# Open Source Upgrades

Release specific upgrading instructions

## Upgrading to DefectDojo Version 1.10.x
security release + breaking changes

## Upgrading to DefectDojo Version 1.11.x
security release

## Upgrading to DefectDojo Version 1.12.x
security release

## Upgrading to DefectDojo Version 1.13.x
hashcode calculation logic has changed

## Upgrading to DefectDojo Version 1.14.x
hashcode calculation logic has changed

## Upgrading to DefectDojo Version 1.15.x
hashcode calculation logic has changed

## Upgrading to DefectDojo Version 1.2.2
multiple instructions

## Upgrading to DefectDojo Version 1.2.3
multiple instructions

## Upgrading to DefectDojo Version 1.2.4
multiple instructions

## Upgrading to DefectDojo Version 1.2.8
multiple instructions

## Upgrading to DefectDojo Version 1.2.9
multiple instructions

## Upgrading to DefectDojo Version 1.3.1
multiple instructions

## Upgrading to DefectDojo Version 1.7.0
multiple instructions

## Upgrading to DefectDojo Version 1.8.0
fix buildwatson create_endpoint_status

## Upgrading to DefectDojo Version 1.9.3
security release

## Upgrading to DefectDojo Version 2.0.x
breaking changes

## Upgrading to DefectDojo Version 2.10.x
breaking change

## Upgrading to DefectDojo Version 2.12.x
breaking change

## Upgrading to DefectDojo Version 2.13.x
instructions for helm chart and others

## Upgrading to DefectDojo Version 2.15.x
No special instructions.

## Upgrading to DefectDojo Version 2.16.x
No special instructions.

## Upgrading to DefectDojo Version 2.17.x
No special instructions.

## Upgrading to DefectDojo Version 2.18.x
instructions for helm chart

## Upgrading to DefectDojo Version 2.19.x
breaking change

## Upgrading to DefectDojo Version 2.2.x
No special instructions.

## Upgrading to DefectDojo Version 2.20.x
No special instructions.

## Upgrading to DefectDojo Version 2.21.x
No special instructions.

## Upgrading to DefectDojo Version 2.22.x
No special instructions.

## Upgrading to DefectDojo Version 2.23.x
breaking change

## Upgrading to DefectDojo Version 2.24.x
No special instructions.

## Upgrading to DefectDojo Version 2.25.x
No special instructions.

## Upgrading to DefectDojo Version 2.26.x
No special instructions.

## Upgrading to DefectDojo Version 2.27.x
No special instructions.

## Upgrading to DefectDojo Version 2.28.x
No special instructions.

## Upgrading to DefectDojo Version 2.29.x
No special instructions.

## Upgrading to DefectDojo Version 2.3.x
No special instructions.

## Upgrading to DefectDojo Version 2.30.x
Breaking Change for Auditlog.

## Upgrading to DefectDojo Version 2.31.x
breaking change

## Upgrading to DefectDojo Version 2.32.x
Breaking change for Removal of OpenAPI 2.0 Swagger

## Upgrading to DefectDojo Version 2.33.x
breaking change

## Upgrading to DefectDojo Version 2.34.x
Breaking Change for AWS_Scout2.

## Upgrading to DefectDojo Version 2.35.x
Integrity checker announced

## Upgrading to DefectDojo Version 2.36.x
Breaking Change for HELM deployments with PostgreSQL

## Upgrading to DefectDojo Version 2.37.x
Breaking Change for HELM deployments and MySQL / RabbitMQ users

## Upgrading to DefectDojo Version 2.38.x
Breaking Change for HELM deployments

## Upgrading to DefectDojo Version 2.39.x
Major upgrade of Postgres 16 to 17

## Upgrading to DefectDojo Version 2.4.x (Security Release)
security Release

## Upgrading to DefectDojo Version 2.40.x
Breaking Change for Postgres 12.

## Upgrading to DefectDojo Version 2.41.x
No special instructions.

## Upgrading to DefectDojo Version 2.42.x
No special instructions.

## Upgrading to DefectDojo Version 2.43.x
Disclaimer field renamed/split, removal of `dc-` scripts, audit log updates, and hash codes updates.

## Upgrading to DefectDojo Version 2.44.0
No special instructions.

## Upgrading to DefectDojo Version 2.44.1
No special instructions.

## Upgrading to DefectDojo Version 2.45.x
No special instructions.

## Upgrading to DefectDojo Version 2.46.x
Tag Formatting Changes + Import Payload Changes

## Upgrading to DefectDojo Version 2.47.x
Drop support for PostgreSQL-HA in HELM

## Upgrading to DefectDojo Version 2.48.2
Tag invalid character cleanup

## Upgrading to DefectDojo Version 2.48.x
Better pushing to JIRA for Finding Groups

## Upgrading to DefectDojo Version 2.49.x
No special instructions.

## Upgrading to DefectDojo Version 2.5.x
legacy authorization removed

## Upgrading to DefectDojo Version 2.50.x
Dropped support for time_zone in System settings.

## Upgrading to DefectDojo Version 2.51.x
Helm chart changes and Postgres major version updates.

## Upgrading to DefectDojo Version 2.52.x
Replaced Redis with Valkey & Helm chart changes & MobSF parser merge

## Upgrading to DefectDojo Version 2.53.x
Helm chart: changes for initializer annotations + Replaced Redis with Valkey + HPA & PDB support + Batch Deduplication

## Upgrading to DefectDojo Version 2.54.3
Trivy parser deduplication

## Upgrading to DefectDojo Version 2.54.x
Removal of django-auditlog & Dropped support for DD_PARSER_EXCLUDE & Reimport performance improvements & Removal of Finding Template Matching

## Upgrading to DefectDojo Version 2.55.2
JIRA Reconciliation now also processes Finding Groups.

## Upgrading to DefectDojo Version 2.55.x
Authorization related optimizations

## Upgrading to DefectDojo Version 2.56.4
JFrog Xray API Summary Artifact parser deduplication

## Upgrading to DefectDojo Version 2.56.x
Deprecation of Questionnaire API Endpoints

## Upgrading to DefectDojo Version 2.57.x
Deprecation of Credential Manager and Stub Findings

## Upgrading to DefectDojo Version 2.58.x
Notification .tpl templates relocated under dojo/notifications/

## Upgrading to DefectDojo Version 2.6.x
No special instructions.

## Upgrading to DefectDojo Version 2.7.x
breaking change

## Upgrading to DefectDojo Version 2.8.x
breaking changes

## Upgrading to DefectDojo Version 2.9.x
breaking change for APIv2

## Upgrading to DefectDojo Version 3.0.100
Xygeni parser keeps repeated SAST/Secrets occurrences in the same file as distinct findings.

## Upgrading to DefectDojo Version 3.0.200
Xygeni parser keys SAST/Secrets deduplication on uniqueHash; repeated secrets are aggregated into one finding.

## Upgrading to DefectDojo Version 3.0.x
Locations and Asset/Organization labels are now enabled by default; Authorized Users panel replaces Members/Groups under legacy authorization; SSO providers move to DefectDojo Pro; removal of Questionnaire API Endpoints, Credential Manager, and Stub Findings; Dependency Check parser no longer emits separate findings for related dependencies; related file paths are now listed in the main finding's description.

## Upgrading to DefectDojo Version 3.1.x
Blank Finding components are now normalized to NULL so component-less findings group together; JIRA project configurations now support multiple comma-separated components; Tool Configuration credentials are re-encrypted to AES-256-GCM; the JFrog Xray API Summary Artifact parser now sorts impact paths so findings deduplicate consistently across re-imports; a new optional DD_OS_MESSAGE_ENABLED setting controls the open-source promo banner; and a new deduplication execution mode controls how import/reimport deduplication is dispatched.
