DefectDojo Weekly Changelog v3.1.300: Custom Roles, New Connectors, Enhanced SSO & Performance Updates (July 27, 2026)
DefectDojo Weekly Changelog ๐ โ v3.1.300 (July 27, 2026) Hey everyone! A new update of DefectDojo Pro and Community Edition is out. Here's what's in this week's release:
๐ (RBAC) Added user-defined Custom Roles. You can now create your own roles with a granular permission set per object type, instead of being limited to the built-in roles.
๐ (Connectors) Added another large batch of Connectors. New findings connectors: Fortify (SSC and FoD), HCL AppScan (ASoC and AppScan 360ยฐ), Datadog Cloud Security, MobSF, Deepfence ThreatMapper, NeuVector, Lacework / FortiCNAPP, Socket.dev, Bright Security, Aqua Security, Escape, Detectify, Fairwinds Insights, Wallarm, Vanta, NowSecure, FOSSA, Codacy, DeepSource, Beagle Security, Orca, AccuKnox, Halo Security, and Nightfall AI. Connector nomenclature is now unified as Upstream and Downstream Connectors, and you can request either type from the cloud UI.
๐ (Connectors) JFrog Xray gained an artifact-level record mode, with connector-declared parents materialized as asset hierarchy edges. The new mode is on by default for new installations only, so existing installations keep their current record layout. Checkmarx One added opt-in per-branch sync via a `track_branches` toggle, which creates a separate engagement per tracked branch. Connector engagement names now include the asset name.
๐ (Connectors) Connector syncs are more resilient on large data sets.
๐ค (Sensei) Added Bitbucket, Azure DevOps, and GitHub Enterprise connections, along with a Revert action and GitLab remediation support.
๐ (Authentication) Login, logout, MFA, SSO, and password reset now run natively in the Pro UI rather than falling back to the classic UI. Added a generic LDAP authentication integration, configurable from the Tuner.
๐ (SSO) Added self-serve SSO diagnostics and logs so you can troubleshoot a misconfigured provider without opening a support ticket.
๐ฉ (Feature Flags) Organization / Asset relabeling is now a database-driven feature flag. Feature flags are also readable through the v2 API and MCP, and the legacy feature flag table was retired.
๐ (Integrations) The ServiceNow integrator now supports transition-time custom fields and `client_credentials` authentication, and surfaces integration errors in the UI.
๐๏ธ (Filters) Date filters now resolve day boundaries in the viewing user's timezone, and the SLA filter options were reworked.
โ๏ธ (API) Tightened validation and authorization across the user, product type, test, location, and endpoint reference endpoints. Configuration permission assignment is now restricted to superusers.
โก (Performance) Reimport matching now builds a run-scoped candidate index, global search splits matching into per-lane index-served queries, and vulnerability IDs gained a case-insensitive index.
๐ ๏ธ (Tools) Added a Fortify parser V2 that prefers the true line number reported by the scanner. Fixed KICS severity mapping.
๐ชฒ (Bug Fixes) Report summary charts now render after the table of contents is rebuilt; connector records are marked STALE when their owner is deleted through an async cascade; non-superusers can view the MCP page while MCP is enabled; a background sub-fetch failure no longer ejects you to the error page on secondary navigation; dropdown filters keep every character you type; an explicit scalar `cwe` stays primary when a `cwes` list is also supplied; API schema generation no longer scopes serializer querysets by `AnonymousUser`.
Check out the full changelog here: docs.defectdojo.com/releases/pro/changelog#โฆ

