diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 0ab4c9bfe1..318cd30d4f 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -4,6 +4,14 @@ All notable changes to the **Prowler API** are documented in this file. +## [1.43.0] (Prowler v5.42.0) + +### 🔄 Changed + +- Speed up compliance overview ingestion by reading ThreatScore mappings from the compliance template instead of each finding, generating time-ordered `uuid7` row ids and grouping inserted rows by framework and requirement [(#12738)](https://github.com/prowler-cloud/prowler/pull/12738) + +--- + ## [1.42.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/api/changelog.d/compliance-overviews-ingest-perf.changed.md b/api/changelog.d/compliance-overviews-ingest-perf.changed.md deleted file mode 100644 index 6e833d184e..0000000000 --- a/api/changelog.d/compliance-overviews-ingest-perf.changed.md +++ /dev/null @@ -1 +0,0 @@ -Speed up compliance overview ingestion by reading ThreatScore mappings from the compliance template instead of each finding, generating time-ordered `uuid7` row ids and grouping inserted rows by framework and requirement diff --git a/mcp_server/CHANGELOG.md b/mcp_server/CHANGELOG.md index 4c6c858d28..80bdabd28a 100644 --- a/mcp_server/CHANGELOG.md +++ b/mcp_server/CHANGELOG.md @@ -4,6 +4,14 @@ All notable changes to the **Prowler MCP Server** are documented in this file. +## [0.12.1] (Prowler v5.42.0) + +### 🔐 Security + +- `libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410 [(#12780)](https://github.com/prowler-cloud/prowler/pull/12780) + +--- + ## [0.12.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md b/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md deleted file mode 100644 index 602458c777..0000000000 --- a/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410 diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 4161d195b8..7232bd41a0 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -4,6 +4,33 @@ All notable changes to the **Prowler SDK** are documented in this file. +## [5.42.0] (Prowler v5.42.0) + +### 🚀 Added + +- AWS ISO partitions (`aws-iso`, `aws-iso-b`, `aws-iso-e` and `aws-iso-f`) to the AWS service region matrix, generated from the endpoints data bundled with botocore [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- `--aws-connect-timeout` and `--aws-read-timeout` CLI flags, plus `PROWLER_AWS_BOTO3_CONNECT_TIMEOUT` and `PROWLER_AWS_BOTO3_READ_TIMEOUT` environment variables, to bound how long each AWS API call waits for an endpoint [(#12774)](https://github.com/prowler-cloud/prowler/pull/12774) + +### 🔄 Changed + +- AWS provider default Boto3 connect timeout lowered from 60 to 10 seconds, so scans in restricted-egress networks (VPC endpoints for a subset of services, GovCloud, private deployments) no longer spend 4 minutes per region on every service whose endpoint is unreachable [(#12774)](https://github.com/prowler-cloud/prowler/pull/12774) + +### 🐞 Fixed + +- Duplicate requirement ids, checks listed twice in a requirement and references to non-existent checks across compliance frameworks, now guarded by a catalog integrity test [(#12717)](https://github.com/prowler-cloud/prowler/pull/12717) +- Duplicate requirement `3.2.1` in ProwlerThreatScore for Azure (SQL auditing retention is now `3.2.4`) and doubled check id in requirement `1.2.1` of ProwlerThreatScore for GCP [(#12717)](https://github.com/prowler-cloud/prowler/pull/12717) +- Jira connection checks no longer log an error when a single project has no issue types visible to the integration user (typically a missing "create issue" permission on that project), a case the caller already treats as non-fatal [(#12742)](https://github.com/prowler-cloud/prowler/pull/12742) +- `Jira.test_connection()` now fetches each project's issue types concurrently instead of one request at a time, so accounts with many Jira projects no longer take tens of seconds (unbounded, scaling with the project count) to verify the connection [(#12742)](https://github.com/prowler-cloud/prowler/pull/12742) +- `AwsProvider.get_available_aws_service_regions()` now returns an empty set for an unknown service or partition instead of raising `KeyError`, so a service unavailable in the audited partition is skipped [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- `AwsProvider.generate_regional_clients()` now returns an empty dict instead of `None` when the regional clients cannot be built, a failure that surfaced later as `AttributeError: 'NoneType' object has no attribute 'values'` [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- `AwsProvider.get_global_region()` now returns a real region for each ISO partition instead of the `aws-iso-global` pseudo endpoint, which collapsed the four partitions into one answer [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- Bootstrap STS calls now use the session region when `PROWLER_AWS_PARTITION` is set and the region belongs to that partition, instead of always going to the partition's global STS region, which a deployment reached only through its own region's VPC endpoints cannot route to [(#12764)](https://github.com/prowler-cloud/prowler/pull/12764) +- The Image provider now uses the directory named by `TRIVY_CACHE_DIR` when one is set, instead of a fresh temporary directory it deletes afterwards, so a deployment can supply a vulnerability database it already holds and one with network access stops re-downloading the database for every image it scans [(#12773)](https://github.com/prowler-cloud/prowler/pull/12773) +- `--aws-retries-max-attempts 0` now disables Boto3 retries instead of being silently ignored in favour of the default of 3 [(#12774)](https://github.com/prowler-cloud/prowler/pull/12774) +- `rolesanywhere_profile_restricts_session_permissions`, `iam_role_service_trust_restricts_source_to_account` and `codebuild_project_uses_allowed_github_organizations` crashing with `TypeError` when `iam:ListRoles` is denied [(#12785)](https://github.com/prowler-cloud/prowler/pull/12785) + +--- + ## [5.41.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md b/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md deleted file mode 100644 index a204443b2a..0000000000 --- a/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md +++ /dev/null @@ -1 +0,0 @@ -AWS provider default Boto3 connect timeout lowered from 60 to 10 seconds, so scans in restricted-egress networks (VPC endpoints for a subset of services, GovCloud, private deployments) no longer spend 4 minutes per region on every service whose endpoint is unreachable diff --git a/prowler/changelog.d/aws-boto3-timeouts.added.md b/prowler/changelog.d/aws-boto3-timeouts.added.md deleted file mode 100644 index df5d6e4f2b..0000000000 --- a/prowler/changelog.d/aws-boto3-timeouts.added.md +++ /dev/null @@ -1 +0,0 @@ -`--aws-connect-timeout` and `--aws-read-timeout` CLI flags, plus `PROWLER_AWS_BOTO3_CONNECT_TIMEOUT` and `PROWLER_AWS_BOTO3_READ_TIMEOUT` environment variables, to bound how long each AWS API call waits for an endpoint diff --git a/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md b/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md deleted file mode 100644 index dc24ad1b49..0000000000 --- a/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`rolesanywhere_profile_restricts_session_permissions`, `iam_role_service_trust_restricts_source_to_account` and `codebuild_project_uses_allowed_github_organizations` crashing with `TypeError` when `iam:ListRoles` is denied diff --git a/prowler/changelog.d/aws-iso-partitions.added.md b/prowler/changelog.d/aws-iso-partitions.added.md deleted file mode 100644 index 41282ea353..0000000000 --- a/prowler/changelog.d/aws-iso-partitions.added.md +++ /dev/null @@ -1 +0,0 @@ -AWS ISO partitions (`aws-iso`, `aws-iso-b`, `aws-iso-e` and `aws-iso-f`) to the AWS service region matrix, generated from the endpoints data bundled with botocore diff --git a/prowler/changelog.d/aws-iso-partitions.fixed.md b/prowler/changelog.d/aws-iso-partitions.fixed.md deleted file mode 100644 index c3424d51ba..0000000000 --- a/prowler/changelog.d/aws-iso-partitions.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`AwsProvider.get_global_region()` now returns a real region for each ISO partition instead of the `aws-iso-global` pseudo endpoint, which collapsed the four partitions into one answer diff --git a/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md b/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md deleted file mode 100644 index 93a6c8d7b1..0000000000 --- a/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Bootstrap STS calls now use the session region when `PROWLER_AWS_PARTITION` is set and the region belongs to that partition, instead of always going to the partition's global STS region, which a deployment reached only through its own region's VPC endpoints cannot route to diff --git a/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md b/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md deleted file mode 100644 index bd5f7798ac..0000000000 --- a/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`AwsProvider.generate_regional_clients()` now returns an empty dict instead of `None` when the regional clients cannot be built, a failure that surfaced later as `AttributeError: 'NoneType' object has no attribute 'values'` diff --git a/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md b/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md deleted file mode 100644 index 8eb2ad9e07..0000000000 --- a/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`--aws-retries-max-attempts 0` now disables Boto3 retries instead of being silently ignored in favour of the default of 3 diff --git a/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md b/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md deleted file mode 100644 index 881ce2c94b..0000000000 --- a/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`AwsProvider.get_available_aws_service_regions()` now returns an empty set for an unknown service or partition instead of raising `KeyError`, so a service unavailable in the audited partition is skipped diff --git a/prowler/changelog.d/compliance-catalog-integrity.fixed.md b/prowler/changelog.d/compliance-catalog-integrity.fixed.md deleted file mode 100644 index 1bfcf0462c..0000000000 --- a/prowler/changelog.d/compliance-catalog-integrity.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Duplicate requirement ids, checks listed twice in a requirement and references to non-existent checks across compliance frameworks, now guarded by a catalog integrity test diff --git a/prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md b/prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md deleted file mode 100644 index 85d3bad72a..0000000000 --- a/prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`Jira.test_connection()` now fetches each project's issue types concurrently instead of one request at a time, so accounts with many Jira projects no longer take tens of seconds (unbounded, scaling with the project count) to verify the connection diff --git a/prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md b/prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md deleted file mode 100644 index 0d0a1f5477..0000000000 --- a/prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Jira connection checks no longer log an error when a single project has no issue types visible to the integration user (typically a missing "create issue" permission on that project), a case the caller already treats as non-fatal diff --git a/prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md b/prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md deleted file mode 100644 index 0fb7547adb..0000000000 --- a/prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Duplicate requirement `3.2.1` in ProwlerThreatScore for Azure (SQL auditing retention is now `3.2.4`) and doubled check id in requirement `1.2.1` of ProwlerThreatScore for GCP diff --git a/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md b/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md deleted file mode 100644 index fd2f0ca117..0000000000 --- a/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md +++ /dev/null @@ -1 +0,0 @@ -The Image provider now uses the directory named by `TRIVY_CACHE_DIR` when one is set, instead of a fresh temporary directory it deletes afterwards, so a deployment can supply a vulnerability database it already holds and one with network access stops re-downloading the database for every image it scans diff --git a/ui/CHANGELOG.md b/ui/CHANGELOG.md index eeadba64b8..8687ddde54 100644 --- a/ui/CHANGELOG.md +++ b/ui/CHANGELOG.md @@ -4,6 +4,26 @@ All notable changes to the **Prowler UI** are documented in this file. +## [1.42.0] (Prowler v5.42.0) + +### 🚀 Added + +- PostHog Toolbar support in development with separate ingestion and app hosts [(#12582)](https://github.com/prowler-cloud/prowler/pull/12582) + +### 🐞 Fixed + +- Scan Jobs onboarding tour no longer targets an unmounted In Progress row from other tabs [(#12705)](https://github.com/prowler-cloud/prowler/pull/12705) +- Integration connection test polling now waits up to ~3 minutes instead of ~57 seconds before giving up, so it no longer reports a false failure on slower checks (e.g. Jira accounts with many projects) that were still going to succeed [(#12742)](https://github.com/prowler-cloud/prowler/pull/12742) +- Scans page filter widths and action button styling, with Launch Scan and Import Findings grouped beside the tabs and sized consistently with Configure Mutelist [(#12781)](https://github.com/prowler-cloud/prowler/pull/12781) + +### 🔐 Security + +- `nanoid` to 5.1.16, `js-yaml` to 4.3.1 and `postcss` to 8.5.23, plus transitive `hono`, `@hono/node-server`, `browserslist`, `qs`, `dompurify`, `brace-expansion`, `fast-uri`, `ip-address`, `mermaid`, `body-parser` and `@humanfs/node` to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low) [(#12758)](https://github.com/prowler-cloud/prowler/pull/12758) +- `next` to 16.3.3, patching an unauthenticated remote code execution in the Image Optimization API when AVIF files are used (GHSA-2xp9-vwfh-vxw4) [(#12778)](https://github.com/prowler-cloud/prowler/pull/12778) +- `sharp` to 0.35.4, patching two libheif vulnerabilities reachable through image decoding (GHSA-rgj7-g3m4-5g8c) [(#12778)](https://github.com/prowler-cloud/prowler/pull/12778) + +--- + ## [1.41.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/ui/changelog.d/dependabot-audit-vulnerabilities.security.md b/ui/changelog.d/dependabot-audit-vulnerabilities.security.md deleted file mode 100644 index 9d030097f0..0000000000 --- a/ui/changelog.d/dependabot-audit-vulnerabilities.security.md +++ /dev/null @@ -1 +0,0 @@ -`nanoid` to 5.1.16, `js-yaml` to 4.3.1 and `postcss` to 8.5.23, plus transitive `hono`, `@hono/node-server`, `browserslist`, `qs`, `dompurify`, `brace-expansion`, `fast-uri`, `ip-address`, `mermaid`, `body-parser` and `@humanfs/node` to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low) diff --git a/ui/changelog.d/integration-connection-poll-timeout.fixed.md b/ui/changelog.d/integration-connection-poll-timeout.fixed.md deleted file mode 100644 index 629eef9a45..0000000000 --- a/ui/changelog.d/integration-connection-poll-timeout.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Integration connection test polling now waits up to ~3 minutes instead of ~57 seconds before giving up, so it no longer reports a false failure on slower checks (e.g. Jira accounts with many projects) that were still going to succeed diff --git a/ui/changelog.d/next-image-optimization-rce.security.md b/ui/changelog.d/next-image-optimization-rce.security.md deleted file mode 100644 index 5000fa95f8..0000000000 --- a/ui/changelog.d/next-image-optimization-rce.security.md +++ /dev/null @@ -1 +0,0 @@ -`next` to 16.3.3, patching an unauthenticated remote code execution in the Image Optimization API when AVIF files are used (GHSA-2xp9-vwfh-vxw4) diff --git a/ui/changelog.d/posthog-toolbar-localhost.added.md b/ui/changelog.d/posthog-toolbar-localhost.added.md deleted file mode 100644 index a2aa815a1c..0000000000 --- a/ui/changelog.d/posthog-toolbar-localhost.added.md +++ /dev/null @@ -1 +0,0 @@ -PostHog Toolbar support in development with separate ingestion and app hosts diff --git a/ui/changelog.d/scans-filter-actions.fixed.md b/ui/changelog.d/scans-filter-actions.fixed.md deleted file mode 100644 index 3220d59a8e..0000000000 --- a/ui/changelog.d/scans-filter-actions.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Scans page filter widths and action button styling, with Launch Scan and Import Findings grouped beside the tabs and sized consistently with Configure Mutelist diff --git a/ui/changelog.d/sharp-libheif-vulnerabilities.security.md b/ui/changelog.d/sharp-libheif-vulnerabilities.security.md deleted file mode 100644 index 75296b55dc..0000000000 --- a/ui/changelog.d/sharp-libheif-vulnerabilities.security.md +++ /dev/null @@ -1 +0,0 @@ -`sharp` to 0.35.4, patching two libheif vulnerabilities reachable through image decoding (GHSA-rgj7-g3m4-5g8c) diff --git a/ui/changelog.d/view-first-scan-tour-selector.fixed.md b/ui/changelog.d/view-first-scan-tour-selector.fixed.md deleted file mode 100644 index 13f56ac446..0000000000 --- a/ui/changelog.d/view-first-scan-tour-selector.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Scan Jobs onboarding tour no longer targets an unmounted In Progress row from other tabs