HugoPBrito
d35e5a4bec
fix: enforce cloudflare token/key format validation
...
- Reject API key-shaped values in Cloudflare api_token
- Validate Cloudflare api_key as 32-character hexadecimal format
- Add UI form validation to prevent token/key cross-input
- Update API and UI changelog entries for the current PR
2026-03-02 10:14:13 +01:00
HugoPBrito
861be13b7d
Merge branch 'master' of https://github.com/prowler-cloud/prowler into ensure-key-format-cloudflare
2026-03-02 09:49:06 +01:00
Pepe Fagoaga
8af9b333c9
ci: restore persist credentials when no output is generated ( #10211 )
2026-03-02 09:14:02 +01:00
Pepe Fagoaga
4e71a9dcf1
ci(security): Add zizmor ( #10208 )
2026-03-02 08:25:13 +01:00
Pepe Fagoaga
7adcbed727
fix(ci): zizmor security improvements ( #10207 )
2026-03-02 08:24:51 +01:00
Andoni Alonso
8be218b29f
fix(ci): harden GitHub Actions workflows against expression injection ( #10200 )
2026-03-01 19:58:43 +01:00
Alejandro Bailo
80e84d1da4
fix(ui): stabilize provider wizard modal and DataTable rendering ( #10194 )
2026-02-27 14:35:13 +01:00
HugoPBrito
62809e523e
docs(api): add changelog entry for cloudflare token fix
2026-02-27 14:05:55 +01:00
HugoPBrito
5ff6c3c35f
fix(api): reject cloudflare api key in token field
...
- Add serializer validation for Cloudflare api_token values
- Reject 32-character hexadecimal values in token credentials
- Add serializer tests for valid token and api key-shaped token
2026-02-27 14:02:46 +01:00
mintlify[bot]
fff80a920b
chore(docs): Add Reo tracking beacon ( #10193 )
...
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-02-27 13:07:46 +01:00
mintlify[bot]
90a4579230
docs(install): Add missing notes for Docker Compose installation ( #10192 )
...
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-02-27 12:53:59 +01:00
Pedro Martín
2f44be8db4
docs(aws): add AWS Organizations ( #10183 )
2026-02-27 12:28:16 +01:00
Alejandro Bailo
288593d01e
fix(ui): patch npm transitive dependency vulnerabilities ( #10187 )
2026-02-27 10:31:20 +01:00
Alejandro Bailo
ddb6c03c0e
test(ui): fix provider E2E test selectors and reliability ( #10178 )
2026-02-27 10:12:54 +01:00
mintlify[bot]
79d4476713
docs(import): Add billing impact section to Findings Import ( #10186 )
...
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-02-27 10:11:16 +01:00
Anthony
06f6e8b99b
fix(ui): apply provider/account filters to Findings Severity Over Time chart ( #10103 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2026-02-27 10:10:47 +01:00
Adrián Peña
8ee4a9e3fc
fix(sdk): scope scan_id by provider and account ( #10184 )
2026-02-26 19:19:29 +01:00
Adrián Peña
336cbe1844
feat(ingestions): allow multiple scan_ids and providers inside the ocsf ( #10182 )
2026-02-26 17:56:21 +01:00
Andoni Alonso
c8ce590039
feat(m365): add entra_default_app_management_policy_enabled security check ( #9898 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2026-02-26 16:14:29 +01:00
Josema Camacho
b3a67fa1a0
feat(api): add accept header text/plain to attack paths query endpoints for support llm-friendly output ( #10162 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2026-02-26 12:53:58 +01:00
Adrián Peña
902558f2d4
feat(api): block attack-paths-scans custom queries and schema endpoints ( #10177 )
2026-02-26 12:27:52 +01:00
Alan Buscaglia
09302f9d7d
fix(ci): include E2E test paths in impact analysis module matching ( #10176 )
2026-02-26 12:10:36 +01:00
Andoni Alonso
df09b14c75
feat(m365): add entra_all_apps_conditional_access_coverage security check ( #9902 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2026-02-26 11:37:09 +01:00
Adrián Peña
eacb3430cb
fix(api): recalc tenant compliance summary after provider deletion ( #10172 )
2026-02-26 11:18:15 +01:00
Alan Buscaglia
c151d08712
fix(skills): add Bash 3.2 compatibility to sync.sh ( #9841 )
2026-02-26 10:26:22 +01:00
Pedro Martín
fac089ab78
feat(compliance): add SecNumCloud for AWS ( #10117 )
2026-02-26 09:31:19 +01:00
Rubén De la Torre Vico
d15cabee20
feat(ui): add attack paths tools to Lighthouse allowed list ( #10175 )
2026-02-25 16:42:13 +01:00
Andoni Alonso
ee7ecabe29
docs: add pre-configured GitHub PAT creation links ( #10174 )
2026-02-25 14:13:53 +01:00
Alejandro Bailo
2a58781e37
test(ui): update E2E page objects and improve test stability ( #10158 )
2026-02-25 13:30:54 +01:00
Alejandro Bailo
f403971885
feat(ui): add AWS Organizations bulk connect flow ( #10157 )
2026-02-25 13:16:34 +01:00
Alejandro Bailo
7935e926ac
feat(ui): replace route-based provider flow with modal wizard ( #10156 )
2026-02-25 13:08:17 +01:00
Alejandro Bailo
231bfd6f41
feat(ui): add organization server actions and scan launching ( #10155 )
2026-02-25 12:56:26 +01:00
Alejandro Bailo
fe8d5893af
feat(ui): add organization and wizard types and stores ( #10154 )
2026-02-25 12:45:15 +01:00
Hugo Pereira Brito
db1db7d366
feat(m365): add entra_require_mfa_for_management_api security check ( #10150 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2026-02-25 12:29:23 +01:00
Alejandro Bailo
6d9ef78df1
style(ui): improve shadcn primitives and add shared components ( #10153 )
2026-02-25 12:19:08 +01:00
lydiavilchez
9ee8072572
feat(googleworkspace): add Google Workspace provider with directory service and super admin check ( #10022 )
2026-02-25 12:17:13 +01:00
Hugo Pereira Brito
6935c4eb1b
feat(m365): add entra_app_enforced_restrictions security check ( #10058 )
2026-02-25 11:53:35 +01:00
Adrián Peña
e47f2b4033
fix(api): harden security hub retries ( #10144 )
2026-02-25 11:34:41 +01:00
Rubén De la Torre Vico
7077a56331
chore(mcp_server): bump MCP Server package version to 0.4.0 ( #10171 )
2026-02-25 11:31:35 +01:00
mintlify[bot]
964cc45b14
docs(rbac): add permissions table with scope ( #10163 )
...
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-02-25 11:17:17 +01:00
Rubén De la Torre Vico
a8e504887b
feat(mcp_server): add tools related with attack paths ( #10145 )
2026-02-25 10:56:40 +01:00
mintlify[bot]
2115344de8
docs: add findings ingestion documentation ( #10159 )
...
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-02-24 19:15:46 +01:00
Pepe Fagoaga
6962622fd2
fix(aws): filter VPC endpoint services by audited account to prevent AccessDenied errors ( #10152 )
...
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com >
Co-authored-by: jfagoagas <16007882+jfagoagas@users.noreply.github.com >
2026-02-24 18:30:31 +01:00
Adrián Peña
2a4ee830cc
feat(sdk): add --export-ocsf flag for OCSF ingestion to Prowler Cloud ( #10095 )
2026-02-24 17:47:35 +01:00
Josema Camacho
247bde1ef4
feat(attack-paths): add custom query and cartography schema endpoints ( #10149 )
2026-02-24 15:49:50 +01:00
Andoni Alonso
c159181d27
feat(api): add Image provider support for container image scanning ( #10128 )
2026-02-24 13:06:34 +01:00
Daniel Barranquero
030d053c84
chore(openstack): support multi-region in the same provider ( #10135 )
2026-02-24 12:50:52 +01:00
Prowler Bot
61076c755f
feat(oraclecloud): Update commercial regions ( #10134 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-02-24 11:37:25 +01:00
Andoni Alonso
75d01efc0d
feat(m365): add entra_conditional_access_policy_emergency_access_exclusion security check ( #9903 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2026-02-24 11:35:31 +01:00
Josema Camacho
e688e60fde
feat(attack-paths): configure Neo4j for read-only queries ( #10140 )
2026-02-24 10:15:22 +01:00