From 623dc3125ab0b82f3b9371229b8ce10f8034a69e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Mon, 7 Sep 2026 19:11:56 +0200 Subject: [PATCH 01/16] chore(codeowners): consolidate retired teams under engineering (#12755) --- .github/CODEOWNERS | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index ed97ff5a1a..dc1e714b47 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,23 +1,23 @@ # SDK -/* @prowler-cloud/detection-remediation -/prowler/ @prowler-cloud/detection-remediation -/tests/ @prowler-cloud/detection-remediation -/dashboard/ @prowler-cloud/detection-remediation -/docs/ @prowler-cloud/detection-remediation -/examples/ @prowler-cloud/detection-remediation -/util/ @prowler-cloud/detection-remediation -/contrib/ @prowler-cloud/detection-remediation -/permissions/ @prowler-cloud/detection-remediation -/codecov.yml @prowler-cloud/detection-remediation @prowler-cloud/api +/* @prowler-cloud/engineering +/prowler/ @prowler-cloud/engineering +/tests/ @prowler-cloud/engineering +/dashboard/ @prowler-cloud/engineering +/docs/ @prowler-cloud/engineering +/examples/ @prowler-cloud/engineering +/util/ @prowler-cloud/engineering +/contrib/ @prowler-cloud/engineering +/permissions/ @prowler-cloud/engineering +/codecov.yml @prowler-cloud/engineering # API -/api/ @prowler-cloud/api +/api/ @prowler-cloud/engineering # UI -/ui/ @prowler-cloud/ui +/ui/ @prowler-cloud/engineering # AI -/mcp_server/ @prowler-cloud/detection-remediation +/mcp_server/ @prowler-cloud/engineering # Platform /.github/ @prowler-cloud/platform From 2769cb98766c25902aacc803c2583a50b31f7f8e Mon Sep 17 00:00:00 2001 From: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com> Date: Tue, 8 Sep 2026 11:42:09 +0200 Subject: [PATCH 02/16] fix(ui): patch dependency vulnerabilities flagged by dependabot and pnpm audit (#12758) --- ...pendabot-audit-vulnerabilities.security.md | 1 + ui/dependency-log.json | 16 +- ui/package.json | 6 +- ui/pnpm-lock.yaml | 464 ++++++++++-------- ui/pnpm-workspace.yaml | 68 ++- 5 files changed, 332 insertions(+), 223 deletions(-) create mode 100644 ui/changelog.d/dependabot-audit-vulnerabilities.security.md diff --git a/ui/changelog.d/dependabot-audit-vulnerabilities.security.md b/ui/changelog.d/dependabot-audit-vulnerabilities.security.md new file mode 100644 index 0000000000..9d030097f0 --- /dev/null +++ b/ui/changelog.d/dependabot-audit-vulnerabilities.security.md @@ -0,0 +1 @@ +`nanoid` to 5.1.16, `js-yaml` to 4.3.1 and `postcss` to 8.5.23, plus transitive `hono`, `@hono/node-server`, `browserslist`, `qs`, `dompurify`, `brace-expansion`, `fast-uri`, `ip-address`, `mermaid`, `body-parser` and `@humanfs/node` to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low) diff --git a/ui/dependency-log.json b/ui/dependency-log.json index ee2d398248..556b50cdbb 100644 --- a/ui/dependency-log.json +++ b/ui/dependency-log.json @@ -442,10 +442,10 @@ { "section": "dependencies", "name": "js-yaml", - "from": "4.1.1", - "to": "4.3.0", + "from": "4.3.0", + "to": "4.3.1", "strategy": "installed", - "generatedAt": "2026-07-16T15:29:57.887Z" + "generatedAt": "2026-09-08T07:45:48.316Z" }, { "section": "dependencies", @@ -491,9 +491,9 @@ "section": "dependencies", "name": "nanoid", "from": "5.1.6", - "to": "5.1.6", + "to": "5.1.16", "strategy": "installed", - "generatedAt": "2025-12-10T11:34:11.122Z" + "generatedAt": "2026-09-08T07:45:48.316Z" }, { "section": "dependencies", @@ -930,10 +930,10 @@ { "section": "devDependencies", "name": "postcss", - "from": "8.4.38", - "to": "8.5.14", + "from": "8.5.14", + "to": "8.5.23", "strategy": "installed", - "generatedAt": "2026-05-14T10:09:04.901Z" + "generatedAt": "2026-09-08T07:45:48.316Z" }, { "section": "devDependencies", diff --git a/ui/package.json b/ui/package.json index 05bef52188..8101c117f5 100644 --- a/ui/package.json +++ b/ui/package.json @@ -90,13 +90,13 @@ "driver.js": "1.4.0", "framer-motion": "11.18.2", "import-in-the-middle": "3.3.1", - "js-yaml": "4.3.0", + "js-yaml": "4.3.1", "jwt-decode": "4.0.0", "langchain": "1.4.0", "lucide-react": "0.543.0", "marked": "15.0.12", "modern-screenshot": "4.7.0", - "nanoid": "5.1.6", + "nanoid": "5.1.16", "next": "16.2.11", "next-auth": "5.0.0-beta.32", "next-themes": "0.2.1", @@ -153,7 +153,7 @@ "jsdom": "27.4.0", "knip": "6.3.1", "msw": "2.13.4", - "postcss": "8.5.14", + "postcss": "8.5.23", "prettier": "3.6.2", "prettier-plugin-packagejson": "2.5.22", "prettier-plugin-tailwindcss": "0.6.14", diff --git a/ui/pnpm-lock.yaml b/ui/pnpm-lock.yaml index 6941491765..01200c3e6d 100644 --- a/ui/pnpm-lock.yaml +++ b/ui/pnpm-lock.yaml @@ -14,19 +14,19 @@ overrides: lodash: 4.18.1 sharp: 0.35.3 lodash-es: 4.18.1 - hono: 4.12.28 - '@hono/node-server': 1.19.14 + hono: 4.12.34 + '@hono/node-server': 1.19.17 '@isaacs/brace-expansion': 5.0.1 fast-xml-parser: 5.8.0 serialize-javascript: 7.0.5 - postcss: 8.5.14 + postcss: 8.5.23 esbuild: 0.28.1 rollup@>=4: 4.59.0 vite@>=7 <8: 7.3.5 ws@>=8 <9: 8.21.0 es-module-lexer: 2.3.0 '@babel/core': 7.29.7 - browserslist: 4.28.2 + browserslist: 4.28.7 caniuse-lite: 1.0.30001792 baseline-browser-mapping: 2.10.29 minimatch@<4: 3.1.4 @@ -34,10 +34,18 @@ overrides: minimatch@>=10: 10.2.3 ajv@<7: 6.14.0 ajv@>=8: 8.18.0 - qs: 6.15.2 + qs: 6.16.0 express-rate-limit: 8.5.1 uuid: 11.1.1 - dompurify: 3.4.11 + dompurify: 3.4.13 + brace-expansion@<2: 1.1.18 + brace-expansion@>=5: 5.0.9 + fast-uri: 3.1.6 + ip-address: 10.3.1 + mermaid: 11.16.1 + body-parser: 2.3.0 + '@humanfs/node': 0.16.8 + js-yaml: 4.3.1 importers: @@ -159,7 +167,7 @@ importers: version: 3.26.0(react@19.2.7) '@sentry/nextjs': specifier: 10.65.0 - version: 10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14)) + version: 10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) '@tailwindcss/postcss': specifier: 4.1.18 version: 4.1.18 @@ -209,8 +217,8 @@ importers: specifier: 3.3.1 version: 3.3.1 js-yaml: - specifier: 4.3.0 - version: 4.3.0 + specifier: 4.3.1 + version: 4.3.1 jwt-decode: specifier: 4.0.0 version: 4.0.0 @@ -227,8 +235,8 @@ importers: specifier: 4.7.0 version: 4.7.0 nanoid: - specifier: 5.1.6 - version: 5.1.6 + specifier: 5.1.16 + version: 5.1.16 next: specifier: 16.2.11 version: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) @@ -334,13 +342,13 @@ importers: version: 1.0.5 '@vitejs/plugin-react': specifier: 5.1.2 - version: 5.1.2(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + version: 5.1.2(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) '@vitest/browser': specifier: 4.1.10 - version: 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10) + version: 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10) '@vitest/browser-playwright': specifier: 4.1.10 - version: 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(playwright@1.56.1)(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10) + version: 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(playwright@1.56.1)(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10) '@vitest/coverage-v8': specifier: 4.1.10 version: 4.1.10(@vitest/browser@4.1.10)(vitest@4.1.10) @@ -393,8 +401,8 @@ importers: specifier: 2.13.4 version: 2.13.4(@types/node@24.10.8)(typescript@5.5.4) postcss: - specifier: 8.5.14 - version: 8.5.14 + specifier: 8.5.23 + version: 8.5.23 prettier: specifier: 3.6.2 version: 3.6.2 @@ -415,7 +423,7 @@ importers: version: 8.59.3(eslint@9.39.2(jiti@2.7.0))(typescript@5.5.4) vitest: specifier: 4.1.10 - version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + version: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) vitest-browser-react: specifier: 2.0.4 version: 2.0.4(@types/react-dom@19.2.3(@types/react@19.2.17))(@types/react@19.2.17)(react-dom@19.2.7(react@19.2.7))(react@19.2.7)(vitest@4.1.10) @@ -742,8 +750,8 @@ packages: '@blazediff/core@1.9.1': resolution: {integrity: sha512-ehg3jIkYKulZh+8om/O25vkvSsXXwC+skXmyA87FFx6A/45eqOkZsBltMw/TVteb0mloiGT8oGRTcjRAz66zaA==} - '@braintree/sanitize-url@7.1.1': - resolution: {integrity: sha512-i1L7noDNxtFyL5DmZafWy1wRVhGehQmzZaz1HiN5e7iylJMSZR7ekOV7NsIqa5qBldlLrsKv4HbgFUVlQrz8Mw==} + '@braintree/sanitize-url@7.1.2': + resolution: {integrity: sha512-jigsZK+sMF/cuiB7sERuo9V7N9jx+dhmHHnQyDSVdpZwVutaBu7WvNYqMDLSgFgfB30n452TP3vjDAvFC973mA==} '@cfworker/json-schema@4.1.1': resolution: {integrity: sha512-gAmrUZSGtKc3AiBL71iNWxDsyUC5uMaKKGdvzYsBoTW/xi42JQHl7eKV2OYzCUqvc+D2RCcf7EXY2iCyFIk6og==} @@ -757,8 +765,8 @@ packages: '@codemirror/commands@6.10.3': resolution: {integrity: sha512-JFRiqhKu+bvSkDLI+rUhJwSxQxYb759W5GBezE8Uc8mHLqC9aV/9aTC7yJSqCtB3F00pylrLCwnyS91Ap5ej4Q==} - '@codemirror/commands@6.10.4': - resolution: {integrity: sha512-Ryk9y9T0FFVF0cUGhAknveAyUOl/A1qReTFi+qPKtOh2Z9F4AUBz3XOrYD4ZEgZirdugVzHvd/2/Wcwy5OliTg==} + '@codemirror/commands@6.11.0': + resolution: {integrity: sha512-/K4Rl5BN0OtTiPWmJCdqODu38XnDMsDxKY5rgrPnCkutPTJf2wVbkoixLfealF5Kwse/s8P8M5jAiURiwSwnFA==} '@codemirror/language@6.12.2': resolution: {integrity: sha512-jEPmz2nGGDxhRTg3lTpzmIyGKxz3Gp3SJES4b0nAuE5SWQoKdT5GoQ69cwMmFd+wvFUhYirtDTr0/DRHpQAyWg==} @@ -772,8 +780,8 @@ packages: '@codemirror/state@6.6.0': resolution: {integrity: sha512-4nbvra5R5EtiCzr9BTHiTLc+MLXK2QGiAVYMyi8PkQd3SR+6ixar/Q/01Fa21TBIDOZXgeWV4WppsQolSreAPQ==} - '@codemirror/state@6.7.1': - resolution: {integrity: sha512-9QzNDgE4EYDnAHfrTlR2lwiPciiOymLtwKK+8yHQzCc7GXhAP9xdEbEJFy2IWB1j9UGUl9BsgMmTo/ImA02T7A==} + '@codemirror/state@6.7.2': + resolution: {integrity: sha512-U3RiPX62Wl/Gx4ftQ7UxLlloSfsFTQqKa+7vFBYteZGCzkp6oBqcsD7iSwniWRGobCAmDcwZSY+Six3+3ztdfg==} '@codemirror/theme-one-dark@6.1.3': resolution: {integrity: sha512-NzBdIvEJmx6fjeremiGp3t/okrLPYT0d9orIc7AFun8oZcRk58aejkqhv6spnz4MLAevrKNPMQYXEWMg4s+sKA==} @@ -1055,23 +1063,27 @@ packages: '@floating-ui/utils@0.2.10': resolution: {integrity: sha512-aGTxbpbg8/b5JfU1HXSrbH3wXZuLPJcNEcZQFMxLs3oSzgtVu6nFPkbbGGUvBcUjKV2YyB9Wxxabo+HEH9tcRQ==} - '@hono/node-server@1.19.14': - resolution: {integrity: sha512-GwtvgtXxnWsucXvbQXkRgqksiH2Qed37H9xHZocE5sA3N8O8O8/8FA3uclQXxXVzc9XBZuEOMK7+r02FmSpHtw==} + '@hono/node-server@1.19.17': + resolution: {integrity: sha512-dSneS5qhiauZWGDCeK4o695Xd9nUNjviSZCMQrj10eetr8Uln1ucn6bbphOM6UynAMMtNIzZNSpL9vnASJwrPQ==} engines: {node: '>=18.14.1'} peerDependencies: - hono: 4.12.28 + hono: 4.12.34 '@hookform/resolvers@5.2.2': resolution: {integrity: sha512-A/IxlMLShx3KjV/HeTcTfaMxdwy690+L/ZADoeaTltLx+CVuzkeVIPuybK3jrRfw7YZnmdKsVVHAlEPIAEUNlA==} peerDependencies: react-hook-form: ^7.55.0 - '@humanfs/core@0.19.1': - resolution: {integrity: sha512-5DyQ4+1JEUzejeK1JGICcideyfUbGixgS9jNgex5nqkW+cY7WZhxBigmieN5Qnw9ZosSNVC9KQKyb+GUaGyKUA==} + '@humanfs/core@0.19.2': + resolution: {integrity: sha512-UhXNm+CFMWcbChXywFwkmhqjs3PRCmcSa/hfBgLIb7oQ5HNb1wS0icWsGtSAUNgefHeI+eBrA8I1fxmbHsGdvA==} engines: {node: '>=18.18.0'} - '@humanfs/node@0.16.7': - resolution: {integrity: sha512-/zUx+yOsIrG4Y43Eh2peDeKCxlRt/gET6aHfaKpuq267qXdYDFViVHfMaLyygZOnl0kGWxFIgsBy8QFuTLUXEQ==} + '@humanfs/node@0.16.8': + resolution: {integrity: sha512-gE1eQNZ3R++kTzFUpdGlpmy8kDZD/MLyHqDwqjkVQI0JMdI1D51sy1H958PNXYkM2rAac7e5/CnIKZrHtPh3BQ==} + engines: {node: '>=18.18.0'} + + '@humanfs/types@0.15.0': + resolution: {integrity: sha512-ZZ1w0aoQkwuUuC7Yf+7sdeaNfqQiiLcSRbfI08oAxqLtpXQr9AIVX7Ay7HLDuiLYAaFPu8oBYNq/QIi9URHJ3Q==} engines: {node: '>=18.18.0'} '@humanwhocodes/module-importer@1.0.1': @@ -1381,11 +1393,11 @@ packages: '@marijn/find-cluster-break@1.0.2': resolution: {integrity: sha512-l0h88YhZFyKdXIFNfSWpyjStDjGHwZ/U7iobcK1cQQD8sejsONdQtTVU+1wVN1PBw40PiiHB1vA5S7VTfQiP9g==} - '@marijn/find-cluster-break@1.0.3': - resolution: {integrity: sha512-FY+MKLBoTsLNJF/eLWaOsXGdz6uh3Iu1axjPf6TUq92IYumcTcXWHoS747JARLkcdlJ/Waiaxc5wQfFO8jC6NA==} + '@marijn/find-cluster-break@1.0.4': + resolution: {integrity: sha512-Wy0V7+SGUjnF9/TkiM1hKVDPj7jKXduPNboMVtHTA8dySMURWqfg/JZ9E2Sq8JgSJmkl7k7Qe9FLeMSrSraWmQ==} - '@mermaid-js/parser@1.1.1': - resolution: {integrity: sha512-VuHdsYMK1bT6X2JbcAaWAhugTRvRBRyuZgd+c22swUeI9g/ntaxF7CY7dYarhZovofCbUNO0G7JesfmNtjYOCw==} + '@mermaid-js/parser@1.2.1': + resolution: {integrity: sha512-n12NohV3mrUyUL2o93IgG/ifeW9FTyeJn3zDxkhwa8MJ9Fxg3HQMlA3RiGmD/3UnJvheztkjjQAjA2T4LmUcpw==} '@modelcontextprotocol/sdk@1.26.0': resolution: {integrity: sha512-Y5RmPncpiDtTXDbLKswIJzTqu2hyBKxTNsgKqKclDbhIgg1wgtf1fRuvxgTnRfcnxtvvgbIEcqUOzZrJ6iSReg==} @@ -3735,8 +3747,8 @@ packages: engines: {node: '>=0.4.0'} hasBin: true - acorn@8.17.0: - resolution: {integrity: sha512-xRQbDb9BnwDafYNn6Vwl839DYVjqXYb1XVGtWAZ1kcDc6iwAL4hg3B1dZlRiuENFeO2H53gFG3in621AdERVAg==} + acorn@8.18.0: + resolution: {integrity: sha512-lGq+9yr1/GuAWaVYIHRjvvySG5/4VfKIvC8EWxStPdcDh/Ka7FG3twP6v4d5BkravUilhIAsG4Qj83t02LWUPQ==} engines: {node: '>=0.4.0'} hasBin: true @@ -3889,26 +3901,26 @@ packages: bidi-js@1.0.3: resolution: {integrity: sha512-RKshQI1R3YQ+n9YJz2QQ147P66ELpa1FQEg20Dk8oW9t2KgLbpDLLp9aGZ7y8WHSshDknG0bknqGw5/tyCs5tw==} - body-parser@2.2.2: - resolution: {integrity: sha512-oP5VkATKlNwcgvxi0vM0p/D3n2C3EReYVX+DNYs5TjZFn/oQt2j+4sVJtSMr18pdRr8wjTcBl6LoV+FUwzPmNA==} + body-parser@2.3.0: + resolution: {integrity: sha512-2cGmJupaNgg+QUwVLAucDuWuoMZ6EX9iHDRswZ5lsNYEmwPaRknMPCLZz07yTzVq/83p4o/wzbDZbBrTvGGTIw==} engines: {node: '>=18'} bowser@2.14.1: resolution: {integrity: sha512-tzPjzCxygAKWFOJP011oxFHs57HzIhOEracIgAePE4pqB3LikALKnSzUyU4MGs9/iCEUuHlAJTjTc5M+u7YEGg==} - brace-expansion@1.1.13: - resolution: {integrity: sha512-9ZLprWS6EENmhEOpjCYW2c8VkmOvckIJZfkr7rBW6dObmfgJ/L1GpSYW5Hpo9lDz4D1+n0Ckz8rU7FwHDQiG/w==} + brace-expansion@1.1.18: + resolution: {integrity: sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==} - brace-expansion@5.0.6: - resolution: {integrity: sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==} - engines: {node: 18 || 20 || >=22} + brace-expansion@5.0.9: + resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==} + engines: {node: 20 || >=22} braces@3.0.3: resolution: {integrity: sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==} engines: {node: '>=8'} - browserslist@4.28.2: - resolution: {integrity: sha512-48xSriZYYg+8qXna9kwqjIVzuQxi+KYWp2+5nCYnYKPTr0LvD89Jqk2Or5ogxz0NUMfIjhh2lIUX/LyX9B4oIg==} + browserslist@4.28.7: + resolution: {integrity: sha512-JxV13hNrFxqjOc8alRbq9dK1MM79NEXYpma2B2J4wAtpWS5zIEIKqWPGCl7N4o7Uc7B7itylh7SuDujATRyyTw==} engines: {node: ^6 || ^7 || ^8 || ^9 || ^10 || ^11 || ^12 || >=13.7} hasBin: true @@ -4044,6 +4056,10 @@ packages: resolution: {integrity: sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==} engines: {node: '>= 0.6'} + content-type@2.1.0: + resolution: {integrity: sha512-mj7UPXE0jaqaOsukNZRUEfEi2AcL7C/vwmwcHV0O97eO1E1pxBZuyjlZrx5seTaNBg1U6+o35wpa35Qfcc+7ag==} + engines: {node: '>=18'} + convert-source-map@2.0.0: resolution: {integrity: sha512-Kvp459HrV2FEJ1CAsi1Ku+MY3kasH19TFykTz2xWmMeq6bk2NU3XXvfJ+Q61m0xktWwt+1HSYf3JZsTms3aRJg==} @@ -4114,8 +4130,8 @@ packages: peerDependencies: cytoscape: ^3.2.0 - cytoscape@3.33.1: - resolution: {integrity: sha512-iJc4TwyANnOGR1OmWhsS9ayRS3s+XQ185FmuHObThD+5AeJCakAAbWv8KimMTt08xCCLNgneQwFp+JRJOr9qGQ==} + cytoscape@3.34.2: + resolution: {integrity: sha512-Cm2jaj1X/PBNlzV9yH8zcfGOxO7U+CJ/+mxSBVPSchLaugdp4jtlGx5qaHtPRZ6tgiZ5P+o1XoRfJA+ba6KM3g==} engines: {node: '>=0.10'} d3-array@2.12.1: @@ -4285,8 +4301,8 @@ packages: date-fns@4.1.0: resolution: {integrity: sha512-Ukq0owbQXxa/U3EGtsdVBkR1w7KOQ5gIBqdH2hkvknzZPYvBxb/aa6E8L7tmjFtkwZBu3UXBbjIgPo/Ez4xaNg==} - dayjs@1.11.19: - resolution: {integrity: sha512-t5EcLVS6QPBNqM2z8fakk/NKel+Xzshgt8FFKAn+qwlD1pzZWxh0nVCrvFK7ZDb6XucZeF9z8C7CBWTRIVApAw==} + dayjs@1.11.23: + resolution: {integrity: sha512-QDTCU0M0MxR3hQfnlDJfwekQiaanm1ubOD231u73WBckQ/fsamwRLiE2GBz6D3a/xF1NgfiDLJjXBa1hYOYTtQ==} debug@4.4.3: resolution: {integrity: sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==} @@ -4363,8 +4379,8 @@ packages: dom-helpers@5.2.1: resolution: {integrity: sha512-nRCa7CK3VTrM2NmGkIy4cbK7IZlgBE/PYMn55rrXefr5xXDP0LdtfPnblFDoVdcAfslJ7or6iqAUnx0CCGIWQA==} - dompurify@3.4.11: - resolution: {integrity: sha512-zhlUV12GsaRzMsf9q5M254YhA4+VuF0fG+QFqu6aYpoGlKtz+w8//jBcGVYBgQkR5GHjUomejY84AV+/uPbWdw==} + dompurify@3.4.13: + resolution: {integrity: sha512-2vmYIoqjze2d+kakP8S/nS5shfsl587kzwEjcGlTdiksUVgFHnFCsLYDVj/JNqJVOQZGSYBTmuycv0PodwmnMQ==} dotenv-expand@12.0.3: resolution: {integrity: sha512-uc47g4b+4k/M/SeaW1y4OApx+mtLWl92l5LMPP0GNXctZqELk+YGgOPIIC5elYmUH4OuoK3JLhuRUYegeySiFA==} @@ -4388,8 +4404,8 @@ packages: ee-first@1.1.1: resolution: {integrity: sha512-WMwm9LhRUo+WUaRN+vRuETqG89IgZphVSNkdFgeb6sS/E4OrDIN7t48CAewSHXc6C8lefD8KKfr5vY61brQlow==} - electron-to-chromium@1.5.354: - resolution: {integrity: sha512-JaBHwWcfIdmSAfWM5l3uwjGd431j8YEMikZ+K/2nXVuBqJKyZ0f+2h4n4JY5AyNiZmnY9qQr2RU3v9DxDmHMNg==} + electron-to-chromium@1.5.418: + resolution: {integrity: sha512-UzS26r3AEbG5wSoGVpJKqwHIU9zwQN7LHdVIThDrJpS0I5KdlXFMEb8543fhc9dVnIIAST6ar8rhwa00AL5MlA==} emoji-regex@8.0.0: resolution: {integrity: sha512-MSjYzcWNOA0ewAHpz0MxpYFvwg6yjy1NG3xteoqz644VCo/RPgnr1/GGt+ic3iJTzQ8Eu3TdM14SawnVUmGE6A==} @@ -4405,8 +4421,8 @@ packages: resolution: {integrity: sha512-xe9vQb5kReirPUxgQrXA3ihgbCqssmTiM7cOZ+Gzu+VeGWgpV98lLZvp0dl4yriyAePcewxGUs9UpKD8PET9KQ==} engines: {node: '>=10.13.0'} - enhanced-resolve@5.24.2: - resolution: {integrity: sha512-rpsZEGT1jFuve6QlpyRp9ckQ+kN61hvF9BzCPyMdaKTm8UJce96KBn3sorXOFXlzjPrs3Vc4T1NsSroZ3PxlFw==} + enhanced-resolve@5.24.5: + resolution: {integrity: sha512-L1l8TNvomm6UVW5B253AGxQagSQr+vGwhMlrrfRS2qmhx46AMpMVJKQYLvWYbysTMY8VoicOvzHzoHMbyzB+4A==} engines: {node: '>=10.13.0'} entities@6.0.1: @@ -4666,8 +4682,8 @@ packages: fast-string-width@3.0.2: resolution: {integrity: sha512-gX8LrtNEI5hq8DVUfRQMbr5lpaS4nMIWV+7XEbXk2b8kiQIizgnlr12B4dA3ZEx3308ze0O4Q1R+cHts8kyUJg==} - fast-uri@3.1.2: - resolution: {integrity: sha512-rVjf7ArG3LTk+FS6Yw81V1DLuZl1bRbNrev6Tmd/9RaroeeRRJhAt7jg/6YFxbvAQXUCavSoZhPPj6oOx+5KjQ==} + fast-uri@3.1.6: + resolution: {integrity: sha512-7Ical1vFEMr0onbVzEDIreM22I4khW+fzyQPwvAFWBp1iwdshSZRsL4jjRvPG9JP1uiqMHRto+YU6R2/CzDz5Q==} fast-wrap-ansi@0.2.0: resolution: {integrity: sha512-rLV8JHxTyhVmFYhBJuMujcrHqOT2cnO5Zxj37qROj23CP39GXubJRBUFF0z8KFK77Uc0SukZUf7JZhsVEQ6n8w==} @@ -4929,8 +4945,8 @@ packages: hermes-parser@0.25.1: resolution: {integrity: sha512-6pEjquH3rqaI6cYAXYPcz9MS4rY6R4ngRgrgfDshRptUZIc3lw0MCIJIGDj9++mfySOuPTHB4nrSW99BCvOPIA==} - hono@4.12.28: - resolution: {integrity: sha512-YwUvVpSF7m1yOblFPrU3Hbo8XhPheBoiyfGuII6z19LnOr6JpDnyyp7LFNrfV56wS8tpvtBFGRISHN02pDdLOA==} + hono@4.12.34: + resolution: {integrity: sha512-GqXJqY/xJkJmuloTrnV1ZEXG3fqte+VjkUqoRNZXcrUidiUOP4fMSIHHY4tsqZBK++kVyWmt/AAfSUuy57/eSA==} engines: {node: '>=16.9.0'} html-encoding-sniffer@6.0.0: @@ -5014,8 +5030,8 @@ packages: resolution: {integrity: sha512-5Hh7Y1wQbvY5ooGgPbDaL5iYLAPzMTUrjMulskHLH6wnv/A+1q5rgEaiuqEjB+oxGXIVZs1FF+R/KPN3ZSQYYg==} engines: {node: '>=12'} - ip-address@10.2.0: - resolution: {integrity: sha512-/+S6j4E9AHvW9SWMSEY9Xfy66O5PWvVEJ08O0y5JGyEKQpojb0K0GKpz/v5HJ/G0vi3D2sjGK78119oXZeE0qA==} + ip-address@10.3.1: + resolution: {integrity: sha512-1e9d3kb97NHJTIJDZW9rKqW2h6+dFa50Dy0fpPSMQp2ADje5gvKsXmdiK6dwY5t76TaTt5+P5N1Y/LoToIxP6g==} engines: {node: '>= 12'} ipaddr.js@1.9.1: @@ -5207,8 +5223,8 @@ packages: js-tokens@4.0.0: resolution: {integrity: sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==} - js-yaml@4.3.0: - resolution: {integrity: sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==} + js-yaml@4.3.1: + resolution: {integrity: sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==} hasBin: true jsdom@27.4.0: @@ -5263,6 +5279,10 @@ packages: resolution: {integrity: sha512-aeQoDkuRWSqQN6nSvVCEFvfXdqo1OQiCmmW1kc9xSdjutPv7BGO7pqY9sQRJpMOGrEdfDgF2TfRXe5eUAD2Waw==} hasBin: true + katex@0.16.47: + resolution: {integrity: sha512-Eeo8Ys1doU1z+x8AZsPpQu+p/QcZBI5PeOo7QGQdy2x2m0MU/hYagBbGOmXwr5KVbEfVuWv9LpnQWeehogurjg==} + hasBin: true + keyv@4.5.4: resolution: {integrity: sha512-oxVHkHR/EJf2CNXnWxRLW6mg7JyCCUcG0DtEGmL2ctUo1PNTin1PUil+r/+4r5MpVgC/fn1kjsx7mjSujKqIpw==} @@ -5539,8 +5559,8 @@ packages: resolution: {integrity: sha512-Sz8FzjzI0kN13GK/6MVEsVzMZEPvOhnmmI1lU5+/1cGOiK3QUahntrNNtdVeihrO7t9JpoH75iMNXg6R6uWflQ==} engines: {node: '>=18.0.0'} - mermaid@11.15.0: - resolution: {integrity: sha512-pTMbcf3rWdtLiYGpmoTjHEpeY8seiy6sR+9nD7LOs8KfUbHE4lOUAprTRqRAcWSQ6MQpdX+YEsxShtGsINtPtw==} + mermaid@11.16.1: + resolution: {integrity: sha512-TQsq6u22fAn3rek5VOubrhKPo1g5hwC3FXUN9hiyupTckcYiGuuKGkNQrKYwGJkXUxZdojwRG46gsSCFZMDp4g==} micromark-core-commonmark@2.0.3: resolution: {integrity: sha512-RDBrHEMSxVFLg6xvnXmb1Ayr2WzLAWjeSATAoxwKYJV94TeNavgoIdA0a9ytzDSVzBy2YKFK+emCPOEibLeCrg==} @@ -5740,13 +5760,13 @@ packages: resolution: {integrity: sha512-dkEJPVvun4FryqBmZ5KhDo0K9iDXAwn08tMLDinNdRBNPcYEDiWYysLcc6k3mjTMlbP9KyylvRpd4wFtwrT9rw==} engines: {node: ^20.17.0 || >=22.9.0} - nanoid@3.3.12: - resolution: {integrity: sha512-ZB9RH/39qpq5Vu6Y+NmUaFhQR6pp+M2Xt76XBnEwDaGcVAqhlvxrl3B2bKS5D3NH3QR76v3aSrKaF/Kiy7lEtQ==} + nanoid@3.3.18: + resolution: {integrity: sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==} engines: {node: ^10 || ^12 || ^13.7 || ^14 || >=15.0.1} hasBin: true - nanoid@5.1.6: - resolution: {integrity: sha512-c7+7RQ+dMB5dPwwCp4ee1/iV/q2P6aK1mTZcfr1BTuVlyW9hJYiMPybJCcnBlQtuSmTIWNeazm/zqNoZSSElBg==} + nanoid@5.1.16: + resolution: {integrity: sha512-kVrnsrJqMR8+oLJnGEmSWw9BivK5mt7H3FZatVRjrc5wGqFYuBxX1yG7+A7Gi5AefkX6t/oCkizcQgpu0cY1dQ==} engines: {node: ^18 || >=20} hasBin: true @@ -5818,8 +5838,9 @@ packages: encoding: optional: true - node-releases@2.0.44: - resolution: {integrity: sha512-5WUyunoPMsvvEhS8AxHtRzP+oA8UCkJ7YRxatWKjngndhDGLiqEVAQKWjFAiAiuL8zMRGzGSJxFnLetoa43qGQ==} + node-releases@2.0.54: + resolution: {integrity: sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==} + engines: {node: '>=18'} oauth4webapi@3.8.3: resolution: {integrity: sha512-pQ5BsX3QRTgnt5HxgHwgunIRaDXBdkT23tf8dfzmtTIL2LTpdmxgbpbBm0VgFWAIDlezQvQCTgnVIUmHupXHxw==} @@ -5996,6 +6017,10 @@ packages: resolution: {integrity: sha512-RvwwcruNjI1ncT5xRakeyS9Lf8lcItv34KD+aif+VH9kduAyfYBipGh12274xtenIPZ119/R9BdTBa8gAwSh0A==} engines: {node: '>=12'} + picomatch@4.0.7: + resolution: {integrity: sha512-qcJu88Q2IWqJsDD529JKMdwGm/dvInW4HvQnRwiH9JtihJvzGOscDtHE3x1pBKeUOTysQ8kVmLnJ2kJu7yhcGA==} + engines: {node: '>=12'} + pkce-challenge@5.0.1: resolution: {integrity: sha512-wQ0b/W4Fr01qtpHlqSqspcj3EhBvimsdh0KlHhH8HRZnMsEa0ea2fTULOXOS9ccQr3om+GcGRk4e+isrZWV8qQ==} engines: {node: '>=16.20.0'} @@ -6031,8 +6056,8 @@ packages: resolution: {integrity: sha512-IQ7TZdoaqbT+LCpShg46jnZVlhWD2w6iQYAcYXfHARZ7X1t/UGhhceQDs5X0cGqKvYlHNOuv7Oa1xmb0oQuA3w==} engines: {node: '>=4'} - postcss@8.5.14: - resolution: {integrity: sha512-SoSL4+OSEtR99LHFZQiJLkT59C5B1amGO1NzTwj7TT1qCUgUO6hxOvzkOYxD+vMrXBM3XJIKzokoERdqQq/Zmg==} + postcss@8.5.23: + resolution: {integrity: sha512-g50586zr4bZmwFiTlflMu8E0bDTb5I5gertgwAKmsdUlTQIhZtunzUlD1WSzwcVWPoAVpsrA6vlfCD7oXvRwgg==} engines: {node: ^10 || ^12 || >=14} posthog-js@1.407.2: @@ -6157,8 +6182,8 @@ packages: resolution: {integrity: sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==} engines: {node: '>=6'} - qs@6.15.2: - resolution: {integrity: sha512-Rzq0KEyX/w/tEybncDgdkZrJgVUsUMk3xjh3t5bv3S1HTAtg+uOYt72+ZfwiQwKdysThkTBdL/rTi6HDmX9Ddw==} + qs@6.16.0: + resolution: {integrity: sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==} engines: {node: '>=0.6'} query-selector-shadow-dom@1.0.1: @@ -6490,6 +6515,10 @@ packages: resolution: {integrity: sha512-FCLHtRD/gnpCiCHEiJLOwdmFP+wzCmDEkc9y7NsYxeF4u7Btsn1ZuwgwJGxImImHicJArLP4R0yX4c2KCrMrTA==} engines: {node: '>= 0.4'} + side-channel-list@1.0.1: + resolution: {integrity: sha512-mjn/0bi/oUURjc5Xl7IaWi/OJJJumuoJFQJfDDyO46+hBWsfaVM65TBHq2eoZBhzl9EchxOijpkbRC8SVBQU0w==} + engines: {node: '>= 0.4'} + side-channel-map@1.0.1: resolution: {integrity: sha512-VCjCNfgMsby3tTdo02nbjtM/ewra6jPHmpThenkTYh8pG9ucZ/1P8So4u4FGBek/BjpOVsDCMoLA/iuBKIFXRA==} engines: {node: '>= 0.4'} @@ -6502,6 +6531,10 @@ packages: resolution: {integrity: sha512-ZX99e6tRweoUXqR+VBrslhda51Nh5MTQwou5tnUDgbtyM0dBgmhEDtWGP/xbKn6hqfPRHujUNwz5fy/wbbhnpw==} engines: {node: '>= 0.4'} + side-channel@1.1.1: + resolution: {integrity: sha512-6x6dK6zJdpTzF4sQeNYxwtvBzf6Eg4GtlesS94HOvTudUeyK2WXAaIfmDgsyslYrRBeFIlsi54AYsFGUuhmvrQ==} + engines: {node: '>= 0.4'} + siginfo@2.0.0: resolution: {integrity: sha512-ybx0WO1/8bSBLEWXZvEd7gMW3Sn3JFlW3TvX1nREbDLRNQNaeNN8WK0meBwPdAaOI7TtRRRJn/Es1zhrrCHu7g==} @@ -6725,8 +6758,8 @@ packages: uglify-js: optional: true - terser@5.49.0: - resolution: {integrity: sha512-SNiDnXyHSrxVcIOtVbULzcTmniUiwcV7Nwdyj1twVubeTmbjoa8p69KKDpfkdoOavuM4/GRm1+ykI8qqnavHoA==} + terser@5.51.2: + resolution: {integrity: sha512-bWnjSNscmuI+GJze6ZupnHP8G/cTcsJF+bXCeQknk2SHQsgbNJnLrqiH9jZ2W4STPVXH2mDKKRX3iwPhc9Cn/Q==} engines: {node: '>=10'} hasBin: true @@ -6824,6 +6857,10 @@ packages: resolution: {integrity: sha512-OZs6gsjF4vMp32qrCbiVSkrFmXtG/AZhY3t0iAMrMBiAZyV9oALtXO8hsrHbMXF9x6L3grlFuwW2oAz7cav+Gw==} engines: {node: '>= 0.6'} + type-is@2.1.0: + resolution: {integrity: sha512-faYHw0anBbc/kWF3zFTEnxSFOAGUX9GFbOBthvDdLsIlEoWOFOtS0zgCiQYwIskL9iGXZL3kAXD8OoZ4GmMATA==} + engines: {node: '>= 18'} + typed-array-buffer@1.0.3: resolution: {integrity: sha512-nAYYwfY3qnzX30IkA6AQZjVbtK6duGontcQm1WSG1MD94YLqK0515GNApXkoxKOWMusVssAHWLh9SeaoefYFGw==} engines: {node: '>= 0.4'} @@ -6904,7 +6941,7 @@ packages: resolution: {integrity: sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==} hasBin: true peerDependencies: - browserslist: 4.28.2 + browserslist: 4.28.7 uri-js@4.4.1: resolution: {integrity: sha512-7rKUyy33Q1yc98pQ1DAmLtwX109F7TIfWlW1Ydo8Wl1ii1SeHieeh0HHfPeL2fMXK6z0s8ecKs9frCuLJvndBg==} @@ -7894,7 +7931,7 @@ snapshots: dependencies: '@babel/compat-data': 7.29.7 '@babel/helper-validator-option': 7.29.7 - browserslist: 4.28.2 + browserslist: 4.28.7 lru-cache: 5.1.1 semver: 6.3.1 @@ -7972,7 +8009,7 @@ snapshots: '@blazediff/core@1.9.1': {} - '@braintree/sanitize-url@7.1.1': {} + '@braintree/sanitize-url@7.1.2': {} '@cfworker/json-schema@4.1.1': {} @@ -7992,10 +8029,10 @@ snapshots: '@codemirror/view': 6.40.0 '@lezer/common': 1.5.2 - '@codemirror/commands@6.10.4': + '@codemirror/commands@6.11.0': dependencies: '@codemirror/language': 6.12.2 - '@codemirror/state': 6.7.1 + '@codemirror/state': 6.7.2 '@codemirror/view': 6.40.0 '@lezer/common': 1.5.2 @@ -8024,9 +8061,9 @@ snapshots: dependencies: '@marijn/find-cluster-break': 1.0.2 - '@codemirror/state@6.7.1': + '@codemirror/state@6.7.2': dependencies: - '@marijn/find-cluster-break': 1.0.3 + '@marijn/find-cluster-break': 1.0.4 '@codemirror/theme-one-dark@6.1.3': dependencies: @@ -8202,7 +8239,7 @@ snapshots: globals: 14.0.0 ignore: 5.3.2 import-fresh: 3.3.1 - js-yaml: 4.3.0 + js-yaml: 4.3.1 minimatch: 3.1.4 strip-json-comments: 3.1.1 transitivePeerDependencies: @@ -8245,22 +8282,27 @@ snapshots: '@floating-ui/utils@0.2.10': {} - '@hono/node-server@1.19.14(hono@4.12.28)': + '@hono/node-server@1.19.17(hono@4.12.34)': dependencies: - hono: 4.12.28 + hono: 4.12.34 '@hookform/resolvers@5.2.2(react-hook-form@7.62.0(react@19.2.7))': dependencies: '@standard-schema/utils': 0.3.0 react-hook-form: 7.62.0(react@19.2.7) - '@humanfs/core@0.19.1': {} - - '@humanfs/node@0.16.7': + '@humanfs/core@0.19.2': dependencies: - '@humanfs/core': 0.19.1 + '@humanfs/types': 0.15.0 + + '@humanfs/node@0.16.8': + dependencies: + '@humanfs/core': 0.19.2 + '@humanfs/types': 0.15.0 '@humanwhocodes/retry': 0.4.3 + '@humanfs/types@0.15.0': {} + '@humanwhocodes/module-importer@1.0.1': {} '@humanwhocodes/retry@0.4.3': {} @@ -8545,15 +8587,15 @@ snapshots: '@marijn/find-cluster-break@1.0.2': {} - '@marijn/find-cluster-break@1.0.3': {} + '@marijn/find-cluster-break@1.0.4': {} - '@mermaid-js/parser@1.1.1': + '@mermaid-js/parser@1.2.1': dependencies: '@chevrotain/types': 11.1.2 '@modelcontextprotocol/sdk@1.26.0(@cfworker/json-schema@4.1.1)(zod@4.4.3)': dependencies: - '@hono/node-server': 1.19.14(hono@4.12.28) + '@hono/node-server': 1.19.17(hono@4.12.34) ajv: 8.18.0 ajv-formats: 3.0.1(ajv@8.18.0) content-type: 1.0.5 @@ -8563,7 +8605,7 @@ snapshots: eventsource-parser: 3.1.0 express: 5.2.1 express-rate-limit: 8.5.1(express@5.2.1) - hono: 4.12.28 + hono: 4.12.34 jose: 6.1.3 json-schema-typed: 8.0.2 pkce-challenge: 5.0.1 @@ -9729,7 +9771,7 @@ snapshots: - encoding - supports-color - '@sentry/bundler-plugins@10.65.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14))': + '@sentry/bundler-plugins@10.65.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23))': dependencies: '@babel/core': 7.29.7 '@sentry/cli': 2.58.6 @@ -9740,7 +9782,7 @@ snapshots: magic-string: 0.30.21 optionalDependencies: rollup: 4.59.0 - webpack: 5.104.1(lightningcss@1.30.2)(postcss@8.5.14) + webpack: 5.104.1(lightningcss@1.30.2)(postcss@8.5.23) transitivePeerDependencies: - encoding - supports-color @@ -9799,7 +9841,7 @@ snapshots: dependencies: '@sentry/core': 10.65.0 - '@sentry/nextjs@10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14))': + '@sentry/nextjs@10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23))': dependencies: '@opentelemetry/api': 1.9.1 '@rollup/plugin-commonjs': 28.0.1(rollup@4.59.0) @@ -9811,7 +9853,7 @@ snapshots: '@sentry/opentelemetry': 10.65.0(@opentelemetry/api@1.9.1)(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1)) '@sentry/react': 10.65.0(react@19.2.7) '@sentry/vercel-edge': 10.65.0 - '@sentry/webpack-plugin': 5.4.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14)) + '@sentry/webpack-plugin': 5.4.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) next: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) rollup: 4.59.0 stacktrace-parser: 0.1.11 @@ -9893,10 +9935,10 @@ snapshots: '@opentelemetry/api': 1.9.1 '@sentry/core': 10.65.0 - '@sentry/webpack-plugin@5.4.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14))': + '@sentry/webpack-plugin@5.4.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23))': dependencies: - '@sentry/bundler-plugins': 10.65.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14)) - webpack: 5.104.1(lightningcss@1.30.2)(postcss@8.5.14) + '@sentry/bundler-plugins': 10.65.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) + webpack: 5.104.1(lightningcss@1.30.2)(postcss@8.5.23) transitivePeerDependencies: - encoding - rollup @@ -10217,7 +10259,7 @@ snapshots: '@alloc/quick-lru': 5.2.0 '@tailwindcss/node': 4.1.18 '@tailwindcss/oxide': 4.1.18 - postcss: 8.5.14 + postcss: 8.5.23 tailwindcss: 4.1.18 '@tailwindcss/typography@0.5.16(tailwindcss@4.1.18)': @@ -10695,7 +10737,7 @@ snapshots: '@vercel/oidc@3.2.0': {} - '@vitejs/plugin-react@5.1.2(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))': + '@vitejs/plugin-react@5.1.2(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))': dependencies: '@babel/core': 7.29.7 '@babel/plugin-transform-react-jsx-self': 7.27.1(@babel/core@7.29.7) @@ -10703,33 +10745,33 @@ snapshots: '@rolldown/pluginutils': 1.0.0-beta.53 '@types/babel__core': 7.20.5 react-refresh: 0.18.0 - vite: 7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0) + vite: 7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0) transitivePeerDependencies: - supports-color - '@vitest/browser-playwright@4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(playwright@1.56.1)(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10)': + '@vitest/browser-playwright@4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(playwright@1.56.1)(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10)': dependencies: - '@vitest/browser': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10) - '@vitest/mocker': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + '@vitest/browser': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10) + '@vitest/mocker': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) playwright: 1.56.1 tinyrainbow: 3.1.0 - vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) transitivePeerDependencies: - bufferutil - msw - utf-8-validate - vite - '@vitest/browser@4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10)': + '@vitest/browser@4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10)': dependencies: '@blazediff/core': 1.9.1 - '@vitest/mocker': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + '@vitest/mocker': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) '@vitest/utils': 4.1.10 magic-string: 0.30.21 pngjs: 7.0.0 sirv: 3.0.2 tinyrainbow: 3.1.0 - vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) ws: 8.21.0 transitivePeerDependencies: - bufferutil @@ -10749,9 +10791,9 @@ snapshots: obug: 2.1.1 std-env: 4.1.0 tinyrainbow: 3.1.0 - vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) optionalDependencies: - '@vitest/browser': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10) + '@vitest/browser': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10) '@vitest/expect@4.1.10': dependencies: @@ -10762,14 +10804,14 @@ snapshots: chai: 6.2.2 tinyrainbow: 3.1.0 - '@vitest/mocker@4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))': + '@vitest/mocker@4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))': dependencies: '@vitest/spy': 4.1.10 estree-walker: 3.0.3 magic-string: 0.30.21 optionalDependencies: msw: 2.13.4(@types/node@24.10.8)(typescript@5.5.4) - vite: 7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0) + vite: 7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0) '@vitest/pretty-format@4.1.10': dependencies: @@ -10903,9 +10945,9 @@ snapshots: mime-types: 3.0.2 negotiator: 1.0.0 - acorn-import-phases@1.0.4(acorn@8.17.0): + acorn-import-phases@1.0.4(acorn@8.18.0): dependencies: - acorn: 8.17.0 + acorn: 8.18.0 acorn-jsx@5.3.2(acorn@8.16.0): dependencies: @@ -10913,7 +10955,7 @@ snapshots: acorn@8.16.0: {} - acorn@8.17.0: {} + acorn@8.18.0: {} agent-base@6.0.2: dependencies: @@ -10954,7 +10996,7 @@ snapshots: ajv@8.18.0: dependencies: fast-deep-equal: 3.1.3 - fast-uri: 3.1.2 + fast-uri: 3.1.6 json-schema-traverse: 1.0.0 require-from-string: 2.0.2 @@ -11075,28 +11117,28 @@ snapshots: dependencies: require-from-string: 2.0.2 - body-parser@2.2.2: + body-parser@2.3.0: dependencies: bytes: 3.1.2 - content-type: 1.0.5 + content-type: 2.1.0 debug: 4.4.3 http-errors: 2.0.1 iconv-lite: 0.7.2 on-finished: 2.4.1 - qs: 6.15.2 + qs: 6.16.0 raw-body: 3.0.2 - type-is: 2.0.1 + type-is: 2.1.0 transitivePeerDependencies: - supports-color bowser@2.14.1: {} - brace-expansion@1.1.13: + brace-expansion@1.1.18: dependencies: balanced-match: 1.0.2 concat-map: 0.0.1 - brace-expansion@5.0.6: + brace-expansion@5.0.9: dependencies: balanced-match: 4.0.4 @@ -11104,13 +11146,13 @@ snapshots: dependencies: fill-range: 7.1.1 - browserslist@4.28.2: + browserslist@4.28.7: dependencies: baseline-browser-mapping: 2.10.29 caniuse-lite: 1.0.30001792 - electron-to-chromium: 1.5.354 - node-releases: 2.0.44 - update-browserslist-db: 1.2.3(browserslist@4.28.2) + electron-to-chromium: 1.5.418 + node-releases: 2.0.54 + update-browserslist-db: 1.2.3(browserslist@4.28.7) buffer-from@1.1.2: {} @@ -11193,7 +11235,7 @@ snapshots: codemirror@6.0.2: dependencies: '@codemirror/autocomplete': 6.20.1 - '@codemirror/commands': 6.10.4 + '@codemirror/commands': 6.11.0 '@codemirror/language': 6.12.2 '@codemirror/lint': 6.9.5 '@codemirror/search': 6.6.0 @@ -11226,6 +11268,8 @@ snapshots: content-type@1.0.5: {} + content-type@2.1.0: {} + convert-source-map@2.0.0: {} cookie-signature@1.2.2: {} @@ -11283,17 +11327,17 @@ snapshots: csstype@3.2.3: {} - cytoscape-cose-bilkent@4.1.0(cytoscape@3.33.1): + cytoscape-cose-bilkent@4.1.0(cytoscape@3.34.2): dependencies: cose-base: 1.0.3 - cytoscape: 3.33.1 + cytoscape: 3.34.2 - cytoscape-fcose@2.2.0(cytoscape@3.33.1): + cytoscape-fcose@2.2.0(cytoscape@3.34.2): dependencies: cose-base: 2.2.0 - cytoscape: 3.33.1 + cytoscape: 3.34.2 - cytoscape@3.33.1: {} + cytoscape@3.34.2: {} d3-array@2.12.1: dependencies: @@ -11496,7 +11540,7 @@ snapshots: date-fns@4.1.0: {} - dayjs@1.11.19: {} + dayjs@1.11.23: {} debug@4.4.3: dependencies: @@ -11559,7 +11603,7 @@ snapshots: '@babel/runtime': 7.28.6 csstype: 3.2.3 - dompurify@3.4.11: + dompurify@3.4.13: optionalDependencies: '@types/trusted-types': 2.0.7 @@ -11581,7 +11625,7 @@ snapshots: ee-first@1.1.1: {} - electron-to-chromium@1.5.354: {} + electron-to-chromium@1.5.418: {} emoji-regex@8.0.0: {} @@ -11594,7 +11638,7 @@ snapshots: graceful-fs: 4.2.11 tapable: 2.3.3 - enhanced-resolve@5.24.2: + enhanced-resolve@5.24.5: dependencies: graceful-fs: 4.2.11 tapable: 2.3.3 @@ -11869,7 +11913,7 @@ snapshots: '@eslint/eslintrc': 3.3.3 '@eslint/js': 9.39.2 '@eslint/plugin-kit': 0.4.1 - '@humanfs/node': 0.16.7 + '@humanfs/node': 0.16.8 '@humanwhocodes/module-importer': 1.0.1 '@humanwhocodes/retry': 0.4.3 '@types/estree': 1.0.9 @@ -11947,12 +11991,12 @@ snapshots: express-rate-limit@8.5.1(express@5.2.1): dependencies: express: 5.2.1 - ip-address: 10.2.0 + ip-address: 10.3.1 express@5.2.1: dependencies: accepts: 2.0.0 - body-parser: 2.2.2 + body-parser: 2.3.0 content-disposition: 1.0.1 content-type: 1.0.5 cookie: 0.7.2 @@ -11971,7 +12015,7 @@ snapshots: once: 1.4.0 parseurl: 1.3.3 proxy-addr: 2.0.7 - qs: 6.15.2 + qs: 6.16.0 range-parser: 1.2.1 router: 2.2.0 send: 1.2.1 @@ -12017,7 +12061,7 @@ snapshots: dependencies: fast-string-truncated-width: 3.0.3 - fast-uri@3.1.2: {} + fast-uri@3.1.6: {} fast-wrap-ansi@0.2.0: dependencies: @@ -12048,6 +12092,10 @@ snapshots: optionalDependencies: picomatch: 4.0.5 + fdir@6.5.0(picomatch@4.0.7): + optionalDependencies: + picomatch: 4.0.7 + fflate@0.4.9: {} file-entry-cache@8.0.0: @@ -12349,7 +12397,7 @@ snapshots: dependencies: hermes-estree: 0.25.1 - hono@4.12.28: {} + hono@4.12.34: {} html-encoding-sniffer@6.0.0: dependencies: @@ -12435,7 +12483,7 @@ snapshots: internmap@2.0.3: {} - ip-address@10.2.0: {} + ip-address@10.3.1: {} ipaddr.js@1.9.1: {} @@ -12624,7 +12672,7 @@ snapshots: js-tokens@4.0.0: {} - js-yaml@4.3.0: + js-yaml@4.3.1: dependencies: argparse: 2.0.1 @@ -12687,6 +12735,10 @@ snapshots: dependencies: commander: 8.3.0 + katex@0.16.47: + dependencies: + commander: 8.3.0 + keyv@4.5.4: dependencies: json-buffer: 3.0.1 @@ -13043,23 +13095,23 @@ snapshots: meriyah@6.1.4: {} - mermaid@11.15.0: + mermaid@11.16.1: dependencies: - '@braintree/sanitize-url': 7.1.1 + '@braintree/sanitize-url': 7.1.2 '@iconify/utils': 3.1.0 - '@mermaid-js/parser': 1.1.1 + '@mermaid-js/parser': 1.2.1 '@types/d3': 7.4.3 '@upsetjs/venn.js': 2.0.0 - cytoscape: 3.33.1 - cytoscape-cose-bilkent: 4.1.0(cytoscape@3.33.1) - cytoscape-fcose: 2.2.0(cytoscape@3.33.1) + cytoscape: 3.34.2 + cytoscape-cose-bilkent: 4.1.0(cytoscape@3.34.2) + cytoscape-fcose: 2.2.0(cytoscape@3.34.2) d3: 7.9.0 d3-sankey: 0.12.3 dagre-d3-es: 7.0.14 - dayjs: 1.11.19 - dompurify: 3.4.11 + dayjs: 1.11.23 + dompurify: 3.4.13 es-toolkit: 1.46.1 - katex: 0.16.27 + katex: 0.16.47 khroma: 2.1.0 marked: 16.4.2 roughjs: 4.6.6 @@ -13321,15 +13373,15 @@ snapshots: minimatch@10.2.3: dependencies: - brace-expansion: 5.0.6 + brace-expansion: 5.0.9 minimatch@3.1.4: dependencies: - brace-expansion: 1.1.13 + brace-expansion: 1.1.18 minimatch@9.0.7: dependencies: - brace-expansion: 5.0.6 + brace-expansion: 5.0.9 minimist@1.2.8: {} @@ -13337,7 +13389,7 @@ snapshots: mlly@1.8.0: dependencies: - acorn: 8.16.0 + acorn: 8.18.0 pathe: 2.0.3 pkg-types: 1.3.1 ufo: 1.6.3 @@ -13385,9 +13437,9 @@ snapshots: mute-stream@3.0.0: {} - nanoid@3.3.12: {} + nanoid@3.3.18: {} - nanoid@5.1.6: {} + nanoid@5.1.16: {} napi-postinstall@0.3.4: {} @@ -13415,7 +13467,7 @@ snapshots: '@swc/helpers': 0.5.15 baseline-browser-mapping: 2.10.29 caniuse-lite: 1.0.30001792 - postcss: 8.5.14 + postcss: 8.5.23 react: 19.2.7 react-dom: 19.2.7(react@19.2.7) styled-jsx: 5.1.6(@babel/core@7.29.7)(react@19.2.7) @@ -13441,7 +13493,7 @@ snapshots: dependencies: whatwg-url: 5.0.0 - node-releases@2.0.44: {} + node-releases@2.0.54: {} oauth4webapi@3.8.3: {} @@ -13660,6 +13712,8 @@ snapshots: picomatch@4.0.5: {} + picomatch@4.0.7: {} + pkce-challenge@5.0.1: {} pkg-types@1.3.1: @@ -13692,9 +13746,9 @@ snapshots: cssesc: 3.0.0 util-deprecate: 1.0.2 - postcss@8.5.14: + postcss@8.5.23: dependencies: - nanoid: 3.3.12 + nanoid: 3.3.18 picocolors: 1.1.1 source-map-js: 1.2.1 @@ -13704,7 +13758,7 @@ snapshots: '@posthog/core': 1.45.1 '@posthog/types': 1.398.0 core-js: 3.49.0 - dompurify: 3.4.11 + dompurify: 3.4.13 fflate: 0.4.9 preact: 10.29.7(preact-render-to-string@6.5.11(preact@10.24.3)) query-selector-shadow-dom: 1.0.1 @@ -13761,9 +13815,10 @@ snapshots: punycode@2.3.1: {} - qs@6.15.2: + qs@6.16.0: dependencies: - side-channel: 1.1.0 + es-define-property: 1.0.1 + side-channel: 1.1.1 query-selector-shadow-dom@1.0.1: {} @@ -14240,6 +14295,11 @@ snapshots: es-errors: 1.3.0 object-inspect: 1.13.4 + side-channel-list@1.0.1: + dependencies: + es-errors: 1.3.0 + object-inspect: 1.13.4 + side-channel-map@1.0.1: dependencies: call-bound: 1.0.4 @@ -14263,6 +14323,14 @@ snapshots: side-channel-map: 1.0.1 side-channel-weakmap: 1.0.2 + side-channel@1.1.1: + dependencies: + es-errors: 1.3.0 + object-inspect: 1.13.4 + side-channel-list: 1.0.1 + side-channel-map: 1.0.1 + side-channel-weakmap: 1.0.2 + siginfo@2.0.0: {} signal-exit@4.1.0: {} @@ -14324,7 +14392,7 @@ snapshots: katex: 0.16.27 lucide-react: 0.542.0(react@19.2.7) marked: 16.4.2 - mermaid: 11.15.0 + mermaid: 11.16.1 react: 19.2.7 rehype-harden: 1.1.7 rehype-katex: 7.0.1 @@ -14472,21 +14540,21 @@ snapshots: tapable@2.3.3: {} - terser-webpack-plugin@5.6.1(lightningcss@1.30.2)(postcss@8.5.14)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14)): + terser-webpack-plugin@5.6.1(lightningcss@1.30.2)(postcss@8.5.23)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)): dependencies: '@jridgewell/trace-mapping': 0.3.31 jest-worker: 27.5.1 schema-utils: 4.3.3 - terser: 5.49.0 - webpack: 5.104.1(lightningcss@1.30.2)(postcss@8.5.14) + terser: 5.51.2 + webpack: 5.104.1(lightningcss@1.30.2)(postcss@8.5.23) optionalDependencies: lightningcss: 1.30.2 - postcss: 8.5.14 + postcss: 8.5.23 - terser@5.49.0: + terser@5.51.2: dependencies: '@jridgewell/source-map': 0.3.11 - acorn: 8.17.0 + acorn: 8.18.0 commander: 2.20.3 source-map-support: 0.5.21 @@ -14563,6 +14631,12 @@ snapshots: media-typer: 1.1.0 mime-types: 3.0.2 + type-is@2.1.0: + dependencies: + content-type: 2.1.0 + media-typer: 1.1.0 + mime-types: 3.0.2 + typed-array-buffer@1.0.3: dependencies: call-bound: 1.0.4 @@ -14696,9 +14770,9 @@ snapshots: until-async@3.0.2: {} - update-browserslist-db@1.2.3(browserslist@4.28.2): + update-browserslist-db@1.2.3(browserslist@4.28.7): dependencies: - browserslist: 4.28.2 + browserslist: 4.28.7 escalade: 3.2.0 picocolors: 1.1.1 @@ -14767,12 +14841,12 @@ snapshots: d3-time: 3.1.0 d3-timer: 3.0.1 - vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0): + vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0): dependencies: esbuild: 0.28.1 - fdir: 6.5.0(picomatch@4.0.5) - picomatch: 4.0.5 - postcss: 8.5.14 + fdir: 6.5.0(picomatch@4.0.7) + picomatch: 4.0.7 + postcss: 8.5.23 rollup: 4.59.0 tinyglobby: 0.2.17 optionalDependencies: @@ -14780,22 +14854,22 @@ snapshots: fsevents: 2.3.3 jiti: 2.7.0 lightningcss: 1.30.2 - terser: 5.49.0 + terser: 5.51.2 yaml: 2.9.0 vitest-browser-react@2.0.4(@types/react-dom@19.2.3(@types/react@19.2.17))(@types/react@19.2.17)(react-dom@19.2.7(react@19.2.7))(react@19.2.7)(vitest@4.1.10): dependencies: react: 19.2.7 react-dom: 19.2.7(react@19.2.7) - vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + vitest: 4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) optionalDependencies: '@types/react': 19.2.17 '@types/react-dom': 19.2.3(@types/react@19.2.17) - vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)): + vitest@4.1.10(@opentelemetry/api@1.9.1)(@types/node@24.10.8)(@vitest/browser-playwright@4.1.10)(@vitest/coverage-v8@4.1.10)(jsdom@27.4.0)(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)): dependencies: '@vitest/expect': 4.1.10 - '@vitest/mocker': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0)) + '@vitest/mocker': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0)) '@vitest/pretty-format': 4.1.10 '@vitest/runner': 4.1.10 '@vitest/snapshot': 4.1.10 @@ -14812,12 +14886,12 @@ snapshots: tinyexec: 1.1.2 tinyglobby: 0.2.17 tinyrainbow: 3.1.0 - vite: 7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0) + vite: 7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0) why-is-node-running: 2.3.0 optionalDependencies: '@opentelemetry/api': 1.9.1 '@types/node': 24.10.8 - '@vitest/browser-playwright': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(playwright@1.56.1)(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.49.0)(yaml@2.9.0))(vitest@4.1.10) + '@vitest/browser-playwright': 4.1.10(msw@2.13.4(@types/node@24.10.8)(typescript@5.5.4))(playwright@1.56.1)(vite@7.3.5(@types/node@24.10.8)(jiti@2.7.0)(lightningcss@1.30.2)(terser@5.51.2)(yaml@2.9.0))(vitest@4.1.10) '@vitest/coverage-v8': 4.1.10(@vitest/browser@4.1.10)(vitest@4.1.10) jsdom: 27.4.0 transitivePeerDependencies: @@ -14845,7 +14919,7 @@ snapshots: webpack-sources@3.5.1: {} - webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14): + webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23): dependencies: '@types/eslint-scope': 3.7.7 '@types/estree': 1.0.9 @@ -14853,11 +14927,11 @@ snapshots: '@webassemblyjs/ast': 1.14.1 '@webassemblyjs/wasm-edit': 1.14.1 '@webassemblyjs/wasm-parser': 1.14.1 - acorn: 8.17.0 - acorn-import-phases: 1.0.4(acorn@8.17.0) - browserslist: 4.28.2 + acorn: 8.18.0 + acorn-import-phases: 1.0.4(acorn@8.18.0) + browserslist: 4.28.7 chrome-trace-event: 1.0.4 - enhanced-resolve: 5.24.2 + enhanced-resolve: 5.24.5 es-module-lexer: 2.3.0 eslint-scope: 5.1.1 events: 3.3.0 @@ -14869,7 +14943,7 @@ snapshots: neo-async: 2.6.2 schema-utils: 4.3.3 tapable: 2.3.3 - terser-webpack-plugin: 5.6.1(lightningcss@1.30.2)(postcss@8.5.14)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.14)) + terser-webpack-plugin: 5.6.1(lightningcss@1.30.2)(postcss@8.5.23)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) watchpack: 2.5.2 webpack-sources: 3.5.1 transitivePeerDependencies: diff --git a/ui/pnpm-workspace.yaml b/ui/pnpm-workspace.yaml index cd3f7d25f2..a1bf7c3015 100644 --- a/ui/pnpm-workspace.yaml +++ b/ui/pnpm-workspace.yaml @@ -21,18 +21,20 @@ overrides: # sharp 0.33.x/0.34.x carry GHSA-f88m-g3jw-g9cj; next pulls 0.34.5 transitively. "sharp": "0.35.3" "lodash-es": "4.18.1" - # GHSA-88fw-hqm2-52qc (CORS reflects any Origin with credentials) + 4 moderate - # advisories (serve-static path traversal, Lambda Set-Cookie merge, body-limit - # bypass, Lambda@Edge repeated-header loss), all fixed in 4.12.25, plus - # CVE-2026-59896 (hono/jsx SSR context leak across concurrent requests; in NVD - # but not yet in the npm audit feed), fixed in 4.12.27. Not 4.12.29: it is - # still inside StepSecurity's 7-day npm cooldown gate. - "hono": "4.12.28" - "@hono/node-server": "1.19.14" + # GHSA-88fw-hqm2-52qc (CORS reflects any Origin with credentials), CVE-2026-59896 + # (hono/jsx SSR context leak) and the 4.12.34 batch: CORS ReDoS via + # Access-Control-Request-Headers, `memo()` SSR output retained across requests, + # Language middleware algorithmic DoS, Proxy Helper keeping `Connection` headers. + # Node adapter 1.19.17 fixes serve-static path traversal via `%5C` on Windows + # (1.19.15 was published without provenance and trips `trustPolicy: no-downgrade`). + "hono": "4.12.34" + "@hono/node-server": "1.19.17" "@isaacs/brace-expansion": "5.0.1" "fast-xml-parser": "5.8.0" "serialize-javascript": "7.0.5" - "postcss": "8.5.14" + # GHSA-6g55-p6wh-862q (sourceMappingURL path traversal reads arbitrary .map files) + # and its incomplete-fix follow-up when `from` is unset, both closed in 8.5.23. + "postcss": "8.5.23" "esbuild": "0.28.1" "rollup@>=4": "4.59.0" # GHSA-fx2h-pf6j-xcff (server.fs.deny bypass on Windows alternate paths, high) + @@ -52,10 +54,11 @@ overrides: # fixed in 7.29.1. An override instead of `pnpm update` so the rest of the # babel/browserslist subtree keeps its existing lockfile resolutions. "@babel/core": "7.29.7" - # Ephemeral cooldown pins: the @babel/helper-compilation-targets refresh pulls - # browserslist-ecosystem releases newer than StepSecurity's 7-day npm cooldown. - # Safe to drop after 2026-07-20. - "browserslist": "4.28.2" + # browserslist 4.28.7 fixes unbounded query-result cache growth (OOM) and an + # uncaught crash / prototype write from untrusted browserslist-stats.json. + # caniuse-lite and baseline-browser-mapping stay pinned so the babel subtree + # does not float past StepSecurity's 7-day npm cooldown gate. + "browserslist": "4.28.7" "caniuse-lite": "1.0.30001792" "baseline-browser-mapping": "2.10.29" "minimatch@<4": "3.1.4" @@ -63,7 +66,9 @@ overrides: "minimatch@>=10": "10.2.3" "ajv@<7": "6.14.0" "ajv@>=8": "8.18.0" - "qs": "6.15.2" + # 6.16.0 fixes the bracket-key comma array-limit bypass and DoS via an + # attacker-controlled isBuffer. + "qs": "6.16.0" # 8.2.2 dropped provenance attestation; 8.3.1+ restored it. Pinned to skip 8.2.2 # under `trustPolicy: no-downgrade`. "express-rate-limit": "8.5.1" @@ -73,9 +78,38 @@ overrides: # but the override unifies the tree on a patched version. "uuid": "11.1.1" # GHSA-vxr8-fq34-vvx9 (+ several related XSS sanitization bypasses): DOMPurify < 3.4.9, - # pulled in transitively via streamdown > mermaid (which wants ^3.3.1). Bumped to 3.4.11 - # for GHSA-cmwh-pvxp-8882 (permanent ALLOWED_ATTR pollution via setConfig()). - "dompurify": "3.4.11" + # pulled in transitively via streamdown > mermaid and posthog-js. 3.4.11 closed + # GHSA-cmwh-pvxp-8882 (permanent ALLOWED_ATTR pollution via setConfig()); 3.4.13 + # also closes the CUSTOM_ELEMENT_HANDLING afterSanitizeElements bypass and the + # IN_PLACE hook removal that left a detached subtree executable. + "dompurify": "3.4.13" + + # Advisories flagged by `pnpm audit` on 2026-09-08. Every pin below is the + # oldest patched release and was published more than 7 days before that date, + # so it clears StepSecurity's npm cooldown gate. + # brace-expansion: three DoS advisories (exponential `{}` expansion, unbounded + # expansion length OOM, unbounded intermediate arrays bypassing the + # CVE-2026-14257 mitigation). 1.x via eslint > minimatch, 5.x via @sentry > glob. + "brace-expansion@<2": "1.1.18" + "brace-expansion@>=5": "5.0.9" + # fast-uri (via ajv): host confusion through backslash authority delimiters, + # failed IDN canonicalization and percent-encoded scheme normalization, plus SSRF + # via malformed IPv6 normalization and repeated hostname percent-decoding. + "fast-uri": "3.1.6" + # ip-address (via express-rate-limit): SSRF / trust-boundary bypasses from + # leading-zero octets, CIDR suffixes and IPv4-mapped / NAT64 misclassification. + "ip-address": "10.3.1" + # mermaid (via streamdown): prototype pollution in config APIs and Architecture + # diagrams, CSS injection into sibling elements, XY Chart infinite loop and + # radar diagram DoS. + "mermaid": "11.16.1" + # body-parser (via express): invalid `limit` silently disabled size enforcement. + "body-parser": "2.3.0" + # @humanfs/node (via eslint): recursive copy followed symlinks outside the tree. + "@humanfs/node": "0.16.8" + # js-yaml: quadratic CPU in `!!omap` resolution (CVE-2026-59870 not backported + # to 4.3.0). Direct dep is already 4.3.1; the override lifts eslint's copy too. + "js-yaml": "4.3.1" # --- Level 1: Minimum Release Age --- # Packages must be published for at least 1 day before they can be installed. From 806be2d061b78dcdd4e3f09a9c1e0fb5f0724c9a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Tue, 8 Sep 2026 11:58:06 +0200 Subject: [PATCH 03/16] chore(ci): bump agilepathway/label-checker to v1.6.66 (#12760) --- .github/workflows/backport.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/backport.yml b/.github/workflows/backport.yml index 8563f43038..0c6ef3ad96 100644 --- a/.github/workflows/backport.yml +++ b/.github/workflows/backport.yml @@ -39,7 +39,7 @@ jobs: - name: Check labels id: label_check - uses: agilepathway/label-checker@c3d16ad512e7cea5961df85ff2486bb774caf3c5 # v1.6.65 + uses: agilepathway/label-checker@c324842522fbd012e4f590afe3b4e591301322ed # v1.6.66 with: allow_failure: true prefix_mode: true From 9cab9b8653634d30f7e290d6947e858c92f129c2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 9 Sep 2026 14:30:22 +0200 Subject: [PATCH 04/16] fix(ci): suppress grpc xDS DoS CVE from the Trivy binary (#12777) --- .grype.yaml | 11 +++++++++++ .trivyignore.yaml | 19 +++++++++++++++++++ 2 files changed, 30 insertions(+) diff --git a/.grype.yaml b/.grype.yaml index 38517d7af5..26fec99bdd 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -27,6 +27,17 @@ ignore: package: name: google.golang.org/grpc version: v1.82.1 + # CVE-2026-84445 is the same temporary exception documented in .trivyignore.yaml: + # Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.82.2 / 1.83.2 fix is not in any + # release. The panic needs a gRPC server built with `xds.NewGRPCServer()`; Prowler only + # runs `trivy image` / `trivy fs`, so the image serves no gRPC at all. Pinned to the + # embedded version so the rule stops matching on its own once Trivy bumps grpc. Remove + # with the Trivy exception by 2026-10-15. + # https://github.com/advisories/GHSA-2v4p-qf9q-27wj + - vulnerability: CVE-2026-84445 + package: + name: google.golang.org/grpc + version: v1.82.1 # CVE-2026-56855 / CVE-2026-78662 are the same temporary exception documented in # .trivyignore.yaml: Trivy 0.74.0 still embeds golang.org/x/crypto v0.55.0, while the # 0.56.0 fix (published 2026-09-02) hasn't reached any Trivy release, or even Trivy diff --git a/.trivyignore.yaml b/.trivyignore.yaml index 28c3b7f0a9..715c7b625e 100644 --- a/.trivyignore.yaml +++ b/.trivyignore.yaml @@ -176,6 +176,25 @@ vulnerabilities: - "pkg:golang/google.golang.org/grpc" expired_at: 2026-10-15 + # CVE-2026-84445 is a DoS in grpc-go servers built with `xds.NewGRPCServer()`: a request + # carrying neither `:authority` nor `Host` reaches the xDS routing interceptor, which + # indexes an empty slice of authorities and panics. The per-RPC goroutine does not + # recover, so the whole server process dies. Fixed in 1.82.2 and 1.83.2 (published + # 2026-09-08). Trivy 0.74.0, the latest published release and the version the images + # ship, pins 1.82.1 as an indirect dependency: + # https://github.com/aquasecurity/trivy/blob/v0.74.0/go.mod + # Trivy main already carries 1.83.2, but no published release includes it yet. + # The reachability argument is the one made for CVE-2026-84304 above, only narrower: + # this panic needs an xDS-managed gRPC server. Prowler invokes Trivy exclusively as + # `trivy image` and `trivy fs` on a local path, never `trivy server`, so the image runs + # no gRPC server at all, xDS or otherwise. Remove this temporary suppression as soon as + # a Trivy release pins grpc >= 1.83.2. + # https://github.com/advisories/GHSA-2v4p-qf9q-27wj + - id: CVE-2026-84445 + purls: + - "pkg:golang/google.golang.org/grpc@v1.82.1" + expired_at: 2026-10-15 + # CVE-2026-56855 and CVE-2026-78662 are DoS deadlocks in x/crypto/ssh: a malicious peer # can flood or misuse channel messages (RFC 4254) to block the whole connection. # Fixed in golang.org/x/crypto v0.56.0 (published 2026-09-02). Trivy 0.74.0, the latest From bbf5e1fa9fc13c12476525f5230489ca823dfd49 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pedro=20Mart=C3=ADn?= Date: Wed, 9 Sep 2026 15:58:35 +0100 Subject: [PATCH 05/16] fix(tests): isolate secretsmanager policy test (#12782) --- .../secretsmanager_has_restrictive_resource_policy_test.py | 6 ------ 1 file changed, 6 deletions(-) diff --git a/tests/providers/aws/services/secretsmanager/secretsmanager_has_restrictive_resource_policy/secretsmanager_has_restrictive_resource_policy_test.py b/tests/providers/aws/services/secretsmanager/secretsmanager_has_restrictive_resource_policy/secretsmanager_has_restrictive_resource_policy_test.py index 5482fcbbcc..cdf45e446e 100644 --- a/tests/providers/aws/services/secretsmanager/secretsmanager_has_restrictive_resource_policy/secretsmanager_has_restrictive_resource_policy_test.py +++ b/tests/providers/aws/services/secretsmanager/secretsmanager_has_restrictive_resource_policy/secretsmanager_has_restrictive_resource_policy_test.py @@ -103,12 +103,6 @@ class TestSecretsManagerHasRestrictiveResourcePolicy: with mock_aws(): aws_provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1]) - from prowler.providers.aws.services.secretsmanager.secretsmanager_has_restrictive_resource_policy.secretsmanager_has_restrictive_resource_policy import ( - secretsmanager_client, - ) - - secretsmanager_client.secrets.clear() - with ( mock.patch( "prowler.providers.common.provider.Provider.get_global_provider", From c71f226e5c90acdb41be6e7d0335f87468809eed Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 9 Sep 2026 17:00:50 +0200 Subject: [PATCH 06/16] fix(image): honour TRIVY_CACHE_DIR when it is set (#12773) Co-authored-by: pedrooot --- .../providers/image/getting-started-image.mdx | 23 +++++++++++++ .../trivy-cache-dir-configurable.fixed.md | 1 + prowler/providers/image/image_provider.py | 13 +++++--- tests/providers/image/image_provider_test.py | 33 +++++++++++++++++++ 4 files changed, 66 insertions(+), 4 deletions(-) create mode 100644 prowler/changelog.d/trivy-cache-dir-configurable.fixed.md diff --git a/docs/user-guide/providers/image/getting-started-image.mdx b/docs/user-guide/providers/image/getting-started-image.mdx index d3d74ddba1..6b5d30b72e 100644 --- a/docs/user-guide/providers/image/getting-started-image.mdx +++ b/docs/user-guide/providers/image/getting-started-image.mdx @@ -96,6 +96,29 @@ Install Trivy using one of the following methods: For additional installation methods, see the [Trivy installation guide](https://trivy.dev/latest/getting-started/installation/). +### Vulnerability Database Cache + + + +Trivy keeps its vulnerability database in a cache directory. By default Prowler gives it a temporary one and removes it when the scan ends, so the database is downloaded again for every scan. + +Set `TRIVY_CACHE_DIR` to a directory that persists and the database is downloaded once and reused: + +```bash +export TRIVY_CACHE_DIR="$HOME/.cache/trivy" +prowler image --image +``` + +Prowler never deletes a directory you supply. Trivy still creates and updates its cache and database files inside it. + + +A host with no internet access needs a pre-populated vulnerability database in a persistent directory, with `TRIVY_CACHE_DIR` pointing at it. Populate the directory on a machine that does have access and copy it across. + +Trivy tries to refresh the database when it considers it stale, and that download fails without network access. Set `TRIVY_SKIP_DB_UPDATE=true` (and `TRIVY_SKIP_JAVA_DB_UPDATE=true` if Java scanning is enabled) so it uses the supplied database as is. + +The database ages. A scan run against an old one reports only the vulnerabilities known when it was built, and nothing in the output says so, so keep track of when it was last refreshed. + + ### Supported Scanners diff --git a/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md b/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md new file mode 100644 index 0000000000..fd2f0ca117 --- /dev/null +++ b/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md @@ -0,0 +1 @@ +The Image provider now uses the directory named by `TRIVY_CACHE_DIR` when one is set, instead of a fresh temporary directory it deletes afterwards, so a deployment can supply a vulnerability database it already holds and one with network access stops re-downloading the database for every image it scans diff --git a/prowler/providers/image/image_provider.py b/prowler/providers/image/image_provider.py index 97a014d9f1..2709003bf1 100644 --- a/prowler/providers/image/image_provider.py +++ b/prowler/providers/image/image_provider.py @@ -115,10 +115,15 @@ class ImageProvider(Provider): self._session = None self._identity = "prowler" self._listing_only = False - self._trivy_cache_dir_obj = tempfile.TemporaryDirectory( - prefix="prowler-trivy-cache-" - ) - self._trivy_cache_dir = self._trivy_cache_dir_obj.name + # A supplied cache dir is never deleted: it may hold a DB we cannot refetch + configured_cache_dir = os.environ.get("TRIVY_CACHE_DIR", "").strip() + if configured_cache_dir: + self._trivy_cache_dir = configured_cache_dir + else: + self._trivy_cache_dir_obj = tempfile.TemporaryDirectory( + prefix="prowler-trivy-cache-" + ) + self._trivy_cache_dir = self._trivy_cache_dir_obj.name # Registry authentication (follows IaC pattern: explicit params, env vars internal) self.registry_username = registry_username or os.environ.get( diff --git a/tests/providers/image/image_provider_test.py b/tests/providers/image/image_provider_test.py index cb3bbf2899..94c6a7181b 100644 --- a/tests/providers/image/image_provider_test.py +++ b/tests/providers/image/image_provider_test.py @@ -50,6 +50,11 @@ def _make_provider(**kwargs): return ImageProvider(**defaults) +@pytest.fixture(autouse=True) +def _no_configured_cache_dir(monkeypatch): + monkeypatch.delenv("TRIVY_CACHE_DIR", raising=False) + + class TestImageProvider: def test_image_provider(self): """Test default initialization.""" @@ -999,6 +1004,34 @@ class TestCleanup: provider.cleanup() provider.cleanup() + def test_configured_cache_dir_is_used(self, monkeypatch, tmp_path): + """A deployment that supplies a cache directory gets that one.""" + monkeypatch.setenv("TRIVY_CACHE_DIR", str(tmp_path)) + + provider = _make_provider() + + assert provider._trivy_cache_dir == str(tmp_path) + + def test_configured_cache_dir_survives_cleanup(self, monkeypatch, tmp_path): + """A supplied directory is not the provider's to delete: it holds a + database the deployment may have no way to fetch again.""" + monkeypatch.setenv("TRIVY_CACHE_DIR", str(tmp_path)) + provider = _make_provider() + + provider.cleanup() + + assert os.path.isdir(str(tmp_path)) + + def test_unset_cache_dir_keeps_the_temporary_one(self, monkeypatch): + """Without one configured, nothing changes for existing deployments.""" + monkeypatch.delenv("TRIVY_CACHE_DIR", raising=False) + + provider = _make_provider() + + assert os.path.isdir(provider._trivy_cache_dir) + provider.cleanup() + assert not os.path.isdir(provider._trivy_cache_dir) + def test_cleanup_removes_trivy_cache_dir(self): """Test that cleanup removes the temporary Trivy cache directory.""" provider = _make_provider() From 6f6ae88a66b1808060f45effa22b09247b6ba3a8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 9 Sep 2026 17:11:43 +0200 Subject: [PATCH 07/16] fix(ui): patch the Next.js and sharp image-handling vulnerabilities (#12778) Co-authored-by: alejandrobailo --- .../next-image-optimization-rce.security.md | 1 + .../sharp-libheif-vulnerabilities.security.md | 1 + ui/dependency-log.json | 12 +- ui/package.json | 4 +- ui/pnpm-lock.yaml | 385 +++++++++--------- ui/pnpm-workspace.yaml | 6 +- 6 files changed, 207 insertions(+), 202 deletions(-) create mode 100644 ui/changelog.d/next-image-optimization-rce.security.md create mode 100644 ui/changelog.d/sharp-libheif-vulnerabilities.security.md diff --git a/ui/changelog.d/next-image-optimization-rce.security.md b/ui/changelog.d/next-image-optimization-rce.security.md new file mode 100644 index 0000000000..5000fa95f8 --- /dev/null +++ b/ui/changelog.d/next-image-optimization-rce.security.md @@ -0,0 +1 @@ +`next` to 16.3.3, patching an unauthenticated remote code execution in the Image Optimization API when AVIF files are used (GHSA-2xp9-vwfh-vxw4) diff --git a/ui/changelog.d/sharp-libheif-vulnerabilities.security.md b/ui/changelog.d/sharp-libheif-vulnerabilities.security.md new file mode 100644 index 0000000000..75296b55dc --- /dev/null +++ b/ui/changelog.d/sharp-libheif-vulnerabilities.security.md @@ -0,0 +1 @@ +`sharp` to 0.35.4, patching two libheif vulnerabilities reachable through image decoding (GHSA-rgj7-g3m4-5g8c) diff --git a/ui/dependency-log.json b/ui/dependency-log.json index 556b50cdbb..af0cf7a367 100644 --- a/ui/dependency-log.json +++ b/ui/dependency-log.json @@ -498,10 +498,10 @@ { "section": "dependencies", "name": "next", - "from": "16.2.9", - "to": "16.2.11", + "from": "16.2.11", + "to": "16.3.3", "strategy": "installed", - "generatedAt": "2026-07-24T08:32:45.227Z" + "generatedAt": "2026-09-09T12:23:05.642Z" }, { "section": "dependencies", @@ -594,10 +594,10 @@ { "section": "dependencies", "name": "sharp", - "from": "0.33.5", - "to": "0.35.3", + "from": "0.35.3", + "to": "0.35.4", "strategy": "installed", - "generatedAt": "2026-08-11T11:35:35.609Z" + "generatedAt": "2026-09-09T12:39:08.649Z" }, { "section": "dependencies", diff --git a/ui/package.json b/ui/package.json index 8101c117f5..9afd17df19 100644 --- a/ui/package.json +++ b/ui/package.json @@ -97,7 +97,7 @@ "marked": "15.0.12", "modern-screenshot": "4.7.0", "nanoid": "5.1.16", - "next": "16.2.11", + "next": "16.3.3", "next-auth": "5.0.0-beta.32", "next-themes": "0.2.1", "posthog-js": "1.407.2", @@ -109,7 +109,7 @@ "recharts": "2.15.4", "require-in-the-middle": "8.0.1", "server-only": "0.0.1", - "sharp": "0.35.3", + "sharp": "0.35.4", "streamdown": "1.6.10", "tailwind-merge": "3.3.1", "tailwindcss-animate": "1.0.7", diff --git a/ui/pnpm-lock.yaml b/ui/pnpm-lock.yaml index 01200c3e6d..6ae1c07bdf 100644 --- a/ui/pnpm-lock.yaml +++ b/ui/pnpm-lock.yaml @@ -12,7 +12,7 @@ overrides: '@react-aria/visually-hidden>react': 19.2.7 '@react-aria/interactions>react': 19.2.7 lodash: 4.18.1 - sharp: 0.35.3 + sharp: 0.35.4 lodash-es: 4.18.1 hono: 4.12.34 '@hono/node-server': 1.19.17 @@ -92,7 +92,7 @@ importers: version: 1.2.3 '@next/third-parties': specifier: 16.2.9 - version: 16.2.9(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7) + version: 16.2.9(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7) '@radix-ui/react-alert-dialog': specifier: 1.1.14 version: 1.1.14(@types/react-dom@19.2.3(@types/react@19.2.17))(@types/react@19.2.17)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) @@ -167,7 +167,7 @@ importers: version: 3.26.0(react@19.2.7) '@sentry/nextjs': specifier: 10.65.0 - version: 10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) + version: 10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) '@tailwindcss/postcss': specifier: 4.1.18 version: 4.1.18 @@ -238,14 +238,14 @@ importers: specifier: 5.1.16 version: 5.1.16 next: - specifier: 16.2.11 - version: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) + specifier: 16.3.3 + version: 16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) next-auth: specifier: 5.0.0-beta.32 - version: 5.0.0-beta.32(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7) + version: 5.0.0-beta.32(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7) next-themes: specifier: 0.2.1 - version: 0.2.1(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react-dom@19.2.7(react@19.2.7))(react@19.2.7) + version: 0.2.1(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react-dom@19.2.7(react@19.2.7))(react@19.2.7) posthog-js: specifier: 1.407.2 version: 1.407.2(preact-render-to-string@6.5.11(preact@10.24.3)) @@ -274,8 +274,8 @@ importers: specifier: 0.0.1 version: 0.0.1 sharp: - specifier: 0.35.3 - version: 0.35.3(@types/node@24.10.8) + specifier: 0.35.4 + version: 0.35.4(@types/node@24.10.8) streamdown: specifier: 1.6.10 version: 1.6.10(@types/mdast@4.0.4)(micromark-util-types@2.0.2)(micromark@4.0.2)(react@19.2.7) @@ -780,8 +780,8 @@ packages: '@codemirror/state@6.6.0': resolution: {integrity: sha512-4nbvra5R5EtiCzr9BTHiTLc+MLXK2QGiAVYMyi8PkQd3SR+6ixar/Q/01Fa21TBIDOZXgeWV4WppsQolSreAPQ==} - '@codemirror/state@6.7.2': - resolution: {integrity: sha512-U3RiPX62Wl/Gx4ftQ7UxLlloSfsFTQqKa+7vFBYteZGCzkp6oBqcsD7iSwniWRGobCAmDcwZSY+Six3+3ztdfg==} + '@codemirror/state@6.7.4': + resolution: {integrity: sha512-QhQIVRY+xHZDxwOSFrJ1eUMapJBUID3IdeAjf7dHO7zBUzSkyooHiodnalz5MG3iHzwixKMlAAyn7244y537EA==} '@codemirror/theme-one-dark@6.1.3': resolution: {integrity: sha512-NzBdIvEJmx6fjeremiGp3t/okrLPYT0d9orIc7AFun8oZcRk58aejkqhv6spnz4MLAevrKNPMQYXEWMg4s+sKA==} @@ -1109,160 +1109,160 @@ packages: resolution: {integrity: sha512-Td76q7j57o/tLVdgS746cYARfSyxk8iEfRxewL9h4OMzYhbW4TAcppl0mT4eyqXddh6L/jwoM75mo7ixa/pCeQ==} engines: {node: '>=18'} - '@img/sharp-darwin-arm64@0.35.3': - resolution: {integrity: sha512-RMnFX7YQsMoh7lWfcM4NEHHymBX/rLuKNPVM84XE9ONPcaSCDgE7CHIHpSgPcO2xcRthgBy1HfNO319mwhIAkg==} + '@img/sharp-darwin-arm64@0.35.4': + resolution: {integrity: sha512-Uhfl4V4lhP2nbUVF9+hyH1+luj86f1gUFeo8ALYxFoULoU+G87D43BfeMP8XHsk9boxAnCY/bf2EHwhA7MuGsA==} engines: {node: '>=20.9.0'} cpu: [arm64] os: [darwin] - '@img/sharp-darwin-x64@0.35.3': - resolution: {integrity: sha512-Xo+5uFBtLN0BKqieTxiFzFPQAUlBbbH5iBKyRX/z1JrbnYsHTfKJnUfL8+p2TPXr1pXqao4eeL4Rl144uDpK9w==} + '@img/sharp-darwin-x64@0.35.4': + resolution: {integrity: sha512-hWniXY3bG5qKpkKrAwPe4y+VTPmf086YQAnkxWh7uA1YrlRouWGa0M0Mxj3ZjnXFkv7/TD1bTy9lGUK26vRvWw==} engines: {node: '>=20.9.0'} cpu: [x64] os: [darwin] - '@img/sharp-freebsd-wasm32@0.35.3': - resolution: {integrity: sha512-lUxcqWIj2wMQ9BrwNjngcr1gWUr5xgaGThBRqPPalIC2n67Cqj1uPh8NnA/ZhAg8hUbKl+kVHKwgUIwe6ZYPrg==} + '@img/sharp-freebsd-wasm32@0.35.4': + resolution: {integrity: sha512-lIsKw/BU+kjB4eZjxrYrZmwOJYi3Ajrv66iAlBmUPyKc3HpnloevB1g3wxGD9P/5BbQ1brBGl65VRRrCvQDEqA==} engines: {node: '>=20.9.0'} os: [freebsd] - '@img/sharp-libvips-darwin-arm64@1.3.2': - resolution: {integrity: sha512-9J6ypZFpQBj4YnePGoq/S38w6nz+vqg5WZLrLGY4YuSemdMq47GMLBPO42MzwdGwpg/agZ7xzZcFHa48xlywfg==} + '@img/sharp-libvips-darwin-arm64@1.3.3': + resolution: {integrity: sha512-suTBPTDGrI9WodccaDdwZItTSaBYASlBk1NSfElSHrUfzu3szG6lvIF58+WiFvnfzuK8ZBFS5zE00PxqxnRiPg==} cpu: [arm64] os: [darwin] - '@img/sharp-libvips-darwin-x64@1.3.2': - resolution: {integrity: sha512-m2pW1n6cns9VaubNwsZ+c3CRYjxNQWgJ5gPlnL1nbBcpkBvFm6SCFN5o0psFHI8w9n11NKhFkeEDns98tiqbEw==} + '@img/sharp-libvips-darwin-x64@1.3.3': + resolution: {integrity: sha512-FVJZ5mITMobmXIz/hPDTw0EintTW5H3WfrxwLqEqjiIihlu+hVRyGrFQ60xl0Lxn7Bt3zdpevPaQi0HEzqz9fw==} cpu: [x64] os: [darwin] - '@img/sharp-libvips-linux-arm64@1.3.2': - resolution: {integrity: sha512-dqVSFynCox4C/J8kT16V7SIFAns0IjgLwkvYT7p8LQVmJ5OS5b6tI9IGflxTeuBS//zXeFIUbwt5dwxyZ17cnA==} + '@img/sharp-libvips-linux-arm64@1.3.3': + resolution: {integrity: sha512-0DaL0A6Xu6sQSQFwe4iVCrKWU2cCTItnRsYsCdxAMm9NF6twAA9BKnoqy4hqz4+azQ0JHuA26qiUKsf1XJ/v5A==} cpu: [arm64] os: [linux] libc: [glibc] - '@img/sharp-libvips-linux-arm@1.3.2': - resolution: {integrity: sha512-1eMLzy92I4J6rmi4mAT8yC3HxOtniyGELlzGbNMLLeqe052ahFQ0h6LFq+lh5DsDIdYViIDst08abvSbcEdLXQ==} + '@img/sharp-libvips-linux-arm@1.3.3': + resolution: {integrity: sha512-3rbU4vqXXc3hY/OiXdl52xZvT0F1yEngWfvqudtPJg/KkyiaQw2DRsFrNzpmLvfavbwOq3qXn36GP8obHRULQA==} cpu: [arm] os: [linux] libc: [glibc] - '@img/sharp-libvips-linux-ppc64@1.3.2': - resolution: {integrity: sha512-3z0NHDxD6n5I9gc05U1eW1AyRm+Gznzq3naMrthPNqE6oYykcogW0l/jfpJdjYnuNl8R7yI9pNbE1XiUeyq0Aw==} + '@img/sharp-libvips-linux-ppc64@1.3.3': + resolution: {integrity: sha512-cdn1OvUBwsXhbC0zSzJnNzf5MZ/mTrobawDvNXBTxe8VtqKAm0sRuEY2Evzovb/w9JMk4TvRxqt1mekSuJz64w==} cpu: [ppc64] os: [linux] libc: [glibc] - '@img/sharp-libvips-linux-riscv64@1.3.2': - resolution: {integrity: sha512-bsb4rI+NldGOsXuej2r8OdSS8+zXDVaCWxyWrcv6kneTOlgAHtZABRzBBCwdsPiD90J4myNJuHpg6kA20ImW/w==} + '@img/sharp-libvips-linux-riscv64@1.3.3': + resolution: {integrity: sha512-HjPVx7yKz+0lqdhDlTw1tt90wamBoxhiXpvl1XZpJLiHH4RCJ5yDTqH+VlYPv2fwFs89JFw4c1IexYOcQUi4IQ==} cpu: [riscv64] os: [linux] libc: [glibc] - '@img/sharp-libvips-linux-s390x@1.3.2': - resolution: {integrity: sha512-/ABshyj8gCpyIrNXnHn4LorDJ0HHm1VhXPBlxZ8zAtfVPAaSafXPGn+sUSIRiwaSBy0mmFjSjiXI5mkcwdChKQ==} + '@img/sharp-libvips-linux-s390x@1.3.3': + resolution: {integrity: sha512-neWLh+3yCNThxnfy3c4BbVBeGgt9aftno+XbT56iK28RgeDs3UOFWviLWlUu0bArYVYJaFDK+RRohbicUNCm8Q==} cpu: [s390x] os: [linux] libc: [glibc] - '@img/sharp-libvips-linux-x64@1.3.2': - resolution: {integrity: sha512-ITPEtgffGJ0S6G9dRyw/366tJQqFRcHWPHhC+Stpg3Z8AEMrDrTr2lhdz4f/Y/HMbRh//7Z5mBzEpVdi62Oc3w==} + '@img/sharp-libvips-linux-x64@1.3.3': + resolution: {integrity: sha512-4vKmvAst9nrowcqquKFAyZJUDolUaIp8uRiN0mWFguJ1IplC9/pitXtlnnlU4aa/eJw3J7i67V+pwUL+wZGdsA==} cpu: [x64] os: [linux] libc: [glibc] - '@img/sharp-libvips-linuxmusl-arm64@1.3.2': - resolution: {integrity: sha512-zE9EdiUzUmg5mDT5a1rk5fYJ6GWPloTwWBYDS14naqHsL+EaMpDj1AWnpLgh3u0YCORv2Tt50wrcrpYqkP97Kw==} + '@img/sharp-libvips-linuxmusl-arm64@1.3.3': + resolution: {integrity: sha512-Y9kQaLMuNoB0bPYOOdcZMaseNrFpPodIWWMrx+CZyydf2xn68j9WYc6sWWRrDwNkzCQjKYfc68L7jKjGlHMibw==} cpu: [arm64] os: [linux] libc: [musl] - '@img/sharp-libvips-linuxmusl-x64@1.3.2': - resolution: {integrity: sha512-m0lrLiUt+lBYnCFr8qV/65yMR4E/c7/wf78I5eKTdkEakFAlZ9QlzEM3QIhhAwVeUhLAHLcCq7a7Vszq/oFNZQ==} + '@img/sharp-libvips-linuxmusl-x64@1.3.3': + resolution: {integrity: sha512-fj8Mv0HHfD1Rr+4I68+3agJynxDWtBFgicTbSOb9Bke6pIwzGcJ+RX/yHjmiEGFMCavY/dxvem7MyNaJF+wDiw==} cpu: [x64] os: [linux] libc: [musl] - '@img/sharp-linux-arm64@0.35.3': - resolution: {integrity: sha512-QgKDspHPnrU+GQ55XPhGwyhC8acLVOOSyAvo1oVfFmrIXLkDNmGWzAfDZ4xK8oSA1qBQrALcHX0G5UZni/SuFQ==} + '@img/sharp-linux-arm64@0.35.4': + resolution: {integrity: sha512-De4jpEnAU8Hd5oT0j1G3uL4ZvTuipVMn7YC6vPaJhy6/7EwEae0SVAoBrUMYQbkLGDm85taVWwuPc1a44LTzCQ==} engines: {node: '>=20.9.0'} cpu: [arm64] os: [linux] libc: [glibc] - '@img/sharp-linux-arm@0.35.3': - resolution: {integrity: sha512-affVWCTLooy8TSxbDx2qkzuDeaWLNVBA+P//FNBirHsXpP2fuBhk5AuboYUnrDnzoXes8GFjpTx0SBFOCRg+FA==} + '@img/sharp-linux-arm@0.35.4': + resolution: {integrity: sha512-7OAS8gI0EReKGVN2HssHlM6umJgxF5VI3xN0p9FA91p/YO+ou5hiNghLdZ5BEHztwaaK5+bLKRf8x/o2L2nk9A==} engines: {node: '>=20.9.0'} cpu: [arm] os: [linux] libc: [glibc] - '@img/sharp-linux-ppc64@0.35.3': - resolution: {integrity: sha512-sMd8rDxmpLOwv/7N44klFjOD5DUO7FLdjiXDI0hoxYaf7Ar262dQIEkosE98bps+5HPLtp/EvNqeqQtOycP/IA==} + '@img/sharp-linux-ppc64@0.35.4': + resolution: {integrity: sha512-2oYZJeIl4kCcMGk4ouZVjnkCtFrpQFlNEtJ6GbxzhHQchwH0NH/qEb9ykmOl29dqwMq+JhFdZn+1ak2FKhI9fQ==} engines: {node: '>=20.9.0'} cpu: [ppc64] os: [linux] libc: [glibc] - '@img/sharp-linux-riscv64@0.35.3': - resolution: {integrity: sha512-0Eob78yjlYPfL5vMNWAW55l3R9Y6BQS/gOfe0ZcP9mEz9ohhKSt4im1hayiknXgf8AWrFqMvJcKIdmLmEe7yeQ==} + '@img/sharp-linux-riscv64@0.35.4': + resolution: {integrity: sha512-cPbNChoRURAWdebDIHSenxRpgEdy7JkPydSnUxRm9VvKD7m0/xVaR/8Fzlu81pk5nHEvHH87UZUA7cTtwnbJSA==} engines: {node: '>=20.9.0'} cpu: [riscv64] os: [linux] libc: [glibc] - '@img/sharp-linux-s390x@0.35.3': - resolution: {integrity: sha512-KgAxQ0DxpNOq1rG2t5cgTgShJFGSuU7XO45cqC+1NVOuZnP6tlgZRuSYOfNupGkHID0o3cJOsw4DVeJpMovcGw==} + '@img/sharp-linux-s390x@0.35.4': + resolution: {integrity: sha512-RY0JFY8Fd6RonCBtHz+DvadaPkXDSI1AUn6yWL9TipqkZ1vY8w8evqdgyDFnkm4/K1ve1TvZiaePP5oSd4+WVQ==} engines: {node: '>=20.9.0'} cpu: [s390x] os: [linux] libc: [glibc] - '@img/sharp-linux-x64@0.35.3': - resolution: {integrity: sha512-8pqvxubL2PGdhlPy6GLqzDYMUjyRmKAwKHYKixpdJYBUK7PJ0C029XdsnpFIdgRZG68fZiGdHVWcKPvtiPB4cA==} + '@img/sharp-linux-x64@0.35.4': + resolution: {integrity: sha512-9qvvEAuk8k89TfWUoX2htWjbAMX8p+NxCppjpcg5k6xMsjhBQPTsoIh36h9Qde4WRuGpJeYnOjdosDn/cnv+OA==} engines: {node: '>=20.9.0'} cpu: [x64] os: [linux] libc: [glibc] - '@img/sharp-linuxmusl-arm64@0.35.3': - resolution: {integrity: sha512-Vz0iQjzzcSX3HCbfwFfCSG/9SCIqyO0mH2sXyiHaAYfBk0cRsCWXRyQYX0ovCK/PAQBbTzQ0dsPQHh5MAFL59w==} + '@img/sharp-linuxmusl-arm64@0.35.4': + resolution: {integrity: sha512-KB5jxpfWQTr0nc3xdHtWChdbifHrBGsd2SM62Eyxrl8afikm+f5qGBU75SJIZBT/S1MC8XyacdlXBMSWq6OURA==} engines: {node: '>=20.9.0'} cpu: [arm64] os: [linux] libc: [musl] - '@img/sharp-linuxmusl-x64@0.35.3': - resolution: {integrity: sha512-6O1NPKcDVj9QEdg7Hx549EX8U0rp6yXQERqru6yRN7fGBn32UvIRJUlWnk+8xDCiG76hXVBbX82NZ/ZKr0euIg==} + '@img/sharp-linuxmusl-x64@0.35.4': + resolution: {integrity: sha512-f+eZJZIQNEEd26RPSW+76chwOf1XtA2Y/O+5ocVyLliHkeih3e+jhLVBdNTd2rS3IbNXK8+ug93Vf5ZXtF5Lxg==} engines: {node: '>=20.9.0'} cpu: [x64] os: [linux] libc: [musl] - '@img/sharp-wasm32@0.35.3': - resolution: {integrity: sha512-cZ0XkcYGpHZkqW6iCkqTcmUC0CD9DhD5d/qeZlZkfRBn6GnHniZXLUo5+9xw8Iv76YE6LQFN9YNBlKREcCG76w==} + '@img/sharp-wasm32@0.35.4': + resolution: {integrity: sha512-zQnl4Kwp7Q6NHsENtU2T/00Zi+w3AQNwz3+UaTyVBy2FpXrzXzGjndpK61onhZjRtRpQXxCTeqw19bVyXOh7jA==} engines: {node: '>=20.9.0'} - '@img/sharp-webcontainers-wasm32@0.35.3': - resolution: {integrity: sha512-2rnq7bX3NzeR2T4YWgz8qiG4h3TSdMe+vN1iQXpJleSJ3SM5zQ8Fy2SyyXAWlbxpEZ2Y+Z4u1BePgJEYbSy80Q==} + '@img/sharp-webcontainers-wasm32@0.35.4': + resolution: {integrity: sha512-ESfNkywmCfPNyaZjxooddJQiQ+l/nTpGEOGthxiLnIHXC/CmcBixnfwUleX9mCz9ovrUUvKMap/pm8RYbzfwaA==} engines: {node: '>=20.9.0'} cpu: [wasm32] - '@img/sharp-win32-arm64@0.35.3': - resolution: {integrity: sha512-4bPwFdMbeC4JQ8L8LOyWp6nsHcboP5fxkp6iPOXz2Vg49R42TuMs2whkJ5OAP4/Ul035qOzy0AecOF9VOscn4w==} + '@img/sharp-win32-arm64@0.35.4': + resolution: {integrity: sha512-iNdlBX9gLVvqe2I3uIJSIKTq6wckP/DYxZtcqxm09x5Gi24DnFBmPAWZmr60ZyYMG0xlzo6goG3670ar+RXvRw==} engines: {node: '>=20.9.0'} cpu: [arm64] os: [win32] - '@img/sharp-win32-ia32@0.35.3': - resolution: {integrity: sha512-r53mXsBN6lFUDiST764SvgwUdHAqM4rPAiDzAmf4fLoB6X/rkfyTrLCg6+g17wJJiCmB3JYgHuUldCWUIRFSXw==} + '@img/sharp-win32-ia32@0.35.4': + resolution: {integrity: sha512-kqRsbaa5CS6KHlpxnN7WhE6vAAugXyZButpRdvDWetlv6Qv4N9WTcrWzF7tXfB9T7MsoadqdI8hmwLq6UlLvtw==} engines: {node: ^20.9.0} cpu: [ia32] os: [win32] - '@img/sharp-win32-x64@0.35.3': - resolution: {integrity: sha512-D4y1vNeZrIIJCN+uHaWVtH86B+aCrdMYYjicy9pXHvbGZeGYLLSd3wdVuC37FxVXlU1ARsk84eKWfWMXGYEqvA==} + '@img/sharp-win32-x64@0.35.4': + resolution: {integrity: sha512-XtmnYhBcrORsJ4XJngyzr/EWP0hRZLAZRFaApdKuviyqF78+ylxh2y06ZmtULAMOnObJ3ucpN0AcwSWnMowTRg==} engines: {node: '>=20.9.0'} cpu: [x64] os: [win32] @@ -1422,60 +1422,60 @@ packages: '@ndaidong/bellajs@12.0.1': resolution: {integrity: sha512-1iY42uiHz0cxNMbde7O3zVN+ZX1viOOUOBRt6ht6lkRZbSjwOnFV34Zv4URp3hGzEe6L9Byk7BOq/41H0PzAOQ==} - '@next/env@16.2.11': - resolution: {integrity: sha512-0do5A3BJ2gxWr0ZCMcD6BhW+e595jyxdTl3rXTS6lOtD8ektMiW6CO+EPwt1Eca1DBnm90r/7GdiKWBKxH++DA==} + '@next/env@16.3.3': + resolution: {integrity: sha512-U2eYQRwXj+dsqxV79zFqExDdatnNY/ZWc2nsJU1p/OgT7fd3dXwlF6OjYaFQCfMoeTA19PWq+wVmYgimVA+V+g==} '@next/eslint-plugin-next@16.2.9': resolution: {integrity: sha512-UZi8+YT/MLgTC9nrrn2Xd4lBYv1B7lVmtWHfPcthAI5Tt/C1LuDe6DfmtCtJ+WQod3ksY4VrKSvk3oMVAnL7qw==} - '@next/swc-darwin-arm64@16.2.11': - resolution: {integrity: sha512-wryL4pjKmDwGv2ox6+GZDFxvmtSRLqApBR8kL1j4+vhB7Z5vJC/zAnXpiR9Xkfzl0AS8WLMnsuGV/UKI67/rrw==} + '@next/swc-darwin-arm64@16.3.3': + resolution: {integrity: sha512-8Hiv32QJPwdV6KYJ8meR9SBA061tQqnIKTJDocvOXlEQqib0xMFpzArosuffFUUc0sslbh7QQ8a3Yey1QV8EIw==} engines: {node: '>= 10'} cpu: [arm64] os: [darwin] - '@next/swc-darwin-x64@16.2.11': - resolution: {integrity: sha512-aZl2j4f/fLyjQvOhv0Oe9UaMAQHolYpKhctsoYzplSumKJKPUmgjcf6545aBtysLTcu994TREd0+pSgNE4ohmg==} + '@next/swc-darwin-x64@16.3.3': + resolution: {integrity: sha512-A1lgKgwVchRYmSe467zdwhxT9040dd8lH+o65sL5Jet8fjB4kegw/rDyPIpYVRb6jAqwXFOJpjIXJLxQKLiE3A==} engines: {node: '>= 10'} cpu: [x64] os: [darwin] - '@next/swc-linux-arm64-gnu@16.2.11': - resolution: {integrity: sha512-5jEriyEnH/LWFy27L2ZG0XaLlyEJIjhsImEsiS9P563PKEVp2BVups/xfOucIrsvVntp11oNcZwjHvaDPYVB5g==} + '@next/swc-linux-arm64-gnu@16.3.3': + resolution: {integrity: sha512-bf0FIssMFueU2dm7vQEWWxk0c8UjKTdW0yzuh0sQsD8pf1+KCLDdaqhYZNMYGmXwEOiHAUzgBKudovIlcvvBjg==} engines: {node: '>= 10'} cpu: [arm64] os: [linux] libc: [glibc] - '@next/swc-linux-arm64-musl@16.2.11': - resolution: {integrity: sha512-eIjcpx2fnnFSSkZDbTxy74KnokUXDjfoLClpWelfgHLf621aTqswhwXQ7GkD5K5rplrS6LZ/Bj+mVuvzluBOEg==} + '@next/swc-linux-arm64-musl@16.3.3': + resolution: {integrity: sha512-W7viwCk9JY/cAkdz/A273rd5bb3RgT/IHwR7Upv90tunjBWNtAAhGhoecHh+teRNRSinuAFmE+l7fwZ4YKkrXg==} engines: {node: '>= 10'} cpu: [arm64] os: [linux] libc: [musl] - '@next/swc-linux-x64-gnu@16.2.11': - resolution: {integrity: sha512-8WgzpaWMs46qJT9kiV47cje86L0x/Mu9t8/Gwj+pnbgW3rETVfCnaScPjlYUwNScpOozdcIMHWmAvuZJUonR2w==} + '@next/swc-linux-x64-gnu@16.3.3': + resolution: {integrity: sha512-0W46zw1N3ODpI6n0GeivHvvob1pooozgZVqy65k0mh4/7vr+FbY9+WpHzNVXjHipJf/A3FDheBG19H1s5A25rA==} engines: {node: '>= 10'} cpu: [x64] os: [linux] libc: [glibc] - '@next/swc-linux-x64-musl@16.2.11': - resolution: {integrity: sha512-I3UgPds7G4ZYnTb/H+5GBGuUT2DhAk6j0mL6A4s63RjFs74wB2hOWP0vaxsK+3NJraExt3eYEPQ/UtT0x/64Nw==} + '@next/swc-linux-x64-musl@16.3.3': + resolution: {integrity: sha512-H4mBso8ZTMBPtdT0PN0pBx2ayTvQuTuvS6qT13d77yVFJXAPCxkyIhLTmdMaGTJs0krQYI/qpzdHijCeihXhbg==} engines: {node: '>= 10'} cpu: [x64] os: [linux] libc: [musl] - '@next/swc-win32-arm64-msvc@16.2.11': - resolution: {integrity: sha512-n89CjtcThnjrwgJMAiI5xbqwLY51zvwC9tSlArmVndAJLYVl9T9UAdlkXTmZvE++idoXe8KdglQlhNRdUp1c6g==} + '@next/swc-win32-arm64-msvc@16.3.3': + resolution: {integrity: sha512-cTMUJpcEGmeywofCUfhR+rSsoE33+rVPnPEYNTNdLNlsOeEg/vktOsKUSTb28vUGqD2jkm4Zaskcwn7OCI6FQg==} engines: {node: '>= 10'} cpu: [arm64] os: [win32] - '@next/swc-win32-x64-msvc@16.2.11': - resolution: {integrity: sha512-md8CLNggS1Dx9pUgApzps5uAf+N8GN9xywzmNx9vHAWo94HtBwCCqkSnhIrdfQe83Dhz8Lfo/20Nb1Zxal092w==} + '@next/swc-win32-x64-msvc@16.3.3': + resolution: {integrity: sha512-2VR4cTBzHXaBjnGsuH6GyJjENzQOmHeAh11uY1iUhjm3j5dEUrVJuUj+VL78jaGi/Dik8xS76zEj18BsFhlVZQ==} engines: {node: '>= 10'} cpu: [x64] os: [win32] @@ -3065,12 +3065,12 @@ packages: '@standard-schema/utils@0.3.0': resolution: {integrity: sha512-e7Mew686owMaPJVNNLs55PUvgz371nKgwsc4vxE49zsODpJEnxgxRo2y/OKrqueavXgZNMDVj3DdHFlaSAeU8g==} - '@swc/helpers@0.5.15': - resolution: {integrity: sha512-JQ5TuMi45Owi4/BIMAJBoSQoOJu12oOk/gADqlcUL9JEdHB8vyjUSsxqeNXnmXHjYKMi2WcYtezGEEhqUI/E2g==} - '@swc/helpers@0.5.18': resolution: {integrity: sha512-TXTnIcNJQEKwThMMqBXsZ4VGAza6bvN4pa41Rkqoio6QBKMvo+5lexeTMScGCIxtzgQJzElcvIltani+adC5PQ==} + '@swc/helpers@0.5.23': + resolution: {integrity: sha512-5lSsMOTXURePglDfvuAQUqkGek9Hg2kksOYay2m0+XR++b2NWYL/4sWyuvVBIs8oKnJaxkdi9whaL/sqN13afw==} + '@tailwindcss/node@4.1.18': resolution: {integrity: sha512-DoR7U1P7iYhw16qJ49fgXUlry1t4CpXeErJHnQ44JgTSKMaZUdf17cfn5mHchfJ4KRBZRFA/Coo+MUF5+gOaCQ==} @@ -4573,6 +4573,7 @@ packages: eslint@9.39.2: resolution: {integrity: sha512-LEyamqS7W5HB3ujJyvi0HQK/dtVINZvd5mAAp9eT5S/ujByGjiZLCzPcHVzuXbpJDJF/cxwHlfceVUDZ2lnSTw==} engines: {node: ^18.18.0 || ^20.9.0 || >=21.1.0} + deprecated: This version is no longer supported. Please see https://eslint.org/version-support for other options. hasBin: true peerDependencies: jiti: '*' @@ -5808,8 +5809,8 @@ packages: react: '*' react-dom: '*' - next@16.2.11: - resolution: {integrity: sha512-B339zaqbyK8cmxhoAvLrcwoabwCP1wz21zSzfqxqXAemTu2BXnH7tQnfcglKv1vnMUIDBc+Hth7XODQriTZiRQ==} + next@16.3.3: + resolution: {integrity: sha512-tuRTx1nQ/yVw83cwJBo9F+njGUgMn3UHQycreWHB8XsStvvAh1AthbI8/4IpKnFaF58F+iSiHejYOlMQ/eq83g==} engines: {node: '>=20.9.0'} hasBin: true peerDependencies: @@ -6491,8 +6492,8 @@ packages: setprototypeof@1.2.0: resolution: {integrity: sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==} - sharp@0.35.3: - resolution: {integrity: sha512-ej0zVHuZGHCiABXcNxeYhpRnPNPAcvbG8RMdBAhDAxLKkCRVSpK3Iyu7qbqw3JMzoj0REeM6f3tJLtVwl0023Q==} + sharp@0.35.4: + resolution: {integrity: sha512-n++8XWcj+jCOr2IOl7h8LbKnGBDY4aPbmprMONBNFdn0ImXqpGVv5zliDs0V9HbmbCQLpbuo2ej9rAoOQTvMDA==} engines: {node: '>=20.9.0'} peerDependencies: '@types/node': '*' @@ -8032,7 +8033,7 @@ snapshots: '@codemirror/commands@6.11.0': dependencies: '@codemirror/language': 6.12.2 - '@codemirror/state': 6.7.2 + '@codemirror/state': 6.7.4 '@codemirror/view': 6.40.0 '@lezer/common': 1.5.2 @@ -8061,7 +8062,7 @@ snapshots: dependencies: '@marijn/find-cluster-break': 1.0.2 - '@codemirror/state@6.7.2': + '@codemirror/state@6.7.4': dependencies: '@marijn/find-cluster-break': 1.0.4 @@ -8322,108 +8323,108 @@ snapshots: '@img/colour@1.1.0': {} - '@img/sharp-darwin-arm64@0.35.3': + '@img/sharp-darwin-arm64@0.35.4': optionalDependencies: - '@img/sharp-libvips-darwin-arm64': 1.3.2 + '@img/sharp-libvips-darwin-arm64': 1.3.3 optional: true - '@img/sharp-darwin-x64@0.35.3': + '@img/sharp-darwin-x64@0.35.4': optionalDependencies: - '@img/sharp-libvips-darwin-x64': 1.3.2 + '@img/sharp-libvips-darwin-x64': 1.3.3 optional: true - '@img/sharp-freebsd-wasm32@0.35.3': + '@img/sharp-freebsd-wasm32@0.35.4': dependencies: - '@img/sharp-wasm32': 0.35.3 + '@img/sharp-wasm32': 0.35.4 optional: true - '@img/sharp-libvips-darwin-arm64@1.3.2': + '@img/sharp-libvips-darwin-arm64@1.3.3': optional: true - '@img/sharp-libvips-darwin-x64@1.3.2': + '@img/sharp-libvips-darwin-x64@1.3.3': optional: true - '@img/sharp-libvips-linux-arm64@1.3.2': + '@img/sharp-libvips-linux-arm64@1.3.3': optional: true - '@img/sharp-libvips-linux-arm@1.3.2': + '@img/sharp-libvips-linux-arm@1.3.3': optional: true - '@img/sharp-libvips-linux-ppc64@1.3.2': + '@img/sharp-libvips-linux-ppc64@1.3.3': optional: true - '@img/sharp-libvips-linux-riscv64@1.3.2': + '@img/sharp-libvips-linux-riscv64@1.3.3': optional: true - '@img/sharp-libvips-linux-s390x@1.3.2': + '@img/sharp-libvips-linux-s390x@1.3.3': optional: true - '@img/sharp-libvips-linux-x64@1.3.2': + '@img/sharp-libvips-linux-x64@1.3.3': optional: true - '@img/sharp-libvips-linuxmusl-arm64@1.3.2': + '@img/sharp-libvips-linuxmusl-arm64@1.3.3': optional: true - '@img/sharp-libvips-linuxmusl-x64@1.3.2': + '@img/sharp-libvips-linuxmusl-x64@1.3.3': optional: true - '@img/sharp-linux-arm64@0.35.3': + '@img/sharp-linux-arm64@0.35.4': optionalDependencies: - '@img/sharp-libvips-linux-arm64': 1.3.2 + '@img/sharp-libvips-linux-arm64': 1.3.3 optional: true - '@img/sharp-linux-arm@0.35.3': + '@img/sharp-linux-arm@0.35.4': optionalDependencies: - '@img/sharp-libvips-linux-arm': 1.3.2 + '@img/sharp-libvips-linux-arm': 1.3.3 optional: true - '@img/sharp-linux-ppc64@0.35.3': + '@img/sharp-linux-ppc64@0.35.4': optionalDependencies: - '@img/sharp-libvips-linux-ppc64': 1.3.2 + '@img/sharp-libvips-linux-ppc64': 1.3.3 optional: true - '@img/sharp-linux-riscv64@0.35.3': + '@img/sharp-linux-riscv64@0.35.4': optionalDependencies: - '@img/sharp-libvips-linux-riscv64': 1.3.2 + '@img/sharp-libvips-linux-riscv64': 1.3.3 optional: true - '@img/sharp-linux-s390x@0.35.3': + '@img/sharp-linux-s390x@0.35.4': optionalDependencies: - '@img/sharp-libvips-linux-s390x': 1.3.2 + '@img/sharp-libvips-linux-s390x': 1.3.3 optional: true - '@img/sharp-linux-x64@0.35.3': + '@img/sharp-linux-x64@0.35.4': optionalDependencies: - '@img/sharp-libvips-linux-x64': 1.3.2 + '@img/sharp-libvips-linux-x64': 1.3.3 optional: true - '@img/sharp-linuxmusl-arm64@0.35.3': + '@img/sharp-linuxmusl-arm64@0.35.4': optionalDependencies: - '@img/sharp-libvips-linuxmusl-arm64': 1.3.2 + '@img/sharp-libvips-linuxmusl-arm64': 1.3.3 optional: true - '@img/sharp-linuxmusl-x64@0.35.3': + '@img/sharp-linuxmusl-x64@0.35.4': optionalDependencies: - '@img/sharp-libvips-linuxmusl-x64': 1.3.2 + '@img/sharp-libvips-linuxmusl-x64': 1.3.3 optional: true - '@img/sharp-wasm32@0.35.3': + '@img/sharp-wasm32@0.35.4': dependencies: '@emnapi/runtime': 1.11.3 optional: true - '@img/sharp-webcontainers-wasm32@0.35.3': + '@img/sharp-webcontainers-wasm32@0.35.4': dependencies: - '@img/sharp-wasm32': 0.35.3 + '@img/sharp-wasm32': 0.35.4 optional: true - '@img/sharp-win32-arm64@0.35.3': + '@img/sharp-win32-arm64@0.35.4': optional: true - '@img/sharp-win32-ia32@0.35.3': + '@img/sharp-win32-ia32@0.35.4': optional: true - '@img/sharp-win32-x64@0.35.3': + '@img/sharp-win32-x64@0.35.4': optional: true '@inquirer/ansi@2.0.5': {} @@ -8642,39 +8643,39 @@ snapshots: '@ndaidong/bellajs@12.0.1': {} - '@next/env@16.2.11': {} + '@next/env@16.3.3': {} '@next/eslint-plugin-next@16.2.9': dependencies: fast-glob: 3.3.1 - '@next/swc-darwin-arm64@16.2.11': + '@next/swc-darwin-arm64@16.3.3': optional: true - '@next/swc-darwin-x64@16.2.11': + '@next/swc-darwin-x64@16.3.3': optional: true - '@next/swc-linux-arm64-gnu@16.2.11': + '@next/swc-linux-arm64-gnu@16.3.3': optional: true - '@next/swc-linux-arm64-musl@16.2.11': + '@next/swc-linux-arm64-musl@16.3.3': optional: true - '@next/swc-linux-x64-gnu@16.2.11': + '@next/swc-linux-x64-gnu@16.3.3': optional: true - '@next/swc-linux-x64-musl@16.2.11': + '@next/swc-linux-x64-musl@16.3.3': optional: true - '@next/swc-win32-arm64-msvc@16.2.11': + '@next/swc-win32-arm64-msvc@16.3.3': optional: true - '@next/swc-win32-x64-msvc@16.2.11': + '@next/swc-win32-x64-msvc@16.3.3': optional: true - '@next/third-parties@16.2.9(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)': + '@next/third-parties@16.2.9(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)': dependencies: - next: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) + next: 16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) react: 19.2.7 third-party-capital: 1.0.20 @@ -9598,7 +9599,7 @@ snapshots: '@react-aria/ssr@3.9.10(react@19.2.7)': dependencies: - '@swc/helpers': 0.5.18 + '@swc/helpers': 0.5.23 react: 19.2.7 '@react-aria/ssr@3.9.4(react@19.2.7)': @@ -9629,7 +9630,7 @@ snapshots: '@react-stately/flags@3.1.2': dependencies: - '@swc/helpers': 0.5.18 + '@swc/helpers': 0.5.23 '@react-stately/utils@3.10.8(react@19.2.7)': dependencies: @@ -9638,7 +9639,7 @@ snapshots: '@react-stately/utils@3.11.0(react@19.2.7)': dependencies: - '@swc/helpers': 0.5.18 + '@swc/helpers': 0.5.23 react: 19.2.7 '@react-types/shared@3.26.0(react@19.2.7)': @@ -9841,7 +9842,7 @@ snapshots: dependencies: '@sentry/core': 10.65.0 - '@sentry/nextjs@10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23))': + '@sentry/nextjs@10.65.0(@opentelemetry/core@2.9.0(@opentelemetry/api@1.9.1))(@opentelemetry/sdk-trace-base@2.9.0(@opentelemetry/api@1.9.1))(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23))': dependencies: '@opentelemetry/api': 1.9.1 '@rollup/plugin-commonjs': 28.0.1(rollup@4.59.0) @@ -9854,7 +9855,7 @@ snapshots: '@sentry/react': 10.65.0(react@19.2.7) '@sentry/vercel-edge': 10.65.0 '@sentry/webpack-plugin': 5.4.0(rollup@4.59.0)(webpack@5.104.1(lightningcss@1.30.2)(postcss@8.5.23)) - next: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) + next: 16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) rollup: 4.59.0 stacktrace-parser: 0.1.11 transitivePeerDependencies: @@ -10185,11 +10186,11 @@ snapshots: '@standard-schema/utils@0.3.0': {} - '@swc/helpers@0.5.15': + '@swc/helpers@0.5.18': dependencies: tslib: 2.8.1 - '@swc/helpers@0.5.18': + '@swc/helpers@0.5.23': dependencies: tslib: 2.8.1 @@ -10608,7 +10609,7 @@ snapshots: '@typescript-eslint/visitor-keys': 8.59.3 debug: 4.4.3 minimatch: 10.2.3 - semver: 7.8.0 + semver: 7.8.5 tinyglobby: 0.2.17 ts-api-utils: 2.5.0(typescript@5.5.4) typescript: 5.5.4 @@ -12519,7 +12520,7 @@ snapshots: is-bun-module@2.0.0: dependencies: - semver: 7.8.0 + semver: 7.8.5 is-callable@1.2.7: {} @@ -12908,7 +12909,7 @@ snapshots: make-dir@4.0.0: dependencies: - semver: 7.8.0 + semver: 7.8.5 markdown-table@3.0.4: {} @@ -13449,22 +13450,22 @@ snapshots: neo-async@2.6.2: {} - next-auth@5.0.0-beta.32(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7): + next-auth@5.0.0-beta.32(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react@19.2.7): dependencies: '@auth/core': 0.41.3 - next: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) + next: 16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) react: 19.2.7 - next-themes@0.2.1(next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react-dom@19.2.7(react@19.2.7))(react@19.2.7): + next-themes@0.2.1(next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7))(react-dom@19.2.7(react@19.2.7))(react@19.2.7): dependencies: - next: 16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) + next: 16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7) react: 19.2.7 react-dom: 19.2.7(react@19.2.7) - next@16.2.11(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7): + next@16.3.3(@babel/core@7.29.7)(@opentelemetry/api@1.9.1)(@playwright/test@1.56.1)(@types/node@24.10.8)(babel-plugin-react-compiler@1.0.0)(react-dom@19.2.7(react@19.2.7))(react@19.2.7): dependencies: - '@next/env': 16.2.11 - '@swc/helpers': 0.5.15 + '@next/env': 16.3.3 + '@swc/helpers': 0.5.23 baseline-browser-mapping: 2.10.29 caniuse-lite: 1.0.30001792 postcss: 8.5.23 @@ -13472,18 +13473,18 @@ snapshots: react-dom: 19.2.7(react@19.2.7) styled-jsx: 5.1.6(@babel/core@7.29.7)(react@19.2.7) optionalDependencies: - '@next/swc-darwin-arm64': 16.2.11 - '@next/swc-darwin-x64': 16.2.11 - '@next/swc-linux-arm64-gnu': 16.2.11 - '@next/swc-linux-arm64-musl': 16.2.11 - '@next/swc-linux-x64-gnu': 16.2.11 - '@next/swc-linux-x64-musl': 16.2.11 - '@next/swc-win32-arm64-msvc': 16.2.11 - '@next/swc-win32-x64-msvc': 16.2.11 + '@next/swc-darwin-arm64': 16.3.3 + '@next/swc-darwin-x64': 16.3.3 + '@next/swc-linux-arm64-gnu': 16.3.3 + '@next/swc-linux-arm64-musl': 16.3.3 + '@next/swc-linux-x64-gnu': 16.3.3 + '@next/swc-linux-x64-musl': 16.3.3 + '@next/swc-win32-arm64-msvc': 16.3.3 + '@next/swc-win32-x64-msvc': 16.3.3 '@opentelemetry/api': 1.9.1 '@playwright/test': 1.56.1 babel-plugin-react-compiler: 1.0.0 - sharp: 0.35.3(@types/node@24.10.8) + sharp: 0.35.4(@types/node@24.10.8) transitivePeerDependencies: - '@babel/core' - '@types/node' @@ -14240,37 +14241,37 @@ snapshots: setprototypeof@1.2.0: {} - sharp@0.35.3(@types/node@24.10.8): + sharp@0.35.4(@types/node@24.10.8): dependencies: '@img/colour': 1.1.0 detect-libc: 2.1.2 semver: 7.8.5 optionalDependencies: - '@img/sharp-darwin-arm64': 0.35.3 - '@img/sharp-darwin-x64': 0.35.3 - '@img/sharp-freebsd-wasm32': 0.35.3 - '@img/sharp-libvips-darwin-arm64': 1.3.2 - '@img/sharp-libvips-darwin-x64': 1.3.2 - '@img/sharp-libvips-linux-arm': 1.3.2 - '@img/sharp-libvips-linux-arm64': 1.3.2 - '@img/sharp-libvips-linux-ppc64': 1.3.2 - '@img/sharp-libvips-linux-riscv64': 1.3.2 - '@img/sharp-libvips-linux-s390x': 1.3.2 - '@img/sharp-libvips-linux-x64': 1.3.2 - '@img/sharp-libvips-linuxmusl-arm64': 1.3.2 - '@img/sharp-libvips-linuxmusl-x64': 1.3.2 - '@img/sharp-linux-arm': 0.35.3 - '@img/sharp-linux-arm64': 0.35.3 - '@img/sharp-linux-ppc64': 0.35.3 - '@img/sharp-linux-riscv64': 0.35.3 - '@img/sharp-linux-s390x': 0.35.3 - '@img/sharp-linux-x64': 0.35.3 - '@img/sharp-linuxmusl-arm64': 0.35.3 - '@img/sharp-linuxmusl-x64': 0.35.3 - '@img/sharp-webcontainers-wasm32': 0.35.3 - '@img/sharp-win32-arm64': 0.35.3 - '@img/sharp-win32-ia32': 0.35.3 - '@img/sharp-win32-x64': 0.35.3 + '@img/sharp-darwin-arm64': 0.35.4 + '@img/sharp-darwin-x64': 0.35.4 + '@img/sharp-freebsd-wasm32': 0.35.4 + '@img/sharp-libvips-darwin-arm64': 1.3.3 + '@img/sharp-libvips-darwin-x64': 1.3.3 + '@img/sharp-libvips-linux-arm': 1.3.3 + '@img/sharp-libvips-linux-arm64': 1.3.3 + '@img/sharp-libvips-linux-ppc64': 1.3.3 + '@img/sharp-libvips-linux-riscv64': 1.3.3 + '@img/sharp-libvips-linux-s390x': 1.3.3 + '@img/sharp-libvips-linux-x64': 1.3.3 + '@img/sharp-libvips-linuxmusl-arm64': 1.3.3 + '@img/sharp-libvips-linuxmusl-x64': 1.3.3 + '@img/sharp-linux-arm': 0.35.4 + '@img/sharp-linux-arm64': 0.35.4 + '@img/sharp-linux-ppc64': 0.35.4 + '@img/sharp-linux-riscv64': 0.35.4 + '@img/sharp-linux-s390x': 0.35.4 + '@img/sharp-linux-x64': 0.35.4 + '@img/sharp-linuxmusl-arm64': 0.35.4 + '@img/sharp-linuxmusl-x64': 0.35.4 + '@img/sharp-webcontainers-wasm32': 0.35.4 + '@img/sharp-win32-arm64': 0.35.4 + '@img/sharp-win32-ia32': 0.35.4 + '@img/sharp-win32-x64': 0.35.4 '@types/node': 24.10.8 shebang-command@2.0.0: @@ -14351,7 +14352,7 @@ snapshots: detect-newline: 4.0.1 git-hooks-list: 4.2.1 is-plain-obj: 4.1.0 - semver: 7.8.0 + semver: 7.8.5 sort-object-keys: 2.1.0 tinyglobby: 0.2.17 diff --git a/ui/pnpm-workspace.yaml b/ui/pnpm-workspace.yaml index a1bf7c3015..fbc178ce5a 100644 --- a/ui/pnpm-workspace.yaml +++ b/ui/pnpm-workspace.yaml @@ -18,8 +18,10 @@ overrides: "@react-aria/visually-hidden>react": "19.2.7" "@react-aria/interactions>react": "19.2.7" "lodash": "4.18.1" - # sharp 0.33.x/0.34.x carry GHSA-f88m-g3jw-g9cj; next pulls 0.34.5 transitively. - "sharp": "0.35.3" + # Next.js 16.3.3 requests sharp ^0.35.3; resolve 0.35.4 to fix + # GHSA-rgj7-g3m4-5g8c (libheif). This override controls resolution; + # keep it aligned with the direct dependency in package.json. + "sharp": "0.35.4" "lodash-es": "4.18.1" # GHSA-88fw-hqm2-52qc (CORS reflects any Origin with credentials), CVE-2026-59896 # (hono/jsx SSR context leak) and the 4.12.34 batch: CORS ReDoS via From 1e8454a3cb7645b5d7bed1e96e0393a44728cf96 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 9 Sep 2026 17:21:27 +0200 Subject: [PATCH 08/16] fix(mcp): patch the six high libuuid CVEs in the container image (#12780) --- mcp_server/Dockerfile | 5 ++++- mcp_server/changelog.d/mcp-image-libuuid-cves.security.md | 1 + 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 mcp_server/changelog.d/mcp-image-libuuid-cves.security.md diff --git a/mcp_server/Dockerfile b/mcp_server/Dockerfile index a2ba13ff6c..7dad9e1303 100644 --- a/mcp_server/Dockerfile +++ b/mcp_server/Dockerfile @@ -32,6 +32,8 @@ LABEL maintainer="https://github.com/prowler-cloud" # High CVEs fixed in Alpine 3.23 but not yet in the pinned base image: # sqlite-libs 3.53.4-r0 CVE-2026-11822, CVE-2026-11824 (image ships 3.51.2-r0) # libcrypto3/libssl3 3.5.8-r0 CVE-2026-14456 (image ships 3.5.7-r0) +# libuuid 2.41.6-r1 CVE-2026-53612, -53613, -53614, -76642, -78408, -78410 +# (image ships 2.41.4-r0; -78408 is the one that needs -r1 rather than -r0) # The base image pins python 3.13.14, which has not been rebuilt since those # packages were published, so the upgrade is taken here rather than by moving # the pin -- the newest published python:3.13-alpine3.23 carries the same @@ -43,7 +45,8 @@ LABEL maintainer="https://github.com/prowler-cloud" RUN apk add --no-cache --upgrade \ "sqlite-libs>=3.53.4-r0" \ "libcrypto3>=3.5.8-r0" \ - "libssl3>=3.5.8-r0" + "libssl3>=3.5.8-r0" \ + "libuuid>=2.41.6-r1" # Create non-root user for security # Using specific UID/GID for consistency across environments diff --git a/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md b/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md new file mode 100644 index 0000000000..602458c777 --- /dev/null +++ b/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md @@ -0,0 +1 @@ +`libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410 From 369f8528373918a4d91b7974fc0cff0ac7e9da84 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 9 Sep 2026 18:07:22 +0200 Subject: [PATCH 09/16] fix(aws): lead the partition bootstrap regions with the configured region (#12764) Co-authored-by: pedrooot --- .../providers/aws/regions-and-partitions.mdx | 18 ++ ...-region-honours-configured-region.fixed.md | 1 + prowler/providers/aws/aws_provider.py | 49 +++- tests/providers/aws/aws_provider_test.py | 247 +++++++++++++++++- tests/providers/aws/utils.py | 1 + 5 files changed, 303 insertions(+), 13 deletions(-) create mode 100644 prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md diff --git a/docs/user-guide/providers/aws/regions-and-partitions.mdx b/docs/user-guide/providers/aws/regions-and-partitions.mdx index 8556ccc74e..bf88aafc2f 100644 --- a/docs/user-guide/providers/aws/regions-and-partitions.mdx +++ b/docs/user-guide/providers/aws/regions-and-partitions.mdx @@ -21,10 +21,28 @@ When scanning the China (`aws-cn`), European Sovereign Cloud (`aws-eusc`) or Gov - Specify the regions to audit within that partition using the `-f/--region` flag. +- Declare the partition with the `PROWLER_AWS_PARTITION` environment variable, set to `aws`, `aws-cn`, `aws-eusc` or `aws-us-gov`. + Refer to: https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credentials.html#configuring-credentials for more information about the AWS credential configuration. +### Declaring the Partition + +`PROWLER_AWS_PARTITION` tells Prowler which partition the scan runs against, without relying on a region being configured: + +```bash +export PROWLER_AWS_PARTITION="aws-us-gov" +``` + +It matters most where nothing else says. Resolving an identity means calling STS before anything is known about the credentials, and with no region configured Prowler would otherwise start from the commercial endpoints. Declaring the partition makes that first call go to the right place, which is the difference between a scan that starts and one that fails on an endpoint the credentials cannot use. + +A region configured for the session still wins when it belongs to the declared partition, so a deployment in `us-gov-west-1` is not sent to `us-gov-east-1`. A region belonging to a different partition is ignored, since a partition that has been declared explicitly is the more deliberate statement of the two. + + +Set it wherever the scan runs. For deployments that scan from containers, that means the environment of the containers doing the scanning, not only the one accepting the request. + + ### Scanning Specific Regions To scan a particular AWS region with Prowler, use: diff --git a/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md b/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md new file mode 100644 index 0000000000..93a6c8d7b1 --- /dev/null +++ b/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md @@ -0,0 +1 @@ +Bootstrap STS calls now use the session region when `PROWLER_AWS_PARTITION` is set and the region belongs to that partition, instead of always going to the partition's global STS region, which a deployment reached only through its own region's VPC endpoints cannot route to diff --git a/prowler/providers/aws/aws_provider.py b/prowler/providers/aws/aws_provider.py index d6b24c748c..d0ca3b98ee 100644 --- a/prowler/providers/aws/aws_provider.py +++ b/prowler/providers/aws/aws_provider.py @@ -576,8 +576,15 @@ class AwsProvider(Provider): ) -> str: excluded_regions = set(excluded_regions or ()) session_region = session.region_name + env_partition_regions = get_env_partition_regions(session_region) if session_region and session_region not in excluded_regions: - return session_region + if not env_partition_regions or session_region in env_partition_regions: + return session_region + if env_partition_regions: + for region in env_partition_regions: + if region not in excluded_regions: + return region + return env_partition_regions[0] for region in AwsProvider.get_bootstrap_region_candidates(session_region): if region not in excluded_regions: @@ -673,7 +680,7 @@ class AwsProvider(Provider): session = Session(**session_arguments) session._session.set_default_client_config(session_config) sts_region = ( - get_env_partition_bootstrap_region() + get_env_partition_bootstrap_region(session.region_name) or session.region_name or AWS_STS_GLOBAL_ENDPOINT_REGION ) @@ -1420,12 +1427,6 @@ class AwsProvider(Provider): Connection(is_connected=True, Error=None)) """ try: - if aws_region is None: - aws_region = ( - get_env_partition_bootstrap_region() - or AWS_STS_GLOBAL_ENDPOINT_REGION - ) - session = AwsProvider.setup_session( mfa=mfa_enabled, profile=profile, @@ -1434,6 +1435,12 @@ class AwsProvider(Provider): aws_session_token=aws_session_token, ) + if aws_region is None: + aws_region = ( + get_env_partition_bootstrap_region(session.region_name) + or AWS_STS_GLOBAL_ENDPOINT_REGION + ) + if role_arn: session_duration = validate_session_duration(session_duration) role_session_name = validate_role_session_name(role_session_name) @@ -1759,11 +1766,18 @@ def get_botocore_partition_regions() -> dict: return partition_regions -def get_env_partition_regions() -> Optional[list]: +def get_env_partition_regions( + session_region: Optional[str] = None, +) -> Optional[list]: """ Get the bootstrap region candidates for the partition set in the PROWLER_AWS_PARTITION environment variable. + Args: + session_region (Optional[str]): The region of the AWS session. It leads + the candidates when it belongs to the partition and is ignored + otherwise. + Returns: Optional[list]: The regions of the configured partition, preferred bootstrap region first, or None when the environment variable is @@ -1782,14 +1796,25 @@ def get_env_partition_regions() -> Optional[list]: raise AWSInvalidPartitionError( message=f"Invalid partition: {raw_partition} set in PROWLER_AWS_PARTITION. Valid partitions: {', '.join(sorted(partition_regions))}" ) + + # A deployment reached only through its own region's endpoints has no route + # to the partition's global STS region, so the session region goes first + if session_region in regions: + regions = [session_region] + [r for r in regions if r != session_region] return regions -def get_env_partition_bootstrap_region() -> Optional[str]: +def get_env_partition_bootstrap_region( + session_region: Optional[str] = None, +) -> Optional[str]: """ Get the STS bootstrap region for the partition set in the PROWLER_AWS_PARTITION environment variable. + Args: + session_region (Optional[str]): The region of the AWS session, preferred + when it belongs to the partition. + Returns: Optional[str]: The preferred bootstrap region of the configured partition, or None when the environment variable is not set. @@ -1797,7 +1822,7 @@ def get_env_partition_bootstrap_region() -> Optional[str]: Raises: AWSInvalidPartitionError: If the value is not a partition known to botocore. """ - regions = get_env_partition_regions() + regions = get_env_partition_regions(session_region) return regions[0] if regions else None @@ -1833,7 +1858,7 @@ def get_aws_region_for_sts( if region not in excluded_regions: return region - env_partition_regions = get_env_partition_regions() + env_partition_regions = get_env_partition_regions(session_region) if env_partition_regions: # The configured partition constrains the whole fallback chain: prefer # a non-excluded region, but never leave the partition diff --git a/tests/providers/aws/aws_provider_test.py b/tests/providers/aws/aws_provider_test.py index 4bdb438b99..7ce61b6862 100644 --- a/tests/providers/aws/aws_provider_test.py +++ b/tests/providers/aws/aws_provider_test.py @@ -16,7 +16,12 @@ from moto import mock_aws from pytest import raises from tzlocal import get_localzone -from prowler.providers.aws.aws_provider import AwsProvider, get_aws_region_for_sts +from prowler.providers.aws.aws_provider import ( + AwsProvider, + get_aws_region_for_sts, + get_env_partition_bootstrap_region, + get_env_partition_regions, +) from prowler.providers.aws.config import ( AWS_STS_GLOBAL_ENDPOINT_REGION, BOTO3_USER_AGENT_EXTRA, @@ -56,6 +61,7 @@ from tests.providers.aws.utils import ( AWS_REGION_EU_WEST_1, AWS_REGION_EUSC_DE_EAST_1, AWS_REGION_GOV_CLOUD_US_EAST_1, + AWS_REGION_GOV_CLOUD_US_WEST_1, AWS_REGION_ISO_GLOBAL, AWS_REGION_US_EAST_1, AWS_REGION_US_EAST_2, @@ -2447,6 +2453,245 @@ aws: == AWS_REGION_GOV_CLOUD_US_EAST_1 ) + def test_get_env_partition_regions_leads_with_session_region(self): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + regions = get_env_partition_regions(AWS_REGION_GOV_CLOUD_US_WEST_1) + + assert regions[0] == AWS_REGION_GOV_CLOUD_US_WEST_1 + assert set(regions) == set(get_env_partition_regions()) + + def test_get_env_partition_regions_ignores_session_region_outside_partition( + self, + ): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + regions = get_env_partition_regions(AWS_REGION_EU_WEST_1) + + assert regions[0] == AWS_REGION_GOV_CLOUD_US_EAST_1 + assert AWS_REGION_EU_WEST_1 not in regions + + def test_get_env_partition_bootstrap_region_prefers_session_region(self): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + assert ( + get_env_partition_bootstrap_region(AWS_REGION_GOV_CLOUD_US_WEST_1) + == AWS_REGION_GOV_CLOUD_US_WEST_1 + ) + + def test_get_env_partition_bootstrap_region_without_session_region(self): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + assert ( + get_env_partition_bootstrap_region() == AWS_REGION_GOV_CLOUD_US_EAST_1 + ) + + def test_get_env_partition_bootstrap_region_without_partition(self): + with mock.patch.dict(os.environ, {"PROWLER_AWS_PARTITION": ""}, clear=False): + assert ( + get_env_partition_bootstrap_region(AWS_REGION_GOV_CLOUD_US_WEST_1) + is None + ) + + def test_get_aws_region_for_sts_env_partition_prefers_session_region(self): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + assert ( + get_aws_region_for_sts(AWS_REGION_GOV_CLOUD_US_WEST_1, None) + == AWS_REGION_GOV_CLOUD_US_WEST_1 + ) + + def test_get_profile_region_env_partition_keeps_session_region_inside_partition( + self, + ): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + aws_session = session.Session(region_name=AWS_REGION_GOV_CLOUD_US_WEST_1) + + assert ( + AwsProvider.get_profile_region(aws_session) + == AWS_REGION_GOV_CLOUD_US_WEST_1 + ) + + def test_get_profile_region_env_partition_ignores_session_region_outside_partition( + self, + ): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + aws_session = session.Session(region_name=AWS_REGION_US_EAST_1) + + assert ( + AwsProvider.get_profile_region(aws_session) + == AWS_REGION_GOV_CLOUD_US_EAST_1 + ) + + def test_get_profile_region_env_partition_excluded_session_region_stays_in_partition( + self, + ): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + aws_session = session.Session(region_name=AWS_REGION_GOV_CLOUD_US_WEST_1) + + assert ( + AwsProvider.get_profile_region( + aws_session, {AWS_REGION_GOV_CLOUD_US_WEST_1} + ) + == AWS_REGION_GOV_CLOUD_US_EAST_1 + ) + + def test_get_profile_region_env_partition_all_regions_excluded_stays_in_partition( + self, + ): + with mock.patch.dict( + os.environ, + {"PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION}, + clear=False, + ): + aws_session = session.Session(region_name=AWS_REGION_GOV_CLOUD_US_WEST_1) + gov_cloud_regions = set(get_env_partition_regions()) + + assert ( + AwsProvider.get_profile_region(aws_session, gov_cloud_regions) + == AWS_REGION_GOV_CLOUD_US_WEST_1 + ) + + @mock_aws + def test_test_connection_env_partition_prefers_session_region(self): + with ( + mock.patch.dict( + os.environ, + { + "PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION, + "AWS_DEFAULT_REGION": AWS_REGION_GOV_CLOUD_US_WEST_1, + }, + clear=False, + ), + mock.patch.object( + AwsProvider, + "validate_credentials", + return_value=AWSCallerIdentity( + user_id="test-user-id", + account=AWS_ACCOUNT_NUMBER, + arn=ARN(AWS_GOV_CLOUD_ACCOUNT_ARN), + region=AWS_REGION_GOV_CLOUD_US_WEST_1, + ), + ) as mock_validate_credentials, + ): + connection = AwsProvider.test_connection( + aws_access_key_id="test-access-key", + aws_secret_access_key="test-secret-key", + raise_on_exception=False, + ) + + assert connection.is_connected + assert ( + mock_validate_credentials.call_args.args[1] + == AWS_REGION_GOV_CLOUD_US_WEST_1 + ) + + @mock_aws + def test_test_connection_role_env_partition_prefers_session_region(self): + with ( + mock.patch.dict( + os.environ, + { + "PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION, + "AWS_DEFAULT_REGION": AWS_REGION_GOV_CLOUD_US_WEST_1, + }, + clear=False, + ), + mock.patch.object( + AwsProvider, + "assume_role", + return_value=AWSCredentials( + aws_access_key_id="assumed-access-key", + aws_secret_access_key="assumed-secret-key", + aws_session_token="assumed-session-token", + expiration=datetime.now(), + ), + ) as mock_assume_role, + mock.patch.object( + AwsProvider, + "validate_credentials", + return_value=AWSCallerIdentity( + user_id="test-user-id", + account=AWS_ACCOUNT_NUMBER, + arn=ARN(AWS_GOV_CLOUD_ACCOUNT_ARN), + region=AWS_REGION_GOV_CLOUD_US_WEST_1, + ), + ), + ): + connection = AwsProvider.test_connection( + role_arn=f"arn:{AWS_GOV_CLOUD_PARTITION}:iam::{AWS_ACCOUNT_NUMBER}:role/test-role", + aws_access_key_id="test-access-key", + aws_secret_access_key="test-secret-key", + raise_on_exception=False, + ) + + assert connection.is_connected + assumed_role_info = mock_assume_role.call_args.args[1] + assert assumed_role_info.sts_region == AWS_REGION_GOV_CLOUD_US_WEST_1 + + @mock_aws + def test_setup_session_mfa_env_partition_prefers_session_region(self): + with ( + mock.patch.dict( + os.environ, + { + "PROWLER_AWS_PARTITION": AWS_GOV_CLOUD_PARTITION, + "AWS_DEFAULT_REGION": AWS_REGION_GOV_CLOUD_US_WEST_1, + }, + clear=False, + ), + mock.patch.object( + AwsProvider, + "input_role_mfa_token_and_code", + return_value=AWSMFAInfo( + arn=f"arn:{AWS_GOV_CLOUD_PARTITION}:iam::{AWS_ACCOUNT_NUMBER}:mfa/test", + totp="123456", + ), + ), + mock.patch.object( + AwsProvider, + "create_sts_session", + side_effect=AwsProvider.create_sts_session, + ) as mock_create_sts_session, + ): + AwsProvider.setup_session( + mfa=True, + aws_access_key_id="test-access-key", + aws_secret_access_key="test-secret-key", + ) + + assert ( + mock_create_sts_session.call_args.args[1] + == AWS_REGION_GOV_CLOUD_US_WEST_1 + ) + @mock_aws def test_test_connection_env_partition_mismatch(self): with ( diff --git a/tests/providers/aws/utils.py b/tests/providers/aws/utils.py index 90e2a98e85..b19efd3eec 100644 --- a/tests/providers/aws/utils.py +++ b/tests/providers/aws/utils.py @@ -51,6 +51,7 @@ AWS_REGION_CN_NORTH_1 = "cn-north-1" # Gov Cloud Regions AWS_REGION_GOV_CLOUD_US_EAST_1 = "us-gov-east-1" +AWS_REGION_GOV_CLOUD_US_WEST_1 = "us-gov-west-1" # Iso Regions AWS_REGION_ISO_GLOBAL = "aws-iso-global" From 8270979ec889c5551338814da92a271b108a0be2 Mon Sep 17 00:00:00 2001 From: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com> Date: Wed, 9 Sep 2026 23:05:09 +0200 Subject: [PATCH 10/16] fix(ui): align scan filters and actions (#12781) --- ui/changelog.d/scans-filter-actions.fixed.md | 1 + ui/components/scans/import-findings-modal.tsx | 5 +- ui/components/scans/scans-filter-bar.tsx | 54 ++++++++++-------- ui/components/scans/scans-page-shell.test.tsx | 31 ++++++---- ui/components/scans/scans-page-shell.tsx | 36 ++++++------ .../scans/evidence/scans-controls-desktop.png | Bin 0 -> 28212 bytes .../scans/evidence/scans-controls-mobile.png | Bin 0 -> 24134 bytes .../scans/evidence/scans-controls-tablet.png | Bin 0 -> 23298 bytes ui/tests/scans/scans-page.ts | 4 +- ui/tests/scans/scans.md | 3 +- 10 files changed, 73 insertions(+), 61 deletions(-) create mode 100644 ui/changelog.d/scans-filter-actions.fixed.md create mode 100644 ui/tests/scans/evidence/scans-controls-desktop.png create mode 100644 ui/tests/scans/evidence/scans-controls-mobile.png create mode 100644 ui/tests/scans/evidence/scans-controls-tablet.png diff --git a/ui/changelog.d/scans-filter-actions.fixed.md b/ui/changelog.d/scans-filter-actions.fixed.md new file mode 100644 index 0000000000..3220d59a8e --- /dev/null +++ b/ui/changelog.d/scans-filter-actions.fixed.md @@ -0,0 +1 @@ +Scans page filter widths and action button styling, with Launch Scan and Import Findings grouped beside the tabs and sized consistently with Configure Mutelist diff --git a/ui/components/scans/import-findings-modal.tsx b/ui/components/scans/import-findings-modal.tsx index c367829ea2..2016a50641 100644 --- a/ui/components/scans/import-findings-modal.tsx +++ b/ui/components/scans/import-findings-modal.tsx @@ -223,10 +223,9 @@ export function ImportFindingsModal() { <> diff --git a/ui/components/scans/scans-filter-bar.tsx b/ui/components/scans/scans-filter-bar.tsx index de4539651f..f46a29c07a 100644 --- a/ui/components/scans/scans-filter-bar.tsx +++ b/ui/components/scans/scans-filter-bar.tsx @@ -31,7 +31,7 @@ interface ScansFilterBarProps { onScanStatusChange: (value: string) => void; } -const filterItemClass = "w-full md:w-[calc(50%-0.375rem)] xl:w-60"; +const filterItemClass = "w-full sm:max-w-[240px] sm:min-w-[180px] sm:flex-1"; export function ScansFilterBar({ providers, @@ -67,33 +67,37 @@ export function ScansFilterBar({ {showScheduleTypeFilter && ( - +
+ +
)} {showStatusFilter && ( - +
+ +
)} ); diff --git a/ui/components/scans/scans-page-shell.test.tsx b/ui/components/scans/scans-page-shell.test.tsx index 8d67c0d9da..6809cf087b 100644 --- a/ui/components/scans/scans-page-shell.test.tsx +++ b/ui/components/scans/scans-page-shell.test.tsx @@ -336,26 +336,35 @@ describe("ScansPageShell", () => { expect(screen.queryByRole("alert")).not.toBeInTheDocument(); }); - it("keeps launch scan with filters and mutelist with tabs", () => { - vi.stubEnv("UI_CLOUD_ENABLED", "false"); + it("keeps launch scan, import findings, and mutelist with tabs", () => { + // Given + vi.stubEnv("UI_CLOUD_ENABLED", "true"); + // When render( - +
Scans table
, ); - expect( - screen.getByRole("group", { name: /scan filters and actions/i }), - ).toContainElement(screen.getByRole("button", { name: /launch scan/i })); - expect( - screen.getByRole("group", { name: /scan filters and actions/i }), - ).not.toContainElement( - screen.getByRole("link", { name: /configure mutelist/i }), + // Then + const tabs = screen.getByRole("group", { name: /scan tabs/i }); + expect(tabs).toContainElement( + screen.getByRole("button", { name: /launch scan/i }), ); - expect(screen.getByRole("group", { name: /scan tabs/i })).toContainElement( + expect(tabs).toContainElement( + screen.getByRole("button", { name: /import findings/i }), + ); + expect(tabs).toContainElement( screen.getByRole("link", { name: /configure mutelist/i }), ); + expect( + screen.getByRole("group", { name: /scan filters/i }), + ).toContainElement(screen.getByText("Shared scan filters")); }); it("shows the active scans count in the in progress tab", () => { diff --git a/ui/components/scans/scans-page-shell.tsx b/ui/components/scans/scans-page-shell.tsx index 1575c026fc..fc597c95bf 100644 --- a/ui/components/scans/scans-page-shell.tsx +++ b/ui/components/scans/scans-page-shell.tsx @@ -135,8 +135,8 @@ export function ScansPageShell({ )}
- - - {isCloudEnvironment && hasManageIngestionsPermission && ( - - )}
{isCloudEnvironment && } @@ -174,10 +160,10 @@ export function ScansPageShell({
{Object.values(SCAN_JOBS_TAB).map((tab) => ( @@ -186,7 +172,19 @@ export function ScansPageShell({ ))} -
+
+ + {isCloudEnvironment && hasManageIngestionsPermission && ( + + )}
diff --git a/ui/tests/scans/evidence/scans-controls-desktop.png b/ui/tests/scans/evidence/scans-controls-desktop.png new file mode 100644 index 0000000000000000000000000000000000000000..d7c7733db37014a5ff2cc7d71882454ccad40e04 GIT binary patch literal 28212 zcmeIacUV)~)-N1IP!Uvw(2>0XDWOO)Q~^r@(hVe`1yHJlUR4lK+#&=CQW82yPk|u4 zs30P}NeNwguS)M+_VMg}%6;GOyZ1itecpS{xE`}?d;(ww4YqPxWME4-5#$SS3eh>FH_o#wj z?t;GB{F9JP-0)Zb&zmQ1ojZ^v+ou%4vZzinn;2Ta)%AhgEdLI*1VmB$fG`W7sta8b zw+H2PLUyS>cyssU5kQADV7J6#Uu>#;`k0S9u`^@E5A4c zI5(+t;t{*D1{ZNvXu#0dYmd2)_RPQA%>Q}ib`12)=>p8v(bl1x5yP$i-J2}G0Io({ zqaD4sA>f?dkYaDP)Vrv6kL8zt?)k5_=KsI^Pw6N>;y8HBLyWvSpzaIaGw8ef6i^BI z!uITWcSJ=BpI_#~Qj2`$r*{MY?WX?E=8n6zF>1Fl>78|_%ARMjcS-O5Ex=Ep_yZ{Z z19(4qIJUK$Qu}Z|^F)B_-htluyN$b2)yrqB3CZ&JtTOQG{OomEpeaN()A?sOl~SIpCR}*6eOWG?KPr>J@U~#WW6g*Fa@NEDWu@Y~_)GCJE)#_6EIC z_$X`Ib9;&>D{GFs2Qz2CRH(tQ;o9}#8()4OXl5*kd+2aoiX?qoL?j~}n=Z8cUBjrn zsMU`pxRAm=`Wd;~9Q48bqj2@(CFN%bC4_CKP1Gtm zzdAgfa-lTHMTO$AIu*5*V8#ND5!LyGjkHm#2Sa5htf;1m!B{v1Wnj@j|IxEKAbmeB zr_m>LeyT}bT}$9@cfgV~sa_zM6t-t_*tDSMmeFG*ad%iW_sbW-@3AP}6wA(vt=P?Hvh;ekuRLPFd25b@>+qg#|7fQf8zexr^73jZaW9#;{tCjXSZ@ zRK%V{LHgpZfOXHFD(tM3)xucDk%)owy#)FD@flLk+~w2qP(m)qey1Z3?a4+(bxSC@GMi2H{Aq`Pce7pl4s zMXL}r+?Pj#G(#qW=oB@q-KAckEhz{T)5Td1gV|4cLaXgUi_)ljMC^*FNWbwpDQov{ zLkzFr^(OhVgo=Zqj~*YL6z)e}vi@2!h}^B~zT&v?nqU9=Q0rxLM#ChxwwZ0V?#l3- z5a>Nqiczg|nYq0&f>vf}wV@|{cv?H>NOhs$gEC6vCN%e-sTUnp|24DI38^TsJ70Z6AI7ZSRro+Wd@kLPWXl0hgT6 zRnbfdM|POjKDD)N!_Uk=FPGe(Lx0ict2nhMzPID6@caW(f6x;!lcHSdWk-`q=F)LKfKVjsJ)$^f?jj-#k zAL}*5uxe6a+K47{ARiA6$d4T{d1yR&5Tx}ADD`#9MoIKnTQRIT*Ru#r>;h65$Y${_ z_WUEpY%%Fu+6g6t=nO5+CU&kZ!J?!ImMVRbRQq{q^8!?PNAD+Sj*96^tvbNyC`909v z`*kWLkOGLapNn}??cQfZEi80Z8&wgZbv?Y{Tn{XrbO~F6?}=V(8+<-zKFgi2HZz^R zAqdK?Nl9e9!J3%#!A*|qJG36-{gq??f(ow-!>}J}W~y0eMYclNK?0fZf=8e!42#Ct z)zyZj$B)aj_0-v-$w9mD2XQTJHA|{iY;FFfZRkzQ+{Y zh;MQ2{HnSB@^>iX-Yws0;I%6+NJ~3CNH$fzCIY+WKoijcAz&gEBx|{z$CpuZxRbw0 zo^Z2>?7!(!>h{79JEwIMBNzb|cohzu-oQ!rV(vXEpPX8z-llbGYj;aePdQKTgR!gU zj?EH@pVDSy>7o5I)c7~hL>jBoUDd|;mKZ`M1(o6HSpa2JKkNeKxZlALMvC(mDMec+ zTB@Cl@0H(vL@B*}(?V>WFn75&(^tUpPV6_VWtO-zI=y&}FLiz?ifuueA5GcRN}`oX z&Mz?`8S|k(NNu>e^H~wSp0LonnxfpDcbqb_h-Lj0c=QG+m1o$@rf$6Wao5KrUVOuSPtYX9AaSg&f zKY>W~*gPcI1_zb_LZ{X5#rFafW@Q&r(ib+WgxKjQP=Em9Adai9lb!kM^TQDMEShjp**E z0SPGtykYjui}iMgDPObr>0(lBIcxyO9Ord;qA_8ygh+AgcXlcHM9}~xXl{hWk)P-L zvkRVU&$|o!&mdkEz3RRNwGWyzwkxZ4N;rR>Vq#Y!G|~E;Dv9!o-*^W9$5lL$;!`*z zhO^i4%JjR|^f`ia5y(xQhQqswt26+PZ^p~a10d%J{f3g=hv3L|A}1CBfoxNXrl&uD zq~ROc+I6XQnSXI2z-8}1ZoG8k*3*Ba{^RUVe^CEvRhi#m_II;g0+(SL`W=ES#{YhJ zD&&`<>MKtqtGLm2mH{ByeZ)L<2dw+zUh|X0CQefyl*n8T5b3Z19!P2@MmqBpXn(yT zlT0EKIro`UK)ti-}IrT-Lo^en5a(2#%*Uf;n(ki=$ zTrPr}C=p~a33cU)h`uz9Ko1Z6!|U1Mf==aHrk4@=77ojXX!M@xFA=L^qAbmP&3p>X z&k^W!na90AU2FMZnyT(8f33Syet3Mf8Mn8Bsr$PgJ?a*%V;7gDmgxuTrgOY)?CL4IVr`(#RYMY_Ag`WP4;yGfL-Zqu~i>aMbsQ<(e-1T z3VtISZ<0;r-@eRf-x+tg4@X+I8w<2b%GEWSdoFDHq)E{;y-blZsCQGHMaO|^WtBj~ zG#k=_!M4?}UAsZIVpjpXJsT>#6xm%jup5dK$iGo#zvy7y2HzGG*^p}v+l<+^vaP(g zIR)I57c)?346L9xmUNO{pU*(WSwn3q)gJmcr#7u4=eCf8hY}xeR+f7`#wFlwoX&XGKb{A=G{H z>jpDB@mXhyNrtAd=R%H&GUIrNwPsyf7FzIwlQuK0%9CYx~ zCn_hG4NR8tj}{f&Y7{XSOt2LKZSg7Ry*)r=1oH)F&Pw(NHyFv{?qqD)Illr%x@z_L z&Q7_(BY^3_vc+6@t0Cfl-JfwX4+xr{6pbE8|x8>ZM^Xir%f@fRXjE7c} zug8^4i90?$ zrnH`JeN#?ND@I#<>Ba~HJyDKJ^D~yV`6?1H+a@kl)R*BX5Mg#Hf3hZ5uc%S96P{GG zY-?-FZcF~=qr~IzT^>L)+mu+?IOjO$kwMO{IcdFX+LLUIPJxGyJ_2WJTKife$>k|Q zXR+SJAY=U7ZXd0OG||_@i^YRDg(vbfcr--I&UAb$HzDL(E*=4<1?55a1IJxo)9uYg z7En#2S!ayNteN?y;}~ygiYCE+68dm84L6JRU;>htsu5nq)IW9QFO3oRha$NTwXS<} zmyIPsPv@$eU9!{Bd#R*=Ly$sVmNHr}T>FKNiZ4ghqi8Gp>7L(9->|pmIu2lR54Wza z*H4p4PwAk4c)ceN{{T?HpI-0Z1<$g15UMvBX{7%6L-VDZ_JNw)_x zZ27U?W$i(Ce93iEMrH31rJK50a+8132q}Vx;vw!rbR?>p?HUD?*x+{YbO5nwAD`N^ zCoUdXA;0KeGW9UWHv*PJB4*=Wg?M@7%NV7w2^ZQhQZ!~=G;nZF@4nUhJ=p`+xH*vS zz(W}s83q}|wlWX4csmhrV%aJd9CCPzU;rL!sUA-(Ff5-85z>^d{{ov{O8d{q?5Yb(K zj&VkaKq=Ak5XZ^x?Qs{aN?%{M4y&f9kB8Tq5@C(lLRFE~${G#JX8I>ll=O7su{%+n zEZX=%Q?A5Q+q-iV`HF*SJEBG89zz``e4gDyl z8OyH^F`Th_SuDk0j&i&NpF+awqw)16D^X%^vQwe{ucI;~rCNPGT%FHd+VdKZl_vd;d8}wl%uAuTvp<9>%n3GzET729)OhWD&RP|HJc^^e; zeXXP{7=o|8)^JF+wcjBJR;1y!ON78>Ygbjywzw%JeWJ{n?7jn%q+*!l<`{V_=r_PXK`*Fm z;c4mMFJBy4{By-scSSy zthGq+N;Uic+!(JtJ?&98VjmDB>o9%68D?P>SSynlEBYogimf4ZsSRzAA25))X==8# zBZF6PF$}2GAO0nel4*^Mo%Ee_p@nf{+tFDJEmqv!y?MOuiS+;J9{Tw|+3Ze#>DR-{ z8YOw>q*oe^IkhcmAoP@_slB?vO+k${8Vm*ed`PflE2KA<5F9H)+_kRgUnoEe8VotD zezoxMyPaCpqXQP}C=X3iN{_ls4@Gsis(XMYT0`ppSlB=R)A%(GWfgxF``+h15#+^k zxtPaOBMGd+y*Q0Pk_0agfuBfzdCG+}nKI;YW!~ z)}!NWiN9z7T=?AHAF)5++}_KP`2gSuDf-XY|Hi-vX2d|Q@qM1@Einz+th1tHFSaKP zl$dv5rQ>dIhODV z-&mP~)S=7CVMaHrd;}T{^I9y5bUr6-}VWWtO z7`hoj`u9sv#7vKIr;V=efNeuvZd<$Fn~@P^Z8*>isDlyu9MF9iQUIa3v4EMs94JMNuNv#rmn-{Jd=Bg<`jAglo-!jfs0?y{uNKV>P&AFI7 zwjufHt3Dg;NfL=z3NfKf9|sQ#1Ks3i(Syjb*M?wHrRlr_TG-w)JO1mnFYU?Uc8a|Vr%_28OJYvX4h^)5It_ZK&~z*q^!}^k=W6~H{X>auJ|EbILvvNrqUrpUYh(rM zVQlnuS&VRRhY01q1?tX;*Jsv$$c65&a=Ua=`G;Jp|0=grPs9HzT>Bq#JMjzuUxmy0 zL-|Tv7M?HJdg19z$y0~hoS6%bGrv# zh2;u~8$MS*u$crvg&B5zgB*3RX%fINZBD{sFQ0FIFL{;bmw#n_`adxbh9*YDTZPB* z>ppqq%qB+w$gyNXgFJPy$r5L=+T5hY8IW)Ov70IhVB6STuyglNm|wT>ktjOE+~ru` zV(3fYfuKY=W5KX~3S`SF&v26N#=o*c{h!zeM>Hq-p8FbjcEiG5u=p_eF2@EN!)y}I zbrdsqtOBCH4ZdY{92njMTwU1cX`7t(pw3pVo7o?*ypfq(=E#>-3@$s~=h5kfsF3A) z^SlOzr~g(c_rIW(GQwcw$Ej(Dj`_+-9fyO9Z)D~rI64#+AC(CzNV<~?6N$_9$h?M+ z|IzLOIFaI9)HB4sBXYk^P~tpp#nBPEC7MWx-IoIE$iT<6Eu*A(r9aa43Q~AP1A@C& zusSG36Z_-1KTBztkKVzqU6KWq2M}_1S)_{^~>R&8QGH z*UbNDQ0@<3Wd?MAj`>rzKXvG*t^5F@pP29yZ-4G9KljhScTRp{!arbw-H;QwWK&v` z;2N^<+{S8nxA^v^0s9VD1QD5RP zX_T^44nz3cW;m6@4sG8Z0fu#s0P)H1cpDA34^ZU82S)(aw6`=HVID(amZFKr^(lfN zlA}KjUnM4MM1S6=&w`;9g0SkMt=4vL(bl~LnOFlTL%F7Wqy-gL%x#OM5Z7NH`=+W0 zQfOe>#4^n{W-6?^Q&gXn{6MC-^f${=UcA6bORMoai2(osuj{Shzj;dYOG4X_6!xpq z6W^=v)cu~!x)PuKh>I&b=*}RYos>CMdvYu5`Yc3Ha{uY+GRsJNE^e_WkxFqn+K7N( zuAlUYSB!^4iP`Zi<~9+SA^(g&=%3E2+mc#w;GWKBLJ?xqy~gr}P9HO8tp!CeFeaPW z_n)h5!G^)etLBy*R!{Vhn)On1fn-#y#D@pQA>ob8msT(6*KKF~<$7DMAbm>21;~)3=d>|q!EJ_E_MFv{64Km5KN`+~#QOA9cfqTW7AP`pue|rdV=`Ox7KT&f z5n5EslHh=PPFG~~C<@^bhym#ET#-+TDer5O14ZS=9T!Zar904}UN;BUS z@!P+NAIkI14K)=Y%5*eMr%}$tjs}-kZ20;GrD_;}1(uTI)zwAas#|BY4QLNBnlbc6 z9;m1))=x#Vm9tbJuu2T5Gw?x&1uDb7zf=ewj3?CzZLJQ(-E{EE?bQ{7LQ}^glM1T9 zm!rNtn!w86&o$tEJWUyN$|(9?_cT%<|JHP;qWUx>&oHeV!KMK706QE3U^?h3s_7hv z&pOgh@iHA7-x1)qL_TFNUzpeYcI;v$s^9pEfy0%tNi=vFQOkXt?oRCcwa3NelZuLK zld8fIU}g-<^QgT&&N1ekUskUpzI=0;$Hwy9=%YKhc`6)^sJRda95<>8c|g|T zEC%&aoju;Vk0%!_%=9D<6mz!fe4-EwO0v>4^o=hW&PXVwAkhm()>kUsaOUu9c-Z!j=>}#fN^|`k;jG6*i3iFl*_^T4n9qLXjF{@!)q6!L*n3}nnAF1a8Fz3A3fgOs;g0^=%>InI{djj@wH zAgi`;xS=0{dDg$nj7&5;_l6h|%FHTzzapq_ zom734r(ol$h^|T{U-|REhTvWm?c)dD+n@!|(k2-}&977xGROd9U$k0N+*>|}tUyq1 z)lE4yNbdc*vc08_HP^h{xK7L3HbieI5K#q1>?S)slmWTBSi4j@y* zWDh15@1I3Qs9ifw1AG=RrtrDqo1N1Ndj{voSta5!tj4kHR+frE2B-Xh$=KrfOn z#xWx!D5xUR$ey@vZ>7QXYg{K(;yfHhMRA9a8Q4sGTgW8{J!$=t5wNub&4>`=b;1re z1)>e+<2z1Q2fc@<=23`waaVHUIzKRjfy1A-_FV**HTjpXahdpVcCjtdEwwUow9=#i9{LN#|}wkSQRbVb1P za>Tk3qBV$P+6v)C;sf__HZPzpm?u2jkSgXJjVu0DrZc&EI%Npi4^*O3XKtIJSS1xP zV=K|vnID)ZuoIPlVPQl*OJXR_4NfJW zcjug4V(FGPgxWcVY1YFsbd$B2IAdo(X%mTy{wC#Nx@WDklND0k3yg-st)h~EY%B)S znD4HsPbitBNHESLC8)@K@0*3oXZ7ySbwKr3eo?lTZXpNCasrKHh}X_){w^bTq;xL# zhB`=rGk?5n9&R{2U$dA})Fb?0mb4^2-bB=A?bZsHRwU*+Q=D|P1NOtX^vI(mOOp^* z#Tfo9sP}cgv~f)3fnE7BuB-9x4k^=jo+%gCR52V@Z5rNuYL{!;v3~s3{^3OPb*_}2 zypa`N#>NsYFx2C|wW|<~DYt~^$uodD^DNI}vaT0YQHfz#JM?|mNE6O}K zBzH7n%0Q&OUPe^ylit0YX8L9`89ZCYD}=>{kW9>Q6;Kq|W;kP6-Zv5cxwf5EB=6@;$RUvfl{XzIz1NjkTnX zP;k*?Jp;4ruir6DlPi0;`|=bI?TGG}6|f9(ih}!6p2%73T5TG{?spb307|ouOFTF( zgI>;u!r+MC{J+`Rc#6RA;0VPBsp_HuaUc>{6`#1x7yCqu7iF@izKkpOl0kH<_{8xD z;w>AcgqjDzulaUt6~ z;q1#eC`?LfZO52uJTv;33$F*}|Zba3n|L(ga=rnsmS zGss1OX;P4F8+UM+NvN~v5kOZID}XX|?s}Ac+no7U=e1>~z8P1PpuAN=++ngy3mG$Z z`%;&f$5+mxhRINdb{G(0cp+JIUs;t&%bA#$|l>D%Y!-4L|07K+0C; z3TcqCd`eF%rW){|8e%clom+8(G38|4rTX7 z%W*I-YAH=y?hS0Tp${JrvNFtI!+p{DT`1zUvT^Oc;YN7{qhYK!JtpNEO8I44t>`ggNxBr=HMA!$| zj1~E+Y3ivVd)xWumjQN>@|~^JnDdA20#+{Y$9+Es{3+6ZQpKN2^V2MTBF+DV&_B)M zr&;_oi+=;Ncqb zIn0U4zq|PVRFei&5tQ}vY3I1n_9N5lk4Qc(4`r$(rEbXT-k#zGM9KDw#^-1-v2T_) zQMKJ#q4f!)Mjt)J-VN0`^f~tw1AwhGZEW+>=JeA-wqbj$c}}mC!Sb z?5K0NDf>Jj<^j)uqiha zi>lV32iu}HmA~4>0x< zc2LY+?y&=sF_CGN1@xN2)&x@05=J;3UEb~+a|+GpK_abP7Q);SjO2*V!OMwqQ)i&i z>bqyEaSm@t6+?64o7;GFQ@QaeDZVt(;VB5(vZ9!jt-z=)Z2;FgwS?4S#)YHzxI+Wq zFh#Z>0j?edL$p-)t2Tdy++f8!(6+7in>l58=GO+QKs}7=NNarMO(EeQQzDQI31N(g zk^)W5ZGmiJn5(C|ApJ9866?_XWQeC)(`&KVERJ~$Aq8?*>Z!6?y#~M0=h|gBTId7( z!Y|1scr<6@96H@-{#T!RezpUNV~#h#K*%-tMkFLRi{LTH{9T(nr$%WmG3B_wG+LM> zGG~vr4Kb!QK+T$yk}JSX)I$P+PV&E8Q_pwJT6A1dft%{@MC-+sY?Yhp=`j}~9oc9- zlG?&*fs#57feTw3pVz^!jRMxMt_Y2YDW6XhO6N|3XseDz1dtLU>d=W6G8?Lf-sIx@ z@XwGVfV%P_qcz*{vz5oNO4aAawB4%1aF>LPUi2A>^`3IH(cp{QJOXzq3hfS$sVZu2 zQZXF6q2G5%zRk%;0J?&6gn;*i5#H*Yz29{)Rs_(W)2|lK(^|#yqnC+`iX50ywKBskR7Sb)*os< z1=S16i(5TJ7?D;Tghid$PU-OBc1XF??jXxvp=uZ`KxTz`GVkC{no!343&>2?3&UCG zkVIGim|d6dA28C1#3fML43ys^c1ddqT0acE|Kq;0 zPdv%0`j4Q)bkprD#ll zXky6Dv+#eozj-mbVPO-QYauktS_o0A@ESAvY^i|Y!jv1N&RV85wJx z0|~n8aCJmfK*C7n6!V89q4$gqKSr&)xcL3RY%k?SW^%RXdxLi6l8CO_Q*UedBU-h4 zo2DG?bNxt|6ap~zc47U-!)3`IGmfu}^!4-7;jwlA>RiVLAwg-=A4miu8JP+Fg=Xs? zDL=hH4HEG~=JWZifj}gy@1LuWa}Q8$AXp^+rs-Dyak1G55jLKDB_84|FQk}P&QRpY z*!?;^YIsXRwc{@4;^!Unk#I2kQLqAw${~RGR#6Xm>DIZWgJxv03tYlTYDef6>&xYM^^3cXCB*l*iO5PkqJq zQ*&BZkRtK@2qsvW6^25e+-`5G$51R&PkY@3Z;yIq?RdOdxKqvqhqRF@KVJVwN}5gf z1ky|C#*^UYW9*tJC4^NrCb7c1Y7y0`9dGd&`C)9|;T=R3H)= z^Msc-O)nc7pe)qg2=BTK43r5tMr-Q8M6 zebnNg^7qX1_!=lEfigVR{d`%{i<35$Om0;2(n4`!X>f|hJaLIz6w7-p zhKt!MXP3o<^MDu4L>AB;rKfL`pXb!6m6w6;=lUzYokjr}p^vi%=6Xn%S(ED#{*CkW zKH1HvypV345J4-E#sTi#-@Hh57pvXEnRf|WjcK1>%6$!*#hNO^$_^>c# z+YI5{jeK1%1j>sOcmxp1DzDX|1uH$UCsLOk_;D*9iR%#e@?`{~J2*ug3I^Ngh*~>= zAzw-$)pJ}_!sPZ?o65FcaZipnT7-BFqy>j%P!Vpm$_Oq{dJ#LBZjr3F2@nR{#y1-I(i_<+gTIGi`x#x8@?$1$ogI$VfAKtFIRsmEx6 zKJ}I_yriVGx=-hki511XN-8tvd%nWFrto=I2@m@oLop`{A31I&y-S9OhC(r%!3R5t zBWVu!2%;^i?)$A;;ozemo0+4vtakQ?$>}>LqRyRPjL4=mPL2c{nd~5FT*s|kI0R9{ z0;w4c%F%D_m%ATnJ0QXG`YsG*brQn-JWvEM?j z*Zz%N3_XaR`%R-(XpU1x*=^jl^}DTtdbb_J*!NAg%T$2Ppi+YbLHb%HWwczp6qzZRv_$X`BOcdbsFY5h?kMNA$F@d4X1lCzUCdMW z)xe)@<7eHSLyC_HBqQsnaloNV1p-zbCX3t^-{A%`*9k`e8M7n6ir^8T_09uIDg7C1 zOi(2yUIfU!d0Qs77vup-lPJE;)aEfn@gXN3=kh5a(&@Uw96 zaDgr;&Rs1{!Ex?MvACtedUvOC@wL_IdyzhbN>bWbE>KGEep*x~6|R3LFC*FLGBLm6saG(WE|0x8Wy$}zOJDhnvsW=I zDmo|LL7b9IGJPSFq`7S>=0+wCO_?)#Ni}zD+KIGUkqMaWJD4;i+$x;Dm!!m-qA;y7 z9l;%`#ow{q?yk^O_HMX}HzeL3u&`Qz%YDWud5rGb2^`WM$ig@ z7%uRAt1T&+z8xJk`Js=e&&Aa5}3*YjubJl z7gN)E^@<|~`>@rm=W#Zfm_2sQCnRl*`Si51X=3tJO=8s(Yd=bQw5*(&g#8uZJB^rV zoD^I|z7WTeSPStP+jMO+^C@rHG!@@q<5V=BoAA7gG&j@Hj^H1d$!}>vt7Gi$2MG@u za7!vMcv0QHz2|{1jTJX0@MQ(GkL)C~W<6A(7*833n>I-w+|)tiq!ixZy$Sv$uZM%e z){*#Jd{(pP7f@!PNbX{m6Z{p@RsxGfA(+hHH(;w3zJXKj=n}o6u9%rZd4RWxS%$Z{ zMJ@?SzoTu@bu^&eZ@r~CKt!7wh- zIp}~8S@b)WT1kh;-*^vVqr5TLZ}YU~o@!v#f9NPF&B zDjh;)5a#aLR9K@K9Lv|-7XN+YLy9;g=0#S;&8Tb0_nGBGa|zKz8quj zO7Zg68@A_MCr1F;6t6%L$a1eNcHiDpA9rPie|^!ZD4cGUftn$k1XC=0_PT?7y?{_H zkWhLSJ~h@>b31-UZju!HCd4+Jh;fL|Qk9o~F@I1q;$YRpb?>SYd}hETovt>i0Pb?C@8_LtYXlwqKkT0zf(C;+&idOVaXxiMp}*o0dw>A=BPM` z<-OV6p-)v2q8i+k8An-pMx^6HSF|68%M8wv1jn*7vhj{XEnA;^mE^u+vgJPdwZb;w z22wJ56UWt$g~2woh=D1O^=I&wH}CZ8?cb!6vx4xM#=K|dJ$)!=7ZK1}=2Iv)b8978 zEvlATlq{wq#;#qNTe@LUvbN0jO@9XPP z>vlMPNi0{JiFxR^xZ1j<*>Y_IrXVheGVhgud95QrdDjtOpk`NOgScvVn1NvH^t#2j zW^gNX9jrbze*`$bW9g8)=lP1;e($>AuYU%p8h+fTzdW?J&)qal8aA~l88f^Yi4-!h zUvEu{DBtG-HuMUzk4|lSScR;ODJ`Ir>!mhi%CS~f9!Mx0S-M#4e>Ny%^TcpLKAuFB zF6g?f+czgN));(Ms!<2hFlD2KKQ1)+04}a-b+;8Fzbs7QdQ#H3t05gKo?F_2FELt0 z4mVs$E$jLsozxo9`MJ9_j!C9t=}BxU5YjrWeIX&q6h5QeModC&cM5?T%F0867%hCz zIu@rSRtH6wjm>;=^CXte^)V8DHLCSKkKqhRf* zKlVwA0(ba^GGN&pP2&tnwHjpTRO=l}4s%aaqOFzM8YN(km$u25c6uhJgtT`B-|v(^ z{9rsV4IA-VgXOrQD6`EM25iVZ#wS;8W(LVyU+qO%!$rkQuSb^-6unHTbzwst;9!q~}!~09pviUG6?M1(` z6orb4-1e|#Qj!H%4^qJzWwL=nG%h3H(E3pq4*od_?f6pt0xrgqw5dB=&3firP4zS7 zO_QFv4iSZ-2tS061m}m3URvh5cY7xB&-9|Y;U2A879cocAWm5s=`aP45asvwQ;H3% z=3Hcwgw&Yug5!o<+&gSDwO*JQ=uSO(o6)AG+}uVQaz#kqxM=9Nnf{$;H|jO=U^C$J z!}(ugDlVhLYmNYuowpQuca8wZg{6%dPrdTgG+Ylkhu8gOM&$>>WiXe_gp^LZmiMQu zZgcNT9RZN+zB=>GweRx^-0cEeC+zsk6*65FWnK0q5|-M>T-!FMXC@X^9u=EWWJB<# z$Mawb4U)*lb&y8Ovg9S+vkbV$bV8@sxU4c9kw_JLG|ANQNrXM((rBdCaiEESF-dAO zfk)#%QuE%c@(f+8JPYy+kvBiRXlEy(Q06N&tq7(BRvgUo-)yX~UjWUnUYG?*t_u)uP|B`rXBH2d8M z!SNEpI0qb&)2Ux<2SGfM&<4UtGsU6dwag6XWbb}~-PQ7|u%;$6yg@}Lm!y3KpS#39 zO(m0W*aL{o23(G^{S%R}6NE8~G?0~;5J7&No{@qnKt~l|saIH2I z#hHFOn?&kHXu~cvQ?W`OF4V`ok(-0Xb2!#AUbT{G>J?>~S$^N-K3BN*juh0NeQlvP zWNkSCk&uwlno#{s-Zk{)X{r4&;j$$4<4PVcV&>>|vp|xWh36GlM_ipl@aL!a$Ig@e&lM6*#zA|RB$Tu`u z5Nh7eDVMt$?Ua>oG@+SDitH=C^hIqWGt1-wb%<5u`Ei|OgkNa*`|+4X%6oHn%*^9R z;(D$JaB$iDtz@4jQc!tecdIDskO{Ub8eta1F>p|Z{(K?r zgYe`OHcDu zp~Ts;*zJf3j%$4Wb|+i){e?FxNHl!?;kE9^$}XjF)7)#t%{+c-a>etZoH-qaQiv<< z^(c2MEGSlxKIr)ofG|TD#T2y?J?k-DDCpty|OD_Y3b@DH8Rsq zn1AL>_at1_Wt?KX(Z2b1nR%+I{2gH4%C$W*-+7|IE+049KT&a{m=TVEbLkx8XUtXmT_X6jQ8_6$WaQ) z^eRJ`IWzYfHh-e(F7EKghqYNm^6_23&n84EyD=Shh0ihE`XjIn*L8o#U>GNPtK$9B zf1dY$;rWuviv#hl$q&V1k0FgoE>^hi4JJ8-`?YS!^7r#Y2t$^hSW4bQl%94u?eUIb zcG%`uGx5guLC7PCBS5zCJ9w}B=Qh3kfLGFYcs!tB(>2$sXXyK-GBO9 zfBSX$bXl3n65;!JXe)J=g$ zd4+7s$KO5X3E-dFCsk6XB<>==F4M@nOQ;NMl+lmu{W*A%I*KU|c0`5=6DrSBuaZsL3gZ^y{nI-WGu^eU_4Z0Y|#iJT7T z0(efeD~<`s%!?JICmkQ-~WUuY2k literal 0 HcmV?d00001 diff --git a/ui/tests/scans/evidence/scans-controls-mobile.png b/ui/tests/scans/evidence/scans-controls-mobile.png new file mode 100644 index 0000000000000000000000000000000000000000..a5308650527cd2ed91fa4733c0bb2efe26306afd GIT binary patch literal 24134 zcmeFZ2~<KI^P!Y5dBFZ2wlM)662?z+N5N5=fgfK;vNeS~51O$|B5rPQ@WH1P5 zfDjT0GK3)rh|IGLVIGuuMrHwlN4MR5yYKto_kHiJyWU#gy8n~4l9N+ayLQ#yRlD|Y zSDn3{z0ZK340QB$00#~L00;IzfW3Zz7J%arI|utA4i0vX!-qMJaQ?)}dGshJ-|-V% zKk@UOKF!Z}>Xd-6gouEkn9!+HKg;|qCV5^8By~na_LA&{OA;5PF8oI1z~RG(IgfDi za&q!s5I7}p;s5ou_W{6jgpKP!DBA&1z(Jk^Y&-|{ssO_KOddSQ_8Y%{UTpiU9z1;H zz|sBWTR#B~upK;j_`osFLx1P+NUUR;E(Ii>i(d}v7dICXTQ%5 zvaug#V`Kk=qXP$d*r07Ef#+_&J;ci=Do@C{Uh(yw#}jsisP-?HZ|wB}xY+hvz{AD^ z&;%^M`46K1`*-ZilGg)HU)2}PSw7!_^uuiO*0CSCxWce9`d)pek1iQx^W@sG@AF7r zO?e#*Ej&5?&8>rb05wEaYZEk)I&y#F0w18fh2?R1h3`JP=+!2c9q>Q8^zc?^4IRhe z%QdEUHJ{=fN8ih2St)HT!FTV%AO9{E{*4pqojbGT)R*i#mD6jQ{);njY=3$EQ$6&m z`-fV68N7}>&Ir*!3lSB5lBV7SS`9W@4XTu=;f!Bc&P|MYk#|b>qDxO*wGoDP78_C6 zTy*?BM+aHpoFuN_h2fUza>KOM{2*A2)!EqCOI@_`Dcp*fxii_NO?oHWZDdnubx|>s z8uDs=)6NOH=p~pXhJapmkQ-1s&<*HyvpA88Att1HSxBd)7c`4sW>wzY_<*gwOUn*D z?K(WEC6J=67)3O=GNTx@$QKhqGwN>Bi%|W7=YqIBFLLP}JNTTRcsYfo%uI#gb3q~_ z@@r6N{jILLo@CL>9HMm4bL$*=&pC+9s^+ze7CLx}foh+n1*}!g^+a008_#ONWNKtj zJhhN}`$Oje$7Rggkn8paX>=$_S!TC3NJNtxwXK{iXQAoGXwx$H%pbTgEeUt_g2ObF z)Dg_OuyJijwbIUGQ?@+Woz_){Jjl#NTDp|5una*9x(8^tN8t5&5P~ZO-&uW0w)&ax ztlqvyTE2ag9qSMGjizLnWnMvGVrZbWS5vi_I6{FIiW_PqrF->y?wjqN(I#d9EKoPaOT* z`dQ)cm>Um@EEAN}iL4F{@gTvkUD{Q&e>qAI#5oqQ1{Z$%)c@9;N=E37LbSW!5Y!AM zfpD$rP|Qz_##dj!b-s~t4c$4@Aq<#5=#1|%^^b$P5CqCl{3la}_07r8i77BHB=AbzGQ+mS8HWHF+HpIy3+gXVx~bi`+P6MU|e9tH+5k=Yb_A~Shc_TYHGE>ySN?E^W}+R zpzN%P48w$~yRJ^`NK;VHkw)|yO`#HR6S-(hE{JZuY9(ua*g`i@`yR;l?Ev@sgZ=%j4DvuWSmv$V38SwP-F83#o4P zTtvW5AD>*P_sttnv^5n>EOW{%L}Zv{fujwL)qwb}#3g;KmL#Z?r7O2K{C@h!1o@wb z#YtGRtm0CuiP#8HSuB2Cj+15FfYkxaO)2I<7J0P%+Np;dQx%OX^TLZD?r;;JU2h1; z@6m4l5=^Jvat%WmOe?Y)?~dsg= z?(Y>J+%0!;UNCO)FXeBEU}*LluxTWHq4C;MA{e$X4yqcWF3A})_Z?7o$ZzY;sUUxE zuAPg=G}ToBFL)-WADVAYf4aQ-UgrDi)WK`I$!TBiPo`gMZU36L((&f#fwMtzPm_}p z*)$D5wzl4UEdFm2|IrsJn$?9}paoNK`1&j(m?U+4zpoOK5;?&3wp5->oq{XGq7=c& z73wCO>(&nq;o1ra$~TT8-KobLS%eMV2l;*N&D)>vPWf@(0R`RgdH(bwQ1hJXhfMaQ z8*$j=7m2p#469A*ZoZQ~aQ{WxNcz}$v%1?$uw~v%&JX5eQV%mWk9H~Wy@!AQb@t%9 ze-rsH`o#5yPdw|TYr0OUP_L-x=Sa8Yri`&$^4ETs$+4}Sm^_9uc&5rkL9%KOV0Yoz z_Op(eptWJvwb~z2`(J;nXx0>Vi7x1Xr}s5Mlax{QrvZBm`%(BWWA(Qcl+^={NKJ$M zh7Nl)%^aaBp1nmlj}t5B5R3b&)?u6(S?uWgi=$?M)P)4#mNfh;tX>E=ck->U(c0X= z7{qJ|Jvxr|`!vOUw!Hhn_n3A|l%ParYE<~57f(aan6@rDdlMCMFY*<TG*?Mflgx?rh9OF{R& zPvA(yxl@+9{`X?(q0Hl5<{brbsJg1~zPc=JSAlv4t;Dab?|SNn;F_?oY(<+YNFOa3 z0VPuLueKIzTSr}2PH)gy_9N1EK6IOcLA|~UV9QV*MvJHIq}84IH<+{_>=bHq711@c z1%ppR7RcCcp_{mut8@BhxPYFluF9jl)sQvG)2H*9f^RnX2kcWb%5S%s%PFoFo&nj1 z2bf93*v#8jB#AP5Kn$Pv)^g`j_%CK+Xe;Owww4a`?ds%Qre1V2Su6SG)OFA zajuQX>_1(uY3c8(I+MqgBbZvxcN3YEarzsQ#SyEijzhS%QhfDQI-Jlzn}mrD4yx{4 zcg99tna|Y+3T8EB#uDfh1AEBL#{6MwSjp9l63ho>)v~cJtlC9;BubqB=2{xY(=bNN zaoavJU(a)t3N>xvR5t=#!o|316Z9ah@C9Kbl2Y1G{VSwQHOzeJ8)*z=c4H z&Z_ZMI-LGYCJs#_C;CoCnhr6J>JF_IWl3LlGzraih+3>fR@Vldg`G_>S#)<4DvW6` zzPjpC*vj<@{I!+MtV`@{^-#QgIrhK?6N9@>>Vp7FhZh}w-EPI4g;z+0d9)M6n$YAj76Y=l<5TsFlt}$EW`P)2PX7{PNs#`pY8+2vO88>Eo1ognP$wCzrdO9ks}D6Rm)-QvA+f6FPGS zL>CCMcpih~)|9nT*+u-?))5iN9N8ST`B7?ng z>1k2I4opXPT`{DvDQUE@8+(5FVCsLRD*vnJW!iNYZ4ZZwVKlTi8y4k;Mg2HW?tWR_ zN-p(XyY&M>c>X(lVC2s613^gn9X)^v9U%Mw5PqNswE(*x0K(8_q%#r;yLi!oR_f6;JaaK4AldvR_Cp~`9y{p%zCD-9dB1<0kfmGNel@el>HPLm(6} zVF?n(kTR)Ba-u|xkHrRw<_gQRCCUWZd7VmK0r^qBJOx6={%hk+C7o00(Bh(Azu(#M%?= z2}0q$R0fn-(hW4OJ8U}D5(yugA)HdJqXdW5vLLz=T9#rqkHVTxV~eQrK~>d_IedAa zb^xW00;+E>%sRR_np~YP(ui4j(#Yo;MAfvhp$;f7s@+I8T(x*+IG10*IW?No&>u6D zvjEY_rIM3O6(o8~!>Ltk#gGI&7f%x{e`8QeN z$<93fa#PKJQ8{qC&12C-FgDn>{6umneJ7zcPFCc7-_+a8VhdM3?`V*c3RNmu@GN!E zPTP|tI+74nS%&s*)lJJwYl))Qave>XcC+xarv~2E%$e&-lp@TBThIr-Uo!G3$Y2fj zC_XK07E3o!`-M86zsl#K-BoI;r1DPwY*+#T+SjxD^P@MPBD_yY`?MM=MoEiW5p&x* z3J7ZoW#XQN`Tk%S6iX>`L0Iu0l3uVl8W6gJaLH?L4AQd{3WuV@*LX^!l+E!=FurQ} zo-+Ft!S}$}Qczl(VXAWCSrW5Xwy6N#zc}aFQCGLt7NyKlEP~Ypx>oB-su}H^Z{OyY zh%k~`y~)Jm$s}So2cv*J)!wMB43fA6<^c*~(-ZE$KAsk*lbvIsHY-aUYjn8cFley) zY#){4Ql1-r|71NN0R;LvkjcpFxDmsv^G-#W&mb&AESd{iq(Z~aRn$+a(NpwYq`m0v zZZBWvnxAjm-N>zq40eu^RePu`Cr&UWm+4Y5Q$ex9l`KL(^lBop3NXdJ9Bc+jeAvu4Q z0LHBfORv0v2UC-kxk;o~OSO{wxKuHWy;>=8GTrB8m(xUa*Pu6^i1r^82_5Esn;kIW zoE;)-WeaENFg)Tcg=Z%b(g7L6bKR&D@AV}XhLJurB2iDA(R%sv7A=HHiuqP>9$d75 z`X>2VRs3HWipKnY^uorG2QHs7Sujwl2Z`ha5~Z)fjqAwgB(Ao1m!b{RG)NFpADMS3>-2(QZpy4cDJ4#%x zZS*OUvUx+&BPHkWM*EPFz4N?rvwse6Q+SSMFQD=dT*2-KsGtXk{DC~={D2+Ie?EBi z2R2dj1DLRTd}R3t@Nnh_bP)v*`!|Vy_Jt>JW=&>_k1BX-qMkSIP{5;IdlS)D>F2+7 zZB?P_YD)J9Px>n2&%sk(6sVEDh}wa_`OBkV6B6Wj{9t93W|XC5N@c{rNCta=jFS)B z)xO%O1hbVY_SJ32#!e|kZ{$XW=U9^%ChS)Ubwd>(p3c@g%`Mu9$WwF;)AU5ZikTX+ zLVU_FItgzwz(k%L}nBsK+POPwWbhMphOyVy@{@^-P0<05;+e9lu8j5DR7#1Q^{9dD8a|EdhNMvOUEcygukI3cjL$NiDn<1LqnjvWy9N}e zH^)kUZV$k1;qkGbrxJnU3|zU0Gf1O~$u={e&4y=`Ff`7(ZCUt;ZLae|OA(c;znv$G-pWnE&v~(*XNn%q z1AqRZQci!KJfr|O5xOMbZYV~0ZVLl?Qa^`1yX$D;#aSxSp)T^S-Xnyp z_C7P+-cF{P(AbYrkcSCVYe}T}6<4*$hh zVV7Of#NfdC(5w$`qxk}vfgBpqr`!z`kJ6=Nn}Y3Qlr94y1NaIhI>2X2X*StwcCB3Z zO-WhI3ar^$wlv&CFclI26wJhHvrLP77*uQ#4L)wa;FY=|e1Xw3;{sgoBW_%D*y=ME zLxVNEx=)RU_&xgI_&GmWHygh8vNO6*P96cTn|kwfwbf}n07ac(P~(fC{XkyNIhEQJ zB+rZ*?}Q#hidwcr3g0vHua<`9sJ5@xy^4_al9aw6t8G zI#6FB#Be}fb12Z4y6@z({d5wpC9Al69V)mVB$U2WOWqF>PEqU!WHyfZ2m=v5GB2)M zumaVRLohfac`M~F4CTctF1G)z<^P{Cat_u2kix5Xqfh?9vWSM!eO%&O{pAZ;=jmLp`TJRuY1$7+*0 zk~y_Xj}6`1`xRZ={I`CkBlX2%UC{Wp$cXBtzM{|6qI=^CS*rTB36N2jt{vCLN<&LF z`*b4O@+qja9i&ZQAY!;YX&9_;1REzdX%7(0v=1tabKmM2g8$jXTLE!(^fcSBfC6_g9Nes>=kU4KXh1J^k zj{mh2$HwD;i5lOm;#qbtR z)9mZF_j&W@{dC;Z*t`ECs$p!U!6;u72+H}r`kTwozZe|L{)^^+Fj_gX+?t;_e&*v# ze(S$T{*BFN)#J&IY7Lj4UXUyMi{{_hJQ2~T(eC^5KIg4}+4{30{IP+l|8D&M50Z~0 zbgivP)FcLP#xOb&ioBWN7iDKI)gG2yT?YAebp1->WQwlAF6E#uf0V!jRPuk*Y(du- z*|r{0!y*yJH^$R(;U(2pz+tBtAaWio=F%Sdjkvf6P*L7N`+wEU%^qDCx8BfQSvLg) z+FEUhnPDeEpTokj)C7?O1ZxP)EyG9M`C_O83ADe*>@!)#K~l0^d-yqEoX;(0sxE%A z)EAtA&8T|3zkPMhf>H#M)3~c~(4VSGgrE_yW{!fc_2;Ie>o(UUC9ml7246d=n&eR1 zr+S7bUUXI($;IzEI$NPvow?6+EZXn0vun~BG3W5i>Hq{dx+Q+`#yNSnTYyQf+s0zH zPa~srU7dJ=)*p@olE`>+3=i6I;wispUA3!b(_WDB0C{gH{?}*QJs%gYvd!ka=Di z?g6}pgU5RJ07bv%Zy5zee~k&$eCYHu+hoaa^f~&|M3%tAyPj@aot?Ns1I-bq^6z8A zYZSzh;I=4%nY(h0N1JzGr&`-syop5ThGIiL;m9FQo}~)~vd&Sdt-8`gY>}vKi0I6G@A$I7QwgKa=mLL7VWF(r!^-|P z@fWwHKvtl(X3v}7Ejc?#n<;R(=}tT-;bRRMEBY#8sYA!9l1P1TGI^@A;h1HXE7Laz zcG57h?J?e5Buc0~O?LY-*a6#Sk8*U&f7)!er|F6(8e?B*JX+cfAU# zXq)VcguX|;lAbs|ajCzz2SeA^DPFdTD0Is}IwIW|7W6FKQk!bxxlC_4Ckd}u2XPaB z(NX+ygoEIv;i7JlK&FN(Yb{UJ$c))g;$cHA+yrH>TszLBs$AP z-Z=H;i%;FR4Y|P@7G~|*dJf(M!(U?f5y-=$&Xw$aNnW7&G+5Kitionh-;-Q=vH?(yt^r?%V_#eI2F4n>PNU5W-G{h?7l<%XeExse;m8$x9P^z z={q_}BT}E{8pJ@MI^#rbC!V&^tWXW(1SQEz4nbo&ecJk3e?Ufi$iv=#Og18>lx9Zx zj^wh6z}|b30UrR(#IJYW+!WYI#Y2{hc@J5SzpEo|dnXbUEP9iA2D%G@{h5Oev~lio(K@a(h6cd0K|hTm4$79^_bGH6{8m1Bx{7_x(mIIn+P?0bj2# zeAxR@CTOCPYek+~g5VLDU7kVz+ZT9eLBE59yFq8z@DyY9e_Kqp%QjsY(0;tISwsv7WIZYy?*7 z735*jtuo|omcBp(v$Ybf^61;exGu5$s%k1eZu2~cjT`U!H&^`>)3DjKaoc4@PrZhG zFP0Ex3|)&I&4F6e@=g!~$vIlO5Ts+=DTKj`0+N-l7?s#HH<*(VxxeKk<^IezC_a`1 z!Kc+t6Ht*4C`F{~WXG0(H1B1&20G);)~`wvO1qrKu<${5nX7UZlAvu89iv*!GR{n#8f zP;wUsdx{`~Vk?AQw#Wt3C(F!}rc#@AFXuQ}By=BkHoBVRcJ6G#9-t~l#OK6%ybWuZ z9`llB0z+MWQNry&E5iuppk}|lPHUHb-`SEL%S7Ioz@S-`?5?NpeGfO41ws{@T7osR zXL2A=IO4(gJT=3&1~~c5@D2#4isg5G1T^Ej;&6!6vmvt`d8Y}@)GS&Ck^Xk2vu;`< zNT3C?*87B~<-Gx#PR*K?g=tsI^RGHsT}aS-ZrXJlK5LtMSj8u30D24udIHKH@%L4O zN)VN#-}j`zcu|qad^g9e46GA+v9j?=UgxwR+Hv^M+Q$8=RhAbruP^lLL^#>zp$9&W z1;UbSY$K^H)Ji9!Ki1-kt@rAhd{q}r!=5mYoT2JvyQU!hN8%-0r6knxZKnAqdQv{7 zrBbN|`e^|OY^@r*S9ue*vu`lLz&v}YsVB-{yRt-CtdH3Q=`wDhl_IXrct-1)ixIQw zC2};vyvY}mSi!vZKm@}C8So^aPyKDB?a86s`lkivQnE3^6E^ojg9r2ECAraPNvXnM z+`2z@8^OdWMtw0v@TRAc?Qf*`#869#Dll~5uiTjh1y{tJ3l;57n2VY4R(pQIrZ1a} z1=_n5$0)S)(j65kV*%fdtnjs#B89*!&E8E_%|(_M$J?c-qBe3Rsib^FR$A$-vuiN~ zRBWln5;c`30E@DBt&l=`CEczq8|jjzWJCF+d0~8^eV=WpDl>U}@LP7tM;=j*z8ul;^5aI#eH?1ev=;>GYj#7VeQ3 z>O>bKYg}_hi}|_t08b)-eNmupL@mO{#V~;~Ny@8nJraL0@sf7$jIqMDH{PfzJFN(<80UmAK{cRc4@15-WV!+PimCWL+h)JhzbJ{l&iAeC#4Y0Xg zYwVfYTze8-v##IUP_u(_1_CuYt*$;xImon;B$B(oZx?s-K8!!094IsNyeKFzIah7k zVb#8JWo{>$@pUtW{(Lj{8|#SVVp>95+=;Hml!Xu3bvu`IF zN8vvw{Kbs$Uv-p;DEfR_v0tM8Wc(L1_`m9~K0#ES^80s#|4@bh9tmH*yCj1w7S6$k zT!B7XFi-J3zib=#_2+$Q*E<&lf%g@SW7a3o+oOU{hMa;!G=+i@OJ#X6nBu_T`k$i1 zA@Y}bgROSUE6~(0_74C{YQL%cf4atS2sBl)YRKbn&kxi$n|{H%8QnVm^WUES?e+|! z6RfBn>M9Xg_%yE;oBq7k)pvyB0!RI_h~D<0R|UmZEE~PBT1Ja0)fP{cQ!9mpy;_y) z`f%uX8g`$caAYTjkB}LKE}n@eiGnHAaRe$XER2SI6_L_ym+#yBK(cOTcD*P#P6+&N zm=+nwb5@%~9Juz(MQEEyBs#-9zQi z)R zRy`D<*3SpkVRGQ{uP6XFwIv9&f1yUHbaghhDD9(~sk| zD{e^uZ}cZx5#*q`smCOxLYXA$`DF;(X||Wn-cjJ^Mt8<_NPetqBS&W)9o}Xp#Ztj| z5`U(rd~m~<74SF=3fF>|n2Q_qp`WSeX!2DwG=a-wbAvC*KUP3rph`_Uq8-A`*KY~ZmW7swS{0$mW83OFBSg^Wxj9g=o2ErD+L6RnRZMC_J z=k?nZSGrQ#kAa1S>!lsANr_TXuNZngRuhaSBYADY>48T@pM79ygg#=c|BNJ8br9OE z;%fC%;0Wnhn!1aH(&s4*#wWh6TbbQRDLdOiFpgadddD$$ZWeLE$;6gg{$Pz=9X3u! zR?SFOMa#dOnV7wNXkg4rqsez(tgYt(UCGI%LiXiyXE&=%m6DOgl^9N=;&4|TQZHmJ zRn11owi{Zl6lXf;z^`rjk@nAo*hX)WK2yrPwFH%+ zF^!nz@tm$XMmJ1ELogg@aWu3tsAB5`X}Nw^L6v%nx@gw7P76NdmApGaH$%~*tSof} za&lnp*Lp;8`#mI&RGasTK?Ds$?>IQj{@-SklUcJx_Acz@%%O_&=>Vl(j80*XPLQ8E#sRLLt;(pF2( zW$MBPs6j6Sv;d55uih0>Xql8xwnez#IC0I9JtRsMcOj4d-16S125u3HMxW_?W4p+h zbGD>7aHxW+K0gu$tQES{W0Dqwq1oT}7VvlBZF?E1OQE12cofuP4M88fi)WwVldC;v zvLkXzl+I!TTT0j0Z)p@{bjqL{Ix^{IeP!ORS43Zn(`f_;b5Oc}OIR< zCB$vzz!Y=V_FS%``l7DljW$b6Y)G|5kD!yimQ>>*v_kEo%O zH=EDkb6|)m!pEZ0aDxbelr;jcu!}RsWktfJZ`A6Wh^0F%x1rT=O!AIt!&ZHUIRbpq z-ZTqGQ;;r^u+yt0F?v)mBb4;lt0}vZC3}Dt<2``Ii#C)i-%s^G?m(2{ZIH@b=zV!Q zd|>~S2!cyjrPZ@|hQ9CpQj4e*A^rP%fXY3<4W5&&dw^%Vzg`F%%D)ME<*h?fah`s} zkhM`+?QBnAEMefa28Chemg zky3C4J?1n139fsUJ8^YR+onJrJBGH&ULtrb`Oc{_L0feWkKVC5b)`EFm*#?0hS8(> zqb5k0NuT|UWJJD^2xZMR*DsEHy#F~a?!h!SuG^5P4{>d3T#h1xp4FbpO##PKBCRxB z1sV$-R@7q~10gl|SpSEEe89Lk7))Gmy?D+GEI=3`_T0lN^VM=4e~V|*HM;YtiKPX- zU^{sC_M<&Oc*VZ4B912^ysWa(v~IqAab?V|;fm^dF(vaa74!{F8)5cLJ5XAPRMs5X z1^(O=Er${+qKcOKimDwNev-Ly!^bd_2%71;FhvzMR$!j~qDPRA>5(J3R$sEN>J-nS z#-=e8I$O3vzx+xkAnHTsOIpC-%bmr-u&a40^8I40#=@XwV`Rv=BY?_lf48%LyZ>wQ z5+XF<;EM)Tt<1_#H{}p5GA2>+ z@jDK-^RhyMwSOjD1x+WD1G~;Xsm5gnne73j_5h}M?$M9*S6lZ7?@gTrdbf6H%$~S5 z;$pj8yJ@nO@9y^3v#&IA(5nqI|HHgaBC(nc!K{>D9{%}^+hEq6${aXP&yHhI6Z@7m z5rUcJHlm`(W!tVqYdj3w**{0}z~&GA7gbSdn3G4-*^`ZipuC53xp?M#pMOF3NulI= zO@r#pQumWA_0yt7ChBrjCnB z5l^E^SCMEH%FHW(_#U9|Mx&wiz;eKALZPy2lybGCpwFH4oaSwQ zbN;V4s(q8>c9OReeMTU_Dv$cH&j;GpukC9*+p5s_Z<^Oz9!5s&SnmNMC+7gi-Jbt# zC;$Z9JZU=^!qmW8oNmraZovZ{vnn*2(IZ)MD=KCo z=r{%xKVpWd#5!O}4jq*X#c@p80%6e*7S#3qwcc3;c~e80W0$5rmg;wn2{#_~R z;f;LXL{}8f?QWdL+P&UFOGa0v5V*`$1GOKc{tEL!iHD4XTZUCDeC_M=8rizYIw@-< z=haamU|vtrd-!2d-qwMJ)eKoKWukbV?-#kHni*eA!#D<1jk$6+yyQ?{nM-xPy72J* zFB2$~8nxGj<$F5)Z3$D_=k{$@XRQ%FlppjN@5Lwt?W!re*2=963b35sBW~Hz8R0rp zz2-1|<325;$?u*1qjV`6{M70Bisf()nFn5a~ z@~!H1!=RGRDc0_>K;V$sWJY&-H<7>4CesOjRypfx$}jRJ_mi_HPjqY`3z`0XioY0; zN;{A&%d9nzn)(bWLK7KRU#4r5zzRgW`UhZ&EWAPEUhiNM_TEsjFOdiFu)>} zouc=h$ICp*C3D{~PW;}ME+a^A>}<25lhI6(L=q0lkT3MFrBbP7c5sOGIo-ov32A*B z;6_6_T%m5}C`BN4#fuR9~wzFqikYjPaN)%WKcPbx}lKlilN!ewRn{U@6ZxV7bk~@fMg!}fT6+dpJwt?7jJw{|~ zL3?ed`2?dxmaRW?l3brOjzAV8{pZ#M?elI>FDwd(n9UTu?ibE^AdUum#0(}_W+vJ7 zNY;m&+>e-R9Z#qOH2%Yc2nP&q?*a1T_QTe?yCaw1;Y$~G_D81S#vWjQr?JNwTULKw z@VxG#$VFkm@x`vk`vdLp`_(&ZhN-5U(pg-%M_~Ds^^48Eo5ZqwD`-$<#nbiYj)8js z$iUjWfyq>-ZvLE0UP5I)P6W%yY&I~=H=%(&8C=d2ozS~txg>dr*?at^+x=#@ zD!YmGM_u3b9~axH{3FM~@fTyiC+Ymi7k?~P>qp@;zvnx7SI+!@Itjrg(J1Ard2@j* zYxCGZ0(ja^*JbXjSD+=7e=Ft>V2wQn*}lIxw%7yQ&d;T8!G~w9XAa#xc;PpB{c*AR zv!m$j&@!Hxcjct7IRSL?_HbxTuS`F#M;@Z1ak?~=&ASaw>rmW z(=3X?jtO{P=dm^K==4_#VY%#ua! z#iRN>Zz#^Y`;^6!Q05 zbHf+)6UBr&1I%!?1dLqu;P(yzoM;>Mn2AsEDuy!@(VtRc548=5xvkNSgf>uE-P%3W z1bIjW($Ai(-aeR0bEXiV*wE76!w1iHl~;M{+?<+BqAxHnf;0}PeMG|KccMVV?M zJT~i}C36`Zd*+E|MwC8!UeqJw?es8-Wz3Fn&fdKYyo96A<#;~)?JZ@4h1~Je$o@H` ztVWR|+qr;q8O8N?2q1Ev#WZ4zTK0&a&AGj0sxz+m%_BH(6=9kiG7W8oR7Yi^pKrsU zn5_@dS|u?o_;A+qc7s_IGs%+KpBsZX?#yuF3+qidMMEgrWI+(Fa&T=0S5(um2QezC zS(rIg9W^UPouS!Pd}?pPp}b8&ml0)fL{}f}3E_*fE*(iU#J{j`_0&g~!UtuW(-LvI z3Xa>Z4JbQn;!aUv5GX0{lX@3?1~A##J8)&oVEuT9bb8Jv$S!+wFp{m z;++S#L_e@EO6yV?j=>)pq->}l!dBrJ?n=b|R%eA*1Nd3-&ROn}dT<%~sGQ%ow3sC& z4m|>uD(?Sn79>dpBU?i`QNGIUdUC6#gZxoP)J|uzI)O5jEEj3&Z3}#F2HOC(t1f~T zqRBz0lGO~GMcYwlKT+pT7j)!~vr%LfK1|ETnbsq;WMYmCkA2hFHQ^F~^Z7 z%Z3?!ouwHe&5|TBpTY5pt6}K7e~#$ieoxR=(UGg?cZ@YekW(y?DU&TC2LSN-;PUte+@EN9_=5DgzrV!6yFGq~!V|@^=nTxBCrlA7U-Zhg9lIlcmZJ zyiVv{PWXCCF8-f6%$Rqzek7gwkq{diO5{JG#TuCBAMGQ8x7h= z>A1#*T4RTw@I`4Lo%F^%w;J$2q;@Fhx;TYeGZJ2ka5tGqg}j`miB=^mX##oY*!a&Y z=S>ujD0l^EI0cD+h_gIb-#oXO_3ioVp;qE>_$7XsXaCG$l`HgnQrM4t(FZ*1Jby1N z_9LGWd*gox2@8D!5K5WTpb;8(8*E?IQ6sQ&oRB-=ee%;ecCNWQMbzN$Ao<5X8u%~2 zkAbq&jCUEkX^!@Y)r|74^3G!}$MRv;`ME4KJ=297jMB0Ryzym3G&>roUF|EWCXY&Y z>y?R}ae`4?wp61mC8KgdQw!}drD^z7FLk0_@>s|RN_J01<{YfkhvVts^qc_FiP;4$ zC`gLJG<*|&h7X^p2Fe>xV?j1ym>uG#TLwe*i(5M%wx2I1w_9Ug_%i)vHX**)k)ID? z&O(&%_*h|6krs}-_<>W&PI@~FdLXB7F5gKfKwj#D*p90@P zq`muuY!*K?^){AH*L&BkXJb=ZH-NDzx|`(eA>OfbjxjWn(_ub6ds5o|Eb_8drul?x zF3nxYI|ok%>|x7ebW6o81dp}JO6OCCjpYywJ( zx*r(Nbf8R}+qN1dhQK!cgFwrfs0>71gb-!ErNRT^dKBMu)HSeSp%ZE#SlC#+89y^J1Sj8F4OAzYjY#}DVtNk7(q9ceYU$2saSS{z+LFjc}S6~bu z)Ir?K$C~S?T1*cZDo8C7-Q4(`aI>xWj&o^~i-nXhH}4AH1`)eCB~e_7xJ>dsda~G> z6MdNvp_9IA^@tXlxDA!WkI>e8*pqj>7|n4^TMqMS!)U=yqRm^2jTKF*c?NwYZs)V zu85=pJ0X?%VBwX*;NWfUi?p;@z5Y8}wXoENjnCrsuQ0@of5r+nR}svY)J4JuBi`$J_^nI3KE4Q5+x9*kzZuTwH3kR<7T(q5c$HL9gyI0><+;c7bTlnu> zmkEJKPR-7Z4m{_f;Bi-GqP@hu<622wE4!*LiYDhxpC{;oc5%zv!~AS za$mT>%gw{XCn$QEk6&1ThvygRUxdZPB|(xGFUwq!k+>o%At~_(kpoAM9zAjF1lNfZ zToQadd=mfeYwsg~^Vk9Up<9Oz2muaq9yr8#V6PG&xXgxb9?mI!2`$l ztBubA4jejo@bC$aqeo61*>AW%tb>0v;5^U$Yt&ILo~t)u2xLpE(0#k;HlVzs=hH|A zuP_Fil6Fi1taR(Pv56NsH%|m^`|SCr{LkM-N&7VU{_O4#T0gHpY3|o4aPCX(;Gv@j zISw5@^k;(u2hShkjO6+iW_;hXe>uS7^5(hv`)GGe#zb8#nMm;!S`oTj`p-P5 ze-UZD5@Vyd%FJ|*XxKBp+2Y$^HteNP$F++U$hOJm{Y4nila7Xc;^hggDa}~dl*tHV za;g?MtUtw_-uc@AVSlRZ2taxDZ(7s-Q)L$bgMVs`?{6x5ckfW}pIUSIo5r6$`OiVu z47)p3dV*;-V(sNOPMv{F-o0`YY$;^~mj)G^pFu!o40F!`y3*{Nok@`yVb`hTG-}c_ zC%ll~np2#{Kh;S7hjJXF;*GS)CXYK4b7g}uD}gT!yp9_neh_Kd`Z2Up2`VwD>W0*l zzfE!e^|R^iyUan{+ao&_Q>&WUkA~l&j?N#m&q%s<&n}IiBYdHnf*wQGah|K++D1l{WeC_^y)l+xa2qS1%q0AHC zkE#|OM=O1Z@o89dDRO#2qlf~#!f^c~uEstyonVH=uBMo$9<$YTmKe#XSbvt7n_4`UV z4X$5)B4-*dcsJTRzaT$7$*1qK?)r@}oU$h5GD89BZn^yp185(en;Cr=vwNp#JF3^) zY4Q3-z;?dx8aBC}aQQ>eWJ(sx+@0Gi3Z$e$lT7BnMC%vP!jOc<O*Wnu2%G6oY1$La0U*NF8TU-+xMi}_A$IFWVktjS1q3)^Zn zzs3R;T)dEig>gVY-I1!^Q#M&E;k1%&SugG;zv^x@)jpKA(%jNm8=6$rJq=&xD~w(+!DN1kJ`=s?u+P!SAK!^+~z0V^;EWp*q?jd5sLdhE9>5 z4>N^vN>6X#lczX?@IfN>(R+Y9VJlIKhd?<~@Syne^XJj!WP?rj?K?O6vo>#+rEQ=4 zjhHueW;5#hE$$wc_%*`E6$S zcj>n#INdm@ZsXU*?4A{i^M&B&I&BlyfwJzeS?y=82=0_0Hr=>tS7PIdl`*!8lNx&3 zu_30ND(Z!%t>su?$EOso@*eHN*ZY*T1jL$I02%YHt6tFycy28h8!{ynFZR4=?nCWp z!x?>k_i{SqCZORu0*zmAZ|{G&z}UO6Z#g)1TI)O}ig|G27hh1F>_Cs!bt z6Q*}Je;z{l}Yw-f%hDqyGsj)ilvh?!p`;&a=?i_ zzWh2u1rAs*;%m!N>0YM%gaMhqlrrLwWv*AnVZ~uAq!vnh(V{6jZkZ6m^81+f=kk3Z zXw0d|!a0K`MYZ7uMy9nd$?A6Vci@s=X?&G9xKq&V!Gd=n?zYw`a(ia6&x_sZ>PZA; zuFXz#-37o)fv?6J9O9%<1LWMFY0R4yBvcD4?Y&StCr>YX|~At*$7;;Dn?SrThE-ykn)PT z2ld+M6zL`CthGFs&b_bZws6jt(8KRRe0(o#bOWR?9FsAIw4L3Un>_T}QM-`Gs+CHa zY=_f=Wwg1|Y8Pb-ZyJd(RFxSbE_qtrlXPD>nUQ!QkyavO4RHZ zS2#w_4`0Z5ATiT1Fx{R?7>+iUzDp~S5uaVbbkT4b8AmUjrVP3CeeFbi?QsW2D`M26 zkT><$D;qC)ql7@>*6d%R&JNh-i+1Q4d?GNlX(p<1QzuCDJH@^ZOc*>l;nYVTQ~x8a z?L(F2!+N78dWbyLq&V+K2m|9al2pDhI-S(lrVJuEvN)~ZLtJ@v&0W=mhIRdl_njcI z|Kz~f8@-!eBlXY-9an^P{>&l#kwFp0rEC;ziK7>lij9MdrHj3meb}T!Hv_}dHEa`n z{1cem?;-Bl0jn_SmBoUiQj~DTQYA4nR#{j9r5WNEeFD(s&Qp1YsXEy!*y5J$#K&}o zigUl-?MO0nm}wSX6cZ?|adaEdQ?DwB4e05FtN&`n`qLRcjRpWtt`huT01G09;JRxt z6QL|FSCewlI$u_-lYE##($FLCTNcjt$*9ma-RwHf*IJE8q|f80Hvk-Z`A9E>vYY)a^bCT}~NT?q= zbkF6I1hd^pR$7;@M;Dq&n=J#vXU&b-b(H?mum%Bc$E2nweY2)p4Uw z&Cff|eJIqs#H@nI;$BWbU zjnu8j;m;ZT$9K7U(hx@yaYja}b@1-Gj=&a>HfkBeE9=npVSD4i4c^%T{}=NNXE#JH zqA47eX-23{SEbP_jk4YWvVAun?Mm!VR{NjO1MVAtqkMYnRois1`9hWcp`f9a&E$@f z#k;EX(WpT%5kZo7aJ3BHLhh?VMmThPCHxu#HaA@;1lXW3sHWTw_%A zk(<5D(El2{!a_7LYgl@4{V;whb^^+lRzB-GNI)0RArX1Cgn zS2=ym?Q_Q>ilycZsuvGg(x&)wKaXO28G=NSIB{i_bZq6~P`tZn_8XwFjmta=joz~O zC2~nxio0H@UPy&242e!v^z8&2+F#c?u&{cq{N&x?Eg6|-#n)yr1!Ir0{3BsmG-`Ux z>rfvoL(w#;P$JKk-!kg!Kok(x(rZ_7hN;mek^?pNX=4%jE;^8M>LzE`aH zYd)*zq?aga6>)*?6xxwp;?p4Z^*{XV_7OB#E zjc)328@RCT?BWk`PKGw%B3hg0uH88L(5V=9`xB3FfgYUSWm*=2uR6Fr!N`t+!rSB0 z2Oh=p&&iEeHwM(rRie7SG4vqP|< z3QonhGdW@L$-Yg_UnvlKN6W`xFQnmnl!}SeP_hiy9$;z$iCzUVl0dj2gVTghCo|s9 z3GKSeIvFl(;Js<9UII@5P@|QQa;WBcdEMYN$R_m1(-_nWwcKDZ^f=h2m9nE8B=U=U zN8qo6#zDut0xo1zq}|*zE8#V#b3^ORK$@HEaNt}x7uj;u1+z+RGWoONt)m6-k&-jA z`PP!M(TEP!YEDV)vTl7nQEM564O{E1Gi!&(33Iu zYB{#8`6;y@TdW87q*k_~`kZ^_coDZNwFaSFA}y9l{g>RI*Wb7_6S62HS`v$T%WzX? z7k1kb*w9mNyxy0JyJq=!jT*|>x_H4m8A^NxHP>vDFAV91Ik+NL3e`w93%VH@JW-N{UH*&#P#(U(=8s29KC zt9)B>q#&8oxb1GsP_5*p7}tP&s^+=1Vii6%#2r0`E>$Yjh*k-@C?x~*<`FYTj}RV6 z3JMy4!LBi0?e*0v=3Qx#iZMW5ut7%LD9*R`Z*B_!@OgWi+c>vxTODV*8GpDw{!+Ys zYVdaLj+OK3X3OLEN1ehJAyRWKL$lH~ZKl6k4otY>8GC@*K}Z zf~cckkvlz}+Sc$i+;?O3I?uNDnHPfm3fWMxL`$2hLU9n2sE<-;sZ)u{lmi0%*F5T3Qyl)u5DgcUhkKn{Fb*~r%B6!{7GryG~nVG&tp zvOah6>DG=E*~oG8p1Q?)K-S30LX$QVcI9n~@?KpPq)`^1&!4j`R)Yvelx12|h$x05 z6m(fgJzNXnryikAo2{2kop^t=^&0l#{jrn^@4Kk3$$m%k-!ja*r+cN{&8+9H4Ta9x z*REh(tx8Y6Up{kwQ5vPk!}YEJ1!`&QO^7nCq;)_*&BD1R69hk1!9ac^b%0+?1idr# zyEY%w;1Sb&{s)HcD}4W{@X{~gbWkkM&6_&5WYc+{4g07!1TDNy zscA!u$Ovo_$66iNdqpq8P}YCDs<5zD9|)$msUPmxh?!EeM`pBWGx_m_lJQecgsQ2o z#}^Jw`ssf0m-h$^EVc!i`#YQwv{r53xLn;XTr@seps1gK2c;sh-KoUoUvJU(0QR(R z1KO5ygbi`MlM>W15)tiJqaMDBG&2^DjbmNYu3 zjvXF>Ahpvol|eh?{aBsqHZLyaT{@vYIMn6JocXSg?4uhC8zB@fC z5^1jCZ2)i6Ht$?5iG!7;zS^Hkh>|^kMB{4uw-@qbgB#ipvo#M(KF!|)3`>?9x7|Kv z4C@@0a+7Jzj`rC=U+BTTqC*9IH}%$?*5Vfa+?4_RvvrO=cH!w`I1uUG1`kp`z_UCo zt>8k;oOB2q*??@ZwQomHk^&aYJ0on|W0X`a6jxWzGL1`HZ|mk*%S2#knUSh%IRmBl{3|l|=jOez zxlT^w8n?91jrIkvYIl`VYy`5k|4_{vq`Nz^JGD^y_Z>|AS&c?0hMdXx#CorqG46iSM#hfizIV?) zuDbTD-sXuc-`LV13jH=c&*b*DswxiiUp!WbI^pavR*9Zfp(cfSSz9HM

C}YU zjCO;By5zy+!+?X#iK)RKqY!9W9~-BW~jF6ZpjRu-}fHLvm2k&79UXv-PRbgEw^k4)Oh2aYN*vsfj2VT}%-% z^u`2q8TU7C3tEKnbb< zfeGjY(;+hutzV^#I~P4g;M(}=!T3T*<7R9|tPOcKZ=tRB@RK)xhrpZG^%^_ZpWHdN z`X}`KpRq{;x^&JCuB?L5QkXY#jpa*cU|q<5q|H3z%2;k~knv}R3S87bIc?O)q*80^ z^|vFVTNa0+#)~g3*-$gWwqW}5W1^Uf%Rp&oX|wT=OguACm*f3EwE_HVV+^5Xgv8Mz zXI4rHft$W(N9YE&!Jj`e%2O7Ch=tQ#p>NOi$MB57@Dow_L31w@HiH2@K0RoZxO`>k z8i^+PL$al#_=xmFTfGx>KM>2l^g$^{_@Acr%lU)qe}_7!{H3>6mJa+P{C8-7G5N## z{<)d}b2Pu4H6$>?ZH!YndDl`veW|ui28P*DDXp4Da^_;tE&Waq>&pa)MjNM<{u2Cm zXC&9wyFzk}IlrinactL~Qi12l#P5fU4jJ7g&%x)pn!qQl*&0LFzd8QDQ*v+zQm!oy zHIn12rnp1g!y;9edh_Na{_@`cabVv;n>4kLyRbtN@5FPh{rco#pGGo#voi?9;qh-! z=aEqA_{bi|w%`&Ul<@BR^@qK?$p)JpyAt>Q4Xl4}mGb;$BkGPzIq=F~k%JpuA20a+ z$h>IonvHY;rEA6P0lGrfB?Z^63Y6cUf7?^LMUeT}l|1@ISF9=s$G*_EX6E4^Gut^5QKi-mz?|U-?kb& zyS|rF1|Lx>kW(jl{0)XXV`K&mrm0et7NkijEqo3>`7Gph_ zqWP&7gjaK0P+(B3GOXmmko>w^!Piy|VvF^RKP(>!T;Xg6OTn;O;q&?}oIWI3UoWo% z10DC(3>+^pdO)-6d|toTP%DGGy?*je3b!Fv{9HQ9V180~W4CzP7!p#a=uvaD$geZ( zy@UVcj3S7Rhw0sf+vu5xtX03UOPGu&g%-L16~-;w9E0vV4ym0tC$e#9^Uz)^(JCfT zaSpFV(4MTHl3TIvk1$MzZ9O`^-XW7M@s4@-wrf@=^?q8at80XQ46oBlB+O@mxa`(- zB$4MBqmOQRnJhf-39~h)rpDlPYwEb&GE93(qqbrMoFgrRnyhm()BW4v+0OeHXCxe1 zeRLSac%v0Z;qc}k!A6D$DnyF-Bl&Q2^vbM$girV9(#`Hlv=_ldM&|ak1lw)a%D|dc z`hH@WZ*0=AG!8iR*s#3qF67WfcW-^p`qN$g)4`g!%*~ zMbuXzJE0tHqxtks5tgx1a)jxR%2z1lNG<~5o@_or&~}&jwppd~gj{NB&$2YRAUWn8 z0K8&gm=pBoLfx-uk>4NCXhJ1=X!{RaDh1zTg4|LhR@`RpMhA`ps(N3;)=)8{A8w)bqWnxBASMpv~YHbSs3~6B4(345qNCJwU%i!o?K3QcG84aX*Q!YaR}?WyQHcCLoZm z@&|&lV(-o0GoR+8j>;Hw3~jLx^m+`B+&m$$bwQ55^kQ=J=1O&R-;ata%p3P2%?d%7!-lB zrzW-6$2&I)x=ZY0`b&|R^gY0wkx@n4MFaSyxWH|d&Y5%1O$*n7<-V{*ZN|fSsi39Q z;pk5T^O0$f9S1hQjQ=bPw;k*=*%{NRl6?B;PV04^^$rv`EZEaxJ?1jE3(xLw;Q~lQ zQvYPJcI3ChvRqb{#TIVxL&lHPpTu?VS+y#@;V4~=Y5Ylvud2K#d+W;^9Q@!P-N`Iu z(SK5s=#bf|dN_axFn-JH6)ybgVW0!{C#8R3^J7Vx^QDviGg8E#l>TCg!qG2$=exzA zndMJPu%9fEugFgE={)l)(a&Y4w;=$-SU!ZOmzrRwmv8*Kt_#L zhXY)Xc(=c19OxK+GXWmlwjZ2<<5l}$+vEG8x!3VKXut28pXrP1n4Im@^(}>y1mXh_ zZN&v-VPIIDIqElu)S5(lvHZ?a+^QV##cfb^R;cus9M`F8up*MTr7N@jQ3VB^*pg(U z?Lre$Zh|fb(g$xM#+XgT$42d@Ms1p|dck1uY+9oF$@de6xfTXifpe>cevWOeDzqu2 zn7e^?o@3u;%NhN_N_Y$$p$(HBGMcKt-gC|GX{_1@ZhUEjJ<*KyVJZq4ykc~Ouf)hm z;A^Y1ytc?|tw^FFdJh2QPxAGi?b3NEb-&PhYMO?uI&$N)TM-w9(jx0K8M>B~g5MP`%A1c{H>%u!=^czo~T54@= zmd;z9)s(4N2U7{Bt@tL1ou%_J;o*D>#A0-@ikx;oWrswI$T@9fAl-Va$B!cd#Uz@8 zm=dGit?_Wp{Fk&j*UW-|-={-K>9}inRdSfR@>T21cx)rra#(D;cfu(F5_a|Vj-8Q_ zkI&n<28X$YZF$=Yl(WsPZxdDGJgJxZA6$Un7;~avp+( z+pf_2!l=%IXi@Qea6R4{0*KhK2W+K~|S z>_#0?PPvO>J2XQ?PR|(jYe+@3j+mvSG?LSkBFr`$dzcc;-yd)I`L1}KnMfKZ~6;xf-yIN!)3~cHqnf;3Xm{% zl>waJOeCZ8>f`E6OB_omH4;mPVsLwYfg8Q>P#9(*b5>88$0g>Kr8(-DR!I|Jg;*iWF_DDxG=Mt9UDHJdE9mFvDa#U$+d@P&(qRVwby^6Ns|5D z7Rw%dvz1;ddmLG;8#k-JY?v69-w=Ps>b?tbrNnZrIvaX{ZkM$k)j$n_RA7 zBgRyM7CTd~T1#s=U22HX9pHrV#89Um(6Sau;9hlJSwdA$Jg@Ucg(?7IUMUYFJ)g?`wMbN2%(g_ju zPCc*GuGrEriQU!yyGe~!q0tkcend1vu!Zdg4&F|ePen59GPFlm{Ub9%M!Uj@=_*zp zrTw`oZzy&^mLok$Q485DHcqeCvz?vL^eV!Yxsc2B$lhA*UlBS|M0%sVOC%CAQyV9h zy}APA_KuNn3$8As;?v9@tYCydASa@1C1SIkb+7Z{PVj@}*zZoEM&qt)rm}Bn=@d8N z9~}ckNZ|N2#)|=S~TesU;R0`RDuw4wdrC9C(TDKb4ZGXrYHS>$O z!5wt&W)_Tg3iIuVP9j}6gP8Cw7*1xf6R8oQ0yYsjX~ah{%XEU;B%Achu})X>R#a~l z?fM(OZ~T$Bvc0{5Tm0fGZrMx!7mfdn>Rw zxeNrt8~rfIdg)jvjf!-A9ru?Ee9hgQ2;JIotWZh>(1mYK&H$!>EzY$r%Zn+nOng{Y z;bG_XgH_ZJy9rHd-->wr_Az&ZgUZ5SnYyMUHS>H%!Vtz!k1GxdlyQTje?_zK`W

    =jq%F#<->#1|Bj2MHTK#0{%*SJ+I4$iTw}+3>}s*~Dj^ z^RC}jP=}GtBSwhEL{TxCMiq}tpeMmTrLDCL<*>LnD@)A~BoJd6 z=_A?E?3wPhtp1%{$AP>pg1_K4_hPa#2tQTIr7YJ@T}>{MMXc26cT~tPBC|8Lt4i;q zm2b|~JF;z{O4RAy&ZC-U9Rfc4&lRZ{LIZ^$lQ zJvqG!oP7OBQKfPaB?`N?F^81#F2fWwGCW!*5D$aFd}Dx0AiuA(sYRLeLWsA_t(#_t zujZOb{AhQ1+p#^aqC|O6&d?XIfM=P&!PnUKSCmAsQ@saeb!o-YTKe(CmAR|o&tDjD zDK_i|Id)tU#hM_md^{T2_rLH*`amHEEveve)-#>k(DT8S%z>y>#BQ^7prDl)M33aP zVD6(53EGswjAtY9BwMw?E>lIAkt9AyHs3;fE;mj!8#d<3LpHvIPngig_oHqax_-Nt z1Htf1C1vxb@f0yLK-=ifM6v9p**(C4x~*m}OZD#Eqi!()d8x{6Rc}vg7!CN7hUS~U z3nYJ7hg9?@e^Wv(HN99_+z-V^ttU+u`R8pP6<<(q@mP2Iae5yuCGfgg#+ViYf`D|D z<^6D83R>>xJ?j(v`uUrk3v+lZjUpEU2U;0PA{0BKWkp5FrhknZ7$d@v+um6KV z9mvfgc*&)QUEvG(DMS@b-}$gtC7K`qC&v44^wz;LAH^bJwJcKlO}nuZ1D&waN1-l1 zdHPE)JXaQlTSdia;xi}8B}~?e!)HF|d;ylyQ~egscm69m%e?&{-d7xf`=4maWBWZB zGp!2RPO<2jR;Djr{yTL&%YQXcv#`&B^%;|yOD`U}WDJy4;+)44VNL`nP)Vrt3oCGJ z_otfwGBmN*W~-sHB#rm~$QTsA{hw3QfA#k5f0M!gKPySwg|U}= zfahs@fRSovGM;|faDsnsrH(+R=zDVfd)n5n|Ev`f7QBi@MqPZ_v6ma# zMWuTsF0O}w4Qn_#(! za$(c;qTqn^hqTeCATNK-r0yZGKzG{V{2?8v;6xs%itR|qb`@$&n`soVrTEl zMU8j$2@lqfqnumVOA4?RTJ!`^LKse~j*)TY#X&!9EvM~Z` zgyjCcnLj2cLOauvZRmxtcF_DPJn?1-W>3cHsZU?%`9h6ZSq6zOhJ@hQHs)^no4M0q z1K%d&)d2BTK8B|dZlv@1#L}GZgdaL8qJphTsP(&=%_KOv^%wSUCYso|(k*MmbacpF{U#v(_eBQXByG}d2zCII?W!SeU%zk%9+mcKpK@PDg7gWw3Z%!X)9n6Lz6`)=5{#6;+TF$k%S zs~7K%qU~`ZqlQ^6``beYtv~0M#rAQ&v7pAYY3Ly^LftWpeya;Gdi*{A>2 zdGFP?^b=v0?b(z_fh_}dmH=HpvZXcx6{r`PQ9m7(-0~_!x~*GE_?hp$#N5x_!^ERf zal(QPqm7(?8*T4ae1`bFVrhEl`~ELe6|btSn-~ent4p*r1+|;l<1+I!o;P3RV8?3r zv|j7KlnxP;%8ykSMYFI*s5B!S<5Xe%v-*?MLKIWmuu!isf@^p-vOXS7aR?33r=a4W z&N$#+tgt&aY^-VdUp?v2OO+T>xr{(0Cm$^{S=o&5-j{B2nqHtoS=otDt0N2}siLB! zjwzK(bTmi^4D23ba$+>S-eyM^o>Djdf{ZNa(J`*)PmJa3lqQ;iuzvEOK*wsnN}f$L zO$tH)MnpJ|5-56!w-jEthPI?V7^fJlSdKz$ra(@39-%np+;1OaVvO%jqok1f$Tu;O z4RzM9A>l;#*2WNO9(zkE67pO;(vM5aSk%^Nw-qu>LlZI6wg&3`>;JT?K9FtcOv62us z3Q^*sJ!=*WSk31w({*!;ZjNk>S#)ZOD}WMopA7XRy|%iQsq+k7EB;?rndY`@g-3grfPDm z$@9@&h1Uo zCllR@MD3D^wn#RPW1_T6@C06jGIt|8-I1)p3n-ZM5%BoqD!P%YqWEyoNu`c5ckZ; zb^hD)(FmwVX1@F*8Ow7IQe&DR?k^v(b);ZlGQt|1J3M5(Q_aWQho!Fy5Ppm#vBFSd zUJP|kGvPgeas#W-)^Pz^q7>DCO)nRTux1?QA+Fi>RxvxKUj)pV-(fGN8S7VSwY8d% zM%k8;NFVy=mm)(v_yw~Fr-+x2+s?Hb!z&~F2N*AVzq|a(Ll67Rq9QYg za60i={P!tt1| zjiZ#J(Lqjr6%4v0!PRezL&uSxWM z1w1IPvl~6XAH8K;IQbWa@`8subrr3|Q!QU(gqWyAm{LsQCo8ShJWtfjX;FdIrLVm< zD44MK1Oo;X-X8E3Vr8S$Ac_T!Uc5mUoG&Bo@sVA`;U2Y0UT6@C#35#M9Wf1x?0_}~Bjdl1-4+GL8@arCwr$C{Xq&rq^wk|nSzgylmH#l>fX>s#m>lR zl(eE;zBhO)BnBr1r~k54Nn)VPOFyV$>e8o5w5kG0kF=Oq6sCFIYYd6Xa`iuR` zRA_C4HmQ1D6O35lpTaJ`rYciy17tVVD(kcv@;HlxcJ5g$+mdY;sVh9uQYls$*Myeh`u4LIE1RVbhuh(| zMW!t41b$~kj-`|1VYSqFp9lMiG9?k{*E zh&m-wJkWHQ=$!h@vESvv<^5AM`Z3<-aCH$Ax|DW*@-?e&2IptCy_vY z$C58$SppN8Npxg4Ly0!Ke*||}0sHOH=|8qB8qvEaf*ZFMeo%tntt(V$K1*H>+S-*& zo>XrbL1ixO0WR+WgmRiw!-w{rsLjjomB@lZM$DP4mp~LlfGF#u$1ue0c;o7wGl~$m z;nzJ#pelp&b;8S*k$mkF6IZY4R)DYNohBFKC?Mxvn7|y~Br|?e*4O@}=)@^Iy|v3l zz3zouuFh)wRT}ujMf!skq)VrsI#3H?S-kt%-4^FDO-UFR4%+P{SbPpoEU0H9k*7QG z7MAa;kWfV#C^46=Z<(K47xZBda6i?*#-~KxVVX$etARR`9V}<~`7*}UFx;a6cBXf^h5U4J6};(p(!oIHGjRfZ2-GWTpsFLNhta~O_BJL3OvaxI0xo*@dZz-G&VGdSsCp(DW>hfEY2!)Y;sB?L!N~C;>;s?^K5s-5_}r@nyu804kn>`WzkE zvg@a;;F7MqC-DybVNkDh3aJ6=CI5oUM_u4K3e7!T@JwX4v4;j|o7wJW&? z*q?ddn}^J{2N}V*;7tyV%vF>cJX6FWtVJq zL3L&QT=kZEX`X>FUPC5-v6K_WiRqbet5;7?ObUPU_$Il6`+{GR-^B^<+*O&D=^BzV z^Sitv+NmubyLE>;RdhLrs(bWP==%@9qnh%)@|5ThSGEMpQ)YX>&uo7~se^Xwd13L8 zL)pAHknStnp{kpiIsWqHOH#^QlCN!KOR-`duH8y(6i3&xY*A?RLA|&0^LNNQ(psmZ z7{Rda_m14p;OMfw^xh4Sw|kaX6H5(cKewA)=Ljf*p^*I<4%s=BXGC(it)>-TTiy$S zL<>!pC{94E59^K==!?Mh2*pi;GIg)LfWCM(l2G;Mr5gT?=r z|CvaU)%)CGwSF3bu#_DcEt90(0lnl7(R#>}5f+bBqFd)JKOB;6lyP{u6Uam%Y+blr z1m!=eSs1{g-{8TKK*e~{#2-fiMiZ*NHIFUk@qNqOZa1zi0GWQva3l&fj1o|+#_4W3 z`PBnP&-xVHOFbAa?=1&`U;3q6tJmAq_s_g_4P<0vQmybb@mrGJ_0LIB=k9Mg*c>@; zCg_pvsvl@I>}6jYLStm+TV^-gP6>f1IvmeDW%7=FkAeo0C|OCJQ0WNVMe6|-({UAQ zS_V;N(~9HF*{g?5QT%2LG3PW$po^_eT2)%uNKPN248has&%&5Z{pgIBbM_9%j+j+1 zMR~)Oq?D}IR^{`T0F%Ry9 zbc_+Au=P+NjK*?RnC<(uwRiE%k)pDfkMhpmEykM&x2eQffyM{YwuiB+eAlqQxoYaE zKbw2Zv>Y!tn`>fL<}Wkymvr8(U7d#*h+xfE^&|ht$YCX5vCnEWfwPYTKxTmp2cr8w^J#Jxq9~Rm?F59Izb~?b>=SFAmo+BOF2Z*e7%)j zMw-iHN+}VmN`EaO+JHj&0CCZkxnlu%9 z?dJRYeV#U_3oMxOH=(!nPP^etbF>$)q*@({oMbdKbjpajKghN$kktvdb7{B`#$)Ba z5`DGzTUKIgF7bM9IPbKU{wB&vHRHl>-hJ(Rfc-7_?C>qsd2}#)53uI(^he63o8}Dv zkEq}8?kFX%hHpdbMO1^%c&v(vRZ<`3Bt0I{^>uVbY+m=i{k94NxkPAGcF5E0Nhgzw zTWaUUN0l&6qjOlj*OZNi8fsH4hh*T6^-F@eMr_uy;Tcb$?1joukL+}!X~*&VuF=y2 zs)@~Lrsx|eu-L8HG5Gxov#3W!uqL3WNq;+$I=SdIC^JzLc=G!4aCuf+OTA9Z>N(%^ zV_iP6r)(jGEeHc?m&0&X)!!Zp8cr|;7*G)Jeh{|h(>Dk;8M=9Ru{wJ3))ZRt@${>!A#8$yAkn?v z-G-@i^attsRZMngMn^H*GY$W&I8Nj%b~s2c-U>fDYQltJCRd+kA{rFJoSh$hFU3)s zL&;eYNl6i^vF$ezHRExa$;=4!SR0Zja0g-pIOhe+{|*J`K?r zYQ6EeLx^!PjYV@J(nw;J%_q-}Y+9Hrye1J11YiciE0&=fMfuBbR$`5k&j>UAk4u1}G1<*C!|<9+B}vBsWO2>|2k{BabY0L{B5YYcySSW+0?FoEA6hdiRqu zP^c6ZhMy>O^ykXCKUoxe?tUMq&Wl;M)FfS#UbvUNm<^klO@QqUBDFdlPA;I2ZeR{|!qHL^WIQr}5BF$S*l2uBgm2 z49g7*x2Np0I(?iGCR31jd2Lp02HUStPv+IgQ+-XxGP|mjs^9O-*mK7Kfv0qem6gM6 zSw1AvZ2j9QkK|KVEv~Q$&q_T{isozmFykl~%53XUhFUf$i?pICz91$Rp*4O@ABZ!% zU*1PYdO%e>V8}Kp)47bPRIFE?B^w6pUVS?F&G2OQd{x(%=Ull^NjFKbsF;z7C!6oQ z9)F&Go*{_0M9$pNMzEc?6EV3AaK4uecwe8?VS1MFBE7t~eVYbGP@`f;6vA zKWBVxy^L#njCA-!}O#9rzskRu-|`Y1!(X@iYe;1I(3z>$GUq6|2hjl;LL^l@c5CUaA?$Y|eSL zFXT68vY_Uhe&~YY6J7nO8*#&t0`2vp21;V+u-IFYABR7{-OBIH$dsuCtUTg(gXrdk z`FjV6Ia|r%lx0M)$lA~r{DJCoojc;Y)xqTBAuhZ7Ie$CN)@R320N|fN-T(Ice9g92 zxzn)Lof;vC5NOUaS6KRqViq@Hv-jEUN388Q-E5?JxK*2d>2XqjiD7)yTZOHST_fet zgucvbO6V8c;0JMgfDDgs^C~LOHOrGnmmfzM-fLc%*tk9*tfX0-`rH0#U~7SEYX4ID zlSD|v?sNp#F7xp}MpoFOT{GHb4^=!b8XZ5iyBi$UIE+D=N;=cIDsH0at&DCRSe0~u zt@k9o{o;84h4x`XSn>kb<@FQ4v6}1Nwgo>mV^Z-_Qz?Esv@9e%5#gj#F}iKDGRs|Np)YZN`=`6l=* z4?x@f(;9Gkv$Qsn>JPd{^s?;n1P{CxZ) zB<^MEr1Pn5Zu?e=*1DYN{u2cp4;R0-J6vzguJg9@+jz=t{CdBCUmP=2Ytt+-{TnNe zgjfIvepkIxS+Q!G=kkfCo}W~ndah`_)vEPYvzGNNx2)PH{Hrt~Vq$FZ%Y%Z8wO%ex z@m*U4obb6~+^ICnWAmfClk}~M7yWI!ADJQWdUCbxp&Z(k;C+_@b*mNc9-x2MpLcx2L=b5iJ zj_Lb7Wv8-<>~x^Bzb=oQ=PT;6al7lfFI96op8Q=9!D98~-uaUIjO%>geE0pJ<~=LH z8N!r;h)*0SfwHY}PqKqegZ3t0{K^-$E~BH@_4P?X`!DjL#<$jnD=B?m9MyaNoq`r} V5i!ah4S~@R7!3hzAz=UiCIF!hxzzvw literal 0 HcmV?d00001 diff --git a/ui/tests/scans/scans-page.ts b/ui/tests/scans/scans-page.ts index 667aaaed85..e75c2d3508 100644 --- a/ui/tests/scans/scans-page.ts +++ b/ui/tests/scans/scans-page.ts @@ -27,10 +27,10 @@ export class ScansPage extends BasePage { // The sidebar exposes its own icon-button labeled "Launch Scan" // (aria-label, wrapped in a Tooltip), so scoping by accessible name // alone hits a strict-mode duplicate. Scope to the page-shell's - // filters-and-actions group, which only contains the visible-text + // tabs-and-actions group, which only contains the visible-text // Launch Scan button. this.launchScanButton = page - .getByRole("group", { name: /scan filters and actions/i }) + .getByRole("group", { name: /scan tabs/i }) .getByRole("button", { name: /^Launch Scan$/i }); this.launchScanDialog = page.getByRole("dialog"); // The modal renders the providers picker as the shared MultiSelect-based diff --git a/ui/tests/scans/scans.md b/ui/tests/scans/scans.md index 5baef3a42d..c2dae769ce 100644 --- a/ui/tests/scans/scans.md +++ b/ui/tests/scans/scans.md @@ -27,7 +27,7 @@ ### Flow Steps 1. Navigate to Scans page -2. Click "Launch Scan" to open the launch scan modal +2. Click "Launch Scan" beside the scan tabs to open the launch scan modal 3. Open the Cloud Account selector and choose the entry whose text contains E2E_AWS_PROVIDER_ACCOUNT_ID 4. Optionally fill Scan Note 5. Click "Launch Scan" in the modal @@ -46,6 +46,7 @@ - Scans page loads correctly - Launch Scan modal opens correctly +- The page-level "Launch Scan" button is located in the "Scan tabs" group, distinct from the sidebar action - Cloud Account select is available and lists the configured provider UID - "Launch Scan" button is rendered and enabled when form is valid - Success toast message: "The scan was launched successfully." From 865eebe7fbd0de32d91856b897588e0c74439ff4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pedro=20Mart=C3=ADn?= Date: Thu, 10 Sep 2026 07:21:27 +0100 Subject: [PATCH 11/16] fix(aws): configurable boto3 timeouts, 10s connect default (#12774) --- .../basic-usage/prowler-cli.mdx | 14 +++ .../providers/aws/boto3-configuration.mdx | 29 +++++- ...s-boto3-connect-timeout-default.changed.md | 1 + .../changelog.d/aws-boto3-timeouts.added.md | 1 + .../aws-retries-max-attempts-zero.fixed.md | 1 + prowler/providers/aws/aws_provider.py | 39 +++++--- prowler/providers/aws/config.py | 27 +++++- .../providers/aws/exceptions/exceptions.py | 13 +++ .../providers/aws/lib/arguments/arguments.py | 23 ++++- .../aws/lib/session/aws_set_up_session.py | 8 +- prowler/providers/common/provider.py | 2 + tests/lib/cli/parser_test.py | 29 ++++++ tests/providers/aws/aws_provider_test.py | 88 +++++++++++++++++++ 13 files changed, 258 insertions(+), 17 deletions(-) create mode 100644 prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md create mode 100644 prowler/changelog.d/aws-boto3-timeouts.added.md create mode 100644 prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md diff --git a/docs/getting-started/basic-usage/prowler-cli.mdx b/docs/getting-started/basic-usage/prowler-cli.mdx index ebf3c6515e..d64bef0b77 100644 --- a/docs/getting-started/basic-usage/prowler-cli.mdx +++ b/docs/getting-started/basic-usage/prowler-cli.mdx @@ -2,6 +2,8 @@ title: 'Basic Usage' --- +import { VersionBadge } from "/snippets/version-badge.mdx" + ## Running Prowler Running Prowler requires specifying the provider (e.g. `aws`, `gcp`, `azure`, `kubernetes`, `m365`, `github`, `iac` or `mongodbatlas`): @@ -91,6 +93,18 @@ By default, `prowler` will scan all AWS regions. See more details about AWS Authentication in the [Authentication Section](/user-guide/providers/aws/authentication) section. +- **AWS Retrier and Timeout Configuration** + + + + Tune the Boto3 standard retrier and the endpoint timeouts when AWS throttles the scan or when some endpoints are unreachable from the network Prowler runs in: + + ```console + prowler aws --aws-retries-max-attempts 5 --aws-connect-timeout 5 --aws-read-timeout 30 + ``` + + See the [Boto3 configuration](/user-guide/providers/aws/boto3-configuration) page for defaults and environment variables. + ## Azure Azure requires specifying the auth method: diff --git a/docs/user-guide/providers/aws/boto3-configuration.mdx b/docs/user-guide/providers/aws/boto3-configuration.mdx index 83d01d5e80..d4e348b2b7 100644 --- a/docs/user-guide/providers/aws/boto3-configuration.mdx +++ b/docs/user-guide/providers/aws/boto3-configuration.mdx @@ -1,14 +1,39 @@ --- -title: "Boto3 Retrier Configuration in Prowler" +title: "Boto3 Retrier and Timeout Configuration in Prowler" --- +import { VersionBadge } from "/snippets/version-badge.mdx" + Prowler's AWS Provider leverages Boto3's [Standard](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/retries.html) retry mode to automatically retry client calls to AWS services when encountering errors or exceptions. +## Timeout Configuration + + + +Every AWS API call is bounded by two timeouts: + +- Connect timeout: seconds to wait to establish a connection (TCP, proxy tunnel and TLS handshake) to the AWS endpoint. Prowler's default is 10 seconds, configurable via `--aws-connect-timeout 5`. +- Read timeout: seconds to wait for a response once connected. Prowler's default is 60 seconds, configurable via `--aws-read-timeout 30`. + +Both timeouts can also be set through environment variables, which is the way to tune them in Prowler Cloud and other deployments without a CLI: + +```console +export PROWLER_AWS_BOTO3_CONNECT_TIMEOUT=5 +export PROWLER_AWS_BOTO3_READ_TIMEOUT=30 +``` + +CLI flags take precedence over the environment variables. Prowler sets both timeouts explicitly, so `AWS_DEFAULTS_MODE` and a `connect_timeout` in `~/.aws/config` are ignored; use the flag or the environment variable instead. + + +Boto3 defaults both timeouts to 60 seconds. In networks with restricted egress (for example VPC endpoints for a subset of services, GovCloud or private deployments), every AWS service without a reachable endpoint used to cost up to 4 attempts × 60 seconds (the first call plus the 3 retries) for each region. Prowler lowers the connect timeout to 10 seconds so unreachable endpoints fail fast; lower it further together with `--aws-retries-max-attempts 0`, which disables retries and leaves a single attempt per call, if a scan still spends most of its time waiting on unreachable services. + + + ## Retry Behavior Overview Boto3's Standard retry mode includes the following mechanisms: -- Maximum Retry Attempts: Default value set to 3, configurable via the `--aws-retries-max-attempts 5` argument. +- Maximum Retry Attempts: Default value set to 3, configurable via the `--aws-retries-max-attempts 5` argument. `0` disables retries. - Expanded Error Handling: Retries occur for a comprehensive set of errors. diff --git a/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md b/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md new file mode 100644 index 0000000000..a204443b2a --- /dev/null +++ b/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md @@ -0,0 +1 @@ +AWS provider default Boto3 connect timeout lowered from 60 to 10 seconds, so scans in restricted-egress networks (VPC endpoints for a subset of services, GovCloud, private deployments) no longer spend 4 minutes per region on every service whose endpoint is unreachable diff --git a/prowler/changelog.d/aws-boto3-timeouts.added.md b/prowler/changelog.d/aws-boto3-timeouts.added.md new file mode 100644 index 0000000000..df5d6e4f2b --- /dev/null +++ b/prowler/changelog.d/aws-boto3-timeouts.added.md @@ -0,0 +1 @@ +`--aws-connect-timeout` and `--aws-read-timeout` CLI flags, plus `PROWLER_AWS_BOTO3_CONNECT_TIMEOUT` and `PROWLER_AWS_BOTO3_READ_TIMEOUT` environment variables, to bound how long each AWS API call waits for an endpoint diff --git a/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md b/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md new file mode 100644 index 0000000000..8eb2ad9e07 --- /dev/null +++ b/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md @@ -0,0 +1 @@ +`--aws-retries-max-attempts 0` now disables Boto3 retries instead of being silently ignored in favour of the default of 3 diff --git a/prowler/providers/aws/aws_provider.py b/prowler/providers/aws/aws_provider.py index d0ca3b98ee..07e3ecab89 100644 --- a/prowler/providers/aws/aws_provider.py +++ b/prowler/providers/aws/aws_provider.py @@ -126,6 +126,8 @@ class AwsProvider(Provider): aws_access_key_id: str = None, aws_secret_access_key: str = None, aws_session_token: Optional[str] = None, + connect_timeout: Optional[int] = None, + read_timeout: Optional[int] = None, ): """ Initializes the AWS provider. @@ -155,6 +157,8 @@ class AwsProvider(Provider): - aws_access_key_id: The AWS access key ID. - aws_secret_access_key: The AWS secret access key. - aws_session_token: The AWS session token, optional. + - connect_timeout: Seconds to wait to establish a connection to an AWS endpoint. + - read_timeout: Seconds to wait for a response from an AWS endpoint. Raises: - ArgumentTypeError: If the input MFA ARN is invalid. @@ -229,7 +233,9 @@ class AwsProvider(Provider): # TODO: Use AwsSetUpSession ????? # Configure the initial AWS Session using the local credentials: profile or environment variables - session_config = self.set_session_config(retries_max_attempts) + session_config = self.set_session_config( + retries_max_attempts, connect_timeout, read_timeout + ) aws_session = self.setup_session( mfa=mfa, profile=profile, @@ -1165,26 +1171,35 @@ class AwsProvider(Provider): return AWSMFAInfo(arn=mfa_ARN, totp=mfa_TOTP) @staticmethod - def set_session_config(retries_max_attempts: int) -> Config: + def set_session_config( + retries_max_attempts: int, + connect_timeout: Optional[int] = None, + read_timeout: Optional[int] = None, + ) -> Config: """ - set_session_config returns a botocore Config object with the Prowler user agent and the default retrier configuration if nothing is passed as argument + set_session_config returns a botocore Config object with the Prowler user agent and the default retrier and timeout configuration if nothing is passed as argument Args: - retries_max_attempts: The maximum number of retries for the standard retrier config + - connect_timeout: Seconds to wait to establish a connection to an AWS endpoint + - read_timeout: Seconds to wait for a response from an AWS endpoint Returns: - Config: The botocore Config object """ default_session_config = get_default_session_config() - if retries_max_attempts: - default_session_config = default_session_config.merge( - Config( - retries={ - "max_attempts": retries_max_attempts, - "mode": "standard", - }, - ) - ) + overrides = {} + if retries_max_attempts is not None: + overrides["retries"] = { + "max_attempts": retries_max_attempts, + "mode": "standard", + } + if connect_timeout: + overrides["connect_timeout"] = connect_timeout + if read_timeout: + overrides["read_timeout"] = read_timeout + if overrides: + default_session_config = default_session_config.merge(Config(**overrides)) return default_session_config diff --git a/prowler/providers/aws/config.py b/prowler/providers/aws/config.py index ea55d1a314..ed2ca503d0 100644 --- a/prowler/providers/aws/config.py +++ b/prowler/providers/aws/config.py @@ -2,14 +2,39 @@ import os from botocore.config import Config +from prowler.providers.aws.exceptions.exceptions import AWSInvalidBoto3TimeoutError + AWS_STS_GLOBAL_ENDPOINT_REGION = "us-east-1" AWS_REGION_US_EAST_1 = "us-east-1" BOTO3_USER_AGENT_EXTRA = os.getenv("PROWLER_AWS_BOTO3_USER_AGENT_EXTRA", "APN_1826889") +BOTO3_RETRIES_MAX_ATTEMPTS = 3 +# botocore defaults both to 60s +BOTO3_CONNECT_TIMEOUT = 10 +BOTO3_READ_TIMEOUT = 60 ROLE_SESSION_NAME = "ProwlerAssessmentSession" +def get_boto3_timeout_from_env(name: str, default: int) -> int: + """Positive integer seconds read from the environment, or default when unset.""" + raw = os.getenv(name, "").strip() + if not raw: + return default + if not raw.isdecimal() or int(raw) == 0: + raise AWSInvalidBoto3TimeoutError( + file=os.path.basename(__file__), + message=f"{name} must be a positive integer number of seconds, got {raw!r}", + ) + return int(raw) + + def get_default_session_config() -> Config: return Config( user_agent_extra=BOTO3_USER_AGENT_EXTRA, - retries={"max_attempts": 3, "mode": "standard"}, + retries={"max_attempts": BOTO3_RETRIES_MAX_ATTEMPTS, "mode": "standard"}, + connect_timeout=get_boto3_timeout_from_env( + "PROWLER_AWS_BOTO3_CONNECT_TIMEOUT", BOTO3_CONNECT_TIMEOUT + ), + read_timeout=get_boto3_timeout_from_env( + "PROWLER_AWS_BOTO3_READ_TIMEOUT", BOTO3_READ_TIMEOUT + ), ) diff --git a/prowler/providers/aws/exceptions/exceptions.py b/prowler/providers/aws/exceptions/exceptions.py index 4ea3d5e177..089e0d99c7 100644 --- a/prowler/providers/aws/exceptions/exceptions.py +++ b/prowler/providers/aws/exceptions/exceptions.py @@ -78,6 +78,10 @@ class AWSBaseException(ProwlerException): "message": "The provided AWS partition is invalid", "remediation": "Check the provided AWS partition and ensure it is valid.", }, + (1918, "AWSInvalidBoto3TimeoutError"): { + "message": "The Boto3 timeout configured through the environment is invalid", + "remediation": "Set PROWLER_AWS_BOTO3_CONNECT_TIMEOUT and PROWLER_AWS_BOTO3_READ_TIMEOUT to a positive integer number of seconds.", + }, } def __init__(self, code, file=None, original_exception=None, message=None): @@ -231,3 +235,12 @@ class AWSInvalidPartitionError(AWSBaseException): super().__init__( 1917, file=file, original_exception=original_exception, message=message ) + + +class AWSInvalidBoto3TimeoutError(AWSBaseException): + """Boto3 timeout configured through the environment is not a positive integer.""" + + def __init__(self, file=None, original_exception=None, message=None): + super().__init__( + 1918, file=file, original_exception=original_exception, message=message + ) diff --git a/prowler/providers/aws/lib/arguments/arguments.py b/prowler/providers/aws/lib/arguments/arguments.py index 2d1632422b..84f3b4adfa 100644 --- a/prowler/providers/aws/lib/arguments/arguments.py +++ b/prowler/providers/aws/lib/arguments/arguments.py @@ -156,7 +156,21 @@ def init_parser(self): nargs="?", default=None, type=int, - help="Set the maximum attemps for the Boto3 standard retrier config (Default: 3)", + help="Set the maximum retries for the Boto3 standard retrier config, 0 disables retries (Default: 3)", + ) + boto3_config_subparser.add_argument( + "--aws-connect-timeout", + nargs="?", + default=None, + type=validate_timeout, + help="Seconds to wait to establish a connection (TCP, proxy tunnel and TLS) to an AWS endpoint before retrying (Default: 10)", + ) + boto3_config_subparser.add_argument( + "--aws-read-timeout", + nargs="?", + default=None, + type=validate_timeout, + help="Seconds to wait for a response from an AWS endpoint before retrying (Default: 60)", ) # Scan Unused Services @@ -190,6 +204,13 @@ def validate_session_duration(session_duration: int) -> int: return duration +def validate_timeout(value: str) -> int: + """validate_timeout validates that the input is a whole number of seconds greater than zero""" + if not value.isdecimal() or int(value) == 0: + raise ArgumentTypeError(f"{value} is not a positive integer") + return int(value) + + def validate_role_session_name(session_name) -> str: """ Validates that the role session name is valid. diff --git a/prowler/providers/aws/lib/session/aws_set_up_session.py b/prowler/providers/aws/lib/session/aws_set_up_session.py index 3189400040..8f0b4130ca 100644 --- a/prowler/providers/aws/lib/session/aws_set_up_session.py +++ b/prowler/providers/aws/lib/session/aws_set_up_session.py @@ -42,6 +42,8 @@ class AwsSetUpSession: aws_session_token: Optional[str] = None, retries_max_attempts: int = 3, regions: set = set(), + connect_timeout: Optional[int] = None, + read_timeout: Optional[int] = None, ) -> None: """ The constructor for the AwsSetUpSession class. @@ -58,6 +60,8 @@ class AwsSetUpSession: - aws_session_token: The AWS session token, optional. - retries_max_attempts: The maximum number of retries for the AWS client. - regions: A set of regions to audit. + - connect_timeout: Seconds to wait to establish a connection to an AWS endpoint. + - read_timeout: Seconds to wait for a response from an AWS endpoint. Returns: @@ -73,7 +77,9 @@ class AwsSetUpSession: aws_access_key_id=aws_access_key_id, aws_secret_access_key=aws_secret_access_key, ) - session_config = AwsProvider.set_session_config(retries_max_attempts) + session_config = AwsProvider.set_session_config( + retries_max_attempts, connect_timeout, read_timeout + ) aws_session = AwsProvider.setup_session( mfa=mfa, profile=profile, diff --git a/prowler/providers/common/provider.py b/prowler/providers/common/provider.py index 2e81bad121..7e23b8de7f 100644 --- a/prowler/providers/common/provider.py +++ b/prowler/providers/common/provider.py @@ -382,6 +382,8 @@ class Provider(ABC): ) provider_class( retries_max_attempts=arguments.aws_retries_max_attempts, + connect_timeout=arguments.aws_connect_timeout, + read_timeout=arguments.aws_read_timeout, role_arn=arguments.role, session_duration=arguments.session_duration, external_id=arguments.external_id, diff --git a/tests/lib/cli/parser_test.py b/tests/lib/cli/parser_test.py index da16f437b5..a811186b3b 100644 --- a/tests/lib/cli/parser_test.py +++ b/tests/lib/cli/parser_test.py @@ -1152,6 +1152,35 @@ class Test_Parser: parsed = self.parser.parse(command) assert parsed.aws_retries_max_attempts == int(max_retries) + def test_aws_parser_retries_max_attempts_zero(self): + command = [prowler_command, "--aws-retries-max-attempts", "0"] + parsed = self.parser.parse(command) + assert parsed.aws_retries_max_attempts == 0 + + def test_aws_parser_timeouts_default_to_none(self): + parsed = self.parser.parse([prowler_command]) + assert parsed.aws_connect_timeout is None + assert parsed.aws_read_timeout is None + + @pytest.mark.parametrize( + "argument, attribute", + [ + ("--aws-connect-timeout", "aws_connect_timeout"), + ("--aws-read-timeout", "aws_read_timeout"), + ], + ) + def test_aws_parser_timeouts(self, argument, attribute): + timeout = "5" + command = [prowler_command, argument, timeout] + parsed = self.parser.parse(command) + assert getattr(parsed, attribute) == int(timeout) + + @pytest.mark.parametrize("value", ["0", "-1", "abc"]) + def test_aws_parser_connect_timeout_rejects_non_positive(self, value): + command = [prowler_command, "--aws-connect-timeout", value] + with pytest.raises(SystemExit): + self.parser.parse(command) + def test_aws_parser_scan_unused_services(self): argument = "--scan-unused-services" command = [prowler_command, argument] diff --git a/tests/providers/aws/aws_provider_test.py b/tests/providers/aws/aws_provider_test.py index 7ce61b6862..cd8bb4f049 100644 --- a/tests/providers/aws/aws_provider_test.py +++ b/tests/providers/aws/aws_provider_test.py @@ -24,19 +24,24 @@ from prowler.providers.aws.aws_provider import ( ) from prowler.providers.aws.config import ( AWS_STS_GLOBAL_ENDPOINT_REGION, + BOTO3_CONNECT_TIMEOUT, + BOTO3_READ_TIMEOUT, BOTO3_USER_AGENT_EXTRA, ROLE_SESSION_NAME, + get_boto3_timeout_from_env, get_default_session_config, ) from prowler.providers.aws.exceptions.exceptions import ( AWSArgumentTypeValidationError, AWSIAMRoleARNInvalidResourceTypeError, + AWSInvalidBoto3TimeoutError, AWSInvalidPartitionError, AWSInvalidProviderIdError, AWSNoCredentialsError, ) from prowler.providers.aws.lib.arn.models import ARN from prowler.providers.aws.lib.mutelist.mutelist import AWSMutelist +from prowler.providers.aws.lib.session.aws_set_up_session import AwsSetUpSession from prowler.providers.aws.models import ( AWSAssumeRoleInfo, AWSCallerIdentity, @@ -2735,6 +2740,8 @@ aws: assert session_config.user_agent_extra == BOTO3_USER_AGENT_EXTRA assert session_config.retries == {"max_attempts": 3, "mode": "standard"} + assert session_config.connect_timeout == BOTO3_CONNECT_TIMEOUT + assert session_config.read_timeout == BOTO3_READ_TIMEOUT @mock_aws def test_set_session_config_10_max_attempts(self): @@ -2743,12 +2750,93 @@ aws: assert session_config.user_agent_extra == BOTO3_USER_AGENT_EXTRA assert session_config.retries == {"max_attempts": 10, "mode": "standard"} + assert session_config.connect_timeout == BOTO3_CONNECT_TIMEOUT + assert session_config.read_timeout == BOTO3_READ_TIMEOUT + + def test_set_session_config_0_max_attempts_disables_retries(self): + session_config = AwsProvider.set_session_config(0) + + assert session_config.retries == {"max_attempts": 0, "mode": "standard"} + + @mock_aws + def test_aws_provider_0_max_attempts_reaches_clients(self): + aws_provider = AwsProvider(retries_max_attempts=0) + client = aws_provider.session.current_session.client( + "ec2", region_name=AWS_REGION_US_EAST_1 + ) + + # botocore rewrites max_attempts into total_max_attempts (retries + 1) + assert client.meta.config.retries["total_max_attempts"] == 1 + + def test_set_session_config_timeouts(self): + session_config = AwsProvider.set_session_config( + None, connect_timeout=2, read_timeout=15 + ) + + assert session_config.retries == {"max_attempts": 3, "mode": "standard"} + assert session_config.connect_timeout == 2 + assert session_config.read_timeout == 15 + + @mock_aws + def test_aws_provider_timeouts_reach_session_config(self): + aws_provider = AwsProvider(connect_timeout=2, read_timeout=15) + + assert aws_provider.session.session_config.connect_timeout == 2 + assert aws_provider.session.session_config.read_timeout == 15 + + @mock_aws + def test_aws_set_up_session_forwards_timeouts(self): + aws_session = AwsSetUpSession( + aws_access_key_id="testing", + aws_secret_access_key="testing", + connect_timeout=2, + read_timeout=15, + ) + + assert aws_session._session.session_config.connect_timeout == 2 + assert aws_session._session.session_config.read_timeout == 15 def test_get_default_session_config(self): config = get_default_session_config() assert config.user_agent_extra == BOTO3_USER_AGENT_EXTRA assert config.retries == {"max_attempts": 3, "mode": "standard"} + assert config.connect_timeout == BOTO3_CONNECT_TIMEOUT + assert config.read_timeout == BOTO3_READ_TIMEOUT + + def test_get_default_session_config_timeouts_from_env(self): + with mock.patch.dict( + os.environ, + { + "PROWLER_AWS_BOTO3_CONNECT_TIMEOUT": "3", + "PROWLER_AWS_BOTO3_READ_TIMEOUT": "20", + }, + ): + config = get_default_session_config() + + assert config.connect_timeout == 3 + assert config.read_timeout == 20 + + def test_set_session_config_argument_overrides_env_timeouts(self): + with mock.patch.dict(os.environ, {"PROWLER_AWS_BOTO3_CONNECT_TIMEOUT": "3"}): + config = AwsProvider.set_session_config(None, connect_timeout=7) + + assert config.connect_timeout == 7 + + @pytest.mark.parametrize("raw", ["0", "-5", "ten", "1.5"]) + def test_get_boto3_timeout_from_env_rejects_non_positive_integers(self, raw): + with mock.patch.dict(os.environ, {"PROWLER_AWS_BOTO3_CONNECT_TIMEOUT": raw}): + with raises( + AWSInvalidBoto3TimeoutError, match="PROWLER_AWS_BOTO3_CONNECT_TIMEOUT" + ): + get_boto3_timeout_from_env("PROWLER_AWS_BOTO3_CONNECT_TIMEOUT", 10) + + def test_get_boto3_timeout_from_env_blank_falls_back_to_default(self): + with mock.patch.dict(os.environ, {"PROWLER_AWS_BOTO3_CONNECT_TIMEOUT": " "}): + assert ( + get_boto3_timeout_from_env("PROWLER_AWS_BOTO3_CONNECT_TIMEOUT", 10) + == 10 + ) @mock_aws @patch( From f9c02da90a41f5b00a06c61b7fbfa6006ed4c33b Mon Sep 17 00:00:00 2001 From: StylusFrost <43682773+StylusFrost@users.noreply.github.com> Date: Thu, 10 Sep 2026 17:15:13 +0200 Subject: [PATCH 12/16] feat(aws): support the ISO partitions for region resolution and scanning (#12759) Co-authored-by: pedrooot --- .../sdk-refresh-aws-services-regions.yml | 5 +- .../changelog.d/aws-iso-partitions.added.md | 1 + .../changelog.d/aws-iso-partitions.fixed.md | 1 + .../aws-regional-clients-empty-dict.fixed.md | 1 + ...service-regions-unknown-partition.fixed.md | 1 + prowler/providers/aws/aws_provider.py | 27 +- .../providers/aws/aws_regions_by_service.json | 2621 +++++++++++++++++ tests/providers/aws/aws_provider_test.py | 119 +- tests/providers/aws/utils.py | 5 +- util/update_aws_services_regions.py | 364 ++- 10 files changed, 3045 insertions(+), 100 deletions(-) create mode 100644 prowler/changelog.d/aws-iso-partitions.added.md create mode 100644 prowler/changelog.d/aws-iso-partitions.fixed.md create mode 100644 prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md create mode 100644 prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md diff --git a/.github/workflows/sdk-refresh-aws-services-regions.yml b/.github/workflows/sdk-refresh-aws-services-regions.yml index 5a38858247..075852c6a6 100644 --- a/.github/workflows/sdk-refresh-aws-services-regions.yml +++ b/.github/workflows/sdk-refresh-aws-services-regions.yml @@ -44,7 +44,10 @@ jobs: cache: 'pip' - name: Install dependencies - run: pip install boto3 + # Pinned to the versions in pyproject.toml: the ISO partitions region + # data comes from the endpoints.json bundled with botocore, so the + # botocore version is itself a data source and must be deterministic + run: pip install boto3==1.40.61 botocore==1.40.61 - name: Configure AWS credentials uses: aws-actions/configure-aws-credentials@d979d5b3a71173a29b74b5b88418bfda9437d885 # v6.1.1 diff --git a/prowler/changelog.d/aws-iso-partitions.added.md b/prowler/changelog.d/aws-iso-partitions.added.md new file mode 100644 index 0000000000..41282ea353 --- /dev/null +++ b/prowler/changelog.d/aws-iso-partitions.added.md @@ -0,0 +1 @@ +AWS ISO partitions (`aws-iso`, `aws-iso-b`, `aws-iso-e` and `aws-iso-f`) to the AWS service region matrix, generated from the endpoints data bundled with botocore diff --git a/prowler/changelog.d/aws-iso-partitions.fixed.md b/prowler/changelog.d/aws-iso-partitions.fixed.md new file mode 100644 index 0000000000..c3424d51ba --- /dev/null +++ b/prowler/changelog.d/aws-iso-partitions.fixed.md @@ -0,0 +1 @@ +`AwsProvider.get_global_region()` now returns a real region for each ISO partition instead of the `aws-iso-global` pseudo endpoint, which collapsed the four partitions into one answer diff --git a/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md b/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md new file mode 100644 index 0000000000..bd5f7798ac --- /dev/null +++ b/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md @@ -0,0 +1 @@ +`AwsProvider.generate_regional_clients()` now returns an empty dict instead of `None` when the regional clients cannot be built, a failure that surfaced later as `AttributeError: 'NoneType' object has no attribute 'values'` diff --git a/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md b/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md new file mode 100644 index 0000000000..881ce2c94b --- /dev/null +++ b/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md @@ -0,0 +1 @@ +`AwsProvider.get_available_aws_service_regions()` now returns an empty set for an unknown service or partition instead of raising `KeyError`, so a service unavailable in the audited partition is skipped diff --git a/prowler/providers/aws/aws_provider.py b/prowler/providers/aws/aws_provider.py index 07e3ecab89..e204318593 100644 --- a/prowler/providers/aws/aws_provider.py +++ b/prowler/providers/aws/aws_provider.py @@ -921,6 +921,9 @@ class AwsProvider(Provider): logger.error( f"{error.__class__.__name__}[{error.__traceback__.tb_lineno}]: {error}" ) + # Return an empty dict, as promised by the signature, so the service + # is simply not scanned instead of the callers failing later on a None + return {} @staticmethod def get_available_aws_service_regions( @@ -936,9 +939,13 @@ class AwsProvider(Provider): Returns: - A set of strings representing the available regions for the given service and partition. + A service or a partition not present in the regions file yields an empty set, the same + outcome as a service explicitly recorded as unavailable in the partition. """ data = read_aws_regions_file() - json_regions = set(data["services"][service]["regions"][partition]) + json_regions = set( + data["services"].get(service, {}).get("regions", {}).get(partition, []) + ) if audited_regions: # Get common regions between input and json regions = json_regions.intersection(audited_regions) @@ -1145,16 +1152,14 @@ class AwsProvider(Provider): Example: global_region = get_global_region()a """ - global_region = "us-east-1" - if self._identity.partition == "aws-cn": - global_region = "cn-north-1" - elif self._identity.partition == "aws-eusc": - global_region = "eusc-de-east-1" - elif self._identity.partition == "aws-us-gov": - global_region = "us-gov-east-1" - elif "aws-iso" in self._identity.partition: - global_region = "aws-iso-global" - return global_region + # The first region of the partition is the one of its global STS endpoint, + # which is always a real region, never a pseudo endpoint like "aws-iso-global" + partition_regions = get_botocore_partition_regions().get( + self._identity.partition + ) + if partition_regions: + return partition_regions[0] + return "us-east-1" @staticmethod def input_role_mfa_token_and_code() -> AWSMFAInfo: diff --git a/prowler/providers/aws/aws_regions_by_service.json b/prowler/providers/aws/aws_regions_by_service.json index bd66643d27..bb51556b78 100644 --- a/prowler/providers/aws/aws_regions_by_service.json +++ b/prowler/providers/aws/aws_regions_by_service.json @@ -10,6 +10,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -58,6 +62,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -102,6 +115,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -150,6 +167,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -201,6 +227,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -221,6 +256,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -238,6 +277,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -268,6 +311,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -292,6 +339,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -323,6 +374,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -351,6 +406,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -379,6 +438,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -427,6 +490,17 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -461,6 +535,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -510,6 +588,17 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -561,6 +650,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -612,6 +716,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -640,6 +759,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -659,6 +782,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -693,6 +820,21 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -737,6 +879,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -750,6 +896,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -787,6 +937,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -807,6 +961,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -834,6 +992,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -880,6 +1042,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -923,6 +1089,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -974,6 +1144,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1022,6 +1207,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1073,6 +1262,19 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1097,6 +1299,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1118,6 +1324,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1166,6 +1376,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1217,6 +1431,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1232,6 +1461,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1250,6 +1483,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1298,6 +1535,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1319,6 +1560,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1337,6 +1582,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1385,6 +1634,18 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1418,6 +1679,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1469,6 +1734,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1484,6 +1764,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1496,6 +1780,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1506,6 +1794,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1550,6 +1842,12 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1576,6 +1874,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -1606,6 +1908,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1626,6 +1932,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -1657,6 +1967,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1670,6 +1984,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1680,6 +1998,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1694,6 +2016,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1711,6 +2037,18 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -1754,6 +2092,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1781,6 +2123,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1812,6 +2158,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1826,6 +2176,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1845,6 +2199,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1866,6 +2224,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -1880,6 +2242,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1899,6 +2265,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1919,6 +2289,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1939,6 +2313,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -1970,6 +2348,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2018,6 +2400,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2039,6 +2436,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -2071,6 +2472,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2104,6 +2509,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2155,6 +2564,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2204,6 +2628,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2245,6 +2673,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2267,6 +2699,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2307,6 +2743,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2358,6 +2798,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2385,6 +2840,15 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -2433,6 +2897,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2458,6 +2937,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2501,6 +2984,18 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2515,6 +3010,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2552,6 +3051,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2581,6 +3084,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1" ] @@ -2631,6 +3138,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2653,6 +3175,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2672,6 +3198,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2714,6 +3244,13 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2743,6 +3280,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1" ] @@ -2772,6 +3313,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2782,6 +3327,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2827,6 +3376,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2877,6 +3430,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2925,6 +3482,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -2948,6 +3509,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -2969,6 +3534,15 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-west-1" ] @@ -2987,6 +3561,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -3031,6 +3609,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3060,6 +3647,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3108,6 +3699,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3130,6 +3736,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -3151,6 +3761,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3170,6 +3784,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3189,6 +3807,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3201,6 +3823,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3220,6 +3846,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -3267,6 +3897,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3315,6 +3949,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3330,6 +3968,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -3344,6 +3990,16 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -3363,6 +4019,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3394,6 +4054,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -3416,6 +4080,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3430,6 +4098,12 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3478,6 +4152,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3509,6 +4192,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3536,6 +4223,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3555,6 +4246,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3585,6 +4280,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3598,6 +4297,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3623,6 +4326,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3671,6 +4378,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3690,6 +4412,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -3738,6 +4464,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3789,6 +4530,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3836,6 +4592,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3884,6 +4655,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3935,6 +4710,20 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -3967,6 +4756,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -4015,6 +4808,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4066,6 +4874,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4117,6 +4940,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4168,6 +5006,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4219,6 +5072,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4233,6 +5101,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -4281,6 +5153,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4332,6 +5219,20 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4383,6 +5284,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4429,6 +5345,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4480,6 +5400,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4527,6 +5462,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4578,6 +5517,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4629,6 +5583,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4646,6 +5615,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -4694,6 +5667,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4736,6 +5724,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4787,6 +5779,12 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4811,6 +5809,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -4859,6 +5861,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4910,6 +5927,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4961,6 +5982,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -4995,6 +6031,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5043,6 +6083,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5065,6 +6109,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5084,6 +6132,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5098,6 +6150,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5146,6 +6202,20 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5182,6 +6252,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5231,6 +6305,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5253,6 +6331,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5272,6 +6354,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5287,6 +6373,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5317,6 +6407,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5365,6 +6459,18 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5416,6 +6522,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5467,6 +6577,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5518,6 +6632,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5569,6 +6687,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5607,6 +6729,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5641,6 +6767,15 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5687,6 +6822,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5735,6 +6874,19 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5757,6 +6909,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5785,6 +6941,10 @@ "cn-north-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5809,6 +6969,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -5857,6 +7021,17 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5876,6 +7051,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5927,6 +7110,19 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -5978,6 +7174,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6029,6 +7229,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6080,6 +7284,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6104,6 +7312,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6152,6 +7364,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6200,6 +7416,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6239,6 +7459,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6249,6 +7473,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6284,6 +7512,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6322,6 +7554,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6358,6 +7594,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6373,6 +7613,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6386,6 +7630,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6418,6 +7666,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6456,6 +7708,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6471,6 +7727,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6506,6 +7766,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6531,6 +7795,10 @@ "cn-north-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -6541,6 +7809,10 @@ "aws": [], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6561,6 +7833,10 @@ "cn-north-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -6579,6 +7855,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6595,6 +7875,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6611,6 +7895,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6627,6 +7915,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6675,6 +7967,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6724,6 +8020,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6746,6 +8046,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -6766,6 +8070,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -6814,6 +8122,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6865,6 +8188,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6899,6 +8230,12 @@ "cn-north-1" ], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -6950,6 +8287,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7001,6 +8353,19 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7052,6 +8417,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7100,6 +8480,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7142,6 +8526,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7165,6 +8553,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -7187,6 +8579,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -7237,6 +8633,20 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7285,6 +8695,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7330,6 +8744,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7361,6 +8779,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7409,6 +8831,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7424,6 +8861,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7451,6 +8892,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7481,6 +8926,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7495,6 +8944,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7526,6 +8979,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7557,6 +9014,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7572,6 +9033,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -7584,6 +9049,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7615,6 +9084,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7666,6 +9139,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7681,6 +9158,12 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7691,6 +9174,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7705,6 +9192,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7715,6 +9206,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7750,6 +9245,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -7785,6 +9284,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7817,6 +9320,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -7848,6 +9355,14 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7875,6 +9390,14 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7904,6 +9427,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7934,6 +9461,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7952,6 +9483,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7970,6 +9505,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -7999,6 +9538,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8013,6 +9556,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8044,6 +9591,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8088,6 +9639,12 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8107,6 +9664,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8150,6 +9711,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8179,6 +9744,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8195,6 +9764,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8211,6 +9784,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8223,6 +9800,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8271,6 +9852,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8284,6 +9869,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8327,6 +9916,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8368,6 +9961,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8411,6 +10008,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8448,6 +10060,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8496,6 +10112,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8525,6 +10149,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8568,6 +10196,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8608,6 +10240,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8651,6 +10287,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8663,6 +10303,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8673,6 +10317,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8721,6 +10369,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8765,6 +10428,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8795,6 +10462,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8814,6 +10485,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8862,6 +10537,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8896,6 +10586,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -8917,6 +10611,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8935,6 +10633,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -8983,6 +10685,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9012,6 +10729,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9050,6 +10771,14 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9063,6 +10792,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9073,6 +10806,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9083,6 +10820,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9108,6 +10849,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9153,6 +10898,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9197,6 +10946,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9225,6 +10978,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9248,6 +11005,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9296,6 +11057,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9320,6 +11096,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -9337,6 +11117,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9352,6 +11136,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9394,6 +11182,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9435,6 +11227,15 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -9472,6 +11273,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -9490,6 +11295,18 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -9538,6 +11355,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9561,6 +11382,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9572,6 +11397,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9585,6 +11414,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9596,6 +11429,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9633,6 +11470,13 @@ "cn-north-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9684,6 +11528,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9735,6 +11594,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9786,6 +11660,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9812,6 +11701,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9822,6 +11715,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -9870,6 +11767,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9921,6 +11833,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -9971,6 +11887,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10001,6 +11926,13 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-west-1" ] @@ -10019,6 +11951,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10048,6 +11984,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10097,6 +12037,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10148,6 +12092,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10199,6 +12158,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10250,6 +12224,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10290,6 +12268,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10341,6 +12323,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10392,6 +12389,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10431,6 +12432,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10441,6 +12446,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10451,6 +12460,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10497,6 +12510,15 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10548,6 +12570,20 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10566,6 +12602,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10609,6 +12649,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10660,6 +12704,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10706,6 +12765,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10741,6 +12809,14 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10789,6 +12865,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10840,6 +12920,17 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10880,6 +12971,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10890,6 +12985,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -10931,6 +13030,17 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [] } }, @@ -10979,6 +13089,17 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -10990,6 +13111,10 @@ "aws": [], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11035,6 +13160,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11086,6 +13220,20 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11126,6 +13274,15 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11146,6 +13303,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11194,6 +13355,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11231,6 +13407,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11279,6 +13459,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11308,6 +13497,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11341,6 +13534,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11392,6 +13589,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11437,6 +13649,12 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11478,6 +13696,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11529,6 +13751,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11570,6 +13807,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11611,6 +13852,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11655,6 +13900,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11689,6 +13938,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11740,6 +13993,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11755,6 +14012,10 @@ "cn-north-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -11772,6 +14033,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11798,6 +14063,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11830,6 +14099,15 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11857,6 +14135,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11905,6 +14187,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -11951,6 +14248,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -11999,6 +14300,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12050,6 +14366,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12078,6 +14409,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12103,6 +14438,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12128,6 +14467,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12165,6 +14508,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12213,6 +14560,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12264,6 +14615,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12315,6 +14681,15 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12366,6 +14741,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12417,6 +14807,16 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12432,6 +14832,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12443,6 +14847,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12491,6 +14899,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12542,6 +14965,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12557,6 +14995,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12580,6 +15022,15 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12599,6 +15050,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12616,6 +15071,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -12650,6 +15109,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12667,6 +15130,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -12686,6 +15153,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -12707,6 +15178,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12739,6 +15214,15 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12790,6 +15274,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12841,6 +15329,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12869,6 +15361,15 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-west-1" ] @@ -12919,6 +15420,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -12932,6 +15441,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -12959,6 +15472,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13008,6 +15525,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13044,6 +15565,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13064,6 +15589,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13112,6 +15641,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13154,6 +15687,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13199,6 +15736,10 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13250,6 +15791,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13293,6 +15842,10 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13344,6 +15897,14 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13374,6 +15935,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13404,6 +15969,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13426,6 +15995,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-west-1" ] @@ -13447,6 +16020,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13462,6 +16039,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13474,6 +16055,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13486,6 +16071,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13514,6 +16103,15 @@ "cn-northwest-1" ], "aws-eusc": [], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1" + ], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" @@ -13532,6 +16130,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13551,6 +16153,10 @@ ], "aws-cn": [], "aws-eusc": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], "aws-us-gov": [] } }, @@ -13599,6 +16205,21 @@ "aws-eusc": [ "eusc-de-east-1" ], + "aws-iso": [ + "us-iso-east-1", + "us-iso-west-1" + ], + "aws-iso-b": [ + "us-isob-east-1", + "us-isob-west-1" + ], + "aws-iso-e": [ + "eu-isoe-west-1" + ], + "aws-iso-f": [ + "us-isof-east-1", + "us-isof-south-1" + ], "aws-us-gov": [ "us-gov-east-1", "us-gov-west-1" diff --git a/tests/providers/aws/aws_provider_test.py b/tests/providers/aws/aws_provider_test.py index cd8bb4f049..f899706453 100644 --- a/tests/providers/aws/aws_provider_test.py +++ b/tests/providers/aws/aws_provider_test.py @@ -59,6 +59,7 @@ from tests.providers.aws.utils import ( AWS_EUSC_PARTITION, AWS_GOV_CLOUD_ACCOUNT_ARN, AWS_GOV_CLOUD_PARTITION, + AWS_ISO_B_PARTITION, AWS_ISO_PARTITION, AWS_REGION_CN_NORTH_1, AWS_REGION_CN_NORTHWEST_1, @@ -67,7 +68,9 @@ from tests.providers.aws.utils import ( AWS_REGION_EUSC_DE_EAST_1, AWS_REGION_GOV_CLOUD_US_EAST_1, AWS_REGION_GOV_CLOUD_US_WEST_1, - AWS_REGION_ISO_GLOBAL, + AWS_REGION_ISO_B_EAST_1, + AWS_REGION_ISO_EAST_1, + AWS_REGION_ISO_WEST_1, AWS_REGION_US_EAST_1, AWS_REGION_US_EAST_2, EXAMPLE_AMI_ID, @@ -1192,6 +1195,13 @@ aws: == AWS_REGION_EU_WEST_1 ) + @mock_aws + def test_aws_get_global_region(self): + aws_provider = AwsProvider() + aws_provider._identity.partition = AWS_COMMERCIAL_PARTITION + + assert aws_provider.get_global_region() == AWS_REGION_US_EAST_1 + @mock_aws def test_aws_gov_get_global_region(self): aws_provider = AwsProvider() @@ -1211,7 +1221,21 @@ aws: aws_provider = AwsProvider() aws_provider._identity.partition = AWS_ISO_PARTITION - assert aws_provider.get_global_region() == AWS_REGION_ISO_GLOBAL + assert aws_provider.get_global_region() == AWS_REGION_ISO_EAST_1 + + @mock_aws + def test_aws_iso_b_get_global_region(self): + aws_provider = AwsProvider() + aws_provider._identity.partition = AWS_ISO_B_PARTITION + + assert aws_provider.get_global_region() == AWS_REGION_ISO_B_EAST_1 + + @mock_aws + def test_get_global_region_for_an_unknown_partition(self): + aws_provider = AwsProvider() + aws_provider._identity.partition = "aws-unknown" + + assert aws_provider.get_global_region() == AWS_REGION_US_EAST_1 @mock_aws def test_aws_eusc_get_global_region(self): @@ -1299,6 +1323,88 @@ aws: len(aws_provider.get_available_aws_service_regions("ec2", "aws")) == 17 ) + @mock_aws + def test_get_available_aws_service_regions_commercial_and_gov_cloud(self): + aws_provider = AwsProvider() + + assert AWS_REGION_US_EAST_1 in aws_provider.get_available_aws_service_regions( + "ec2", AWS_COMMERCIAL_PARTITION + ) + assert ( + AWS_REGION_GOV_CLOUD_US_EAST_1 + in aws_provider.get_available_aws_service_regions( + "ec2", AWS_GOV_CLOUD_PARTITION + ) + ) + # A service recorded as unavailable in the partition yields an empty set + assert ( + aws_provider.get_available_aws_service_regions( + "bedrock-agent", AWS_CHINA_PARTITION + ) + == set() + ) + + @mock_aws + def test_get_available_aws_service_regions_iso_partitions(self): + aws_provider = AwsProvider() + + assert aws_provider.get_available_aws_service_regions( + "ec2", AWS_ISO_PARTITION + ) == { + AWS_REGION_ISO_EAST_1, + AWS_REGION_ISO_WEST_1, + } + assert aws_provider.get_available_aws_service_regions( + "guardduty", AWS_ISO_B_PARTITION + ) == {AWS_REGION_ISO_B_EAST_1} + # Every service carries every ISO partition, empty when not available + assert ( + aws_provider.get_available_aws_service_regions( + "bedrock", AWS_ISO_B_PARTITION + ) + == set() + ) + + @mock_aws + def test_get_available_aws_service_regions_unknown_partition(self): + aws_provider = AwsProvider() + + assert ( + aws_provider.get_available_aws_service_regions("ec2", "aws-unknown") + == set() + ) + + @mock_aws + def test_get_available_aws_service_regions_unknown_service(self): + aws_provider = AwsProvider() + + assert ( + aws_provider.get_available_aws_service_regions( + "unknown-service", AWS_COMMERCIAL_PARTITION + ) + == set() + ) + + @mock_aws + def test_generate_regional_clients_service_not_in_partition(self): + aws_provider = AwsProvider() + aws_provider._identity.partition = AWS_ISO_PARTITION + + response = aws_provider.generate_regional_clients("bedrock") + + assert response == {} + + @mock_aws + def test_generate_regional_clients_returns_empty_dict_on_error(self): + aws_provider = AwsProvider() + + with patch.object( + AwsProvider, + "get_available_aws_service_regions", + side_effect=Exception("boom"), + ): + assert aws_provider.generate_regional_clients("ec2") == {} + @mock_aws def test_get_tagged_resources(self): ec2_client = client("ec2", region_name=AWS_REGION_EU_CENTRAL_1) @@ -2065,7 +2171,8 @@ aws: assert not recovered_regions def test_get_regions_all_count(self): - assert len(AwsProvider.get_regions(partition=None)) == 39 + # 34 aws + 2 aws-cn + 2 aws-us-gov + 1 aws-eusc + 7 ISO regions + assert len(AwsProvider.get_regions(partition=None)) == 46 def test_get_regions_cn_count(self): assert len(AwsProvider.get_regions("aws-cn")) == 2 @@ -2073,6 +2180,12 @@ aws: def test_get_regions_aws_count(self): assert len(AwsProvider.get_regions(partition="aws")) == 34 + def test_get_regions_iso_count(self): + assert AwsProvider.get_regions(AWS_ISO_PARTITION) == { + AWS_REGION_ISO_EAST_1, + AWS_REGION_ISO_WEST_1, + } + def test_get_all_regions(self): with patch( "prowler.providers.aws.aws_provider.read_aws_regions_file", diff --git a/tests/providers/aws/utils.py b/tests/providers/aws/utils.py index b19efd3eec..c0cbff1c10 100644 --- a/tests/providers/aws/utils.py +++ b/tests/providers/aws/utils.py @@ -21,6 +21,7 @@ AWS_GOV_CLOUD_PARTITION = "aws-us-gov" AWS_CHINA_PARTITION = "aws-cn" AWS_EUSC_PARTITION = "aws-eusc" AWS_ISO_PARTITION = "aws-iso" +AWS_ISO_B_PARTITION = "aws-iso-b" # Root AWS Account AWS_ACCOUNT_NUMBER = "123456789012" @@ -54,7 +55,9 @@ AWS_REGION_GOV_CLOUD_US_EAST_1 = "us-gov-east-1" AWS_REGION_GOV_CLOUD_US_WEST_1 = "us-gov-west-1" # Iso Regions -AWS_REGION_ISO_GLOBAL = "aws-iso-global" +AWS_REGION_ISO_EAST_1 = "us-iso-east-1" +AWS_REGION_ISO_WEST_1 = "us-iso-west-1" +AWS_REGION_ISO_B_EAST_1 = "us-isob-east-1" # European Sovereign Cloud Regions AWS_REGION_EUSC_DE_EAST_1 = "eusc-de-east-1" diff --git a/util/update_aws_services_regions.py b/util/update_aws_services_regions.py index 40be038723..d3043f50db 100644 --- a/util/update_aws_services_regions.py +++ b/util/update_aws_services_regions.py @@ -4,6 +4,7 @@ import os import sys import boto3 +from botocore.session import Session as BotocoreSession # Logging config logging.basicConfig( @@ -13,91 +14,286 @@ logging.basicConfig( level=logging.INFO, ) -regions_by_service = {"services": {}} +# AWS partitions that the SSM global-infrastructure parameters do not publish. +# Their availability comes from the endpoints.json bundled with botocore, which +# is offline data and needs neither credentials nor network access. +ISO_PARTITIONS = ("aws-iso", "aws-iso-b", "aws-iso-e", "aws-iso-f") -logging.info("Recovering AWS Regions by Service") -client = boto3.client("ssm", region_name="us-east-1") -get_parameters_by_path_paginator = client.get_paginator("get_parameters_by_path") -# Get all AWS Available Services -for page in get_parameters_by_path_paginator.paginate( - Path="/aws/service/global-infrastructure/services" -): - for service in page["Parameters"]: - regions_by_service["services"][service["Value"]] = {} - # Get all AWS Regions for the specific service - regions = {"aws": [], "aws-cn": [], "aws-eusc": [], "aws-us-gov": []} - for page in get_parameters_by_path_paginator.paginate( - Path="/aws/service/global-infrastructure/services/" - + service["Value"] - + "/regions" - ): - for region in page["Parameters"]: - if "cn" in region["Value"]: - regions["aws-cn"].append(region["Value"]) - elif "eusc" in region["Value"]: - regions["aws-eusc"].append(region["Value"]) - elif "gov" in region["Value"]: - regions["aws-us-gov"].append(region["Value"]) - else: - regions["aws"].append(region["Value"]) - # Sort regions per partition - regions["aws"] = sorted(regions["aws"]) - regions["aws-cn"] = sorted(regions["aws-cn"]) - regions["aws-eusc"] = sorted(regions["aws-eusc"]) - regions["aws-us-gov"] = sorted(regions["aws-us-gov"]) - regions_by_service["services"][service["Value"]]["regions"] = regions +# Cost Explorer: botocore keys it by its endpoint prefix "ce", while the matrix +# (and the boto3 client name) calls it "costexplorer". Explicit rename override, +# since no boto3 service model resolves the "ce" prefix. +ISO_ENDPOINT_PREFIX_RENAMES = {"ce": "costexplorer"} -# Include the regions for the subservices and the services not present -logging.info("Updating subservices and the services not present in the original matrix") -# macie2 --> macie -regions_by_service["services"]["macie2"] = regions_by_service["services"]["macie"] -# bedrock-agent is not in SSM, and has different availability than bedrock -# See: https://docs.aws.amazon.com/bedrock/latest/userguide/agents-supported.html -regions_by_service["services"]["bedrock-agent"] = { - "regions": { - "aws": [ - "ap-northeast-1", - "ap-northeast-2", - "ap-south-1", - "ap-southeast-1", - "ap-southeast-2", - "ca-central-1", - "eu-central-1", - "eu-central-2", - "eu-west-1", - "eu-west-2", - "eu-west-3", - "sa-east-1", - "us-east-1", - "us-west-2", - ], - "aws-cn": [], - "aws-eusc": [], - "aws-us-gov": [ - "us-gov-west-1", - ], +# "transcribestreaming" is the streaming endpoint of Amazon Transcribe. The +# "transcribe" prefix is already present in the same partitions with the same +# regions, so mapping it would only duplicate data. Ignoring it is a deliberate +# decision, not a resolution failure. +ISO_IGNORED_ENDPOINT_PREFIXES = {"transcribestreaming"} + +# A service whose only endpoint in a partition is the partition-wide pseudo +# endpoint (for example "aws-iso-global") gets every region of that partition, +# matching how the matrix already records iam, organizations, route53 and +# support for aws and aws-us-gov. Cost Explorer is the exception: the matrix +# records it as a single-region service (aws: us-east-1, aws-cn: cn-northwest-1), +# so it only gets the region declared in the endpoint's credentialScope. +ISO_SINGLE_REGION_PARTITION_GLOBAL_SERVICES = {"costexplorer"} + + +def get_regions_by_service_from_ssm() -> dict: + """Get the AWS services and their regions for the partitions published in + the SSM global-infrastructure parameters: aws, aws-cn, aws-eusc and + aws-us-gov. + + Returns: + dict: The AWS regions matrix, keyed by service name. + """ + regions_by_service = {"services": {}} + + logging.info("Recovering AWS Regions by Service") + client = boto3.client("ssm", region_name="us-east-1") + get_parameters_by_path_paginator = client.get_paginator("get_parameters_by_path") + # Get all AWS Available Services + for page in get_parameters_by_path_paginator.paginate( + Path="/aws/service/global-infrastructure/services" + ): + for service in page["Parameters"]: + regions_by_service["services"][service["Value"]] = {} + # Get all AWS Regions for the specific service + regions = { + "aws": [], + "aws-cn": [], + "aws-eusc": [], + "aws-us-gov": [], + "aws-iso": [], + "aws-iso-b": [], + "aws-iso-e": [], + "aws-iso-f": [], + } + for page in get_parameters_by_path_paginator.paginate( + Path="/aws/service/global-infrastructure/services/" + + service["Value"] + + "/regions" + ): + for region in page["Parameters"]: + if "cn" in region["Value"]: + regions["aws-cn"].append(region["Value"]) + elif "eusc" in region["Value"]: + regions["aws-eusc"].append(region["Value"]) + elif "gov" in region["Value"]: + regions["aws-us-gov"].append(region["Value"]) + else: + regions["aws"].append(region["Value"]) + # Sort regions per partition + regions["aws"] = sorted(regions["aws"]) + regions["aws-cn"] = sorted(regions["aws-cn"]) + regions["aws-eusc"] = sorted(regions["aws-eusc"]) + regions["aws-us-gov"] = sorted(regions["aws-us-gov"]) + regions_by_service["services"][service["Value"]]["regions"] = regions + + return regions_by_service + + +def add_subservices_and_missing_services(regions_by_service: dict) -> None: + """Include the regions for the subservices and the services not present in + the original matrix.""" + logging.info( + "Updating subservices and the services not present in the original matrix" + ) + # macie2 --> macie + regions_by_service["services"]["macie2"] = regions_by_service["services"]["macie"] + # bedrock-agent is not in SSM, and has different availability than bedrock + # See: https://docs.aws.amazon.com/bedrock/latest/userguide/agents-supported.html + regions_by_service["services"]["bedrock-agent"] = { + "regions": { + "aws": [ + "ap-northeast-1", + "ap-northeast-2", + "ap-south-1", + "ap-southeast-1", + "ap-southeast-2", + "ca-central-1", + "eu-central-1", + "eu-central-2", + "eu-west-1", + "eu-west-2", + "eu-west-3", + "sa-east-1", + "us-east-1", + "us-west-2", + ], + "aws-cn": [], + "aws-eusc": [], + "aws-us-gov": [ + "us-gov-west-1", + ], + } } -} -# cognito --> cognito-idp -regions_by_service["services"]["cognito"] = regions_by_service["services"][ - "cognito-idp" -] -# opensearch --> es -regions_by_service["services"]["opensearch"] = regions_by_service["services"]["es"] -# elbv2 --> elb -regions_by_service["services"]["elbv2"] = regions_by_service["services"]["elb"] -# wafv2 --> waf -regions_by_service["services"]["wafv2"] = regions_by_service["services"]["waf"] -# wellarchitected --> wellarchitectedtool -regions_by_service["services"]["wellarchitected"] = regions_by_service["services"][ - "wellarchitectedtool" -] -# sesv2 --> ses -regions_by_service["services"]["sesv2"] = regions_by_service["services"]["ses"] + # cognito --> cognito-idp + regions_by_service["services"]["cognito"] = regions_by_service["services"][ + "cognito-idp" + ] + # opensearch --> es + regions_by_service["services"]["opensearch"] = regions_by_service["services"]["es"] + # elbv2 --> elb + regions_by_service["services"]["elbv2"] = regions_by_service["services"]["elb"] + # wafv2 --> waf + regions_by_service["services"]["wafv2"] = regions_by_service["services"]["waf"] + # wellarchitected --> wellarchitectedtool + regions_by_service["services"]["wellarchitected"] = regions_by_service["services"][ + "wellarchitectedtool" + ] + # sesv2 --> ses + regions_by_service["services"]["sesv2"] = regions_by_service["services"]["ses"] -# Write to file -parsed_matrix_regions_aws = f"{os.path.dirname(os.path.realpath(__name__))}/prowler/providers/aws/aws_regions_by_service.json" -logging.info(f"Writing {parsed_matrix_regions_aws}") -with open(parsed_matrix_regions_aws, "w") as outfile: - json.dump(regions_by_service, outfile, indent=2, sort_keys=True) - outfile.write("\n") + +def get_endpoint_prefix_to_services() -> dict: + """Map every botocore endpoint prefix to the set of boto3 service (client) + names using it. + + botocore's endpoints.json keys services by endpoint prefix, while the matrix + keys them by the boto3/SSM service name. The mapping is derived from the SDK + itself instead of being hand-written, so it stays correct as the SDK evolves + (monitoring -> cloudwatch, elasticloadbalancing -> elb and elbv2, states -> + stepfunctions, api.ecr -> ecr, ...). + + Returns: + dict: A dictionary mapping each endpoint prefix to a set of service names. + """ + session = BotocoreSession() + endpoint_prefix_to_services = {} + for service_name in session.get_available_services(): + endpoint_prefix = session.get_service_model(service_name).endpoint_prefix + endpoint_prefix_to_services.setdefault(endpoint_prefix, set()).add(service_name) + return endpoint_prefix_to_services + + +def resolve_matrix_services( + endpoint_prefix: str, endpoint_prefix_to_services: dict, services: dict +) -> set: + """Resolve a botocore endpoint prefix to the matrix service names it stands + for. + + Args: + - endpoint_prefix: The botocore endpoint prefix. + - endpoint_prefix_to_services: The map returned by get_endpoint_prefix_to_services. + - services: The services of the AWS regions matrix. + + Returns: + set: The matrix service names, empty when the prefix does not resolve. + """ + renamed_service = ISO_ENDPOINT_PREFIX_RENAMES.get(endpoint_prefix) + if renamed_service: + return {renamed_service} & set(services) + + service_names = endpoint_prefix_to_services.get(endpoint_prefix, set()) & set( + services + ) + if not service_names and endpoint_prefix in services: + service_names = {endpoint_prefix} + return service_names + + +def get_partition_global_service_regions( + service_names: set, service_data: dict, partition_regions: list +) -> list: + """Get the regions of a service whose only endpoint in the partition is the + partition-wide pseudo endpoint (for example "aws-iso-global"), which is not + a region and must never be recorded as one. + + Returns: + list: Every region of the partition, or only the credentialScope region + for the services the matrix records as single-region ones. + """ + partition_endpoint = service_data.get("partitionEndpoint") + credential_scope_region = ( + service_data.get("endpoints", {}) + .get(partition_endpoint, {}) + .get("credentialScope", {}) + .get("region") + ) + if service_names & ISO_SINGLE_REGION_PARTITION_GLOBAL_SERVICES: + if credential_scope_region in partition_regions: + return [credential_scope_region] + return [] + return list(partition_regions) + + +def add_iso_partitions_regions(regions_by_service: dict) -> None: + """Fill the aws-iso, aws-iso-b, aws-iso-e and aws-iso-f regions of every + service from the endpoints.json bundled with botocore. + + It runs after the subservices and the services not present in the original + matrix have been added, so it sees the final set of services: the aliases + sharing a single dict and the hand-written bedrock-agent entry all get their + ISO partition keys. + + Raises: + ValueError: If an endpoint prefix present in an ISO partition does not + resolve to a matrix service and is not explicitly ignored. + """ + logging.info("Updating the ISO partitions regions from the botocore endpoints") + services = regions_by_service["services"] + endpoints_data = BotocoreSession().get_data("endpoints") + endpoint_prefix_to_services = get_endpoint_prefix_to_services() + + # Every service carries every partition key, so the matrix stays rectangular + # even for the services with no presence at all in the ISO partitions. + for service in services.values(): + for partition in ISO_PARTITIONS: + service["regions"].setdefault(partition, []) + + for partition_data in endpoints_data["partitions"]: + partition = partition_data["partition"] + if partition not in ISO_PARTITIONS: + continue + partition_regions = sorted(partition_data.get("regions", {})) + for endpoint_prefix, service_data in partition_data.get("services", {}).items(): + if endpoint_prefix in ISO_IGNORED_ENDPOINT_PREFIXES: + continue + service_names = resolve_matrix_services( + endpoint_prefix, endpoint_prefix_to_services, services + ) + if not service_names: + raise ValueError( + f"The botocore endpoint prefix '{endpoint_prefix}', present in the " + f"'{partition}' partition, does not resolve to any service of the " + "AWS regions matrix. Dropping it silently would leave the service " + "out of the scans, so either add the prefix to " + "ISO_ENDPOINT_PREFIX_RENAMES with the matrix service name it " + "corresponds to, or add it to ISO_IGNORED_ENDPOINT_PREFIXES if it " + "must not be mapped." + ) + # Keep only the endpoints that are real regions of the partition, + # which drops the fips-* and the partition-wide pseudo endpoints. + regions = sorted( + set(service_data.get("endpoints", {})) & set(partition_regions) + ) + if not regions: + regions = get_partition_global_service_regions( + service_names, service_data, partition_regions + ) + for service_name in service_names: + services[service_name]["regions"][partition] = list(regions) + + +def write_regions_by_service(regions_by_service: dict) -> None: + """Write the AWS regions matrix to the file read by the AWS provider.""" + repository_root = os.path.dirname(os.path.dirname(os.path.realpath(__file__))) + parsed_matrix_regions_aws = ( + f"{repository_root}/prowler/providers/aws/aws_regions_by_service.json" + ) + logging.info(f"Writing {parsed_matrix_regions_aws}") + with open(parsed_matrix_regions_aws, "w") as outfile: + json.dump(regions_by_service, outfile, indent=2, sort_keys=True) + outfile.write("\n") + + +def main() -> None: + regions_by_service = get_regions_by_service_from_ssm() + add_subservices_and_missing_services(regions_by_service) + add_iso_partitions_regions(regions_by_service) + write_regions_by_service(regions_by_service) + + +if __name__ == "__main__": + main() From b378f1579869ed3f20fddb1712aa81610ab2d9e9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pedro=20Mart=C3=ADn?= Date: Fri, 11 Sep 2026 08:37:20 +0200 Subject: [PATCH 13/16] fix(aws): guard checks reading iam roles when unlisted (#12785) --- .../aws-checks-roles-unlisted.fixed.md | 1 + ...oject_uses_allowed_github_organizations.py | 2 +- ...rvice_trust_restricts_source_to_account.py | 2 +- ...e_profile_restricts_session_permissions.py | 4 +- ..._uses_allowed_github_organizations_test.py | 55 ++++++++++++++++++- ..._trust_restricts_source_to_account_test.py | 4 ++ ...file_restricts_session_permissions_test.py | 13 +++++ 7 files changed, 77 insertions(+), 4 deletions(-) create mode 100644 prowler/changelog.d/aws-checks-roles-unlisted.fixed.md diff --git a/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md b/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md new file mode 100644 index 0000000000..dc24ad1b49 --- /dev/null +++ b/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md @@ -0,0 +1 @@ +`rolesanywhere_profile_restricts_session_permissions`, `iam_role_service_trust_restricts_source_to_account` and `codebuild_project_uses_allowed_github_organizations` crashing with `TypeError` when `iam:ListRoles` is denied diff --git a/prowler/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations.py b/prowler/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations.py index 750a5a6fdd..11bb9a8b00 100644 --- a/prowler/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations.py +++ b/prowler/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations.py @@ -23,7 +23,7 @@ class codebuild_project_uses_allowed_github_organizations(Check): project_role = next( ( role - for role in iam_client.roles + for role in iam_client.roles or [] if role.arn == project.service_role_arn ), None, diff --git a/prowler/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account.py b/prowler/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account.py index 795f39a458..07aa4ac073 100644 --- a/prowler/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account.py +++ b/prowler/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account.py @@ -377,7 +377,7 @@ class iam_role_service_trust_restricts_source_to_account(Check): status. The sibling token-wildcard check carries the same note, for the same reason. """ findings = [] - for role in iam_client.roles: + for role in iam_client.roles or []: # Service-linked roles are excluded: their trust relationship is managed by # the service and cannot be edited, so a finding would not be actionable. if "aws-service-role" in role.arn: diff --git a/prowler/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions.py b/prowler/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions.py index 5138b74ff3..2960518a67 100644 --- a/prowler/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions.py +++ b/prowler/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions.py @@ -205,7 +205,9 @@ class rolesanywhere_profile_restricts_session_permissions(Check): not administrative, and disabled profiles. """ findings = [] - roles_by_arn = {role.arn: role for role in iam_client.roles} + # iam:ListRoles denied leaves roles as None: every referenced role is + # then unknown and the profile falls through to MANUAL. + roles_by_arn = {role.arn: role for role in (iam_client.roles or [])} for profile in rolesanywhere_client.profiles.values(): report = Check_Report_AWS(metadata=self.metadata(), resource=profile) role_statuses = { diff --git a/tests/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations_test.py b/tests/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations_test.py index bdabea03fa..0ac90d50d2 100644 --- a/tests/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations_test.py +++ b/tests/providers/aws/services/codebuild/codebuild_project_uses_allowed_github_organizations/codebuild_project_uses_allowed_github_organizations_test.py @@ -1,4 +1,4 @@ -from unittest.mock import patch +from unittest.mock import MagicMock, patch from boto3 import client from moto import mock_aws @@ -182,6 +182,59 @@ class Test_codebuild_project_uses_allowed_github_organizations: ) assert result[0].region == AWS_REGION_EU_WEST_1 + @mock_aws + def test_project_github_with_unlisted_roles(self): + # iam:ListRoles denied leaves iam_client.roles as None. + aws_provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1]) + codebuild_client = client("codebuild", region_name=AWS_REGION_EU_WEST_1) + codebuild_client.create_project( + name="test-project-github-unlisted-roles", + source={ + "type": "GITHUB", + "location": "https://github.com/allowed-org/repo", + }, + artifacts={"type": "NO_ARTIFACTS"}, + environment={ + "type": "LINUX_CONTAINER", + "image": "aws/codebuild/standard:4.0", + "computeType": "BUILD_GENERAL1_SMALL", + "environmentVariables": [], + }, + serviceRole=f"arn:aws:iam::{AWS_ACCOUNT_NUMBER}:role/codebuild-test-role", + ) + + from prowler.providers.aws.services.codebuild.codebuild_service import Codebuild + + iam_client = MagicMock() + iam_client.roles = None + + with ( + patch( + "prowler.providers.common.provider.Provider.get_global_provider", + return_value=aws_provider, + ), + patch( + "prowler.providers.aws.services.codebuild.codebuild_project_uses_allowed_github_organizations.codebuild_project_uses_allowed_github_organizations.codebuild_client", + new=Codebuild(aws_provider), + ), + patch( + "prowler.providers.aws.services.codebuild.codebuild_project_uses_allowed_github_organizations.codebuild_project_uses_allowed_github_organizations.iam_client", + new=iam_client, + ), + patch( + "prowler.providers.aws.services.codebuild.codebuild_project_uses_allowed_github_organizations.codebuild_project_uses_allowed_github_organizations.codebuild_client.audit_config", + {"codebuild_github_allowed_organizations": ["allowed-org"]}, + ), + ): + from prowler.providers.aws.services.codebuild.codebuild_project_uses_allowed_github_organizations.codebuild_project_uses_allowed_github_organizations import ( + codebuild_project_uses_allowed_github_organizations, + ) + + assert ( + len(codebuild_project_uses_allowed_github_organizations().execute()) + == 0 + ) + @mock_aws def test_project_github_no_codebuild_trusted_principal(self): aws_provider = set_mocked_aws_provider([AWS_REGION_EU_WEST_1]) diff --git a/tests/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account_test.py b/tests/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account_test.py index e01bdb36ba..66e96c571d 100644 --- a/tests/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account_test.py +++ b/tests/providers/aws/services/iam/iam_role_service_trust_restricts_source_to_account/iam_role_service_trust_restricts_source_to_account_test.py @@ -93,6 +93,10 @@ class Test_iam_role_service_trust_restricts_source_to_account: """An account with no roles produces no reports at all.""" assert len(_run([])) == 0 + def test_unlisted_roles_produce_no_reports(self): + # iam:ListRoles denied leaves iam_client.roles as None. + assert len(_run(None)) == 0 + def test_service_linked_role_skipped(self): """A service-linked role is excluded even when its trust policy would FAIL. diff --git a/tests/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions_test.py b/tests/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions_test.py index 09cdb3ae8d..230523239d 100644 --- a/tests/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions_test.py +++ b/tests/providers/aws/services/rolesanywhere/rolesanywhere_profile_restricts_session_permissions/rolesanywhere_profile_restricts_session_permissions_test.py @@ -472,6 +472,19 @@ class Test_rolesanywhere_profile_restricts_session_permissions: assert result[0].status == "MANUAL" assert "could not be evaluated" in result[0].status_extended + def test_unscoped_profile_with_unlisted_roles_is_manual(self): + # iam:ListRoles denied leaves iam_client.roles as None. + patches = _patched( + _build_client({PROFILE_ARN: _profile(role_arns=[ADMIN_ROLE_ARN])}) + ) + patches[-1].new.roles = None + with _enter(patches): + result = _run() + assert len(result) == 1 + assert result[0].status == "MANUAL" + assert ADMIN_ROLE_ARN in result[0].status_extended + assert "could not be evaluated" in result[0].status_extended + def test_unscoped_profile_without_roles_passes(self): with _enter(_patched(_build_client({PROFILE_ARN: _profile(role_arns=[])}))): result = _run() From 4727da7ca71a87be629a888184705eb3f2e4324e Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Fri, 11 Sep 2026 10:21:17 +0200 Subject: [PATCH 14/16] chore(changelog): v5.42.0 (#12794) Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com> --- api/CHANGELOG.md | 8 ++++++ ...ompliance-overviews-ingest-perf.changed.md | 1 - mcp_server/CHANGELOG.md | 8 ++++++ .../mcp-image-libuuid-cves.security.md | 1 - prowler/CHANGELOG.md | 27 +++++++++++++++++++ ...s-boto3-connect-timeout-default.changed.md | 1 - .../changelog.d/aws-boto3-timeouts.added.md | 1 - .../aws-checks-roles-unlisted.fixed.md | 1 - .../changelog.d/aws-iso-partitions.added.md | 1 - .../changelog.d/aws-iso-partitions.fixed.md | 1 - ...-region-honours-configured-region.fixed.md | 1 - .../aws-regional-clients-empty-dict.fixed.md | 1 - .../aws-retries-max-attempts-zero.fixed.md | 1 - ...service-regions-unknown-partition.fixed.md | 1 - .../compliance-catalog-integrity.fixed.md | 1 - ...nection-test-parallel-issue-types.fixed.md | 1 - ...ue-types-permission-gap-log-level.fixed.md | 1 - ...threatscore-azure-gcp-data-errors.fixed.md | 1 - .../trivy-cache-dir-configurable.fixed.md | 1 - ui/CHANGELOG.md | 20 ++++++++++++++ ...pendabot-audit-vulnerabilities.security.md | 1 - ...tegration-connection-poll-timeout.fixed.md | 1 - .../next-image-optimization-rce.security.md | 1 - .../posthog-toolbar-localhost.added.md | 1 - ui/changelog.d/scans-filter-actions.fixed.md | 1 - .../sharp-libheif-vulnerabilities.security.md | 1 - .../view-first-scan-tour-selector.fixed.md | 1 - 27 files changed, 63 insertions(+), 23 deletions(-) delete mode 100644 api/changelog.d/compliance-overviews-ingest-perf.changed.md delete mode 100644 mcp_server/changelog.d/mcp-image-libuuid-cves.security.md delete mode 100644 prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md delete mode 100644 prowler/changelog.d/aws-boto3-timeouts.added.md delete mode 100644 prowler/changelog.d/aws-checks-roles-unlisted.fixed.md delete mode 100644 prowler/changelog.d/aws-iso-partitions.added.md delete mode 100644 prowler/changelog.d/aws-iso-partitions.fixed.md delete mode 100644 prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md delete mode 100644 prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md delete mode 100644 prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md delete mode 100644 prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md delete mode 100644 prowler/changelog.d/compliance-catalog-integrity.fixed.md delete mode 100644 prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md delete mode 100644 prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md delete mode 100644 prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md delete mode 100644 prowler/changelog.d/trivy-cache-dir-configurable.fixed.md delete mode 100644 ui/changelog.d/dependabot-audit-vulnerabilities.security.md delete mode 100644 ui/changelog.d/integration-connection-poll-timeout.fixed.md delete mode 100644 ui/changelog.d/next-image-optimization-rce.security.md delete mode 100644 ui/changelog.d/posthog-toolbar-localhost.added.md delete mode 100644 ui/changelog.d/scans-filter-actions.fixed.md delete mode 100644 ui/changelog.d/sharp-libheif-vulnerabilities.security.md delete mode 100644 ui/changelog.d/view-first-scan-tour-selector.fixed.md diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 0ab4c9bfe1..318cd30d4f 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -4,6 +4,14 @@ All notable changes to the **Prowler API** are documented in this file. +## [1.43.0] (Prowler v5.42.0) + +### 🔄 Changed + +- Speed up compliance overview ingestion by reading ThreatScore mappings from the compliance template instead of each finding, generating time-ordered `uuid7` row ids and grouping inserted rows by framework and requirement [(#12738)](https://github.com/prowler-cloud/prowler/pull/12738) + +--- + ## [1.42.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/api/changelog.d/compliance-overviews-ingest-perf.changed.md b/api/changelog.d/compliance-overviews-ingest-perf.changed.md deleted file mode 100644 index 6e833d184e..0000000000 --- a/api/changelog.d/compliance-overviews-ingest-perf.changed.md +++ /dev/null @@ -1 +0,0 @@ -Speed up compliance overview ingestion by reading ThreatScore mappings from the compliance template instead of each finding, generating time-ordered `uuid7` row ids and grouping inserted rows by framework and requirement diff --git a/mcp_server/CHANGELOG.md b/mcp_server/CHANGELOG.md index 4c6c858d28..80bdabd28a 100644 --- a/mcp_server/CHANGELOG.md +++ b/mcp_server/CHANGELOG.md @@ -4,6 +4,14 @@ All notable changes to the **Prowler MCP Server** are documented in this file. +## [0.12.1] (Prowler v5.42.0) + +### 🔐 Security + +- `libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410 [(#12780)](https://github.com/prowler-cloud/prowler/pull/12780) + +--- + ## [0.12.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md b/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md deleted file mode 100644 index 602458c777..0000000000 --- a/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md +++ /dev/null @@ -1 +0,0 @@ -`libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410 diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 4161d195b8..7232bd41a0 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -4,6 +4,33 @@ All notable changes to the **Prowler SDK** are documented in this file. +## [5.42.0] (Prowler v5.42.0) + +### 🚀 Added + +- AWS ISO partitions (`aws-iso`, `aws-iso-b`, `aws-iso-e` and `aws-iso-f`) to the AWS service region matrix, generated from the endpoints data bundled with botocore [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- `--aws-connect-timeout` and `--aws-read-timeout` CLI flags, plus `PROWLER_AWS_BOTO3_CONNECT_TIMEOUT` and `PROWLER_AWS_BOTO3_READ_TIMEOUT` environment variables, to bound how long each AWS API call waits for an endpoint [(#12774)](https://github.com/prowler-cloud/prowler/pull/12774) + +### 🔄 Changed + +- AWS provider default Boto3 connect timeout lowered from 60 to 10 seconds, so scans in restricted-egress networks (VPC endpoints for a subset of services, GovCloud, private deployments) no longer spend 4 minutes per region on every service whose endpoint is unreachable [(#12774)](https://github.com/prowler-cloud/prowler/pull/12774) + +### 🐞 Fixed + +- Duplicate requirement ids, checks listed twice in a requirement and references to non-existent checks across compliance frameworks, now guarded by a catalog integrity test [(#12717)](https://github.com/prowler-cloud/prowler/pull/12717) +- Duplicate requirement `3.2.1` in ProwlerThreatScore for Azure (SQL auditing retention is now `3.2.4`) and doubled check id in requirement `1.2.1` of ProwlerThreatScore for GCP [(#12717)](https://github.com/prowler-cloud/prowler/pull/12717) +- Jira connection checks no longer log an error when a single project has no issue types visible to the integration user (typically a missing "create issue" permission on that project), a case the caller already treats as non-fatal [(#12742)](https://github.com/prowler-cloud/prowler/pull/12742) +- `Jira.test_connection()` now fetches each project's issue types concurrently instead of one request at a time, so accounts with many Jira projects no longer take tens of seconds (unbounded, scaling with the project count) to verify the connection [(#12742)](https://github.com/prowler-cloud/prowler/pull/12742) +- `AwsProvider.get_available_aws_service_regions()` now returns an empty set for an unknown service or partition instead of raising `KeyError`, so a service unavailable in the audited partition is skipped [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- `AwsProvider.generate_regional_clients()` now returns an empty dict instead of `None` when the regional clients cannot be built, a failure that surfaced later as `AttributeError: 'NoneType' object has no attribute 'values'` [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- `AwsProvider.get_global_region()` now returns a real region for each ISO partition instead of the `aws-iso-global` pseudo endpoint, which collapsed the four partitions into one answer [(#12759)](https://github.com/prowler-cloud/prowler/pull/12759) +- Bootstrap STS calls now use the session region when `PROWLER_AWS_PARTITION` is set and the region belongs to that partition, instead of always going to the partition's global STS region, which a deployment reached only through its own region's VPC endpoints cannot route to [(#12764)](https://github.com/prowler-cloud/prowler/pull/12764) +- The Image provider now uses the directory named by `TRIVY_CACHE_DIR` when one is set, instead of a fresh temporary directory it deletes afterwards, so a deployment can supply a vulnerability database it already holds and one with network access stops re-downloading the database for every image it scans [(#12773)](https://github.com/prowler-cloud/prowler/pull/12773) +- `--aws-retries-max-attempts 0` now disables Boto3 retries instead of being silently ignored in favour of the default of 3 [(#12774)](https://github.com/prowler-cloud/prowler/pull/12774) +- `rolesanywhere_profile_restricts_session_permissions`, `iam_role_service_trust_restricts_source_to_account` and `codebuild_project_uses_allowed_github_organizations` crashing with `TypeError` when `iam:ListRoles` is denied [(#12785)](https://github.com/prowler-cloud/prowler/pull/12785) + +--- + ## [5.41.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md b/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md deleted file mode 100644 index a204443b2a..0000000000 --- a/prowler/changelog.d/aws-boto3-connect-timeout-default.changed.md +++ /dev/null @@ -1 +0,0 @@ -AWS provider default Boto3 connect timeout lowered from 60 to 10 seconds, so scans in restricted-egress networks (VPC endpoints for a subset of services, GovCloud, private deployments) no longer spend 4 minutes per region on every service whose endpoint is unreachable diff --git a/prowler/changelog.d/aws-boto3-timeouts.added.md b/prowler/changelog.d/aws-boto3-timeouts.added.md deleted file mode 100644 index df5d6e4f2b..0000000000 --- a/prowler/changelog.d/aws-boto3-timeouts.added.md +++ /dev/null @@ -1 +0,0 @@ -`--aws-connect-timeout` and `--aws-read-timeout` CLI flags, plus `PROWLER_AWS_BOTO3_CONNECT_TIMEOUT` and `PROWLER_AWS_BOTO3_READ_TIMEOUT` environment variables, to bound how long each AWS API call waits for an endpoint diff --git a/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md b/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md deleted file mode 100644 index dc24ad1b49..0000000000 --- a/prowler/changelog.d/aws-checks-roles-unlisted.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`rolesanywhere_profile_restricts_session_permissions`, `iam_role_service_trust_restricts_source_to_account` and `codebuild_project_uses_allowed_github_organizations` crashing with `TypeError` when `iam:ListRoles` is denied diff --git a/prowler/changelog.d/aws-iso-partitions.added.md b/prowler/changelog.d/aws-iso-partitions.added.md deleted file mode 100644 index 41282ea353..0000000000 --- a/prowler/changelog.d/aws-iso-partitions.added.md +++ /dev/null @@ -1 +0,0 @@ -AWS ISO partitions (`aws-iso`, `aws-iso-b`, `aws-iso-e` and `aws-iso-f`) to the AWS service region matrix, generated from the endpoints data bundled with botocore diff --git a/prowler/changelog.d/aws-iso-partitions.fixed.md b/prowler/changelog.d/aws-iso-partitions.fixed.md deleted file mode 100644 index c3424d51ba..0000000000 --- a/prowler/changelog.d/aws-iso-partitions.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`AwsProvider.get_global_region()` now returns a real region for each ISO partition instead of the `aws-iso-global` pseudo endpoint, which collapsed the four partitions into one answer diff --git a/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md b/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md deleted file mode 100644 index 93a6c8d7b1..0000000000 --- a/prowler/changelog.d/aws-partition-bootstrap-region-honours-configured-region.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Bootstrap STS calls now use the session region when `PROWLER_AWS_PARTITION` is set and the region belongs to that partition, instead of always going to the partition's global STS region, which a deployment reached only through its own region's VPC endpoints cannot route to diff --git a/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md b/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md deleted file mode 100644 index bd5f7798ac..0000000000 --- a/prowler/changelog.d/aws-regional-clients-empty-dict.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`AwsProvider.generate_regional_clients()` now returns an empty dict instead of `None` when the regional clients cannot be built, a failure that surfaced later as `AttributeError: 'NoneType' object has no attribute 'values'` diff --git a/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md b/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md deleted file mode 100644 index 8eb2ad9e07..0000000000 --- a/prowler/changelog.d/aws-retries-max-attempts-zero.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`--aws-retries-max-attempts 0` now disables Boto3 retries instead of being silently ignored in favour of the default of 3 diff --git a/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md b/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md deleted file mode 100644 index 881ce2c94b..0000000000 --- a/prowler/changelog.d/aws-service-regions-unknown-partition.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`AwsProvider.get_available_aws_service_regions()` now returns an empty set for an unknown service or partition instead of raising `KeyError`, so a service unavailable in the audited partition is skipped diff --git a/prowler/changelog.d/compliance-catalog-integrity.fixed.md b/prowler/changelog.d/compliance-catalog-integrity.fixed.md deleted file mode 100644 index 1bfcf0462c..0000000000 --- a/prowler/changelog.d/compliance-catalog-integrity.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Duplicate requirement ids, checks listed twice in a requirement and references to non-existent checks across compliance frameworks, now guarded by a catalog integrity test diff --git a/prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md b/prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md deleted file mode 100644 index 85d3bad72a..0000000000 --- a/prowler/changelog.d/jira-connection-test-parallel-issue-types.fixed.md +++ /dev/null @@ -1 +0,0 @@ -`Jira.test_connection()` now fetches each project's issue types concurrently instead of one request at a time, so accounts with many Jira projects no longer take tens of seconds (unbounded, scaling with the project count) to verify the connection diff --git a/prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md b/prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md deleted file mode 100644 index 0d0a1f5477..0000000000 --- a/prowler/changelog.d/jira-issue-types-permission-gap-log-level.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Jira connection checks no longer log an error when a single project has no issue types visible to the integration user (typically a missing "create issue" permission on that project), a case the caller already treats as non-fatal diff --git a/prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md b/prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md deleted file mode 100644 index 0fb7547adb..0000000000 --- a/prowler/changelog.d/threatscore-azure-gcp-data-errors.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Duplicate requirement `3.2.1` in ProwlerThreatScore for Azure (SQL auditing retention is now `3.2.4`) and doubled check id in requirement `1.2.1` of ProwlerThreatScore for GCP diff --git a/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md b/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md deleted file mode 100644 index fd2f0ca117..0000000000 --- a/prowler/changelog.d/trivy-cache-dir-configurable.fixed.md +++ /dev/null @@ -1 +0,0 @@ -The Image provider now uses the directory named by `TRIVY_CACHE_DIR` when one is set, instead of a fresh temporary directory it deletes afterwards, so a deployment can supply a vulnerability database it already holds and one with network access stops re-downloading the database for every image it scans diff --git a/ui/CHANGELOG.md b/ui/CHANGELOG.md index eeadba64b8..8687ddde54 100644 --- a/ui/CHANGELOG.md +++ b/ui/CHANGELOG.md @@ -4,6 +4,26 @@ All notable changes to the **Prowler UI** are documented in this file. +## [1.42.0] (Prowler v5.42.0) + +### 🚀 Added + +- PostHog Toolbar support in development with separate ingestion and app hosts [(#12582)](https://github.com/prowler-cloud/prowler/pull/12582) + +### 🐞 Fixed + +- Scan Jobs onboarding tour no longer targets an unmounted In Progress row from other tabs [(#12705)](https://github.com/prowler-cloud/prowler/pull/12705) +- Integration connection test polling now waits up to ~3 minutes instead of ~57 seconds before giving up, so it no longer reports a false failure on slower checks (e.g. Jira accounts with many projects) that were still going to succeed [(#12742)](https://github.com/prowler-cloud/prowler/pull/12742) +- Scans page filter widths and action button styling, with Launch Scan and Import Findings grouped beside the tabs and sized consistently with Configure Mutelist [(#12781)](https://github.com/prowler-cloud/prowler/pull/12781) + +### 🔐 Security + +- `nanoid` to 5.1.16, `js-yaml` to 4.3.1 and `postcss` to 8.5.23, plus transitive `hono`, `@hono/node-server`, `browserslist`, `qs`, `dompurify`, `brace-expansion`, `fast-uri`, `ip-address`, `mermaid`, `body-parser` and `@humanfs/node` to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low) [(#12758)](https://github.com/prowler-cloud/prowler/pull/12758) +- `next` to 16.3.3, patching an unauthenticated remote code execution in the Image Optimization API when AVIF files are used (GHSA-2xp9-vwfh-vxw4) [(#12778)](https://github.com/prowler-cloud/prowler/pull/12778) +- `sharp` to 0.35.4, patching two libheif vulnerabilities reachable through image decoding (GHSA-rgj7-g3m4-5g8c) [(#12778)](https://github.com/prowler-cloud/prowler/pull/12778) + +--- + ## [1.41.0] (Prowler v5.41.0) ### 🚀 Added diff --git a/ui/changelog.d/dependabot-audit-vulnerabilities.security.md b/ui/changelog.d/dependabot-audit-vulnerabilities.security.md deleted file mode 100644 index 9d030097f0..0000000000 --- a/ui/changelog.d/dependabot-audit-vulnerabilities.security.md +++ /dev/null @@ -1 +0,0 @@ -`nanoid` to 5.1.16, `js-yaml` to 4.3.1 and `postcss` to 8.5.23, plus transitive `hono`, `@hono/node-server`, `browserslist`, `qs`, `dompurify`, `brace-expansion`, `fast-uri`, `ip-address`, `mermaid`, `body-parser` and `@humanfs/node` to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low) diff --git a/ui/changelog.d/integration-connection-poll-timeout.fixed.md b/ui/changelog.d/integration-connection-poll-timeout.fixed.md deleted file mode 100644 index 629eef9a45..0000000000 --- a/ui/changelog.d/integration-connection-poll-timeout.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Integration connection test polling now waits up to ~3 minutes instead of ~57 seconds before giving up, so it no longer reports a false failure on slower checks (e.g. Jira accounts with many projects) that were still going to succeed diff --git a/ui/changelog.d/next-image-optimization-rce.security.md b/ui/changelog.d/next-image-optimization-rce.security.md deleted file mode 100644 index 5000fa95f8..0000000000 --- a/ui/changelog.d/next-image-optimization-rce.security.md +++ /dev/null @@ -1 +0,0 @@ -`next` to 16.3.3, patching an unauthenticated remote code execution in the Image Optimization API when AVIF files are used (GHSA-2xp9-vwfh-vxw4) diff --git a/ui/changelog.d/posthog-toolbar-localhost.added.md b/ui/changelog.d/posthog-toolbar-localhost.added.md deleted file mode 100644 index a2aa815a1c..0000000000 --- a/ui/changelog.d/posthog-toolbar-localhost.added.md +++ /dev/null @@ -1 +0,0 @@ -PostHog Toolbar support in development with separate ingestion and app hosts diff --git a/ui/changelog.d/scans-filter-actions.fixed.md b/ui/changelog.d/scans-filter-actions.fixed.md deleted file mode 100644 index 3220d59a8e..0000000000 --- a/ui/changelog.d/scans-filter-actions.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Scans page filter widths and action button styling, with Launch Scan and Import Findings grouped beside the tabs and sized consistently with Configure Mutelist diff --git a/ui/changelog.d/sharp-libheif-vulnerabilities.security.md b/ui/changelog.d/sharp-libheif-vulnerabilities.security.md deleted file mode 100644 index 75296b55dc..0000000000 --- a/ui/changelog.d/sharp-libheif-vulnerabilities.security.md +++ /dev/null @@ -1 +0,0 @@ -`sharp` to 0.35.4, patching two libheif vulnerabilities reachable through image decoding (GHSA-rgj7-g3m4-5g8c) diff --git a/ui/changelog.d/view-first-scan-tour-selector.fixed.md b/ui/changelog.d/view-first-scan-tour-selector.fixed.md deleted file mode 100644 index 13f56ac446..0000000000 --- a/ui/changelog.d/view-first-scan-tour-selector.fixed.md +++ /dev/null @@ -1 +0,0 @@ -Scan Jobs onboarding tour no longer targets an unmounted In Progress row from other tabs From c08cb65d8480fae1f37216824d84a1cfc3503d2e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pedro=20Mart=C3=ADn?= Date: Fri, 11 Sep 2026 12:11:44 +0200 Subject: [PATCH 15/16] chore(changelog): v5.42.0 highlights (#12795) Co-authored-by: Pepe Fagoaga --- docs/changelog.mdx | 56 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+) diff --git a/docs/changelog.mdx b/docs/changelog.mdx index 40df5cb9df..db0bb4409c 100644 --- a/docs/changelog.mdx +++ b/docs/changelog.mdx @@ -4,6 +4,62 @@ description: "New features and improvements in each Prowler release" rss: true --- + + ### ☁️ AWS — ISO Partitions + + Prowler now resolves regions and services for the AWS ISO partitions (`aws-iso`, `aws-iso-b`, `aws-iso-e` and `aws-iso-f`) the same way it does for the commercial, China, European Sovereign Cloud and GovCloud partitions. The region matrix is filled from the endpoint metadata bundled with botocore, which needs no credentials or network access, so it covers partitions that are air-gapped from the internet. Scanning them no longer requires a hand-edited `aws_regions_by_service.json`: ISO regions such as `us-isob-east-1` are accepted by `--region` and `--excluded-region`. + + Deployments that declare `PROWLER_AWS_PARTITION` also keep their bootstrap STS calls in the configured region when it belongs to that partition. An install in `us-gov-west-1` that reaches AWS only through its own VPC endpoints is no longer sent to `us-gov-east-1`, where the connection check and the scan used to time out. + + Read more in the [AWS Regions and Partitions documentation](https://docs.prowler.com/user-guide/providers/aws/regions-and-partitions). + + ### ⏱️ AWS — Configurable Timeouts for Restricted Networks + + Scans from networks with restricted egress (VPC endpoints for only some services, GovCloud or private deployments) could take hours: Boto3 waits 60 seconds to connect by default and retries connection errors, so every service without a reachable endpoint cost up to four 60-second attempts in every region. Prowler now lowers the default connect timeout to 10 seconds, keeps the read timeout at 60 seconds, and exposes both through `--aws-connect-timeout` and `--aws-read-timeout`, or through the `PROWLER_AWS_BOTO3_CONNECT_TIMEOUT` and `PROWLER_AWS_BOTO3_READ_TIMEOUT` environment variables for deployments without a CLI. `--aws-retries-max-attempts 0` now disables retries instead of silently falling back to three, leaving a single attempt per call. + + Read more in the [Boto3 configuration documentation](https://docs.prowler.com/user-guide/providers/aws/boto3-configuration). + + ### 🐳 Image Provider — Reusable Vulnerability Database + + The Image provider now honors `TRIVY_CACHE_DIR`. When the variable names a directory, Trivy keeps its vulnerability database there and Prowler leaves the directory in place after the scan, so the database is downloaded once instead of on every scan. Hosts without internet access can now scan images by pointing `TRIVY_CACHE_DIR` at a pre-populated database and setting `TRIVY_SKIP_DB_UPDATE=true`. Without the variable, the temporary cache is created and removed as before. + + Read more in the [Image provider documentation](https://docs.prowler.com/user-guide/providers/image/getting-started-image#vulnerability-database-cache). + + ### 🎫 Jira Integration — Faster Connection Test + + Testing a Jira integration no longer reports a false failure on accounts with many projects. The connection test fetched the issue types of every project one request at a time, which could outlast the wait in the UI even when the check was about to succeed. Issue types are now fetched concurrently, a project whose issue types the integration user cannot see is no longer logged as an error, and the Integrations page keeps following the connection test instead of giving up after about a minute. + + Read more in the [Jira integration documentation](https://docs.prowler.com/user-guide/tutorials/prowler-app-jira-integration). + + ### 📚 Compliance — Catalog Integrity Fixes + + A new integrity test runs over every compliance framework, asserting unique requirement IDs, no check listed twice within a requirement, and that every referenced check exists for its provider. The fixes it drove span 42 frameworks across AWS, Azure, GCP, GitHub, Kubernetes and Microsoft 365: + + - **Duplicate requirement IDs:** identical copies are removed, and distinct requirements that shared an ID get their own, such as `1.10` in CIS AWS 5.0 and `rc_rp_1` for RC.RP-1 in NIST CSF 1.1. In Prowler ThreatScore for Azure, SQL auditing retention moves from `3.2.1` to `3.2.4`, and requirement `1.2.1` of Prowler ThreatScore for GCP now points to `iam_sa_no_user_managed_keys`. + - **Stale check references:** checks that no longer exist are replaced with their current name when there is a direct equivalent, or removed so the requirement reports as manual. Most of these were in the FedRAMP 20x KSI frameworks. + + Renamed requirement IDs appear as new requirements for scans run after the upgrade. + + The compliance overview task that runs after every scan is also faster: ThreatScore mappings are read once from the compliance template instead of from every finding, and rows are inserted with time-ordered `uuid7` IDs grouped by framework and requirement. + + Read more in the [Compliance documentation](https://docs.prowler.com/user-guide/compliance/tutorials/compliance). + + ### 🔍 Checks + + `rolesanywhere_profile_restricts_session_permissions`, `iam_role_service_trust_restricts_source_to_account` and `codebuild_project_uses_allowed_github_organizations` no longer crash with `TypeError` when the scanning role is denied `iam:ListRoles`, which dropped every finding of those checks for the account. Without the role inventory, an enabled IAM Roles Anywhere profile without session scoping reports `MANUAL`, and CodeBuild projects whose service role cannot be resolved are skipped. + + Explore all AWS checks at [Prowler Hub](https://hub.prowler.com/check?provider=aws). + + ### 🔐 Security Updates + + - `next` upgraded to 16.3.3 in the UI, patching unauthenticated remote code execution through AVIF image optimization ([GHSA-2xp9-vwfh-vxw4](https://github.com/advisories/GHSA-2xp9-vwfh-vxw4)) and on Windows-hosted servers ([GHSA-p293-qw3h-jr36](https://github.com/advisories/GHSA-p293-qw3h-jr36)). + - `sharp` upgraded to 0.35.4 in the UI, patching libheif image-decoding vulnerabilities ([GHSA-rgj7-g3m4-5g8c](https://github.com/advisories/GHSA-rgj7-g3m4-5g8c)). + - `nanoid`, `js-yaml` and `postcss`, plus eleven transitive UI dependencies, upgraded to patched versions, resolving 40 npm audit advisories (21 high, 15 moderate, 4 low). + - `libuuid` upgraded to 2.41.6-r1 in the MCP Server image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410. + + See the [full release notes on GitHub](https://github.com/prowler-cloud/prowler/releases/tag/5.42.0) for the complete list of changes. + + ### 📥 Scans — Import Findings from the Browser From 282fe5b46b96e5bcb7a22d0faca6519acffa3978 Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Fri, 11 Sep 2026 13:23:08 +0200 Subject: [PATCH 16/16] chore(release): Bump versions to v5.43.0 (#12797) Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com> --- .env | 2 +- api/pyproject.toml | 2 +- api/src/backend/api/specs/v1.yaml | 2 +- api/uv.lock | 2 +- docs/getting-started/installation/prowler-app.mdx | 4 ++-- prowler/config/config.py | 2 +- pyproject.toml | 2 +- uv.lock | 2 +- 8 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.env b/.env index 018b25a8a9..721d25f4bf 100644 --- a/.env +++ b/.env @@ -158,7 +158,7 @@ SENTRY_RELEASE=local # REO_DEV_CLIENT_ID= #### Prowler release version #### -NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.42.0 +NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.43.0 # Social login credentials SOCIAL_GOOGLE_OAUTH_CALLBACK_URL="${AUTH_URL}/api/auth/callback/google" diff --git a/api/pyproject.toml b/api/pyproject.toml index f9af7f04be..00b50e8300 100644 --- a/api/pyproject.toml +++ b/api/pyproject.toml @@ -71,7 +71,7 @@ name = "prowler-api" package-mode = false # Needed for the SDK compatibility requires-python = ">=3.11,<3.13" -version = "1.43.0" +version = "1.44.0" # Shared ruff baseline (kept in sync with mcp_server/pyproject.toml). # target-version tracks this project's lowest supported Python. diff --git a/api/src/backend/api/specs/v1.yaml b/api/src/backend/api/specs/v1.yaml index 4b5cebdb2e..ab57f94702 100644 --- a/api/src/backend/api/specs/v1.yaml +++ b/api/src/backend/api/specs/v1.yaml @@ -1,7 +1,7 @@ openapi: 3.0.3 info: title: Prowler API - version: 1.43.0 + version: 1.44.0 description: |- Prowler API specification. diff --git a/api/uv.lock b/api/uv.lock index bfaad1f98a..a835e2f223 100644 --- a/api/uv.lock +++ b/api/uv.lock @@ -4938,7 +4938,7 @@ dependencies = [ [[package]] name = "prowler-api" -version = "1.43.0" +version = "1.44.0" source = { virtual = "." } dependencies = [ { name = "cartography" }, diff --git a/docs/getting-started/installation/prowler-app.mdx b/docs/getting-started/installation/prowler-app.mdx index e9ec980e09..b27b7142d2 100644 --- a/docs/getting-started/installation/prowler-app.mdx +++ b/docs/getting-started/installation/prowler-app.mdx @@ -128,8 +128,8 @@ To update the environment file: Edit the `.env` file and change version values: ```env -PROWLER_UI_VERSION="5.41.0" -PROWLER_API_VERSION="5.41.0" +PROWLER_UI_VERSION="5.42.0" +PROWLER_API_VERSION="5.42.0" ``` diff --git a/prowler/config/config.py b/prowler/config/config.py index f1aa774ce2..21929b5099 100644 --- a/prowler/config/config.py +++ b/prowler/config/config.py @@ -52,7 +52,7 @@ class _MutableTimestamp: timestamp = _MutableTimestamp(datetime.today()) timestamp_utc = _MutableTimestamp(datetime.now(timezone.utc)) -prowler_version = "5.42.0" +prowler_version = "5.43.0" html_logo_url = "https://github.com/prowler-cloud/prowler/" square_logo_img = "https://raw.githubusercontent.com/prowler-cloud/prowler/dc7d2d5aeb92fdf12e8604f42ef6472cd3e8e889/docs/img/prowler-logo-black.png" aws_logo = "https://user-images.githubusercontent.com/38561120/235953920-3e3fba08-0795-41dc-b480-9bea57db9f2e.png" diff --git a/pyproject.toml b/pyproject.toml index cabf2740f7..8e49417f09 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -143,7 +143,7 @@ maintainers = [{name = "Prowler Engineering", email = "engineering@prowler.com"} name = "prowler" readme = "README.md" requires-python = ">=3.10,<3.14" -version = "5.42.0" +version = "5.43.0" [project.scripts] prowler = "prowler.__main__:prowler" diff --git a/uv.lock b/uv.lock index fe04be07b8..ca1afd8346 100644 --- a/uv.lock +++ b/uv.lock @@ -3752,7 +3752,7 @@ wheels = [ [[package]] name = "prowler" -version = "5.42.0" +version = "5.43.0" source = { editable = "." } dependencies = [ { name = "alibabacloud-actiontrail20200706" },