Releases
Provisioning the dojodb-ddorch PostgreSQL database and pointing DefectDojo Pro at it on an existing self-hosted installation.
DefectDojo Changelog
Release specific upgrading instructions
security release + breaking changes
security release
security release
hashcode calculation logic has changed
hashcode calculation logic has changed
hashcode calculation logic has changed
multiple instructions
multiple instructions
multiple instructions
multiple instructions
multiple instructions
multiple instructions
multiple instructions
fix buildwatson create_endpoint_status
security release
breaking changes
breaking change
breaking change
instructions for helm chart and others
No special instructions.
No special instructions.
No special instructions.
instructions for helm chart
breaking change
No special instructions.
No special instructions.
No special instructions.
No special instructions.
breaking change
No special instructions.
No special instructions.
No special instructions.
No special instructions.
No special instructions.
No special instructions.
No special instructions.
Breaking Change for Auditlog.
breaking change
Breaking change for Removal of OpenAPI 2.0 Swagger
breaking change
Breaking Change for AWS_Scout2.
Integrity checker announced
Breaking Change for HELM deployments with PostgreSQL
Breaking Change for HELM deployments and MySQL / RabbitMQ users
Breaking Change for HELM deployments
Major upgrade of Postgres 16 to 17
security Release
Breaking Change for Postgres 12.
No special instructions.
No special instructions.
Disclaimer field renamed/split, removal of `dc-` scripts, audit log updates, and hash codes updates.
No special instructions.
No special instructions.
No special instructions.
Tag Formatting Changes + Import Payload Changes
Drop support for PostgreSQL-HA in HELM
Tag invalid character cleanup
Better pushing to JIRA for Finding Groups
No special instructions.
legacy authorization removed
Dropped support for time_zone in System settings.
Helm chart changes and Postgres major version updates.
Replaced Redis with Valkey & Helm chart changes & MobSF parser merge
Helm chart: changes for initializer annotations + Replaced Redis with Valkey + HPA & PDB support + Batch Deduplication
Trivy parser deduplication
Removal of django-auditlog & Dropped support for DD_PARSER_EXCLUDE & Reimport performance improvements & Removal of Finding Template Matching
JIRA Reconciliation now also processes Finding Groups.
Authorization related optimizations
JFrog Xray API Summary Artifact parser deduplication
Deprecation of Questionnaire API Endpoints
Deprecation of Credential Manager and Stub Findings
Notification .tpl templates relocated under dojo/notifications/
No special instructions.
breaking change
breaking changes
breaking change for APIv2
Xygeni parser keeps repeated SAST/Secrets occurrences in the same file as distinct findings.
Xygeni parser keys SAST/Secrets deduplication on uniqueHash; repeated secrets are aggregated into one finding.
Locations and Asset/Organization labels are now enabled by default; Authorized Users panel replaces Members/Groups under legacy authorization; SSO providers move to DefectDojo Pro; removal of Questionnaire API Endpoints, Credential Manager, and Stub Findings; Dependency Check parser no longer emits separate findings for related dependencies; related file paths are now listed in the main finding's description.
Blank Finding components are now normalized to NULL so component-less findings group together; JIRA project configurations now support multiple comma-separated components; Tool Configuration credentials are re-encrypted to AES-256-GCM; the JFrog Xray API Summary Artifact parser now sorts impact paths so findings deduplicate consistently across re-imports; a new optional DD_OS_MESSAGE_ENABLED setting controls the open-source promo banner; and a new deduplication execution mode controls how import/reimport deduplication is dispatched.
Notes marked private are now visible only to their author and to superusers.
DefectDojo Pro can now enable Locations as a self-service, database-backed toggle on the Feature Flags page, and carry existing history forward with an in-app data-migration suite that backfills endpoint, dependency, and source-code locations before an identity rehash.
Vulnerability ids gain an autodetected type and a uniqueness constraint; findings can now carry multiple CWEs via a new Finding_CWE relationship. Migrations add the type column, de-duplicate vulnerability-id rows, add the uniqueness constraint, create the CWE table, and backfill it. The vulnerability id and CWE changes leave existing hash codes untouched; four split deduplication registrations are repaired, which changes the identity of Burp Suite DAST Scan findings, and the AWS Security Hub parser now sorts resource IDs, which is an identity change for findings that report more than one resource. This release also deprecates the API-based (pull) parsers, the Tool Type / Tool Configuration feature, and the django-dbbackup integration, all scheduled for removal in 3.5.0.