-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Release: Merge release into master from: release/2.41.0 #11357
Conversation
….0-dev Release: Merge back 2.40.0 into dev from: master-into-dev/2.40.0-2.41.0-dev
Bumps [boto3](https://github.com/boto/boto3) from 1.35.53 to 1.35.54. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.53...1.35.54) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.7.1 to 0.7.2. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.7.1...0.7.2) --- updated-dependencies: - dependency-name: ruff dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pdfmake](https://github.com/bpampuch/pdfmake) from 0.2.14 to 0.2.15. - [Release notes](https://github.com/bpampuch/pdfmake/releases) - [Changelog](https://github.com/bpampuch/pdfmake/blob/0.2.15/CHANGELOG.md) - [Commits](bpampuch/pdfmake@0.2.14...0.2.15) --- updated-dependencies: - dependency-name: pdfmake dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matt Tesauro <[email protected]>
Co-authored-by: Matt Tesauro <[email protected]>
Bumps [django](https://github.com/django/django) from 5.1.2 to 5.1.3. - [Commits](django/django@5.1.2...5.1.3) --- updated-dependencies: - dependency-name: django dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.35.54 to 1.35.55. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.54...1.35.55) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.35.55 to 1.35.56. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.55...1.35.56) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fix(helm): add missing env config on job The job isn't working well when using external database because the init container checking if the database is accessible isn't taking the same env values as the container that is initializing the database config * fix(helm): remove unused env * chore(helm): prefer using with over if
….0-dev Release: Merge back 2.40.1 into dev from: master-into-dev/2.40.1-2.41.0-dev
Co-authored-by: Pedro Souza <[email protected]>
Co-authored-by: Raouf HADDADA <[email protected]>
* 🐛 fix renovate ruff update * ruff * Update dojo/api_v2/serializers.py Co-authored-by: Charles Neill <[email protected]> --------- Co-authored-by: Charles Neill <[email protected]>
* Ruff: Add and fix S113 * Update dojo/settings/settings.dist.py Co-authored-by: Charles Neill <[email protected]> --------- Co-authored-by: Charles Neill <[email protected]> Co-authored-by: Matt Tesauro <[email protected]>
* Ruff: Add and fix PTH113 * sha sum * sha sum
Bumps [boto3](https://github.com/boto/boto3) from 1.35.56 to 1.35.58. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.56...1.35.58) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ocker-compose.yml) (#11239) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* Ruff: Add and fix PTH120 * fix dedupe_test * fix dedupe_test * fix * sha sum * ruff * retrigger unittest * sha sum
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…11330) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* Ruff: add SIM * Ruff: fix some SIM
Bumps [boto3](https://github.com/boto/boto3) from 1.35.69 to 1.35.70. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.69...1.35.70) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…e.json) (#11337) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* Fix sarif parser locations files processing * Fix tests * linter fixes * fix snippet for each file hit * fix snippet
Bumps [python-gitlab](https://github.com/python-gitlab/python-gitlab) from 5.0.0 to 5.1.0. - [Release notes](https://github.com/python-gitlab/python-gitlab/releases) - [Changelog](https://github.com/python-gitlab/python-gitlab/blob/main/CHANGELOG.md) - [Commits](python-gitlab/python-gitlab@v5.0.0...v5.1.0) --- updated-dependencies: - dependency-name: python-gitlab dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.10.0 to 2.10.1. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.10.0...2.10.1) --- updated-dependencies: - dependency-name: pyjwt dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…json) (#11348) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.35.70 to 1.35.71. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.35.70...1.35.71) --- updated-dependencies: - dependency-name: boto3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [cryptography](https://github.com/pyca/cryptography) from 43.0.3 to 44.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@43.0.3...44.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Release 2.41.0: Merge Bugfix into Dev
DryRun Security SummaryThe pull request includes various updates to the DefectDojo application's infrastructure, dependencies, and configuration, focusing on maintaining the security and stability of the application. Expand for full summarySummary: The code changes in this pull request cover a variety of updates, including changes to the The key security-related aspects of these changes include:
While there are no immediate security concerns raised by these changes, it is important to continue monitoring the application's dependencies and infrastructure for any potential vulnerabilities that may arise in the future. Additionally, thorough testing of the application after these changes is recommended to ensure that there are no regressions or unintended consequences. Files Changed:
Code AnalysisWe ran
|
Release triggered by
rossops