Skip to content

3.3.300 馃寛

Latest

Choose a tag to compare

@github-actions github-actions released this 28 Sep 11:39
8b12d80

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 3.3.200

  • docs(jira connector): describe select-list custom field values @Maffooch (#16104)
  • Docs/mcp dashboard @mtesauro (#16096)
  • Ship only runtime files in the nginx image's static tree @devGregA (#16102)
  • test(finding): accept either deadlock victim in the bulk-delete vs tag writer race @Maffooch (#16100)
  • ci(unit-tests): capture stacks and database activity when the rest framework job stalls @Maffooch (#16099)
  • docs(appearance): document the Appearance page, theme presets, and color customizer @blakeaowens (#16087)
  • fix(jira): order the authorized JIRA project queryset by id @Maffooch (#16095)
  • Harden authorization on the audit history page @svader0 (#15956)
  • Fix crash bugs in Aqua and Snyk parsers caused by None field concatenation @Jaimin2687 (#16021)
  • docs(sensei): note how the Advisor's cross-tool estimate reads Dedupe Pools @devGregA (#16041)
  • docs: remove 190 unreferenced images @paulOsinski (#16083)
  • docs(onprem): add the dojo-helm-cli guide to the Kubernetes section @rossops (#16094)
  • docs(risk-acceptance): document the Host column and host filter @paulOsinski (#16073)
  • Add docs on MCP Report Generation @mtesauro (#16076)
  • docs(onprem): fix the Docker Compose install guide from an end-to-end install run @Maffooch (#16090)
  • docs(navigation): choosing the interface language, and what stays in English @blakeaowens (#16077)
  • docs: load analytics and marketing tags only after cookie consent @devGregA (#16088)
  • docs(reporting): report template variables and per-finding / per-asset Triage Engine reports @blakeaowens (#16062)
  • docs(site): backport the 2026 brand for docs.defectdojo.com to bugfix @devGregA (#16084)
  • docs(mfa): document the Reset MFA action for Superusers @Maffooch (#16085)
  • docs(findings): document Mitigation Policies @paulOsinski (#16081)
  • docs(connectors): document the GitLab Exclude Archived Projects toggle @Maffooch (#16082)
  • docs(tables): sort numeric, score and date columns descending first, with blanks last @blakeaowens (#16071)
  • docs(pro): document how to get and enable the FIPS images @devGregA (#16080)
  • Scope the remaining Location relation filters to the caller's products @svader0 (#16029)
  • Align the merge finding action with the object-level permission check @svader0 (#16027)
  • Hardening: narrow a scan-import validation error message @svader0 (#16030)
  • docs(onprem): add a restore runbook and fix the backup page against a live drill @Maffooch (#16074)
  • docs(epss-kev): document Vulnerability Explorer filters and null-last multi-column sorting @blakeaowens (#16070)
  • docs(findings): add Priority, Risk and Risk Score to every findings export @blakeaowens (#16069)
  • docs(tables): document the column picker select all / deselect all and "select all matching" list filters @blakeaowens (#16068)
  • docs(dashboards): Command Center softer beams, risk colors, automation bar @blakeaowens (#16061)
  • docs: describe the two ways to start DefectDojo Cloud @devGregA (#15937)
  • docs(reporting): document the Report Builder CSV, Excel and JSON formats @blakeaowens (#16036)
  • docs(sensei): AI Agent Red Teaming is GA, drop the feature-flag gating @Maffooch (#16034)
  • docs(reports): Report Builder block filters open with Add Filters @Maffooch (#16044)
  • Stream uid/hash dedupe candidates to bound reimport memory @Maffooch (#16042)
  • docs: editable Exploit Maturity and manual Reachability on findings @Maffooch (#16039)
  • Update logo in readme @mtesauro (#16040)
  • docs(triage_engine): condition operators follow the field's data type @blakeaowens (#16035)
  • Update changelog.md @Maffooch (#16038)
  • docs(changelog): add DefectDojo Pro 3.3.200 release notes @Maffooch (#16033)

馃毄 Changes to settings.dist.py / local_settings.py

  • fix(dedupe): drop description from the Tenable Scan hash_code fields @Eljees (#16013)

馃毄 Database migration

  • Keep user flags in migration 0268 when an installed app manages the role tables @devGregA (#16103)

馃悰 Bug Fixes

  • fix(finding): lock a bulk-delete chunk before clearing its child and M2M rows @Maffooch (#16091)
  • fix(importers): lock test tag rows in id order before setting a test's tags @Maffooch (#16092)
  • Reimport with group_by no longer 500s on duplicate same-name finding groups @Maffooch (#16065)
  • Dedupe: row-lock the duplicate_finding self-FK so import dedup and duplicate deletion stop failing at COMMIT @Maffooch (#16064)
  • Generic Findings Import: fix CSV KEV/fix booleans, CVSSV3_score and empty cells; document every field @Maffooch (#16043)

馃摑 Documentation updates

  • docs(mcp): document DD_MCP_LOGLEVEL for self-hosted installs @Maffooch (#16093)
  • docs(feature-flags): drop Classic UI pages from the restart-time surfaces @Maffooch (#16075)
  • docs(connectors): Rapid7 InsightVM Cloud needs a platform admin API key @Maffooch (#16067)
  • Generic Findings Import: fix CSV KEV/fix booleans, CVSSV3_score and empty cells; document every field @Maffooch (#16043)

馃枌 Updates in UI

  • fix(os-message): decode banner as UTF-8 and restore list/paragraph styles @Maffooch (#16066)