 
|
f7669649f0
|
fix(ui): patch the Next.js and sharp image-handling vulnerabilities (#12783)
Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com>
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
|
2026-09-09 17:34:00 +02:00 |
|
 Prowler BotandCésar Arroba
|
510fc1108c
|
fix(mcp): patch the six high libuuid CVEs in the container image (#12784)
Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com>
|
2026-09-09 17:24:42 +02:00 |
|
 Prowler BotandCésar Arroba
|
19a2875e28
|
fix(ci): suppress grpc xDS DoS CVE from the Trivy binary (#12779)
Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com>
|
2026-09-09 14:41:41 +02:00 |
|
 Prowler BotandAlejandro Bailo
|
a2526d946b
|
fix(ui): patch dependency vulnerabilities flagged by dependabot and pnpm audit (#12761)
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com>
|
2026-09-08 12:27:57 +02:00 |
|
 
|
19269ff2a8
|
fix(jira): fix connection check timeout (#12743)
Co-authored-by: Pedro Martín <pedromarting3@gmail.com>
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
|
2026-09-04 16:14:58 +02:00 |
|
 Prowler BotandPedro Martín
|
03d4c23551
|
fix(compliance): remove duplicate ids and stale check refs (#12731)
Co-authored-by: Pedro Martín <pedromarting3@gmail.com>
|
2026-09-04 13:59:23 +02:00 |
|
 Prowler BotandPedro Martín
|
18dc77f5ae
|
fix(ci): suppress unfixed x/crypto CVEs from Trivy binary (#12741)
Co-authored-by: Pedro Martín <pedromarting3@gmail.com>
|
2026-09-04 10:28:27 +02:00 |
|
  
|
39f20b883b
|
chore(release): Bump versions to v5.41.1 (#12714)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-09-04 08:50:22 +02:00 |
|
 Prowler BotandPedro Martín
|
94fbf76f5d
|
fix(tests): isolate mock class attrs leaking across tests (#12730)
Co-authored-by: Pedro Martín <pedromarting3@gmail.com>
|
2026-09-03 12:34:27 +02:00 |
|
 Prowler BotandPedro Martín
|
c6156b20d3
|
fix(tests): isolate provider mock in agentcore passrole (#12725)
Co-authored-by: Pedro Martín <pedromarting3@gmail.com>
|
2026-09-03 10:32:05 +02:00 |
|
 Prowler Botandprowler-bot
|
286c1e4840
|
chore(api): Update prowler dependency to v5.41 for release 5.41.0 (#12708)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
5.41.0
|
2026-09-02 11:37:40 +02:00 |
|
 Prowler Botandprowler-bot
|
18453e592e
|
chore(changelog): v5.41.0 (#12707)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
|
2026-09-02 11:23:18 +02:00 |
|
Jonathan Nguyen
|
86e4408f29
|
feat(ecr): assess enhanced scanning on registries holding repositories (#12660)
|
2026-09-02 08:53:52 +02:00 |
|
Jonathan Nguyen
|
ae43d21efb
|
fix(sagemaker): read DirectInternetAccess instead of RootAccess on notebook instances (#12659)
|
2026-09-01 18:22:41 +02:00 |
|
Pedro Martín
|
7c84822fa3
|
fix(image): skip non-image OCI artifacts in registry scan (#12695)
|
2026-09-01 17:18:47 +02:00 |
|
Daniel Barranquero
|
51c5fa7168
|
fix(checks): report MANUAL instead of FAIL on permission and data-availability errors (#12645)
|
2026-09-01 17:16:56 +02:00 |
|
Jonathan Nguyen
|
e9121f5f1a
|
feat(cloudwatch): add agentcore log group data protection policy check (#12662)
|
2026-09-01 17:04:16 +02:00 |
|
Jonathan Nguyen
|
821fe43efd
|
feat(iam): scope AgentCore PassRole and workload token grants, and flag unbound service trust (#12664)
|
2026-09-01 17:02:05 +02:00 |
|
Jonathan Nguyen
|
9ffbb4b758
|
fix(ecr): read each registry scanning rule's frequency instead of assuming scan on push (#12560)
|
2026-09-01 16:53:58 +02:00 |
|
Jonathan Nguyen
|
9c5285adc3
|
fix(cloudwatch): skip metric filters whose log group was not retrieved (#12561)
|
2026-09-01 14:00:41 +02:00 |
|
Pedro Martín
|
f295d290dd
|
feat(image): private network allowlist for SSRF guard (#12678)
|
2026-09-01 14:00:04 +02:00 |
|
Jonathan Nguyen
|
e5df95c259
|
feat(eks): assess Kubernetes network policy enforcement in the Amazon VPC CNI add-on (#12661)
|
2026-09-01 13:40:45 +02:00 |
|
Jonathan Nguyen
|
b6a8af3c54
|
feat(guardduty): assess unified Runtime Monitoring and AI Protection (#12564)
|
2026-09-01 13:18:57 +02:00 |
|
 Pedro MartínandLydia Vilchez
|
fb7064401b
|
feat(compliance): add CIS 1.4 google workspace compliance (#12513)
Co-authored-by: Lydia Vilchez <lydiavilchezlopez@gmail.com>
|
2026-09-01 09:35:39 +02:00 |
|
Josema Camacho
|
8d60f9703a
|
fix(api): limit mute rules to current and future scans (#12681)
|
2026-09-01 09:33:15 +02:00 |
|
Pablo Fernandez Guerra (PFE)
|
ceb601028e
|
fix(ui): apply Slack integration design feedback (#12677)
|
2026-08-31 18:27:11 +02:00 |
|
 Pedro MartínandDavid
|
6422178b76
|
feat(sdk): AWS partition selection via PROWLER_AWS_PARTITION (#12680)
Co-authored-by: David <david.copo@gmail.com>
|
2026-08-31 18:13:30 +02:00 |
|
 Daniel BarranqueroandJosema Camacho
|
587c47bfe2
|
feat(api): add finding labels, finding URL and tenant info to Jira issues (#12540)
Co-authored-by: Josema Camacho <josema@prowler.com>
|
2026-08-31 18:00:46 +02:00 |
|
 Rubén De la Torre VicoandClaude Opus 5
|
13a31d9225
|
feat(mcp): raise instead of returning error objects in the Prowler Docs tools (#12534)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
2026-08-31 17:36:19 +02:00 |
|
 Pablo Fernandez Guerra (PFE)andalejandrobailo
|
0715619435
|
feat(ui): import Prowler OCSF findings from the Scans page (#12554)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
|
2026-08-31 17:14:12 +02:00 |
|
Rubén De la Torre Vico
|
1679094f22
|
feat(mcp): raise instead of returning error objects in the Prowler Hub tools (#12533)
|
2026-08-31 13:09:34 +02:00 |
|
Rubén De la Torre Vico
|
f05a490cd7
|
feat(mcp): raise instead of returning error objects in the Prowler App tools (#12532)
|
2026-08-31 10:57:58 +02:00 |
|
Alejandro Bailo
|
89988dada5
|
fix(ui): refresh cached permissions after token rotation (#12640)
|
2026-08-31 10:49:10 +02:00 |
|
 ye11oc4tandDaniel Barranquero
|
0326844527
|
fix(github): paginate repository discovery (#12460)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-08-31 10:15:29 +02:00 |
|
mintlify[bot]
|
73d5c6952b
|
docs: fix typos and grammar (#12672)
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
|
2026-08-31 09:18:08 +02:00 |
|
mintlify[bot]
|
ad76b3026f
|
docs: brand tone and writing style fixes (#12671)
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
|
2026-08-31 09:15:46 +02:00 |
|
Utkarsh Batham
|
e21946874f
|
feat(memorydb): add memorydb_cluster_in_transit_encryption_enabled check (#12246)
|
2026-08-28 14:03:10 +02:00 |
|
 SejalandDaniel Barranquero
|
2cae2058e9
|
feat(aws): add elasticbeanstalk_environment_no_secrets_in_configuration check (#12378)
Signed-off-by: unknown <sej1306kook@gmail.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-08-28 13:54:23 +02:00 |
|
 Daniel BarranqueroandJosema Camacho
|
c88f745038
|
feat(jira): return the created issue, sanitize labels and add bulk status lookup (#12539)
Co-authored-by: Josema Camacho <josema@prowler.com>
|
2026-08-28 13:47:12 +02:00 |
|
 Prowler Botandprowler-bot
|
c923c58a39
|
chore(release): Bump versions to v5.41.0 (#12647)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
|
2026-08-28 13:16:00 +02:00 |
|
 
|
c3bee8c21e
|
chore(changelog): v5.40.0 highlights (#12569)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-08-28 13:10:06 +02:00 |
|
 Prowler Botandprowler-bot
|
4d13e8432e
|
chore(changelog): v5.40.0 (#12642)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
|
2026-08-28 11:51:30 +02:00 |
|
Pedro Martín
|
5f24bec9fe
|
fix(compliance): correct Cyber Essentials mappings and remediation text (#12596)
|
2026-08-28 11:08:15 +02:00 |
|
César Arroba
|
afefb8f333
|
fix(api): apply findings partition max age in months, not days (#12580)
|
2026-08-28 10:34:12 +02:00 |
|
Rubén De la Torre Vico
|
2b81fdcc04
|
fix(mcp): call the Mintlify search endpoint the documentation moved to (#12578)
|
2026-08-27 16:48:38 +02:00 |
|
Pablo Fernandez Guerra (PFE)
|
db298c1d48
|
fix(ui): redirect the Slack OAuth callback relative to the browser's origin (#12577)
|
2026-08-27 16:13:36 +02:00 |
|
 
|
2877c3d6c0
|
fix(slack): handle scans that produce no findings (#12229)
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-08-27 14:03:33 +02:00 |
|
 
|
ee64c17108
|
fix(kubernetes): return empty list when resource gather fails (#12225)
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-08-27 13:55:46 +02:00 |
|
 Pablo Fernandez Guerra (PFE)andalejandrobailo
|
a610314eba
|
fix(ui): complete Slack OAuth callback server-side to avoid router race (#12572)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
|
2026-08-27 13:54:15 +02:00 |
|
 Muhammad Ibrahimandpedrooot
|
301edea7ce
|
feat(compliance): add Cyber Essentials 3.3 for Azure (#11588)
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-08-27 13:31:18 +02:00 |
|