github DefectDojo/django-DefectDojo 3.4.0
3.4.0 🌈

3 hours ago

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 3.3.300

  • docs(compliance): document supporting files on regulatory obligations @Jino-T (#16168)
  • docs(findings): move or copy findings to another test @Jino-T (#16098)
  • Add docs on MCP PSIRT toolset @empty-usr (#16129)
  • docs: recapture Pro UI screenshots for the Menu 2.0 sidebar @paulOsinski (#16128)
  • docs: update Pro navigation instructions for the Menu 2.0 sidebar @paulOsinski (#16116)
  • Docs: change plans, review every hierarchy change before it happens @devGregA (#16191)
  • Docs: Security Hub account parents, OU and account tag placement, and re-placing existing assets @devGregA (#16190)
  • docs(connectors): describe the Checkmarx One Result States filter @svader0 (#16134)
  • docs(pci dss): the regulatory profile opens on Regulatory Profile or PCI DSS @Maffooch (#16174)
  • Docs: container image repositories as shared asset identity @devGregA (#16196)
  • Docs: plan your hierarchy, and what reorganizing later changes @devGregA (#16195)
  • Docs: asset grouping for Defender for Cloud, Prowler, Google Cloud SCC and Lacework connectors @devGregA (#16194)
  • Docs: finish onboarding with the assets needing attention list @devGregA (#16193)
  • Docs: computed destinations and connector attributes in Rules Engine asset actions @devGregA (#16192)
  • docs(locations): describe the Location page's Custom Fields card and Referenced by table @Maffooch (#16183)
  • docs(connectors): document the Backstage lifecycle and owner-description sync @Maffooch (#16182)
  • Docs: what happens to imported findings when a connector record is re-mapped @devGregA (#16181)
  • docs(connectors): document the Defender "Consolidate Findings by Vulnerability" option @paulOsinski (#16169)
  • docs(locations): cloud resource drift matching and the endpoint migration boundary @svader0 (#16032)
  • docs(risk-acceptance): describe the Exception Requested finding-table column @paulOsinski (#16031)
  • Docs: moving assets between organizations and the bulk update API @devGregA (#16180)
  • Docs: Security Hub connector asset grouping and organization placement @devGregA (#16179)
  • docs(connectors): document the Microsoft Azure asset connector @svader0 (#15841)
  • docs(page-layouts): the Asset and Organization record cards are widgets @blakeaowens (#16197)
  • docs(risk-acceptance): use the hyphenated Pro UI path in the webhook example @blakeaowens (#16198)
  • docs(sandbox): the Pro sandbox, and turning it on self-hosted @blakeaowens (#16185)
  • docs(webhook gateway): the database role is named after the database @blakeaowens (#16184)
  • docs(dashboards): Command Center rows and the teal secondary color @blakeaowens (#16172)
  • Helm: add the chart repo from charts.defectdojo.com, with a privacy notice @devGregA (#16178)
  • docs(sso): note that a saved client secret is not shown again @devGregA (#16124)
  • docs(sensei): note that a new API base URL needs the key again @devGregA (#16126)
  • Add CODE_OF_CONDUCT.md @devGregA (#16165)
  • docs(sensei): say who can run a /fix comment @devGregA (#16125)
  • docs: correct pre-pay savings on Contact Sales to 48% @devGregA (#16123)
  • Docs: describe open-source authentication and access accurately @devGregA (#16166)
  • docs: say what registry.defectdojo.com logs next to the Compose install steps @devGregA (#16176)
  • Pull the Docker Compose images through registry.defectdojo.com @devGregA (#16121)
  • docs(triage-engine): webhook receivers and Jira two-way sync @blakeaowens (#16060)
  • Google Cloud Artifact Scan: handle vulnerabilities without relatedUrls @anthonwellsjo (#16167)
  • docs(pro): point the support docs at the Support page @svader0 (#16118)
  • Update sample data @github-actions[bot] (#16155)
  • docs(connectors): document the Google Cloud asset connector @svader0 (#16113)
  • docs(compliance): walk through CRA evidence packs end to end @skywalke34 (#16159)
  • docs(report builder): Location per Asset blocks and Asset/Organization name columns @Maffooch (#16136)
  • docs(dashboards): a duplicated Section Break keeps its title, which can be blank @Maffooch (#16119)
  • docs(connectors): document the Checkmarx One Tag Findings With Scan ID option @Jino-T (#16153)
  • docs(pro): describe the Support pages, the docs search and the airgapped setting @svader0 (#15925)
  • docs(crowdstrike): say which CID the Falcon API client must be created in @Maffooch (#16120)
  • CycloneDX: keep component.type on dependency locations; AI Inventory docs @Maffooch (#16135)
  • Return the v2 nested user shape from API v3 expand @svader0 (#16112)
  • fix(base_models): make the model save hook sequence atomic @svader0 (#15732)
  • docs(metrics): Insights dashboards remember the last applied timeframe @blakeaowens (#16157)
  • docs(reporting): widget blocks honor template variables @blakeaowens (#16117)
  • ci(docs): hold dev docs deploys until bugfix is retired @Maffooch (#16131)
  • Retire the bugfix branch: every release is cut from dev @Maffooch (#16086)
  • docs(markdown editor): add images to markdown fields through the API @blakeaowens (#16105)
  • docs: cross-tool deduplication explainer, llms.txt, sitemap lastmod @devGregA (#16122)
  • docs: load DefectDojo's own developer-activity tracker next to Reo @devGregA (#16114)
  • fix(sonatype): handle null componentIdentifier instead of failing the import @skywalke34 (#16101)
  • docs(changelog): add DefectDojo Pro 3.3.300 release notes @Maffooch (#16111)
  • perf(api): eliminate N+1 queries in product and asset list endpoints @Jaimin2687 (#16037)
  • docs(site): rebrand docs.defectdojo.com to the 2026 brand (Earth Undertones) @devGregA (#15736)
  • docs: retire the PSIRT 1.x sidecar from the Pro on-prem guides and document the migration @devGregA (#15964)

🚀 General features and enhancements

🚀 API features and enhancements

  • fix(metadata): authorize the location_product scope on location metadata @Maffooch (#16170)
  • fix(metadata): accept location-only payloads and persist the product scope; document the Location page @paulOsinski (#16152)

🐛 Bug Fixes

  • fix(metadata): authorize the location_product scope on location metadata @Maffooch (#16170)
  • fix(user api): remove N+1 on the users list endpoint @Maffooch (#16127)
  • fix(locations): return location_type and location_value on reference endpoints @Maffooch (#16130)
  • fix(metadata): accept location-only payloads and persist the product scope; document the Location page @paulOsinski (#16152)

🖌 Updates in UI

🧰 Maintenance

48 changes
  • test: use the memory broker for local unit tests; fix the lost webhook checkbox click @Maffooch (#16171)
  • chore(deps): bump @babel/core from 7.29.0 to 7.29.7 in /docs @dependabot[bot] (#16107)
  • chore(deps): bump django from 5.2.16 to 5.2.17 @dependabot[bot] (#16164)
  • chore(deps): bump sqlalchemy from 2.0.54 to 2.1.1 @dependabot[bot] (#16143)
  • chore(deps): bump pyjwt from 2.14.0 to 2.15.0 @dependabot[bot] (#16145)
  • chore(deps): bump markdown from 3.10.3 to 3.11 @dependabot[bot] (#16146)
  • chore(deps): bump @scalar/api-reference from 1.69.2 to 1.72.1 in /components @dependabot[bot] (#16144)
  • chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) @renovate[bot] (#16137)
  • chore(deps): update dependency kubernetes from 1.34.11 to v1.34.12 (.github/workflows/k8s-tests.yml) @renovate[bot] (#16138)
  • chore(deps): update dependency kubernetes/kubernetes from v1.35.8 to v1.35.9 (.github/workflows/k8s-tests.yml) @renovate[bot] (#16139)
  • chore(deps): update manusa/actions-setup-minikube action from v2.18.0 to v2.19.0 (.github/workflows/k8s-tests.yml) @renovate[bot] (#16140)
  • chore(deps-dev): bump django-test-migrations from 1.6.0 to 1.7.0 @dependabot[bot] (#16141)
  • chore(deps): bump ruff from 0.16.8 to 0.16.9 @dependabot[bot] (#16142)
  • chore(deps): bump sqlalchemy from 2.0.52 to 2.0.54 @dependabot[bot] (#16057)
  • chore(deps): bump django-permissions-policy from 4.33.0 to 4.34.0 @dependabot[bot] (#16052)
  • chore(deps): bump urllib3 from 2.7.0 to 2.8.0 @dependabot[bot] (#16059)
  • chore(deps): bump @scalar/api-reference from 1.68.0 to 1.69.2 in /components @dependabot[bot] (#16058)
  • chore(deps): bump moment from 2.30.1 to 2.31.0 in /components @dependabot[bot] (#16056)
  • chore(deps): bump django-tagulous from 2.2.2 to 2.2.3 @dependabot[bot] (#16055)
  • chore(deps): bump psycopg from 3.3.5 to 3.3.6 @dependabot[bot] (#16054)
  • chore(deps): bump django-ninja from 1.7.0 to 1.7.1 @dependabot[bot] (#16053)
  • chore(deps): bump django-imagekit from 6.1.0 to 6.1.1 @dependabot[bot] (#16051)
  • chore(deps): bump ruff from 0.16.7 to 0.16.8 @dependabot[bot] (#16050)
  • chore(deps): update suzuki-shunsuke/github-action-renovate-config-validator action from v2.1.0 to v2.2.0 (.github/workflows/renovate.yaml) @renovate[bot] (#16049)
  • chore(deps): update valkey/valkey:9.1.2-alpine docker digest from 9.1.2 to 9.1.2-alpine (docker-compose.yml) @renovate[bot] (#16048)
  • chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) @renovate[bot] (#16047)
  • chore(deps): update python:3.14.7-alpine3.23 docker digest from 3.14.7 to 3.14.7-alpine3.23 (dockerfile.nginx-alpine) @renovate[bot] (#16046)
  • chore(deps): update postgres:18.6-alpine docker digest from 18.6 to 18.6-alpine (docker-compose.yml) @renovate[bot] (#16045)
  • chore(deps): update dependency hugo from v0.153.4 to v0.153.5 (.github/workflows/validate_docs_build.yml) @renovate[bot] (#15962)
  • chore(deps): update docker/build-push-action action from v7.3.0 to v7.4.0 (.github/workflows/release-x-manual-docker-containers.yml) - autoclosed @renovate[bot] (#15967)
  • chore(deps): update docker/setup-buildx-action action from v4.3.0 to v4.4.1 (.github/workflows/release-x-manual-tag-as-latest.yml) @renovate[bot] (#15968)
  • chore(deps): bump djangorestframework from 3.18.0 to 3.18.1 @dependabot[bot] (#15969)
  • chore(deps): bump django-dbbackup from 5.3.0 to 5.3.1 @dependabot[bot] (#15970)
  • chore(deps): bump ruff from 0.16.6 to 0.16.7 @dependabot[bot] (#15971)
  • chore(deps): bump jszip from 3.10.1 to 3.10.2 in /components @dependabot[bot] (#15973)
  • chore(deps): bump pyjwt from 2.13.0 to 2.14.0 @dependabot[bot] (#15974)
  • chore(deps): bump gitpython from 3.1.61 to 3.1.62 @dependabot[bot] (#15975)
  • chore(deps): bump @scalar/api-reference from 1.67.0 to 1.68.0 in /components @dependabot[bot] (#15976)
  • chore(deps): bump ruff from 0.16.5 to 0.16.6 @dependabot[bot] (#15912)
  • chore(deps): update valkey docker tag from 0.25.8 to v0.25.11 (helm/defectdojo/chart.yaml) @renovate[bot] (#15898)
  • chore(deps): bump drf-spectacular-sidecar from 2026.8.1 to 2026.9.1 @dependabot[bot] (#15909)
  • chore(deps): update valkey/valkey:9.1.2-alpine docker digest from 9.1.2 to 9.1.2-alpine (docker-compose.yml) @renovate[bot] (#15897)
  • chore(deps): update dependency node from 24.19.0 to v24.21.0 (.github/workflows/validate_docs_build.yml) @renovate[bot] (#15902)
  • chore(deps): bump psycopg from 3.3.4 to 3.3.5 @dependabot[bot] (#15906)
  • chore(deps): bump django-ninja from 1.6.3 to 1.7.0 @dependabot[bot] (#15907)
  • chore(deps): bump lxml from 6.1.2 to 6.1.3 @dependabot[bot] (#15911)
  • chore(deps): update dependency django-debug-toolbar from 7.1.1 to v8 (requirements-dev.txt) @renovate[bot] (#15913)
  • chore(deps): update dependency renovatebot/renovate from 44.61.5 to v44.72.0 (.github/workflows/renovate.yaml) @renovate[bot] (#15881)

Don't miss a new django-DefectDojo release

NewReleases is sending notifications on new releases.