HugoPBrito
d35e5a4bec
fix: enforce cloudflare token/key format validation
...
- Reject API key-shaped values in Cloudflare api_token
- Validate Cloudflare api_key as 32-character hexadecimal format
- Add UI form validation to prevent token/key cross-input
- Update API and UI changelog entries for the current PR
2026-03-02 10:14:13 +01:00
HugoPBrito
62809e523e
docs(api): add changelog entry for cloudflare token fix
2026-02-27 14:05:55 +01:00
HugoPBrito
5ff6c3c35f
fix(api): reject cloudflare api key in token field
...
- Add serializer validation for Cloudflare api_token values
- Reject 32-character hexadecimal values in token credentials
- Add serializer tests for valid token and api key-shaped token
2026-02-27 14:02:46 +01:00
Josema Camacho
b3a67fa1a0
feat(api): add accept header text/plain to attack paths query endpoints for support llm-friendly output ( #10162 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2026-02-26 12:53:58 +01:00
Adrián Peña
902558f2d4
feat(api): block attack-paths-scans custom queries and schema endpoints ( #10177 )
2026-02-26 12:27:52 +01:00
Adrián Peña
eacb3430cb
fix(api): recalc tenant compliance summary after provider deletion ( #10172 )
2026-02-26 11:18:15 +01:00
Adrián Peña
e47f2b4033
fix(api): harden security hub retries ( #10144 )
2026-02-25 11:34:41 +01:00
Josema Camacho
247bde1ef4
feat(attack-paths): add custom query and cartography schema endpoints ( #10149 )
2026-02-24 15:49:50 +01:00
Andoni Alonso
c159181d27
feat(api): add Image provider support for container image scanning ( #10128 )
2026-02-24 13:06:34 +01:00
Daniel Barranquero
030d053c84
chore(openstack): support multi-region in the same provider ( #10135 )
2026-02-24 12:50:52 +01:00
Josema Camacho
e688e60fde
feat(attack-paths): configure Neo4j for read-only queries ( #10140 )
2026-02-24 10:15:22 +01:00
Adrián Peña
584455a12a
feat(api): add finding groups summaries ( #9961 )
...
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com >
2026-02-23 13:44:45 +01:00
Josema Camacho
75c7f61513
feat(api): private labels and properties in Attack Paths graph - phase 1 ( #10124 )
2026-02-23 11:30:26 +01:00
Josema Camacho
b5d2a75151
feat(api): filter Attack Paths query results by provider_id ( #10118 )
2026-02-23 11:06:30 +01:00
Josema Camacho
c12f27413d
fix(api): handle provider deletion race condition in attack paths scan ( #10116 )
2026-02-23 10:53:58 +01:00
Josema Camacho
a9c7351489
fix(api): upgrade cartography to 0.129.0 and neo4j driver to 6.x ( #10110 )
2026-02-18 16:28:24 +01:00
Alan Buscaglia
639333b540
feat(ui): setup vitest with react testing library and TDD workflow ( #9925 )
2026-02-18 11:25:50 +01:00
Josema Camacho
be3be3eb62
fix(api): clean up temp Neo4j databases on scan failure and provider deletion ( #10101 )
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-02-18 10:18:34 +01:00
Daniel Barranquero
338d514197
fix(api): gcp project id validation for legacy projects ( #10078 )
2026-02-18 10:11:07 +01:00
Josema Camacho
7698cdce2e
feat(attack-paths): add graph_data_ready field to decouple query availability from scan state ( #10089 )
...
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com >
2026-02-17 17:29:36 +01:00
Pedro Martín
e8c48b7827
feat(reporting): support CSA CCM PDF reports ( #10088 )
2026-02-17 09:48:45 +01:00
Josema Camacho
bb34f6cc3d
refactor(api): remove graph_database and is_graph_database_deleted from AttackPathsScan ( #10077 )
2026-02-16 12:46:49 +01:00
Josema Camacho
02b58d8a31
fix(api): mark attack paths scan as failed when celery task fails ( #10065 )
2026-02-13 13:20:38 +01:00
Josema Camacho
ceb4691c36
build(deps): bump cryptography to 44.0.3 and py-ocsf-models to 0.8.1 ( #10059 )
2026-02-13 12:36:38 +01:00
Pedro Martín
961b247d36
feat(compliance): add csa ccm for the alibabacloud provider ( #10061 )
2026-02-13 10:36:29 +01:00
Pedro Martín
627088e214
feat(compliance): add csa ccm for the oraclecloud provider ( #10057 )
2026-02-12 18:06:51 +01:00
Josema Camacho
93ac38ca90
feat(attack-pahts--aws-queries): The rest of Path Finding paths queries ( #10008 )
2026-02-12 17:09:08 +01:00
Daniel Barranquero
b94c8a5e5e
feat(api): add OpenStack provider support ( #10003 )
2026-02-12 14:40:19 +01:00
dependabot[bot]
1f4e308374
build(deps): bump pillow from 12.1.0 to 12.1.1 in /api ( #10027 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-02-12 14:26:03 +01:00
Pedro Martín
4d569d5b79
feat(compliance): add csa ccm for the gcp provider ( #10042 )
2026-02-12 14:13:24 +01:00
Pedro Martín
29090adb03
feat(compliance): add csa ccm for the azure provider ( #10039 )
2026-02-12 13:35:22 +01:00
Pedro Martín
f55983a77d
feat(compliance): add csa ccm 4.0 for the aws provider ( #10018 )
2026-02-12 13:10:59 +01:00
Adrián Peña
378c2ff7f6
fix(saml): prevent SAML role mapping from removing last manage-account user ( #10007 )
2026-02-10 15:57:34 +01:00
Josema Camacho
530fef5106
chore(attack-pahts): Internet node is now created while Attack Paths scan ( #9992 )
2026-02-09 12:17:51 +01:00
Josema Camacho
5cbbceb3be
chore(attack-pahts): improve attack paths queries attribution ( #9983 )
2026-02-09 11:07:12 +01:00
Josema Camacho
ecc8eaf366
feat(skills): create new Attack Packs queries in openCypher ( #9975 )
2026-02-06 11:57:33 +01:00
Prowler Bot
cb76e77851
chore(api): Bump version to v1.20.0 ( #9968 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-02-05 22:18:33 +01:00
Josema Camacho
4ebded6ab1
chore(attack-paths): A Neo4j database per tenant ( #9955 )
2026-02-05 10:29:37 +01:00
Josema Camacho
ab18ddb81a
chore(api): prepare changelog for 5.18.0 release ( #9960 )
2026-02-05 09:34:54 +01:00
Josema Camacho
658ae755ae
chore(attack-paths): pin cartography to 0.126.1 ( #9893 )
...
Co-authored-by: César Arroba <cesar@prowler.com >
2026-02-04 19:20:15 +01:00
Víctor Fernández Poyatos
e1900fc776
fix(api): bump outdated versions ( #9950 )
2026-02-03 11:03:11 +01:00
Víctor Fernández Poyatos
3c0cb3cd58
chore: update poetry lock for SDK and API ( #9941 )
2026-02-03 09:44:02 +01:00
Hugo Pereira Brito
b1f9971617
feat(api): add Cloudflare provider support ( #9907 )
2026-02-02 14:08:33 +01:00
Alejandro Bailo
0c5778d4a1
feat: resource view re-styling with new components ( #9864 )
2026-01-28 14:07:01 +01:00
Víctor Fernández Poyatos
c77d9dd3a9
fix(api): enable autocommit for concurrent index migrations ( #9905 )
2026-01-28 13:26:16 +01:00
Víctor Fernández Poyatos
8783e963d3
feat(api): remove unused database indexes and improve new failed findings index ( #9904 )
2026-01-28 12:35:36 +01:00
dependabot[bot]
ac32f03de3
build(deps): bump azure-core from 1.35.0 to 1.38.0 in /api ( #9790 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-01-27 17:17:33 +01:00
Pepe Fagoaga
b2c18b69ee
fix(api): handle AccessDenied during AssumeRole in events endpoint ( #9899 )
2026-01-27 15:32:51 +01:00
Andoni Alonso
727fafb147
fix(attack-paths): correct aws-security-groups-open-internet-facing query ( #9892 )
2026-01-27 14:20:05 +01:00
Sergio Garcia
9e7ecb39fa
feat(aws): CloudTrail timeline for findings ( #9101 )
...
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-01-27 13:00:46 +01:00