Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
fbfeaca
feat(dedupe): let a caller supply the candidate scope and the winner …
blakeaowens Aug 25, 2026
98fc2f9
test(dedupe): the target must outlive the only candidate for the age …
blakeaowens Aug 25, 2026
f8b3138
docs: dedupe pools
blakeaowens Aug 26, 2026
061836e
docs: reimports do deduplicate across a dedupe pool
blakeaowens Aug 28, 2026
a2160f2
docs: the deduplication tuning page now describes Matching Configuration
blakeaowens Aug 31, 2026
fc614be
docs: hash fields are editable again, per axis
blakeaowens Aug 31, 2026
c01f4b1
docs: fix the stale drift page, the global-algorithm blast radius, an…
blakeaowens Sep 4, 2026
752daea
docs(dedupe): the Apply Now ceiling, and drop em dashes from the Pro …
blakeaowens Sep 4, 2026
6d21889
refactor(dedupe): make candidate_qs keyword-only, and pin its forward…
blakeaowens Sep 4, 2026
b519c0b
docs(dedupe): scope of false-positive history, pool overrides and rei…
blakeaowens Sep 6, 2026
743ce14
docs(dedupe): 3.3.0 changelog entries, the Apply Now ceiling, disabli…
blakeaowens Sep 6, 2026
f08a3a0
docs(dedupe): navigation paths, permissions, scope statements and pro…
blakeaowens Sep 7, 2026
a588d98
feat(dedupe): let a plugin supply the false-positive history scope
blakeaowens Sep 7, 2026
8fdf6e6
docs(dedupe): hub procedures for the global pages, two deduplication …
blakeaowens Sep 7, 2026
f2c3fb5
docs(dedupe): the global pages name the hub, and the last em dashes go
blakeaowens Sep 7, 2026
6e28604
docs(dedupe): the Global Locations intro names the hub; last em dashe…
blakeaowens Sep 8, 2026
ab414f5
docs(dedupe): the last three em dashes on pages this PR touches
blakeaowens Sep 8, 2026
7a4df06
Merge remote-tracking branch 'origin/bugfix' into work/15819-mergeup2
Sep 8, 2026
22d1e4e
fix(dedupe): ask the history scope provider once per engagement; eigh…
blakeaowens Sep 8, 2026
237d629
docs(changelog): the dedupe pools entries ship in 3.3.100, the patch …
blakeaowens Sep 8, 2026
20ac801
Merge origin/bugfix into feature/dedupe-injectable-candidate-scope
blakeaowens Sep 9, 2026
cc7a14e
docs(dedupe): correct the tuner permission scope and add the upgrade …
blakeaowens Sep 12, 2026
3a6665f
docs(dedupe): give the upgrade page the deploy ordering, not just the…
blakeaowens Sep 12, 2026
7b344fa
Merge remote-tracking branch 'origin/bugfix' into feature/dedupe-inje…
blakeaowens Sep 13, 2026
f4dfc88
docs(dedupe): say what old and new pods actually do across the upgrad…
blakeaowens Sep 14, 2026
327a01f
docs(dedupe): the seeded matching rows have no audit trail, and say so
blakeaowens Sep 14, 2026
d77fe2b
docs(dedupe): the upgrade no longer has a required order, and the mig…
blakeaowens Sep 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions docs/content/navigation/PRO__sidebar.md
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ Settings is divided into eight groups, named for what you are trying to do rathe
| **System** | System Settings, Appearance, Announcement Banner, Login Banner, Email |
| **UI Defaults** | Form Configuration, Layout Defaults |
| **Users & Permissions** | Users, Groups, Roles |
| **Finding Workflow** | The three Deduplication pages, Finding Enrichment, Service Level Agreements, Prioritization Engines, Mitigation Policies |
| **Finding Workflow** | Dedupe Pools, Matching Configuration, Finding Enrichment, Service Level Agreements, Prioritization Engines, Mitigation Policies |
| **Configuration** | Environments, Regulations, Note Types, Test Types, CI/CD Infrastructure, Tool Types, Tool Configurations |
| **Notifications** | Notification Events, Notification Webhooks |
| **Operations** | Audit Logs, Usage Logs, Schedules, Celery Status, and on DefectDojo Cloud, Message Portal, Firewall Rules, Maintenance Windows |
Expand All @@ -138,7 +138,7 @@ Settings is divided into eight groups, named for what you are trying to do rathe

### All Settings

The first entry in the section, **All Settings**, opens a directory of every settings page your account can reach, arranged in the same groups as the menu and searchable by name or by what the page does. Searching `deduplication` finds the three deduplication pages *and* System Settings, because System Settings holds deduplication options too.
The first entry in the section, **All Settings**, opens a directory of every settings page your account can reach, arranged in the same groups as the menu and searchable by name or by what the page does. Searching `deduplication` finds the two deduplication pages (Dedupe Pools and Matching Configuration) *and* System Settings, because System Settings holds deduplication options too.

The last category, **Elsewhere in the app**, lists pages that configure DefectDojo but live in other sidebar sections: the authorization providers, Login and MFA settings, Jira instances, the Upstream and Downstream connectors, and the Universal Parser. Each tile is chipped with the section it belongs to.

Expand Down Expand Up @@ -171,7 +171,7 @@ If you are used to the previous layout:
| Manage → Rules Engine and Rules Engine 2.0 | Act → Triage Engine |
| Manage → *(any)* → New *(record)* | The **New** button on the matching list page |
| Dashboards → Home | Overview → Dashboards *(when Dashboards 2.0 is on)* |
| Settings → *(top level)* → Feature Flags | Unchanged — still at the top level, below All Settings |
| Settings → *(top level)* → Feature Flags | Unchanged: still at the top level, below All Settings |
| Settings → Pro Settings → System Settings | Settings → System → System Settings |
| Settings → Pro Settings → Appearance | Settings → System → Appearance |
| Settings → Pro Settings → Banner Settings → Announcement Banner Settings | Settings → System → Announcement Banner |
Expand All @@ -180,7 +180,7 @@ If you are used to the previous layout:
| Settings → Users → All Users / New User | Settings → Users & Permissions → Users |
| Settings → Users → All Groups / New Group | Settings → Users & Permissions → Groups |
| Settings → Users → Roles | Settings → Users & Permissions → Roles |
| Settings → Pro Settings → Deduplication Settings → *(three pages)* | Settings → Finding Workflow → Same Tool / Cross Tool / Reimport Deduplication |
| Settings → Pro Settings → Deduplication Settings → *(three pages)* | Settings → Finding Workflow → Matching Configuration (one page covering same-tool, cross-tool and reimport matching), beside Dedupe Pools |
| Settings → Pro Settings → Finding Enrichment Settings | Settings → Finding Workflow → Finding Enrichment |
| Settings → Configuration → Service Level Agreements | Settings → Finding Workflow → Service Level Agreements |
| Settings → Configuration → Prioritization Engines | Settings → Finding Workflow → Prioritization Engines |
Expand Down
24 changes: 22 additions & 2 deletions docs/content/releases/pro/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,26 @@ For Open Source release notes, please see the [Releases page on GitHub](https://

## September 2026: v3.3

### September 14, 2026: v3.3.100

New features:
* **(Deduplication)** Added Dedupe Pools: group the Assets that should deduplicate against each other, choose where their originals collect, preview what a membership change would link, and re-run deduplication over the Findings already in scope with Apply Now.
* **(Deduplication)** The three deduplication tuning pages are now one Matching Configuration page: every tool listed once, with its same-tool, cross-tool and reimport matching side by side, and every change previewed before it is saved.

Behavior changes:
* **(Deduplication)** False-positive history now follows deduplication scope. A Finding is compared against the Assets it deduplicates with, so an Engagement that deduplicates within itself only replicates false positives inside that Engagement. An Asset in a Dedupe Pool replicates its false positives across the pool for same-tool matching. Instances using false-positive history across such Engagements see narrower replication than before. A pool may span Organizations, and both effects follow the pool: a duplicate mark or a replicated false positive originating in one Organization can change a Finding in another Organization that shares the pool.
* **(Deduplication)** For an Asset in a Dedupe Pool, Global Component, Global Vulnerability ID and Global Locations matching is bounded to the pool rather than the whole instance.
* **(Deduplication)** The three deduplication pages move off the Tuner permissions onto four Dedupe Pool permissions (view, add, edit, delete). Roles that held the Tuner permissions are carried over for those pages: Tuner edit maps to all four, Tuner view to view only. The Tuner permissions themselves are unchanged and still gate the other 14 Tuner sections (SSO, LDAP, SCIM, email, MFA and the rest).
* **(Rules)** A new asset rule action, Assign to Dedupe Pool, pools an Asset or removes the rows a rule created; it never moves an Asset another pool holds, and the rule owner needs the Dedupe Pool edit permission.
* **(Assets)** The Asset page gains a Dedupe Pool panel showing which pool the Asset matches within, per kind, with the pool change, subtree pooling and untoggle available in place.
* **(Audit Log)** Dedupe pools, their memberships and the per-tool matching rows are tracked in the audit log.

Upgrade notes:
* **(Deduplication)** Pods may roll in either order relative to the migration. The upgrade copies the deduplication tuning into per-tool matching rows and retires the old tuning fields from the application, but leaves their columns in the database for this release. A pod still on the previous image keeps reading and writing those columns and behaves exactly as before until it is rolled; a pod on the new image reaches a database that has not migrated yet and matches without pools, reading the old tuning where it needs to, until the migration lands. The columns are removed by a later release, once no pod on the previous image can exist. Hold imports across the roll if you want no import to straddle the changeover; nothing fails if you do not.
* **(Deduplication)** The migration is reversible. Rolling back to the previous node drops the new pool tables and restores the previous release's view of the settings; the tuning columns never left. Take a database backup before upgrading anyway, as ordinary upgrade hygiene.
* **(Deduplication)** The matching rows the upgrade seeds carry no audit log entry: the migration writes them before it installs their audit triggers. Audit history for Matching Configuration starts with the first change made after the upgrade; the seeded state itself is what the Tuner held, and is not recorded as an event.
* **(Deduplication)** The first nightly identity check after the upgrade may send a system notification saying the cross-tool identity changed for some tools. Those tools had cross-tool hash fields configured but no algorithm; the previous release treated that as Hash code, and the upgrade records Hash code explicitly, so the identity definition moved while the stored hashes did not. The rehash the notification suggests (`manage.py identity_drift --kind cross_tool --rehash`) is safe, recomputes the same values, and records the new baseline so the notice does not repeat.

### September 9, 2026: v3.3.0

New features:
Expand Down Expand Up @@ -366,7 +386,7 @@ Additional features:
### June 15, 2026: v3.0.0

* **(Locations)** Locations are now enabled by default, superseding the legacy Endpoint model. The legacy Endpoint API stays read-compatible and your data is preserved. See [Locations enabled by default](/releases/os_upgrading/3.0/#locations-enabled-by-default).
* **(Assets & Organizations)** "Product Type" → "Organization" and "Product" → "Asset" relabeling (UI labels + URL routing) is now on by default. The change is cosmetic — API endpoints and field names are unchanged. See [Asset / Organization labels enabled by default](/releases/os_upgrading/3.0/#asset--organization-labels-enabled-by-default).
* **(Assets & Organizations)** "Product Type" → "Organization" and "Product" → "Asset" relabeling (UI labels + URL routing) is now on by default. The change is cosmetic: API endpoints and field names are unchanged. See [Asset / Organization labels enabled by default](/releases/os_upgrading/3.0/#asset--organization-labels-enabled-by-default).
* **(Authorization)** Open Source restores the **Authorized Users** panel on Product/Product Type detail under the legacy authorization model; Pro deployments retain full RBAC and are not impacted. See [Authorized Users panel replaces Members/Groups under legacy authorization](/releases/os_upgrading/3.0/#authorized-users-panel-replaces-membersgroups-under-legacy-authorization).
* **(SSO)** SSO providers (SAML, OIDC, Google, Okta, Azure AD, GitLab, Auth0, Keycloak, GitHub Enterprise, remote-user header auth) are now DefectDojo Pro-only. See [SSO providers are available in DefectDojo Pro only](/releases/os_upgrading/3.0/#sso-providers-are-available-in-defectdojo-pro-only).
* **(API)** Removed the Questionnaire API endpoints. See [Removal: Questionnaire API Endpoints](/releases/os_upgrading/3.0/#removal-questionnaire-api-endpoints).
Expand Down Expand Up @@ -400,7 +420,7 @@ Additional features:
* **(Pro UI)** You can now activate or deactivate Test Types and Users directly from their list menus, so retiring or restoring entries no longer requires opening the edit form.
* **(Pro UI)** Anchor links now open in a new tab as expected, so following a reference no longer pulls you away from the page you were working on.
* **(Pro UI)** Adding Findings to an existing Risk Acceptance works reliably again. A recent performance improvement caused the form to fail for some users; you can now resume managing accepted Findings without errors.
* **(Pro UI)** Your customized table column order is now preserved across page refreshes. Previously only column visibility carried over, so any rearranging you did would silently revert to the default — forcing you to reorder columns every session.
* **(Pro UI)** Your customized table column order is now preserved across page refreshes. Previously only column visibility carried over, so any rearranging you did would silently revert to the default, forcing you to reorder columns every session.
* **(API)** Fixed a 500 error when fetching vulnerable endpoints (`GET /api/vue/endpoints/{id}/vulnerable/`), restoring reliable access to vulnerability data for an endpoint.

### May 4, 2026: v2.58.0
Expand Down
Loading
Loading