Skip to content

⬆️ Bump ruff from 0.14.6 to 0.14.8#13799

Merged
Maffooch merged 8 commits into
DefectDojo:devfrom
manuel-sommer:bump_ruff0147
Dec 5, 2025
Merged

⬆️ Bump ruff from 0.14.6 to 0.14.8#13799
Maffooch merged 8 commits into
DefectDojo:devfrom
manuel-sommer:bump_ruff0147

Conversation

@manuel-sommer
Copy link
Copy Markdown
Contributor

@manuel-sommer manuel-sommer commented Dec 1, 2025

@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Dec 1, 2025

DryRun Security

🔴 Risk threshold exceeded.

This pull request modifies a sensitive file (dojo/importers/base_importer.py) and the scanner flagged multiple sensitive edits to that path; update rules for sensitive paths and allowed authors can be configured in .dryrunsecurity.yaml if these changes are expected. Please review those edits carefully since they hit a configured sensitive codepath.

🔴 Configured Codepaths Edit in dojo/importers/base_importer.py
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.
🔴 Configured Codepaths Edit in dojo/importers/base_importer.py
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.
🔴 Configured Codepaths Edit in dojo/importers/base_importer.py
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.

We've notified @mtesauro.


All finding details can be found in the DryRun Security Dashboard.

@mtesauro
Copy link
Copy Markdown
Contributor

mtesauro commented Dec 1, 2025

Helm test failure appears to be from today's release not from this update.

Copy link
Copy Markdown
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

Comment thread dojo/importers/base_importer.py Outdated
Copy link
Copy Markdown
Contributor

@Maffooch Maffooch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed with the feedback from @kiblik

Comment thread dojo/labels.py
@manuel-sommer manuel-sommer changed the title ⬆️ Bump ruff from 0.14.6 to 0.14.7 ⬆️ Bump ruff from 0.14.6 to 0.14.8 Dec 5, 2025
@manuel-sommer
Copy link
Copy Markdown
Contributor Author

can we merge this now?

@Maffooch Maffooch merged commit 38950fe into DefectDojo:dev Dec 5, 2025
149 of 150 checks passed
@manuel-sommer manuel-sommer deleted the bump_ruff0147 branch December 5, 2025 21:43
Maffooch pushed a commit to valentijnscholten/django-DefectDojo that referenced this pull request Feb 16, 2026
* ⬆️ Bump ruff from 0.14.6 to 0.14.7

* ruff fixes

* Update dojo/importers/base_importer.py

Co-authored-by: kiblik <5609770+kiblik@users.noreply.github.com>

* Fix indentation in base_importer.py

* Update labels.py

* bump

---------

Co-authored-by: kiblik <5609770+kiblik@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants