From 4d13e8432e57289a188c2a12200dcd8437f35543 Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Fri, 28 Aug 2026 11:51:30 +0200 Subject: [PATCH] chore(changelog): v5.40.0 (#12642) Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com> --- api/CHANGELOG.md | 13 +++++++ .../api-image-openssl-cves.security.md | 1 - .../findings-partition-max-age-unit.fixed.md | 1 - api/changelog.d/sqlparse-0.6.security.md | 1 - mcp_server/CHANGELOG.md | 18 +++++++++ .../mcp-docs-search-endpoint.fixed.md | 1 - .../mcp-image-openssl-cve.security.md | 1 - .../mcp-image-sqlite-cves.security.md | 1 - .../mcp-shared-failure-messages.added.md | 1 - .../mcp-upstream-error-bodies.security.md | 1 - prowler/CHANGELOG.md | 37 +++++++++++++++++++ ...ain-dmarc-records-published-check.added.md | 1 - .../bedrock-agent-arn-partition.fixed.md | 1 - .../bedrock-model-artifact-checks.added.md | 1 - .../changelog.d/cyber-essentials-3.3.added.md | 1 - .../ec2-securitygroup-not-used-batch.fixed.md | 1 - .../ecr-repository-image-no-secrets.added.md | 1 - .../fsbp-iam9-eks1-check-mapping.fixed.md | 1 - ...-wif-provider-attribute-condition.added.md | 1 - .../iac-clone-failure-exit.fixed.md | 1 - ...es-compliance-report-cluster-name.added.md | 1 - ...ubernetes-control-plane-pods-none.fixed.md | 1 - ...ion-actions-pull-request-approval.added.md | 1 - ...tion-default-workflow-permissions.added.md | 1 - ...et-server-side-encryption-enabled.added.md | 1 - .../oss-bucket-subresource-parsing.fixed.md | 1 - .../oss-bucket-versioning-check.added.md | 1 - .../push-to-cloud-system-trust.fixed.md | 1 - ...tory-default-workflow-permissions.added.md | 1 - ...sanywhere-profile-session-scoping.added.md | 1 - .../sdk-image-openssl-cves.security.md | 1 - .../ske-cluster-no-public-endpoint.added.md | 1 - .../changelog.d/slack-zero-findings.fixed.md | 1 - ...universal-compliance-entry-points.fixed.md | 1 - .../vpc-security-group-open-egress.added.md | 1 - ui/CHANGELOG.md | 30 +++++++++++++++ .../alert-slack-channel-destinations.added.md | 1 - .../alerts-destinations-column.changed.md | 1 - ...ross-provider-catalog-unavailable.fixed.md | 1 - .../cross-provider-framework-catalog.fixed.md | 1 - ui/changelog.d/cyber-essentials-3.3.added.md | 1 - .../imported-provider-provenance.added.md | 1 - ...ghthouse-request-outcome-feedback.added.md | 1 - .../scan-auto-refresh-settlement.fixed.md | 1 - .../scan-trial-sidebar-banner.added.md | 1 - .../slack-authorized-channels.added.md | 1 - ...ack-integration-connect-workspace.added.md | 1 - .../slack-oauth-callback-redirect.fixed.md | 1 - .../trial-sidebar-banner-cancelled.added.md | 1 - .../ui-image-openssl-cves.security.md | 1 - 50 files changed, 98 insertions(+), 46 deletions(-) delete mode 100644 api/changelog.d/api-image-openssl-cves.security.md delete mode 100644 api/changelog.d/findings-partition-max-age-unit.fixed.md delete mode 100644 api/changelog.d/sqlparse-0.6.security.md delete mode 100644 mcp_server/changelog.d/mcp-docs-search-endpoint.fixed.md delete mode 100644 mcp_server/changelog.d/mcp-image-openssl-cve.security.md delete mode 100644 mcp_server/changelog.d/mcp-image-sqlite-cves.security.md delete mode 100644 mcp_server/changelog.d/mcp-shared-failure-messages.added.md delete mode 100644 mcp_server/changelog.d/mcp-upstream-error-bodies.security.md delete mode 100644 prowler/changelog.d/add-defender-domain-dmarc-records-published-check.added.md delete mode 100644 prowler/changelog.d/bedrock-agent-arn-partition.fixed.md delete mode 100644 prowler/changelog.d/bedrock-model-artifact-checks.added.md delete mode 100644 prowler/changelog.d/cyber-essentials-3.3.added.md delete mode 100644 prowler/changelog.d/ec2-securitygroup-not-used-batch.fixed.md delete mode 100644 prowler/changelog.d/ecr-repository-image-no-secrets.added.md delete mode 100644 prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md delete mode 100644 prowler/changelog.d/gcp-wif-provider-attribute-condition.added.md delete mode 100644 prowler/changelog.d/iac-clone-failure-exit.fixed.md delete mode 100644 prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md delete mode 100644 prowler/changelog.d/kubernetes-control-plane-pods-none.fixed.md delete mode 100644 prowler/changelog.d/organization-actions-pull-request-approval.added.md delete mode 100644 prowler/changelog.d/organization-default-workflow-permissions.added.md delete mode 100644 prowler/changelog.d/oss-bucket-server-side-encryption-enabled.added.md delete mode 100644 prowler/changelog.d/oss-bucket-subresource-parsing.fixed.md delete mode 100644 prowler/changelog.d/oss-bucket-versioning-check.added.md delete mode 100644 prowler/changelog.d/push-to-cloud-system-trust.fixed.md delete mode 100644 prowler/changelog.d/repository-default-workflow-permissions.added.md delete mode 100644 prowler/changelog.d/rolesanywhere-profile-session-scoping.added.md delete mode 100644 prowler/changelog.d/sdk-image-openssl-cves.security.md delete mode 100644 prowler/changelog.d/ske-cluster-no-public-endpoint.added.md delete mode 100644 prowler/changelog.d/slack-zero-findings.fixed.md delete mode 100644 prowler/changelog.d/universal-compliance-entry-points.fixed.md delete mode 100644 prowler/changelog.d/vpc-security-group-open-egress.added.md delete mode 100644 ui/changelog.d/alert-slack-channel-destinations.added.md delete mode 100644 ui/changelog.d/alerts-destinations-column.changed.md delete mode 100644 ui/changelog.d/cross-provider-catalog-unavailable.fixed.md delete mode 100644 ui/changelog.d/cross-provider-framework-catalog.fixed.md delete mode 100644 ui/changelog.d/cyber-essentials-3.3.added.md delete mode 100644 ui/changelog.d/imported-provider-provenance.added.md delete mode 100644 ui/changelog.d/lighthouse-request-outcome-feedback.added.md delete mode 100644 ui/changelog.d/scan-auto-refresh-settlement.fixed.md delete mode 100644 ui/changelog.d/scan-trial-sidebar-banner.added.md delete mode 100644 ui/changelog.d/slack-authorized-channels.added.md delete mode 100644 ui/changelog.d/slack-integration-connect-workspace.added.md delete mode 100644 ui/changelog.d/slack-oauth-callback-redirect.fixed.md delete mode 100644 ui/changelog.d/trial-sidebar-banner-cancelled.added.md delete mode 100644 ui/changelog.d/ui-image-openssl-cves.security.md diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 183f1270ee..7b05c116bc 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -4,6 +4,19 @@ All notable changes to the **Prowler API** are documented in this file. +## [1.41.0] (Prowler v5.40.0) + +### 🐞 Fixed + +- `FINDINGS_TABLE_PARTITION_MAX_AGE_MONTHS` is now applied in months instead of days, and negative values are rejected [(#12580)](https://github.com/prowler-cloud/prowler/pull/12580) + +### 🔐 Security + +- `sqlparse` upgraded to 0.6.0, patching CVE-2026-54284, CVE-2026-59893, and CVE-2026-71491 [(#12509)](https://github.com/prowler-cloud/prowler/pull/12509) +- `openssl`, `libssl3t64` and `openssl-provider-legacy` upgraded to 3.5.7-1~deb13u2 in the API container image, patching ten high OpenSSL CVEs [(#12549)](https://github.com/prowler-cloud/prowler/pull/12549) + +--- + ## [1.40.1] (Prowler v5.39.1) ### 🔄 Changed diff --git a/api/changelog.d/api-image-openssl-cves.security.md b/api/changelog.d/api-image-openssl-cves.security.md deleted file mode 100644 index 9c3b2d5209..0000000000 --- a/api/changelog.d/api-image-openssl-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`openssl`, `libssl3t64` and `openssl-provider-legacy` upgraded to 3.5.7-1~deb13u2 in the API container image, patching ten high OpenSSL CVEs diff --git a/api/changelog.d/findings-partition-max-age-unit.fixed.md b/api/changelog.d/findings-partition-max-age-unit.fixed.md deleted file mode 100644 index 4b6cd02146..0000000000 --- a/api/changelog.d/findings-partition-max-age-unit.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`FINDINGS_TABLE_PARTITION_MAX_AGE_MONTHS` is now applied in months instead of days, and negative values are rejected diff --git a/api/changelog.d/sqlparse-0.6.security.md b/api/changelog.d/sqlparse-0.6.security.md deleted file mode 100644 index f9327d24e5..0000000000 --- a/api/changelog.d/sqlparse-0.6.security.md +++ /dev/null @@ -1 +0,0 @@ -`sqlparse` upgraded to 0.6.0, patching CVE-2026-54284, CVE-2026-59893, and CVE-2026-71491 diff --git a/mcp_server/CHANGELOG.md b/mcp_server/CHANGELOG.md index c040aa17e7..62e0446bb0 100644 --- a/mcp_server/CHANGELOG.md +++ b/mcp_server/CHANGELOG.md @@ -4,6 +4,24 @@ All notable changes to the **Prowler MCP Server** are documented in this file. +## [0.11.0] (Prowler v5.40.0) + +### 🚀 Added + +- Failures shared by every tool - a rejected credential, a missing permission, a rate limit, an outage, an unreachable API, a bad argument - are now explained with a message that says what went wrong and what to do about it [(#12531)](https://github.com/prowler-cloud/prowler/pull/12531) + +### 🐞 Fixed + +- `prowler_docs_search` returns results again: it calls the search endpoint docs.prowler.com moved to, since the one it used no longer exists, and each result now names the page's title, the section it matched and a URL anchored at that section [(#12578)](https://github.com/prowler-cloud/prowler/pull/12578) + +### 🔐 Security + +- Stop relaying upstream response bodies to agents: a failed request now reaches the caller as a sentence this server wrote, with the full body kept to the logs, so a gateway error page or a debug traceback can no longer be replayed into a model's context [(#12531)](https://github.com/prowler-cloud/prowler/pull/12531) +- `sqlite-libs` upgraded to 3.53.4-r0 in the container image, patching CVE-2026-11822 and CVE-2026-11824 [(#12537)](https://github.com/prowler-cloud/prowler/pull/12537) +- `libcrypto3` and `libssl3` upgraded to 3.5.8-r0 in the container image, patching CVE-2026-14456 [(#12547)](https://github.com/prowler-cloud/prowler/pull/12547) + +--- + ## [0.10.0] (Prowler v5.38.0) ### 🚀 Added diff --git a/mcp_server/changelog.d/mcp-docs-search-endpoint.fixed.md b/mcp_server/changelog.d/mcp-docs-search-endpoint.fixed.md deleted file mode 100644 index b5c1930136..0000000000 --- a/mcp_server/changelog.d/mcp-docs-search-endpoint.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`prowler_docs_search` returns results again: it calls the search endpoint docs.prowler.com moved to, since the one it used no longer exists, and each result now names the page's title, the section it matched and a URL anchored at that section diff --git a/mcp_server/changelog.d/mcp-image-openssl-cve.security.md b/mcp_server/changelog.d/mcp-image-openssl-cve.security.md deleted file mode 100644 index 9eb80f75a9..0000000000 --- a/mcp_server/changelog.d/mcp-image-openssl-cve.security.md +++ /dev/null @@ -1 +0,0 @@ -`libcrypto3` and `libssl3` upgraded to 3.5.8-r0 in the container image, patching CVE-2026-14456 diff --git a/mcp_server/changelog.d/mcp-image-sqlite-cves.security.md b/mcp_server/changelog.d/mcp-image-sqlite-cves.security.md deleted file mode 100644 index e69ac2a161..0000000000 --- a/mcp_server/changelog.d/mcp-image-sqlite-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`sqlite-libs` upgraded to 3.53.4-r0 in the container image, patching CVE-2026-11822 and CVE-2026-11824 diff --git a/mcp_server/changelog.d/mcp-shared-failure-messages.added.md b/mcp_server/changelog.d/mcp-shared-failure-messages.added.md deleted file mode 100644 index 90097193d7..0000000000 --- a/mcp_server/changelog.d/mcp-shared-failure-messages.added.md +++ /dev/null @@ -1 +0,0 @@ -Failures shared by every tool - a rejected credential, a missing permission, a rate limit, an outage, an unreachable API, a bad argument - are now explained with a message that says what went wrong and what to do about it diff --git a/mcp_server/changelog.d/mcp-upstream-error-bodies.security.md b/mcp_server/changelog.d/mcp-upstream-error-bodies.security.md deleted file mode 100644 index edc9dd7db5..0000000000 --- a/mcp_server/changelog.d/mcp-upstream-error-bodies.security.md +++ /dev/null @@ -1 +0,0 @@ -Stop relaying upstream response bodies to agents: a failed request now reaches the caller as a sentence this server wrote, with the full body kept to the logs, so a gateway error page or a debug traceback can no longer be replayed into a model's context diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 076bffb52a..401d8a7a1a 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -4,6 +4,43 @@ All notable changes to the **Prowler SDK** are documented in this file. +## [5.40.0] (Prowler v5.40.0) + +### 🚀 Added + +- NCSC Cyber Essentials 3.3 compliance framework with Azure provider coverage across the five Cyber Essentials themes [(#11588)](https://github.com/prowler-cloud/prowler/pull/11588) +- `oss_bucket_versioning_enabled` check for Alibaba Cloud provider, verifying that OSS buckets have versioning enabled to allow recovery from accidental or malicious object overwrite and deletion [(#11913)](https://github.com/prowler-cloud/prowler/pull/11913) +- `defender_domain_dmarc_records_published` checks that every Exchange Online domain publishes a DMARC record with an enforcing policy (`p=quarantine` or `p=reject`) [(#11936)](https://github.com/prowler-cloud/prowler/pull/11936) +- `ske_cluster_no_public_endpoint` check for STACKIT provider, flagging SKE clusters whose Kubernetes API endpoint is reachable from the whole internet because the ACL extension is disabled or its allowed CIDR list contains `0.0.0.0/0` or `::/0` [(#11943)](https://github.com/prowler-cloud/prowler/pull/11943) +- `oss_bucket_server_side_encryption_enabled` check for Alibaba Cloud provider, verifying that OSS buckets have a default server-side encryption rule (AES256 or KMS) [(#11981)](https://github.com/prowler-cloud/prowler/pull/11981) +- `organization_default_workflow_permissions_read_only` check for GitHub provider, verifying that organizations grant GitHub Actions workflows a read-only default `GITHUB_TOKEN` [(#12122)](https://github.com/prowler-cloud/prowler/pull/12122) +- `ecr_repository_image_no_secrets` check for AWS provider, scanning the latest ECR repository image's configuration and filesystem layers for hardcoded secrets [(#12123)](https://github.com/prowler-cloud/prowler/pull/12123) +- `repository_default_workflow_permissions_read_only` check for GitHub provider, verifying that repositories grant GitHub Actions workflows a read-only default `GITHUB_TOKEN` [(#12143)](https://github.com/prowler-cloud/prowler/pull/12143) +- `vpc_security_group_open_egress` check for Huawei Cloud provider: VPC security groups do not allow open egress to the internet [(#12209)](https://github.com/prowler-cloud/prowler/pull/12209) +- `organization_actions_pull_request_approval_disabled` check for GitHub provider, verifying that organizations prevent GitHub Actions from creating and approving pull requests [(#12394)](https://github.com/prowler-cloud/prowler/pull/12394) +- Add the `iam_workload_identity_pool_provider_attribute_condition` check to flag GCP Workload Identity Federation providers that trust a multi-tenant issuer without an attribute condition restricting which external identities can impersonate federated principals [(#12416)](https://github.com/prowler-cloud/prowler/pull/12416) +- Add the `rolesanywhere_profile_restricts_session_permissions` check to flag AWS IAM Roles Anywhere profiles that reference an administrative role without scoping down the vended session with a session policy or managed policies [(#12416)](https://github.com/prowler-cloud/prowler/pull/12416) +- `bedrock_guardrail_contextual_grounding_filter_enabled`, `bedrock_custom_model_encrypted_with_cmk`, `bedrock_knowledge_base_encrypted_with_cmk` and `bedrock_agent_role_not_shared_across_agents` are four new AWS Bedrock checks covering guardrail contextual grounding, custom model encryption, knowledge-base data-source encryption, and non-shared agent execution roles. [(#12459)](https://github.com/prowler-cloud/prowler/pull/12459) +- `Cluster` column in Kubernetes CIS, ISO27001, Prowler ThreatScore, and universal compliance outputs, populated with the resolved cluster name so multi-cluster scans can be told apart in the output [(#12506)](https://github.com/prowler-cloud/prowler/pull/12506) + +### 🐞 Fixed + +- Kubernetes `kubelet` checks no longer disappear from the scan with `TypeError: 'NoneType' object is not iterable` when a `kubelet-config` ConfigMap is broken: one with malformed YAML is logged and skipped while the valid ones are still evaluated, one without kubelet data is evaluated with an empty configuration instead of crashing the checks, and the `apiserver`, `controllermanager`, `etcd` and `scheduler` pod gatherers now always return a list [(#12225)](https://github.com/prowler-cloud/prowler/pull/12225) +- IaC provider now raises typed `IacBaseException` errors (repository clone, Trivy missing, scan and output processing failures) instead of calling `sys.exit(1)`; the CLI still stops with the logged message, and API scans fail as regular task errors instead of a `SystemExit` escaping the worker [(#12227)](https://github.com/prowler-cloud/prowler/pull/12227) +- CLI Slack integration (`--slack`) no longer fails when a scan produces no findings: the pass and fail percentages are guarded against a `findings_count` of 0, which previously raised `ZeroDivisionError` and sent `blocks=None` to Slack instead of the summary [(#12229)](https://github.com/prowler-cloud/prowler/pull/12229) +- AWS FSBP compliance mapping for `IAM.9` and `EKS.1` referenced missing/renamed checks; both now point to their real, existing check IDs [(#12372)](https://github.com/prowler-cloud/prowler/pull/12372) +- `ec2_securitygroup_not_used` no longer reports a false positive for security groups attached only to an AWS Batch compute environment, which holds them in configuration without creating a network interface while scaled down to zero instances [(#12458)](https://github.com/prowler-cloud/prowler/pull/12458) +- Bedrock Agent ARNs are now built from the audited partition instead of a hardcoded `arn:aws:`, so findings in GovCloud and China carry a resolvable ARN and `--resource-arn` scoping matches agents in those partitions. [(#12459)](https://github.com/prowler-cloud/prowler/pull/12459) +- `push-to-cloud` now validates Private Cloud TLS certificates with the operating system trust store without changing provider HTTP clients [(#12485)](https://github.com/prowler-cloud/prowler/pull/12485) +- `prowler.compliance.universal` entry point directories are resolved through a single shared helper and deduplicated by resolved path, so a directory reached through two entry points is parsed once and a package that fails to import no longer hides the rest [(#12536)](https://github.com/prowler-cloud/prowler/pull/12536) +- OSS bucket logging, versioning, default encryption and ACL configurations are now read correctly from the Alibaba Cloud SDK, so `oss_bucket_logging_enabled`, `oss_bucket_versioning_enabled`, `oss_bucket_server_side_encryption_enabled` and `oss_bucket_not_publicly_accessible` no longer report every bucket as unconfigured [(#12546)](https://github.com/prowler-cloud/prowler/pull/12546) + +### 🔐 Security + +- `openssl`, `libssl3t64` and `openssl-provider-legacy` upgraded to 3.5.7-1~deb13u2 in the SDK container image, patching ten high OpenSSL CVEs [(#12549)](https://github.com/prowler-cloud/prowler/pull/12549) + +--- + ## [5.39.1] (Prowler v5.39.1) ### 🐞 Fixed diff --git a/prowler/changelog.d/add-defender-domain-dmarc-records-published-check.added.md b/prowler/changelog.d/add-defender-domain-dmarc-records-published-check.added.md deleted file mode 100644 index 63bf4e01a9..0000000000 --- a/prowler/changelog.d/add-defender-domain-dmarc-records-published-check.added.md +++ /dev/null @@ -1 +0,0 @@ -`defender_domain_dmarc_records_published` checks that every Exchange Online domain publishes a DMARC record with an enforcing policy (`p=quarantine` or `p=reject`) diff --git a/prowler/changelog.d/bedrock-agent-arn-partition.fixed.md b/prowler/changelog.d/bedrock-agent-arn-partition.fixed.md deleted file mode 100644 index 96d4424272..0000000000 --- a/prowler/changelog.d/bedrock-agent-arn-partition.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Bedrock Agent ARNs are now built from the audited partition instead of a hardcoded `arn:aws:`, so findings in GovCloud and China carry a resolvable ARN and `--resource-arn` scoping matches agents in those partitions. diff --git a/prowler/changelog.d/bedrock-model-artifact-checks.added.md b/prowler/changelog.d/bedrock-model-artifact-checks.added.md deleted file mode 100644 index 43d08aaf79..0000000000 --- a/prowler/changelog.d/bedrock-model-artifact-checks.added.md +++ /dev/null @@ -1 +0,0 @@ -`bedrock_guardrail_contextual_grounding_filter_enabled`, `bedrock_custom_model_encrypted_with_cmk`, `bedrock_knowledge_base_encrypted_with_cmk` and `bedrock_agent_role_not_shared_across_agents` are four new AWS Bedrock checks covering guardrail contextual grounding, custom model encryption, knowledge-base data-source encryption, and non-shared agent execution roles. diff --git a/prowler/changelog.d/cyber-essentials-3.3.added.md b/prowler/changelog.d/cyber-essentials-3.3.added.md deleted file mode 100644 index 35309f6805..0000000000 --- a/prowler/changelog.d/cyber-essentials-3.3.added.md +++ /dev/null @@ -1 +0,0 @@ -NCSC Cyber Essentials 3.3 compliance framework with Azure provider coverage across the five Cyber Essentials themes diff --git a/prowler/changelog.d/ec2-securitygroup-not-used-batch.fixed.md b/prowler/changelog.d/ec2-securitygroup-not-used-batch.fixed.md deleted file mode 100644 index a979e6f27f..0000000000 --- a/prowler/changelog.d/ec2-securitygroup-not-used-batch.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`ec2_securitygroup_not_used` no longer reports a false positive for security groups attached only to an AWS Batch compute environment, which holds them in configuration without creating a network interface while scaled down to zero instances diff --git a/prowler/changelog.d/ecr-repository-image-no-secrets.added.md b/prowler/changelog.d/ecr-repository-image-no-secrets.added.md deleted file mode 100644 index eb92d46823..0000000000 --- a/prowler/changelog.d/ecr-repository-image-no-secrets.added.md +++ /dev/null @@ -1 +0,0 @@ -`ecr_repository_image_no_secrets` check for AWS provider, scanning the latest ECR repository image's configuration and filesystem layers for hardcoded secrets diff --git a/prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md b/prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md deleted file mode 100644 index f3b3085687..0000000000 --- a/prowler/changelog.d/fsbp-iam9-eks1-check-mapping.fixed.md +++ /dev/null @@ -1 +0,0 @@ -AWS FSBP compliance mapping for `IAM.9` and `EKS.1` referenced missing/renamed checks; both now point to their real, existing check IDs diff --git a/prowler/changelog.d/gcp-wif-provider-attribute-condition.added.md b/prowler/changelog.d/gcp-wif-provider-attribute-condition.added.md deleted file mode 100644 index 4ab15242e2..0000000000 --- a/prowler/changelog.d/gcp-wif-provider-attribute-condition.added.md +++ /dev/null @@ -1 +0,0 @@ -Add the `iam_workload_identity_pool_provider_attribute_condition` check to flag GCP Workload Identity Federation providers that trust a multi-tenant issuer without an attribute condition restricting which external identities can impersonate federated principals diff --git a/prowler/changelog.d/iac-clone-failure-exit.fixed.md b/prowler/changelog.d/iac-clone-failure-exit.fixed.md deleted file mode 100644 index da14e4fb65..0000000000 --- a/prowler/changelog.d/iac-clone-failure-exit.fixed.md +++ /dev/null @@ -1 +0,0 @@ -IaC provider now raises typed `IacBaseException` errors (repository clone, Trivy missing, scan and output processing failures) instead of calling `sys.exit(1)`; the CLI still stops with the logged message, and API scans fail as regular task errors instead of a `SystemExit` escaping the worker diff --git a/prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md b/prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md deleted file mode 100644 index f713013dff..0000000000 --- a/prowler/changelog.d/kubernetes-compliance-report-cluster-name.added.md +++ /dev/null @@ -1 +0,0 @@ -`Cluster` column in Kubernetes CIS, ISO27001, Prowler ThreatScore, and universal compliance outputs, populated with the resolved cluster name so multi-cluster scans can be told apart in the output diff --git a/prowler/changelog.d/kubernetes-control-plane-pods-none.fixed.md b/prowler/changelog.d/kubernetes-control-plane-pods-none.fixed.md deleted file mode 100644 index 6a9e30f912..0000000000 --- a/prowler/changelog.d/kubernetes-control-plane-pods-none.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Kubernetes `kubelet` checks no longer disappear from the scan with `TypeError: 'NoneType' object is not iterable` when a `kubelet-config` ConfigMap is broken: one with malformed YAML is logged and skipped while the valid ones are still evaluated, one without kubelet data is evaluated with an empty configuration instead of crashing the checks, and the `apiserver`, `controllermanager`, `etcd` and `scheduler` pod gatherers now always return a list diff --git a/prowler/changelog.d/organization-actions-pull-request-approval.added.md b/prowler/changelog.d/organization-actions-pull-request-approval.added.md deleted file mode 100644 index aba0be0820..0000000000 --- a/prowler/changelog.d/organization-actions-pull-request-approval.added.md +++ /dev/null @@ -1 +0,0 @@ -`organization_actions_pull_request_approval_disabled` check for GitHub provider, verifying that organizations prevent GitHub Actions from creating and approving pull requests diff --git a/prowler/changelog.d/organization-default-workflow-permissions.added.md b/prowler/changelog.d/organization-default-workflow-permissions.added.md deleted file mode 100644 index efdcb7e921..0000000000 --- a/prowler/changelog.d/organization-default-workflow-permissions.added.md +++ /dev/null @@ -1 +0,0 @@ -`organization_default_workflow_permissions_read_only` check for GitHub provider, verifying that organizations grant GitHub Actions workflows a read-only default `GITHUB_TOKEN` diff --git a/prowler/changelog.d/oss-bucket-server-side-encryption-enabled.added.md b/prowler/changelog.d/oss-bucket-server-side-encryption-enabled.added.md deleted file mode 100644 index 630fac9252..0000000000 --- a/prowler/changelog.d/oss-bucket-server-side-encryption-enabled.added.md +++ /dev/null @@ -1 +0,0 @@ -`oss_bucket_server_side_encryption_enabled` check for Alibaba Cloud provider, verifying that OSS buckets have a default server-side encryption rule (AES256 or KMS) diff --git a/prowler/changelog.d/oss-bucket-subresource-parsing.fixed.md b/prowler/changelog.d/oss-bucket-subresource-parsing.fixed.md deleted file mode 100644 index 99564bdfb4..0000000000 --- a/prowler/changelog.d/oss-bucket-subresource-parsing.fixed.md +++ /dev/null @@ -1 +0,0 @@ -OSS bucket logging, versioning, default encryption and ACL configurations are now read correctly from the Alibaba Cloud SDK, so `oss_bucket_logging_enabled`, `oss_bucket_versioning_enabled`, `oss_bucket_server_side_encryption_enabled` and `oss_bucket_not_publicly_accessible` no longer report every bucket as unconfigured diff --git a/prowler/changelog.d/oss-bucket-versioning-check.added.md b/prowler/changelog.d/oss-bucket-versioning-check.added.md deleted file mode 100644 index 28126db09b..0000000000 --- a/prowler/changelog.d/oss-bucket-versioning-check.added.md +++ /dev/null @@ -1 +0,0 @@ -`oss_bucket_versioning_enabled` check for Alibaba Cloud provider, verifying that OSS buckets have versioning enabled to allow recovery from accidental or malicious object overwrite and deletion diff --git a/prowler/changelog.d/push-to-cloud-system-trust.fixed.md b/prowler/changelog.d/push-to-cloud-system-trust.fixed.md deleted file mode 100644 index cc06e8de25..0000000000 --- a/prowler/changelog.d/push-to-cloud-system-trust.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`push-to-cloud` now validates Private Cloud TLS certificates with the operating system trust store without changing provider HTTP clients diff --git a/prowler/changelog.d/repository-default-workflow-permissions.added.md b/prowler/changelog.d/repository-default-workflow-permissions.added.md deleted file mode 100644 index 0df7ab6dc4..0000000000 --- a/prowler/changelog.d/repository-default-workflow-permissions.added.md +++ /dev/null @@ -1 +0,0 @@ -`repository_default_workflow_permissions_read_only` check for GitHub provider, verifying that repositories grant GitHub Actions workflows a read-only default `GITHUB_TOKEN` diff --git a/prowler/changelog.d/rolesanywhere-profile-session-scoping.added.md b/prowler/changelog.d/rolesanywhere-profile-session-scoping.added.md deleted file mode 100644 index 6f50731aae..0000000000 --- a/prowler/changelog.d/rolesanywhere-profile-session-scoping.added.md +++ /dev/null @@ -1 +0,0 @@ -Add the `rolesanywhere_profile_restricts_session_permissions` check to flag AWS IAM Roles Anywhere profiles that reference an administrative role without scoping down the vended session with a session policy or managed policies diff --git a/prowler/changelog.d/sdk-image-openssl-cves.security.md b/prowler/changelog.d/sdk-image-openssl-cves.security.md deleted file mode 100644 index ef78982da5..0000000000 --- a/prowler/changelog.d/sdk-image-openssl-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`openssl`, `libssl3t64` and `openssl-provider-legacy` upgraded to 3.5.7-1~deb13u2 in the SDK container image, patching ten high OpenSSL CVEs diff --git a/prowler/changelog.d/ske-cluster-no-public-endpoint.added.md b/prowler/changelog.d/ske-cluster-no-public-endpoint.added.md deleted file mode 100644 index 88a70a0931..0000000000 --- a/prowler/changelog.d/ske-cluster-no-public-endpoint.added.md +++ /dev/null @@ -1 +0,0 @@ -`ske_cluster_no_public_endpoint` check for STACKIT provider, flagging SKE clusters whose Kubernetes API endpoint is reachable from the whole internet because the ACL extension is disabled or its allowed CIDR list contains `0.0.0.0/0` or `::/0` diff --git a/prowler/changelog.d/slack-zero-findings.fixed.md b/prowler/changelog.d/slack-zero-findings.fixed.md deleted file mode 100644 index 7b62939855..0000000000 --- a/prowler/changelog.d/slack-zero-findings.fixed.md +++ /dev/null @@ -1 +0,0 @@ -CLI Slack integration (`--slack`) no longer fails when a scan produces no findings: the pass and fail percentages are guarded against a `findings_count` of 0, which previously raised `ZeroDivisionError` and sent `blocks=None` to Slack instead of the summary diff --git a/prowler/changelog.d/universal-compliance-entry-points.fixed.md b/prowler/changelog.d/universal-compliance-entry-points.fixed.md deleted file mode 100644 index 81fbff0864..0000000000 --- a/prowler/changelog.d/universal-compliance-entry-points.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`prowler.compliance.universal` entry point directories are resolved through a single shared helper and deduplicated by resolved path, so a directory reached through two entry points is parsed once and a package that fails to import no longer hides the rest diff --git a/prowler/changelog.d/vpc-security-group-open-egress.added.md b/prowler/changelog.d/vpc-security-group-open-egress.added.md deleted file mode 100644 index b184075f24..0000000000 --- a/prowler/changelog.d/vpc-security-group-open-egress.added.md +++ /dev/null @@ -1 +0,0 @@ -`vpc_security_group_open_egress` check for Huawei Cloud provider: VPC security groups do not allow open egress to the internet diff --git a/ui/CHANGELOG.md b/ui/CHANGELOG.md index 6486d56867..c3c655e442 100644 --- a/ui/CHANGELOG.md +++ b/ui/CHANGELOG.md @@ -4,6 +4,36 @@ All notable changes to the **Prowler UI** are documented in this file. +## [1.40.0] (Prowler v5.40.0) + +### 🚀 Added + +- NCSC Cyber Essentials 3.3 compliance support with its dedicated mapper, details panel, and icon [(#11588)](https://github.com/prowler-cloud/prowler/pull/11588) +- Thumbs-up and thumbs-down feedback form for Lighthouse assistant answers with optional details [(#12419)](https://github.com/prowler-cloud/prowler/pull/12419) +- Display the default one-scan free trial and trial expiration in the existing sidebar banner [(#12420)](https://github.com/prowler-cloud/prowler/pull/12420) +- Slack integration: connect a Slack workspace from the Integrations page (Prowler Cloud only) [(#12435)](https://github.com/prowler-cloud/prowler/pull/12435) +- Prowler Cloud indicator for providers created via Import Findings alongside every connection status [(#12447)](https://github.com/prowler-cloud/prowler/pull/12447) +- Slack integration: authorize several destination channels at once — the connection check confirms each authorized channel with a one-time message and names the one Slack refuses [(#12491)](https://github.com/prowler-cloud/prowler/pull/12491) +- Slack channels confirmed on the Slack integration as alert rule destinations, selectable in the alert modal alongside email recipients [(#12492)](https://github.com/prowler-cloud/prowler/pull/12492) +- Cancelled-subscription variant in the sidebar trial banner (Prowler Cloud only) [(#12538)](https://github.com/prowler-cloud/prowler/pull/12538) + +### 🔄 Changed + +- Alerts list Recipients column becomes Destinations, summarizing a rule's email recipients and Slack channels at a glance [(#12493)](https://github.com/prowler-cloud/prowler/pull/12493) + +### 🐞 Fixed + +- Scan auto-refresh no longer overlaps slow client refreshes and now signals when scan execution settles [(#12455)](https://github.com/prowler-cloud/prowler/pull/12455) +- The compliance "Across providers" section builds its framework list from the API catalog instead of a hardcoded set of ids, so a universal framework registered by an installed package renders like a shipped one [(#12536)](https://github.com/prowler-cloud/prowler/pull/12536) +- The compliance "Across providers" section reports a failed catalog request instead of rendering the "no data yet" empty state [(#12536)](https://github.com/prowler-cloud/prowler/pull/12536) +- Returning from Slack after approving the install now reliably lands on the Slack integration page instead of getting stuck on the callback screen (Prowler Cloud only) [(#12572)](https://github.com/prowler-cloud/prowler/pull/12572) + +### 🔐 Security + +- `libcrypto3` and `libssl3` upgraded to 3.5.8-r0 in the UI container image, patching seven high OpenSSL CVEs [(#12549)](https://github.com/prowler-cloud/prowler/pull/12549) + +--- + ## [1.39.0] (Prowler v5.39.0) ### 🚀 Added diff --git a/ui/changelog.d/alert-slack-channel-destinations.added.md b/ui/changelog.d/alert-slack-channel-destinations.added.md deleted file mode 100644 index 23075a1572..0000000000 --- a/ui/changelog.d/alert-slack-channel-destinations.added.md +++ /dev/null @@ -1 +0,0 @@ -Slack channels confirmed on the Slack integration as alert rule destinations, selectable in the alert modal alongside email recipients diff --git a/ui/changelog.d/alerts-destinations-column.changed.md b/ui/changelog.d/alerts-destinations-column.changed.md deleted file mode 100644 index b29fe4603f..0000000000 --- a/ui/changelog.d/alerts-destinations-column.changed.md +++ /dev/null @@ -1 +0,0 @@ -Alerts list Recipients column becomes Destinations, summarizing a rule's email recipients and Slack channels at a glance diff --git a/ui/changelog.d/cross-provider-catalog-unavailable.fixed.md b/ui/changelog.d/cross-provider-catalog-unavailable.fixed.md deleted file mode 100644 index 8bd42d749e..0000000000 --- a/ui/changelog.d/cross-provider-catalog-unavailable.fixed.md +++ /dev/null @@ -1 +0,0 @@ -The compliance "Across providers" section reports a failed catalog request instead of rendering the "no data yet" empty state diff --git a/ui/changelog.d/cross-provider-framework-catalog.fixed.md b/ui/changelog.d/cross-provider-framework-catalog.fixed.md deleted file mode 100644 index 18d5cef965..0000000000 --- a/ui/changelog.d/cross-provider-framework-catalog.fixed.md +++ /dev/null @@ -1 +0,0 @@ -The compliance "Across providers" section builds its framework list from the API catalog instead of a hardcoded set of ids, so a universal framework registered by an installed package renders like a shipped one diff --git a/ui/changelog.d/cyber-essentials-3.3.added.md b/ui/changelog.d/cyber-essentials-3.3.added.md deleted file mode 100644 index 14ad178fa7..0000000000 --- a/ui/changelog.d/cyber-essentials-3.3.added.md +++ /dev/null @@ -1 +0,0 @@ -NCSC Cyber Essentials 3.3 compliance support with its dedicated mapper, details panel, and icon diff --git a/ui/changelog.d/imported-provider-provenance.added.md b/ui/changelog.d/imported-provider-provenance.added.md deleted file mode 100644 index 79999a976a..0000000000 --- a/ui/changelog.d/imported-provider-provenance.added.md +++ /dev/null @@ -1 +0,0 @@ -Prowler Cloud indicator for providers created via Import Findings alongside every connection status diff --git a/ui/changelog.d/lighthouse-request-outcome-feedback.added.md b/ui/changelog.d/lighthouse-request-outcome-feedback.added.md deleted file mode 100644 index 134c5fa8c3..0000000000 --- a/ui/changelog.d/lighthouse-request-outcome-feedback.added.md +++ /dev/null @@ -1 +0,0 @@ -Thumbs-up and thumbs-down feedback form for Lighthouse assistant answers with optional details diff --git a/ui/changelog.d/scan-auto-refresh-settlement.fixed.md b/ui/changelog.d/scan-auto-refresh-settlement.fixed.md deleted file mode 100644 index c87c5085ed..0000000000 --- a/ui/changelog.d/scan-auto-refresh-settlement.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Scan auto-refresh no longer overlaps slow client refreshes and now signals when scan execution settles diff --git a/ui/changelog.d/scan-trial-sidebar-banner.added.md b/ui/changelog.d/scan-trial-sidebar-banner.added.md deleted file mode 100644 index 9b853f2e48..0000000000 --- a/ui/changelog.d/scan-trial-sidebar-banner.added.md +++ /dev/null @@ -1 +0,0 @@ -Display the default one-scan free trial and trial expiration in the existing sidebar banner diff --git a/ui/changelog.d/slack-authorized-channels.added.md b/ui/changelog.d/slack-authorized-channels.added.md deleted file mode 100644 index b1f68dfa96..0000000000 --- a/ui/changelog.d/slack-authorized-channels.added.md +++ /dev/null @@ -1 +0,0 @@ -Slack integration: authorize several destination channels at once — the connection check confirms each authorized channel with a one-time message and names the one Slack refuses diff --git a/ui/changelog.d/slack-integration-connect-workspace.added.md b/ui/changelog.d/slack-integration-connect-workspace.added.md deleted file mode 100644 index 8352e887ef..0000000000 --- a/ui/changelog.d/slack-integration-connect-workspace.added.md +++ /dev/null @@ -1 +0,0 @@ -Slack integration: connect a Slack workspace from the Integrations page (Prowler Cloud only) diff --git a/ui/changelog.d/slack-oauth-callback-redirect.fixed.md b/ui/changelog.d/slack-oauth-callback-redirect.fixed.md deleted file mode 100644 index e19bb9bd83..0000000000 --- a/ui/changelog.d/slack-oauth-callback-redirect.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Returning from Slack after approving the install now reliably lands on the Slack integration page instead of getting stuck on the callback screen (Prowler Cloud only) diff --git a/ui/changelog.d/trial-sidebar-banner-cancelled.added.md b/ui/changelog.d/trial-sidebar-banner-cancelled.added.md deleted file mode 100644 index baf343b974..0000000000 --- a/ui/changelog.d/trial-sidebar-banner-cancelled.added.md +++ /dev/null @@ -1 +0,0 @@ -Cancelled-subscription variant in the sidebar trial banner (Prowler Cloud only) diff --git a/ui/changelog.d/ui-image-openssl-cves.security.md b/ui/changelog.d/ui-image-openssl-cves.security.md deleted file mode 100644 index 4e5ae59efc..0000000000 --- a/ui/changelog.d/ui-image-openssl-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`libcrypto3` and `libssl3` upgraded to 3.5.8-r0 in the UI container image, patching seven high OpenSSL CVEs