Skip to content

Release: Merge release into master from: release/2.52.0#13602

Merged
rossops merged 138 commits intomasterfrom
release/2.52.0
Nov 3, 2025
Merged

Release: Merge release into master from: release/2.52.0#13602
rossops merged 138 commits intomasterfrom
release/2.52.0

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Nov 3, 2025

Release triggered by rossops

DefectDojo release bot and others added 30 commits October 6, 2025 18:09
….0-dev

Release: Merge back 2.51.0 into dev from: master-into-dev/2.51.0-2.52.0-dev
Bumps [django-pghistory](https://github.com/AmbitionEng/django-pghistory) from 3.7.0 to 3.8.3.
- [Release notes](https://github.com/AmbitionEng/django-pghistory/releases)
- [Changelog](https://github.com/AmbitionEng/django-pghistory/blob/main/CHANGELOG.md)
- [Commits](AmbitionEng/django-pghistory@3.7.0...3.8.3)

---
updated-dependencies:
- dependency-name: django-pghistory
  dependency-version: 3.8.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…pose.yml) (#13325)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps vulners from 2.3.7 to 3.1.1.

---
updated-dependencies:
- dependency-name: vulners
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [social-auth-app-django](https://github.com/python-social-auth/social-app-django) from 5.4.3 to 5.5.1.
- [Release notes](https://github.com/python-social-auth/social-app-django/releases)
- [Changelog](https://github.com/python-social-auth/social-app-django/blob/master/CHANGELOG.md)
- [Commits](python-social-auth/social-app-django@5.4.3...5.5.1)

---
updated-dependencies:
- dependency-name: social-auth-app-django
  dependency-version: 5.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [jira](https://github.com/pycontribs/jira) from 3.8.0 to 3.10.5.
- [Release notes](https://github.com/pycontribs/jira/releases)
- [Changelog](https://github.com/pycontribs/jira/blob/main/RELEASE.md)
- [Commits](pycontribs/jira@3.8.0...3.10.5)

---
updated-dependencies:
- dependency-name: jira
  dependency-version: 3.10.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…workflows/close-stale.yml) (#13349)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
… v2.4.0 (.github/workflows/release-x-manual-helm-chart.yml) (#13358)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.40.44 to 1.40.46.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.40.44...1.40.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.40.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fix: add missing resources, securityContext and env entries

* chore: docs and schema

* fix: missing securityContext for initializer job

* fix: add resources to all cloudsql containers

* chore: add missing explicit namespace

* chore: refactor, split container and pod security context

* chore: docs and schema

* fix: lint

* chore: sort helper

* fix: lint and add changes to release notes

* chore: trigger CI

* chore: move to 2.52, fix pending issues

* chore: docs
Bumps [social-auth-core](https://github.com/python-social-auth/social-core) from 4.7.0 to 4.8.0.
- [Release notes](https://github.com/python-social-auth/social-core/releases)
- [Changelog](https://github.com/python-social-auth/social-core/blob/master/CHANGELOG.md)
- [Commits](python-social-auth/social-core@4.7.0...4.8.0)

---
updated-dependencies:
- dependency-name: social-auth-core
  dependency-version: 4.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* ⬆️ Bump ruff from 0.13.2 to 0.13.3

* bump

* fix

* Update settings.dist.py

* Update requirements-lint.txt
…3396)

Bumps [datatables.net-colreorder](https://github.com/DataTables/Dist-DataTables-ColReorder) from 2.1.1 to 2.1.2.
- [Release notes](https://github.com/DataTables/Dist-DataTables-ColReorder/releases)
- [Commits](DataTables/Dist-DataTables-ColReorder@2.1.1...2.1.2)

---
updated-dependencies:
- dependency-name: datatables.net-colreorder
  dependency-version: 2.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.40.46 to 1.40.49.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.40.46...1.40.49)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.40.49
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [social-auth-core](https://github.com/python-social-auth/social-core) from 4.8.0 to 4.8.1.
- [Release notes](https://github.com/python-social-auth/social-core/releases)
- [Changelog](https://github.com/python-social-auth/social-core/blob/master/CHANGELOG.md)
- [Commits](python-social-auth/social-core@4.8.0...4.8.1)

---
updated-dependencies:
- dependency-name: social-auth-core
  dependency-version: 4.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…v (docker-compose.yml) (#13386)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…8.0-alpine (docker-compose.yml) (#13385)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…/package.json) (#13382)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…rkflows/test-helm-chart.yml) (#13374)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [social-auth-app-django](https://github.com/python-social-auth/social-app-django) from 5.5.1 to 5.6.0.
- [Release notes](https://github.com/python-social-auth/social-app-django/releases)
- [Changelog](https://github.com/python-social-auth/social-app-django/blob/master/CHANGELOG.md)
- [Commits](python-social-auth/social-app-django@5.5.1...5.6.0)

---
updated-dependencies:
- dependency-name: social-auth-app-django
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dorkdiaries9 and others added 12 commits October 31, 2025 14:47
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.14.2 to 0.14.3.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.14.2...0.14.3)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [boto3](https://github.com/boto/boto3) from 1.40.62 to 1.40.63.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.40.62...1.40.63)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.40.63
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* priority engine docs

* Update docs/content/en/working_with_findings/priority_adjustments.md

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>

* Update docs/content/en/working_with_findings/priority_adjustments.md

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>

---------

Co-authored-by: Paul Osinski <paul.m.osinski@gmail.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
* 🐛 Robustify create_user to handle None value

* fix

* update

* update according to review
Release 2.52.0: Merge Bugfix into Dev
@rossops rossops closed this Nov 3, 2025
@rossops rossops reopened this Nov 3, 2025
@github-actions github-actions Bot added docker New Migration Adding a new migration file. Take care when merging. settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 docs unittests ui parser helm lint labels Nov 3, 2025
@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Nov 3, 2025

DryRun Security

🔴 Risk threshold exceeded.

This pull request includes a sensitive edit to the file dojo/apps.py; the scanner flagged this change as potentially sensitive and notes that sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml. No other issues were reported.

🔴 Configured Codepaths Edit in dojo/apps.py
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.

We've notified @mtesauro.


All finding details can be found in the DryRun Security Dashboard.

@rossops rossops merged commit 8bc3738 into master Nov 3, 2025
152 checks passed
Maffooch pushed a commit to valentijnscholten/django-DefectDojo that referenced this pull request Feb 16, 2026
Release: Merge release into master from: release/2.52.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

apiv2 docker docs helm lint New Migration Adding a new migration file. Take care when merging. parser settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui unittests

Projects

None yet

Development

Successfully merging this pull request may close these issues.