-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add pro release notes for 2.41.4 #11483
Conversation
DryRun Security SummaryThe pull request updates the DefectDojo Pro changelog with API modifications, Beta UI improvements, and Generic Findings Import parser enhancements, while also highlighting potential security considerations related to the 'Force To Active / Verified' flag and the new Expand for full summarySummary: The code changes in this pull request primarily focus on updating the changelog for the DefectDojo Pro (Cloud Version) application. The key changes include API updates, Beta UI improvements, and changes to the Generic Findings Import parser. From an application security perspective, the changes to the 'Force To Active / Verified' flag in the API endpoints are worth noting. This flag is used to control the initial status of findings imported into the system, and the change to make this flag optional could potentially lead to security issues if users are not careful about the default status they choose for imported findings. The application security team should ensure that all findings are properly triaged and marked as active or inactive based on their risk level. Additionally, the new Files Changed:
Code AnalysisWe ran |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approved
* add release notes for 2.41.4 * Update changelog.md --------- Co-authored-by: Paul Osinski <[email protected]>
Release notes for DefectDojo Pro 2.41.4: