César Arroba
15630f54d2
fix(aws): reuse the STS region that answered and add PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTS ( #12870 )
2026-09-24 10:24:44 +02:00
César Arroba and pedrooot
757cd44ecb
fix(aws): try the rest of the partition when the bootstrap region is unreachable ( #12799 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-09-16 09:24:41 +02:00
Pedro Martín
3860cd3dce
feat(compliance): FedRAMP 20x Class C FRR + AWS checks ( #12808 )
2026-09-14 16:35:05 +02:00
Pedro Martín
b378f15798
fix(aws): guard checks reading iam roles when unlisted ( #12785 )
2026-09-11 08:37:20 +02:00
StylusFrost and pedrooot
f9c02da90a
feat(aws): support the ISO partitions for region resolution and scanning ( #12759 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-09-10 17:15:13 +02:00
Pedro Martín
865eebe7fb
fix(aws): configurable boto3 timeouts, 10s connect default ( #12774 )
2026-09-10 08:21:27 +02:00
César Arroba and pedrooot
369f852837
fix(aws): lead the partition bootstrap regions with the configured region ( #12764 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-09-09 18:07:22 +02:00
Pedro Martín
bbf5e1fa9f
fix(tests): isolate secretsmanager policy test ( #12782 )
2026-09-09 16:58:35 +02:00
Pedro Martín
ab51d09543
fix(tests): isolate mock class attrs leaking across tests ( #12728 )
2026-09-03 12:20:33 +02:00
Pedro Martín
9621bdfb9c
fix(tests): isolate provider mock in agentcore passrole ( #12724 )
2026-09-03 10:15:49 +02:00
Jonathan Nguyen
86e4408f29
feat(ecr): assess enhanced scanning on registries holding repositories ( #12660 )
2026-09-02 08:53:52 +02:00
Jonathan Nguyen
ae43d21efb
fix(sagemaker): read DirectInternetAccess instead of RootAccess on notebook instances ( #12659 )
2026-09-01 18:22:41 +02:00
Daniel Barranquero
51c5fa7168
fix(checks): report MANUAL instead of FAIL on permission and data-availability errors ( #12645 )
2026-09-01 17:16:56 +02:00
Jonathan Nguyen
e9121f5f1a
feat(cloudwatch): add agentcore log group data protection policy check ( #12662 )
2026-09-01 17:04:16 +02:00
Jonathan Nguyen
821fe43efd
feat(iam): scope AgentCore PassRole and workload token grants, and flag unbound service trust ( #12664 )
2026-09-01 17:02:05 +02:00
Jonathan Nguyen
9ffbb4b758
fix(ecr): read each registry scanning rule's frequency instead of assuming scan on push ( #12560 )
2026-09-01 16:53:58 +02:00
Jonathan Nguyen
9c5285adc3
fix(cloudwatch): skip metric filters whose log group was not retrieved ( #12561 )
2026-09-01 14:00:41 +02:00
Jonathan Nguyen
e5df95c259
feat(eks): assess Kubernetes network policy enforcement in the Amazon VPC CNI add-on ( #12661 )
2026-09-01 13:40:45 +02:00
Jonathan Nguyen
b6a8af3c54
feat(guardduty): assess unified Runtime Monitoring and AI Protection ( #12564 )
2026-09-01 13:18:57 +02:00
Pedro Martín and David
6422178b76
feat(sdk): AWS partition selection via PROWLER_AWS_PARTITION ( #12680 )
...
Co-authored-by: David <david.copo@gmail.com >
2026-08-31 18:13:30 +02:00
Utkarsh Batham
e21946874f
feat(memorydb): add memorydb_cluster_in_transit_encryption_enabled check ( #12246 )
2026-08-28 14:03:10 +02:00
Sejal and Daniel Barranquero
2cae2058e9
feat(aws): add elasticbeanstalk_environment_no_secrets_in_configuration check ( #12378 )
...
Signed-off-by: unknown <sej1306kook@gmail.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-28 13:54:23 +02:00
83d8cfa829
fix(aws): treat security groups on Batch compute environments as used ( #12458 )
...
Co-authored-by: hackertwinten <193916571+hackertwinten@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-24 16:18:56 +02:00
Jonathan Nguyen and Hugo P.Brito
f39c92b8f8
feat(bedrock): add model artifact and guardrail grounding security checks for the AWS provider ( #12459 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-21 10:50:34 +01:00
Eugene C. and Hugo P.Brito
0b9791ffdc
feat(ecr): add ecr_repository_image_no_secrets check ( #12123 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-18 11:10:07 +01:00
ye11oc4t and Hugo P.Brito
f3224d0988
fix(ses): evaluate all identity authorization policies ( #12464 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-17 14:19:45 +01:00
2cd93fe119
fix(sdk): skip undescribed ECS task definitions ( #12217 )
...
Co-authored-by: Nguyễn Công Thuận Huy <nguyencongthuanhuy@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-08-17 12:42:06 +01:00
Pedro Martín
0758c3585d
feat(rolesanywhere): flag profiles with unscoped sessions ( #12416 )
2026-08-13 17:06:24 +02:00
praneetrajv and Daniel Barranquero
94594d6766
feat(batch): add batch_job_definition_no_secrets check ( #12117 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-08-07 11:57:58 +02:00
6e71dee85d
feat(awslambda): add awslambda_layer_no_secrets_in_content check ( #12233 )
...
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Claude Opus 5 <noreply@anthropic.com >
2026-08-07 11:33:54 +02:00
Pedro Martín
8bf788ea95
fix(aws): delegated administrator lookup and reporting ( #12319 )
2026-08-05 09:48:00 +02:00
Daniel Barranquero
a19fd70001
feat(aws): add pathfinding.cloud privilege-escalation coverage ( #12237 )
2026-08-04 08:59:52 +02:00
lydiavilchez
f19106281b
feat(aws): add Nitro Enclaves security checks for EC2 and KMS ( #12283 )
2026-08-03 13:00:26 +02:00
0b98a34687
feat(aws): add glue_catalog_connection_no_secrets check ( #11963 )
...
Signed-off-by: Alex Chen <l46983284@gmail.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Rishi943 <84287593+Rishi943@users.noreply.github.com >
Co-authored-by: Utkarsh <udaydeepak1928@gmail.com >
2026-07-30 15:12:37 +02:00
Siddhant Jadhav and Daniel Barranquero
fc0204a40d
feat(codecommit): add codecommit service and codecommit_repository_no_secrets check ( #11846 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-30 15:05:27 +02:00
7a6a35afec
feat(sagemaker): add sagemaker_endpoint_config_kms_encryption_enabled check ( #12118 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Alex Chen <l46983284@gmail.com >
2026-07-30 14:29:45 +02:00
Nithin Reddy and Daniel Barranquero
339930ef13
feat(ec2): add ec2_instance_stopped_older_than_specific_days check ( #12076 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-27 09:13:18 +02:00
kiranrajsg and Daniel Barranquero
97233189c3
feat(sagemaker): add sagemaker_notebook_instance_no_secrets check ( #11843 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-21 10:44:41 +02:00
Hugo Pereira Brito
8e9af708f8
feat(aws): add elbv2_listener_pqc_tls_enabled security check ( #11254 )
2026-07-15 12:45:23 +01:00
Deep Shah and Daniel Barranquero
24b670ac36
feat(sdk): add AWS Amplify app secret scanning check ( #11825 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-15 13:44:20 +02:00
Adrián Peña
470e218bb8
fix(sdk): preserve regional IMDSv2 account findings ( #11959 )
2026-07-13 17:32:08 +02:00
Hugo Pereira Brito
0f6137dd04
fix(aws): target EC2 Amazon AMI loading ( #11945 )
2026-07-13 15:33:30 +01:00
Hugo Pereira Brito
c6dae3a711
chore: remove __init__.py from test directories ( #10582 )
2026-07-13 15:09:42 +01:00
GOUTHAM HARIGOVIND and Daniel Barranquero
3369e48260
feat(ec2): Implement AMI block public access check ( #11794 ) ( #11828 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-10 13:10:15 +02:00
1ee4de18be
chore: add trailing newlines to 7 files for POSIX compliance ( #11765 )
...
Co-authored-by: Janderik Marins <janderik@email.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-09 18:19:55 +02:00
Yinka Metrics and Daniel Barranquero
0b36d08b92
feat(sdk): add Data Pipeline secret scanning check ( #11821 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-09 16:21:05 +02:00
Narahari Raghava and Daniel Barranquero
13bd6fc0bf
fix(aws): check statement Effect instead of policy Statement in SCP a… ( #11727 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-09 11:19:33 +02:00
Hugo Pereira Brito
25bcbac309
fix(dms): lazy load ec2 for public access check ( #11899 )
2026-07-08 16:42:23 +01:00
Hugo Pereira Brito
20aad80a78
fix(aws): avoid full ec2 inventory in dlm check ( #11850 )
2026-07-08 15:59:16 +01:00
Hugo Pereira Brito
991c204a88
fix(sdk): limit ECS task definitions by registration date ( #11868 )
2026-07-08 13:09:25 +01:00