Skip to content

Conversation

@skywalke34
Copy link
Contributor

Description
documentation update: Clarifying the differences between DefectDojo Pro and Open Source for cross-product risk acceptances. Specifically, Pro supports CVE-level risk acceptance across products while OSS only provides for product-level risk acceptances.

@valentijnscholten valentijnscholten added this to the 2.53.0 milestone Nov 13, 2025
* **Cross-Product Risk Acceptances**: In DefectDojo Pro, you can apply a single Risk Acceptance across multiple Products. For example, if CVE-2024-1234 appears in 10 different products, you can create one Risk Acceptance that governs all instances of that CVE across your entire portfolio.
* **Bulk CVE Management**: Search for all Findings with a specific CVE or vulnerability ID, then apply a Risk Acceptance to all instances simultaneously, regardless of which Product they belong to.

**DefectDojo Open Source** implements Risk Acceptances at the Product level:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In OS the risk acceptances are at Engagement level.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm the one that misspoke to @skywalke34 and told him it was Product level but, yeah, it's engagement level in Open Source.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wanted to extend it to the Product level, but I have received no feedback about it #12361 (comment)

So, do you agree to redo to the product level?

Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

Assuming @skywalke34 addresses the requested changes from @valentijnscholten

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants