Release: Merge release into master from: release/2.38.0#10852
Release: Merge release into master from: release/2.38.0#10852
Conversation
Bumps [debugpy](https://github.com/microsoft/debugpy) from 1.8.2 to 1.8.3. - [Release notes](https://github.com/microsoft/debugpy/releases) - [Commits](microsoft/debugpy@v1.8.2...v1.8.3) --- updated-dependencies: - dependency-name: debugpy dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [django-filter](https://github.com/carltongibson/django-filter) from 24.2 to 24.3. - [Release notes](https://github.com/carltongibson/django-filter/releases) - [Changelog](https://github.com/carltongibson/django-filter/blob/main/CHANGES.rst) - [Commits](carltongibson/django-filter@24.2...24.3) --- updated-dependencies: - dependency-name: django-filter dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.34.152 to 1.34.153. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.152...1.34.153) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….0-dev Release: Merge back 2.37.0 into dev from: master-into-dev/2.37.0-2.38.0-dev
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.5.5 to 0.5.6. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.5.5...0.5.6) --- updated-dependencies: - dependency-name: ruff dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* feat(django): Upgrade to 5.0 * Remove obsolete code * Fix RemovedInDjango60Warning for FORMS_URLFIELD_ASSUME_HTTPS * fix(multiselectfield): Use original repo * Upgrade to 5.0.8
Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.31 to 2.0.32. - [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases) - [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst) - [Commits](https://github.com/sqlalchemy/sqlalchemy/commits) --- updated-dependencies: - dependency-name: sqlalchemy dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [python-gitlab](https://github.com/python-gitlab/python-gitlab) from 4.8.0 to 4.9.0. - [Release notes](https://github.com/python-gitlab/python-gitlab/releases) - [Changelog](https://github.com/python-gitlab/python-gitlab/blob/main/CHANGELOG.md) - [Commits](python-gitlab/python-gitlab@v4.8.0...v4.9.0) --- updated-dependencies: - dependency-name: python-gitlab dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.34.153 to 1.34.154. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.153...1.34.154) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ackage.json) (#10681) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.34.154 to 1.34.155. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.154...1.34.155) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.34.155 to 1.34.156. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.155...1.34.156) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.5.6 to 0.5.7. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.5.6...0.5.7) --- updated-dependencies: - dependency-name: ruff dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.34.156 to 1.34.157. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.156...1.34.157) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pdfmake](https://github.com/bpampuch/pdfmake) from 0.2.10 to 0.2.11. - [Release notes](https://github.com/bpampuch/pdfmake/releases) - [Changelog](https://github.com/bpampuch/pdfmake/blob/0.2.11/CHANGELOG.md) - [Commits](bpampuch/pdfmake@0.2.10...0.2.11) --- updated-dependencies: - dependency-name: pdfmake dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…mpose.yml) (#10724) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* replace site url variable name to match values.yaml style * rework app settings block in values.yaml to match file style * rework uwsgi debug variable setting * fix configmap boolean value to string * remove unneded variable * update release documentation * fix variable name * move documentation to the next realease notes * change description in the changelog * remove empty line at the end of file
* Change ingress netpol * Keep old and new options * Fix lint
Bumps [boto3](https://github.com/boto/boto3) from 1.34.157 to 1.34.158. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.157...1.34.158) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….0-dev Release: Merge back 2.37.1 into dev from: master-into-dev/2.37.1-2.38.0-dev
Bumps [lxml](https://github.com/lxml/lxml) from 5.2.2 to 5.3.0. - [Release notes](https://github.com/lxml/lxml/releases) - [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt) - [Commits](lxml/lxml@lxml-5.2.2...lxml-5.3.0) --- updated-dependencies: - dependency-name: lxml dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [django-dbbackup](https://github.com/jazzband/django-dbbackup) from 4.1.0 to 4.2.1. - [Release notes](https://github.com/jazzband/django-dbbackup/releases) - [Changelog](https://github.com/jazzband/django-dbbackup/blob/master/docs/changelog.rst) - [Commits](Archmonger/django-dbbackup@4.1.0...4.2.1) --- updated-dependencies: - dependency-name: django-dbbackup dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.35.6 to 1.35.8. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.6...1.35.8) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fixing CWE issue * adding weird findings to unit test * modifying the unit test to include the weird findings I'm seeing * restoring file to original state * creating new file for new unit test * add new unit test function merge conflict * switch to recommended file name * scan report name change * adding encoding * double quoutes --------- Co-authored-by: Timmins, Adam <timminsa@ryanair.com>
…ted (#10429) * improved naming of findings filter for "on", "before", "after" and added similar for mitigated field on api & UI * fix ruff * fix ruff * Update dojo/filters.py Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com> * Update dojo/filters.py Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com> * Update dojo/filters.py Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com> * fix ruff * fix ruff * Update dojo/filters.py --------- Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
Co-authored-by: Cody Maffucci <cmmaffucci@gmail.com>
Bumps [python-gitlab](https://github.com/python-gitlab/python-gitlab) from 4.9.0 to 4.10.0. - [Release notes](https://github.com/python-gitlab/python-gitlab/releases) - [Changelog](https://github.com/python-gitlab/python-gitlab/blob/main/CHANGELOG.md) - [Commits](python-gitlab/python-gitlab@v4.9.0...v4.10.0) --- updated-dependencies: - dependency-name: python-gitlab dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.35.8 to 1.35.9. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.8...1.35.9) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.6.2 to 0.6.3. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.6.2...0.6.3) --- updated-dependencies: - dependency-name: ruff dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bugfix -> Dev: Release 2.38.0
DryRun Security SummaryThe provided GitHub Pull Request includes a variety of changes across multiple files in the DefectDojo application, covering documentation updates, dependency version updates, configuration changes, and updates to the core application code, with a few areas that deserve closer attention for potential security implications, such as input validation, access control, secure communication, logging and monitoring, and the need for regular security assessments. Expand for full summarySummary: The provided GitHub Pull Request includes a variety of changes across multiple files in the DefectDojo application. The changes cover a wide range of functionality, including documentation updates, dependency version updates, configuration changes, and updates to the core application code. From an application security perspective, the changes do not introduce any obvious security vulnerabilities. However, there are a few areas that deserve closer attention:
Files Changed:
Code AnalysisWe ran
Riskiness🟢 Risk threshold not exceeded. |
Release triggered by
Maffooch