diff --git a/.github/workflows/api-container-checks.yml b/.github/workflows/api-container-checks.yml
index 4798fd9df7..f8d5df5417 100644
--- a/.github/workflows/api-container-checks.yml
+++ b/.github/workflows/api-container-checks.yml
@@ -92,6 +92,8 @@ jobs:
_http._tcp.deb.debian.org:443
powershellinfraartifacts-gkhedzdeaghdezhr.z01.azurefd.net:443
get.trivy.dev:443
+ raw.githubusercontent.com:443
+ releases.astral.sh:443
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
diff --git a/.github/workflows/renovate-config-validate.yml b/.github/workflows/renovate-config-validate.yml
index 8426efa6b4..daed2353c1 100644
--- a/.github/workflows/renovate-config-validate.yml
+++ b/.github/workflows/renovate-config-validate.yml
@@ -34,6 +34,7 @@ jobs:
allowed-endpoints: >
api.github.com:443
github.com:443
+ raw.githubusercontent.com:443
objects.githubusercontent.com:443
codeload.github.com:443
release-assets.githubusercontent.com:443
@@ -41,6 +42,7 @@ jobs:
files.pythonhosted.org:443
registry.npmjs.org:443
nodejs.org:443
+ releases.astral.sh:443
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
diff --git a/.github/workflows/sdk-container-checks.yml b/.github/workflows/sdk-container-checks.yml
index 709a785974..1e2e092dbc 100644
--- a/.github/workflows/sdk-container-checks.yml
+++ b/.github/workflows/sdk-container-checks.yml
@@ -94,6 +94,8 @@ jobs:
_http._tcp.deb.debian.org:443
powershellinfraartifacts-gkhedzdeaghdezhr.z01.azurefd.net:443
get.trivy.dev:443
+ raw.githubusercontent.com:443
+ releases.astral.sh:443
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
diff --git a/.trivyignore b/.trivyignore
index 744c94a193..c0207c8374 100644
--- a/.trivyignore
+++ b/.trivyignore
@@ -15,21 +15,32 @@
# neither vulnerable code path (Archive::Tar parsing or regex compilation of
# attacker-controlled input) is reachable from Prowler. No Debian bookworm fix
# is available yet.
-CVE-2026-42496 pkg:perl exp:2026-07-15
-CVE-2026-42496 pkg:perl-base exp:2026-07-15
-CVE-2026-42496 pkg:perl-modules-5.36 exp:2026-07-15
-CVE-2026-42496 pkg:libperl5.36 exp:2026-07-15
-CVE-2026-8376 pkg:perl exp:2026-07-15
-CVE-2026-8376 pkg:perl-base exp:2026-07-15
-CVE-2026-8376 pkg:perl-modules-5.36 exp:2026-07-15
-CVE-2026-8376 pkg:libperl5.36 exp:2026-07-15
+CVE-2026-42496 pkg:perl exp:2026-08-15
+CVE-2026-42496 pkg:perl-base exp:2026-08-15
+CVE-2026-42496 pkg:perl-modules-5.36 exp:2026-08-15
+CVE-2026-42496 pkg:libperl5.36 exp:2026-08-15
+CVE-2026-8376 pkg:perl exp:2026-08-15
+CVE-2026-8376 pkg:perl-base exp:2026-08-15
+CVE-2026-8376 pkg:perl-modules-5.36 exp:2026-08-15
+CVE-2026-8376 pkg:libperl5.36 exp:2026-08-15
+
+# CVE-2026-13221 - Perl regex trie overflow.
+# Packages: perl, perl-base, perl-modules-5.36, libperl5.36.
+# Why ignored: upstream confirms Perl 5.36.0 is not affected; the regression
+# was introduced after this version. Debian currently marks bookworm as
+# vulnerable, which causes Trivy to report a false positive.
+# Ref: https://github.com/Perl/perl5/issues/23388
+CVE-2026-13221 pkg:perl exp:2026-08-15
+CVE-2026-13221 pkg:perl-base exp:2026-08-15
+CVE-2026-13221 pkg:perl-modules-5.36 exp:2026-08-15
+CVE-2026-13221 pkg:libperl5.36 exp:2026-08-15
# CVE-2025-7458 — SQLite integer overflow.
# Package: libsqlite3-0.
# Why ignored: transitive dependency of CPython's stdlib sqlite3 module. The
# Prowler SDK does not open user-supplied SQLite databases; SQLite usage is
# internal and bounded. No Debian bookworm fix is available.
-CVE-2025-7458 pkg:libsqlite3-0 exp:2026-07-15
+CVE-2025-7458 pkg:libsqlite3-0 exp:2026-08-15
# CVE-2026-43185 — Linux kernel ksmbd signedness bug.
# Package: linux-libc-dev.
@@ -37,7 +48,7 @@ CVE-2025-7458 pkg:libsqlite3-0 exp:2026-07-15
# not a running kernel. Containers execute against the host kernel, so these
# headers are inert at runtime. The upstream fix landed in kernel 7.0-rc2 and
# has not been backported to Debian's 6.1 LTS line.
-CVE-2026-43185 pkg:linux-libc-dev exp:2026-07-15
+CVE-2026-43185 pkg:linux-libc-dev exp:2026-08-15
# CVE-2023-45853 — zlib MiniZip integer overflow / heap overflow in
# zipOpenNewFileInZip4_64.
@@ -49,8 +60,8 @@ CVE-2026-43185 pkg:linux-libc-dev exp:2026-07-15
# zlib 1.3.1, available in Debian trixie (13); migrating the base image would
# clear it fully.
# Ref: https://security-tracker.debian.org/tracker/CVE-2023-45853
-CVE-2023-45853 pkg:zlib1g exp:2026-07-15
-CVE-2023-45853 pkg:zlib1g-dev exp:2026-07-15
+CVE-2023-45853 pkg:zlib1g exp:2026-08-15
+CVE-2023-45853 pkg:zlib1g-dev exp:2026-08-15
# CVE-2026-55200 — libssh2 out-of-bounds write in ssh2_transport_read() due to
# an unchecked packet_length field in transport.c (heap corruption, possible RCE).
@@ -63,7 +74,7 @@ CVE-2023-45853 pkg:zlib1g-dev exp:2026-07-15
# affected code is unreachable at runtime. Fixed upstream in libssh2 commit
# 97acf3df (PR #2052); no Debian bookworm fix is available yet.
# Ref: https://security-tracker.debian.org/tracker/CVE-2026-55200
-CVE-2026-55200 pkg:libssh2-1 exp:2026-07-15
+CVE-2026-55200 pkg:libssh2-1 exp:2026-08-15
# --- API container image (api/Dockerfile) ---
# The entries below are specific to the Prowler API image, which ships
@@ -78,13 +89,13 @@ CVE-2026-55200 pkg:libssh2-1 exp:2026-07-15
# at runtime. The vulnerable path requires parsing attacker-controlled XML with
# the affected interpreter, which Prowler does not do with the system Python.
# Full mitigation also needs libexpat >= 2.8.0; no Debian bookworm fix yet.
-CVE-2026-7210 pkg:python3.11 exp:2026-07-15
-CVE-2026-7210 pkg:python3.11-dev exp:2026-07-15
-CVE-2026-7210 pkg:python3.11-minimal exp:2026-07-15
-CVE-2026-7210 pkg:libpython3.11 exp:2026-07-15
-CVE-2026-7210 pkg:libpython3.11-dev exp:2026-07-15
-CVE-2026-7210 pkg:libpython3.11-minimal exp:2026-07-15
-CVE-2026-7210 pkg:libpython3.11-stdlib exp:2026-07-15
+CVE-2026-7210 pkg:python3.11 exp:2026-08-15
+CVE-2026-7210 pkg:python3.11-dev exp:2026-08-15
+CVE-2026-7210 pkg:python3.11-minimal exp:2026-08-15
+CVE-2026-7210 pkg:libpython3.11 exp:2026-08-15
+CVE-2026-7210 pkg:libpython3.11-dev exp:2026-08-15
+CVE-2026-7210 pkg:libpython3.11-minimal exp:2026-08-15
+CVE-2026-7210 pkg:libpython3.11-stdlib exp:2026-08-15
# CVE-2026-33278 — Unbound DNSSEC validator use-after-free (DoS, possible RCE).
# CVE-2026-42960 — Unbound DNS cache poisoning via promiscuous additional records.
@@ -94,5 +105,5 @@ CVE-2026-7210 pkg:libpython3.11-stdlib exp:2026-07-15
# vulnerabilities require operating a live Unbound recursive DNSSEC validator
# that processes attacker-influenced DNS responses. Prowler never starts an
# Unbound resolver, so neither code path is reachable. No Debian bookworm fix yet.
-CVE-2026-33278 pkg:libunbound8 exp:2026-07-15
-CVE-2026-42960 pkg:libunbound8 exp:2026-07-15
+CVE-2026-33278 pkg:libunbound8 exp:2026-08-15
+CVE-2026-42960 pkg:libunbound8 exp:2026-08-15
diff --git a/README.md b/README.md
index 50df95484f..c58d903c08 100644
--- a/README.md
+++ b/README.md
@@ -3,7 +3,7 @@
- Prowler is the Open Cloud Security Platform trusted by thousands to automate security and compliance in any cloud environment. With hundreds of ready-to-use checks and compliance frameworks, Prowler delivers real-time, customizable monitoring and seamless integrations, making cloud security simple, scalable, and cost-effective for organizations of any size. + Prowler is the Open Cloud Security Platform trusted by thousands to automate security and compliance in any cloud environment. With thousands of ready-to-use checks and compliance frameworks, Prowler delivers real-time, customizable monitoring and seamless integrations, making cloud security simple, scalable, and cost-effective for organizations of any size.
Secure ANY cloud at AI Speed at prowler.com
@@ -21,7 +21,7 @@
-
+
@@ -62,7 +62,7 @@ Review findings during scan execution in the following sections:
- **Compliance** – Displays compliance insights based on security frameworks.
-> For detailed usage instructions, refer to the [Prowler App Guide](/user-guide/tutorials/prowler-app).
+> For detailed usage instructions, refer to the [Prowler Cloud guide](/user-guide/tutorials/prowler-app), which also applies to Prowler Local Server.
diff --git a/docs/user-guide/providers/github/authentication.mdx b/docs/user-guide/providers/github/authentication.mdx
index 0b5ab6b720..1546bf284a 100644
--- a/docs/user-guide/providers/github/authentication.mdx
+++ b/docs/user-guide/providers/github/authentication.mdx
@@ -12,7 +12,7 @@ Prowler offers three authentication methods. Fine-Grained Personal Access Tokens
| Method | Best For | Key Benefit |
|--------|----------|-------------|
-| [**Fine-Grained Personal Access Token**](#fine-grained-personal-access-token-recommended) | Individual users, quick setup | Simple, user-scoped access |
+| [**Fine-Grained Personal Access Token**](#fine-grained-personal-access-token-recommended-for-individual-use) | Individual users, quick setup | Simple, user-scoped access |
| [**GitHub App**](#github-app-credentials) | Organizations, automation, CI/CD | Organization-scoped, no personal account dependency |
| [**OAuth App Token**](#oauth-app-token) | Delegated user authorization | User-consented access flows |
@@ -271,7 +271,7 @@ Store the `.pem` private key securely. Anyone with this key can authenticate as
## Prowler Cloud Authentication
-For step-by-step setup instructions for Prowler Cloud, see the [Getting Started Guide](/user-guide/providers/github/getting-started-github#prowler-cloudapp).
+For step-by-step setup instructions for Prowler Cloud, see the [Getting Started Guide](/user-guide/providers/github/getting-started-github#prowler-cloud-and-prowler-local-server).
### Using Personal Access Token
@@ -301,7 +301,7 @@ For step-by-step setup instructions for Prowler Cloud, see the [Getting Started
3. Enter your GitHub App ID and upload the private key (`.pem` file).
-For complete step-by-step instructions, see the [Getting Started Guide](/user-guide/providers/github/getting-started-github#prowler-cloudapp).
+For complete step-by-step instructions, see the [Getting Started Guide](/user-guide/providers/github/getting-started-github#prowler-cloud-and-prowler-local-server).
---
diff --git a/docs/user-guide/providers/github/getting-started-github.mdx b/docs/user-guide/providers/github/getting-started-github.mdx
index 079f9a1d7b..09acdfe0c9 100644
--- a/docs/user-guide/providers/github/getting-started-github.mdx
+++ b/docs/user-guide/providers/github/getting-started-github.mdx
@@ -16,7 +16,7 @@ Prowler can scan either:
## Configuring Social Login Credentials
diff --git a/docs/user-guide/tutorials/prowler-app-sso-entra.mdx b/docs/user-guide/tutorials/prowler-app-sso-entra.mdx
index 37f3bbdda5..07cf4709be 100644
--- a/docs/user-guide/tutorials/prowler-app-sso-entra.mdx
+++ b/docs/user-guide/tutorials/prowler-app-sso-entra.mdx
@@ -2,7 +2,11 @@
title: 'Entra ID Configuration'
---
-This page provides instructions for creating and configuring a Microsoft Entra ID (formerly Azure AD) application to use SAML SSO with Prowler App.
+import { AppliesTo } from "/snippets/applies-to.mdx"
+
+
@@ -84,7 +85,7 @@ For detailed instructions on configuring credentials for each provider, refer to
diff --git a/docs/user-guide/tutorials/prowler-cloud-aws-organizations.mdx b/docs/user-guide/tutorials/prowler-cloud-aws-organizations.mdx
index 2a6128e92e..8bb6e320ae 100644
--- a/docs/user-guide/tutorials/prowler-cloud-aws-organizations.mdx
+++ b/docs/user-guide/tutorials/prowler-cloud-aws-organizations.mdx
@@ -1,5 +1,5 @@
---
-title: 'AWS Organizations in Prowler Cloud'
+title: 'AWS Organizations'
description: 'Onboard all AWS accounts in your Organization through a single guided wizard'
---
@@ -464,7 +464,7 @@ Each AWS account you connect through the Organizations wizard counts as one **pr
- **Large organizations**: connecting a 500-account organization will result in up to 500 providers on your subscription. Review your plan limits before proceeding.
- **Deleted providers**: if you later remove an account, the deleted provider no longer counts toward your subscription.
-For pricing details, see [Prowler Cloud Pricing](/getting-started/products/prowler-cloud-pricing).
+For pricing details, see [Prowler Cloud Pricing](https://prowler.com/pricing).
## Troubleshooting
@@ -505,7 +505,7 @@ No accounts pass the connection test.
- Verify the CloudFormation StackSet was deployed — complete [Step 2](#step-2-deploy-the-cloudformation-stackset) and wait for stack instances to reach **CREATE_COMPLETE**
- Check that the **ExternalId** parameter in the StackSet matches the External ID shown in the Prowler wizard
-- If your accounts use IP-based IAM policies, allow [Prowler Cloud public IPs](/user-guide/tutorials/prowler-cloud-public-ips)
+- If your accounts use IP-based IAM policies, allow [Prowler Cloud egress IPs](/security/networking)
### Connection Test Fails for Some Accounts
diff --git a/docs/user-guide/tutorials/prowler-cloud-azure-management-groups.mdx b/docs/user-guide/tutorials/prowler-cloud-azure-management-groups.mdx
new file mode 100644
index 0000000000..98cfe095ce
--- /dev/null
+++ b/docs/user-guide/tutorials/prowler-cloud-azure-management-groups.mdx
@@ -0,0 +1,11 @@
+---
+title: 'Azure Management Groups'
+description: 'Onboard all Azure subscriptions in your management groups through a single guided wizard'
+tag: "Coming Soon"
+---
+
+Onboarding Azure management groups through a single guided wizard is coming soon to Prowler Cloud.
+
+Today, Azure subscriptions are onboarded individually. See [Getting Started with Azure](/user-guide/providers/azure/getting-started-azure) and [Bulk Provider Provisioning](/user-guide/tutorials/bulk-provider-provisioning) to automate onboarding multiple subscriptions.
+
+Keep an eye on the [changelog](https://github.com/prowler-cloud/prowler/releases) for updates.
diff --git a/docs/user-guide/tutorials/prowler-cloud-gcp-organizations.mdx b/docs/user-guide/tutorials/prowler-cloud-gcp-organizations.mdx
new file mode 100644
index 0000000000..c0c11747a9
--- /dev/null
+++ b/docs/user-guide/tutorials/prowler-cloud-gcp-organizations.mdx
@@ -0,0 +1,11 @@
+---
+title: 'GCP Organizations'
+description: 'Onboard all GCP projects in your organization through a single guided wizard'
+tag: "Coming Soon"
+---
+
+Onboarding a full GCP organization through a single guided wizard is coming soon to Prowler Cloud.
+
+Today, GCP projects are onboarded individually. See [Getting Started with GCP](/user-guide/providers/gcp/getting-started-gcp) and [Bulk Provider Provisioning](/user-guide/tutorials/bulk-provider-provisioning) to automate onboarding multiple projects.
+
+Keep an eye on the [changelog](https://github.com/prowler-cloud/prowler/releases) for updates.
diff --git a/docs/user-guide/tutorials/prowler-cloud-lighthouse-multi-llm.mdx b/docs/user-guide/tutorials/prowler-cloud-lighthouse-multi-llm.mdx
index ea19b1fe7f..0cb251df1f 100644
--- a/docs/user-guide/tutorials/prowler-cloud-lighthouse-multi-llm.mdx
+++ b/docs/user-guide/tutorials/prowler-cloud-lighthouse-multi-llm.mdx
@@ -1,5 +1,6 @@
---
title: 'Using Multiple LLM Providers'
+sidebarTitle: 'Multiple LLM Providers'
---
import { SubscriptionBanner } from "/snippets/subscription-banner.mdx"
diff --git a/docs/user-guide/tutorials/prowler-cloud-public-ips.mdx b/docs/user-guide/tutorials/prowler-cloud-public-ips.mdx
deleted file mode 100644
index f3b285056c..0000000000
--- a/docs/user-guide/tutorials/prowler-cloud-public-ips.mdx
+++ /dev/null
@@ -1,29 +0,0 @@
----
-title: 'Prowler Cloud Public IPs'
----
-
-## Overview
-
-Prowler Cloud uses a dedicated egress IPv4 address for all outbound connections to customer infrastructure. This enables organizations to implement network-level security controls by whitelisting Prowler's IP address.
-
-## Use Cases
-
-Whitelisting Prowler's egress IP address enables:
-
-- **Credential Usage Control**: Restrict where cloud provider credentials can be used from across AWS, Azure, GCP, and other providers
-- **Kubernetes Security**: Limit inbound HTTPS traffic to clusters by allowing only Prowler's IP address
-- **Compliance Requirements**: Meet security policies requiring allowlisting of external services
-
-## Query the Egress IP Address
-
-Retrieve Prowler Cloud's current egress IP address using the following command:
-
-```bash
-dig egress.prowler.com +short
-```
-
-This command returns the IPv4 address that Prowler Cloud uses for all outbound connections to customer infrastructure.
-
-
{label}
{highlight && (
-
{label}
{highlight && (
-
+ Prowler Cloud includes managed OpenAI access with no API keys to + provision, plus a hosted remote MCP server to automate security + workflows. +
+