Kay Agahd
|
67234210ba
|
feat(aws): add check secretsmanager_has_restrictive_resource_policy (#6985)
|
2026-04-27 21:49:34 +01:00 |
|
Hugo Pereira Brito
|
3441ad7f70
|
fix(sdk): align googleworkspace finding resources (#10901)
|
2026-04-27 15:17:29 +01:00 |
|
lydiavilchez
|
013809919c
|
feat(googleworkspace): add Gmail service with first batch of checks (#10683)
|
2026-04-27 13:49:07 +02:00 |
|
Daniel Barranquero
|
368d9c1519
|
fix(admincenter): restrict admincenter group visibility check to Unified groups (#10899)
|
2026-04-27 13:23:03 +02:00 |
|
Andoni Alonso
|
b668770480
|
feat(github): add zizmor GitHub Actions scanning as a service of the GitHub provider (#10607)
|
2026-04-27 08:55:07 +02:00 |
|
 Pedro MartínandAlan Buscaglia
|
d4ece2b43e
|
feat(sdk): add multi-provider compliance framework JSONs (#10300)
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com>
|
2026-04-24 13:27:31 +02:00 |
|
Daniel Barranquero
|
80d62f355f
|
fix(alibabacloud): fix CS service SDK compatibility and harden Alibaba provider (#10871)
|
2026-04-24 09:26:09 +02:00 |
|
 MathisdjangoandDaniel Barranquero
|
927be17fb7
|
feat(github): add check for dismissing stale PR approvals on default branch (CIS 1.1.4) (#10569)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-04-22 16:14:10 +02:00 |
|
 Andoni AlonsoandPepe Fagoaga
|
43bd1083e0
|
feat(sdk): add SARIF output format for IaC provider (#10626)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-04-22 09:32:20 +02:00 |
|
Pedro Martín
|
a24869fc26
|
feat(sdk): add universal compliance output modules (CSV, OCSF, table) (#10299)
|
2026-04-22 09:01:45 +02:00 |
|
Pepe Fagoaga
|
f2c5d2ec87
|
fix(aws): fallback lookup events to resource name (#10828)
|
2026-04-21 18:31:50 +02:00 |
|
 
|
39911e3ab7
|
feat(github): add --repo-list-file flag for GitHub scanning (#10501)
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com>
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-04-21 15:31:34 +02:00 |
|
Pedro Martín
|
ac6dd03fb8
|
feat(sdk): add universal compliance schema models and loaders (#10298)
|
2026-04-21 11:39:04 +02:00 |
|
Andoni Alonso
|
19c752c127
|
fix(cloudflare): guard validate_credentials against paginator infinite loops (#10771)
|
2026-04-17 11:23:31 +02:00 |
|
 Erich BlumeandAndoni A.
|
a2a1a73749
|
fix(image): --registry-list crashes with AttributeError on global_provider (#10691)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-04-16 13:02:25 +02:00 |
|
lydiavilchez
|
08fbe17e29
|
fix(googleworkspace): treat secure Google defaults as PASS for Drive checks (#10727)
|
2026-04-16 13:01:55 +02:00 |
|
lydiavilchez
|
d920f78059
|
fix(googleworkspace): treat secure Google defaults as PASS for Calendar checks (#10726)
|
2026-04-16 12:51:40 +02:00 |
|
Daniel Barranquero
|
43913b1592
|
feat(aws): support excluding regions from scans via CLI, env var, and config (#10688)
|
2026-04-15 17:59:46 +02:00 |
|
Daniel Barranquero
|
c3acb818d9
|
fix(vercel): handle team-scoped firewall config responses (#10695)
|
2026-04-15 11:59:20 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
a82eaa885d
|
refactor(m365): normalize CA platforms at model level (#10635)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-04-14 15:00:23 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
90a619a8b4
|
feat(m365): add entra_conditional_access_policy_block_unknown_device_platforms security check (#10615)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-04-14 14:32:37 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
638bf62d76
|
feat(entra): directory sync account exclusion (#10620)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-04-14 14:16:32 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
5610f5ad90
|
feat(m365): add entra_conditional_access_policy_corporate_device_sign_in_frequency_enforced security check (#10618)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-04-14 14:10:00 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
92b838866a
|
feat(m365): add entra_conditional_access_policy_mfa_enforced_for_guest_users security check (#10616)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-04-14 13:45:12 +02:00 |
|
Hugo Pereira Brito
|
e24e1ab771
|
feat(m365): add exchange_organization_delicensing_resiliency_enabled security check (#10608)
|
2026-04-14 13:30:45 +02:00 |
|
Hugo Pereira Brito
|
bc3fd79457
|
feat(intune): add device compliance policy marks noncompliant check (#10599)
|
2026-04-14 13:01:47 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
4941ed5797
|
feat(entra): add new check entra_conditional_access_policy_all_apps_all_users (#10619)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-04-14 12:47:57 +02:00 |
|
Daniel Barranquero
|
0f4d8ff891
|
feat(aws): add bedrock_vpc_endpoints_configured security check (#10591)
|
2026-04-14 12:22:22 +02:00 |
|
 Daniel BarranqueroandHugo P.Brito
|
d1ab8b8ae5
|
feat(aws): add iam_policy_no_wildcard_marketplace_subscribe and iam_inline_policy_no_wildcard_marketplace_subscribe checks (#10525)
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com>
|
2026-04-14 12:08:40 +02:00 |
|
Daniel Barranquero
|
65e9593b41
|
feat(aws): add bedrock_access_not_stale security check (#10536)
|
2026-04-14 11:20:40 +02:00 |
|
Daniel Barranquero
|
131112398b
|
feat(aws): add bedrock_full_access_policy_attached security check (#10577)
|
2026-04-14 11:00:40 +02:00 |
|
lydiavilchez
|
e33825747f
|
fix(googleworkspace): apply customer-level policy filter to Calendar service (#10658)
|
2026-04-13 11:26:35 +02:00 |
|
lydiavilchez
|
d919d979dd
|
feat(googleworkspace): add Drive and Docs service checks using Cloud Identity Policy API (#10648)
|
2026-04-13 10:48:24 +02:00 |
|
Alejandro Bailo
|
4e508b69c9
|
fix(vercel): use canonical Hub URLs in check metadata (#10636)
|
2026-04-09 16:23:50 +02:00 |
|
 Avula Jeevan YadavandAndoni A.
|
b898f257f1
|
feat(stepfunctions): add check for secrets in state machine definition (#10570)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-04-09 15:56:29 +02:00 |
|
Pedro Martín
|
56c370d3a4
|
chore(ccc): update with latest version and improve mapping (#10625)
|
2026-04-09 15:27:18 +02:00 |
|
lydiavilchez
|
bc38104903
|
feat(googleworkspace): add calendar service checks using Cloud Identity Policy API (#10597)
|
2026-04-08 13:26:56 +02:00 |
|
Andoni Alonso
|
9290d7e105
|
feat(sdk): warn when sensitive CLI flags receive explicit values (#10532)
|
2026-04-08 13:15:05 +02:00 |
|
 lydiavilchezandDaniel Barranquero
|
72e8f09c07
|
feat(googleworkspace): add directory check for CIS 1.1.3 - super admin only admin roles (#10488)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-04-08 12:05:15 +02:00 |
|
 Kay AgahdandClaude Opus 4.6
|
89fe867944
|
fix(aws): recognize service-specific condition keys as restrictive in is_policy_public (#10600)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
|
2026-04-08 10:55:55 +02:00 |
|
 Pepe FagoagaandAndoni Alonso
|
2be2753c55
|
fix(codeartifact): only retrieve the latest version from a package (#10243)
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com>
|
2026-04-08 09:21:19 +02:00 |
|
Josema Camacho
|
283259f34c
|
fix(sdk): resolve empty-set bug in _enabled_regions causing 36-region client creation and CI timeouts (#10598)
|
2026-04-08 08:40:58 +02:00 |
|
 
|
5e1e4bd8e4
|
fix(oci): Mutelist support (#10566)
Co-authored-by: Ronan Chota <ronan.chota@saic.com>
Co-authored-by: Hugo P.Brito <hugopbrito@users.noreply.github.com>
|
2026-04-07 13:23:51 +01:00 |
|
 
|
8985280621
|
fix(azure): create distinct report per key/secret in keyvault checks (#10332)
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com>
|
2026-04-07 09:36:48 +01:00 |
|
  
|
c99ed991b7
|
fix: show all checks including threat-detection in --list-checks (#10578)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: kaiisfree <kai@users.noreply.github.com>
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
|
2026-04-06 16:55:15 +01:00 |
|
 Adrián Peñaandalejandrobailo
|
ab8e83da3f
|
fix(api,ui): dynamically fetch Jira issue types instead of hardcoding "Task" (#10534)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
|
2026-04-01 14:37:49 +02:00 |
|
 
|
4f86667433
|
feat(sdk): add Vercel provider with 30 security checks (#10189)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-03-31 16:21:22 +02:00 |
|
Andoni Alonso
|
4bb1e5cff7
|
fix(sdk): redact sensitive CLI flags in HTML output (#10518)
|
2026-03-31 15:01:09 +02:00 |
|
 Hugo Pereira BritoandDaniel Barranquero
|
ab00c2dce1
|
feat(m365): add entra_conditional_access_policy_block_elevated_insider_risk security check (#10234)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-30 17:27:00 +02:00 |
|
 Erich BlumeandAndoni Alonso
|
de5bb94ff6
|
fix(image): pass registry arguments through init_global_provider (#10470)
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com>
|
2026-03-30 15:19:01 +02:00 |
|