<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DefectDojo Pro Changelog</title><link>https://docs.defectdojo.com/releases/pro/changelog/</link><description>DefectDojo Pro Changelog</description><language>en</language><copyright>Copyright (c) 2020-2025 DefectDojo, Inc.</copyright><atom:link href="https://docs.defectdojo.com/releases/pro/changelog/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Mon, 14 Sep 2026 00:00:00 +0000</lastBuildDate><item><title>September 14, 2026: v3.3.100</title><link>https://docs.defectdojo.com/releases/pro/changelog/#september-14-2026-v33100</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#september-14-2026-v33100</guid><pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; Added Dedupe Pools: group the Assets that should deduplicate against each other, choose where their originals collect, preview what a membership change would link, and re-run deduplication over the Findings already in scope with Apply Now.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The three deduplication tuning pages are now one Matching Configuration page: every tool listed once, with its same-tool, cross-tool and reimport matching side by side, and every change previewed before it is saved.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; New Palo Alto Cortex connector family, covering XDR, XSIAM, XSOAR, and Cloud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Connector sync and discovery frequency is now configurable (6, 12, or 24 hours), with schedule times shown in your browser&amp;rsquo;s local time.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Dashboards)&lt;/strong&gt; Collaborative shared dashboard layouts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Editor)&lt;/strong&gt; The markdown editor now stores images you paste or drop into any markdown field.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Google Vertex AI is available as an on-prem LLM provider.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Keyless and delegated cloud authentication for Prowler scans and Sensei CSPM, using cloud federation or Connect DefectDojo Cloud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Dashboards 2.0 widgets can now be reused as Report Builder blocks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine 2.0)&lt;/strong&gt; Date condition fields support relative-date operators.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Federal)&lt;/strong&gt; FedRAMP VDR, PAIN, and KEV-cap SLA fields are exposed in the Pro UI and REST API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Qualys)&lt;/strong&gt; Opt-in endpoint creation from host identity.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Dashboards)&lt;/strong&gt; Duplicate a dashboard tile from its edit-mode chrome.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The Aqua Supply Chain Branch field accepts a comma-separated list and gains a per-branch deduplication toggle, and its placeholders now show the real default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; Auth settings show callback and ACS URLs inline, with richer help text and corrected field labels.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; The Threat Modeling and Advisor pages show the licensed per-run quotas.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bug fixes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; JFrog scopes each nested child image to its own latest build; Dependency-Track paginates project findings so large projects aren&amp;rsquo;t truncated; YesWeHack maps every workflow state and falls back to the CVSS score for severity; GitHub Advanced Security 403 and 404 responses are treated as feature-disabled rather than token errors; a tool-reported finding status now survives a sync; and KEV/EPSS enrichment staging is isolated per connection to avoid concurrent-run collisions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; You can now request a review from yourself.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine)&lt;/strong&gt; &amp;ldquo;Clear Filters&amp;rdquo; now clears a rule&amp;rsquo;s saved filters.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; Unconfigured social-login backends return you to the login form instead of a 500.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Assets)&lt;/strong&gt; Each personnel picker gets its own users list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; A stored inactive contact stays readable, a new contact can no longer be assigned to an inactive user, and the finding API&amp;rsquo;s SonarQube issue relation is read-only.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Dashboards)&lt;/strong&gt; The Top Root Causes widget is registered and receives its configuration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; GitHub App creation opens in a new tab, and the Targets &amp;ldquo;Last Scan&amp;rdquo; value aligns with the scan-run ledger while the Scan-now dialog stays responsive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; Table columns size to fit their headers so filter and sort controls stay reachable, and the Upstream menu item is a plain link while Field Mappings is unreleased.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Questionnaires)&lt;/strong&gt; Corrected the share note on the general questionnaire list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(JIRA)&lt;/strong&gt; Corrected the exception class the webhook lookups catch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Removed a duplicate vulnerability reference prefetch in the finding report.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Parsers)&lt;/strong&gt; bundler-audit resets advisory fields so warnings can&amp;rsquo;t inherit stale values.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The endpoint rehash runs once per tool instead of once per finding.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Behavior changes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; False-positive history now follows deduplication scope. A Finding is compared against the Assets it deduplicates with, so an Engagement that deduplicates within itself only replicates false positives inside that Engagement. An Asset in a Dedupe Pool replicates its false positives across the pool for same-tool matching. Instances using false-positive history across such Engagements see narrower replication than before. A pool may span Organizations, and both effects follow the pool: a duplicate mark or a replicated false positive originating in one Organization can change a Finding in another Organization that shares the pool.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; For an Asset in a Dedupe Pool, Global Component, Global Vulnerability ID and Global Locations matching is bounded to the pool rather than the whole instance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The three deduplication pages move off the Tuner permissions onto four Dedupe Pool permissions (view, add, edit, delete). Roles that held the Tuner permissions are carried over for those pages: Tuner edit maps to all four, Tuner view to view only. The Tuner permissions themselves are unchanged and still gate the other 14 Tuner sections (SSO, LDAP, SCIM, email, MFA and the rest).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules)&lt;/strong&gt; A new asset rule action, Assign to Dedupe Pool, pools an Asset or removes the rows a rule created; it never moves an Asset another pool holds, and the rule owner needs the Dedupe Pool edit permission.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Assets)&lt;/strong&gt; The Asset page gains a Dedupe Pool panel showing which pool the Asset matches within, per kind, with the pool change, subtree pooling and untoggle available in place.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Audit Log)&lt;/strong&gt; Dedupe pools, their memberships and the per-tool matching rows are tracked in the audit log.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Upgrade notes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; Pods may roll in either order relative to the migration. The upgrade copies the deduplication tuning into per-tool matching rows and retires the old tuning fields from the application, but leaves their columns in the database for this release. A pod still on the previous image keeps reading and writing those columns and behaves exactly as before until it is rolled; a pod on the new image reaches a database that has not migrated yet and matches without pools, reading the old tuning where it needs to, until the migration lands. The columns are removed by a later release, once no pod on the previous image can exist. Hold imports across the roll if you want no import to straddle the changeover; nothing fails if you do not.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The migration is reversible. Rolling back to the previous node drops the new pool tables and restores the previous release&amp;rsquo;s view of the settings; the tuning columns never left. Take a database backup before upgrading anyway, as ordinary upgrade hygiene.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The matching rows the upgrade seeds carry no audit log entry: the migration writes them before it installs their audit triggers. Audit history for Matching Configuration starts with the first change made after the upgrade; the seeded state itself is what the Tuner held, and is not recorded as an event.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The first nightly identity check after the upgrade may send a system notification saying the cross-tool identity changed for some tools. Those tools had cross-tool hash fields configured but no algorithm; the previous release treated that as Hash code, and the upgrade records Hash code explicitly, so the identity definition moved while the stored hashes did not. The rehash the notification suggests (&lt;code&gt;manage.py identity_drift --kind cross_tool --rehash&lt;/code&gt;) is safe, recomputes the same values, and records the new baseline so the notice does not repeat.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deployment)&lt;/strong&gt; A new &lt;code&gt;DD_V3_ASSET_ALIASES&lt;/code&gt; chart value and compose environment variable enable per-source asset aliases; Sensei CSPM adds keyless and delegated cloud-auth boot gates.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>September 9, 2026: v3.3.0</title><link>https://docs.defectdojo.com/releases/pro/changelog/#september-9-2026-v330</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#september-9-2026-v330</guid><pubDate>Wed, 09 Sep 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Correlation)&lt;/strong&gt; Cross-domain finding correlation groups related findings into shared root causes. A finding&amp;rsquo;s page now lists its root causes, root-cause blast radius feeds finding prioritization, and a new Top Root Causes dashboard widget plus a Product breakdown show where risk concentrates. Root causes cover CVE, component, resource, and endpoint types, hide CVE causes a component already covers, and are readable through a public read-only Root Cause API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(PSIRT)&lt;/strong&gt; PSIRT 2.0 is folded natively into DefectDojo Pro: native advisory feeds and a catalog, feed rules and rule templates, advisory-to-case conversion, and a dedicated PSIRT permission so an analyst does not need global maintainer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Risk Acceptance)&lt;/strong&gt; Risk Acceptances 2.0 adds a reviewable lifecycle with a pending-review queue and a durable ledger. You can also choose to restore a finding to Verified when its risk acceptance expires.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Assets)&lt;/strong&gt; A rebuilt asset model adds asset versions with BOM snapshots and per-version SBOM/VEX export, per-source identity and aliases so connectors resolve assets by the vendor&amp;rsquo;s id, typed asset kinds, typed relationship edges that distinguish direct from indirect vulnerabilities, and asset exposure and deployment context (including live reachability probing and business-criticality sync from the CMDB).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Organizations)&lt;/strong&gt; Organizations can now be non-exclusive: an asset can belong to multiple organizations with union-of-grants RBAC, membership-aware organization filters on the asset and finding lists, and roles that can be granted across an entire organization type.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Dashboards)&lt;/strong&gt; Dashboards 2.0 expands into the DefectDojo Command Center, with a published security-posture score.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; Endpoints continue their move to Locations: asset connectors can emit standalone location inventory, and a new Location Map draws an asset&amp;rsquo;s locations as derived trees per location type.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Navigation)&lt;/strong&gt; Menu 2.0 now covers the whole sidebar, including a Sensei + AI section, a full-height sidebar rail with pinned pages, and server-backed shell preferences.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Added Sensei Advisor, which recommends settings changes and offers one-click fixes for mechanical deduplication-hygiene issues, with per-run license quotas for threat modeling and Advisor. The Sensei engine now ships in the on-prem compose bundles.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; New Rapid7 InsightVM - Cloud Instance and Aqua Supply Chain connectors, plus a Wiz option to import Issues only. Connectors gain customer-defined field mappings (versioned and identity-safe, per scan type), a connector registry the UI reads from, per-record sync checkpoints so an interrupted sync resumes, and health notifications when a connector stops working or authenticates but sees no data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Universal Parser)&lt;/strong&gt; Universal Parser field mappings can now be edited from a dedicated screen, with an impact warning attached.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Compliance)&lt;/strong&gt; Added DISA STIG checklist import (.ckl/.cklb) with a CCI to NIST 800-53 crosswalk.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Exporters)&lt;/strong&gt; Added a CycloneDX/SPDX SBOM and CycloneDX VEX export API, and the Pro UI now accepts .spdx files on import.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; Added API v3 (alpha) at &lt;code&gt;/api/v3-alpha/&lt;/code&gt; with slim references, expansion, RBAC sub-resources, and the Pro importer. Custom Fields are now available on the token-authenticated &lt;code&gt;/api/v2&lt;/code&gt; API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Federal)&lt;/strong&gt; Added FIPS 140-3 image support (FedRAMP SC-13), PAIN-keyed FedRAMP VDR remediation deadlines, and a FedRAMP prioritization preset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine 2.0)&lt;/strong&gt; Rules can now trigger on scan absence, draw from a rule-template gallery, assign an SLA configuration or Risk Priority to assets, and condition on exploit evidence, reachability, and asset exposure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Added a Location Count field on every entity and reorderable block fields in the Report Builder.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Assets)&lt;/strong&gt; Added checkbox bulk edit on the asset list (organization, SLA, engine, tags) and customer-editable platform, lifecycle, and origin dropdowns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Integrations)&lt;/strong&gt; The Freshservice integration can push findings as ITIL Incidents or Problems per mapping, and MCP finding tools gained tag filtering.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Audit Log)&lt;/strong&gt; System Settings changes are now recorded in the audit log.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The JFrog, Tenable.io WAS, and Tenable VM connectors now stream findings per page instead of holding a whole sync in memory, and connectors report data-visibility warnings at config-test time. The Location URL is pre-filled for single-host tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; A first pass of accessibility and readability foundations: a visible focus ring, AA-contrast muted text, a System theme option, comfortable reading line-height, and shared type tokens. Toggleable panels now expand from a click anywhere on the header, and locked dropdowns gained a copy button.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; Finding identity is now recorded in a signature ledger, versioned and bridged across formula changes, with a scheduled drift check that reports what moved; reimport can match on identity signatures.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Notifications)&lt;/strong&gt; Notifications now fan out to every organization an asset belongs to.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Report charts export as PNG so labels survive PDF rendering.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Importers)&lt;/strong&gt; Import and reimport bulk-create new findings, reducing per-finding overhead on large scans.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bug fixes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Wiz now imports findings from tenants that use no Projects, the Microsoft Defender connector no longer fails a good sync during spool cleanup, and connector product descriptions are capped at the column limit.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Licensing)&lt;/strong&gt; A usage block now answers with 402 rather than a throttle status, and license enforcement no longer blocks authentication.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Importers)&lt;/strong&gt; Scan severities are accepted case-insensitively, &lt;code&gt;.spdx&lt;/code&gt; files are accepted for import, concurrent imports no longer race on scan-directory creation, and edited tests keep their scan type so reimport matching survives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Parsers)&lt;/strong&gt; Fortify now marks only suppressed FPR findings as false positive, Anchore Grype parses the CISA KEV date, and Xeol and Checkmarx One finding identity is deterministic.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; The Components list no longer renders an empty body while its paginator counts every row, ECharts resolves theme tokens to concrete colors, and the New Issue Tracker Assignment dialog no longer closes when going full-screen.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Notable changes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; The classic Bootstrap UI and the classic report engine have been retired; Menu 2.0 and the Pro Vue UI are now standard.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Operations)&lt;/strong&gt; The maintenance window feature has been removed.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>August 31, 2026: v3.2.400</title><link>https://docs.defectdojo.com/releases/pro/changelog/#august-31-2026-v32400</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#august-31-2026-v32400</guid><pubDate>Mon, 31 Aug 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Added a generic fix flow: you can now associate a repository with a finding inline, and a gap-closing wizard walks you through anything else Sensei needs before it can generate a fix. Finding file paths are also resolved against the repository tree before the fix is generated, so fixes land in the right file.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Scan-and-fix now includes a scanner for AI agent skills (Skillspector).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Engagements)&lt;/strong&gt; Added engagement checklists to the Pro UI.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine 2.0)&lt;/strong&gt; Rules can now be conditioned on KEV (Known Exploited Vulnerabilities) listing and exploit evidence.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Navigation)&lt;/strong&gt; Added a searchable menu palette over the sidebar, opened with Cmd/Ctrl+K.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Correlation)&lt;/strong&gt; The Root Cause view now has a Root Cause Organization column, asset and organization filters, and per-organization drill-in.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Exporters)&lt;/strong&gt; The UI SBOM export now offers SPDX alongside CycloneDX.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Custom Fields)&lt;/strong&gt; Custom fields now render on the entity create and edit forms, and are configured like any other form field.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The Wiz, Microsoft Defender for Cloud, and CrowdStrike connectors now stream findings page by page rather than holding a whole sync in memory, so large syncs are faster and lighter.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>August 24, 2026: v3.2.300</title><link>https://docs.defectdojo.com/releases/pro/changelog/#august-24-2026-v32300</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#august-24-2026-v32300</guid><pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Custom Fields)&lt;/strong&gt; Added typed Custom Fields: define your own fields across seven datatypes and attach them to six entity types. Custom field values are tracked in the audit log, and Rules Engine 2.0 rules can read and write them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine 2.0)&lt;/strong&gt; Rules can now work with Assets end to end, and a new asset provenance widget on the asset page layout shows which rule produced an asset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Asset Hierarchy)&lt;/strong&gt; Rebuilt the Asset Hierarchy page on the Rules Engine 2.0 editor shell.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The GitHub Advanced Security connector can now import repository issues as a fourth finding family, under the new &lt;strong&gt;GitHub: Issues&lt;/strong&gt; scan type. Pre-existing mappings are backfilled with the new subtype automatically.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The OpenVAS / Greenbone connector now supports GMP over SSH as a transport.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; The deduplication identity ledger is now enabled by default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The Action1 connector now consolidates findings per organization, with machines recorded as endpoints, and each connector tile now counts only actively syncing records as mapped and surfaces unmapped records directly on the tile.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; The component and code backfills now run in batches, and stale-run reaping was moved off the poll, making the data-migration suite faster and lighter.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Operations)&lt;/strong&gt; DefectDojo now reports when a Celery task is routed to a queue that no worker consumes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; The scan-and-fix release image is smaller, with scanner installs split into per-ecosystem layers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(MCP)&lt;/strong&gt; The Pro MCP server now reports its version (with commit hash) via a CLI option.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Compliance)&lt;/strong&gt; The POA&amp;amp;M scheduled completion date is now derived from the finding&amp;rsquo;s SLA.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; The Risk Acceptance name is now offered as a finding report column.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Jira)&lt;/strong&gt; The custom fields JSON limit was raised from 200 to 1000.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>August 18, 2026: v3.2.201</title><link>https://docs.defectdojo.com/releases/pro/changelog/#august-18-2026-v32201</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#august-18-2026-v32201</guid><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Page Layouts)&lt;/strong&gt; The Risk Acceptance view page now uses a customizable widget grid, like the other View pages.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Added Amazon Bedrock as an on-prem LLM connection.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; The data-migration suite on the Feature Flags page can now be cancelled while a backfill is running. Cancelling stops the run at the next batch boundary and keeps everything migrated so far, so re-running the item resumes and converges on the same result. A run whose worker is lost is now detected and marked failed on its own, so a stuck suite becomes runnable again instead of blocking every item.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Endpoints)&lt;/strong&gt; Endpoints are now deprecated in favour of Locations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Menu)&lt;/strong&gt; Classic-menu users are now warned that Menu 2.0 becomes the standard in 3.3.0.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(CSPM)&lt;/strong&gt; Cloud Security Posture Management is now gated on the Sensei license rather than a separate feature flag.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Scan-and-fix scanner parallelism is now configurable, via &lt;code&gt;--max-parallel&lt;/code&gt; / &lt;code&gt;MAX_PARALLEL&lt;/code&gt; (and &lt;code&gt;sensei.maxParallel&lt;/code&gt; in Helm).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bug fixes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Authorization)&lt;/strong&gt; Import and reimport preview targets are now scoped to the caller&amp;rsquo;s permissions, POA&amp;amp;M item findings are validated against the record&amp;rsquo;s own product, and questionnaire expiration and question-set editing are checked against the response route and the questionnaire change permission.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Risk Acceptance)&lt;/strong&gt; A companion-less risk acceptance is now counted correctly, as active and as non-global, when filtering.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Report graph blocks that no browser captured are now drawn instead of failing silently, and the BETA badge that Menu 2.0 re-added after GA is gone.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Licensing)&lt;/strong&gt; License enforcement no longer blocks authentication.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The Action1 connector derives severity from the CVSS score when no severity bucket is usable, and a chunked sync now records one Import History row per sync.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; The endpoints-to-locations backfill now reports distinct locations and per-endpoint failures.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Dedupe)&lt;/strong&gt; Finding post-processing now retries on a transient DB deadlock.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; The Advisor now renders with PrimeVue, and PSIRT and Field Mappings are nested correctly in the legacy sidebar.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Threat Model)&lt;/strong&gt; The schema-repair loop no longer deletes the prompt it is repairing.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>August 17, 2026: v3.2.200</title><link>https://docs.defectdojo.com/releases/pro/changelog/#august-17-2026-v32200</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#august-17-2026-v32200</guid><pubDate>Mon, 17 Aug 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(CSPM)&lt;/strong&gt; Added Cloud Security Posture Management: connect AWS, Azure, and GCP cloud accounts, run posture scans against them, and apply reversible direct remediation to the misconfigurations that are found.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Asset Exposure)&lt;/strong&gt; Added asset exposure reporting from Wiz, Shodan, and Censys, and from CrowdStrike Spotlight (which reports only the exposure it can prove).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Registered the Aikido Security, Jit, and Cycode connectors.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Finding Templates)&lt;/strong&gt; You can now apply a finding template to a Finding, and turn a Finding into a template, directly from the Vue UI.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Form Configuration)&lt;/strong&gt; Added admin-controlled Form Configuration for the Vue create and edit forms, so an administrator can decide which fields appear.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; Added a DB-backed Locations toggle, with a data-migration suite to move existing data over.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Assets)&lt;/strong&gt; You can now export the asset and organization inventory as CSV.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Quick Export now names its output from the current context, and you can apply a report template to an export.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Added a filterable Review Claimant column to the findings list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine)&lt;/strong&gt; Rules Engine permissions now split into View / Add / Edit / Delete for finer RBAC.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Feature Flags)&lt;/strong&gt; Promoted nine feature flags off the menu, turned five more on by default, and moved Feature Flags out of System into its own settings location.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Layouts)&lt;/strong&gt; Layout customization can now be restricted to admin-designated defaults.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Qualys)&lt;/strong&gt; The Qualys connector now accepts a &lt;strong&gt;Host Tags&lt;/strong&gt; filter that scopes discovery to hosts carrying the Qualys asset tags you name. The filter is sent to Qualys, so out-of-scope hosts are never downloaded. It applies to the detection download as well as the host listing, so a narrowed scope also shortens each Sync. Tag names are matched exactly, because Qualys supports no wildcards on tag names. Leave the field blank to keep discovering every host.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(JFrog)&lt;/strong&gt; The JFrog connector now surfaces a pending status.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Jira)&lt;/strong&gt; The Jira connector now accepts service accounts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; The count of Findings a tool submitted is now recorded before deduplication runs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; The finding serializer now exposes a flat &lt;code&gt;test_type_name&lt;/code&gt; field.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(MCP)&lt;/strong&gt; Finding and asset Location retrieval is now consolidated into single REST calls.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bug fixes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Authorization)&lt;/strong&gt; Location data, DojoMeta visibility, and the &lt;code&gt;/api/v2/location/&lt;/code&gt; endpoint are now scoped to the requesting user&amp;rsquo;s products and RBAC rather than superusers only; every routed connector endpoint is named in the permission allow-list; the user edit form authorization was hardened; Tool Configuration credentials are kept out of the edit form; and the private-note visibility rule is now applied in the note UI views.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Export)&lt;/strong&gt; Spreadsheet formulas can no longer execute out of an exported file (CSV/formula injection).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; SAML2 routes now answer 404 when SAML is disabled.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; The Priority filter and override inputs now accept decimal values.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Assets)&lt;/strong&gt; A PATCH without a &lt;code&gt;parent&lt;/code&gt; field no longer orphans the asset, and auto-creating the same asset name concurrently no longer returns a 500.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Importers)&lt;/strong&gt; Bulk finding deletes, tag-count updates, and async cascade deletes now retry on transient DB conflicts and are ordered so concurrent imports and deletes cannot deadlock.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; The Action1 connector tolerates non-numeric sentinels in quoted numeric fields, and the Microsoft Defender connector retries a transient 5xx/429 on a single export page instead of failing the whole export.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Parsers)&lt;/strong&gt; Fixed a Trivy Scan crash from an uninitialized &lt;code&gt;resource_name&lt;/code&gt;, and reset Scout Suite parser state so a report parses to the same findings twice.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Notes)&lt;/strong&gt; A partial note PATCH now keeps the note body and no longer writes a null NoteHistory entry.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Reports no longer fetch unrenderable columns, report cells are now bounded, and a block&amp;rsquo;s Order By is applied through the filterset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tables &amp;amp; UI)&lt;/strong&gt; Clipped table cell text now wraps, the empty band below short pages is gone, the viewport row cap no longer oscillates and stalls a table, and the severity bar chart is positioned correctly in the open findings chart.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Page Grid)&lt;/strong&gt; A widget&amp;rsquo;s Title and Icon now follow its Records choice.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Jira)&lt;/strong&gt; Fixed the Jira migration.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>August 10, 2026: v3.2.100</title><link>https://docs.defectdojo.com/releases/pro/changelog/#august-10-2026-v32100</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#august-10-2026-v32100</guid><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;&lt;strong&gt;NOTE: The classic report engine (Report Builder, Report Templates and Generated Reports) will be removed in 3.3.0 on September 8, 2026.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(VEX)&lt;/strong&gt; Added CycloneDX SBOM / VEX / VDR export and import, as a round trip: a document exported from DefectDojo can be imported back into DefectDojo. The raw CycloneDX VEX analysis is now preserved on parsed Findings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SCIM)&lt;/strong&gt; Added SCIM 2.0 provisioning. Your identity provider can now create, update and deactivate DefectDojo users and manage groups directly, rather than DefectDojo only learning about a user when that user first signs in. Deactivating a user over SCIM also deletes that user&amp;rsquo;s API tokens. SCIM is configured under &lt;strong&gt;Connect &amp;gt; Authorization&lt;/strong&gt;, alongside your login providers, and is tagged &lt;strong&gt;Provisioning&lt;/strong&gt; to distinguish it from the providers that put a button on the login page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Downstream Connectors)&lt;/strong&gt; Added Messaging Connectors (beta), which send alerts to Slack, Microsoft Teams, email, or an Amazon SNS topic. Alerts are routed by Rules Engine 2.0: a rule decides when to send, which Findings qualify, and which connection and destination the message goes to. Requires the &lt;strong&gt;Messaging Connectors&lt;/strong&gt; and &lt;strong&gt;Rules Engine 2.0&lt;/strong&gt; feature flags.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reporting)&lt;/strong&gt; Reporting is now generally available, and no longer carries the BETA label.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reports)&lt;/strong&gt; Both the classic Report Builder and the new Report Builder now offer a one-click migration of your existing report templates. The migration works with the Reporting feature flag off, so you can move on your own schedule. Reports you have already generated are finished files and stay downloadable until removal.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Page Layouts)&lt;/strong&gt; The five View pages now use customizable widget grids, so you can arrange each page&amp;rsquo;s widgets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tables)&lt;/strong&gt; Table columns can now be resized, and the widths you set are saved to your table preferences. List tables also render a per-column loading skeleton while data is loading.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Registered the Tenable Web App Scanning and Rapid7 InsightVM connectors, along with six connectors that had shipped without a registration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; A provider can now hold several connections rather than one, and setup is scoped to the connection you are working in. Add Repositories now opens on the repository step. Semgrep scans run under a memory cap and recover across a hard kill (OOM).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Risk Acceptance)&lt;/strong&gt; Added Expire and Reinstate to the risk acceptance menu, and as API actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine 2.0)&lt;/strong&gt; A Rules Engine 2.0 rule can now be given its own schedule. Enabling the feature flag now warns that a worker restart is required before it takes effect.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; Added &lt;code&gt;migrate_locations_to_endpoints&lt;/code&gt;, the reverse of the endpoint-to-location conversion.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enhancements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; A connector request now requires a usable credential and a base URL, so a request cannot be submitted with details that will not connect.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Snyk)&lt;/strong&gt; Snyk reachability is now rendered as the raw values Snyk reports, rather than a derived yes/no.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Notes are now serialized a page at a time without re-filtering the page, and deduplication no longer lowercases the hash input on every Finding purely to log it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Dashboards)&lt;/strong&gt; The two Group By selects now focus their filter automatically when opened.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>August 4, 2026: v3.2.0</title><link>https://docs.defectdojo.com/releases/pro/changelog/#august-4-2026-v320</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#august-4-2026-v320</guid><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><description>&lt;p&gt;&lt;strong&gt;NOTE: We have deprecated API-based pull parsers, Tool Type/Tool Configuration, and dbbackup, with end-of-life scheduled for 3.5.0.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This release added many entries to the Feature Flags list: features that can be opted into.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Review Claiming)&lt;/strong&gt; Let a requested reviewer claim a Finding review so the other eligible reviewers can see it is being handled. Once claimed, only the claimer or the requester can clear the review.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Work Assignment)&lt;/strong&gt; Assign Findings and Risk Acceptances to individual people, alongside the existing group Owners, and give each person a My Work queue of what they are responsible for.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Priority)&lt;/strong&gt; Added a threat-intel risk floor, which is based on whether a Finding has EPSS, KEV or other exploitability. Only takes effect if Threat Intelligence Enrichment is enabled.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Rules Engine 2.0)&lt;/strong&gt; Build automation rules as visual node graphs that react to Finding events, with per-run traces and a delivery outbox.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Threat Intelligence Enrichment)&lt;/strong&gt; Threat Intelligence reached general availability, with signed threat-intel bundles, downgrade hysteresis, and new list and dashboard surfaces.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Menu 2.0)&lt;/strong&gt; Reorganized the Settings menu behind Menu 2.0, with a new All Settings hub.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Compliance)&lt;/strong&gt; The federal compliance pack: FedRAMP POA&amp;amp;M ledger and ConMon deliverables, CMMC Level 2 assessments, and control coverage.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; DefectDojo REST API can now produce reports as HTML, CSV, and Excel, not just JSON. Use the &lt;code&gt;/generate_report/&lt;/code&gt; endpoint path, e.g. &lt;code&gt;api/v2/findings/generate_report/&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Improved the performance of Celery/Async tasks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Deduplication)&lt;/strong&gt; Added set-based deduplication that matches Findings on their full set of vulnerability IDs and CWEs, including partial/subset matches, alongside a new global vulnerability-ID deduplication algorithm and &lt;code&gt;global_locations&lt;/code&gt; cross-product deduplication on shared locations. False-positive history now honors the same vulnerability-ID/CWE set-match tokens, false-positive-history candidate filtering is now pluggable, and deduplication now produces a stable &amp;ldquo;original&amp;rdquo; finding regardless of scan-import order.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Findings can now carry multiple CWEs across the API, the Vue UI, and the universal parser. Vulnerability IDs are normalized into a first-class Vulnerability entity with ordered references, per-vulnerability KEV/EPSS enrichment columns, and vulnerability aliases. Added a copy-finding action with an auto-detected vulnerability-ID type.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; Location drift matching keeps a finding tracked as its locations change across reimports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Enrichment)&lt;/strong&gt; Added a two-stage KEV/EPSS pipeline that projects the worst score per vulnerability onto Findings, plus bulk cloud-enrichment reads and import-time enrichment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added one-button migration from classic Jira to Downstream Connectors. Connector syncs now keep branch tags current on the Findings they report, and the public &lt;code&gt;/assign_product&lt;/code&gt; endpoint can map Findings-type records again.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; JFrog now scopes artifact-mode Findings to each artifact&amp;rsquo;s latest build.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Notes)&lt;/strong&gt; Notes now support Markdown.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Added SPDX, CSAF 2.0, and OpenVEX interchange-format parsers and a Promptfoo (LLM eval and red-teaming) parser.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 31, 2026: v3.1.303</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-31-2026-v31303</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-31-2026-v31303</guid><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connector)&lt;/strong&gt; For Checkmarx Connector, A branch value containing * now selects across every matching branch&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 29, 2026: v3.1.302</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-29-2026-v31302</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-29-2026-v31302</guid><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added another large batch of Connectors to the Pro UI. New Findings connectors: AppCheck, CyCognito, Picus, Red Hat Satellite, ImmuniWeb, Trustwave Fusion, Scantist, Black Duck Continuous Dynamic, Finite State, SOOS, Ostorlab, Automox, Qwiet AI, HiddenLayer, Nozomi Networks, NetRise, Uptycs, Klocwork, Parasoft DTP, CI Fuzz, Akto, BigID, Action1, ManageEngine Vulnerability Manager Plus, Zimperium, Dragos, CyberArk Certificate Manager, Calico Cloud, Rapid7 InsightCloudSec, Holm Security, Wazuh SCA, Fleet, and Elastic Security.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Checkmarx One branch tracking now accepts wildcard branch patterns, and JFrog Xray gained a &lt;code&gt;repository_filter&lt;/code&gt; that scopes discovery before any per-repository work is done. The all-records view can now be filtered by record state.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Fixed a Microsoft Defender export page whose body arrives truncated being dropped instead of refetched, Microsoft Defender for Cloud now tolerates Azure Resource Graph shape drift on &lt;code&gt;additionalData.cve&lt;/code&gt;, and a Checkmarx One wildcard that matches no branch in the scan window now skips the sync instead of closing every finding.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Connector syncs now fetch only the records they need rather than the full record set.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Security)&lt;/strong&gt; Hardened SAML assertion handling, and the login rate limiter now also applies to the API token authentication endpoint.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Import)&lt;/strong&gt; Failure-path cleanup no longer masks the real import error, and import/reimport failures keep their intended status codes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Search)&lt;/strong&gt; The search language facet is now seeded from the authorized queryset.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Bug Fixes)&lt;/strong&gt; The affected-engagements recompute no longer deadlocks concurrent risk acceptance updates, and stored JFrog api-summary deduplication settings are refreshed to match the current algorithm.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 28, 2026: v3.1.301</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-28-2026-v31301</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-28-2026-v31301</guid><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added nine parser-backed Findings connectors: Google Artifact Analysis, Zora, PingCastle, Promptfoo, Alert Logic, Cyberwatch, WebInspect Enterprise, TruffleHog, and Chef Automate. Each mirrors its existing DefectDojo parser&amp;rsquo;s mapping and scan type, so connector imports and file imports land in the same parser and the same deduplication configuration. Also wired up the credential forms for the Coverity, Cobalt.io, and Nuclei connectors, and gave five connectors their own logo.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Connector syncs can now stream Findings in chunks, so very large syncs no longer exhaust memory. Checkmarx One per-branch tracking now defaults on for new installations only, leaving existing installations on their current behavior.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(FIPS)&lt;/strong&gt; Added optional FIPS 140-3 image variants (CMVP #5247) for the connectors service, MCP server, integrators, and PSIRT advisory engine, deployable via &lt;code&gt;fips.enabled&lt;/code&gt; in the Helm chart.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Integrations)&lt;/strong&gt; Added Opsgenie and ServiceNow SecOps / Vulnerability Response outbound integrators.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; Added structured attribute-mapping editors for SAML, LDAP, and OIDC in the Tuner, along with OIDC group mapping.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Feature Flags and Appearance are now flagged as new in the menu, and dropdown menu triggers are hidden when they have no visible items.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Authorization)&lt;/strong&gt; Risk acceptances are now scoped by their accepted Findings, the Jira finding-mapping project field and the bulk-update target finding group are restricted to authorized objects, the member-management check is applied on every serializer exposing the field, metadata API object authorization was hardened, and finding and engagement UI actions now require POST.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Bug Fixes)&lt;/strong&gt; Locations are now carried across a finding merge; the risk acceptance expiration job no longer aborts on an unattached risk acceptance; chained duplicates are re-pointed before excess duplicates are deleted; the deduplication hash-recompute task no longer prefetches deprecated endpoints; and the API returns a validation error instead of a 500 when &lt;code&gt;environment&lt;/code&gt; is omitted.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Docs)&lt;/strong&gt; Documented the SSO attribute-mapping editors and OIDC group mapping, and enabling the Jira integration in System Settings. Clarified that the Jira webhook secret authenticates incoming requests.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 27, 2026: v3.1.300</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-27-2026-v31300</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-27-2026-v31300</guid><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(RBAC)&lt;/strong&gt; Added user-defined Custom Roles. You can now create your own roles with a granular permission set per object type, instead of being limited to the built-in roles.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added another large batch of Connectors. New Findings connectors: Fortify (SSC and FoD), HCL AppScan (ASoC and AppScan 360°), Datadog Cloud Security, MobSF, Deepfence ThreatMapper, NeuVector, Lacework / FortiCNAPP, Socket.dev, Bright Security, Aqua Security, Escape, Detectify, Fairwinds Insights, Wallarm, Vanta, NowSecure, FOSSA, Codacy, DeepSource, Beagle Security, Orca, AccuKnox, Halo Security, and Nightfall AI. Connector nomenclature is now unified as Upstream and Downstream Connectors, and you can request either type from the cloud UI.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; JFrog Xray gained an artifact-level record mode, with connector-declared parents materialized as asset hierarchy edges. The new mode is on by default for new installations only, so existing installations keep their current record layout. Checkmarx One added opt-in per-branch sync via a &lt;code&gt;track_branches&lt;/code&gt; toggle, which creates a separate engagement per tracked branch. Connector engagement names now include the asset name.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Connector syncs are more resilient on large data sets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Added Bitbucket, Azure DevOps, and GitHub Enterprise connections, along with a Revert action and GitLab remediation support.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Authentication)&lt;/strong&gt; Login, logout, MFA, SSO, and password reset now run natively in the Pro UI rather than falling back to the classic UI. Added a generic LDAP authentication integration, configurable from the Tuner.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; Added self-serve SSO diagnostics and logs so you can troubleshoot a misconfigured provider without opening a support ticket.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Feature Flags)&lt;/strong&gt; Organization / Asset relabeling is now a database-driven feature flag. Feature flags are also readable through the v2 API and MCP, and the legacy feature flag table was retired.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Integrations)&lt;/strong&gt; The ServiceNow integrator now supports transition-time custom fields and &lt;code&gt;client_credentials&lt;/code&gt; authentication, and surfaces integration errors in the UI.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Filters)&lt;/strong&gt; Date filters now resolve day boundaries in the viewing user&amp;rsquo;s timezone, and the SLA filter options were reworked.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; Tightened validation and authorization across the user, product type, test, location, and endpoint reference endpoints. Configuration permission assignment is now restricted to superusers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Reimport matching now builds a run-scoped candidate index, global search splits matching into per-lane index-served queries, and vulnerability IDs gained a case-insensitive index.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Added a Fortify parser V2 that prefers the true line number reported by the scanner. Fixed KICS severity mapping.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Bug Fixes)&lt;/strong&gt; Report summary charts now render after the table of contents is rebuilt; connector records are marked STALE when their owner is deleted through an async cascade; non-superusers can view the MCP page while MCP is enabled; a background sub-fetch failure no longer ejects you to the error page on secondary navigation; dropdown filters keep every character you type; an explicit scalar &lt;code&gt;cwe&lt;/code&gt; stays primary when a &lt;code&gt;cwes&lt;/code&gt; list is also supplied; API schema generation no longer scopes serializer querysets by &lt;code&gt;AnonymousUser&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 22, 2026: v3.1.202</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-22-2026-v31202</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-22-2026-v31202</guid><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Registered the Intigriti bug bounty connector and the runZero asset connector in the Pro UI. The Qualys connector now sizes its request timeout for large detection exports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Integrations)&lt;/strong&gt; Integrator assignments now support per-assignment push filters, so you can limit what gets pushed by minimum severity and active-only status.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Added a cloud dispatch guard, retroactive re-staging of auto-fixes, and a per-row actions menu. Fixed the &amp;ldquo;Configure Product&amp;rdquo; button clipping in the Findings list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Request Review is now gated on &lt;code&gt;Finding_View&lt;/code&gt; instead of &lt;code&gt;Finding_Edit&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Export options now prefill from the active table preference, the AI menu was flattened into top-level Sensei, Model Settings, and MCP links, and the PSIRT menu link now opens in a new tab.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Import)&lt;/strong&gt; Scan-import cleanup now streams files and fails loudly on error.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Dashboard count tiles no longer time out on large finding buckets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Bug Fixes)&lt;/strong&gt; Cleared default ordering in count subqueries&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 20, 2026: v3.1.200</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-20-2026-v31200</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-20-2026-v31200</guid><pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added another large batch of Connectors. New Findings connectors: Rapid7 InsightAppSec, Cobalt.io PtaaS, Sonatype IQ (Nexus Lifecycle), Acunetix 360, Mend (WhiteSource), Bugcrowd, Black Duck, Edgescan, Sysdig Secure, Coverity Connect, Harbor, OpenVAS / Greenbone, Nuclei / ProjectDiscovery Cloud, Endor Labs, Prowler, Kubescape / ARMO, Quay + Clair, Intruder.io, and YesWeHack. Added a ServiceNow CMDB asset connector. You can now request a new connector directly from the cloud UI, and CrowdStrike Spotlight now derives its severity floor from structured sync filters.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Integrations)&lt;/strong&gt; Added a Linear integrator for pushing Findings to Linear.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Feature Flags)&lt;/strong&gt; Redesigned feature flags into a two-tier, metadata-driven system with a dedicated Feature Flags admin page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Similar Findings now only surfaces genuinely similar Findings, the CVSS and EPSS columns now expose numeric filter operators, and several broken Findings-table column filters were fixed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; Metric colors in the Vue UI are now configurable per instance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; Added a configurable OIDC username claim and hardened SSO user creation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Authorized-finding queries now filter by a literal product-id list, and the paginated count-cache refill is now single-flighted to avoid redundant recounts on busy instances.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Import)&lt;/strong&gt; The generic parser no longer produces a nested list when a finding has both a CVE and vulnerability IDs, and the Import/ReImport forms no longer touch the database at import time.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Settings)&lt;/strong&gt; Added &lt;code&gt;DD_EDITABLE_MITIGATED_DATA&lt;/code&gt; to control whether mitigation data is editable, and ignored close-finding fields are now hidden.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Bug Fixes)&lt;/strong&gt; Connector backend config refresh now encodes datetimes correctly&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 15, 2026: v3.1.101</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-15-2026-v31101</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-15-2026-v31101</guid><pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Consolidated the bulk-edit actions in the Findings table into a single surface, and added bulk &amp;ldquo;replace tag&amp;rdquo; and bulk review actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Search)&lt;/strong&gt; Retired the legacy Watson search backend in Pro in favor of the native Postgres global search introduced in v3.1.100. Watson indexing can now be toggled with &lt;code&gt;DD_WATSON_SEARCH_ENABLED&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Full-table pagination counts on large API list endpoints can now be cached behind an opt-in flag, speeding up paginated list requests on big instances.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; Groups created through SSO now default to the Reader role.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Jira)&lt;/strong&gt; Fixed the &amp;ldquo;Connect with Jira&amp;rdquo; OAuth flow being blocked by hidden-field validation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reports)&lt;/strong&gt; Chart blocks in report PDFs no longer capture mid-animation, so exported charts render fully drawn.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 13, 2026: v3.1.100</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-13-2026-v31100</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-13-2026-v31100</guid><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added a large batch of new Connectors. New Findings connectors: CrowdStrike Falcon, Microsoft Defender Vulnerability Management, Microsoft Defender for Cloud, Veracode, Qualys, Rapid7 InsightVM, GitHub Advanced Security, HackerOne, Contrast, Google Cloud Security Command Center, Shodan, Wazuh, Cloudflare, Censys, Docker Scout, and Have I Been Pwned. New asset connectors: GitLab, Atlassian JSM Assets, Bitbucket Cloud, Azure DevOps, Backstage, and Group-IB ASM. Added a GitGuardian secrets connector.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Integrations)&lt;/strong&gt; Added new outbound integrators for Jira (Cloud and Data Center, with per-transition custom fields, ticket templates, and a test-render path), PagerDuty, Shortcut, and Bitbucket Cloud. Jira integrations now support setting fields on close/reopen transitions and Jira Cloud OAuth.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Search)&lt;/strong&gt; Added cross-model global search backed by native Postgres full-text search and trigram indexes, so you can search across Findings and related objects from one place.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Added a public API endpoint for merging Findings, and &amp;ldquo;Not X&amp;rdquo; negation options on the finding status filter.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Notes)&lt;/strong&gt; You can now @mention users in notes with autocomplete; mentioned users receive a notification.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Users)&lt;/strong&gt; Added bulk API-token and password resets from the users list.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Sensei)&lt;/strong&gt; Added candidate triage directly in the Findings table&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Reworked the big-table toolbar menu. Long unbroken names now wrap instead of being clipped, table scrollbars stay visible on hover, and in-page navigation refreshes data in place instead of triggering a full-page reload. Added a classic-UI deprecation banner with one-click opt-in to the Pro UI. The test page now shows the effective deduplication matching policy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Authorization)&lt;/strong&gt; Tightened authorization on product reassignment, V3 location routes, location-reference writes, and questionnaire relink routes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; &lt;code&gt;close_old_Findings&lt;/code&gt; now fetches only the columns it needs, and uWSGI workers and Celery prefork children are recycled by memory to keep long-running instances healthy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Import)&lt;/strong&gt; Fixed reimport so it dispatches post-processing with the correct per-finding &lt;code&gt;push_to_jira&lt;/code&gt; value, stopped dynamic Test Type names from doubling the &lt;code&gt;(scan_type)&lt;/code&gt; suffix, and made risk-acceptance Findings reinstate correctly when the expiration date is updated via the API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Checkmarx One parser now handles explicit null scanner sections in filtered reports, and the CSV universal parser no longer strips backticks from imported values.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Bug Fixes)&lt;/strong&gt; After deleting the object you were viewing, the Pro UI now lands on its parent context instead of erroring; a background sub-fetch 404 no longer ejects authorized users to the 404 page; the global loader no longer gets stuck open in bulk menus; and audit-log history context is now JSON-safe before Celery dispatch.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>July 7, 2026: v3.1.0</title><link>https://docs.defectdojo.com/releases/pro/changelog/#july-7-2026-v310</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#july-7-2026-v310</guid><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Insights)&lt;/strong&gt; Added export functionality and per-metric descriptions to Insights charts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Connectors)&lt;/strong&gt; Added Connectors filtering\&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Prioritization)&lt;/strong&gt; Added a per-user Products/Assets count column to the prioritization engine.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Import)&lt;/strong&gt; Import and reimport can now wait for deduplication to finish before returning. Reimport title hashing now applies the full titlecase transform for multi-line titles.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Jira)&lt;/strong&gt; Project settings now support multiple components. Issue status is now read from &lt;code&gt;statusCategory&lt;/code&gt; instead of the resolution field.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reports)&lt;/strong&gt; PDF reports now show vulnerability IDs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Security)&lt;/strong&gt; Tool Configuration credentials are now encrypted with AES-256-GCM.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Breadcrumbs are now deterministic and derived from the object hierarchy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Locations)&lt;/strong&gt; Legacy endpoint access in Make Template and Merge Findings is now guarded behind the Locations feature flag, and the finding Asset-tag (AND) filter uses the v3 Asset vocabulary.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(UI)&lt;/strong&gt; Finding Groups now fold under Findings in the sidebar; filter category accordions and collapse panels animate smoothly; right-aligned dropdown menus no longer overflow off the page edge; new-UI styling uses brand/design tokens instead of hardcoded colors; and a global required-fields notice was added for WCAG H90 compliance. The open source message banner can now be disabled and dismissed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Added an Alert Logic CSV parser and a Garak (NVIDIA LLM vulnerability scanner) parser. The GitHub Vulnerability parser now sets &lt;code&gt;fix_available&lt;/code&gt;; Dependency-Track FPF Findings now include &lt;code&gt;analysis.detail&lt;/code&gt; in the description; the Trivy parser no longer crashes on legacy reports missing the &lt;code&gt;Class&lt;/code&gt; field; govulncheck now rejects SARIF reports with a clear error pointing to the SARIF scan type; and JFrog Xray impact paths are now deterministic.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Faster imports and deduplication: batched &lt;code&gt;Vulnerability_Id&lt;/code&gt; and &lt;code&gt;BurpRawRequestResponse&lt;/code&gt; inserts, skip-unchanged-row and &lt;code&gt;VALUES&lt;/code&gt; fast-write dedup paths, batched prefetching of Pro relations, Watson search index prefetch with async indexing, a new &lt;code&gt;sla_expiration_date&lt;/code&gt; index for the global finding list, a case-insensitive product-name index, and a fix for finding-group Jira push N+1 queries.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>June 29, 2026: v3.0.200</title><link>https://docs.defectdojo.com/releases/pro/changelog/#june-29-2026-v30200</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#june-29-2026-v30200</guid><pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Reports)&lt;/strong&gt; Added a Graph block type to the Pro Report Builder, letting you embed Insights chart-catalog visualizations directly in reports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Dashboard V2 can now be exported as a branded, paginated PDF.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Number columns now support multi-value &amp;ldquo;In List&amp;rdquo; / &amp;ldquo;Not In List&amp;rdquo; filtering.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; KEV and EPSS data is now aggregated across all CVEs on a Finding.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Custom Enrichment)&lt;/strong&gt; Added a dedicated error page for EPSS/KEV connectivity failures, and default KEV/EPSS URLs now persist in tuner settings across upgrades.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Import)&lt;/strong&gt; Reimport no longer closes and recreates Findings whose titles exceed 511 characters.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; The SAML configuration form now clarifies which fields are conditionally required.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Permissions)&lt;/strong&gt; The Engagement Testing Lead selector now resolves product-scoped users, and authorized-users handling has been improved.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Performance)&lt;/strong&gt; Heavy dashboard metric aggregations can now be cached behind &lt;code&gt;DD_METRICS_CACHE_ENABLED&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Xygeni parser no longer deduplicates distinct SAST/Secrets Findings in the same file (now keyed on &lt;code&gt;uniqueHash&lt;/code&gt;). SARIF parser now unwraps BlackDuck nested fingerprint values.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tags)&lt;/strong&gt; User-set tags are now preserved when creating a Finding under product tag inheritance.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>June 22, 2026: v3.0.100</title><link>https://docs.defectdojo.com/releases/pro/changelog/#june-22-2026-v30100</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#june-22-2026-v30100</guid><pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Added native Excel (&lt;code&gt;.xlsx&lt;/code&gt;) export for Findings, Engagements, and Users.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Pro UI)&lt;/strong&gt; Bulk &amp;ldquo;Add to Existing Finding Group&amp;rdquo; no longer fails with an &amp;ldquo;Invalid pk &amp;lsquo;None&amp;rsquo;&amp;rdquo; error.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Classic UI)&lt;/strong&gt; Fixed the disclaimer border rendering in the new UI.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Findings)&lt;/strong&gt; Blank component values are now normalized to NULL for consistent matching and filtering.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Reports)&lt;/strong&gt; Added DefectDojo Pro Report Builder guides (UI, API, and LLM).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Added a PICUS Breach and Attack Simulation CSV parser.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; Added a Govulncheck Scanner V2 parser.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(Tools)&lt;/strong&gt; cargo-audit parser now parses CVSS vectors and derives severity from them.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>June 18, 2026: v3.0.2</title><link>https://docs.defectdojo.com/releases/pro/changelog/#june-18-2026-v302</link><guid>https://docs.defectdojo.com/releases/pro/changelog/#june-18-2026-v302</guid><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;(SSO)&lt;/strong&gt; SAML now keeps the Pro group-mapping backend as the active authentication backend.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; Restored &lt;code&gt;members&lt;/code&gt; and &lt;code&gt;authorization_groups&lt;/code&gt; fields on the Asset and Organization serializers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; Registered the &lt;code&gt;asset_*&lt;/code&gt; / &lt;code&gt;organization_*&lt;/code&gt; RBAC alias routes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;(API)&lt;/strong&gt; Restored RBAC fields on &lt;code&gt;/api/v2/user_profile/&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>