Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Release: Merge release into master from: release/2.45.2 #12286

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 7 commits into from
Apr 22, 2025
Merged

Conversation

github-actions[bot]
Copy link
Contributor

Release triggered by Maffooch

DefectDojo release bot and others added 7 commits April 14, 2025 16:03
….46.0-dev

Release: Merge back 2.45.1 into bugfix from: master-into-bugfix/2.45.1-2.46.0-dev
* sla calc: add unit tests

* sla calc: add unit tests

* sla calc: add unit tests

* linting

* sla: simplify

* sla config: cleanup

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <[email protected]>

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <[email protected]>

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <[email protected]>

* Update unittests/test_sla_calculations.py

Co-authored-by: Blake Owens <[email protected]>

---------

Co-authored-by: Blake Owens <[email protected]>
* 🎉 Implement Fortify Webinspect new report format

* update

* fix

* update

* update

* update

* update

* update

* update according to comment

* docs update

* fix
* merge all jira articles into single article

* reweight articles

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: Charles Neill <[email protected]>

* add wiz documentation

* Update docs/content/en/share_your_findings/jira_guide.md

Co-authored-by: valentijnscholten <[email protected]>

* update Pro features docs

* reorganize support docs

* rework import documentation for OS context

* update changelog 2.45.1

* fix broken links

---------

Co-authored-by: Paul Osinski <[email protected]>
Co-authored-by: Charles Neill <[email protected]>
Co-authored-by: valentijnscholten <[email protected]>
@Maffooch Maffooch closed this Apr 22, 2025
@Maffooch Maffooch reopened this Apr 22, 2025
@github-actions github-actions bot added settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR docs unittests ui parser helm labels Apr 22, 2025
Copy link

dryrunsecurity bot commented Apr 22, 2025

DryRun Security

This pull request contains documentation updates that reveal potential security considerations around dependency management, sensitive credential handling, and information disclosure risks, with recommendations to carefully manage service account credentials, use authenticated links, and be cautious about external references.

💭 Unconfirmed Findings (5)
Vulnerability Dependency Management Risks
Description Using direct GitHub repository references could introduce security risks if upstream repositories are compromised. Version ranges might inadvertently pull in newer versions with potential security updates.
Vulnerability External Links and Information Disclosure
Description Documentation files include external links to Wiz, OWASP, and other resources. Some links require authentication to help mitigate potential information exposure risks.
Vulnerability Sensitive Information Handling
Description Wiz connector documentation guides users to create service accounts and input sensitive credentials like Client ID and Client Secret, which could pose a risk of credential exposure if not properly managed.
Vulnerability Potential Information Disclosure
Description Documentation patches reveal details about Pro features, tool integrations, and import mechanisms, which could provide insights into application internals.
Vulnerability URL Security Considerations
Description Most documentation links use HTTPS, but some example curl commands include placeholders for sensitive information that could be misused if not carefully handled.

All finding details can be found in the DryRun Security Dashboard.

@Maffooch Maffooch merged commit 8e7cc01 into master Apr 22, 2025
76 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docs helm parser settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui unittests
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants