Skip to content

🐛 fix finding closed with a provided mitigated date #13699#13700

Merged
mtesauro merged 2 commits intoDefectDojo:bugfixfrom
manuel-sommer:fix_close_finding_ui
Nov 17, 2025
Merged

🐛 fix finding closed with a provided mitigated date #13699#13700
mtesauro merged 2 commits intoDefectDojo:bugfixfrom
manuel-sommer:fix_close_finding_ui

Conversation

@manuel-sommer
Copy link
Copy Markdown
Contributor

@manuel-sommer manuel-sommer commented Nov 13, 2025

#13699

closing a finding with a provided "mitigated date" results in an error.

@dryrunsecurity
Copy link
Copy Markdown

DryRun Security

🔴 Risk threshold exceeded.

This pull request includes a sensitive edit to the file dojo/finding/helper.py (a configured codepath), which may require review against .dryrunsecurity.yaml settings for allowed authors and sensitive paths. The change triggered a failing risk threshold but is not marked as blocking.

🔴 Configured Codepaths Edit in dojo/finding/helper.py
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.

We've notified @mtesauro.


All finding details can be found in the DryRun Security Dashboard.

@manuel-sommer
Copy link
Copy Markdown
Contributor Author

please review @valentijnscholten

Copy link
Copy Markdown
Member

@valentijnscholten valentijnscholten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. I think the reported issue still needs fixing? That could be depending on the valueof DD_EDITABLE_MITIGATED_DATA?

@valentijnscholten valentijnscholten added this to the 2.52.2 milestone Nov 13, 2025
@manuel-sommer
Copy link
Copy Markdown
Contributor Author

Thanks. I think the reported issue still needs fixing? That could be depending on the valueof DD_EDITABLE_MITIGATED_DATA?

I was not able to reproduce the original issue, but discovered this one while testing it, thus I can't judge on this.

@manuel-sommer
Copy link
Copy Markdown
Contributor Author

Thanks. I think the reported issue still needs fixing? That could be depending on the valueof DD_EDITABLE_MITIGATED_DATA?

Good hint @valentijnscholten, I was not sure if I should fix this issue also here, so I opened up a second PR, then you can test it easier with 2 different PRs resolving the 2 different issues #13701

@manuel-sommer
Copy link
Copy Markdown
Contributor Author

@Maffooch and @mtesauro: Just a heads-up: I assume you’d like to merge this quickly since it’s a bug that could potentially affect a larger group.

Copy link
Copy Markdown
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@mtesauro mtesauro merged commit 2593926 into DefectDojo:bugfix Nov 17, 2025
150 checks passed
@manuel-sommer manuel-sommer deleted the fix_close_finding_ui branch November 17, 2025 06:42
Maffooch pushed a commit to valentijnscholten/django-DefectDojo that referenced this pull request Feb 16, 2026
…efectDojo#13700)

* 🐛 fix finding closed with a provided mitigated date

* advance unittests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants