Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Release: Merge back 2.45.0 into bugfix from: master-into-bugfix/2.45.0-2.46.0-dev #12188

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 134 commits into from
Apr 7, 2025

Conversation

github-actions[bot]
Copy link
Contributor

@github-actions github-actions bot commented Apr 7, 2025

Release triggered by Maffooch

DefectDojo release bot and others added 30 commits March 3, 2025 16:51
….0-dev

Release: Merge back 2.44.0 into dev from: master-into-dev/2.44.0-2.45.0-dev
Bumps openapitools/openapi-generator-cli from v7.11.0 to v7.12.0.

---
updated-dependencies:
- dependency-name: openapitools/openapi-generator-cli
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [cryptography](https://github.com/pyca/cryptography) from 44.0.1 to 44.0.2.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@44.0.1...44.0.2)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.3 to 1.37.4.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.3...1.37.4)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [drf-spectacular-sidecar](https://github.com/tfranzel/drf-spectacular-sidecar) from 2025.2.1 to 2025.3.1.
- [Commits](tfranzel/drf-spectacular-sidecar@2025.2.1...2025.3.1)

---
updated-dependencies:
- dependency-name: drf-spectacular-sidecar
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…11927)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…7.4-alpine (docker-compose.yml) (#11922)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.4 to 1.37.5.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.4...1.37.5)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…7 to v7.0.8 (.github/workflows/update-sample-data.yml) (#11939)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…2.16.1 (docker-compose.override.unit_tests_cicd.yml) (#11941)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…11916)

* Update parser documentation template to include additional detail beneficial to users & maintainers.

* Update parser-documentation-template.md

Small edits

---------

Co-authored-by: skywalke34 <[email protected]>
…cs/package.json) (#11944)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.5 to 1.37.6.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.5...1.37.6)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [easymde](https://github.com/Ionaru/easy-markdown-editor) from 2.19.0 to 2.20.0.
- [Changelog](https://github.com/Ionaru/easy-markdown-editor/blob/master/CHANGELOG.md)
- [Commits](Ionaru/easy-markdown-editor@2.19.0...2.20.0)

---
updated-dependencies:
- dependency-name: easymde
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.6 to 1.37.7.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.6...1.37.7)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.7 to 1.37.8.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.7...1.37.8)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…e.json) (#11967)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [pycurl](https://github.com/pycurl/pycurl) from 7.45.4 to 7.45.6.
- [Changelog](https://github.com/pycurl/pycurl/blob/master/ChangeLog)
- [Commits](https://github.com/pycurl/pycurl/commits)

---
updated-dependencies:
- dependency-name: pycurl
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Added first warning

* Added warnings to async_process_findings

* Added comments to settings to show deprecation

* Moved import statement to top of file

* Update default_importer.py

* Update default_importer.py

* Update default_reimporter.py

---------

Co-authored-by: Jino Tesauro <[email protected]>
….0-dev

Release: Merge back 2.44.1 into dev from: master-into-dev/2.44.1-2.45.0-dev
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.9.9 to 0.9.10.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.9.9...0.9.10)

---
updated-dependencies:
- dependency-name: ruff
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.8 to 1.37.9.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.8...1.37.9)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…pages.yml) (#11987)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.37.9 to 1.37.10.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.37.9...1.37.10)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2.17.1 (docker-compose.override.unit_tests_cicd.yml) (#11975)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…helm/defectdojo/chart.yaml) (#11978)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
kevin-vuong99 and others added 6 commits April 6, 2025 20:45
* session-expire-notification

* move return to else block

* remove unused variables expiry time and update context processor name

---------

Co-authored-by: Kevin Vuong <[email protected]>
* Ruff: Add B018 rule

* update

* fix
Release: Merge release into master from: release/2.45.0
Copy link
Contributor Author

github-actions bot commented Apr 7, 2025

This pull request has conflicts, please resolve those before we can evaluate the pull request.

Copy link

dryrunsecurity bot commented Apr 7, 2025

DryRun Security Summary

Multiple security vulnerabilities were identified in GitHub Actions workflows and configuration files for the DefectDojo project, including exposed email addresses, hardcoded default credentials, insecure network configurations, and sensitive environment variables.

Expand for full summary

Summary: Multiple GitHub Actions workflows and configuration files were updated, primarily focusing on version bumps, platform flexibility, and minor configuration changes across the DefectDojo project.

Security Findings:

  1. Email Exposure Vulnerability:

    • File: .github/pr-reminder.py
    • Risk: Revealed internal email address ([email protected])
    • Potential Information Disclosure
  2. Hardcoded Credentials/Sensitive Information:

    • File: Dockerfile.integration-tests-debian
    • Risks:
      • Default admin user: DD_ADMIN_USER=admin
      • Empty admin password: DD_ADMIN_PASSWORD=''
      • Insecure base URL: DD_BASE_URL="http://localhost:8080/"
      • HTTP downloads for Chrome and ChromeDriver
  3. Default Credentials in Development Configurations:

    • File: docker-compose.override.dev.yml
    • Risks:
      • DD_ADMIN_USER defaults to "admin"
      • DD_ADMIN_PASSWORD defaults to "admin"
      • Debug mode enabled (DD_DEBUG: 'True')
  4. Sensitive Environment Variables:

    • File: docker-compose.yml
    • Risks:
      • DD_DATABASE_PASSWORD with default value "defectdojo"
      • Default DD_SECRET_KEY
      • Default DD_CREDENTIAL_AES_256_KEY
  5. Network Security Concerns:

    • File: Dockerfile.integration-tests-debian
    • Risks:
      • Direct downloads using HTTP
      • Potential for network interception or manipulation

Code Analysis

We ran 7 analyzers against 27 files and 1 analyzer had findings. 6 analyzers had no findings.

Analyzer Findings
Configured Codepaths Analyzer 6 findings

Overall Riskiness

🔴 Risk threshold exceeded.

We've notified @mtesauro.

View PR in the DryRun Dashboard.

Copy link
Contributor Author

github-actions bot commented Apr 7, 2025

Conflicts have been resolved. A maintainer will review the pull request shortly.

@github-actions github-actions bot added docker New Migration Adding a new migration file. Take care when merging. settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 docs unittests integration_tests ui parser helm lint and removed conflicts-detected labels Apr 7, 2025
@Maffooch Maffooch merged commit 3f037d2 into bugfix Apr 7, 2025
78 of 79 checks passed
@Maffooch Maffooch deleted the master-into-bugfix/2.45.0-2.46.0-dev branch April 7, 2025 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
apiv2 docker docs helm integration_tests lint New Migration Adding a new migration file. Take care when merging. parser settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui unittests
Projects
None yet
Development

Successfully merging this pull request may close these issues.

10 participants