StylusFrost
765a6cec28
feat(api): derive report availability from provider frameworks
...
- Gate threatscore/ens/nis2/csa reports on the provider's available
compliance frameworks instead of hard-coded provider whitelists
- Reference the ASFF/SecurityHub gate via the provider enum symbol
- Cover external-provider report availability and generic compliance
fallback with tests
2026-06-01 15:05:46 +02:00
StylusFrost
82cd317390
docs(api): add changelog entry for dynamic compliance discovery
2026-06-01 13:48:42 +02:00
StylusFrost
58fb424ed7
feat(api): discover compliance frameworks from available providers
...
- Source compliance template, checks mapping, and overview filter
validation from the SDK's available providers
- Replace static provider enum loops with get_available_providers()
- Cover dynamic external-provider compliance discovery with tests
2026-06-01 13:44:56 +02:00
StylusFrost
b8d3312577
feat: validate external provider secrets via SDK credential schema
...
- Add get_credentials_schema to the provider contract
- Validate non-built-in secrets against the declared schema; built-ins unchanged
- Accept secrets as-is when no schema is declared (validated at connection)
2026-06-01 01:08:41 +02:00
StylusFrost
51581c35ec
feat: add SDK contract for dynamic provider construction args
...
- Add get_scan_arguments/get_connection_arguments to the provider contract
- Route non-built-in providers through the contract; built-ins unchanged
- Cover the external dynamic path in tests
2026-06-01 00:19:17 +02:00
StylusFrost
cd15ed07eb
feat(api): resolve provider class dynamically via the SDK resolver
...
- Replace the hardcoded provider match with Provider.get_class
- Drop the closed provider-type union and TYPE_CHECKING imports
- Cover built-in and external entry-point resolution in tests
2026-05-31 23:41:10 +02:00
StylusFrost
30f8244ec1
docs(api): add changelog entry for provider varchar migration
2026-05-31 23:33:23 +02:00
StylusFrost
37323e691a
feat(api): drive provider-type filters from SDK-available providers
...
- Replace the static provider enum in filters with the SDK provider list
- Cache the provider-type choices for hot list endpoints
- Drop the dead provider enum filter override
2026-05-31 23:33:23 +02:00
StylusFrost
f14778438e
feat(api): validate provider against SDK-available providers
...
- Drive provider validity from the SDK instead of a static enum
- Tolerate providers without a uid validator at model clean()
- Accept any SDK-exposed provider in the provider serializer field
2026-05-31 23:33:23 +02:00
StylusFrost
64fdea2954
feat(api): store provider as varchar and drop the enum type
...
- Promote the synced shadow column into provider, dropping the enum
- Rebuild the partial unique index concurrently after the swap
- Keep provider input validation at the serializer layer
2026-05-31 23:33:23 +02:00
StylusFrost
7dc0895581
feat(api): backfill provider_str shadow column per-tenant
...
- Add batched per-tenant backfill job for the provider_str column
- Register backfill task on the backfill queue
- Dispatch the backfill from a data-only migration
2026-05-31 23:33:23 +02:00
StylusFrost
383e9c6bd8
feat(api): add provider_str shadow column synced by trigger
...
- Add nullable provider_str CharField mirroring the provider enum column
- DB trigger keeps provider_str in sync on INSERT and UPDATE
- First step of the zero-downtime migration of the provider enum to varchar
2026-05-31 23:33:23 +02:00
StylusFrost
459f986abe
Merge branch 'PROWLER-1391-provider-contract-dynamic-discovery' into PROWLER-1771-public-dynamic-provider-class-resolver
...
# Conflicts:
# prowler/CHANGELOG.md
2026-05-31 20:18:56 +02:00
StylusFrost
468234577c
docs(sdk): move #10700 changelog entries to 5.30.0 unreleased
2026-05-31 20:17:50 +02:00
StylusFrost
fe821a41ea
Merge branch 'PROWLER-1391-provider-contract-dynamic-discovery' into PROWLER-1771-public-dynamic-provider-class-resolver
...
# Conflicts:
# prowler/CHANGELOG.md
2026-05-31 20:05:35 +02:00
StylusFrost
c1e131766d
fix(sdk): sync CLI parser provider list with available built-ins
...
- Add okta, scaleway, stackit to known_providers so they no longer
appear as dynamically-discovered "extra" providers
- Fix missing comma in usage string (stackitvercel -> stackit,vercel)
2026-05-31 19:53:32 +02:00
StylusFrost
e1ade761b5
Merge branch 'master' into PROWLER-1391-provider-contract-dynamic-discovery
2026-05-31 19:30:23 +02:00
StylusFrost
64907898f7
Merge branch 'PROWLER-1391-provider-contract-dynamic-discovery' into PROWLER-1771-public-dynamic-provider-class-resolver
...
# Conflicts:
# prowler/CHANGELOG.md
2026-05-31 19:10:18 +02:00
StylusFrost
a6ae4903b8
docs(sdk): move #10700 changelog entries to 5.29.0 unreleased
...
- Move "external/custom providers" (Added) and namespaced-config unwrap
(Fixed) out of the released 5.26.0/5.25.0 blocks
- Remove the duplicated Fixed section left in 5.25.0
2026-05-31 19:09:19 +02:00
StylusFrost
dde265731c
docs(sdk): add changelog entry for Provider.get_class
2026-05-31 18:57:19 +02:00
StylusFrost
073dbb74f6
feat(sdk): add Provider.get_class dynamic provider resolver
...
- Add public get_class() resolving built-in and entry-point providers
- Refactor init_global_provider to use it; collision warning stays there
- Refactor get_providers_help_text to use it
2026-05-31 18:52:03 +02:00
Pepe Fagoaga
8b0cb4b981
chore: fix SDK changelog for v5.29 ( #11392 )
2026-05-29 18:23:36 +02:00
Pepe Fagoaga and Copilot Autofix powered by AI
9422eff8ab
chore: changelog v5.29.0 ( #11390 )
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-05-29 17:29:52 +02:00
e3c4368d32
fix(azure): pass authority to credentials for sovereign clouds ( #10284 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2026-05-29 15:17:41 +02:00
OokaToru and Hugo P.Brito
2a641b39c8
chore(s3): deprecate s3_bucket_default_encryption check ( #11230 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-29 14:41:52 +02:00
Alejandro Bailo
02b713572b
test(ui): find scheduled scan e2e row in In Progress tab ( #11385 )
2026-05-29 10:55:16 +02:00
Alejandro Bailo
74251350bc
feat(ui): add new scan jobs view ( #11258 )
2026-05-28 19:20:39 +02:00
Pablo Fernandez Guerra (PFE) and Pablo F.G
8f745cdbe6
chore(ui): upgrade pnpm to 11 and harden supply-chain defaults ( #11225 )
...
Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com >
2026-05-28 14:39:57 +02:00
Adrián Peña
81226cd837
perf(api): use literal scan_ids in finding-groups /latest aggregation ( #11380 )
2026-05-28 13:46:15 +02:00
a2824f7166
feat(stackit): add new provider with 4 checks ( #9237 )
...
Co-authored-by: Claude <noreply@anthropic.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2026-05-28 13:16:38 +02:00
Hugo Pereira Brito
edbbd86828
fix(openstack): move exception codes off the Alibaba Cloud range ( #11382 )
2026-05-28 11:52:45 +02:00
lydiavilchez and Daniel Barranquero
c58dad2ca4
feat(googleworkspace): add rules service checks ( #11379 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-28 11:17:33 +02:00
b4befe3a10
feat(googleworkspace): add security service checks ( #11356 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-28 10:15:10 +02:00
Alan Buscaglia
d98933c2e7
fix(ui): improve invitation error messages ( #11376 )
2026-05-28 09:37:28 +02:00
StylusFrost
03cacb83d1
fix(sdk): gate external mutelist delegate to non-builtin providers
...
- Azure/Cloudflare set per-finding mutelist args inside the loop;
the external else-branch was overwriting them
- Use is_builtin_provider to scope get_mutelist_finding_args to
truly external providers
2026-05-27 17:59:24 +02:00
StylusFrost
b25a8e5b6e
ci(sdk): switch external provider tests from poetry to uv
...
- Replace poetry.lock filter with uv.lock
- Run pytest via uv to match the migrated workflow
2026-05-27 17:33:46 +02:00
Pedro Martín
03dfa3816d
docs: fix alerts/import-findings URLs and pricing note ( #11378 )
2026-05-27 17:26:50 +02:00
StylusFrost
b3c0f78801
style(sdk): remove trailing whitespace on blank lines
...
- prowler/lib/check/check.py
- prowler/providers/common/provider.py
2026-05-27 17:20:27 +02:00
StylusFrost
ca72922dca
Merge branch 'master' into PROWLER-1391-provider-contract-dynamic-discovery
2026-05-27 17:12:54 +02:00
ad1261ce54
ci(docs): add markdownlint foundation (prek + CI) ( #11210 )
...
Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com >
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-27 16:42:01 +02:00
3252f9cf19
fix(compliance/ens): remap resilience VPC checks out of mp.com.4 ( #11372 )
...
Co-authored-by: Juan Pablo Mora <juanpablo.mora@logalty.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-27 13:10:58 +02:00
Hugo Pereira Brito
f1cdf3df15
feat(ui): improve dark mode contrast for editorial readability ( #11073 )
2026-05-27 12:49:50 +02:00
Pedro Martín
03ddb8a708
fix(ui): show compliance data when opening compliance sidebar ( #11374 )
2026-05-27 11:18:32 +02:00
Daniel Barranquero
2678c6bc9f
feat(okta): add application service with 6 new checks ( #11358 )
2026-05-27 11:16:18 +02:00
Pedro Martín
48c071297f
fix(sdk): align compliance CSV row emission with framework JSON ( #11370 )
2026-05-27 11:06:23 +02:00
Prowler Bot and prowler-bot
7e9a16d022
feat(aws): Update regions for AWS services ( #11349 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-05-27 10:36:28 +02:00
Pedro Martín and Pepe Fagoaga
84b388f649
fix(ui): honor page size select in compliance req findings ( #11365 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-05-26 15:35:33 +02:00
Rubén De la Torre Vico and Pepe Fagoaga
671d0c746c
fix(mcp_server): preserve authorization header in HTTP mode ( #11366 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-05-26 15:25:46 +02:00
Pepe Fagoaga
0e4b117161
chore: SDK changelog v5.28.1 ( #11363 )
2026-05-26 12:15:19 +02:00
Alan Buscaglia and Adrián Jesús Peña Rodríguez
a70bc3c1c7
fix(ui): avoid report preflight timeouts ( #11350 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2026-05-26 11:47:34 +02:00