From efa042b31bd35fbdd18a7f56f244dac4f60feb52 Mon Sep 17 00:00:00 2001 From: blakeaowens Date: Wed, 23 Sep 2026 22:29:56 -0500 Subject: [PATCH 1/3] docs(navigation): language and localization page --- .../navigation/language_and_localization.md | 73 +++++++++++++++++++ 1 file changed, 73 insertions(+) create mode 100644 docs/content/navigation/language_and_localization.md diff --git a/docs/content/navigation/language_and_localization.md b/docs/content/navigation/language_and_localization.md new file mode 100644 index 00000000000..78422371fb4 --- /dev/null +++ b/docs/content/navigation/language_and_localization.md @@ -0,0 +1,73 @@ +--- +title: "Language and Localization" +description: "Choose the language DefectDojo's interface is shown in, and understand which languages are offered and what stays in English" +weight: 12 +--- + +DefectDojo can show its interface in a language other than English. The choice belongs to each +user, not to the instance: two people signed in to the same DefectDojo can read it in two +different languages, and neither setting affects the other. + +## Choosing a language + +Open the **language** button and pick from the list. Where that button is depends on which +interface you are in: + +- **DefectDojo Pro**: the globe icon in the sidebar, between your account button and the alerts + bell. The interface switches as soon as you choose, with no reload. +- **DefectDojo (open source)**: the **Language** field on your profile page, saved with the rest + of the form. + +Both write the same setting, so choosing a language in one interface changes it in the other. +The choice follows your account rather than the browser: sign in from a different computer and +the interface is already in the language you picked. + +## Which languages are offered + +The menu lists only languages whose translations are complete. A language is added to the list +when every message in the interface has been translated and checked, so you should never see a +page that is half translated. Languages still being worked on are not offered at all. + +English is always available and is the language a new account starts in, unless an administrator +has set a different default for the instance. + +Right-to-left languages (Arabic, Hebrew, Persian, Urdu) are held back until the mirrored layout +has been verified, so they do not appear in the menu yet even where their translations exist. + +## What is translated, and what is not + +**Translated**: menus, buttons, headings, form labels, help text, confirmation dialogs, table +column headers and the messages DefectDojo shows you. + +**Not translated**, deliberately: + +- **Your data.** Finding titles, asset and organization names, descriptions, tags, notes and + anything else you or your tools entered stays exactly as written. A finding imported from a + scanner reads the same in every language. +- **Values the API uses.** A finding's severity is `Critical` in every language: what changes is + the label on screen, not the value stored, exported or sent to an integration. Automation + written against the API keeps working, and a report exported in one language carries the same + values as the same report exported in another. +- **Commands, settings names and identifiers.** A management command, an environment variable + and a CVE identifier are the same everywhere. +- **Content from connected tools.** Text that Jira, a scanner or another integration supplies is + passed through as it arrives. + +## Machine translation + +Translations other than English are machine generated and reviewed for completeness rather than +for style. They are accurate enough to work in, and they are corrected over time. If a phrase +reads badly in your language, tell your DefectDojo contact: the fix is applied to the whole +interface rather than to that one screen. + +## For administrators + +The instance's default language is `DD_LANGUAGE_CODE` (default `en-us`). It applies to anyone who +has not chosen a language and to places that run without a signed-in user, such as a scheduled +notification. + +A user's language is stored on their profile, so you can set it for them from the user +administration page in the same place you set their other contact details. + +Notifications, scheduled reports and other messages generated outside a browser session use the +instance default rather than the recipient's language. From ab733d4344f7ae17e3c4667da1f9b2f3b8f769a6 Mon Sep 17 00:00:00 2001 From: blakeaowens Date: Thu, 24 Sep 2026 16:02:08 -0500 Subject: [PATCH 2/3] docs(navigation): a notification is written in the recipient's language The page said notifications use the instance default rather than the recipient's language. That was true when it was written and is no longer: a notification addressed to a person is now rendered in that person's language, whichever language the event was triggered from. The distinction worth documenting is which destinations are not a person. A Slack or Teams channel, a webhook and the instance-wide notification address are read by many people with different preferences, so one language has to be chosen for them, and that is the instance default. Co-Authored-By: Claude Opus 5 --- docs/content/navigation/language_and_localization.md | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/docs/content/navigation/language_and_localization.md b/docs/content/navigation/language_and_localization.md index 78422371fb4..423dea131f5 100644 --- a/docs/content/navigation/language_and_localization.md +++ b/docs/content/navigation/language_and_localization.md @@ -39,6 +39,10 @@ has been verified, so they do not appear in the menu yet even where their transl **Translated**: menus, buttons, headings, form labels, help text, confirmation dialogs, table column headers and the messages DefectDojo shows you. +Notifications are translated too, and in **your** language rather than the language of whoever +caused them. If a colleague reading DefectDojo in German does something that notifies you, the +email you receive is in the language you chose. + **Not translated**, deliberately: - **Your data.** Finding titles, asset and organization names, descriptions, tags, notes and @@ -69,5 +73,7 @@ notification. A user's language is stored on their profile, so you can set it for them from the user administration page in the same place you set their other contact details. -Notifications, scheduled reports and other messages generated outside a browser session use the -instance default rather than the recipient's language. +A notification addressed to a person is written in that person's language, whichever language the +event was triggered from. Destinations that are not a person use the instance default instead: a +Slack or Microsoft Teams channel, a webhook, and the instance-wide notification email address are +read by many people with different preferences, so one language has to be chosen for them. From 77ba39d3a5b9f3641d5a07f8ad2263907bb0b154 Mon Sep 17 00:00:00 2001 From: blakeaowens Date: Fri, 25 Sep 2026 00:27:19 -0500 Subject: [PATCH 3/3] docs(navigation): open source offers the right-to-left languages today The page said they were held back until the mirrored layout was verified and so did not appear in the menu. That is not true of open source, which carries all four complete and flips the layout from LANGUAGE_BIDI, and this page is read by open source users first. It describes what the mirroring actually does instead, including the identifiers that keep their own direction, and states the Pro caveat separately. Co-Authored-By: Claude Opus 5 --- docs/content/navigation/language_and_localization.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/docs/content/navigation/language_and_localization.md b/docs/content/navigation/language_and_localization.md index 423dea131f5..951a1fa02f3 100644 --- a/docs/content/navigation/language_and_localization.md +++ b/docs/content/navigation/language_and_localization.md @@ -31,8 +31,13 @@ page that is half translated. Languages still being worked on are not offered at English is always available and is the language a new account starts in, unless an administrator has set a different default for the instance. -Right-to-left languages (Arabic, Hebrew, Persian, Urdu) are held back until the mirrored layout -has been verified, so they do not appear in the menu yet even where their translations exist. +Arabic, Hebrew, Persian and Urdu are written right to left. DefectDojo offers them, and the +interface mirrors to match: the navigation, spacing and alignment flip, while identifiers that +are read left to right whatever the surrounding language (a CVE number, a file path, a URL, a +command) keep their own direction, because reversing those would change what they say. + +The Pro interface offers them once its own translations are complete, which is tracked +separately from the open source ones. ## What is translated, and what is not