Releases

Adding the Dd-Orch Database on Upgrade →

Provisioning the dojodb-ddorch PostgreSQL database and pointing DefectDojo Pro at it on an existing self-hosted installation.

DefectDojo Pro Changelog →

DefectDojo Changelog

Open Source Upgrading →

Release specific upgrading instructions

Upgrading to DefectDojo Version 1.10.x →

security release + breaking changes

Upgrading to DefectDojo Version 1.13.x →

hashcode calculation logic has changed

Upgrading to DefectDojo Version 1.14.x →

hashcode calculation logic has changed

Upgrading to DefectDojo Version 1.15.x →

hashcode calculation logic has changed

Upgrading to DefectDojo Version 1.8.0 →

fix buildwatson create_endpoint_status

Upgrading to DefectDojo Version 2.13.x →

instructions for helm chart and others

Upgrading to DefectDojo Version 2.30.x →

Breaking Change for Auditlog.

Upgrading to DefectDojo Version 2.32.x →

Breaking change for Removal of OpenAPI 2.0 Swagger

Upgrading to DefectDojo Version 2.34.x →

Breaking Change for AWS_Scout2.

Upgrading to DefectDojo Version 2.36.x →

Breaking Change for HELM deployments with PostgreSQL

Upgrading to DefectDojo Version 2.37.x →

Breaking Change for HELM deployments and MySQL / RabbitMQ users

Upgrading to DefectDojo Version 2.38.x →

Breaking Change for HELM deployments

Upgrading to DefectDojo Version 2.39.x →

Major upgrade of Postgres 16 to 17

Upgrading to DefectDojo Version 2.40.x →

Breaking Change for Postgres 12.

Upgrading to DefectDojo Version 2.43.x →

Disclaimer field renamed/split, removal of `dc-` scripts, audit log updates, and hash codes updates.

Upgrading to DefectDojo Version 2.46.x →

Tag Formatting Changes + Import Payload Changes

Upgrading to DefectDojo Version 2.47.x →

Drop support for PostgreSQL-HA in HELM

Upgrading to DefectDojo Version 2.48.2 →

Tag invalid character cleanup

Upgrading to DefectDojo Version 2.48.x →

Better pushing to JIRA for Finding Groups

Upgrading to DefectDojo Version 2.5.x →

legacy authorization removed

Upgrading to DefectDojo Version 2.50.x →

Dropped support for time_zone in System settings.

Upgrading to DefectDojo Version 2.51.x →

Helm chart changes and Postgres major version updates.

Upgrading to DefectDojo Version 2.52.x →

Replaced Redis with Valkey & Helm chart changes & MobSF parser merge

Upgrading to DefectDojo Version 2.53.x →

Helm chart: changes for initializer annotations + Replaced Redis with Valkey + HPA & PDB support + Batch Deduplication

Upgrading to DefectDojo Version 2.54.x →

Removal of django-auditlog & Dropped support for DD_PARSER_EXCLUDE & Reimport performance improvements & Removal of Finding Template Matching

Upgrading to DefectDojo Version 2.55.2 →

JIRA Reconciliation now also processes Finding Groups.

Upgrading to DefectDojo Version 2.55.x →

Authorization related optimizations

Upgrading to DefectDojo Version 2.56.4 →

JFrog Xray API Summary Artifact parser deduplication

Upgrading to DefectDojo Version 2.56.x →

Deprecation of Questionnaire API Endpoints

Upgrading to DefectDojo Version 2.57.x →

Deprecation of Credential Manager and Stub Findings

Upgrading to DefectDojo Version 2.58.x →

Notification .tpl templates relocated under dojo/notifications/

Upgrading to DefectDojo Version 3.0.100 →

Xygeni parser keeps repeated SAST/Secrets occurrences in the same file as distinct findings.

Upgrading to DefectDojo Version 3.0.200 →

Xygeni parser keys SAST/Secrets deduplication on uniqueHash; repeated secrets are aggregated into one finding.

Upgrading to DefectDojo Version 3.0.x →

Locations and Asset/Organization labels are now enabled by default; Authorized Users panel replaces Members/Groups under legacy authorization; SSO providers move to DefectDojo Pro; removal of Questionnaire API Endpoints, Credential Manager, and Stub Findings; Dependency Check parser no longer emits separate findings for related dependencies; related file paths are now listed in the main finding's description.

Upgrading to DefectDojo Version 3.1.x →

Blank Finding components are now normalized to NULL so component-less findings group together; JIRA project configurations now support multiple comma-separated components; Tool Configuration credentials are re-encrypted to AES-256-GCM; the JFrog Xray API Summary Artifact parser now sorts impact paths so findings deduplicate consistently across re-imports; a new optional DD_OS_MESSAGE_ENABLED setting controls the open-source promo banner; and a new deduplication execution mode controls how import/reimport deduplication is dispatched.

Upgrading to DefectDojo Version 3.2.100 →

Notes marked private are now visible only to their author and to superusers.

Upgrading to DefectDojo Version 3.2.200 →

DefectDojo Pro can now enable Locations as a self-service, database-backed toggle on the Feature Flags page, and carry existing history forward with an in-app data-migration suite that backfills endpoint, dependency, and source-code locations before an identity rehash.

Upgrading to DefectDojo Version 3.2.x →

Vulnerability ids gain an autodetected type and a uniqueness constraint; findings can now carry multiple CWEs via a new Finding_CWE relationship. Migrations add the type column, de-duplicate vulnerability-id rows, add the uniqueness constraint, create the CWE table, and backfill it. The vulnerability id and CWE changes leave existing hash codes untouched; four split deduplication registrations are repaired, which changes the identity of Burp Suite DAST Scan findings, and the AWS Security Hub parser now sorts resource IDs, which is an identity change for findings that report more than one resource. This release also deprecates the API-based (pull) parsers, the Tool Type / Tool Configuration feature, and the django-dbbackup integration, all scheduled for removal in 3.5.0.