Lydia Vilchez
b03f7fff76
fix(docs): correct MDX Tab indentation in Azure authentication page
2026-08-24 18:06:13 +02:00
Lydia Vilchez
0f778b0862
feat(azure): clarify certificate onboarding permissions and trim wizard copy
2026-08-24 17:55:28 +02:00
Hugo P.Brito
844f766c8f
fix(ci): allow pinned Bicep download
2026-08-24 15:18:58 +01:00
Hugo P.Brito
cc58a2709c
ci(azure): verify Bicep template synchronization
2026-08-24 15:13:50 +01:00
Hugo P.Brito
bb2a0031d0
test(azure): cover certificate authentication flows
2026-08-22 20:19:18 +01:00
Hugo P.Brito
2b34abe30c
fix(ui): simplify Azure certificate onboarding
2026-08-21 11:59:19 +01:00
Hugo P.Brito
5f64b34d08
fix(azure): stabilize deployment role assignments
2026-08-21 11:56:04 +01:00
Hugo P.Brito
0698987007
fix(api): preserve Azure provider ID compatibility
2026-08-21 11:55:12 +01:00
Hugo P.Brito
4d423bb357
fix(azure): wire certificate authentication flags
2026-08-21 11:54:56 +01:00
Hugo P.Brito
b1230d7cc9
feat(ui): guide Azure certificate onboarding
...
- Keep the six-step provider workflow in the certificate form
- Generate certificate bundles in the browser for secure upload
- Link deployment actions to the documentation-hosted ARM template
2026-08-21 09:45:48 +01:00
Hugo P.Brito
c230fdf9ce
feat(docs): publish Azure deployment template
...
- Serve the generated ARM template from public Mintlify documentation
- Display the same canonical JSON in the Azure authentication guide
- Enforce byte-for-byte synchronization with drift tests
2026-08-21 09:45:21 +01:00
Hugo P.Brito
970bb22df2
fix(azure): validate certificate key pairs
...
- Reject malformed, key-only, and mismatched certificate bundles
- Support matching PEM and unencrypted PKCS#12 credentials
- Cover SDK and API validation paths
2026-08-21 09:45:01 +01:00
Hugo P.Brito
d9b3bbebba
chore(azure): merge master into certificate onboarding
2026-08-21 09:44:33 +01:00
Eugene C. and Hugo P.Brito
0b9791ffdc
feat(ecr): add ecr_repository_image_no_secrets check ( #12123 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-18 11:10:07 +01:00
Prowler Bot and prowler-bot
f6defefb58
chore(changelog): v5.39.1 forward-sync to master ( #12483 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-18 11:32:20 +02:00
ye11oc4t and Hugo P.Brito
f3224d0988
fix(ses): evaluate all identity authorization policies ( #12464 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-17 14:19:45 +01:00
Pepe Fagoaga
450e6ba553
chore(api): drop temporary SDK pin overrides after cryptography cap bump ( #12473 )
2026-08-17 13:42:09 +02:00
2cd93fe119
fix(sdk): skip undescribed ECS task definitions ( #12217 )
...
Co-authored-by: Nguyễn Công Thuận Huy <nguyencongthuanhuy@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-17 12:42:06 +01:00
Pablo Fernandez Guerra (PFE)
f807b22ea6
ci: lint .github markdown and fix the violations it exposed ( #12290 )
2026-08-17 13:00:32 +02:00
Pepe Fagoaga
b6e9967da6
fix(deps): make published wheels installable and add package checks ( #12467 )
2026-08-17 12:34:11 +02:00
Hugo Pereira Brito
16e62f7514
ci(labeler): cover existing provider labels ( #12476 )
2026-08-17 11:33:22 +01:00
Adrián Peña
13ce9436b3
chore: update Trivy to 0.74.0 ( #12466 )
2026-08-17 10:25:28 +02:00
mintlify[bot]
d3ced63397
fix(docs): typos and grammar ( #12468 )
...
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-08-17 09:21:56 +02:00
Adrián Peña
758b696ca5
feat(ui): highlight imported providers ( #12447 )
2026-08-17 08:53:14 +02:00
Pepe Fagoaga
0d3ce45374
fix(pypi): bump to pypa/gh-action-pypi-publish v1.14.2 ( #12456 )
2026-08-14 14:57:07 +02:00
Lydia Vilchez
4004c53bc7
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-14 13:14:42 +02:00
Alejandro Bailo
f35666ff0a
fix(ui): settle scan auto-refresh safely ( #12455 )
2026-08-14 11:48:08 +02:00
Pedro Martín
0758c3585d
feat(rolesanywhere): flag profiles with unscoped sessions ( #12416 )
2026-08-13 17:06:24 +02:00
dd882c70e7
chore(release): Bump versions to v5.40.0 ( #12443 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-08-13 13:49:26 +02:00
Hugo Pereira Brito and Pablo F.G
d05c9fbb31
feat(ui): add trial usage sidebar banner ( #12420 )
...
Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com >
2026-08-13 11:36:59 +01:00
Josema Camacho
7bde42ffb9
docs: update attack paths documentation for grouped graphs ( #12440 )
2026-08-13 12:25:14 +02:00
Pepe Fagoaga
0d3df0fd0b
chore(changelog): v5.39.0 release highlights ( #12432 )
2026-08-13 12:08:15 +02:00
Pedro Martín
ab996417e6
fix(ci): bump Trivy to v0.73.0 to fix CVE-2026-46600 ( #12444 )
2026-08-13 12:04:51 +02:00
Prowler Bot and prowler-bot
5f109bc00e
chore(changelog): v5.39.0 ( #12433 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-13 09:01:51 +02:00
Lydia Vilchez
903025aadc
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 16:21:32 +02:00
Pepe Fagoaga
472e04f4cc
docs(triage): manual PASS verification for MANUAL findings ( #12431 )
2026-08-12 15:46:54 +02:00
Rubén De la Torre Vico
b848aace33
docs(mcp): document the Cloud organization tools and Jira dispatch options ( #12427 )
2026-08-12 15:05:24 +02:00
Pedro Martín
94c20eb9fe
feat(ui): add CMMC compliance framework ( #12414 )
2026-08-12 14:52:09 +02:00
02df22ca19
fix(html): escape provider identity fields in report header ( #12424 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: pedrooot <56402503+pedrooot@users.noreply.github.com >
2026-08-12 13:58:31 +02:00
Hugo Pereira Brito and Josema Camacho
de64df11b9
fix(api): normalize social account names ( #12413 )
...
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-08-12 12:41:44 +01:00
Pedro Martín
37ebd9b6fd
fix(cmmc): remove stale config_requirements ( #12425 )
2026-08-12 12:29:43 +02:00
Pedro Martín
a28487cbff
fix(ci): suppress .NET runtime CVE temporarily ( #12426 )
2026-08-12 12:16:14 +02:00
Lydia Vilchez
0a6206e9a8
fix(ui): pre-optimize @peculiar/x509 and reflect-metadata for vitest browser
...
The Azure certificate generator (PROWLER-2378) imports @peculiar/x509 and
reflect-metadata. Without them in vitest.config.ts optimizeDeps.include,
Vite discovered them the first time a component test loaded the cert
generator lazily and emitted "optimized dependencies changed. reloading"
mid-run. That reload races with Playwright's route handlers on the
integration project, surfacing as "Unhandled Rejection: There was an
error when mocking a module" and taking down the whole run in CI.
Pre-bundling both packages up front removes the mid-run reload — verified
by clearing node_modules/.vite and rerunning the previously-failing
providers-page.integration.test.tsx: 62/62 pass with no reload warning.
2026-08-12 10:23:21 +02:00
Rubén De la Torre Vico
68471d2a0e
feat(ui): add Manage Lighthouse AI role permission ( #12412 )
2026-08-12 10:19:20 +02:00
Lydia Vilchez
47c42bbe42
fix(ci): suppress .NET runtime CVE-2026-62901 in PowerShell M365 module
...
Trivy flags .NET 9 runtime 9.0.18 shipped with PowerShell 7 (bundled for
M365 Exchange/Teams/Skype cmdlets). Not reachable — Prowler only invokes
pwsh subprocesses for M365, none handling the untrusted input the CVE
requires. No fixed .NET runtime available in a Prowler-compatible
PowerShell release yet. Short expiry to re-look once MS ships a patch.
2026-08-12 10:08:50 +02:00
Lydia Vilchez
3be989c5b1
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00
Lydia Vilchez
2eff97c2cc
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00
Lydia Vilchez
a47d94954a
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00
Lydia Vilchez
d2df95546b
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00
Lydia Vilchez
ab738e8a4e
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00