and the CCI control crosswalk @devGregA (#15571)
  • docs(notifications): note where notification settings live in the Pro UI @Maffooch (#15567)
  • docs(universal parser): field mappings can be edited, with identity classified and versioned @devGregA (#15556)
  • fix(reimporter): always dispatch the final post-processing batch @devGregA (#15548)
  • ci: port the bugfix CI stack to dev @devGregA (#15549)
  • refactor(finding): extract save()'s field derivation so batched writers can reuse it @devGregA (#15489)

🚩 Changes to settings.dist.py / local_settings.py

  • fix(importers): accept .spdx files for scan import @Maffooch (#15875)
  • Add Aqua Supply Chain connector docs and dedup registration @svader0 (#15874)
  • Add Seal Security CSV parser @amita-seal (#15592)
  • chore(deps): switch django-tagulous from fork to upstream 2.2.2 @valentijnscholten (#15828)
  • Add Open Pentest Format (OPF) parser @Su1ph3r (#15558)
  • fix(dedupe): give Checkmarx Scan detailed a hash_code field list @devGregA (#15580)
  • feat: API v3 (alpha) — parallel /api/v3-alpha/ with slim refs, expand, and a tested query-count contract @valentijnscholten (#15304)
  • fix(dedupe): hash Checkmarx One on the vendor id it already matches on @devGregA (#15663)
  • fix(dedupe): stop Xeol finding identity depending on the wall clock @devGregA (#15658)
  • feat(i18n): full platform internationalization with per-user language selection @devGregA (#15622)
  • feat(parsers): fifteen new file-import parsers @devGregA (#15611)
  • feat(parsers): add 39 file-import parsers (with tests, fixtures, and docs) @devGregA (#15595)
  • feat(api-tokens): API token expiry and revoke-by-key endpoint @svader0 (#14932)
  • refactor(ui): remove the classic Bootstrap UI @Maffooch (#15565)
  • feat(parsers): add fifty-six file parsers for vendors with no importer @devGregA (#15482)

🚩 Database migration

  • feat(risk-acceptance): add option to restore Verified when a Risk Acceptance expires @Maffooch (#15878)
  • feat(product): editable platform/lifecycle/origin lookup tables @Maffooch (#15869)
  • chore(deps): switch django-tagulous from fork to upstream 2.2.2 @valentijnscholten (#15828)
  • fix(migrations): make the ui_use_tailwind removal idempotent @Maffooch (#15842)
  • perf(finding): drop four dojo_finding indexes that no query uses @devGregA (#15659)
  • feat(i18n): full platform internationalization with per-user language selection @devGregA (#15622)
  • feat(api-tokens): API token expiry and revoke-by-key endpoint @svader0 (#14932)
  • refactor(ui): remove the classic Bootstrap UI @Maffooch (#15565)

🚀 General features and enhancements

  • Allow a false-positive-history candidate hook to supply candidates, not only narrow them @devGregA (#15502)

🚀 API features and enhancements

🐛 Bug Fixes

  • fix(importers): accept scan severities case-insensitively @Maffooch (#15864)
  • fix(locations): tolerate concurrent creation in bulk_get_or_create @Maffooch (#15845)
  • fix(engagement): allow saving engagements with an empty status @Maffooch (#15472)

📝 Documentation updates

  • docs(connectors): Rapid7 InsightVM - Cloud Instance connector reference @Maffooch (#15867)

🖌 Updates in UI

  • feat(risk-acceptance): add option to restore Verified when a Risk Acceptance expires @Maffooch (#15878)
  • chore(ui): improve readability of the version in the footer @nisnopa (#15863)
  • feat(product): editable platform/lifecycle/origin lookup tables @Maffooch (#15869)
  • feat: API v3 (alpha) — parallel /api/v3-alpha/ with slim refs, expand, and a tested query-count contract @valentijnscholten (#15304)
  • feat(i18n): full platform internationalization with per-user language selection @devGregA (#15622)
  • feat(api-tokens): API token expiry and revoke-by-key endpoint @svader0 (#14932)
  • refactor(ui): remove the classic Bootstrap UI @Maffooch (#15565)

🗣 Updates in localization

  • feat(i18n): full platform internationalization with per-user language selection @devGregA (#15622)

🔧 Improved code quality with linters

  • ci(migrations): bring the migration graph check to dev @devGregA (#15504)

🧰 Maintenance

69 changes
  • chore(deps): bump ruff from 0.16.4 to 0.16.5 @dependabot[bot] (#15856)
  • chore(deps): bump djangorestframework from 3.17.1 to 3.17.2 @dependabot[bot] (#15846)
  • chore(deps): bump gitpython from 3.1.59 to 3.1.61 @dependabot[bot] (#15859)
  • chore(deps): bump @scalar/api-reference from 1.66.1 to 1.67.0 in /components @dependabot[bot] (#15858)
  • chore(deps): bump browserslist from 4.28.1 to 4.28.8 in /docs @dependabot[bot] (#15849)
  • chore(deps): bump postcss-selector-parser from 6.1.2 to 6.1.4 in /docs @dependabot[bot] (#15850)
  • chore(deps): update valkey docker tag from 0.25.5 to v0.25.8 (helm/defectdojo/chart.yaml) @renovate[bot] (#15860)
  • chore(deps): update python:3.14.7-alpine3.23 docker digest from 3.14.7 to 3.14.7-alpine3.23 (dockerfile.nginx-alpine) @renovate[bot] (#15852)
  • chore(deps): update valkey/valkey docker tag from 9.1.1 to v9.1.2 (docker-compose.yml) @renovate[bot] (#15861)
  • chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) @renovate[bot] (#15853)
  • chore(deps): update dependency renovatebot/renovate from 44.47.0 to v44.61.5 (.github/workflows/renovate.yaml) @renovate[bot] (#15830)
  • chore(deps): bump cryptography from 50.0.0 to 50.0.1 @dependabot[bot] (#15857)
  • chore(deps): update softprops/action-gh-release action from v3.0.2 to v3.0.3 (.github/workflows/release-x-manual-helm-chart.yml) @renovate[bot] (#15855)
  • chore(deps): update losisin/helm-values-schema-json-action digest from v3.2.0 to v3 (.github/workflows/test-helm-chart.yml) @renovate[bot] (#15848)
  • chore(deps): update losisin/helm-docs-github-action digest from v2.0.1 to v2 (.github/workflows/test-helm-chart.yml) @renovate[bot] (#15847)
  • chore(deps): bump lxml from 6.1.1 to 6.1.2 @dependabot[bot] (#15803)
  • chore(deps): bump django-ninja from 1.6.2 to 1.6.3 @dependabot[bot] (#15801)
  • chore(deps): update dependency renovatebot/renovate from 44.33.2 to v44.47.0 (.github/workflows/renovate.yaml) @renovate[bot] (#15766)
  • Release drafter: exclude release-train merge PRs from release notes @rossops (#15780)
  • chore(deps): bump @scalar/api-reference from 1.65.1 to 1.66.1 in /components @dependabot[bot] (#15806)
  • chore(deps): bump pygithub from 2.9.1 to 2.10.0 @dependabot[bot] (#15805)
  • chore(deps): bump vulners from 4.0.1 to 4.3.0 @dependabot[bot] (#15802)
  • chore(deps): bump ruff from 0.16.3 to 0.16.4 @dependabot[bot] (#15800)
  • chore(deps): update openapitools/openapi-generator-cli docker tag from v7.24.0 to v7.25.0 (dockerfile.integration-tests-debian) @renovate[bot] (#15799)
  • chore(deps): update dependency kubernetes/kubernetes from v1.35.7 to v1.35.8 (.github/workflows/k8s-tests.yml) @renovate[bot] (#15798)
  • chore(deps): update dependency kubernetes from 1.34.10 to v1.34.11 (.github/workflows/k8s-tests.yml) @renovate[bot] (#15796)
  • chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) @renovate[bot] (#15795)
  • docs: restore eight markdown links mangled into NUL bytes @devGregA (#15756)
  • chore(deps): update valkey/valkey:9.1.1-alpine docker digest from 9.1.1 to 9.1.1-alpine (docker-compose.yml) @renovate[bot] (#15744)
  • chore(deps): update nginx/nginx-prometheus-exporter docker tag from 1.5.1 to v1.5.3 (helm/defectdojo/values.yaml) @renovate[bot] (#15720)
  • chore(deps): update gcr.io/cloudsql-docker/gce-proxy docker tag from 1.38.2 to v1.38.3 (helm/defectdojo/values.yaml) @renovate[bot] (#15718)
  • chore(deps): update valkey docker tag from 0.25.4 to v0.25.5 (helm/defectdojo/chart.yaml) @renovate[bot] (#15721)
  • chore(deps): update dependency django-debug-toolbar from 7.1.0 to v7.1.1 (requirements-dev.txt) - autoclosed @renovate[bot] (#15717)
  • chore(deps): bump ruff from 0.16.2 to 0.16.3 @dependabot[bot] (#15722)
  • chore(deps): bump vulners from 4.0.0 to 4.0.1 @dependabot[bot] (#15723)
  • chore(deps-dev): bump django-debug-toolbar from 7.1.0 to 7.1.1 @dependabot[bot] (#15724)
  • chore(deps): bump @scalar/api-reference from 1.63.0 to 1.65.1 in /components @dependabot[bot] (#15725)
  • chore(deps): bump gitpython from 3.1.58 to 3.1.59 @dependabot[bot] (#15726)
  • chore(deps): bump sqlalchemy from 2.0.51 to 2.0.52 @dependabot[bot] (#15727)
  • chore(deps): bump django-permissions-policy from 4.32.0 to 4.33.0 @dependabot[bot] (#15728)
  • chore(deps): update postgres docker tag from 18.4 to v18.6 (docker-compose.yml) @renovate[bot] (#15729)
  • chore(deps): update docker/setup-buildx-action action from v4.2.0 to v4.3.0 (.github/workflows/release-x-manual-tag-as-latest.yml) @renovate[bot] (#15734)
  • chore(deps): update dependency renovatebot/renovate from 44.30.1 to v44.33.2 (.github/workflows/renovate.yaml) @renovate[bot] (#15680)
  • chore(deps): update python:3.14.7-alpine3.23 docker digest from 3.14.7 to 3.14.7-alpine3.23 (dockerfile.nginx-alpine) @renovate[bot] (#15647)
  • chore(deps): update dependency renovatebot/renovate from 44.14.3 to v44.30.1 (.github/workflows/renovate.yaml) @renovate[bot] (#15585)
  • chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) @renovate[bot] (#15648)
  • chore(deps): bump gitpython from 3.1.57 to 3.1.58 @dependabot[bot] (#15639)
  • chore(deps): update release-drafter/release-drafter action from v7.5.1 to v7.7.0 (.github/workflows/release_drafter_valentijn.yml) @renovate[bot] (#15635)
  • chore(deps): update valkey docker tag from 0.25.0 to v0.25.4 (helm/defectdojo/chart.yaml) @renovate[bot] (#15630)
  • chore(deps): bump django-htmx from 1.28.0 to 1.29.0 @dependabot[bot] (#15637)
  • chore(deps): update dependency django-debug-toolbar from 7.0.0 to v7.1.0 (requirements-dev.txt) @renovate[bot] (#15631)
  • chore(deps): bump setuptools from 83.0.0 to 84.0.0 @dependabot[bot] (#15638)
  • chore(deps): bump ruff from 0.16.1 to 0.16.2 @dependabot[bot] (#15643)
  • chore(deps): bump djangorestframework from 3.17.1 to 3.18.0 @dependabot[bot] (#15644)
  • chore(deps): bump cryptography from 49.0.0 to 50.0.0 @dependabot[bot] (#15541)
  • chore(deps): bump django-crispy-forms from 2.6 to 2.7 @dependabot[bot] (#15534)
  • chore(deps): update dependency node from 24.18.1 to v24.19.0 (.github/workflows/validate_docs_build.yml) @renovate[bot] (#15527)
  • chore(deps): bump drf-spectacular-sidecar from 2026.7.1 to 2026.8.1 @dependabot[bot] (#15542)
  • chore(deps): bump pyopenssl from 26.3.0 to 26.4.0 @dependabot[bot] (#15535)
  • chore(deps): bump ruff from 0.16.0 to 0.16.1 @dependabot[bot] (#15543)
  • chore(deps): bump markdown from 3.10.2 to 3.10.3 @dependabot[bot] (#15540)
  • chore(deps): update python docker tag from 3.14.6 to v3.14.7 (dockerfile.nginx-alpine) @renovate[bot] (#15546)
  • chore(deps): update dependency django-test-migrations from 1.5.0 to v1.6.0 (requirements-dev.txt) @renovate[bot] (#15544)
  • chore(deps): bump django-polymorphic from 4.11.6 to 4.11.7 @dependabot[bot] (#15538)
  • chore(deps): bump redis from 8.0.1 to 8.1.0 @dependabot[bot] (#15536)
  • chore(deps): update valkey docker tag from 0.24.6 to v0.25.0 (helm/defectdojo/chart.yaml) @renovate[bot] (#15532)
  • chore(deps): update dependency renovatebot/renovate from 43.288.0 to v44 (.github/workflows/renovate.yaml) @renovate[bot] (#15473)
  • chore(deps): update dependency node from 24.18.0 to v24.18.1 (.github/workflows/validate_docs_build.yml) @renovate[bot] (#15526)
  • chore(deps): bump pillow from 12.2.0 to 12.3.0 @dependabot[bot] (#15302)

Don't miss a new django-DefectDojo release

NewReleases is sending notifications on new releases.