You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/content/en/open_source/upgrading/2.54.md
+6-1Lines changed: 6 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: 'Upgrading to DefectDojo Version 2.54.x'
3
3
toc_hide: true
4
4
weight: -20251201
5
-
description: Removal of django-auditlog and exclusive use of django-pghistory for audit logging.
5
+
description: Removal of django-auditlog and exclusive use of django-pghistory for audit logging & Dropped support for DD_PARSER_EXCLUDE
6
6
---
7
7
8
8
## Breaking Change: Removal of django-auditlog
@@ -39,4 +39,9 @@ The switch to `django-pghistory` provides several advantages:
39
39
40
40
The backfill migration is not mandatory to succeed. If it fails for some reason, the only side effect will be that the first auditlog diff will contain all fields of an object instead just the changed fields.
41
41
42
+
## Dropped support for DD_PARSER_EXCLUDE
43
+
44
+
To simplify the management of the DefectDojo application, parser exclusions are no longer controlled via the environment variable DD_PARSER_EXCLUDE or application settings. This variable is now unsupported.
45
+
From now on, you should use the active flag in the Test_Type model to enable or disable parsers. Only parsers associated with active Test_Type entries will be available for use.
46
+
42
47
Check the [Release Notes](https://github.com/DefectDojo/django-DefectDojo/releases/tag/2.54.0) for the contents of the release.
Copy file name to clipboardExpand all lines: docs/content/en/working_with_findings/findings_workflows/risk_acceptances.md
+13Lines changed: 13 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,6 +25,19 @@ Any Findings associated with a Full Risk Acceptance will be set to **Inactive**,
25
25
26
26
Generally, any Risk Acceptances should follow your internal security policy and be re\-examined at an appropriate time. As a result, Risk Acceptances also have expiration dates. Once a Risk Acceptance expires, any Findings will be set to Active again.
27
27
28
+
### DefectDojo Pro vs Open Source: Cross-Product Risk Acceptances
29
+
30
+
**DefectDojo Pro** provides enhanced Risk Acceptance capabilities that aid in managing risk decisions at scale:
31
+
32
+
***Cross-Product Risk Acceptances**: In DefectDojo Pro, you can apply a single Risk Acceptance across multiple Products. For example, if CVE-2024-1234 appears in 10 different products, you can create one Risk Acceptance that governs all instances of that CVE across your entire portfolio.
33
+
***Bulk CVE Management**: Search for all Findings with a specific CVE or vulnerability ID, then apply a Risk Acceptance to all instances simultaneously, regardless of which Product they belong to.
34
+
35
+
**DefectDojo Open Source** implements Risk Acceptances at the Engagement level:
36
+
37
+
***Product-Scoped Risk Acceptances**: Risk Acceptances are restricted to individual Products. If CVE-2024-1234 appears in 10 different products, you need to create 10 separate Risk Acceptances—one for each Engagement.
38
+
39
+
Both approaches follow the same Risk Acceptance workflow described below, but the scope differs based on your DefectDojo edition.
40
+
28
41
### Add a new Full Risk Acceptance
29
42
30
43
Risk Acceptances can be added to a Finding in two ways:
0 commit comments