Replies: 1 comment 1 reply
-
|
Has there been any discussion on considering a modern UI framework familiar to the community like React or Svelte? Also I know a lot of the architecture is heavily opininated based on Django design. But its a discussion worth having given how resource heavy the Django app has become. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Welcome to the end of the year and boy what a year it's been!
I did a ton of changelog reading and talked to the maintainers and below is the summary of that work.
If you don't want to read the below (or use an AI to summarize it), there's also a video of the latest Office Hours that's a review of both Pro and Community DefectDojo at https://www.youtube.com/watch?v=WVw4BwUMi1U.
2025 in Review
Beyond the normal care and feeding we give DefectDojo, we had some notable updates which I want to make note of below.
Before I go there, two themes came out of my look backwards on this year:
Both of the efforts move us closer to the mythical 3.0 (more on that later).
Noteworthy optimizations and improvements to DefectDojo's core:
Chord#12914Streamlining workflows and other improvements:
/import//reimportwere not being identified as duplicates.tags__andAPI filter.In flight items
DefectDojo 3.0
So, the project with great excitement and anticipation spoke of DefectDojo 3.0 a while ago. This wasn't some bait and switch tactic. Rather, it was the project letting the community know our aspirations for DefectDojo.
We started the 3.0 discussion knowing that there was a long list of unknown unknowns that were between us and 3.0. We've spent the bulk of this year finding and making known (by addressing them) all those unknown unknowns. Most of the work above in the "Noteworthy optimizations..." section above was really 3.0 work just not explicitly labeled that way.
So, what's the timeline for 3.0?
The project has taken inspiration from the Debian community and is following their lead: DefectDojo 3.0 will happen when its ready but not before. We don't see any value in putting an artificial timeline that we can't really know we can meet.
We'll spend 2026 addressing anything that blocks our progress towards 3.0 while doing what we've done for years:
To the wonderful DefectDojo Community: Have a great rest of 2025 and a fantastic 2026!
That's what we're planning for DefectDojo 🚀
Beta Was this translation helpful? Give feedback.
All reactions