diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 318cd30d4f..1a927baa9c 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -4,6 +4,22 @@ All notable changes to the **Prowler API** are documented in this file. +## [1.44.0] (Prowler v5.43.0) + +### 🐞 Fixed + +- Report download URLs can be signed against a browser-reachable storage host via `DJANGO_OUTPUT_S3_AWS_PUBLIC_ENDPOINT_URL`, so downloads complete on deployments where storage is only reachable inside the container network [(#12552)](https://github.com/prowler-cloud/prowler/pull/12552) +- A scan report download no longer fails with a server error when `DJANGO_OUTPUT_S3_AWS_DEFAULT_REGION` is unset, which is common on storage with no meaningful region [(#12552)](https://github.com/prowler-cloud/prowler/pull/12552) +- Lapsed pending invitations are reported as expired and no longer block a new invitation for the same email [(#12831)](https://github.com/prowler-cloud/prowler/pull/12831) + +### 🔐 Security + +- `libsqlite3-0`, `gzip`, `perl-base` and `libpcre2-8-0` upgraded in the API container image, patching high Debian CVEs [(#12804)](https://github.com/prowler-cloud/prowler/pull/12804) +- PowerShell from 7.5.9 to 7.5.11 in the API container image, bundling .NET runtime 9.0.20 and patching CVE-2026-62901 [(#12811)](https://github.com/prowler-cloud/prowler/pull/12811) +- Bumped `anyio` to 4.14.2 to resolve CVE-2026-63374 [(#12848)](https://github.com/prowler-cloud/prowler/pull/12848) + +--- + ## [1.43.0] (Prowler v5.42.0) ### 🔄 Changed diff --git a/api/changelog.d/api-anyio-cve-2026-63374.security.md b/api/changelog.d/api-anyio-cve-2026-63374.security.md deleted file mode 100644 index 4298c771df..0000000000 --- a/api/changelog.d/api-anyio-cve-2026-63374.security.md +++ /dev/null @@ -1 +0,0 @@ -Bumped `anyio` to 4.14.2 to resolve CVE-2026-63374 diff --git a/api/changelog.d/api-image-debian-cves.security.md b/api/changelog.d/api-image-debian-cves.security.md deleted file mode 100644 index 2d8b0403ad..0000000000 --- a/api/changelog.d/api-image-debian-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`libsqlite3-0`, `gzip`, `perl-base` and `libpcre2-8-0` upgraded in the API container image, patching high Debian CVEs diff --git a/api/changelog.d/api-image-powershell-dotnet-cve.security.md b/api/changelog.d/api-image-powershell-dotnet-cve.security.md deleted file mode 100644 index 28b91a32a0..0000000000 --- a/api/changelog.d/api-image-powershell-dotnet-cve.security.md +++ /dev/null @@ -1 +0,0 @@ -PowerShell from 7.5.9 to 7.5.11 in the API container image, bundling .NET runtime 9.0.20 and patching CVE-2026-62901 diff --git a/api/changelog.d/lapsed-invitations-block-re-invites.fixed.md b/api/changelog.d/lapsed-invitations-block-re-invites.fixed.md deleted file mode 100644 index 29a8e99235..0000000000 --- a/api/changelog.d/lapsed-invitations-block-re-invites.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Lapsed pending invitations are reported as expired and no longer block a new invitation for the same email diff --git a/api/changelog.d/report-download-public-storage-endpoint.fixed.md b/api/changelog.d/report-download-public-storage-endpoint.fixed.md deleted file mode 100644 index 87004d8a56..0000000000 --- a/api/changelog.d/report-download-public-storage-endpoint.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Report download URLs can be signed against a browser-reachable storage host via `DJANGO_OUTPUT_S3_AWS_PUBLIC_ENDPOINT_URL`, so downloads complete on deployments where storage is only reachable inside the container network diff --git a/api/changelog.d/s3-client-default-region.fixed.md b/api/changelog.d/s3-client-default-region.fixed.md deleted file mode 100644 index 62efc579f2..0000000000 --- a/api/changelog.d/s3-client-default-region.fixed.md +++ /dev/null @@ -1 +0,0 @@ -A scan report download no longer fails with a server error when `DJANGO_OUTPUT_S3_AWS_DEFAULT_REGION` is unset, which is common on storage with no meaningful region diff --git a/mcp_server/CHANGELOG.md b/mcp_server/CHANGELOG.md index 80bdabd28a..07e92992fc 100644 --- a/mcp_server/CHANGELOG.md +++ b/mcp_server/CHANGELOG.md @@ -4,6 +4,14 @@ All notable changes to the **Prowler MCP Server** are documented in this file. +## [0.12.2] (Prowler v5.43.0) + +### 🔐 Security + +- Bumped `anyio` to 4.14.2 to resolve CVE-2026-63374 [(#12848)](https://github.com/prowler-cloud/prowler/pull/12848) + +--- + ## [0.12.1] (Prowler v5.42.0) ### 🔐 Security diff --git a/mcp_server/changelog.d/mcp-anyio-cve-2026-63374.security.md b/mcp_server/changelog.d/mcp-anyio-cve-2026-63374.security.md deleted file mode 100644 index 4298c771df..0000000000 --- a/mcp_server/changelog.d/mcp-anyio-cve-2026-63374.security.md +++ /dev/null @@ -1 +0,0 @@ -Bumped `anyio` to 4.14.2 to resolve CVE-2026-63374 diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 7232bd41a0..3a7bc157bf 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -4,6 +4,34 @@ All notable changes to the **Prowler SDK** are documented in this file. +## [5.43.0] (Prowler v5.43.0) + +### 🚀 Added + +- `FedRAMP-20x-KSI` universal compliance framework (`fedramp_20x_ksi_2026`) with the 46 Key Security Indicators from the FedRAMP Consolidated Rules 2026 mapped for AWS, Azure, GCP, Kubernetes and M365 [(#11701)](https://github.com/prowler-cloud/prowler/pull/11701) +- `smn_topic_subscriptions` check for Huawei Cloud provider: SMN topics have at least one subscription configured [(#12186)](https://github.com/prowler-cloud/prowler/pull/12186) +- `inspector2_coverage_scan_status_active`, `inspector2_coverage_recently_scanned`, `inspector2_active_findings_no_known_exploited_vulnerabilities`, `inspector2_active_findings_kev_within_due_date`, `inspector2_active_findings_within_max_age`, `elbv2_listener_fips_tls_enabled` and `transfer_server_fips_security_policy_enabled` checks for AWS provider, covering FedRAMP 20x Class C vulnerability detection, CISA KEV remediation and FIPS cryptography rules; the KEV checks require `inspector2:BatchGetFindingDetails`, now in the Prowler additions policy [(#12808)](https://github.com/prowler-cloud/prowler/pull/12808) +- `FedRAMP-20x-FRR-Class-C` universal compliance framework (`fedramp_20x_frr_class_c_2026`) with the 158 provider rules of the FedRAMP 20x Class C ruleset from the FedRAMP Consolidated Rules 2026 for AWS, Azure, GCP, Kubernetes and M365 [(#12808)](https://github.com/prowler-cloud/prowler/pull/12808) + +### 🔄 Changed + +- FedRAMP 20x Phase One pilot frameworks `fedramp_20x_ksi_low_aws`, `fedramp_20x_ksi_low_azure` and `fedramp_20x_ksi_low_gcp` replaced by `fedramp_20x_ksi_2026` [(#12855)](https://github.com/prowler-cloud/prowler/pull/12855) + +### 🐞 Fixed + +- `security_2sv_enforced` reports domain-wide 2-Step Verification failures as FAIL even when every failing setting is overridden for a group or organizational unit [(#12700)](https://github.com/prowler-cloud/prowler/pull/12700) +- Bootstrap STS calls now try up to two more regions of the partition declared in `PROWLER_AWS_PARTITION` when the first one cannot be reached, so a deployment that routes to only one region of its partition no longer fails on an endpoint it has no path to. This covers validating credentials, assuming a role and getting an MFA session token [(#12799)](https://github.com/prowler-cloud/prowler/pull/12799) +- `KeyError` in M365 Defender malware, anti-phishing and inbound anti-spam checks when the tenant has Standard or Strict preset security policies [(#12809)](https://github.com/prowler-cloud/prowler/pull/12809) +- Azure Defender security contacts and Key Vault key rotation policies now use the endpoints of the selected cloud (`--azure-region`) instead of the hardcoded `management.azure.com` and `vault.azure.net` hosts, so both work on `AzureUSGovernment` and `AzureChinaCloud` [(#12813)](https://github.com/prowler-cloud/prowler/pull/12813) + +### 🔐 Security + +- `libsqlite3-0`, `gzip`, `perl-base`, `libssh2-1t64` and `libpcre2-8-0` upgraded in the SDK container image, patching nine high Debian CVEs [(#12804)](https://github.com/prowler-cloud/prowler/pull/12804) +- PowerShell from 7.5.9 to 7.5.11 in the SDK container image, bundling .NET runtime 9.0.20 and patching CVE-2026-62901 [(#12811)](https://github.com/prowler-cloud/prowler/pull/12811) +- Bumped `anyio` to 4.14.2 to resolve CVE-2026-63374 [(#12848)](https://github.com/prowler-cloud/prowler/pull/12848) + +--- + ## [5.42.0] (Prowler v5.42.0) ### 🚀 Added diff --git a/prowler/changelog.d/aws-inspector2-fips-checks.added.md b/prowler/changelog.d/aws-inspector2-fips-checks.added.md deleted file mode 100644 index 40c36f8062..0000000000 --- a/prowler/changelog.d/aws-inspector2-fips-checks.added.md +++ /dev/null @@ -1 +0,0 @@ -`inspector2_coverage_scan_status_active`, `inspector2_coverage_recently_scanned`, `inspector2_active_findings_no_known_exploited_vulnerabilities`, `inspector2_active_findings_kev_within_due_date`, `inspector2_active_findings_within_max_age`, `elbv2_listener_fips_tls_enabled` and `transfer_server_fips_security_policy_enabled` checks for AWS provider, covering FedRAMP 20x Class C vulnerability detection, CISA KEV remediation and FIPS cryptography rules; the KEV checks require `inspector2:BatchGetFindingDetails`, now in the Prowler additions policy diff --git a/prowler/changelog.d/aws-partition-bootstrap-falls-back-to-the-next-region.fixed.md b/prowler/changelog.d/aws-partition-bootstrap-falls-back-to-the-next-region.fixed.md deleted file mode 100644 index 4bd9c855d1..0000000000 --- a/prowler/changelog.d/aws-partition-bootstrap-falls-back-to-the-next-region.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Bootstrap STS calls now try up to two more regions of the partition declared in `PROWLER_AWS_PARTITION` when the first one cannot be reached, so a deployment that routes to only one region of its partition no longer fails on an endpoint it has no path to. This covers validating credentials, assuming a role and getting an MFA session token diff --git a/prowler/changelog.d/azure-sovereign-cloud-defender-keyvault-hosts.fixed.md b/prowler/changelog.d/azure-sovereign-cloud-defender-keyvault-hosts.fixed.md deleted file mode 100644 index 99ef3354e0..0000000000 --- a/prowler/changelog.d/azure-sovereign-cloud-defender-keyvault-hosts.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Azure Defender security contacts and Key Vault key rotation policies now use the endpoints of the selected cloud (`--azure-region`) instead of the hardcoded `management.azure.com` and `vault.azure.net` hosts, so both work on `AzureUSGovernment` and `AzureChinaCloud` diff --git a/prowler/changelog.d/fedramp-20x-frr-class-c-2026.added.md b/prowler/changelog.d/fedramp-20x-frr-class-c-2026.added.md deleted file mode 100644 index 147ad052f3..0000000000 --- a/prowler/changelog.d/fedramp-20x-frr-class-c-2026.added.md +++ /dev/null @@ -1 +0,0 @@ -`FedRAMP-20x-FRR-Class-C` universal compliance framework (`fedramp_20x_frr_class_c_2026`) with the 158 provider rules of the FedRAMP 20x Class C ruleset from the FedRAMP Consolidated Rules 2026 for AWS, Azure, GCP, Kubernetes and M365 diff --git a/prowler/changelog.d/fedramp-20x-ksi-2026.added.md b/prowler/changelog.d/fedramp-20x-ksi-2026.added.md deleted file mode 100644 index 5fae5bb4a2..0000000000 --- a/prowler/changelog.d/fedramp-20x-ksi-2026.added.md +++ /dev/null @@ -1 +0,0 @@ -`FedRAMP-20x-KSI` universal compliance framework (`fedramp_20x_ksi_2026`) with the 46 Key Security Indicators from the FedRAMP Consolidated Rules 2026 mapped for AWS, Azure, GCP, Kubernetes and M365 diff --git a/prowler/changelog.d/fedramp-20x-ksi-low-pilot.changed.md b/prowler/changelog.d/fedramp-20x-ksi-low-pilot.changed.md deleted file mode 100644 index d6670c283d..0000000000 --- a/prowler/changelog.d/fedramp-20x-ksi-low-pilot.changed.md +++ /dev/null @@ -1 +0,0 @@ -FedRAMP 20x Phase One pilot frameworks `fedramp_20x_ksi_low_aws`, `fedramp_20x_ksi_low_azure` and `fedramp_20x_ksi_low_gcp` replaced by `fedramp_20x_ksi_2026` diff --git a/prowler/changelog.d/googleworkspace-2sv-all-users-overrides.fixed.md b/prowler/changelog.d/googleworkspace-2sv-all-users-overrides.fixed.md deleted file mode 100644 index 1283ac91ad..0000000000 --- a/prowler/changelog.d/googleworkspace-2sv-all-users-overrides.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`security_2sv_enforced` reports domain-wide 2-Step Verification failures as FAIL even when every failing setting is overridden for a group or organizational unit diff --git a/prowler/changelog.d/m365-defender-preset-policy-keyerror.fixed.md b/prowler/changelog.d/m365-defender-preset-policy-keyerror.fixed.md deleted file mode 100644 index 2a50037e84..0000000000 --- a/prowler/changelog.d/m365-defender-preset-policy-keyerror.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`KeyError` in M365 Defender malware, anti-phishing and inbound anti-spam checks when the tenant has Standard or Strict preset security policies diff --git a/prowler/changelog.d/sdk-anyio-cve-2026-63374.security.md b/prowler/changelog.d/sdk-anyio-cve-2026-63374.security.md deleted file mode 100644 index 4298c771df..0000000000 --- a/prowler/changelog.d/sdk-anyio-cve-2026-63374.security.md +++ /dev/null @@ -1 +0,0 @@ -Bumped `anyio` to 4.14.2 to resolve CVE-2026-63374 diff --git a/prowler/changelog.d/sdk-image-debian-cves.security.md b/prowler/changelog.d/sdk-image-debian-cves.security.md deleted file mode 100644 index 50bd4186f3..0000000000 --- a/prowler/changelog.d/sdk-image-debian-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`libsqlite3-0`, `gzip`, `perl-base`, `libssh2-1t64` and `libpcre2-8-0` upgraded in the SDK container image, patching nine high Debian CVEs diff --git a/prowler/changelog.d/sdk-image-powershell-dotnet-cve.security.md b/prowler/changelog.d/sdk-image-powershell-dotnet-cve.security.md deleted file mode 100644 index 370aa37289..0000000000 --- a/prowler/changelog.d/sdk-image-powershell-dotnet-cve.security.md +++ /dev/null @@ -1 +0,0 @@ -PowerShell from 7.5.9 to 7.5.11 in the SDK container image, bundling .NET runtime 9.0.20 and patching CVE-2026-62901 diff --git a/prowler/changelog.d/smn-topic-subscriptions.added.md b/prowler/changelog.d/smn-topic-subscriptions.added.md deleted file mode 100644 index 87ca0c8c28..0000000000 --- a/prowler/changelog.d/smn-topic-subscriptions.added.md +++ /dev/null @@ -1 +0,0 @@ -`smn_topic_subscriptions` check for Huawei Cloud provider: SMN topics have at least one subscription configured diff --git a/ui/CHANGELOG.md b/ui/CHANGELOG.md index 8687ddde54..9ea71d69e9 100644 --- a/ui/CHANGELOG.md +++ b/ui/CHANGELOG.md @@ -4,6 +4,24 @@ All notable changes to the **Prowler UI** are documented in this file. +## [1.43.0] (Prowler v5.43.0) + +### 🚀 Added + +- Registry marketplace and external provider onboarding for Private Cloud, with permission-based access independent of billing, confirmed artifact installation, schema-driven credentials, connection checks, and scan launch [(#12494)](https://github.com/prowler-cloud/prowler/pull/12494) +- AWS Marketplace button variant with outlined styling for light and dark themes [(#12803)](https://github.com/prowler-cloud/prowler/pull/12803) +- `UI_SELF_REGISTRATION_ENABLED` flag for Prowler Private Cloud deployments; when `"false"`, `/sign-up` only opens with an invitation, the sign-in page drops the "Sign up" link and the profile hides **Create organization** [(#12815)](https://github.com/prowler-cloud/prowler/pull/12815) +- "Invite your team" step offered once after the first provider is connected, before the onboarding checkpoint, reusing the invitation form tagged with `source=onboarding` [(#12819)](https://github.com/prowler-cloud/prowler/pull/12819) + +### 🐞 Fixed + +- Automatic onboarding stays hidden on billing pages and remains available after leaving billing [(#12803)](https://github.com/prowler-cloud/prowler/pull/12803) +- Per-provider breakdown and OCSF download for FedRAMP 20x KSI and Class C FRR in the cross-provider compliance view [(#12810)](https://github.com/prowler-cloud/prowler/pull/12810) +- Edit and Revoke actions are disabled for expired and revoked invitations [(#12831)](https://github.com/prowler-cloud/prowler/pull/12831) +- Cloudflare API token links in the provider wizard request the SSL and Certificates, Bot Management and Zone WAF read permissions the scan needs [(#12842)](https://github.com/prowler-cloud/prowler/pull/12842) + +--- + ## [1.42.0] (Prowler v5.42.0) ### 🚀 Added diff --git a/ui/changelog.d/aws-marketplace-button.added.md b/ui/changelog.d/aws-marketplace-button.added.md deleted file mode 100644 index 235112967f..0000000000 --- a/ui/changelog.d/aws-marketplace-button.added.md +++ /dev/null @@ -1 +0,0 @@ -AWS Marketplace button variant with outlined styling for light and dark themes diff --git a/ui/changelog.d/cloudflare-token-permissions.fixed.md b/ui/changelog.d/cloudflare-token-permissions.fixed.md deleted file mode 100644 index 9a862ee88c..0000000000 --- a/ui/changelog.d/cloudflare-token-permissions.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Cloudflare API token links in the provider wizard request the SSL and Certificates, Bot Management and Zone WAF read permissions the scan needs diff --git a/ui/changelog.d/defer-onboarding-on-billing.fixed.md b/ui/changelog.d/defer-onboarding-on-billing.fixed.md deleted file mode 100644 index 5afcc36bcc..0000000000 --- a/ui/changelog.d/defer-onboarding-on-billing.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Automatic onboarding stays hidden on billing pages and remains available after leaving billing diff --git a/ui/changelog.d/disable-self-registration.added.md b/ui/changelog.d/disable-self-registration.added.md deleted file mode 100644 index 46e62eb1b3..0000000000 --- a/ui/changelog.d/disable-self-registration.added.md +++ /dev/null @@ -1 +0,0 @@ -`UI_SELF_REGISTRATION_ENABLED` flag for Prowler Private Cloud deployments; when `"false"`, `/sign-up` only opens with an invitation, the sign-in page drops the "Sign up" link and the profile hides **Create organization** diff --git a/ui/changelog.d/fedramp-20x-cross-provider-breakdown.fixed.md b/ui/changelog.d/fedramp-20x-cross-provider-breakdown.fixed.md deleted file mode 100644 index dc7c71ce1b..0000000000 --- a/ui/changelog.d/fedramp-20x-cross-provider-breakdown.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Per-provider breakdown and OCSF download for FedRAMP 20x KSI and Class C FRR in the cross-provider compliance view diff --git a/ui/changelog.d/invitation-row-actions-non-pending.fixed.md b/ui/changelog.d/invitation-row-actions-non-pending.fixed.md deleted file mode 100644 index dda0527b0d..0000000000 --- a/ui/changelog.d/invitation-row-actions-non-pending.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Edit and Revoke actions are disabled for expired and revoked invitations diff --git a/ui/changelog.d/onboarding-invite-step.added.md b/ui/changelog.d/onboarding-invite-step.added.md deleted file mode 100644 index c2220888b5..0000000000 --- a/ui/changelog.d/onboarding-invite-step.added.md +++ /dev/null @@ -1 +0,0 @@ -"Invite your team" step offered once after the first provider is connected, before the onboarding checkpoint, reusing the invitation form tagged with `source=onboarding` diff --git a/ui/changelog.d/registry-private-cloud.added.md b/ui/changelog.d/registry-private-cloud.added.md deleted file mode 100644 index 0f5b9fb6d3..0000000000 --- a/ui/changelog.d/registry-private-cloud.added.md +++ /dev/null @@ -1 +0,0 @@ -Registry marketplace and external provider onboarding for Private Cloud, with permission-based access independent of billing, confirmed artifact installation, schema-driven credentials, connection checks, and scan launch