-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Release: Merge release into master from: release/2.39.3 #11144
Conversation
….40.0-dev Release: Merge back 2.39.2 into bugfix from: master-into-bugfix/2.39.2-2.40.0-dev
Old link does not work
* JIRA Finding Groups: Accommodate status function inconsistency * Fix ruff
…ds (#11135) * Threat Uploads: Server side file extension validation + force downloads * Fix ruff
DryRun Security SummaryThe pull request includes a wide range of updates to the DefectDojo application, including version updates, bug fixes, security improvements, and testing enhancements across various components, with a focus on improving the overall security and reliability of the platform. Expand for full summarySummary: The code changes in this pull request cover a wide range of updates to the DefectDojo application, including version updates, bug fixes, security improvements, and testing enhancements. The changes span across various components of the application, such as the Jira integration, file upload handling, vulnerability parsing, and Helm chart configuration. From an application security perspective, the changes generally appear to be positive and focused on improving the overall security and reliability of the DefectDojo platform. Key security-related improvements include:
While the changes do not appear to introduce any immediate security vulnerabilities, it is important to thoroughly review the code, configuration, and dependencies to ensure the ongoing security and integrity of the application. Additionally, regular security audits and vulnerability assessments are recommended to identify and address any potential security issues that may arise in the future. Files Changed:
Code AnalysisWe ran
Riskiness🟢 Risk threshold not exceeded. |
Release triggered by
rossops