Resources hub

Learn from people who do the work.

Practitioner writing, live training and real customer detail.

Not vendor content marketing. Everything here is written or recorded by people who run vulnerability management for a living.

Getting startedInstall / Import / Join

Getting started with DefectDojo

New to DefectDojo? Start with the guides that take you from your first scan import to a prioritized, deduplicated queue.

1

Install the Community Edition

Clone the repository and run the stack locally. The open source edition is the same core engine, with the parsers and the deduplication model included.

Get it on GitHub
2

Import your first scan

Point a scanner report at DefectDojo and watch it normalize. The docs cover every supported parser and the exact report format each one expects.

Read the docs
3

Join the community

Ask questions, follow the release notes, and see what other teams are running. The Slack workspace and the release feed are both open.

Go to community
Case studies01 on record

Proof, not personas

We only publish what customers put on record. Named teams, measured results, and the part of the program that actually changed.

Events37 sessions / recordings ungated

What is coming up

Live training, monthly office hours, and conference talks. If you miss one, the recording goes up without a gate.

August 2026
Mon Tue Wed Thu Fri Sat Sun 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Scheduled sessionToday

A Slack where people actually answer.

The maintainers are in there. So are the people running Dojo across 10,000 organizations. Ask a real question, get a real answer.

The roadmap, the issues, and every release note live in the open on GitHub. Nothing about how this gets built is a surprise.