Release: Merge back 2.52.1 into dev from: master-into-dev/2.52.1-2.53.0-dev #13667
DryRunSecurity / General Security Analyzer
succeeded
Nov 10, 2025 in 3s
DryRun Security
Details
General Security Analyzer Findings: 1 detected
⚠️ Delayed Security Patching for Supply Chain Tool .github/renovate.json (click for details)
| Type | Delayed Security Patching for Supply Chain Tool |
| Description | The configuration for the Renovate bot is changed to delay its own updates to a weekly schedule. Renovate is a critical supply chain tool with privileged access to repository data. Delaying its updates creates a window of up to a week where the repository is exposed to any newly discovered and patched vulnerabilities in Renovate itself. Past vulnerabilities in Renovate have included serious issues like token leakage and arbitrary command injection, highlighting the risk of delayed patching. |
| Filename | .github/renovate.json |
| CodeLink | django-DefectDojo/.github/renovate.json Lines 29 to 32 in 5bf54c2 |
Loading