Skip to content

Release: Merge back 2.52.0 into dev from: master-into-dev/2.52.0-2.53.0-dev#13605

Merged
rossops merged 6 commits intodevfrom
master-into-dev/2.52.0-2.53.0-dev
Nov 3, 2025
Merged

Release: Merge back 2.52.0 into dev from: master-into-dev/2.52.0-2.53.0-dev#13605
rossops merged 6 commits intodevfrom
master-into-dev/2.52.0-2.53.0-dev

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Nov 3, 2025

Release triggered by rossops

@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Nov 3, 2025

DryRun Security

This pull request uses a mutable GitHub Action reference: the workflow .github/workflows/slack-pr-reminder.yml pins DefectDojo-Inc/notify-pr-reviewers-action to @master, which is a supply-chain risk because changes to that branch could execute arbitrary or malicious code in your CI. Consider pinning to a specific tag or commit SHA to mitigate this.

Unpinned GitHub Action Version in .github/workflows/slack-pr-reminder.yml
Vulnerability Unpinned GitHub Action Version
Description The GitHub Actions workflow '.github/workflows/slack-pr-reminder.yml' uses a mutable reference ('@master') for the action 'DefectDojo-Inc/notify-pr-reviewers-action'. This creates a supply chain risk, as any changes pushed to the master branch of the action's repository, whether malicious or accidental, will be automatically executed by this workflow. This could lead to compromised builds, secret exfiltration, or other CI/CD pipeline attacks.

uses: DefectDojo-Inc/notify-pr-reviewers-action@master # Do not use a specific version to always get the latest updates
with:
owner: "DefectDojo"
repository: "django-DefectDojo"


All finding details can be found in the DryRun Security Dashboard.

@rossops rossops closed this Nov 3, 2025
@rossops rossops reopened this Nov 3, 2025
@rossops rossops merged commit bd689fe into dev Nov 3, 2025
149 checks passed
@rossops rossops deleted the master-into-dev/2.52.0-2.53.0-dev branch November 3, 2025 19:47
Maffooch pushed a commit to valentijnscholten/django-DefectDojo that referenced this pull request Feb 16, 2026
….52.0-2.53.0-dev

Release: Merge back 2.52.0 into dev from: master-into-dev/2.52.0-2.53.0-dev
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants