-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Release: Merge back 2.35.3 into dev from: master-into-dev/2.35.3-2.36.0-dev #10419
Conversation
….36.0-dev Release: Merge back 2.35.2 into bugfix from: master-into-bugfix/2.35.2-2.36.0-dev
Bumps [braces](https://github.com/micromatch/braces) from 3.0.2 to 3.0.3. - [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md) - [Commits](micromatch/braces@3.0.2...3.0.3) --- updated-dependencies: - dependency-name: braces dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* 🐛 fix trivy operator deduplication setting * update
Release: Merge release into master from: release/2.35.3
Hi there 👋, @DryRunSecurity here, below is a summary of our analysis and findings.
Note 🟢 Risk threshold not exceeded. Change Summary (click to expand)The following is a summary of changes in this pull request made by me, your security buddy 🤖. Note that this summary is auto-generated and not meant to be a definitive list of security issues but rather a helpful summary from a security perspective. Summary: This pull request includes a variety of changes across multiple files in the DefectDojo application, which is an open-source web application for managing software vulnerabilities. The changes cover a range of areas, including updates to issue templates, configuration files, Helm chart dependencies, and test cases. From an application security perspective, the changes do not appear to introduce any significant security vulnerabilities. The updates are primarily focused on improving the functionality, reliability, and robustness of the application's components. However, there are a few areas that warrant closer review and consideration:
Overall, the changes in this pull request appear to be focused on improving the functionality and reliability of the DefectDojo application, with no immediate security concerns. However, it's essential to thoroughly review the changes, address the potential security implications, and ensure that the application's security posture is maintained throughout the development process. Files Changed:
Powered by DryRun Security |
Signed-off-by: DefectDojo <defectdojo-project@owasp.org>
This pull request has conflicts, please resolve those before we can evaluate the pull request. |
Conflicts have been resolved. A maintainer will review the pull request shortly. |
Signed-off-by: DefectDojo <defectdojo-project@owasp.org>
Release triggered by
Maffooch