- This is a security release: full fix 1 high vulnerability
- Security: implement multiple hardening measures
- Allow creating API tokens with/without superuser permissions
- Disable user after multiple failed MFA login attempts
- Remove PDF compression and
COMPRESS_PDFSsetting - Rework plugin loading to make source code directory readonly in docker image
- Use redis as django cache
- Throttle sending password reset mails per email
- Validate initial status transition on create
- Send mention/assignee notifications only to project members
- Generate random postgres and redis passwords in install.sh
backup/restorebackupcommand: allow reading AES key from stdin- Harden PDF rendering
- Plugin
scanimport: add Prowler and ScoutSuite importers
Click here to go to the update instructions: https://docs.sysreptor.com/setup/updates/