Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.
Changes since 3.3.100
- Update MCP documentation @mtesauro (#15987)
- docs(connectors): correct Aqua Supply Chain branch guidance (pinning is not the fix) @Maffooch (#16022)
- docs(fda): component support metadata and the cyber device evidence pack @devGregA (#16017)
- fix(location): resolve location_type/location_value filters through the location FK @Maffooch (#16020)
- fix(govulncheck): don't crash on OSV entries without aliases @Tatamis (#16014)
- docs: the Command Center is the DefectDojo Pro home page @blakeaowens (#16018)
- docs(dashboards): the Command Center scene @blakeaowens (#16015)
- docs(sensei): document the Tier Advisor @devGregA (#16010)
- docs(pci): document PCI DSS evidence packs @devGregA (#16011)
- docs(asset_modelling): framework presets page @devGregA (#16007)
- docs: vulnerability response policies on the priority and SLA page @devGregA (#16008)
- docs(pci): document PCI DSS scan and ASV evidence @devGregA (#16006)
- docs(connectors): clarify Aqua Supply Chain imports default + pinned branches only @Maffooch (#16005)
- Keep finding group members inside the group's test @svader0 (#15946)
- docs: add CRA and DORA evidence packs @devGregA (#15996)
- feat(locations): container scanners emit the scanned image as an Image location @blakeaowens (#15999)
- docs(psirt): CRA Article 14 reporting page @devGregA (#16004)
- docs: add a FedRAMP PAIN ratings setup walkthrough @skywalke34 (#16000)
- docs(onprem): give the forward-proxy page a sidebar and fix on-prem section ordering @Maffooch (#16003)
- docs(onprem): document trusting an internal or private CA @Maffooch (#16001)
- Scope engineer metrics to the requester's authorized findings @svader0 (#15945)
- docs(locations): Container Image Locations, image to repository link, suggested hierarchy edges @blakeaowens (#15979)
- docs(triage_engine): document the import triggers and the report scope built for them @blakeaowens (#15965)
- fix(api v3): resolve the import target before the auto-create permission check @svader0 (#15997)
- docs(reports): document the chart-block Date Range setting @Maffooch (#15998)
- docs: explain Sensei schedules and scan cadence policies @devGregA (#15994)
- Tie the API token to the forced-password-reset state @svader0 (#15954)
- Fix finding group list visibility for product members @adilalperenciftci (#15961)
- Fix crash bugs in KICS, AppSpider, KubeHunter, Terrascan, TFSec, and ZAP parsers @Jaimin2687 (#15958)
- fix(api v3): resolve the import target consistently in the auto permission check @svader0 (#15988)
- Route the v3 notes list through the shared note-visibility helper @svader0 (#15985)
- Fix Nuclei deduplication for protocol-less URLs @Jaimin2687 (#15957)
- fix(files): return 404 instead of 500 when an uploaded file is missing on disk @Maffooch (#15960)
- docs(pro): PCI DSS scope, patch clock, and scope inventory @devGregA (#15966)
- docs(onprem): hardware-sizing tuning knobs + deep-link edition routing @Maffooch (#15986)
- docs: threat-intelligence (EPSS/KEV) fields are editable on the Add/Edit Finding form @Maffooch (#15984)
- docs: rename Rules Engine 2.0 to Triage Engine @Maffooch (#15989)
- docs(connectors): document Microsoft Defender device-group filtering @Maffooch (#15991)
- docs(connectors): clarify Aqua Supply Chain's two hosts and the 405 @Maffooch (#15992)
- docs(feature-flags): a restart now applies the Locations and Relabeling toggles to the Classic UI and /api/v2 @Maffooch (#15990)
- docs(sensei): AI Agent Red Teaming capability page @Maffooch (#15983)
- docs(onprem): split Pro on-prem docs into Kubernetes and Docker Compose sections @Maffooch (#15959)
- docs(sensei): document Dynamic Scanning (DAST) @Maffooch (#15948)
- docs(changelog): expand the Pro 3.3.100 release notes @Maffooch (#15955)
- docs(connectors): document the Qualys create_endpoints toggle @paulOsinski (#15933)
🚩 Changes to settings.dist.py / local_settings.py
- perf: debounce product grade recalculation per product @devGregA (#16016)
- fix(api): return a clear 400 when a scan import exceeds upload limits @Maffooch (#15993)
🚀 General features and enhancements
🐛 Bug Fixes
- fix(location): map created_at/updated_at API filters to created/updated model fields @Maffooch (#15995)
- fix(fixtures): ship the asset attribute option rows in the sample-data fixtures @Jino-T (#15982)
- fix(api): return a clear 400 when a scan import exceeds upload limits @Maffooch (#15993)
🖌 Updates in UI
- perf: debounce product grade recalculation per product @devGregA (#16016)
- Harden text rendering in the classic confirm dialogs @svader0 (#15952)
- Scope classic search and endpoint report reads of shared location tags @svader0 (#15981)
- docs(connectors): document the Aqua per-branch deduplication setting @svader0 (#15917)
🗣 Updates in localization
🧰 Maintenance
- chore(deps): bump nanoid from 3.3.16 to 3.3.19 in /docs @dependabot[bot] (#15949)