Pedro Martín
|
5ca6e31f45
|
fix(vercel): exclude API token from serialization and repr (#11198)
|
2026-05-18 14:30:44 +02:00 |
|
lydiavilchez
|
9894ac7bc3
|
feat(googleworkspace): implement Chat service with 6 CIS checks (#11126)
|
2026-05-14 17:19:11 +02:00 |
|
lydiavilchez
|
bf4fd8fabd
|
fix(googleworkspace): use per-service resources for Directory (#11176)
|
2026-05-14 13:07:06 +02:00 |
|
lydiavilchez
|
5f92989492
|
fix(googleworkspace): use per-service resources for Calendar and Drive (#11161)
|
2026-05-14 12:43:29 +02:00 |
|
Hugo Pereira Brito
|
6befa78978
|
fix(cloudflare): plan-aware WAF FAIL hints for zones (#9896)
|
2026-05-14 12:27:47 +02:00 |
|
lydiavilchez
|
78af0c24fe
|
fix(googleworkspace): use per-service resources for Gmail (#11169)
|
2026-05-14 12:01:07 +02:00 |
|
June
|
1f39b01fb2
|
feat(sagemaker): add sagemaker_domain_sso_configured check (#11094)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-05-14 11:42:30 +02:00 |
|
Hugo Pereira Brito
|
739be07077
|
chore(aws): skip unattached IAM policies unless --scan-unused-services (#11150)
|
2026-05-14 08:10:20 +01:00 |
|
Daniel Barranquero
|
4dd5baadf6
|
feat(okta): add provider to the SDK with 1 security check (#11079)
|
2026-05-13 15:57:57 +02:00 |
|
abdou
|
7f3dcdf02f
|
fix(m365): surface AuditLog.Read.All permission errors instead of false positives (#10907)
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com>
|
2026-05-12 18:22:19 +01:00 |
|
Hugo Pereira Brito
|
1b99550572
|
feat(m365): add entra_service_principal_no_secrets_for_permanent_tier0_roles security check (#10788)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-05-12 10:45:32 +01:00 |
|
Hugo Pereira Brito
|
80482da1cb
|
refactor(m365): scope entra_emergency_access_exclusion to Block-grant policies (#10849)
|
2026-05-12 10:40:46 +01:00 |
|
Hugo Pereira Brito
|
1b0e12ec51
|
fix(m365): exclude disabled guest users from entra_users_mfa_capable (#11002)
|
2026-05-12 08:35:24 +01:00 |
|
Daniel Barranquero
|
759f7b84d6
|
feat(aws): add cloudtrail_bedrock_logging_enabled security check (#10858)
|
2026-05-11 17:11:49 +02:00 |
|
Hugo Pereira Brito
|
0b26c1a39c
|
feat(aws): add iam_user_access_not_stale_to_sagemaker security check (#11000)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-05-11 16:34:18 +02:00 |
|
Daniel Barranquero
|
73c0305dc4
|
feat(aws): add bedrock_prompt_encrypted_with_cmk security check (#10905)
|
2026-05-11 10:32:44 +02:00 |
|
lydiavilchez
|
962ebac8e4
|
feat(googleworkspace): add Gmail consequence-based checks for attachment safety and spoofing (#10980)
|
2026-05-07 16:50:36 +02:00 |
|
Hugo Pereira Brito
|
2c5d47a8cd
|
chore: route vulnerability references to canonical URLs (#10853)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-05-07 15:28:50 +01:00 |
|
Ivan Necheporenko
|
bcaa6ac488
|
fix(sdk): scan every Azure subscription when display names collide (#10718)
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-05-07 13:59:38 +02:00 |
|
Pedro Martín
|
e585ae45bd
|
feat(aws): rename Essential Eight to ASD Essential Eight (#11054)
Co-authored-by: César Arroba <cesar@prowler.com>
|
2026-05-06 13:11:29 +02:00 |
|
rchotacode
|
19b602c381
|
fix(oci): scan identity in known valid region (#10529)
Co-authored-by: Ronan Chota <ronan.chota@saic.com>
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com>
|
2026-05-06 11:19:19 +01:00 |
|
Pepe Fagoaga
|
7c6d658154
|
fix(k8s): match RBAC rules by apiGroup, not just core (#10969)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-05-04 19:54:03 +02:00 |
|
Pepe Fagoaga
|
21d7d08b4b
|
fix(timeline): Return a compact actor name from CloudTrail events (#10986)
|
2026-05-04 19:39:17 +02:00 |
|
Daniel Barranquero
|
921f49a0de
|
feat(aws): add bedrock_prompt_management_exists security check (#10878)
|
2026-05-04 12:38:15 +02:00 |
|
Daniel Barranquero
|
86449fb99d
|
chore(vercel): add disclaimer for checks depending on billing plan (#10663)
|
2026-05-04 08:56:50 +02:00 |
|
Andoni Alonso
|
40dd0e640b
|
fix(sdk): strip http(s):// scheme from image registry URLs (#10950)
|
2026-05-04 08:37:46 +02:00 |
|
Danny Lyubenov
|
c802dc8a36
|
feat(codebuild): use batched API calls to prevent throttling and false positives (#10639)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-04-30 17:19:21 +02:00 |
|
Pepe Fagoaga
|
36b8aa1b79
|
fix(boto3): pass config to clients (#10944)
|
2026-04-30 14:11:29 +02:00 |
|
Boon
|
228fe6d579
|
feat: add ASD Essential Eight compliance framework for AWS (#10808)
Co-authored-by: Boon <boon@security8.work>
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-04-30 13:49:08 +02:00 |
|
Pedro Martín
|
578186aa40
|
feat(sdk): integrate universal compliance into CLI pipeline (#10301)
|
2026-04-30 13:49:00 +02:00 |
|
Andoni Alonso
|
4608e45c8a
|
fix(image): block parser-mismatch SSRF in registry auth (#10945)
|
2026-04-30 12:56:35 +02:00 |
|
Josema Camacho
|
9297453b8a
|
fix(sdk): add autouse mock_aws fixture and leak detector to prevent AWS test leaks (#10605)
|
2026-04-29 17:49:40 +02:00 |
|
Andoni Alonso
|
7076900fb1
|
fix(kubernetes): use cluster name as provider_uid in OCSF output (#10483)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-04-29 13:45:49 +02:00 |
|
Hugo Pereira Brito
|
380b89cfb6
|
fix(sdk): cover CNAME → dangling S3 in route53 takeover check (#10920)
|
2026-04-29 11:14:33 +01:00 |
|
Davlet Dzhakishev
|
1de01bcb78
|
fix(azure): tighten flow log workspace checks (#10645)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-04-28 16:57:04 +02:00 |
|
Daniel Barranquero
|
8b368e1343
|
feat(aws): add bedrock_guardrails_configured security check (#10844)
|
2026-04-28 14:16:19 +02:00 |
|
Hugo Pereira Brito
|
e252058af4
|
fix(m365): exclude guest users from entra_users_mfa_capable (#10785)
|
2026-04-28 08:58:16 +01:00 |
|
Pepe Fagoaga
|
7df2703db1
|
fix(aws): get organization's metadata with assumed role (#10894)
|
2026-04-27 22:15:11 +01:00 |
|
Kay Agahd
|
67234210ba
|
feat(aws): add check secretsmanager_has_restrictive_resource_policy (#6985)
|
2026-04-27 21:49:34 +01:00 |
|
Hugo Pereira Brito
|
3441ad7f70
|
fix(sdk): align googleworkspace finding resources (#10901)
|
2026-04-27 15:17:29 +01:00 |
|
lydiavilchez
|
013809919c
|
feat(googleworkspace): add Gmail service with first batch of checks (#10683)
|
2026-04-27 13:49:07 +02:00 |
|
Daniel Barranquero
|
368d9c1519
|
fix(admincenter): restrict admincenter group visibility check to Unified groups (#10899)
|
2026-04-27 13:23:03 +02:00 |
|
Andoni Alonso
|
b668770480
|
feat(github): add zizmor GitHub Actions scanning as a service of the GitHub provider (#10607)
|
2026-04-27 08:55:07 +02:00 |
|
Pedro Martín
|
d4ece2b43e
|
feat(sdk): add multi-provider compliance framework JSONs (#10300)
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com>
|
2026-04-24 13:27:31 +02:00 |
|
Daniel Barranquero
|
80d62f355f
|
fix(alibabacloud): fix CS service SDK compatibility and harden Alibaba provider (#10871)
|
2026-04-24 09:26:09 +02:00 |
|
Mathisdjango
|
927be17fb7
|
feat(github): add check for dismissing stale PR approvals on default branch (CIS 1.1.4) (#10569)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-04-22 16:14:10 +02:00 |
|
Andoni Alonso
|
43bd1083e0
|
feat(sdk): add SARIF output format for IaC provider (#10626)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-04-22 09:32:20 +02:00 |
|
Pedro Martín
|
a24869fc26
|
feat(sdk): add universal compliance output modules (CSV, OCSF, table) (#10299)
|
2026-04-22 09:01:45 +02:00 |
|
Pepe Fagoaga
|
f2c5d2ec87
|
fix(aws): fallback lookup events to resource name (#10828)
|
2026-04-21 18:31:50 +02:00 |
|
Raajhesh Kannaa Chidambaram
|
39911e3ab7
|
feat(github): add --repo-list-file flag for GitHub scanning (#10501)
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com>
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-04-21 15:31:34 +02:00 |
|