From 3ec379a75ae601cd8bc5d084068111956f5d3b03 Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Tue, 29 Sep 2026 13:32:41 +0200 Subject: [PATCH] chore(changelog): v5.44.0 (#12900) Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com> --- api/CHANGELOG.md | 27 +++++++++++++++++++ .../api-key-auth-no-row-lock.fixed.md | 1 - .../attack-paths-tmp-db-reaper.fixed.md | 1 - .../ephemeral-resource-count-reset.fixed.md | 1 - .../latest-scan-null-completed-at.fixed.md | 1 - .../latest-scan-selector.changed.md | 1 - ...ovider-deletion-unconfigured-sink.fixed.md | 1 - .../s3-output-internal-endpoint.added.md | 1 - .../s3-report-download-sigv4.fixed.md | 1 - .../scan-create-task-args.fixed.md | 1 - .../task-revoke-permissions.security.md | 1 - .../worker-logging-restart-policy.fixed.md | 1 - prowler/CHANGELOG.md | 16 +++++++++++ .../aws-retries-max-attempts-env.added.md | 1 - .../aws-sts-reuse-answering-region.fixed.md | 1 - .../ui-e2e-secrets-via-env.security.md | 1 - ui/CHANGELOG.md | 21 +++++++++++++++ .../aws-one-step-connect.changed.md | 1 - ui/changelog.d/bundled-icons-offline.fixed.md | 1 - .../findings-page-streaming.changed.md | 1 - .../first-run-add-provider.changed.md | 1 - .../mute-rule-error-toast-raw-json.fixed.md | 1 - .../provider-connection-check-wait.fixed.md | 1 - .../sidebar-add-provider-action.added.md | 1 - .../sidebar-mode-hydration.fixed.md | 1 - 25 files changed, 64 insertions(+), 22 deletions(-) delete mode 100644 api/changelog.d/api-key-auth-no-row-lock.fixed.md delete mode 100644 api/changelog.d/attack-paths-tmp-db-reaper.fixed.md delete mode 100644 api/changelog.d/ephemeral-resource-count-reset.fixed.md delete mode 100644 api/changelog.d/latest-scan-null-completed-at.fixed.md delete mode 100644 api/changelog.d/latest-scan-selector.changed.md delete mode 100644 api/changelog.d/provider-deletion-unconfigured-sink.fixed.md delete mode 100644 api/changelog.d/s3-output-internal-endpoint.added.md delete mode 100644 api/changelog.d/s3-report-download-sigv4.fixed.md delete mode 100644 api/changelog.d/scan-create-task-args.fixed.md delete mode 100644 api/changelog.d/task-revoke-permissions.security.md delete mode 100644 api/changelog.d/worker-logging-restart-policy.fixed.md delete mode 100644 prowler/changelog.d/aws-retries-max-attempts-env.added.md delete mode 100644 prowler/changelog.d/aws-sts-reuse-answering-region.fixed.md delete mode 100644 prowler/changelog.d/ui-e2e-secrets-via-env.security.md delete mode 100644 ui/changelog.d/aws-one-step-connect.changed.md delete mode 100644 ui/changelog.d/bundled-icons-offline.fixed.md delete mode 100644 ui/changelog.d/findings-page-streaming.changed.md delete mode 100644 ui/changelog.d/first-run-add-provider.changed.md delete mode 100644 ui/changelog.d/mute-rule-error-toast-raw-json.fixed.md delete mode 100644 ui/changelog.d/provider-connection-check-wait.fixed.md delete mode 100644 ui/changelog.d/sidebar-add-provider-action.added.md delete mode 100644 ui/changelog.d/sidebar-mode-hydration.fixed.md diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 1a927baa9c..afd6c2d86d 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -4,6 +4,33 @@ All notable changes to the **Prowler API** are documented in this file. +## [1.45.0] (Prowler v5.44.0) + +### 🚀 Added + +- Scan output uploads and downloads can now target S3-compatible object storage such as MinIO directly via `DJANGO_OUTPUT_S3_AWS_ENDPOINT_URL`, instead of relying on process-wide AWS environment variables that also hijacked unrelated AWS API calls [(#12871)](https://github.com/prowler-cloud/prowler/pull/12871) + +### 🔄 Changed + +- Unify how every endpoint resolves a provider latest completed scan, so overlapping scans no longer make findings, compliance and mute rules read from different scans [(#12858)](https://github.com/prowler-cloud/prowler/pull/12858) + +### 🐞 Fixed + +- Celery loggers are now declared explicitly in `custom_logging.py` so fatal worker errors are no longer silenced by `disable_existing_loggers=True`. All long-running services in `docker-compose.yml` now have `restart: unless-stopped` so containers recover automatically after unexpected crashes. [(#12465)](https://github.com/prowler-cloud/prowler/pull/12465) +- Scan report downloads from an S3 bucket with default SSE-KMS encryption no longer fail with an `InvalidArgument` error: when `DJANGO_OUTPUT_S3_AWS_DEFAULT_REGION` is set, presigned download URLs are signed with AWS Signature Version 4 for that region [(#12746)](https://github.com/prowler-cloud/prowler/pull/12746) +- Adds a periodic sweep that drops orphaned Attack Paths temp Neo4j scan databases left behind when a worker or Neo4j crashes mid-scan, before they accumulate unbounded [(#12832)](https://github.com/prowler-cloud/prowler/pull/12832) +- Providers whose most recent completed scan has no `completed_at` timestamp are no longer missing from every endpoint that reports a provider's latest scan, which now falls back to scan creation order instead of skipping the provider [(#12858)](https://github.com/prowler-cloud/prowler/pull/12858) +- Resources no longer keep a stale failed findings count forever when a scoped or imported scan for the same provider completes after a full scan, which used to make the full scan skip its own cleanup [(#12858)](https://github.com/prowler-cloud/prowler/pull/12858) +- `POST /api/v1/scans` again returns the new scan id in the response `task_args`, which had been empty since the scan broker publish moved to transaction commit [(#12878)](https://github.com/prowler-cloud/prowler/pull/12878) +- API key authentication no longer locks the key row on every request and now throttles `last_used_at` updates to once per 60 seconds, preventing a hot key from serializing all its requests onto a single locked row [(#12882)](https://github.com/prowler-cloud/prowler/pull/12882) +- Provider deletion no longer fails when the provider has Attack Paths scans recorded on a sink that is no longer configured, such as Neptune after moving back to Neo4j [(#12894)](https://github.com/prowler-cloud/prowler/pull/12894) + +### 🔐 Security + +- `DELETE /api/v1/tasks/{id}` requires the permission of the operation that queued the task and rejects provider deletions, and `GET /api/v1/tasks` hides tasks of providers outside the visibility of the role [(#12893)](https://github.com/prowler-cloud/prowler/pull/12893) + +--- + ## [1.44.0] (Prowler v5.43.0) ### 🐞 Fixed diff --git a/api/changelog.d/api-key-auth-no-row-lock.fixed.md b/api/changelog.d/api-key-auth-no-row-lock.fixed.md deleted file mode 100644 index 3d0a40260c..0000000000 --- a/api/changelog.d/api-key-auth-no-row-lock.fixed.md +++ /dev/null @@ -1 +0,0 @@ -API key authentication no longer locks the key row on every request and now throttles `last_used_at` updates to once per 60 seconds, preventing a hot key from serializing all its requests onto a single locked row diff --git a/api/changelog.d/attack-paths-tmp-db-reaper.fixed.md b/api/changelog.d/attack-paths-tmp-db-reaper.fixed.md deleted file mode 100644 index b165fc6d40..0000000000 --- a/api/changelog.d/attack-paths-tmp-db-reaper.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Adds a periodic sweep that drops orphaned Attack Paths temp Neo4j scan databases left behind when a worker or Neo4j crashes mid-scan, before they accumulate unbounded diff --git a/api/changelog.d/ephemeral-resource-count-reset.fixed.md b/api/changelog.d/ephemeral-resource-count-reset.fixed.md deleted file mode 100644 index 0c56ae2e5d..0000000000 --- a/api/changelog.d/ephemeral-resource-count-reset.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Resources no longer keep a stale failed findings count forever when a scoped or imported scan for the same provider completes after a full scan, which used to make the full scan skip its own cleanup diff --git a/api/changelog.d/latest-scan-null-completed-at.fixed.md b/api/changelog.d/latest-scan-null-completed-at.fixed.md deleted file mode 100644 index 9932210055..0000000000 --- a/api/changelog.d/latest-scan-null-completed-at.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Providers whose most recent completed scan has no `completed_at` timestamp are no longer missing from every endpoint that reports a provider's latest scan, which now falls back to scan creation order instead of skipping the provider diff --git a/api/changelog.d/latest-scan-selector.changed.md b/api/changelog.d/latest-scan-selector.changed.md deleted file mode 100644 index 417cf9e997..0000000000 --- a/api/changelog.d/latest-scan-selector.changed.md +++ /dev/null @@ -1 +0,0 @@ -Unify how every endpoint resolves a provider latest completed scan, so overlapping scans no longer make findings, compliance and mute rules read from different scans diff --git a/api/changelog.d/provider-deletion-unconfigured-sink.fixed.md b/api/changelog.d/provider-deletion-unconfigured-sink.fixed.md deleted file mode 100644 index 93f5e2bc73..0000000000 --- a/api/changelog.d/provider-deletion-unconfigured-sink.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Provider deletion no longer fails when the provider has Attack Paths scans recorded on a sink that is no longer configured, such as Neptune after moving back to Neo4j diff --git a/api/changelog.d/s3-output-internal-endpoint.added.md b/api/changelog.d/s3-output-internal-endpoint.added.md deleted file mode 100644 index 88159f1ef8..0000000000 --- a/api/changelog.d/s3-output-internal-endpoint.added.md +++ /dev/null @@ -1 +0,0 @@ -Scan output uploads and downloads can now target S3-compatible object storage such as MinIO directly via `DJANGO_OUTPUT_S3_AWS_ENDPOINT_URL`, instead of relying on process-wide AWS environment variables that also hijacked unrelated AWS API calls diff --git a/api/changelog.d/s3-report-download-sigv4.fixed.md b/api/changelog.d/s3-report-download-sigv4.fixed.md deleted file mode 100644 index 7c11870c11..0000000000 --- a/api/changelog.d/s3-report-download-sigv4.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Scan report downloads from an S3 bucket with default SSE-KMS encryption no longer fail with an `InvalidArgument` error: when `DJANGO_OUTPUT_S3_AWS_DEFAULT_REGION` is set, presigned download URLs are signed with AWS Signature Version 4 for that region diff --git a/api/changelog.d/scan-create-task-args.fixed.md b/api/changelog.d/scan-create-task-args.fixed.md deleted file mode 100644 index 26d42cf0c4..0000000000 --- a/api/changelog.d/scan-create-task-args.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`POST /api/v1/scans` again returns the new scan id in the response `task_args`, which had been empty since the scan broker publish moved to transaction commit diff --git a/api/changelog.d/task-revoke-permissions.security.md b/api/changelog.d/task-revoke-permissions.security.md deleted file mode 100644 index 2497621e99..0000000000 --- a/api/changelog.d/task-revoke-permissions.security.md +++ /dev/null @@ -1 +0,0 @@ -`DELETE /api/v1/tasks/{id}` requires the permission of the operation that queued the task and rejects provider deletions, and `GET /api/v1/tasks` hides tasks of providers outside the visibility of the role diff --git a/api/changelog.d/worker-logging-restart-policy.fixed.md b/api/changelog.d/worker-logging-restart-policy.fixed.md deleted file mode 100644 index dad995fdd9..0000000000 --- a/api/changelog.d/worker-logging-restart-policy.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Celery loggers are now declared explicitly in `custom_logging.py` so fatal worker errors are no longer silenced by `disable_existing_loggers=True`. All long-running services in `docker-compose.yml` now have `restart: unless-stopped` so containers recover automatically after unexpected crashes. diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 3a7bc157bf..d424abdd01 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -4,6 +4,22 @@ All notable changes to the **Prowler SDK** are documented in this file. +## [5.44.0] (Prowler v5.44.0) + +### 🚀 Added + +- `PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTS` environment variable to set the Boto3 retries for deployments without CLI flags [(#12870)](https://github.com/prowler-cloud/prowler/pull/12870) + +### 🐞 Fixed + +- STS calls after role assumption use the answering region, avoiding a second wait for an unreachable partition region [(#12870)](https://github.com/prowler-cloud/prowler/pull/12870) + +### 🔐 Security + +- Pass the E2E AWS credentials to the UI E2E workflow through environment variables instead of template expansion [(#12864)](https://github.com/prowler-cloud/prowler/pull/12864) + +--- + ## [5.43.0] (Prowler v5.43.0) ### 🚀 Added diff --git a/prowler/changelog.d/aws-retries-max-attempts-env.added.md b/prowler/changelog.d/aws-retries-max-attempts-env.added.md deleted file mode 100644 index d88cc59507..0000000000 --- a/prowler/changelog.d/aws-retries-max-attempts-env.added.md +++ /dev/null @@ -1 +0,0 @@ -`PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTS` environment variable to set the Boto3 retries for deployments without CLI flags diff --git a/prowler/changelog.d/aws-sts-reuse-answering-region.fixed.md b/prowler/changelog.d/aws-sts-reuse-answering-region.fixed.md deleted file mode 100644 index 431426522a..0000000000 --- a/prowler/changelog.d/aws-sts-reuse-answering-region.fixed.md +++ /dev/null @@ -1 +0,0 @@ -STS calls after role assumption use the answering region, avoiding a second wait for an unreachable partition region diff --git a/prowler/changelog.d/ui-e2e-secrets-via-env.security.md b/prowler/changelog.d/ui-e2e-secrets-via-env.security.md deleted file mode 100644 index 476f690e3c..0000000000 --- a/prowler/changelog.d/ui-e2e-secrets-via-env.security.md +++ /dev/null @@ -1 +0,0 @@ -Pass the E2E AWS credentials to the UI E2E workflow through environment variables instead of template expansion diff --git a/ui/CHANGELOG.md b/ui/CHANGELOG.md index 9ea71d69e9..5d62b9da6f 100644 --- a/ui/CHANGELOG.md +++ b/ui/CHANGELOG.md @@ -4,6 +4,27 @@ All notable changes to the **Prowler UI** are documented in this file. +## [1.44.0] (Prowler v5.44.0) + +### 🚀 Added + +- Sidebar action reads Add Provider while the tenant has no providers [(#12852)](https://github.com/prowler-cloud/prowler/pull/12852) + +### 🔄 Changed + +- AWS accounts are connected in a single wizard step: the account is read from the role ARN, or typed for access keys, the role is assumed with Prowler's own credentials, and the credentials are stored and tested with the account [(#12852)](https://github.com/prowler-cloud/prowler/pull/12852) +- New tenants without providers land on the Add Provider wizard on first sign-in instead of a welcome modal [(#12852)](https://github.com/prowler-cloud/prowler/pull/12852) +- Findings page paints a skeleton at once and streams the table before the filters; the "Finding Group" options load in a single request when the dropdown opens [(#12891)](https://github.com/prowler-cloud/prowler/pull/12891) + +### 🐞 Fixed + +- Mute rule creation errors show the API error message instead of the raw JSON:API response body [(#12853)](https://github.com/prowler-cloud/prowler/pull/12853) +- Provider connection test no longer reports `Max retries exceeded` for checks that take longer than 30 seconds, such as networks where some AWS endpoints are unreachable; the wait now covers the backend task's full time limit and falls back to the provider's current connection state if it is still exhausted [(#12869)](https://github.com/prowler-cloud/prowler/pull/12869) +- Sidebar no longer throws a React hydration error on full page loads for users who last used the chat mode [(#12873)](https://github.com/prowler-cloud/prowler/pull/12873) +- Icons now ship in the UI bundle instead of being fetched from `api.iconify.design`, so pages render correctly in air-gapped deployments [(#12892)](https://github.com/prowler-cloud/prowler/pull/12892) + +--- + ## [1.43.0] (Prowler v5.43.0) ### 🚀 Added diff --git a/ui/changelog.d/aws-one-step-connect.changed.md b/ui/changelog.d/aws-one-step-connect.changed.md deleted file mode 100644 index 924f32b1bb..0000000000 --- a/ui/changelog.d/aws-one-step-connect.changed.md +++ /dev/null @@ -1 +0,0 @@ -AWS accounts are connected in a single wizard step: the account is read from the role ARN, or typed for access keys, the role is assumed with Prowler's own credentials, and the credentials are stored and tested with the account diff --git a/ui/changelog.d/bundled-icons-offline.fixed.md b/ui/changelog.d/bundled-icons-offline.fixed.md deleted file mode 100644 index 52bfe6d1c6..0000000000 --- a/ui/changelog.d/bundled-icons-offline.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Icons now ship in the UI bundle instead of being fetched from `api.iconify.design`, so pages render correctly in air-gapped deployments diff --git a/ui/changelog.d/findings-page-streaming.changed.md b/ui/changelog.d/findings-page-streaming.changed.md deleted file mode 100644 index ea82b76707..0000000000 --- a/ui/changelog.d/findings-page-streaming.changed.md +++ /dev/null @@ -1 +0,0 @@ -Findings page paints a skeleton at once and streams the table before the filters; the "Finding Group" options load in a single request when the dropdown opens diff --git a/ui/changelog.d/first-run-add-provider.changed.md b/ui/changelog.d/first-run-add-provider.changed.md deleted file mode 100644 index a40ae414e3..0000000000 --- a/ui/changelog.d/first-run-add-provider.changed.md +++ /dev/null @@ -1 +0,0 @@ -New tenants without providers land on the Add Provider wizard on first sign-in instead of a welcome modal diff --git a/ui/changelog.d/mute-rule-error-toast-raw-json.fixed.md b/ui/changelog.d/mute-rule-error-toast-raw-json.fixed.md deleted file mode 100644 index d59b218727..0000000000 --- a/ui/changelog.d/mute-rule-error-toast-raw-json.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Mute rule creation errors show the API error message instead of the raw JSON:API response body diff --git a/ui/changelog.d/provider-connection-check-wait.fixed.md b/ui/changelog.d/provider-connection-check-wait.fixed.md deleted file mode 100644 index 779efa5e74..0000000000 --- a/ui/changelog.d/provider-connection-check-wait.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Provider connection test no longer reports `Max retries exceeded` for checks that take longer than 30 seconds, such as networks where some AWS endpoints are unreachable; the wait now covers the backend task's full time limit and falls back to the provider's current connection state if it is still exhausted diff --git a/ui/changelog.d/sidebar-add-provider-action.added.md b/ui/changelog.d/sidebar-add-provider-action.added.md deleted file mode 100644 index 29cc8aec45..0000000000 --- a/ui/changelog.d/sidebar-add-provider-action.added.md +++ /dev/null @@ -1 +0,0 @@ -Sidebar action reads Add Provider while the tenant has no providers diff --git a/ui/changelog.d/sidebar-mode-hydration.fixed.md b/ui/changelog.d/sidebar-mode-hydration.fixed.md deleted file mode 100644 index c495c3071d..0000000000 --- a/ui/changelog.d/sidebar-mode-hydration.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Sidebar no longer throws a React hydration error on full page loads for users who last used the chat mode