Skip to content

Release: Merge back 2.32.0 into bugfix from: master-into-bugfix/2.32.0-2.33.0-dev#9677

Merged
Maffooch merged 124 commits into
bugfixfrom
master-into-bugfix/2.32.0-2.33.0-dev
Mar 4, 2024
Merged

Release: Merge back 2.32.0 into bugfix from: master-into-bugfix/2.32.0-2.33.0-dev#9677
Maffooch merged 124 commits into
bugfixfrom
master-into-bugfix/2.32.0-2.33.0-dev

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Mar 4, 2024

Release triggered by Maffooch

DefectDojo release bot and others added 30 commits February 5, 2024 23:04
…0-dev

Release: Merge back 2.31.0 into dev from: master-into-dev/2.31.0-2.32.0-dev
…thub/workflows/release-drafter.yml) (#9460)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [pytz](https://github.com/stub42/pytz) from 2023.4 to 2024.1.
- [Release notes](https://github.com/stub42/pytz/releases)
- [Commits](stub42/pytz@release_2023.4...release_2024.1)

---
updated-dependencies:
- dependency-name: pytz
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [django-debug-toolbar](https://github.com/jazzband/django-debug-toolbar) from 4.2.0 to 4.3.0.
- [Release notes](https://github.com/jazzband/django-debug-toolbar/releases)
- [Changelog](https://github.com/jazzband/django-debug-toolbar/blob/main/docs/changes.rst)
- [Commits](django-commons/django-debug-toolbar@4.2...4.3)

---
updated-dependencies:
- dependency-name: django-debug-toolbar
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps nginx from `d12e6f7` to `f2802c2`.

---
updated-dependencies:
- dependency-name: nginx
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…9481)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…alpine (docker-compose.yml) (#9458)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.34.32 to 1.34.35.
- [Release notes](https://github.com/boto/boto3/releases)
- [Changelog](https://github.com/boto/boto3/blob/develop/CHANGELOG.rst)
- [Commits](boto/boto3@1.34.32...1.34.35)

---
updated-dependencies:
- dependency-name: boto3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…9459)

* Update dependency ruff from 0.1.15 to v0.2.1 (requirements-lint.txt)

* Fix ruff warning (#9461)

* Update dependency ruff from 0.1.15 to v0.2.0 (requirements-lint.txt)

* fix ruff warning

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: kiblik <tomas@kubla.sk>
Co-authored-by: Charles Neill <1749665+cneill@users.noreply.github.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
This reverts commit 0f55a7f.

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
…from cvss module when a CVSS vector string should evaluate to "Info" (#9453)

* dojo/importers/importer/importer.py - Change "None" string to "Info" from cvss module when a CVSS vector string evaluates to "Info"

* dojo/importers/importer/importer.py - Change "None" string to "Info" from cvss module when a CVSS vector string evaluates to "Info" #flake8_fix
* Rename unittest

* Define exceptions for now

* Announcement was implemented
…r checks (#9435)

* Fix unittests with assertRaises

* Replace assertTrue/False with better checks

* Fixes
* 🐛 fix wfuzz, issue #7863

* add 302

* update docs
* Set PYTHONWARNINGS=error

* Add basic filterwarnings

* Mute some warnings

* Mute one more warning
Bumps [vulners]() from 2.1.2 to 2.1.5.

---
updated-dependencies:
- dependency-name: vulners
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Override default Django APPEND_SLASH

* Update dojo/settings/settings.dist.py
* improvement for wazuh importer

* 🔧 change on dedupe for Wazuh

* 🔧 change on dedupe for Wazuh

* 📝

* ✏️

* 📝

* 📝

* flake8

* 🎉 recoded wazuh importer to support endpoints

* ✅ adjusted unittests

* 📝

* ✏️

* ✏️

---------

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
…alpine (docker-compose.yml) (#9501)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…9502)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
#9517)

* Modifying Bugcrowd API Parser to align to vendor documentation on what the not_applicable state means.  It is now active == False and severity == 'Info'. [sc-4217]

* fixing Flake8 errors

* fixing Flake8 errors, part deux
kiblik and others added 14 commits March 3, 2024 22:11
* Add support for findings with a GHSA but no CVE

* Update unit test to handle case with GHSA but no CVE

* Format JSON so it's human readable

* Also populate the CVE field to be as flexible as possible

* Unit tests to check cve value

* Add new line at bottom of file to fix linting issue
* add unittest file

* add unittest

* adapt parser

* fix unittest

* flake8
* 🔨 restructure openvas parser

* adapt csv parser

* fix csv parser

* fix xml parser

* flake8
* 🔨 restructure clair parser

* refactor clair

* refactor clairklar

* update

* flake8
* ✨ implement osv-scanner, #7321

* add unittest files

* add unittests

* 🚧 basic setup

* add docs

* flake8

* 🚧 not finished yet

* update

* add finding fields

* fix finding fields

* add severity

* fix severity

* fix reference

* add unittests

* fix unittest

* flake8

* add setting
* resolve doing, remove dead code

* more dead code

* ruff linter

* remove unnecessary todo
Release: Merge release into master from: release/2.32.0
@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Mar 4, 2024

Hi there 👋, @DryRunSecurity here, below is a summary of our analysis and findings.

DryRun Security Status Findings
Sensitive Functions Analyzer 0 findings
Configured Sensitive Files Analyzer 2 findings
Sensitive Files Analyzer 2 findings

Note

🔴 Risk threshold exceeded. Adding a reviewer if one is configured in .dryrunsecurity.yaml.

notification list: @mtesauro @grendel513

Tip

Get answers to your security questions. Add a comment in this PR starting with @DryRunSecurity. For example...

@dryrunsecurity What are common security issues with web application cookies?

Powered by DryRun Security

@Maffooch Maffooch closed this Mar 4, 2024
@Maffooch Maffooch reopened this Mar 4, 2024
@github-actions github-actions Bot added docker New Migration Adding a new migration file. Take care when merging. settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 docs unittests integration_tests ui parser helm localization labels Mar 4, 2024
@Maffooch Maffooch merged commit e88d490 into bugfix Mar 4, 2024
@Maffooch Maffooch deleted the master-into-bugfix/2.32.0-2.33.0-dev branch March 4, 2024 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

apiv2 docker docs helm integration_tests localization New Migration Adding a new migration file. Take care when merging. parser settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui unittests

Projects

None yet

Development

Successfully merging this pull request may close these issues.