Repository navigation
docs(pro): describe the Support pages, the docs search and the airgapped setting - #15925
Merged
Merged
Conversation
…form sits behind a link
… environment variables
Voters hear about a status change at the address on their DefectDojo user, and only when that address is at the domain of the organization's Cloud Portal account.
…-hosted section Support now appears in the settings menu on cloud, self-hosted and airgapped instances: Settings -> Support, or Settings -> License & Support -> Support in the reorganized menu. The sidebar page and its seven translated tables list the new entry. The self-hosted section now matches the hub: the first instance to enrol with a license keeps the enrolment and a second one is refused, staff can reset or revoke it, and a connector request from a self-hosted instance cannot carry tool details. It also names the two hosts the instance must reach, and the page paths gain their /ui/ prefix.
…hoice Each search suggestion now carries a tag that says community request or documentation. The request form also offers Security disclosure, which files nothing and points to DefectDojo's coordinated disclosure program on HackerOne.
The Support docs change stays English only. This removes the Support entry from the seven translated settings menu pages. The English sidebar page still lists it.
svader0
marked this pull request as ready for review
September 28, 2026 19:20
|
This pull request contains multiple low-severity findings where the user 'svader0' modified various sensitive codepaths in the
Configured Sensitive Codepath Modified by Non-Allowed Author in
|
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/authorization/api_permissions.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/authorization/serializer_guards.py (drs_cac8d5e6)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/authorization/serializer_guards.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/endpoint/models.py (drs_3a43202c)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/endpoint/models.py' matches configured sensitive codepath pattern 'dojo/endpoint/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/engagement/services.py (drs_43337fa7)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/engagement/services.py' matches configured sensitive codepath pattern 'dojo/engagement/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/finding/deduplication.py (drs_cca42354)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/finding/deduplication.py' matches configured sensitive codepath pattern 'dojo/finding/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/finding/helper.py (drs_868859a3)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/finding/helper.py' matches configured sensitive codepath pattern 'dojo/finding/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/finding_group/views.py (drs_a5c1ad46)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/finding_group/views.py' matches configured sensitive codepath pattern 'dojo/finding_group/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/jira/views.py (drs_0da319ba)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/jira/views.py' matches configured sensitive codepath pattern 'dojo/jira/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/metrics/views.py (drs_94b57d99)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/metrics/views.py' matches configured sensitive codepath pattern 'dojo/metrics/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/reports/queries.py (drs_40176a6f)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/reports/queries.py' matches configured sensitive codepath pattern 'dojo/reports/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/search/views.py (drs_b14d925d)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/search/views.py' matches configured sensitive codepath pattern 'dojo/search/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/tasks.py (drs_5d99965b)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/tasks.py' matches configured sensitive codepath pattern 'dojo/tasks.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/base.html (drs_ce1ba536)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/base.html' matches configured sensitive codepath pattern 'dojo/templates/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/defectDojo-engagement-survey/list_surveys.html (drs_342f5106)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/defectDojo-engagement-survey/list_surveys.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/request_endpoint_report.html (drs_688ea38b)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/request_endpoint_report.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/simple_search.html (drs_9ce27b83)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/simple_search.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/support.html (drs_75ecf2dd)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/support.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/view_product_details.html (drs_d3091895)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/view_product_details.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/view_product_type.html (drs_e01d1ee2)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/view_product_type.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/view_user.html (drs_c510f304)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/view_user.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templatetags/display_tags.py (drs_71ec39c5)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templatetags/display_tags.py' matches configured sensitive codepath pattern 'dojo/templatetags/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/test/services.py (drs_1578b244)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/test/services.py' matches configured sensitive codepath pattern 'dojo/test/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/urls.py (drs_beabbd14)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/urls.py' matches configured sensitive codepath pattern 'dojo/urls.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/user/models.py (drs_2e03743a)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/user/models.py' matches configured sensitive codepath pattern 'dojo/user/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/utils.py (drs_ae9770d7)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/utils.py' matches configured sensitive codepath pattern 'dojo/utils.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/authorization/query_registrations.py (drs_870641c4)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/authorization/query_registrations.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit 45816dc) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/announcement/os_message.py (drs_d868571f)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/announcement/os_message.py' matches configured sensitive codepath pattern 'dojo/announcement/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/db_migrations/0268_release_authorization_to_pro.py (drs_c6ffc2fe)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/db_migrations/0268_release_authorization_to_pro.py' matches configured sensitive codepath pattern 'dojo/db_migrations/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/importers/auto_create_context.py (drs_387660c4)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/importers/auto_create_context.py' matches configured sensitive codepath pattern 'dojo/importers/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/importers/base_importer.py (drs_15001e80)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/importers/base_importer.py' matches configured sensitive codepath pattern 'dojo/importers/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Comment to provide feedback on these findings.
Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]
Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing
All finding details can be found in the DryRun Security Dashboard.
blakeaowens
approved these changes
Oct 2, 2026
Maffooch
approved these changes
Oct 2, 2026
devGregA
approved these changes
Oct 2, 2026
Maffooch
added a commit
that referenced
this pull request
Oct 5, 2026
* Update versions in application files
* chore(deps): update dependency renovatebot/renovate from 44.61.5 to v44.72.0 (.github/workflows/renovate.yaml) (#15881)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update dependency django-debug-toolbar from 7.1.1 to v8 (requirements-dev.txt) (#15913)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): bump lxml from 6.1.2 to 6.1.3 (#15911)
Bumps [lxml](https://github.com/lxml/lxml) from 6.1.2 to 6.1.3.
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.1.2...lxml-6.1.3)
---
updated-dependencies:
- dependency-name: lxml
dependency-version: 6.1.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django-ninja from 1.6.3 to 1.7.0 (#15907)
Bumps [django-ninja](https://github.com/vitalik/django-ninja) from 1.6.3 to 1.7.0.
- [Release notes](https://github.com/vitalik/django-ninja/releases)
- [Commits](https://github.com/vitalik/django-ninja/compare/v1.6.3...v1.7.0)
---
updated-dependencies:
- dependency-name: django-ninja
dependency-version: 1.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump psycopg from 3.3.4 to 3.3.5 (#15906)
Bumps [psycopg](https://github.com/psycopg/psycopg) from 3.3.4 to 3.3.5.
- [Changelog](https://github.com/psycopg/psycopg/blob/master/docs/news.rst)
- [Commits](https://github.com/psycopg/psycopg/compare/3.3.4...3.3.5)
---
updated-dependencies:
- dependency-name: psycopg
dependency-version: 3.3.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): update dependency node from 24.19.0 to v24.21.0 (.github/workflows/validate_docs_build.yml) (#15902)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update valkey/valkey:9.1.2-alpine docker digest from 9.1.2 to 9.1.2-alpine (docker-compose.yml) (#15897)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): bump drf-spectacular-sidecar from 2026.8.1 to 2026.9.1 (#15909)
Bumps [drf-spectacular-sidecar](https://github.com/tfranzel/drf-spectacular-sidecar) from 2026.8.1 to 2026.9.1.
- [Commits](https://github.com/tfranzel/drf-spectacular-sidecar/compare/2026.8.1...2026.9.1)
---
updated-dependencies:
- dependency-name: drf-spectacular-sidecar
dependency-version: 2026.9.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): update valkey docker tag from 0.25.8 to v0.25.11 (helm/defectdojo/chart.yaml) (#15898)
* chore(deps): update valkey docker tag from 0.25.8 to v0.25.11 (helm/defectdojo/chart.yaml)
* update Helm documentation
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
* chore(deps): bump ruff from 0.16.5 to 0.16.6 (#15912)
* chore(deps): bump ruff from 0.16.5 to 0.16.6
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.5 to 0.16.6.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.16.5...0.16.6)
---
updated-dependencies:
- dependency-name: ruff
dependency-version: 0.16.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore: drop now-unused I001 noqa flagged by ruff 0.16.6
ruff 0.16.6 no longer needs the I001 suppression on the deferred
product_type.ui.forms import; remove it to satisfy ruff-linting.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* Update versions in application files
* Update versions in application files
* Update Chart.yaml
* docs: retire the PSIRT 1.x sidecar from the Pro on-prem guides and document the migration (#15964)
DefectDojo Pro 3.3.0 replaced the PSIRT Advisory Engine sidecar with PSIRT 2.0 inside the main application, and the v2 Helm chart no longer ships the component. The Kubernetes install guide still carried a full section on enabling it, and the FIPS page listed it as a FIPS container and set PSIRT_ENABLED in the ECS and compose samples.
Remove those, add a revision-history row, and give the PSIRT chapter a short section on carrying an existing sidecar database into PSIRT 2.0 with manage.py psirt_import_legacy.
English only: per docs/TRANSLATIONS.md the translated copies are regenerated from the English source on the quarterly refresh.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* chore(deps): bump @scalar/api-reference in /components (#15976)
Bumps [@scalar/api-reference](https://github.com/scalar/scalar/tree/HEAD/packages/api-reference) from 1.67.0 to 1.68.0.
- [Release notes](https://github.com/scalar/scalar/releases)
- [Changelog](https://github.com/scalar/scalar/blob/main/packages/api-reference/CHANGELOG.md)
- [Commits](https://github.com/scalar/scalar/commits/HEAD/packages/api-reference)
---
updated-dependencies:
- dependency-name: "@scalar/api-reference"
dependency-version: 1.68.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump gitpython from 3.1.61 to 3.1.62 (#15975)
Bumps [gitpython](https://github.com/gitpython-developers/GitPython) from 3.1.61 to 3.1.62.
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](https://github.com/gitpython-developers/GitPython/compare/3.1.61...3.1.62)
---
updated-dependencies:
- dependency-name: gitpython
dependency-version: 3.1.62
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump pyjwt from 2.13.0 to 2.14.0 (#15974)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.14.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0)
---
updated-dependencies:
- dependency-name: pyjwt
dependency-version: 2.14.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump jszip from 3.10.1 to 3.10.2 in /components (#15973)
Bumps [jszip](https://github.com/Stuk/jszip) from 3.10.1 to 3.10.2.
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](https://github.com/Stuk/jszip/compare/v3.10.1...v3.10.2)
---
updated-dependencies:
- dependency-name: jszip
dependency-version: 3.10.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump ruff from 0.16.6 to 0.16.7 (#15971)
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.6 to 0.16.7.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7)
---
updated-dependencies:
- dependency-name: ruff
dependency-version: 0.16.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django-dbbackup from 5.3.0 to 5.3.1 (#15970)
Bumps [django-dbbackup](https://github.com/Archmonger/django-dbbackup) from 5.3.0 to 5.3.1.
- [Release notes](https://github.com/Archmonger/django-dbbackup/releases)
- [Changelog](https://github.com/Archmonger/django-dbbackup/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Archmonger/django-dbbackup/compare/5.3.0...5.3.1)
---
updated-dependencies:
- dependency-name: django-dbbackup
dependency-version: 5.3.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump djangorestframework from 3.18.0 to 3.18.1 (#15969)
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.18.0 to 3.18.1.
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](https://github.com/encode/django-rest-framework/compare/3.18.0...3.18.1)
---
updated-dependencies:
- dependency-name: djangorestframework
dependency-version: 3.18.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): update docker/setup-buildx-action action from v4.3.0 to v4.4.1 (.github/workflows/release-x-manual-tag-as-latest.yml) (#15968)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update docker/build-push-action action from v7.3.0 to v7.4.0 (.github/workflows/release-x-manual-docker-containers.yml) (#15967)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update dependency hugo from v0.153.4 to v0.153.5 (.github/workflows/validate_docs_build.yml) (#15962)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* Update versions in application files
* docs(site): rebrand docs.defectdojo.com to the 2026 brand (Earth Undertones) (#15736)
* docs(site): rebrand docs.defectdojo.com to the 2026 brand (Earth Undertones)
Applies Brand Guidelines v1.0 (Aug 2026) to the docs site:
- Palette: Dystopian Orange primary, deep-midnight header/footer/code
surfaces, Dust reading canvas, Daybreak/Dusk secondary tones,
Accent Blue links per the guide's digital-only colors. Dark mode
runs Deep Midnight / Midnight surfaces.
- Typography: self-hosted Inter variable (latin, OFL) replaces the
six Work Sans faces; italics synthesize until an italic subset is
added.
- Logos: wordmark SVGs regenerated from the 2026 wordmark
(standalone, no symbol lockup per the logo rules).
- Shape: zero border radius across the site, including Bootstrap's
.rounded-pill; single orange hairline replaces the blue-to-orange
gradient.
- Buttons: explicit .btn-primary/.btn-outline-primary skins in both
color modes (doks-core's dark defaults previously leaked Bootstrap
blue tints into the home CTAs).
- Edition toggle: Open Source = Dusk, Pro = Dystopian Orange,
matching the Pro-is-hot coding used across brand materials.
- Chroma/code: card chrome moves to Midnight surfaces; blue-family
syntax hues re-tinted to the Daybreak family, semantic green/amber/
red hues kept for meaning.
- DocSearch modal reskinned to the same tokens.
No DOM, class-name, or content changes; PurgeCSS safelisting and the
existing token architecture are preserved.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* docs(site): align the docs skin with the shipped defectdojo.com, add the dot field and grain
Final pass on the August draft, measured against the live site like the
status page and trust center:
- Header, hero and footer are Midnight in both modes with Dust 18% rules;
orange wordmark; JetBrains Mono (self-hosted variable latin, OFL) for the
nav, the "Docs" label, the release chip, sidebar and TOC headings, footer
column titles and the bottom bar
- Hero: flat Midnight, calm Inter 900 uppercase "Documentation", the site's
buttons (mono label, 2px stroke, no radius), search field on hairlines;
the lattice scatters and eases home on load (canvas from custom.js, CSP
stays default-src 'self', reduced motion respected, CSS lattice as the
no-JS fallback); the site's grain as an overlay layer on the dark bands
- Removed the orange top hairline, the orange glows, the blueprint grid and
the theme's grey dot grid behind the cards band
- Dark surfaces re-stepped so cards read against the Midnight hero
- Footer tagline updated to the current line; copyright string matches the site
- Favicon swapped to the brand symbol, theme-color meta, branded 1200x630
cover for og:image (the tag pointed at a missing file)
- Font preloads fixed: they still referenced the deleted Work Sans files,
which is what failed the deploy link check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Greg Anderson <greg@Gregs-MBP.lan>
* perf(api): eliminate N+1 queries in product and asset list endpoints (#16037)
* perf(api): eliminate N+1 queries in product and asset list endpoints
ProductViewSet and AssetViewSet.get_queryset() returned a bare queryset
with zero prefetching, so every serialized relation was lazy-loaded per
product: tags, product_meta, authorized_users, regulations, and the
active-finding count — roughly 6 extra queries per product in the
response.
Apply the same optimization strategy the Product UI views already use:
- select_related for the platform/lifecycle/origin FKs (SlugRelatedField
reads .value on the related object)
- prefetch_related for tags, product_meta, authorized_users, regulations
- annotate active_finding_count via a correlated subquery using the
project's own build_count_subquery utility — the Product.findings_count
cached_property already checks for this attribute before falling back
to a per-product count()
The only remaining per-product query is open_findings_list(), which
returns a variable-length list of finding IDs and cannot be collapsed
into a scalar annotation. This is a known limitation (the model method
carries a TODO comment) that requires either a PostgreSQL-specific
ArrayAgg or deprecating the findings_list field to resolve.
Add a regression test (test_api_product_prefetch) that creates 1 vs 5
products with full relation graphs and asserts the query-count growth
equals exactly the number of extra products — proving all N+1 sources
except the documented open_findings_list are eliminated.
* fix(jira): add deterministic ordering to JIRA querysets to prevent flaky CI tests
* fix(test): correct V3 API testing route, auth, and query expectations
* chore(deps): update postgres:18.6-alpine docker digest from 18.6 to 18.6-alpine (docker-compose.yml) (#16045)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update python:3.14.7-alpine3.23 docker digest from 3.14.7 to 3.14.7-alpine3.23 (dockerfile.nginx-alpine) (#16046)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) (#16047)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update valkey/valkey:9.1.2-alpine docker digest from 9.1.2 to 9.1.2-alpine (docker-compose.yml) (#16048)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update suzuki-shunsuke/github-action-renovate-config-validator action from v2.1.0 to v2.2.0 (.github/workflows/renovate.yaml) (#16049)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): bump ruff from 0.16.7 to 0.16.8 (#16050)
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.7 to 0.16.8.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.16.7...0.16.8)
---
updated-dependencies:
- dependency-name: ruff
dependency-version: 0.16.8
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django-imagekit from 6.1.0 to 6.1.1 (#16051)
Bumps [django-imagekit](https://github.com/matthewwithanm/django-imagekit) from 6.1.0 to 6.1.1.
- [Release notes](https://github.com/matthewwithanm/django-imagekit/releases)
- [Commits](https://github.com/matthewwithanm/django-imagekit/compare/6.1...6.1.1)
---
updated-dependencies:
- dependency-name: django-imagekit
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django-ninja from 1.7.0 to 1.7.1 (#16053)
Bumps [django-ninja](https://github.com/vitalik/django-ninja) from 1.7.0 to 1.7.1.
- [Release notes](https://github.com/vitalik/django-ninja/releases)
- [Commits](https://github.com/vitalik/django-ninja/compare/v1.7.0...v1.7.1)
---
updated-dependencies:
- dependency-name: django-ninja
dependency-version: 1.7.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump psycopg from 3.3.5 to 3.3.6 (#16054)
Bumps [psycopg](https://github.com/psycopg/psycopg) from 3.3.5 to 3.3.6.
- [Changelog](https://github.com/psycopg/psycopg/blob/master/docs/news.rst)
- [Commits](https://github.com/psycopg/psycopg/compare/3.3.5...3.3.6)
---
updated-dependencies:
- dependency-name: psycopg
dependency-version: 3.3.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django-tagulous from 2.2.2 to 2.2.3 (#16055)
Bumps [django-tagulous](https://github.com/radiac/django-tagulous) from 2.2.2 to 2.2.3.
- [Changelog](https://github.com/radiac/django-tagulous/blob/main/docs/changelog.rst)
- [Commits](https://github.com/radiac/django-tagulous/compare/v2.2.2...v2.2.3)
---
updated-dependencies:
- dependency-name: django-tagulous
dependency-version: 2.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump moment from 2.30.1 to 2.31.0 in /components (#16056)
Bumps [moment](https://github.com/moment/moment) from 2.30.1 to 2.31.0.
- [Release notes](https://github.com/moment/moment/releases)
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/moment/moment/compare/2.30.1...2.31.0)
---
updated-dependencies:
- dependency-name: moment
dependency-version: 2.31.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump @scalar/api-reference in /components (#16058)
Bumps [@scalar/api-reference](https://github.com/scalar/scalar/tree/HEAD/packages/api-reference) from 1.68.0 to 1.69.2.
- [Release notes](https://github.com/scalar/scalar/releases)
- [Changelog](https://github.com/scalar/scalar/blob/main/packages/api-reference/CHANGELOG.md)
- [Commits](https://github.com/scalar/scalar/commits/HEAD/packages/api-reference)
---
updated-dependencies:
- dependency-name: "@scalar/api-reference"
dependency-version: 1.69.2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump urllib3 from 2.7.0 to 2.8.0 (#16059)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0)
---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django-permissions-policy from 4.33.0 to 4.34.0 (#16052)
Bumps [django-permissions-policy](https://github.com/adamchainz/django-permissions-policy) from 4.33.0 to 4.34.0.
- [Changelog](https://github.com/adamchainz/django-permissions-policy/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/adamchainz/django-permissions-policy/compare/4.33.0...4.34.0)
---
updated-dependencies:
- dependency-name: django-permissions-policy
dependency-version: 4.34.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* chore(deps): bump sqlalchemy from 2.0.52 to 2.0.54 (#16057)
Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.52 to 2.0.54.
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)
---
updated-dependencies:
- dependency-name: sqlalchemy
dependency-version: 2.0.54
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Update versions in application files
* Retire the bugfix branch: every release is cut from dev (#16086)
* chore(release): retire the bugfix branch; release from dev -> master
Every release, the weekly patch (x.y.100, x.y.200, ...) and the monthly
minor (x.y.0), is now cut from dev and merged into master. There is no
separate bugfix line and no hotfix path off master. All PRs target dev.
Workflows:
- release-1: from_branch keeps its input for existing callers but only
offers dev; one version check accepts x.y.0 and x.y.100; drop the dead
release/ guard on the push step; reword the chart -dev strip messages.
- release-3: remove the master-into-bugfix merge-back job.
- Drop bugfix from branch filters and conditions in test-helm-chart,
unit-tests, ci-warm-caches, migration-graph, ruff,
detect-merge-conflicts and renovate.
- gh-pages: publish on pushes to master and dev, with a concurrency
group so the two deploys queue instead of racing.
- release_drafter_valentijn: the previous release tag is now the normal
changeset start; update the input help text.
Docs and agent guidance:
- PR template, CONTRIBUTING and RELEASING describe the single dev line.
- branching-model page and its 7 translations: dev -> release -> master
diagram, patch releases from dev, fixed workflow links.
- AGENTS.md, branch-guard.sh and the repo skills: all work on dev,
master stays gated behind explicit confirmation, one milestone query.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* ci: skip CI on release PRs and merge-backs
Release PRs (release/<version>) and merge-backs
(master-into-dev/<version>-<dev>) are merged as soon as they are
conflict-free, without waiting for CI. Guard the root jobs of the test,
lint and verification workflows so they skip on those PRs when the
release-management label is present, and on pushes of such branches or
of GitHub's merge commit for such a PR. Unit Tests Complete skips with
them instead of reporting a failure. RELEASING.md drops the "wait for
the tests" steps.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* ci(release): name release branches release/merge-* like the other repos
The release PR head is now release/merge-dev-into-master-<version> (was
release/<version>) and the merge-back head is
release/merge-master-into-dev-<version> (was master-into-dev/<version>-<dev>).
The version suffix keeps each release's branches unique.
CI now skips on the same rule as the other DefectDojo repositories: a pull
request whose head starts with release/merge- AND that has the
release-management label, or on push a release/merge-* branch or GitHub's
merge commit for such a PR. RELEASING.md and the branching-model pages use
the new names.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* ci(docs): hold dev docs deploys until bugfix is retired (#16131)
#16086 changed the docs deploy triggers on dev from master+bugfix to
master+dev, but bugfix stays live until the next release and its own
copy of the workflow still deploys. Both branches then published to
gh-pages, and each deploy replaces the whole site. The dev deploy from
the #16086 merge dropped docs merged only to bugfix (including the
3.3.300 Pro changelog) and published docs for unreleased 3.4 work.
Trigger on master and bugfix again until bugfix is retired after the
release, then swap bugfix for dev. Keep the concurrency group.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* chore(deps): bump ruff from 0.16.8 to 0.16.9 (#16142)
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.8 to 0.16.9.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.16.8...0.16.9)
---
updated-dependencies:
- dependency-name: ruff
dependency-version: 0.16.9
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps-dev): bump django-test-migrations from 1.6.0 to 1.7.0 (#16141)
Bumps [django-test-migrations](https://github.com/wemake-services/django-test-migrations) from 1.6.0 to 1.7.0.
- [Release notes](https://github.com/wemake-services/django-test-migrations/releases)
- [Changelog](https://github.com/wemake-services/django-test-migrations/blob/master/CHANGELOG.md)
- [Commits](https://github.com/wemake-services/django-test-migrations/compare/1.6.0...1.7.0)
---
updated-dependencies:
- dependency-name: django-test-migrations
dependency-version: 1.7.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): update manusa/actions-setup-minikube action from v2.18.0 to v2.19.0 (.github/workflows/k8s-tests.yml) (#16140)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update dependency kubernetes/kubernetes from v1.35.8 to v1.35.9 (.github/workflows/k8s-tests.yml) (#16139)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update dependency kubernetes from 1.34.11 to v1.34.12 (.github/workflows/k8s-tests.yml) (#16138)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): update python:3.14.7-slim-trixie docker digest from 3.14.7 to 3.14.7-slim-trixie (dockerfile.integration-tests-debian) (#16137)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* chore(deps): bump @scalar/api-reference in /components (#16144)
Bumps [@scalar/api-reference](https://github.com/scalar/scalar/tree/HEAD/packages/api-reference) from 1.69.2 to 1.72.1.
- [Release notes](https://github.com/scalar/scalar/releases)
- [Changelog](https://github.com/scalar/scalar/blob/main/packages/api-reference/CHANGELOG.md)
- [Commits](https://github.com/scalar/scalar/commits/HEAD/packages/api-reference)
---
updated-dependencies:
- dependency-name: "@scalar/api-reference"
dependency-version: 1.72.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump markdown from 3.10.3 to 3.11 (#16146)
Bumps [markdown](https://github.com/Python-Markdown/markdown) from 3.10.3 to 3.11.
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](https://github.com/Python-Markdown/markdown/compare/3.10.3...3.11.0)
---
updated-dependencies:
- dependency-name: markdown
dependency-version: '3.11'
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump pyjwt from 2.14.0 to 2.15.0 (#16145)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.14.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0)
---
updated-dependencies:
- dependency-name: pyjwt
dependency-version: 2.15.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump sqlalchemy from 2.0.54 to 2.1.1 (#16143)
Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.54 to 2.1.1.
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)
---
updated-dependencies:
- dependency-name: sqlalchemy
dependency-version: 2.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump django from 5.2.16 to 5.2.17 (#16164)
Bumps [django](https://github.com/django/django) from 5.2.16 to 5.2.17.
- [Commits](https://github.com/django/django/compare/5.2.16...5.2.17)
---
updated-dependencies:
- dependency-name: django
dependency-version: 5.2.17
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* chore(deps): bump @babel/core from 7.29.0 to 7.29.7 in /docs (#16107)
Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.29.0 to 7.29.7.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.7/packages/babel-core)
---
updated-dependencies:
- dependency-name: "@babel/core"
dependency-version: 7.29.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* fix(metadata): accept location-only payloads and persist the product scope; document the Location page (#16152)
* fix(metadata): accept location-only payloads and persist the asset scope; document the Location page
MetaSerializer's endpoint->location compatibility popped ``endpoint`` unconditionally.
The field defaults to None, so the key is always present and a payload that named a
``location`` had it replaced with None: "Metadata entries need either a product,
endpoint, location or a finding". Only an endpoint that was actually given now stands in
for the location.
``location_product`` is ``editable=False`` on the model, so ModelSerializer dropped it
and every entry written through the API landed unscoped although a Location is shared
by every product that recorded the same value. Declare it writable, and reject it
without a location.
Docs: describe the Pro Location page (the counterpart of the old Endpoint page, with
the per-asset Metadata box) and state where migrated endpoint metadata is shown.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* test(metadata): add the trailing commas ruff COM812 requires
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* docs(crowdstrike): say which CID the Falcon API client must be created in (#16120)
Under Falcon Flight Control, an API client created in the parent CID may
not list the hosts that belong to child CIDs, which leaves a connector
that authenticates but sees no hosts. Tell users to create the client in
the CID that holds the hosts, and say what saving the connector reports,
matching the new CrowdStrike visibility hint.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(pro): describe the Support pages, the docs search and the airgapped setting (#15925)
* docs(pro): describe the Support pages, the docs search and the airgapped setting
* docs(pro): the support search also lists community requests, and the form sits behind a link
* docs(pro): the board outlines the request you arrived from
* docs(support): describe completed and removed community requests
* docs(support): airgapped is a feature flag; the support pages need no environment variables
* docs(support): the airgapped notice is inline, so the menu stays usable
* docs(support): the airgapped dialog carries a Go back button
* docs(support): say who receives a status e-mail
Voters hear about a status change at the address on their DefectDojo user,
and only when that address is at the domain of the organization's Cloud
Portal account.
* docs(support): show Support on every deployment, and correct the self-hosted section
Support now appears in the settings menu on cloud, self-hosted and
airgapped instances: Settings -> Support, or Settings -> License & Support
-> Support in the reorganized menu. The sidebar page and its seven
translated tables list the new entry.
The self-hosted section now matches the hub: the first instance to enrol
with a license keeps the enrolment and a second one is refused, staff can
reset or revoke it, and a connector request from a self-hosted instance
cannot carry tool details. It also names the two hosts the instance must
reach, and the page paths gain their /ui/ prefix.
* docs(support): describe the result tags and the security disclosure choice
Each search suggestion now carries a tag that says community request or
documentation. The request form also offers Security disclosure, which files
nothing and points to DefectDojo's coordinated disclosure program on
HackerOne.
* docs(support): leave the translated settings menu pages unchanged
The Support docs change stays English only. This removes the Support
entry from the seven translated settings menu pages. The English sidebar
page still lists it.
* docs(connectors): document the Checkmarx One Tag Findings With Scan ID option (#16153)
Explains the opt-in tag_scan_id toggle: synced findings are tagged scan-id:<id> for the Checkmarx scan they came from, which together with the result hash in Unique ID From Tool locates the finding in Checkmarx. Notes that deduplication is unchanged, that the tag records the scan of first import because reimport keeps a matched finding's tags, and that existing findings are not backfilled. Added to the English page and its de, es, fr and ja translations.
* docs(connectors): document the Google Cloud asset connector (#16113)
* docs(connectors): document the Google Cloud asset connector
Add the tool-reference page for the new Google Cloud asset connector
(English plus de/es/fr/ja translations), and list it in the upstream
connector index and the asset-connector call-outs so it shows up next
to Google Cloud SCC.
* docs(connectors): fix Google Cloud asset connector accuracy gaps
- The ACTIVE filter applies to folders and projects both; reword the
sentence so it does not read as projects-only.
- State the SCC handoff correctly: when the google-scc connector
creates the Asset first, that Asset keeps its existing Organization,
and this connector only adds the folder relationship above it.
- Document that a mapped Record's metadata never refreshes, so a
folder rename or a project move in Google Cloud does not reach
DefectDojo after the first sync.
Same three corrections applied to the de/es/fr/ja translations.
* docs(connectors): name the two get permissions the Google Cloud root label needs
roles/browser carries resourcemanager.folders.get and
resourcemanager.organizations.get, but the page told readers a custom role
with only the two list permissions works too. It does for the walk, and the
top-level Asset then falls back to its resource id as its name because the
connector cannot read the root's display name.
* docs(connectors): say where organization-level SCC findings land
google-scc files a finding it cannot attribute to a project under a record
for its configured parent, named after that resource. That is a different
Asset from the organization or folder Asset the Google Cloud connector
creates, so a customer running both sees one extra Asset for those findings.
Keeping the display-name label on our root record was chosen over matching
the bare resource name; this paragraph sets the expectation instead.
* docs(connectors): cover a Google Cloud account with no organization
The Parent Resource field is now optional. Blank means every project the
service account can read, as a flat list. With no organization there is no
parent to grant the Browser role at, so it goes on each project instead.
* Update sample data (#16155)
Co-authored-by: rossops <20447042+rossops@users.noreply.github.com>
* fix(metadata): authorize the location_product scope on location metadata (#16170)
A Location is shared by every product that recorded the same value, and edit
rights on it come from any one of those products. #16152 made
DojoMeta.location_product writable, but nothing checked the scoped product, so
a user who could edit a shared Location through one product could create
metadata scoped to another product they have no access to.
- UserHasDojoMetaPermission now checks location_product on its own: edit to
write, view to read, at both the request and the object level.
- MetaSerializer rejects a location_product that does not reference the given
location.
Tests: an unauthorized scope is denied (403) on create, the object check
denies update and delete of an entry scoped to an unauthorized product, and a
mismatched product/location pair is rejected. All four fail without the fix.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(pro): point the support docs at the Support page (#16118)
* docs(pro): describe the Support pages, the docs search and the airgapped setting
* docs(pro): the support search also lists community requests, and the form sits behind a link
* docs(pro): the board outlines the request you arrived from
* docs(support): describe completed and removed community requests
* docs(support): airgapped is a feature flag; the support pages need no environment variables
* docs(support): the airgapped notice is inline, so the menu stays usable
* docs(support): the airgapped dialog carries a Go back button
* docs(support): say who receives a status e-mail
Voters hear about a status change at the address on their DefectDojo user,
and only when that address is at the domain of the organization's Cloud
Portal account.
* docs(support): show Support on every deployment, and correct the self-hosted section
Support now appears in the settings menu on cloud, self-hosted and
airgapped instances: Settings -> Support, or Settings -> License & Support
-> Support in the reorganized menu. The sidebar page and its seven
translated tables list the new entry.
The self-hosted section now matches the hub: the first instance to enrol
with a license keeps the enrolment and a second one is refused, staff can
reset or revoke it, and a connector request from a self-hosted instance
cannot carry tool details. It also names the two hosts the instance must
reach, and the page paths gain their /ui/ prefix.
* docs(support): describe the result tags and the security disclosure choice
Each search suggestion now carries a tag that says community request or
documentation. The request form also offers Security disclosure, which files
nothing and points to DefectDojo's coordinated disclosure program on
HackerOne.
* docs(support): leave the translated settings menu pages unchanged
The Support docs change stays English only. This removes the Support
entry from the seven translated settings menu pages. The English sidebar
page still lists it.
* docs(pro): point the support docs at the Support page
DefectDojo Pro reaches support through Settings > Support only. The help
page and the sidebar tables no longer list the Contact Support entries.
---------
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* test: use the memory broker for local unit tests; fix the lost webhook checkbox click (#16171)
Local unit tests (docker-compose.override.unit_tests.yml) used the sqla+sqlite
Celery broker. Since the SQLAlchemy 2.1 bump, kombu's SQLAlchemy transport trips
the `noload` deprecation, and under PYTHONWARNINGS=error the first task dispatch
in any test fails. Use the in-memory broker that the CI override already uses.
notification_webhook_test toggled the enable_webhooks_notifications checkbox
with a raw click(). The box sits low on a long form, and a click that lands on
the footer is lost silently, so the form saved with webhooks still disabled and
the next test 404'd on the webhook list. Use click_centered() and assert the box
changed before submitting, for both the enable and the disable test. Also
correct the list test's comment, which blamed a cross-worker cache window that
the per-request L1 reset rules out.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs: webhook receivers, the bundled webhook gateway and two-way Jira sync (#16060)
Rebuilt on dev (bugfix is retired). The same documentation as before, now
on the dev line: Triage Engine webhook receivers and their gateway, the
Jira template, Push Notes as Comments on the Jira Downstream Connector,
the node reference and configuration entries, the webhook gateway upgrade
page and the v3.4.0 changelog entry.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* Pull the Docker Compose images through registry.defectdojo.com (#16121)
* Pull the Docker Compose images through registry.defectdojo.com
docker-compose.yml now names its DefectDojo images
${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-*.
registry.defectdojo.com redirects every request to the same images on
Docker Hub; nothing is stored or changed there. It logs each pull so the
project can see where DefectDojo is installed.
DD_IMAGE_REGISTRY switches it off: docker.io pulls straight from Docker
Hub, and a mirror's host pulls from the mirror. `docker compose build`
tags images with the same name the file resolves to, so building and
running works either way.
CI sets DD_IMAGE_REGISTRY=docker.io in every workflow that runs Docker
Compose. The integration, performance and REST framework tests load
images CI built itself, tagged defectdojo/... (the same reference as
docker.io/defectdojo/...), so compose keeps using those builds instead of
pulling published images, and CI pulls never count as installs.
readme-docs/DOCKER.md documents the registry and the opt-out.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Say plainly what registry.defectdojo.com logs and why, where people will see it
The notice now lives at the top of docker-compose.yml and in DOCKER.md: who runs the
host, what a pull logs, that the IP is deleted within three days and the rest kept
up to 13 months, that DefectDojo may reach out about its products or for feedback,
the one-variable opt-out, and how to object. Links to section 1.4 of the privacy policy.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs: say what registry.defectdojo.com logs next to the Compose install steps (#16176)
Ships with #16121, which makes docker-compose.yml pull through the registry. The
Compose comment is the first-layer notice, but most people install from this page
and never open the YAML, so the same facts and the policy link live here too.
English only for now; the translated pages pick it up on the next pass.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* Helm: add the chart repo from charts.defectdojo.com, with a privacy notice (#16178)
* Helm: add the chart repo from charts.defectdojo.com, with the notice
Companion to #16121 (Compose through registry.defectdojo.com). The chart README now adds
the repo from charts.defectdojo.com, which serves the same index and redirects chart
downloads to GitHub. Next to the command it says what's logged, how long it's kept, why,
the GitHub URL to use instead, how to object, and links section 1.4 of the privacy policy.
The docs Kubernetes install section says the same in one sentence. Images are unchanged:
the chart still pulls from Docker Hub by default.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Helm: note the chart repo change in artifacthub.io/changes
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(webhook gateway): the database role is named after the database (#16184)
The gateway's login role now defaults to <database>_webhook_gateway
(DD_WEBHOOK_GATEWAY_DB_ROLE=auto), since PostgreSQL roles belong to the
whole server and installations can share one. Explains the ownership
comment that keeps one installation from changing another's role, and
updates the administrator statements and cleanup steps.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(sandbox): the Pro sandbox, and turning it on self-hosted (#16185)
Adds the Sandbox page under Administration (opening it, accounts and
personas, Reset and Wipe, what the sandbox blocks, its API, how it counts
against the license, and how it is turned on for DefectDojo Cloud and
self-hosted) and a self-hosted page under On-Premise covering the one
setting that turns it on, the database privileges it needs, what it
creates, how the two sides are kept apart, troubleshooting, backups, and
removal.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(connectors): document the Microsoft Azure asset connector (#15841)
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* docs(connectors): Security Hub asset grouping and organization placement (#16179)
Documents the optional Asset Grouping field (account and region, resource
type, resource), how switching grouping moves findings, the optional
Organization Placement field, and the optional organizations:ListAccounts
permission used for account names.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(hierarchy): moving assets between organizations and the bulk update API (#16180)
Describes what an organization move does to the hierarchy (the subtree moves
along unless move_children is false, a parent left in the old organization
is detached and its owners are notified, priority is recalculated in both
organizations), the same-organization rule for parents, and
POST /api/v2/assets/bulk_update/ with its fields, limits and all-or-nothing
behavior.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(risk-acceptance): describe the Exception Requested finding-table column (#16031)
The "Requested exceptions in your metrics" section pointed readers at the
has_pending_exception API filter as the only way to build the exception
queue. DefectDojo Pro's finding tables now offer an Exception Requested
column (hidden by default) with a Yes/No filter, so describe that first and
keep the API filter name as the alternative.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* docs(locations): cloud resource drift matching and the endpoint migration boundary (#16032)
* docs(locations): cloud resource drift matching and the endpoint migration boundary
Add two decisions to the OSS docs for the CloudResource location work.
The endpoint migration guide now says the migration does not convert
cloud resources held in Endpoint rows. Those rows keep migrating as
URL Locations. A cloud connector re-import is the way to get a real
Cloud Resource Location.
The location drift matching guide now documents cloud resource
matching. A cloud resource matches on its provider-assigned
identifier alone, with no fuzzy matching.
* docs(locations): note the dedupe effect for cloud resource findings
Say what a user sees after the Pro change. Two findings on two different cloud
resources are never duplicates. An earlier merge does not survive the next
import.
* docs(dedupe): state what the cloud resource check does and does not do
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(connectors): document the Defender "Consolidate Findings by Vulnerability" option (#16169)
Describes the new opt-in connector setting: one finding per CVE and software
version per device group, affected devices attached as endpoints, device
status following each sync, and the re-baseline caveat when toggling it on
an existing connector.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* docs(connectors): what happens to imported findings when a record is re-mapped (#16181)
Describe the Move (default) and Start fresh choices offered when a mapped
Record is pointed at a different Asset, the permission it needs, what
Auto-Mapping does, and the remap_findings field on the assign_product API.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(connectors): document the Backstage lifecycle and owner-description sync (#16182)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(locations): describe the Location page's Custom Fields card and Referenced by table (#16183)
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(triage-engine): computed destinations, connector attributes, organization membership node (#16192)
Document how Set Organization, Set Parent and Assign SLA Configuration can work
their destination out per asset (tag, field, custom field, connector attribute or
name segment, with an optional mapping table and transforms), the new Add
Organization Membership node, the connector.* paths asset rules can read, and what
Preview shows for computed destinations. Includes two worked examples: placing
assets by team tag and placing AWS accounts by OU.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs: finish onboarding with the assets needing attention list (#16193)
Describe the Needs Attention page in DefectDojo Pro: the two reasons an
asset is listed (left in a connector's default organization, or missing
any of the five priority fields), how unset is decided for each field,
the bulk and rule actions, the What Drives Priority and SLA card on the
asset page, the onboarding complete measure and its dashboard widget,
and the /api/v2 endpoints.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(connectors): asset grouping and organization placement for Defender for Cloud, Prowler, Google Cloud SCC and Lacework (#16194)
Documents the optional Asset Grouping field (finer assets linked to their
parents, flip behavior, discovery and retention, prefixed tags) and, where
available, the Organization Placement field for four cloud connectors.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(asset modelling): plan your hierarchy, and what reorganizing later changes (#16195)
Two pages in the Pro hierarchy section:
- Plan your hierarchy: why the structure matters for reporting,
deduplication scope, access and priority; three common patterns;
a copyable LLM planning prompt in the same format as the report and
dashboard prompts; four checks for the result; the five priority
fields to plan alongside the tree; a setup order.
- You can reorganize later: what changes and what stays the same when
an Asset moves to another Organization, when many move at once, when
an Asset is re-parented, and when a Connector Record is re-mapped
(Move or Start fresh).
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(assets): container image repositories as shared asset identity (#16196)
Document the oci namespace's Repository alias: how connectors that report the
same container image repository resolve to one asset, the normalization table,
declaring a repository by hand, how disagreements surface as repository
conflicts and how to settle them with Move, and the backfill_oci_aliases
command. The auto-mapping order on Managing Records gains the repository step.
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* docs(connectors): describe the Checkmarx One Result States filter (#16134)
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* Docs: Security Hub account parents, OU and account tag placement, and re-placing existing assets (#16190)
* docs(connectors): Security Hub asset grouping and organization placement
Documents the optional Asset Grouping field (account and region, resource
type, resource), how switching grouping moves findings, the optional
Organization Placement field, and the optional organizations:ListAccounts
permission used for account names.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* docs(connectors): Security Hub account parent assets, OU and account tag placement, and re-placing existing assets
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* Docs: change plans, review every hierarchy change before it happens (#16191)
* docs(hierarchy): moving assets between organizations and the bulk update API
Describes what an organization move does to the hierarchy (the subtree moves
along unless move_children is false, a parent left in the old organization
is detached and its owners are notified, priority is recalculated in both
organizations), the same-organization rule for parents, and
POST /api/v2/assets/bulk_update/ with its fields, limits and all-or-nothing
behavior.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* docs(hierarchy): change plans, review every hierarchy change before it happens
A new page under the asset hierarchy docs covering the change plans API,
the CSV format and its round trip, review in the UI, apply, stale plans
and undo, plus a pointer to dry runs from the bulk update section.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* Update versions in application files
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: DefectDojo release bot <dojo-release-bot@users.noreply.github.com>
Co-authored-by: Ross E Esposito <ross@defectdojo.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Greg Anderson <greg.anderson@owasp.org>
Co-authored-by: devGregA <greg-agent-2@defectdojo.com>
Co-authored-by: Ross Esposito <rossespo@gmail.com>
Co-authored-by: Greg Anderson <greg@Gregs-MBP.lan>
Co-authored-by: Jaimin Parmar <132206640+Jaimin2687@users.noreply.github.com>
Co-authored-by: Paul Osinski <42211303+paulOsinski@users.noreply.github.com>
Co-authored-by: Sam Vader <sam@defectdojo.com>
Co-authored-by: Jino Tesauro <53376807+Jino-T@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: rossops <20447042+rossops@users.noreply.github.com>
Co-authored-by: Blake Owens <76979297+blakeaowens@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds a Pro documentation page,
navigation/PRO__support.md, for the Support pages in DefectDojo Pro. It also lists Support under License & Support innavigation/PRO__sidebar.md.The new page covers:
The page also says that the support pages need no environment variables.
The page uses the same front matter as
navigation/PRO__sidebar.mdand the Pro-feature notice that the other Pro pages use. The docs dry-run build passes on this branch. The page's path is/navigation/pro__support/.