Conversation
…form sits behind a link
… environment variables
Voters hear about a status change at the address on their DefectDojo user, and only when that address is at the domain of the organization's Cloud Portal account.
…-hosted section Support now appears in the settings menu on cloud, self-hosted and airgapped instances: Settings -> Support, or Settings -> License & Support -> Support in the reorganized menu. The sidebar page and its seven translated tables list the new entry. The self-hosted section now matches the hub: the first instance to enrol with a license keeps the enrolment and a second one is refused, staff can reset or revoke it, and a connector request from a self-hosted instance cannot carry tool details. It also names the two hosts the instance must reach, and the page paths gain their /ui/ prefix.
…hoice Each search suggestion now carries a tag that says community request or documentation. The request form also offers Security disclosure, which files nothing and points to DefectDojo's coordinated disclosure program on HackerOne.
The Support docs change stays English only. This removes the Support entry from the seven translated settings menu pages. The English sidebar page still lists it.
DefectDojo Pro reaches support through Settings > Support only. The help page and the sidebar tables no longer list the Contact Support entries.
|
This pull request contains multiple low-severity findings where the user 'svader0' modified various sensitive codepaths in the
Configured Sensitive Codepath Modified by Non-Allowed Author in
|
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/authorization/api_permissions.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/authorization/serializer_guards.py (drs_44ef0f9e)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/authorization/serializer_guards.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/endpoint/models.py (drs_3c50745e)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/endpoint/models.py' matches configured sensitive codepath pattern 'dojo/endpoint/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/engagement/services.py (drs_9ebe19d1)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/engagement/services.py' matches configured sensitive codepath pattern 'dojo/engagement/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/finding/deduplication.py (drs_1b601a08)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/finding/deduplication.py' matches configured sensitive codepath pattern 'dojo/finding/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/finding/helper.py (drs_ef18ffed)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/finding/helper.py' matches configured sensitive codepath pattern 'dojo/finding/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/finding_group/views.py (drs_233ae479)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/finding_group/views.py' matches configured sensitive codepath pattern 'dojo/finding_group/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/jira/views.py (drs_1891e30c)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/jira/views.py' matches configured sensitive codepath pattern 'dojo/jira/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/metrics/views.py (drs_49699b32)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/metrics/views.py' matches configured sensitive codepath pattern 'dojo/metrics/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/reports/queries.py (drs_9a5e2f44)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/reports/queries.py' matches configured sensitive codepath pattern 'dojo/reports/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/search/views.py (drs_3bdbb5a9)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/search/views.py' matches configured sensitive codepath pattern 'dojo/search/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/tasks.py (drs_909b7994)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/tasks.py' matches configured sensitive codepath pattern 'dojo/tasks.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/base.html (drs_fe274a39)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/base.html' matches configured sensitive codepath pattern 'dojo/templates/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/defectDojo-engagement-survey/list_surveys.html (drs_2e961e53)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/defectDojo-engagement-survey/list_surveys.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/request_endpoint_report.html (drs_47ce115a)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/request_endpoint_report.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/simple_search.html (drs_d1e9faf0)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/simple_search.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/support.html (drs_8cb5a6fc)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/support.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/view_product_details.html (drs_8af0c462)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/view_product_details.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/view_product_type.html (drs_aa21fd2e)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/view_product_type.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/view_user.html (drs_f37ff2fd)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templates/dojo/view_user.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templatetags/display_tags.py (drs_bfcf4dd0)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/templatetags/display_tags.py' matches configured sensitive codepath pattern 'dojo/templatetags/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/test/services.py (drs_c03bc0ce)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/test/services.py' matches configured sensitive codepath pattern 'dojo/test/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/urls.py (drs_3a2a9112)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/urls.py' matches configured sensitive codepath pattern 'dojo/urls.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/user/models.py (drs_9a2ecc72)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/user/models.py' matches configured sensitive codepath pattern 'dojo/user/*.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/utils.py (drs_b0b3f45c)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/utils.py' matches configured sensitive codepath pattern 'dojo/utils.py' and was modified by 'svader0' (commit a6dd57d) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/authorization/query_registrations.py (drs_9d61f2da)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/authorization/query_registrations.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit 45816dc) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/announcement/os_message.py (drs_05d4ebd9)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/announcement/os_message.py' matches configured sensitive codepath pattern 'dojo/announcement/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/db_migrations/0268_release_authorization_to_pro.py (drs_618a0595)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/db_migrations/0268_release_authorization_to_pro.py' matches configured sensitive codepath pattern 'dojo/db_migrations/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/importers/auto_create_context.py (drs_278d6d58)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/importers/auto_create_context.py' matches configured sensitive codepath pattern 'dojo/importers/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/importers/base_importer.py (drs_37087999)
| Vulnerability | Configured Sensitive Codepath Modified by Non-Allowed Author |
|---|---|
| Description | File 'dojo/importers/base_importer.py' matches configured sensitive codepath pattern 'dojo/importers/*.py' and was modified by 'svader0' (commit 901e5ac) who is not in the allowed authors list. |
Comment to provide feedback on these findings.
Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]
Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing
All finding details can be found in the DryRun Security Dashboard.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the support docs for the Support page. DefectDojo Pro now reaches support through Settings > Support only, so the Contact Support entries leave the docs.
help/contact_support.md: "Within DefectDojo" points at Settings > Support and links the Support guide.navigation/PRO__sidebar.md: License & Support lists License Manager, Version Manager and Support.This branch sits on #15925, which adds the Support guide. Merge #15925 first.