Skip to content

update regulations form - #15694

Merged
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
paulOsinski:regs
Aug 17, 2026
Merged

update regulations form#15694
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
paulOsinski:regs

Conversation

@paulOsinski

Copy link
Copy Markdown
Contributor
Screenshot 2026-08-17 at 4 02 37 PM

On the Add/Edit Asset form, the Regulations field is now a searchable multi-select: type to filter (e.g. "pci") and each chosen regulation appears as a removable tag with an ×, making it obvious you can pick several.

Previously it was an unclear widget — a plain listbox or a "Nothing selected" dropdown depending on the UI, which gave no hint multiple selections were possible.

@paulOsinski paulOsinski added this to the 3.2.300 milestone Aug 17, 2026
@github-actions github-actions Bot added the ui label Aug 17, 2026
@dryrunsecurity

Copy link
Copy Markdown

DryRun Security

This pull request contains two critical findings where user 'paulOsinski' modified sensitive HTML template files without being on the allowed authors list. Specifically, the files 'edit_product.html' and 'new_product.html' were altered in violation of the configured sensitive codepath policies.

🔴 Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/edit_product.html (drs_fb90370a)
Vulnerability Configured Sensitive Codepath Modified by Non-Allowed Author
Description File 'dojo/templates/dojo/edit_product.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'paulOsinski' (commit 1b29596) who is not in the allowed authors list.
🔴 Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/templates/dojo/new_product.html (drs_961bfe58)
Vulnerability Configured Sensitive Codepath Modified by Non-Allowed Author
Description File 'dojo/templates/dojo/new_product.html' matches configured sensitive codepath pattern 'dojo/templates/**/*.html' and was modified by 'paulOsinski' (commit 1b29596) who is not in the allowed authors list.

We've notified @mtesauro.


Comment to provide feedback on these findings.

Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]

Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing

All finding details can be found in the DryRun Security Dashboard.

@Maffooch
Maffooch added this pull request to the merge queue Aug 17, 2026
Merged via the queue into DefectDojo:bugfix with commit 9828ff8 Aug 17, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants