Release Information | DefectDojo Documentation
Releases
Adding the Dd-Orch Database on Upgrade
Provisioning the dojodb-ddorch PostgreSQL database and pointing DefectDojo Pro at it on an existing self-hosted installation.
DefectDojo Pro Changelog
DefectDojo Changelog
Open Source Upgrading
Release specific upgrading instructions
Upgrading to DefectDojo Version 1.10.x
security release + breaking changes
Upgrading to DefectDojo Version 1.11.x
security release
Upgrading to DefectDojo Version 1.12.x
security release
Upgrading to DefectDojo Version 1.13.x
hashcode calculation logic has changed
Upgrading to DefectDojo Version 1.14.x
hashcode calculation logic has changed
Upgrading to DefectDojo Version 1.15.x
hashcode calculation logic has changed
Upgrading to DefectDojo Version 1.2.2
multiple instructions
Upgrading to DefectDojo Version 1.2.3
multiple instructions
Upgrading to DefectDojo Version 1.2.4
multiple instructions
Upgrading to DefectDojo Version 1.2.8
multiple instructions
Upgrading to DefectDojo Version 1.2.9
multiple instructions
Upgrading to DefectDojo Version 1.3.1
multiple instructions
Upgrading to DefectDojo Version 1.7.0
multiple instructions
Upgrading to DefectDojo Version 1.8.0
fix buildwatson create_endpoint_status
Upgrading to DefectDojo Version 1.9.3
security release
Upgrading to DefectDojo Version 2.0.x
breaking changes
Upgrading to DefectDojo Version 2.10.x
breaking change
Upgrading to DefectDojo Version 2.12.x
breaking change
Upgrading to DefectDojo Version 2.13.x
instructions for helm chart and others
Upgrading to DefectDojo Version 2.15.x
No special instructions.
Upgrading to DefectDojo Version 2.16.x
No special instructions.
Upgrading to DefectDojo Version 2.17.x
No special instructions.
Upgrading to DefectDojo Version 2.18.x
instructions for helm chart
Upgrading to DefectDojo Version 2.19.x
breaking change
Upgrading to DefectDojo Version 2.2.x
No special instructions.
Upgrading to DefectDojo Version 2.20.x
No special instructions.
Upgrading to DefectDojo Version 2.21.x
No special instructions.
Upgrading to DefectDojo Version 2.22.x
No special instructions.
Upgrading to DefectDojo Version 2.23.x
breaking change
Upgrading to DefectDojo Version 2.24.x
No special instructions.
Upgrading to DefectDojo Version 2.25.x
No special instructions.
Upgrading to DefectDojo Version 2.26.x
No special instructions.
Upgrading to DefectDojo Version 2.27.x
No special instructions.
Upgrading to DefectDojo Version 2.28.x
No special instructions.
Upgrading to DefectDojo Version 2.29.x
No special instructions.
Upgrading to DefectDojo Version 2.3.x
No special instructions.
Upgrading to DefectDojo Version 2.30.x
Breaking Change for Auditlog.
Upgrading to DefectDojo Version 2.31.x
breaking change
Upgrading to DefectDojo Version 2.32.x
Breaking change for Removal of OpenAPI 2.0 Swagger
Upgrading to DefectDojo Version 2.33.x
breaking change
Upgrading to DefectDojo Version 2.34.x
Breaking Change for AWS_Scout2.
Upgrading to DefectDojo Version 2.35.x
Integrity checker announced
Upgrading to DefectDojo Version 2.36.x
Breaking Change for HELM deployments with PostgreSQL
Upgrading to DefectDojo Version 2.37.x
Breaking Change for HELM deployments and MySQL / RabbitMQ users
Upgrading to DefectDojo Version 2.38.x
Breaking Change for HELM deployments
Upgrading to DefectDojo Version 2.39.x
Major upgrade of Postgres 16 to 17
Upgrading to DefectDojo Version 2.4.x (Security Release)
security Release
Upgrading to DefectDojo Version 2.40.x
Breaking Change for Postgres 12.
Upgrading to DefectDojo Version 2.41.x
No special instructions.
Upgrading to DefectDojo Version 2.42.x
No special instructions.
Upgrading to DefectDojo Version 2.43.x
Disclaimer field renamed/split, removal of dc- scripts, audit log updates, and hash codes updates.
Upgrading to DefectDojo Version 2.44.0
No special instructions.
Upgrading to DefectDojo Version 2.44.1
No special instructions.
Upgrading to DefectDojo Version 2.45.x
No special instructions.
Upgrading to DefectDojo Version 2.46.x
Tag Formatting Changes + Import Payload Changes
Upgrading to DefectDojo Version 2.47.x
Drop support for PostgreSQL-HA in HELM
Upgrading to DefectDojo Version 2.48.2
Tag invalid character cleanup
Upgrading to DefectDojo Version 2.48.x
Better pushing to JIRA for Finding Groups
Upgrading to DefectDojo Version 2.49.x
No special instructions.
Upgrading to DefectDojo Version 2.5.x
legacy authorization removed
Upgrading to DefectDojo Version 2.50.x
Dropped support for time_zone in System settings.
Upgrading to DefectDojo Version 2.51.x
Helm chart changes and Postgres major version updates.
Upgrading to DefectDojo Version 2.52.x
Replaced Redis with Valkey & Helm chart changes & MobSF parser merge
Upgrading to DefectDojo Version 2.53.x
Helm chart: changes for initializer annotations + Replaced Redis with Valkey + HPA & PDB support + Batch Deduplication
Upgrading to DefectDojo Version 2.54.3
Trivy parser deduplication
Upgrading to DefectDojo Version 2.54.x
Removal of django-auditlog & Dropped support for DD_PARSER_EXCLUDE & Reimport performance improvements & Removal of Finding Template Matching
Upgrading to DefectDojo Version 2.55.2
JIRA Reconciliation now also processes Finding Groups.
Upgrading to DefectDojo Version 2.55.x
Authorization related optimizations
Upgrading to DefectDojo Version 2.56.4
JFrog Xray API Summary Artifact parser deduplication
Upgrading to DefectDojo Version 2.56.x
Deprecation of Questionnaire API Endpoints
Upgrading to DefectDojo Version 2.57.x
Deprecation of Credential Manager and Stub Findings
Upgrading to DefectDojo Version 2.58.x
Notification .tpl templates relocated under dojo/notifications/
Upgrading to DefectDojo Version 2.6.x
No special instructions.
Upgrading to DefectDojo Version 2.7.x
breaking change
Upgrading to DefectDojo Version 2.8.x
breaking changes
Upgrading to DefectDojo Version 2.9.x
breaking change for APIv2
Upgrading to DefectDojo Version 3.0.100
Xygeni parser keeps repeated SAST/Secrets occurrences in the same file as distinct findings.
Upgrading to DefectDojo Version 3.0.200
Xygeni parser keys SAST/Secrets deduplication on uniqueHash; repeated secrets are aggregated into one finding.
Upgrading to DefectDojo Version 3.0.x
Locations and Asset/Organization labels are now enabled by default; Authorized Users panel replaces Members/Groups under legacy authorization; SSO providers move to DefectDojo Pro; removal of Questionnaire API Endpoints, Credential Manager, and Stub Findings; Dependency Check parser no longer emits separate findings for related dependencies; related file paths are now listed in the main finding's description.
Upgrading to DefectDojo Version 3.1.x
Blank Finding components are now normalized to NULL so component-less findings group together; JIRA project configurations now support multiple comma-separated components; Tool Configuration credentials are re-encrypted to AES-256-GCM; the JFrog Xray API Summary Artifact parser now sorts impact paths so findings deduplicate consistently across re-imports; a new optional DD_OS_MESSAGE_ENABLED setting controls the open-source promo banner; and a new deduplication execution mode controls how import/reimport deduplication is dispatched.