Skip to content

2.6.0 👾 (security release)

Choose a tag to compare

@github-actions github-actions released this 04 Jan 18:18
3e454d1

Please consult the security advisories GHSA-f82x-m585-gj24 (moderate) and GHSA-v7fv-g69g-x7p2 (high) to see what security issues were fixed in this release. These will be published and become visible at January 18th, 2022.

Please consult the Upgrade notes in the documentation for specific instructions for this release, and general upgrade instructions. Below is an automatically generated list of all PRs merged since the previous release.

Changes since 2.5.0

  • Add header to nginx configuration @StefanFl (#5674)
  • Add UI label to PR labeler and release drafter @kiblik (#5586)
  • docs: add pointer to open items for DD_ASYNC_FINDING_IMPORT @valentijnscholten (#5639)
  • Reversed x-axis on Product's Detailed Metrics Page @blakeaowens (#5617)
  • Fix: filesystem not to be writable by the defectdojo user @dsever (#5284)
  • feat(helm-chart): celery worker app_settings @qlimenoque (#5573)
  • Fix typo @fabaff (#5575)
  • Release: Merge back 2.5.0 into dev from: master-into-dev/2.5.0-2.6.0-dev @github-actions (#5570)
  • Release: Merge release into master from: release/2.5.0 @github-actions (#5569)

🚩 Changes to settings.dist.py / local_settings.py

  • Release: Merge release into master from: release/2.6.0 @github-actions (#5676)
  • New parser for pip-audit @StefanFl (#5642)
  • Move USER_PROFILE_EDITABLE to system_settings @dsever (#5611)
  • Support version 8 of gitleaks @StefanFl (#5625)
  • Solar change deduplication model @zapililirad (#5620)
  • Configuration authorization: Permission checks and editing of permissions for users and groups @StefanFl (#5423)
  • Revert "Release: Merge release into master from: release/2.5.0" @Maffooch (#5567)

🚩 Database migration

  • Release: Merge release into master from: release/2.6.0 @github-actions (#5676)
  • Remove Objects_Engagement and introduce flag to enable/disable Objects_Product @StefanFl (#5608)
  • Fix database migration for deletion of development environments @StefanFl (#5649)
  • Restrict deletion of environments @StefanFl (#5592)
  • Move USER_PROFILE_EDITABLE to system_settings @dsever (#5611)
  • Configuration authorization: Permission checks and editing of permissions for users and groups @StefanFl (#5423)
  • Add migration to enable/disable Google Sheets and Rules Framework (PR 1 of 3) @Maffooch (#5587)
  • Revert "Release: Merge release into master from: release/2.5.0" @Maffooch (#5567)

🚩 Security

🚀 New importers

🚀 General features and enhancements

  • Updating engineer metrics and removing research metrics @StefanFl (#5613)
  • Configuration authorization 2: Making more staff-permissions configurable @StefanFl (#5621)
  • Mail notification improvement @kiblik (#5610)
  • Give readers the permission to add notes @StefanFl (#5593)
  • Show descriptions for scan types on pages for import and re-import @StefanFl (#5645)
  • Move USER_PROFILE_EDITABLE to system_settings @dsever (#5611)
  • Disable not supported notifications @dsever (#5624)

🚀 API features and enhancements

  • Release: Merge release into master from: release/2.6.0 @github-actions (#5676)
  • Adjust several permissions for API and UI @StefanFl (#5672)
  • Close old findings of same service only @StefanFl (#5631)
  • Configuration authorization 2: Making more staff-permissions configurable @StefanFl (#5621)
  • simplify and add comments for auto_create_context @valentijnscholten (#5591)
  • add scan_date fix also for reimport, fix validation @valentijnscholten (#5574)
  • Configuration authorization: Permission checks and editing of permissions for users and groups @StefanFl (#5423)
  • Revert "Release: Merge release into master from: release/2.5.0" @Maffooch (#5567)

🐛 Bug Fixes

🧰 Maintenance

🖌 Updates in UI

  • Adjust several permissions for API and UI @StefanFl (#5672)
  • Updating engineer metrics and removing research metrics @StefanFl (#5613)
  • Remove Objects_Engagement and introduce flag to enable/disable Objects_Product @StefanFl (#5608)