Hugo P.Brito
bb2a0031d0
test(azure): cover certificate authentication flows
2026-08-22 20:19:18 +01:00
Hugo P.Brito
0698987007
fix(api): preserve Azure provider ID compatibility
2026-08-21 11:55:12 +01:00
Hugo P.Brito
970bb22df2
fix(azure): validate certificate key pairs
...
- Reject malformed, key-only, and mismatched certificate bundles
- Support matching PEM and unencrypted PKCS#12 credentials
- Cover SDK and API validation paths
2026-08-21 09:45:01 +01:00
Hugo P.Brito
d9b3bbebba
chore(azure): merge master into certificate onboarding
2026-08-21 09:44:33 +01:00
Prowler Bot and prowler-bot
f6defefb58
chore(changelog): v5.39.1 forward-sync to master ( #12483 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-18 11:32:20 +02:00
Pepe Fagoaga
450e6ba553
chore(api): drop temporary SDK pin overrides after cryptography cap bump ( #12473 )
2026-08-17 13:42:09 +02:00
Pepe Fagoaga
b6e9967da6
fix(deps): make published wheels installable and add package checks ( #12467 )
2026-08-17 12:34:11 +02:00
Adrián Peña
13ce9436b3
chore: update Trivy to 0.74.0 ( #12466 )
2026-08-17 10:25:28 +02:00
dd882c70e7
chore(release): Bump versions to v5.40.0 ( #12443 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-08-13 13:49:26 +02:00
Pedro Martín
ab996417e6
fix(ci): bump Trivy to v0.73.0 to fix CVE-2026-46600 ( #12444 )
2026-08-13 12:04:51 +02:00
Prowler Bot and prowler-bot
5f109bc00e
chore(changelog): v5.39.0 ( #12433 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-13 09:01:51 +02:00
Hugo Pereira Brito and Josema Camacho
de64df11b9
fix(api): normalize social account names ( #12413 )
...
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-08-12 12:41:44 +01:00
Lydia Vilchez
a47d94954a
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00
Lydia Vilchez
ab738e8a4e
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
2026-08-12 09:48:34 +02:00
Adrián Peña
34b4e6f016
fix(api): enforce POST on SAML ACS endpoint ( #12393 )
2026-08-07 14:24:45 +02:00
Josema Camacho
3672b17a00
feat(api): identify active membership in current user response ( #12388 )
2026-08-07 10:40:21 +02:00
Adrián Peña
cf558c5f0a
fix(api): make tenant deletion cleanup atomic ( #12379 )
2026-08-06 17:36:52 +02:00
Prowler Bot and prowler-bot
d8c8027215
chore(release): Bump versions to v5.39.0 ( #12376 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-06 15:59:35 +02:00
Prowler Bot and prowler-bot
226504982b
chore(changelog): v5.38.0 ( #12373 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-06 13:25:12 +02:00
César Arroba
d1a37039fd
fix(deps): upgrade cryptography to 50.0.0 ( #12356 )
2026-08-05 19:16:11 +02:00
César Arroba
f3c602a5ac
feat(container): ship an SBOM and provenance with the published images ( #12352 )
2026-08-05 16:19:42 +02:00
Daniel Barranquero
dd61c417b7
feat(attack-paths): add outcome to query metadata ( #12344 )
2026-08-05 14:13:24 +02:00
César Arroba
af757a4d69
ci(container): pin Trivy to v0.72.0 across the estate ( #12346 )
2026-08-05 13:12:24 +02:00
Pedro Martín and Alan Buscaglia
a6d5dbacd9
fix(api): log comp report output dir failures with exc_info ( #12142 )
...
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com >
2026-08-05 11:12:35 +02:00
César Arroba
87bc1eceae
ci(container): scan images with Grype alongside Trivy, blocking on critical and high ( #12340 )
2026-08-04 18:49:53 +02:00
César Arroba
635e451d9b
fix(container): verify the checksum of downloaded third-party binaries ( #12334 )
2026-08-04 18:07:46 +02:00
c610d9ac31
chore(changelog): v5.37.1 forward-sync to master ( #12322 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
Co-authored-by: César Arroba <cesar@prowler.com >
2026-08-04 12:12:15 +02:00
Daniel Barranquero
caf27de6ee
fix(m365): bump microsoft-kiota packages to 1.9.10 so guest-user CA checks parse guestOrExternalUserTypes ( #12280 )
2026-08-04 10:37:04 +02:00
César Arroba
f4d6cd8609
fix(deps): restore the SDK dependency to master (PROWLER-2328) ( #12309 )
2026-08-04 09:59:21 +02:00
César Arroba
8ebb4a1ee7
fix(container): clear the Private Cloud image vulnerabilities (PROWLER-2291) ( #12258 )
2026-08-04 09:41:47 +02:00
Daniel Barranquero
a19fd70001
feat(aws): add pathfinding.cloud privilege-escalation coverage ( #12237 )
2026-08-04 08:59:52 +02:00
Prowler Bot and prowler-bot
ce77eb7f41
chore(release): Bump versions to v5.38.0 ( #12302 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-08-03 18:20:09 +02:00
b9aa863e52
chore(changelog): v5.37.0 ( #12293 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-08-03 14:35:29 +02:00
Rubén De la Torre Vico
b08d2eb472
fix(api): prevent 500 on Jira integrations with sparse fieldsets ( #12261 )
2026-07-31 15:03:04 +02:00
88c666a0d2
feat(attack-paths): Add 4 IAM privilege escalation detection queries ( #11460 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Josema Camacho <josema@prowler.com >
2026-07-31 10:29:28 +02:00
Adrián Peña
3dd6b29477
fix(api): make social signup transactional ( #12245 )
2026-07-30 16:28:45 +02:00
Daniel Barranquero
5c4b0ba1fe
fix(api): scope Attack Paths predefined queries with provider label ( #12167 )
2026-07-30 11:55:24 +02:00
Adrián Peña
8dac2a7ccf
fix(api): assign fallback role to SAML users ( #12223 )
2026-07-30 11:17:25 +02:00
Josema Camacho
f8be9afa7c
fix(api): safely decode stored Celery task arguments ( #12165 )
2026-07-30 10:30:19 +02:00
Adrián Peña
ecf7ec8e85
fix(api): respect provider group scope in provider actions ( #12216 )
2026-07-30 10:06:57 +02:00
Pedro Martín
976220dbf5
fix(api): reject API keys whose owning user was deleted ( #12210 )
2026-07-29 17:18:09 +02:00
Adrián Peña
03f2ab46c9
fix(api): refresh Security Hub connection status ( #12212 )
2026-07-29 11:17:25 +02:00
Daniel Barranquero
e9bbde2f01
fix(api): remove cartesian product in Attack Paths IAM privesc queries ( #12136 )
2026-07-28 11:12:10 +02:00
Prowler Bot and prowler-bot
da09ad9813
chore(release): Bump versions to v5.37.0 ( #12113 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-07-24 14:56:54 +02:00
Prowler Bot and prowler-bot
2298d4a3f8
chore(changelog): v5.36.0 ( #12109 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2026-07-24 12:22:40 +02:00
Pedro Martín
cf433128ed
fix(api): duplicate finding rows in outputs on tasks re-run ( #12097 )
2026-07-24 10:18:18 +02:00
Hugo Pereira Brito and Pablo F.G
0b782fcb8c
fix(kubernetes): block kubeconfig command auth bypass ( #12091 )
...
Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com >
2026-07-24 08:40:23 +01:00
Hugo Pereira Brito
3bd13d173d
fix(api): recover missing scan resources ( #12002 )
2026-07-22 12:24:45 +01:00
César Arroba
2b7f7e7dc0
fix(api): invoke m365 module without a hardcoded python version path ( #12085 )
2026-07-22 12:19:13 +02:00
Pedro Martín
d70a7e3d02
fix(api): scope integrations to role provider visibility ( #12060 )
2026-07-22 11:50:04 +02:00