Hey folks- v3.3.0 is now available and there are quite a few new features and bug fixes in this release!
DefectDojo Weekly Changelog ๐ โ v3.3.0 (September 9, 2026) Hey everyone! A new update of DefectDojo Pro and Community Edition is out. Here's what's in this week's release:
๐งฉ (Correlation) Cross-domain finding correlation groups related findings into shared root causes. A finding's page now lists its root causes, root-cause blast radius feeds finding prioritization, and a new Top Root Causes dashboard widget plus a Product breakdown show where risk concentrates. Root causes cover CVE, component, resource, and endpoint types, hide CVE causes a component already covers, and are readable through a public read-only Root Cause API.
๐จ (PSIRT) PSIRT 2.0 is folded natively into DefectDojo Pro: native advisory feeds and a catalog, feed rules and rule templates, advisory-to-case conversion, and a dedicated PSIRT permission so an analyst does not need global maintainer.
โ๏ธ (Risk Acceptance) Risk Acceptances 2.0 adds a reviewable lifecycle with a pending-review queue and a durable ledger. You can also choose to restore a finding to Verified when its risk acceptance expires.
๐ฆ (Assets) A rebuilt asset model adds asset versions with BOM snapshots and per-version SBOM/VEX export, per-source identity and aliases so connectors resolve assets by the vendor's id, typed asset kinds, typed relationship edges that distinguish direct from indirect vulnerabilities, and asset exposure and deployment context (including live reachability probing and business-criticality sync from the CMDB).
๐ข (Organizations) Organizations can now be non-exclusive: an asset can belong to multiple organizations with union-of-grants RBAC, membership-aware organization filters on the asset and finding lists, and roles that can be granted across an entire organization type.
๐ (Dashboards) Dashboards 2.0 expands into the DefectDojo Command Center, with a published security-posture score.
๐ (Locations) Endpoints continue their move to Locations: asset connectors can emit standalone location inventory, and a new Location Map draws an asset's locations as derived trees per location type.
๐งญ (Navigation) Menu 2.0 now covers the whole sidebar, including a Sensei + AI section, a full-height sidebar rail with pinned pages, and server-backed shell preferences.
๐ค (Sensei) Added Sensei Advisor, which recommends settings changes and offers one-click fixes for mechanical deduplication-hygiene issues, with per-run license quotas for threat modeling and Advisor. The Sensei engine now ships in the on-prem compose bundles.
๐ (Connectors) New Rapid7 InsightVM - Cloud Instance and Aqua Supply Chain connectors, plus a Wiz option to import Issues only. Connectors gain customer-defined field mappings (versioned and identity-safe, per scan type), a connector registry the UI reads from, per-record sync checkpoints so an interrupted sync resumes, and health notifications when a connector stops working or authenticates but sees no data.
๐ ๏ธ (Universal Parser) Universal Parser field mappings can now be edited from a dedicated screen, with an impact warning attached.
๐ (Compliance) Added DISA STIG checklist import (.ckl/.cklb) with a CCI to NIST 800-53 crosswalk.
๐ค (Exporters) Added a CycloneDX/SPDX SBOM and CycloneDX VEX export API, and the Pro UI now accepts .spdx files on import.
โ๏ธ (API) Added API v3 (alpha) at `/api/v3-alpha/` with slim references, expansion, RBAC sub-resources, and the Pro importer. Custom Fields are now available on the token-authenticated `/api/v2` API.
๐๏ธ (Federal) Added FIPS 140-3 image support (FedRAMP SC-13), PAIN-keyed FedRAMP VDR remediation deadlines, and a FedRAMP prioritization preset.
๐ (Rules Engine 2.0) Rules can now trigger on scan absence, draw from a rule-template gallery, assign an SLA configuration or Risk Priority to assets, and condition on exploit evidence, reachability, and asset exposure.
๐ (Reporting) Added a Location Count field on every entity and reorderable block fields in the Report Builder.
๐ฆ (Assets) Added checkbox bulk edit on the asset list (organization, SLA, engine, tags) and customer-editable platform, lifecycle, and origin dropdowns.
๐ (Integrations) The Freshservice integration can push findings as ITIL Incidents or Problems per mapping, and MCP finding tools gained tag filtering.
๐งพ (Audit Log) System Settings changes are now recorded in the audit log.
๐ (Connectors) The JFrog, Tenable.io WAS, and Tenable VM connectors now stream findings per page instead of holding a whole sync in memory, and connectors report data-visibility warnings at config-test time. The Location URL is pre-filled for single-host tools.
โจ (UI) A first pass of accessibility and readability foundations: a visible focus ring, AA-contrast muted text, a System theme option, comfortable reading line-height, and shared type tokens. Toggleable panels now expand from a click anywhere on the header, and locked dropdowns gained a copy button.
โป๏ธ (Deduplication) Finding identity is now recorded in a signature ledger, versioned and bridged across formula changes, with a scheduled drift check that reports what moved; reimport can match on identity signatures.
๐ (Notifications) Notifications now fan out to every organization an asset belongs to.
๐ (Reporting) Report charts export as PNG so labels survive PDF rendering.
๐ฅ (Importers) Import and reimport bulk-create new findings, reducing per-finding overhead on large scans.
๐ (Connectors) Wiz now imports findings from tenants that use no Projects, the Microsoft Defender connector no longer fails a good sync during spool cleanup, and connector product descriptions are capped at the column limit.
๐ซ (Licensing) A usage block now answers with 402 rather than a throttle status, and license enforcement no longer blocks authentication.
๐ฅ (Importers) Scan severities are accepted case-insensitively, `.spdx` files are accepted for import, concurrent imports no longer race on scan-directory creation, and edited tests keep their scan type so reimport matching survives.
๐ ๏ธ (Parsers) Fortify now marks only suppressed FPR findings as false positive, Anchore Grype parses the CISA KEV date, and Xeol and Checkmarx One finding identity is deterministic.
โจ (UI) The Components list no longer renders an empty body while its paginator counts every row, ECharts resolves theme tokens to concrete colors, and the New Issue Tracker Assignment dialog no longer closes when going full-screen.
โจ (UI) The classic Bootstrap UI and the classic report engine have been retired; Menu 2.0 and the Pro Vue UI are now standard.
๐งฐ (Operations) The maintenance window feature has been removed.
Check out the full changelog here: docs.defectdojo.com/releases/pro/changelog#โฆ
DefectDojo Weekly Changelog ๐ โ v3.2.400 (August 31, 2026) Hey everyone! A new update of DefectDojo Pro and Community Edition is out. Here's what's in this week's release:
๐ค (Sensei) Added a generic fix flow: you can now associate a repository with a finding inline, and a gap-closing wizard walks you through anything else Sensei needs before it can generate a fix. Finding file paths are also resolved against the repository tree before the fix is generated, so fixes land in the right file.
๐ค (Sensei) Scan-and-fix now includes a scanner for AI agent skills (Skillspector).
๐ (Engagements) Added engagement checklists to the Pro UI.
โ๏ธ (Rules Engine 2.0) Rules can now be conditioned on KEV (Known Exploited Vulnerabilities) listing and exploit evidence.
๐งญ (Navigation) Added a searchable menu palette over the sidebar, opened with Cmd/Ctrl+K.
๐ (Correlation) The Root Cause view now has a Root Cause Organization column, asset and organization filters, and per-organization drill-in.
๐ค (Exporters) The UI SBOM export now offers SPDX alongside CycloneDX.
๐งฉ (Custom Fields) Custom fields now render on the entity create and edit forms, and are configured like any other form field.
๐ (Connectors) The Wiz, Microsoft Defender for Cloud, and CrowdStrike connectors now stream findings page by page rather than holding a whole sync in memory, so large syncs are faster and lighter.
Check out the full changelog here: docs.defectdojo.com/releases/pro/changelog#โฆ
Hey all - next week we're going to kickoff a new weekly product newsletter that highlights some of the updates made for DefectDojo Community Edition and DefectDojo Pro. If you'd like to receive an email instead of looking at the notes on slack be sure to subscribe to the newsletter on this page. We want to make sure this email is as useful as possible so let us know what things you'd like to see, what things you like, and what could be improved.
DefectDojo Weekly Changelog ๐ โ v3.2.201 (August 18, 2026) Hey everyone! A new update of DefectDojo Pro and Community Edition is out. Here's what's in this week's release:
๐งฉ (Page Layouts) The Risk Acceptance view page now uses a customizable widget grid, like the other View pages.
๐ค (Sensei) Added Amazon Bedrock as an on-prem LLM connection.
๐ (Locations) The data-migration suite on the Feature Flags page can now be cancelled while a backfill is running. Cancelling stops the run at the next batch boundary and keeps everything migrated so far, so re-running the item resumes and converges on the same result. A run whose worker is lost is now detected and marked failed on its own, so a stuck suite becomes runnable again instead of blocking every item.
๐ (Endpoints) Endpoints are now deprecated in favour of Locations.
๐งญ (Menu) Classic-menu users are now warned that Menu 2.0 becomes the standard in 3.3.0.
โ๏ธ (CSPM) Cloud Security Posture Management is now gated on the Sensei license rather than a separate feature flag.
๐ค (Sensei) Scan-and-fix scanner parallelism is now configurable, via `--max-parallel` / `MAX_PARALLEL` (and `sensei.maxParallel` in Helm).
๐ (Authorization) Import and reimport preview targets are now scoped to the caller's permissions, POA&M item findings are validated against the record's own product, and questionnaire expiration and question-set editing are checked against the response route and the questionnaire change permission.
โ (Risk Acceptance) A companion-less risk acceptance is now counted correctly, as active and as non-global, when filtering.
๐ (Reporting) Report graph blocks that no browser captured are now drawn instead of failing silently, and the BETA badge that Menu 2.0 re-added after GA is gone.
๐ซ (Licensing) License enforcement no longer blocks authentication.
๐ (Connectors) The Action1 connector derives severity from the CVSS score when no severity bucket is usable, and a chunked sync now records one Import History row per sync.
๐ (Locations) The endpoints-to-locations backfill now reports distinct locations and per-endpoint failures.
๐ (Dedupe) Finding post-processing now retries on a transient DB deadlock.
โจ (UI) The Advisor now renders with PrimeVue, and PSIRT and Field Mappings are nested correctly in the legacy sidebar.
๐ง (Threat Model) The schema-repair loop no longer deletes the prompt it is repairing.
Check out the full changelog here: docs.defectdojo.com/releases/pro/changelog#โฆ
Hey Folks next week we have a new training webinar on the use cases and new features surrounding LLM's and DefectDojo. There are quite a few applications for LLM's to utilize the data in DefectDojo in a secure way (reporting, parsers, and much more). Join us next week as we cover the basics
DefectDojo Weekly Changelog ๐ โ v3.2.200 (August 17, 2026) Hey everyone! A new update of DefectDojo Pro and Community Edition is out. Here's what's in this week's release: New features:
โ๏ธ (CSPM) Added Cloud Security Posture Management: connect AWS, Azure, and GCP cloud accounts, run posture scans against them, and apply reversible direct remediation to the misconfigurations that are found.
๐ฐ๏ธ (Asset Exposure) Added asset exposure reporting from Wiz, Shodan, and Censys, and from CrowdStrike Spotlight (which reports only the exposure it can prove).
๐ (Connectors) Registered the Aikido Security, Jit, and Cycode connectors.
๐ฏ (Finding Templates) You can now apply a finding template to a Finding, and turn a Finding into a template, directly from the Vue UI.
โจ (Form Configuration) Added admin-controlled Form Configuration for the Vue create and edit forms, so an administrator can decide which fields appear.
๐ (Locations) Added a DB-backed Locations toggle, with a data-migration suite to move existing data over.
๐๏ธ (Assets) You can now export the asset and organization inventory as CSV.
๐ (Reporting) Quick Export now names its output from the current context, and you can apply a report template to an export.
๐ฏ (Findings) Added a filterable Review Claimant column to the findings list.
โ๏ธ (Rules Engine) Rules Engine permissions now split into View / Add / Edit / Delete for finer RBAC.
๐ฉ (Feature Flags) Promoted nine feature flags off the menu, turned five more on by default, and moved Feature Flags out of System into its own settings location.
โจ (Layouts) Layout customization can now be restricted to admin-designated defaults.
Enhancements:
๐ (Qualys) The Qualys connector now accepts a Host Tags filter that scopes discovery to hosts carrying the Qualys asset tags you name. The filter is sent to Qualys, so out-of-scope hosts are never downloaded. It applies to the detection download as well as the host listing, so a narrowed scope also shortens each Sync. Tag names are matched exactly, because Qualys supports no wildcards on tag names. Leave the field blank to keep discovering every host.
๐ (JFrog) The JFrog connector now surfaces a pending status.
๐ (Jira) The Jira connector now accepts service accounts.
๐ฏ (Findings) The count of Findings a tool submitted is now recorded before deduplication runs.
๐ (API) The finding serializer now exposes a flat test_type_name field.
๐ค (MCP) Finding and asset Location retrieval is now consolidated into single REST calls.
๐ (Locations) The data-migration suite on the Feature Flags page can now be cancelled while a backfill is running. Cancelling stops the run at the next batch boundary and keeps everything migrated so far, so re-running the item resumes and converges on the same result. A run whose worker is lost is now detected and marked failed on its own, so a stuck suite becomes runnable again instead of blocking every item.
Bug fixes:
๐ (Authorization) Location data, DojoMeta visibility, and the /api/v2/location/ endpoint are now scoped to the requesting user's products and RBAC rather than superusers only; every routed connector endpoint is named in the permission allow-list; the user edit form authorization was hardened; Tool Configuration credentials are kept out of the edit form; and the private-note visibility rule is now applied in the note UI views.
๐ค (Export) Spreadsheet formulas can no longer execute out of an exported file (CSV/formula injection).
๐ (SSO) SAML2 routes now answer 404 when SAML is disabled.
๐ฏ (Findings) The Priority filter and override inputs now accept decimal values.
๐๏ธ (Assets) A PATCH without a parent field no longer orphans the asset, and auto-creating the same asset name concurrently no longer returns a 500.
๐ฅ (Importers) Bulk finding deletes, tag-count updates, and async cascade deletes now retry on transient DB conflicts and are ordered so concurrent imports and deletes cannot deadlock.
๐ (Connectors) The Action1 connector tolerates non-numeric sentinels in quoted numeric fields, and the Microsoft Defender connector retries a transient 5xx/429 on a single export page instead of failing the whole export.
๐ ๏ธ (Parsers) Fixed a Trivy Scan crash from an uninitialized resource_name, and reset Scout Suite parser state so a report parses to the same findings twice.
๐ (Notes) A partial note PATCH now keeps the note body and no longer writes a null NoteHistory entry.
๐ (Reporting) Reports no longer fetch unrenderable columns, report cells are now bounded, and a block's Order By is applied through the filterset.
โจ (Tables & UI) Clipped table cell text now wraps, the empty band below short pages is gone, the viewport row cap no longer oscillates and stalls a table, and the severity bar chart is positioned correctly in the open findings chart.
โจ (Page Grid) A widget's Title and Icon now follow its Records choice.
๐ (Jira) Fixed the Jira migration.
Check out the full changelog here: docs.defectdojo.com/releases/pro/changelog#โฆ
DefectDojo Weekly Changelog ๐ โ v3.2.100 (August 10, 2026) Hey everyone! A new update of DefectDojo Pro and Community Edition is out. Here's what's in this week's release: NOTE: The classic report engine (Report Builder, Report Templates and Generated Reports) will be removed in 3.3.0 on September 8, 2026. New features:
๐ฆ (VEX) Added CycloneDX SBOM / VEX / VDR export and import, as a round trip: a document exported from DefectDojo can be imported back into DefectDojo. The raw CycloneDX VEX analysis is now preserved on parsed Findings.
๐ชช (SCIM) Added SCIM 2.0 provisioning. Your identity provider can now create, update and deactivate DefectDojo users and manage groups directly, rather than DefectDojo only learning about a user when that user first signs in. Deactivating a user over SCIM also deletes that user's API tokens. SCIM is configured under Connect > Authorization, alongside your login providers, and is tagged Provisioning to distinguish it from the providers that put a button on the login page.
๐ (Downstream Connectors) Added Messaging Connectors (beta), which send alerts to Slack, Microsoft Teams, email, or an Amazon SNS topic. Alerts are routed by Rules Engine 2.0: a rule decides when to send, which Findings qualify, and which connection and destination the message goes to. Requires the Messaging Connectors and Rules Engine 2.0 feature flags.
๐ (Reporting) Reporting is now generally available, and no longer carries the BETA label.
๐ (Reports) Both the classic Report Builder and the new Report Builder now offer a one-click migration of your existing report templates. The migration works with the Reporting feature flag off, so you can move on your own schedule. Reports you have already generated are finished files and stay downloadable until removal.
๐งฉ (Page Layouts) The five View pages now use customizable widget grids, so you can arrange each page's widgets.
๐ (Tables) Table columns can now be resized, and the widths you set are saved to your table preferences. List tables also render a per-column loading skeleton while data is loading.
๐ (Connectors) Registered the Tenable Web App Scanning and Rapid7 InsightVM connectors, along with six connectors that had shipped without a registration.
๐ค (Sensei) A provider can now hold several connections rather than one, and setup is scoped to the connection you are working in. Add Repositories now opens on the repository step. Semgrep scans run under a memory cap and recover across a hard kill (OOM).
โ (Risk Acceptance) Added Expire and Reinstate to the risk acceptance menu, and as API actions.
โ๏ธ (Rules Engine 2.0) A Rules Engine 2.0 rule can now be given its own schedule. Enabling the feature flag now warns that a worker restart is required before it takes effect.
๐ (Locations) Added migrate_locations_to_endpoints, the reverse of the endpoint-to-location conversion.
Enhancements:
๐ (Connectors) A connector request now requires a usable credential and a base URL, so a request cannot be submitted with details that will not connect.
๐ ๏ธ (Snyk) Snyk reachability is now rendered as the raw values Snyk reports, rather than a derived yes/no.
โก (Performance) Notes are now serialized a page at a time without re-filtering the page, and deduplication no longer lowercases the hash input on every Finding purely to log it.
๐ (Dashboards) The two Group By selects now focus their filter automatically when opened.
Check out the full changelog here: docs.defectdojo.com/releases/pro/changelog#โฆ
Hey Folks this week's release is a massive one! To shoutout some of the more noteworthy features--
New Reachability Support
A brand new Drag and Drop Rules Engine 2.0 for building automations/rules
New Threat Intelligence support for Priority Engine
A new federal compliance bundle for FedRamp, ConMon, and others
Check out the latest release and have your super admins toggle the feature flags on if you'd like to test out the new features!

