Skip to content

fix: enable uwsgi DD_UWSGI_EXTRA_ARGS passthrough#13756

Merged
rossops merged 3 commits intoDefectDojo:devfrom
Bump-Action:uwsgi-extra-args
Dec 1, 2025
Merged

fix: enable uwsgi DD_UWSGI_EXTRA_ARGS passthrough#13756
rossops merged 3 commits intoDefectDojo:devfrom
Bump-Action:uwsgi-extra-args

Conversation

@Bump-Action
Copy link
Copy Markdown
Contributor

@Bump-Action Bump-Action commented Nov 22, 2025

Description

Prevent resetting DD_UWSGI_EXTRA_ARGS variable in uwsgi entry point

What problem does it solve?

Allows you to passthrough your startup parameters to the uwsgi binary

@dryrunsecurity
Copy link
Copy Markdown

dryrunsecurity Bot commented Nov 22, 2025

DryRun Security

🔴 Risk threshold exceeded.

This pull request modifies a sensitive file (docker/entrypoint-uwsgi.sh) with edits flagged by the scanner; review carefully and update .dryrunsecurity.yaml if these changes and authors are expected. The finding is non-blocking but marked as failing under the configured risk threshold.

🔴 Configured Codepaths Edit in docker/entrypoint-uwsgi.sh
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.
🔴 Configured Codepaths Edit in docker/entrypoint-uwsgi.sh
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.

We've notified @mtesauro.


All finding details can be found in the DryRun Security Dashboard.

@Bump-Action Bump-Action changed the base branch from master to dev November 22, 2025 16:59
@valentijnscholten valentijnscholten added this to the 2.53.0 milestone Nov 22, 2025
Copy link
Copy Markdown
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

Comment thread docker/entrypoint-uwsgi.sh Outdated
Copy link
Copy Markdown
Member

@valentijnscholten valentijnscholten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Bump-Action Thank you for the PR. Could you change it to be DD_UWSGI_EXTRA_ARGS?

@Bump-Action
Copy link
Copy Markdown
Contributor Author

@Bump-Action Thank you for the PR. Could you change it to be DD_UWSGI_EXTRA_ARGS?

Done

@valentijnscholten valentijnscholten changed the title fix: enable uwsgi EXTRA_ARGS passthrough fix: enable uwsgi DD_UWSGI_EXTRA_ARGS passthrough Nov 28, 2025
@rossops rossops merged commit 9f3d23b into DefectDojo:dev Dec 1, 2025
150 checks passed
Maffooch pushed a commit to valentijnscholten/django-DefectDojo that referenced this pull request Feb 16, 2026
fix: enable uwsgi DD_UWSGI_EXTRA_ARGS passthrough
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants