César Arroba
|
94899e20fd
|
ci(ui): pass E2E AWS credentials through env vars (#12864)
|
2026-09-22 10:42:40 +02:00 |
|
 Alan Buscagliaandalejandrobailo
|
2198ba2d84
|
feat(ui): complete Registry provider onboarding for Private Cloud (#12494)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
|
2026-09-16 12:21:25 +02:00 |
|
 StylusFrostandpedrooot
|
f9c02da90a
|
feat(aws): support the ISO partitions for region resolution and scanning (#12759)
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-09-10 17:15:13 +02:00 |
|
César Arroba
|
806be2d061
|
chore(ci): bump agilepathway/label-checker to v1.6.66 (#12760)
|
2026-09-08 11:58:06 +02:00 |
|
César Arroba
|
623dc3125a
|
chore(codeowners): consolidate retired teams under engineering (#12755)
|
2026-09-07 19:11:56 +02:00 |
|
Pedro Martín
|
6827eef347
|
fix(ci): don't fail setup-python-uv on empty grep match (#12737)
|
2026-09-04 09:12:15 +02:00 |
|
Rubén De la Torre Vico
|
f299e1d9ac
|
fix(mcp): patch the two high sqlite CVEs in the container image (#12537)
|
2026-08-25 17:41:44 +02:00 |
|
Pablo Fernandez Guerra (PFE)
|
ba564af4f4
|
fix(ci): unblock the Python runtime download in blocked-egress jobs (#12490)
|
2026-08-20 10:48:16 +02:00 |
|
Pablo Fernandez Guerra (PFE)
|
f807b22ea6
|
ci: lint .github markdown and fix the violations it exposed (#12290)
|
2026-08-17 13:00:32 +02:00 |
|
Pepe Fagoaga
|
b6e9967da6
|
fix(deps): make published wheels installable and add package checks (#12467)
|
2026-08-17 12:34:11 +02:00 |
|
Hugo Pereira Brito
|
16e62f7514
|
ci(labeler): cover existing provider labels (#12476)
|
2026-08-17 11:33:22 +01:00 |
|
Adrián Peña
|
13ce9436b3
|
chore: update Trivy to 0.74.0 (#12466)
|
2026-08-17 10:25:28 +02:00 |
|
Pepe Fagoaga
|
0d3ce45374
|
fix(pypi): bump to pypa/gh-action-pypi-publish v1.14.2 (#12456)
|
2026-08-14 14:57:07 +02:00 |
|
Pedro Martín
|
ab996417e6
|
fix(ci): bump Trivy to v0.73.0 to fix CVE-2026-46600 (#12444)
|
2026-08-13 12:04:51 +02:00 |
|
Hugo Pereira Brito
|
9daca2e4df
|
fix(ci): suppress Trivy go-git vulnerability temporarily (#12405)
|
2026-08-10 10:41:19 +01:00 |
|
César Arroba
|
a700865340
|
ci: always report from actionlint, skipping the work when nothing changed (#12371)
|
2026-08-06 12:53:43 +02:00 |
|
César Arroba
|
07faddd64e
|
ci: fix the remaining shellcheck findings and enable the check (#12367)
|
2026-08-06 12:35:55 +02:00 |
|
César Arroba
|
1b9a44b164
|
fix(ci): keep the cloud sync dispatch payload within the 10-property limit (#12370)
|
2026-08-06 12:31:37 +02:00 |
|
César Arroba
|
b684ad06f3
|
ci: forward stacked PR metadata in the cloud sync dispatch (#12368)
|
2026-08-06 12:24:48 +02:00 |
|
César Arroba
|
76d7a2882c
|
ci: quote the unquoted shell expansions in workflows (#12365)
|
2026-08-06 11:59:40 +02:00 |
|
César Arroba
|
31d8faccfa
|
ci: check GitHub Actions schemas with actionlint (#12361)
|
2026-08-06 11:01:53 +02:00 |
|
César Arroba
|
f3c602a5ac
|
feat(container): ship an SBOM and provenance with the published images (#12352)
|
2026-08-05 16:19:42 +02:00 |
|
César Arroba
|
af757a4d69
|
ci(container): pin Trivy to v0.72.0 across the estate (#12346)
|
2026-08-05 13:12:24 +02:00 |
|
César Arroba
|
3b577907e4
|
ci(container): gate Grype only on fixable findings, and comment results on the PR (#12341)
|
2026-08-05 10:23:29 +02:00 |
|
César Arroba
|
87bc1eceae
|
ci(container): scan images with Grype alongside Trivy, blocking on critical and high (#12340)
|
2026-08-04 18:49:53 +02:00 |
|
César Arroba
|
765a1596f9
|
chore(docs): sync Docker Hub repository overviews from a single source (#12333)
|
2026-08-04 16:53:59 +02:00 |
|
Rubén De la Torre Vico
|
138d643119
|
test(mcp): add test foundation for the MCP server (#12291)
|
2026-08-04 16:19:10 +02:00 |
|
César Arroba
|
5cf49805a2
|
fix(ci): make the YAML Trivy suppressions actually apply (#12326)
|
2026-08-04 13:05:46 +02:00 |
|
César Arroba
|
681be7537d
|
chore(security): migrate suppressions to .trivyignore.yaml (PROWLER-2327) (#12314)
|
2026-08-04 11:13:16 +02:00 |
|
César Arroba
|
aab8154139
|
ci(workflows): align container build-push workflows across api, ui, mcp and sdk (#12310)
|
2026-08-04 10:25:31 +02:00 |
|
 CopilotandPepe Fagoaga
|
e15f6970ef
|
fix(ci): use PROWLER_BOT_ACCESS_TOKEN for release freeze (#12295)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-08-03 14:45:23 +02:00 |
|
 Pablo Fernandez Guerra (PFE)andPablo F.G
|
2db3bebd15
|
feat(ui): GCP org onboarding — canonical contract + shared lifecycle (#12255)
Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com>
|
2026-07-31 13:30:46 +02:00 |
|
César Arroba
|
bd9fa88d2a
|
fix(ci): harden osv-scan.sh against a missing osv-scanner.toml (#12267)
|
2026-07-31 13:09:58 +02:00 |
|
César Arroba
|
7275b46707
|
chore(ci): repin trivy-action to a resolvable tag (#12257)
|
2026-07-31 09:51:18 +02:00 |
|
stepsecurity-app[bot]
|
8abd72e857
|
feat(security): security best practices from StepSecurity (#12254)
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
|
2026-07-31 09:27:01 +02:00 |
|
Alan Buscaglia
|
7a62926a09
|
fix(ui): stabilize cloud e2e prerequisites (#12024)
|
2026-07-30 14:54:26 +02:00 |
|
stepsecurity-app[bot]
|
a57a507cee
|
feat(security): security best practices from StepSecurity (#12232)
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
|
2026-07-30 09:24:44 +02:00 |
|
Hugo Pereira Brito
|
1bb3fc9bda
|
ci: add release freeze gate (#11621)
|
2026-07-29 10:08:15 +01:00 |
|
![coderabbitai[bot]](/assets/img/avatar_default.png) 
|
f5fe9c7b40
|
ci(helm): publish immutable chart versions on release (#12056)
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
|
2026-07-27 16:58:59 +02:00 |
|
César Arroba
|
98015dafef
|
ci(api): scan the SDK pin that ships, not the committed lock (#12084)
|
2026-07-22 12:08:40 +02:00 |
|
Pepe Fagoaga
|
7df1054966
|
chore(step-security): allow endpoints (#11973)
|
2026-07-14 12:02:35 +02:00 |
|
stepsecurity-app[bot]
|
c7583a5633
|
feat(security): security best practices from StepSecurity (#11962)
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
|
2026-07-14 08:17:06 +02:00 |
|
Hugo Pereira Brito
|
c6dae3a711
|
chore: remove __init__.py from test directories (#10582)
|
2026-07-13 15:09:42 +01:00 |
|
Hugo Pereira Brito
|
cef131812c
|
fix(ci): correct bot and dependency PR labeling (#11425)
|
2026-07-13 09:06:12 +01:00 |
|
Pepe Fagoaga
|
3c78a0df43
|
fix(changelog): correct fragments for the UI (#11952)
|
2026-07-13 09:31:57 +02:00 |
|
Hugo Pereira Brito
|
5bc41b2609
|
docs: require duplicate PR check (#11946)
|
2026-07-10 12:59:49 +01:00 |
|
lydiavilchez
|
08ee83c572
|
fix(docs): use python3 and add CI check for provider cards hook (#11930)
|
2026-07-10 09:27:34 +02:00 |
|
 stepsecurity-app[bot]andPepe Fagoaga
|
2a077cae5e
|
feat(security): security best practices from StepSecurity (#11937)
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-07-10 09:00:40 +02:00 |
|
César Arroba
|
9d899ae0e2
|
ci: rename public ECR push-role secret to PUBLIC_ECR_PUSH_ROLE_ARN (#11916)
|
2026-07-09 11:27:55 +02:00 |
|
Pepe Fagoaga
|
c665005790
|
fix(workflow): bump AI issue triage (#11896)
|
2026-07-08 15:45:52 +02:00 |
|