diff --git a/.env b/.env index f1bf980b5b..f06fa10e4a 100644 --- a/.env +++ b/.env @@ -158,7 +158,7 @@ SENTRY_RELEASE=local # REO_DEV_CLIENT_ID= #### Prowler release version #### -NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.41.0 +NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.41.1 # Social login credentials SOCIAL_GOOGLE_OAUTH_CALLBACK_URL="${AUTH_URL}/api/auth/callback/google" diff --git a/.grype.yaml b/.grype.yaml index 8fe74513c9..17a3c8474b 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -17,6 +17,16 @@ ignore: - vulnerability: CVE-2026-71556 package: name: github.com/go-git/go-git/v5 + # CVE-2026-84304 is the same temporary exception documented in .trivyignore.yaml: + # Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.83.1 fix is not in any release. + # Prowler only runs `trivy image` / `trivy fs`, never client/server mode, so no gRPC + # endpoint exists in the image. Pinned to the embedded version so the rule stops + # matching on its own once Trivy bumps grpc. Remove with the Trivy exception by 2026-10-15. + # https://github.com/aquasecurity/trivy/pull/11176 + - vulnerability: CVE-2026-84304 + package: + name: google.golang.org/grpc + version: v1.82.1 - vulnerability: CVE-2026-56852 package: name: golang.org/x/text diff --git a/.trivyignore.yaml b/.trivyignore.yaml index b78162ecc4..23fd083b46 100644 --- a/.trivyignore.yaml +++ b/.trivyignore.yaml @@ -113,6 +113,18 @@ vulnerabilities: purls: - "pkg:npm/fast-uri" expired_at: 2027-01-31 + - id: CVE-2026-75899 + purls: + - "pkg:npm/fast-uri" + expired_at: 2027-01-31 + - id: CVE-2026-75975 + purls: + - "pkg:npm/fast-uri" + expired_at: 2027-01-31 + - id: CVE-2026-76172 + purls: + - "pkg:npm/fast-uri" + expired_at: 2027-01-31 - id: CVE-2026-69192 purls: - "pkg:npm/ip-address" @@ -148,6 +160,22 @@ vulnerabilities: - "pkg:golang/github.com/go-git/go-git/v5" expired_at: 2026-09-15 + # CVE-2026-84304 is a DoS in grpc-go <= 1.83.0: a peer fragments a gRPC stream into + # millions of tiny HTTP/2 DATA frames until the receiver runs out of heap. Fixed in + # 1.83.1 (published 2026-09-01). Trivy 0.74.0, the latest published release and the + # version the images ship, pins 1.82.1 as an indirect dependency: + # https://github.com/aquasecurity/trivy/blob/v0.74.0/go.mod + # Upstream bump still open: https://github.com/aquasecurity/trivy/pull/11176 + # Trivy only speaks gRPC in client/server mode (`trivy server`, `--server`). Prowler + # invokes it exclusively as `trivy image` and `trivy fs` on a local path, so no gRPC + # listener or connection ever exists in the image and the affected path is not + # reachable. Remove this temporary suppression as soon as a Trivy release pins + # grpc >= 1.83.1. + - id: CVE-2026-84304 + purls: + - "pkg:golang/google.golang.org/grpc" + expired_at: 2026-10-15 + - id: CVE-2026-56852 purls: - "pkg:golang/golang.org/x/text" diff --git a/api/pyproject.toml b/api/pyproject.toml index 34df1a0aaf..4f66d7676b 100644 --- a/api/pyproject.toml +++ b/api/pyproject.toml @@ -71,7 +71,7 @@ name = "prowler-api" package-mode = false # Needed for the SDK compatibility requires-python = ">=3.11,<3.13" -version = "1.42.0" +version = "1.42.1" # Shared ruff baseline (kept in sync with mcp_server/pyproject.toml). # target-version tracks this project's lowest supported Python. diff --git a/api/src/backend/api/specs/v1.yaml b/api/src/backend/api/specs/v1.yaml index 9c321bdf13..d2a7595ba0 100644 --- a/api/src/backend/api/specs/v1.yaml +++ b/api/src/backend/api/specs/v1.yaml @@ -1,7 +1,7 @@ openapi: 3.0.3 info: title: Prowler API - version: 1.42.0 + version: 1.42.1 description: |- Prowler API specification. diff --git a/api/uv.lock b/api/uv.lock index 2434fbb4dd..a70760fbd3 100644 --- a/api/uv.lock +++ b/api/uv.lock @@ -4938,7 +4938,7 @@ dependencies = [ [[package]] name = "prowler-api" -version = "1.42.0" +version = "1.42.1" source = { virtual = "." } dependencies = [ { name = "cartography" }, diff --git a/prowler/config/config.py b/prowler/config/config.py index 1c0ae406cc..ce011b31c5 100644 --- a/prowler/config/config.py +++ b/prowler/config/config.py @@ -52,7 +52,7 @@ class _MutableTimestamp: timestamp = _MutableTimestamp(datetime.today()) timestamp_utc = _MutableTimestamp(datetime.now(timezone.utc)) -prowler_version = "5.41.0" +prowler_version = "5.41.1" html_logo_url = "https://github.com/prowler-cloud/prowler/" square_logo_img = "https://raw.githubusercontent.com/prowler-cloud/prowler/dc7d2d5aeb92fdf12e8604f42ef6472cd3e8e889/docs/img/prowler-logo-black.png" aws_logo = "https://user-images.githubusercontent.com/38561120/235953920-3e3fba08-0795-41dc-b480-9bea57db9f2e.png" diff --git a/pyproject.toml b/pyproject.toml index 12c599420d..01968967f3 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -143,7 +143,7 @@ maintainers = [{name = "Prowler Engineering", email = "engineering@prowler.com"} name = "prowler" readme = "README.md" requires-python = ">=3.10,<3.14" -version = "5.41.0" +version = "5.41.1" [project.scripts] prowler = "prowler.__main__:prowler" diff --git a/uv.lock b/uv.lock index ea51810322..c57526ff03 100644 --- a/uv.lock +++ b/uv.lock @@ -3752,7 +3752,7 @@ wheels = [ [[package]] name = "prowler" -version = "5.41.0" +version = "5.41.1" source = { editable = "." } dependencies = [ { name = "alibabacloud-actiontrail20200706" },