Commit Graph
721 Commits
Author SHA1 Message Date
Prowler Botandprowler-bot a5b0fd14fc chore(api): Update prowler dependency to v5.43 for release 5.43.0 (#12857)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-09-21 15:41:25 +02:00
Prowler Botandprowler-bot 81d90fc31e chore(changelog): v5.43.0 (#12856)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-09-21 15:30:24 +02:00
César Arroba c9068515b2 fix(deps): bump anyio to 4.14.2 and accept unfixable CPython CVE-2026-82049 (#12848) 2026-09-21 12:51:41 +02:00
Pedro Martín 6c8d6994bb fix(api): sign report URLs against public storage host (#12552) 2026-09-18 10:16:13 +02:00
Alejandro Bailo 5fe1a6713b revert: remove the onboarding profile step (#12818) (#12838) 2026-09-17 18:01:41 +02:00
Pedro Martín f382400037 fix(invitations): expire lapsed invitations on re-invite (#12831) 2026-09-17 12:12:14 +02:00
Alejandro BailoandClaude Opus 5 3069486549 feat: record the tenant profile declared at onboarding (#12818)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 10:03:59 +02:00
Pedro Martín 682353e054 fix(container): bump PowerShell to 7.5.11 in SDK and API (#12811) 2026-09-15 09:44:32 +02:00
Pedro Martín ba258a5346 fix(container): patch high Debian CVEs in SDK and API (#12804) 2026-09-14 11:01:15 +02:00
Prowler Botandprowler-bot 282fe5b46b chore(release): Bump versions to v5.43.0 (#12797)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-09-11 13:23:08 +02:00
Prowler Botandprowler-bot 4727da7ca7 chore(changelog): v5.42.0 (#12794)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-09-11 10:21:17 +02:00
Pedro Martín 8bdb597921 perf(api): speed up compliance overview ingestion (#12738) 2026-09-04 11:13:25 +02:00
90fc815d3c chore(release): Bump versions to v5.42.0 (#12713)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
Co-authored-by: pedrooot <pedromarting3@gmail.com>
2026-09-03 14:23:50 +02:00
Prowler Botandprowler-bot 18453e592e chore(changelog): v5.41.0 (#12707)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-09-02 11:23:18 +02:00
Josema Camacho 8d60f9703a fix(api): limit mute rules to current and future scans (#12681) 2026-09-01 09:33:15 +02:00
Daniel BarranqueroandJosema Camacho 587c47bfe2 feat(api): add finding labels, finding URL and tenant info to Jira issues (#12540)
Co-authored-by: Josema Camacho <josema@prowler.com>
2026-08-31 18:00:46 +02:00
Prowler Botandprowler-bot c923c58a39 chore(release): Bump versions to v5.41.0 (#12647)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-28 13:16:00 +02:00
Prowler Botandprowler-bot 4d13e8432e chore(changelog): v5.40.0 (#12642)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-28 11:51:30 +02:00
César Arroba afefb8f333 fix(api): apply findings partition max age in months, not days (#12580) 2026-08-28 10:34:12 +02:00
Pedro Martín 6449f3a592 fix(container): patch the high OpenSSL CVEs for container img (#12549) 2026-08-26 11:10:55 +02:00
Hugo Pereira Brito e3a3acc799 fix(api): upgrade sqlparse to 0.6.0 (#12509) 2026-08-24 08:47:29 +02:00
Prowler Botandprowler-bot f6defefb58 chore(changelog): v5.39.1 forward-sync to master (#12483)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-18 11:32:20 +02:00
Pepe Fagoaga 450e6ba553 chore(api): drop temporary SDK pin overrides after cryptography cap bump (#12473) 2026-08-17 13:42:09 +02:00
Pepe Fagoaga b6e9967da6 fix(deps): make published wheels installable and add package checks (#12467) 2026-08-17 12:34:11 +02:00
Adrián Peña 13ce9436b3 chore: update Trivy to 0.74.0 (#12466) 2026-08-17 10:25:28 +02:00
dd882c70e7 chore(release): Bump versions to v5.40.0 (#12443)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: Josema Camacho <josema@prowler.com>
2026-08-13 13:49:26 +02:00
Pedro Martín ab996417e6 fix(ci): bump Trivy to v0.73.0 to fix CVE-2026-46600 (#12444) 2026-08-13 12:04:51 +02:00
Prowler Botandprowler-bot 5f109bc00e chore(changelog): v5.39.0 (#12433)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-13 09:01:51 +02:00
Hugo Pereira BritoandJosema Camacho de64df11b9 fix(api): normalize social account names (#12413)
Co-authored-by: Josema Camacho <josema@prowler.com>
2026-08-12 12:41:44 +01:00
Adrián Peña 34b4e6f016 fix(api): enforce POST on SAML ACS endpoint (#12393) 2026-08-07 14:24:45 +02:00
Josema Camacho 3672b17a00 feat(api): identify active membership in current user response (#12388) 2026-08-07 10:40:21 +02:00
Adrián Peña cf558c5f0a fix(api): make tenant deletion cleanup atomic (#12379) 2026-08-06 17:36:52 +02:00
Prowler Botandprowler-bot d8c8027215 chore(release): Bump versions to v5.39.0 (#12376)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-06 15:59:35 +02:00
Prowler Botandprowler-bot 226504982b chore(changelog): v5.38.0 (#12373)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-06 13:25:12 +02:00
César Arroba d1a37039fd fix(deps): upgrade cryptography to 50.0.0 (#12356) 2026-08-05 19:16:11 +02:00
César Arroba f3c602a5ac feat(container): ship an SBOM and provenance with the published images (#12352) 2026-08-05 16:19:42 +02:00
Daniel Barranquero dd61c417b7 feat(attack-paths): add outcome to query metadata (#12344) 2026-08-05 14:13:24 +02:00
César Arroba af757a4d69 ci(container): pin Trivy to v0.72.0 across the estate (#12346) 2026-08-05 13:12:24 +02:00
Pedro MartínandAlan Buscaglia a6d5dbacd9 fix(api): log comp report output dir failures with exc_info (#12142)
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com>
2026-08-05 11:12:35 +02:00
César Arroba 87bc1eceae ci(container): scan images with Grype alongside Trivy, blocking on critical and high (#12340) 2026-08-04 18:49:53 +02:00
César Arroba 635e451d9b fix(container): verify the checksum of downloaded third-party binaries (#12334) 2026-08-04 18:07:46 +02:00
c610d9ac31 chore(changelog): v5.37.1 forward-sync to master (#12322)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: César Arroba <cesar@prowler.com>
2026-08-04 12:12:15 +02:00
Daniel Barranquero caf27de6ee fix(m365): bump microsoft-kiota packages to 1.9.10 so guest-user CA checks parse guestOrExternalUserTypes (#12280) 2026-08-04 10:37:04 +02:00
César Arroba f4d6cd8609 fix(deps): restore the SDK dependency to master (PROWLER-2328) (#12309) 2026-08-04 09:59:21 +02:00
César Arroba 8ebb4a1ee7 fix(container): clear the Private Cloud image vulnerabilities (PROWLER-2291) (#12258) 2026-08-04 09:41:47 +02:00
Daniel Barranquero a19fd70001 feat(aws): add pathfinding.cloud privilege-escalation coverage (#12237) 2026-08-04 08:59:52 +02:00
Prowler Botandprowler-bot ce77eb7f41 chore(release): Bump versions to v5.38.0 (#12302)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-03 18:20:09 +02:00
b9aa863e52 chore(changelog): v5.37.0 (#12293)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
2026-08-03 14:35:29 +02:00
Rubén De la Torre Vico b08d2eb472 fix(api): prevent 500 on Jira integrations with sparse fieldsets (#12261) 2026-07-31 15:03:04 +02:00
88c666a0d2 feat(attack-paths): Add 4 IAM privilege escalation detection queries (#11460)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
Co-authored-by: Josema Camacho <josema@prowler.com>
2026-07-31 10:29:28 +02:00