Jonathan Nguyen
86e4408f29
feat(ecr): assess enhanced scanning on registries holding repositories ( #12660 )
2026-09-02 08:53:52 +02:00
Jonathan Nguyen
ae43d21efb
fix(sagemaker): read DirectInternetAccess instead of RootAccess on notebook instances ( #12659 )
2026-09-01 18:22:41 +02:00
Pedro Martín
7c84822fa3
fix(image): skip non-image OCI artifacts in registry scan ( #12695 )
2026-09-01 17:18:47 +02:00
Daniel Barranquero
51c5fa7168
fix(checks): report MANUAL instead of FAIL on permission and data-availability errors ( #12645 )
2026-09-01 17:16:56 +02:00
Jonathan Nguyen
e9121f5f1a
feat(cloudwatch): add agentcore log group data protection policy check ( #12662 )
2026-09-01 17:04:16 +02:00
Jonathan Nguyen
821fe43efd
feat(iam): scope AgentCore PassRole and workload token grants, and flag unbound service trust ( #12664 )
2026-09-01 17:02:05 +02:00
Jonathan Nguyen
9ffbb4b758
fix(ecr): read each registry scanning rule's frequency instead of assuming scan on push ( #12560 )
2026-09-01 16:53:58 +02:00
Jonathan Nguyen
9c5285adc3
fix(cloudwatch): skip metric filters whose log group was not retrieved ( #12561 )
2026-09-01 14:00:41 +02:00
Pedro Martín
f295d290dd
feat(image): private network allowlist for SSRF guard ( #12678 )
2026-09-01 14:00:04 +02:00
Jonathan Nguyen
e5df95c259
feat(eks): assess Kubernetes network policy enforcement in the Amazon VPC CNI add-on ( #12661 )
2026-09-01 13:40:45 +02:00
Jonathan Nguyen
b6a8af3c54
feat(guardduty): assess unified Runtime Monitoring and AI Protection ( #12564 )
2026-09-01 13:18:57 +02:00
Pedro Martín and Lydia Vilchez
fb7064401b
feat(compliance): add CIS 1.4 google workspace compliance ( #12513 )
...
Co-authored-by: Lydia Vilchez <lydiavilchezlopez@gmail.com >
2026-09-01 09:35:39 +02:00
Pedro Martín and David
6422178b76
feat(sdk): AWS partition selection via PROWLER_AWS_PARTITION ( #12680 )
...
Co-authored-by: David <david.copo@gmail.com >
2026-08-31 18:13:30 +02:00
ye11oc4t and Daniel Barranquero
0326844527
fix(github): paginate repository discovery ( #12460 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-31 10:15:29 +02:00
Utkarsh Batham
e21946874f
feat(memorydb): add memorydb_cluster_in_transit_encryption_enabled check ( #12246 )
2026-08-28 14:03:10 +02:00
Sejal and Daniel Barranquero
2cae2058e9
feat(aws): add elasticbeanstalk_environment_no_secrets_in_configuration check ( #12378 )
...
Signed-off-by: unknown <sej1306kook@gmail.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-28 13:54:23 +02:00
Daniel Barranquero and Josema Camacho
c88f745038
feat(jira): return the created issue, sanitize labels and add bulk status lookup ( #12539 )
...
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-08-28 13:47:12 +02:00
2877c3d6c0
fix(slack): handle scans that produce no findings ( #12229 )
...
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-27 14:03:33 +02:00
ee64c17108
fix(kubernetes): return empty list when resource gather fails ( #12225 )
...
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-27 13:55:46 +02:00
Muhammad Ibrahim and pedrooot
301edea7ce
feat(compliance): add Cyber Essentials 3.3 for Azure ( #11588 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-08-27 13:31:18 +02:00
c89d900aae
fix(iac): raise typed exceptions instead of sys.exit on provider failures ( #12227 )
...
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-27 12:15:50 +02:00
Hugo Pereira Brito
4cfb4eeb96
fix(sdk): use system trust store for push-to-cloud ( #12485 )
2026-08-27 11:07:14 +01:00
Pedro Martín and alejandrobailo
f19478f2f6
fix(compliance): discover universal frameworks from entry point ( #12536 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2026-08-27 09:17:39 +02:00
Chethas Dileep and Daniel Barranquero
2f11b16299
feat(github): add repository_default_workflow_permissions_read_only check ( #12143 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-27 09:00:42 +02:00
Chethas Dileep and Daniel Barranquero
2721d42594
feat(github): add organization_actions_pull_request_approval_disabled check ( #12394 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-27 08:25:32 +02:00
Daniel Barranquero
bd1956446d
fix(alibabacloud): read OSS bucket sub-resource configs via the SDK execute path ( #12546 )
2026-08-26 16:41:13 +02:00
Chethas Dileep and Daniel Barranquero
9dc53ffc60
feat(github): add organization_default_workflow_permissions_read_only check ( #12122 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-26 12:21:49 +02:00
Alex Chen and Daniel Barranquero
301ca50541
feat(alibabacloud): add oss_bucket_server_side_encryption_enabled check ( #11981 )
...
Signed-off-by: Alex Chen <l46983284@gmail.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-25 17:41:52 +02:00
abidedavana and Daniel Barranquero
411d112165
feat(alibabacloud): add oss_bucket_versioning_enabled check ( #11913 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-25 13:03:25 +02:00
Gabriel and pedrooot
8a4cc8780d
feat(kubernetes): include cluster name in compliance reports ( #12506 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-08-25 11:08:04 +02:00
9898cf7364
feat(m365): add defender_domain_dmarc_records_published check ( #11936 )
...
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: hdy2001 <56308320+hdy2001@users.noreply.github.com >
2026-08-24 16:49:36 +02:00
83d8cfa829
fix(aws): treat security groups on Batch compute environments as used ( #12458 )
...
Co-authored-by: hackertwinten <193916571+hackertwinten@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-24 16:18:56 +02:00
Jonathan Nguyen and Hugo P.Brito
f39c92b8f8
feat(bedrock): add model artifact and guardrail grounding security checks for the AWS provider ( #12459 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-21 10:50:34 +01:00
Johannes Engler and Hugo P.Brito
3da4209ee7
feat(stackit): add ske_cluster_no_public_endpoint check ( #11943 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-20 13:01:01 +01:00
acb6ff0425
feat(providers/huaweicloud): add vpc_security_group_open_egress check ( #12209 )
...
Co-authored-by: tomitobio <tomitobio@users.noreply.github.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-20 10:52:13 +01:00
Eugene C. and Hugo P.Brito
0b9791ffdc
feat(ecr): add ecr_repository_image_no_secrets check ( #12123 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-18 11:10:07 +01:00
ye11oc4t and Hugo P.Brito
f3224d0988
fix(ses): evaluate all identity authorization policies ( #12464 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-17 14:19:45 +01:00
2cd93fe119
fix(sdk): skip undescribed ECS task definitions ( #12217 )
...
Co-authored-by: Nguyễn Công Thuận Huy <nguyencongthuanhuy@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-17 12:42:06 +01:00
Pepe Fagoaga
b6e9967da6
fix(deps): make published wheels installable and add package checks ( #12467 )
2026-08-17 12:34:11 +02:00
Pedro Martín
0758c3585d
feat(rolesanywhere): flag profiles with unscoped sessions ( #12416 )
2026-08-13 17:06:24 +02:00
02df22ca19
fix(html): escape provider identity fields in report header ( #12424 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: pedrooot <56402503+pedrooot@users.noreply.github.com >
2026-08-12 13:58:31 +02:00
ce037318cd
feat(m365): add CIS M365 v7.0.0 entra authentication method, PIM and access review checks ( #12155 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-10 15:37:48 +01:00
Pedro Martín and Hugo P.Brito
356036fe1f
feat(m365): add CIS M365 v7.0.0 entra conditional access and session checks ( #12154 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-10 11:17:19 +01:00
Andoni Alonso and Lydia Vilchez
286685a4f3
feat(github): scale organization_repository_creation_limited severity by repository visibility ( #12164 )
...
Co-authored-by: Lydia Vilchez <lydiavilchezlopez@gmail.com >
2026-08-10 11:51:38 +02:00
Hugo Pereira Brito
3ca3a977a9
test(m365): avoid Lob secret pattern in test name ( #12395 )
2026-08-10 08:35:28 +01:00
Pedro Martín and Hugo P.Brito
f2a00f19aa
feat(m365): add CIS M365 v7.0.0 entra password protection and default user permission checks ( #12153 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-07 13:42:52 +01:00
praneetrajv and Daniel Barranquero
94594d6766
feat(batch): add batch_job_definition_no_secrets check ( #12117 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-07 11:57:58 +02:00
6e71dee85d
feat(awslambda): add awslambda_layer_no_secrets_in_content check ( #12233 )
...
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Claude Opus 5 <noreply@anthropic.com >
2026-08-07 11:33:54 +02:00
Hugo Pereira Brito
d0da56f352
fix(alibabacloud): retry STS connection failures ( #12353 )
2026-08-06 09:44:00 +01:00
Pedro Martín and Daniel Barranquero
aaa29d3528
feat(m365): add CIS M365 v7.0.0 entra device registration checks ( #12152 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-05 13:51:29 +02:00