StylusFrost
efa3283a25
fix(provider): return generic OutputOptions default instead of raising
...
External providers that do not override get_output_options no longer abort
the run with NotImplementedError. The base contract returns a generic
ProviderOutputOptions, honoring arguments.output_filename and otherwise
falling back to a provider-typed filename. Built-ins are unaffected.
2026-06-05 13:42:29 +02:00
StylusFrost
38788b7922
Merge remote-tracking branch 'origin/master' into PROWLER-1391-provider-contract-dynamic-discovery
...
# Conflicts:
# prowler/CHANGELOG.md
2026-06-03 12:15:24 +02:00
Pedro Martín
f7f8747512
feat(compliance): add DORA framework for AWS ( #11131 )
2026-06-03 11:43:55 +02:00
d573af911d
feat(aws): add sagemaker_models_monitor_enabled check ( #11278 )
...
Co-authored-by: RishiWig3 <rishi.wig@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2026-06-02 16:10:13 +01:00
Pedro Martín and Pepe Fagoaga
a652e28b4a
fix(api): clean up scan tmp output failure to avoid disk fill ( #11421 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-06-02 11:37:05 +02:00
StylusFrost
9c7afd64c5
fix(sdk): match compliance provider segment exactly in get_bulk
...
- Compare the module's last dotted segment instead of substring
- Prevent a provider name from capturing overlapping built-ins
- Add parametrized regression test (cloud, git, work, open cases)
- Update get_bulk test mock to the real dotted module name
2026-06-01 19:51:27 +02:00
StylusFrost
64e82682bd
fix(sdk): detect shadowed provider plug-ins without loading them
...
- Match shadowing entry point by name instead of calling ep.load()
- Prevent plug-in code from executing during a built-in run
- Update regression test to assert ep.load is never called
2026-06-01 19:44:17 +02:00
StylusFrost
5070ce39c2
fix(sdk): guard built-in providers in is_tool_wrapper_provider
...
- Short-circuit on is_builtin_provider before loading entry points
- Prevent same-name plug-ins from flipping a built-in onto the tool-wrapper path
- Avoid executing plug-in code via ep.load() for built-in names
- Add regression test asserting ep.load is never called
2026-06-01 19:43:36 +02:00
StylusFrost
e1ade761b5
Merge branch 'master' into PROWLER-1391-provider-contract-dynamic-discovery
2026-05-31 19:30:23 +02:00
e3c4368d32
fix(azure): pass authority to credentials for sovereign clouds ( #10284 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2026-05-29 15:17:41 +02:00
a2824f7166
feat(stackit): add new provider with 4 checks ( #9237 )
...
Co-authored-by: Claude <noreply@anthropic.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2026-05-28 13:16:38 +02:00
lydiavilchez and Daniel Barranquero
c58dad2ca4
feat(googleworkspace): add rules service checks ( #11379 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-28 11:17:33 +02:00
b4befe3a10
feat(googleworkspace): add security service checks ( #11356 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-28 10:15:10 +02:00
StylusFrost
ca72922dca
Merge branch 'master' into PROWLER-1391-provider-contract-dynamic-discovery
2026-05-27 17:12:54 +02:00
Daniel Barranquero
2678c6bc9f
feat(okta): add application service with 6 new checks ( #11358 )
2026-05-27 11:16:18 +02:00
Pedro Martín
48c071297f
fix(sdk): align compliance CSV row emission with framework JSON ( #11370 )
2026-05-27 11:06:23 +02:00
Pedro Martín
723d161c63
fix(az-m365): asyncio.run() in Azure/M365 Celery worker event ( #11360 )
2026-05-26 11:26:39 +02:00
Aline Almeida and Hugo Pereira Brito
d560020592
fix(gcp): match enable-oslogin metadata case-insensitively ( #11341 )
...
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2026-05-26 10:35:26 +02:00
Hugo Pereira Brito and Daniel Barranquero
4c59af93eb
fix(azure): require all SMB channel encryption algorithms to be secure (storage_smb_channel_encryption_with_secure_algorithm) ( #11327 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-25 18:28:21 +02:00
Hugo Pereira Brito
6ca8e726f7
feat(azure): add storage_account_public_network_access_disabled and fix CIS storage mapping ( #11334 )
2026-05-25 18:17:41 +02:00
Kristofer Jussmann and Hugo P.Brito
6177fc6286
fix(oci): use home region for audit configuration API call ( #10347 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-21 16:09:29 +01:00
Sandiyo Christan and Hugo P.Brito
0fd952ae2b
chore(m365): use PowerShell best practices for quoting credential variables ( #9997 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-21 15:17:23 +01:00
lydiavilchez
74622dd576
feat(googleworkspace): add sites, additional_services and marketplace service checks ( #11281 )
2026-05-21 15:52:15 +02:00
Daniel Barranquero
349611d52d
feat(okta): 4 new signon service checks ( #11224 )
2026-05-21 12:48:06 +02:00
534dedb608
feat(sagemaker): add sagemaker_models_registry_in_use check ( #11196 )
...
Co-authored-by: cascioli <simdon2015?gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-20 13:59:18 +02:00
cff1704d7b
feat(ses): add check for DKIM signing enabled on SES identities ( #10923 )
...
Co-authored-by: Mohamed Solaiman <mohamedsolaiman@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com >
2026-05-20 13:33:03 +02:00
lydiavilchez
0ca444895f
feat(googleworkspace): add groups service checks ( #11186 )
2026-05-20 12:54:49 +02:00
Daniel Barranquero
6eebfcfe77
feat(api): add okta provider support ( #11184 )
2026-05-20 10:46:29 +02:00
Hugo Pereira Brito
40c1761840
fix(s3): only emit shadow-resource finding when bucket name matches a predictable pattern ( #11220 )
2026-05-19 15:46:05 +01:00
Pedro Martín
0ab0e8671d
fix(azure): skip system 'master' DB in sqlserver_tde_encrypted_with_cmk ( #11233 )
2026-05-19 16:34:33 +02:00
7a7c828fc7
feat(m365/entra): add entra_app_registration_client_secret_unused check (consolidates #11097 and #11212 ) ( #11232 )
...
Co-authored-by: shadyfox <git@twink.energy >
Co-authored-by: Oleksandr Yizchak Sanin <alexaaander.sanin@gmail.com >
2026-05-19 15:14:32 +01:00
s1ns3nz0 and Daniel Barranquero
9dc4deccb6
feat(gcp): add cloudsql_instance_cmek_encryption_enabled check ( #11023 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-19 15:52:16 +02:00
Pedro Martín
bfcbe0a9c4
feat(scaleway): add new provider ( #11166 )
2026-05-18 16:42:10 +02:00
Pedro Martín
5ca6e31f45
fix(vercel): exclude API token from serialization and repr ( #11198 )
2026-05-18 14:30:44 +02:00
lydiavilchez
9894ac7bc3
feat(googleworkspace): implement Chat service with 6 CIS checks ( #11126 )
2026-05-14 17:19:11 +02:00
lydiavilchez
bf4fd8fabd
fix(googleworkspace): use per-service resources for Directory ( #11176 )
2026-05-14 13:07:06 +02:00
lydiavilchez
5f92989492
fix(googleworkspace): use per-service resources for Calendar and Drive ( #11161 )
2026-05-14 12:43:29 +02:00
Hugo Pereira Brito
6befa78978
fix(cloudflare): plan-aware WAF FAIL hints for zones ( #9896 )
2026-05-14 12:27:47 +02:00
lydiavilchez
78af0c24fe
fix(googleworkspace): use per-service resources for Gmail ( #11169 )
2026-05-14 12:01:07 +02:00
June and Daniel Barranquero
1f39b01fb2
feat(sagemaker): add sagemaker_domain_sso_configured check ( #11094 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-14 11:42:30 +02:00
Hugo Pereira Brito
739be07077
chore(aws): skip unattached IAM policies unless --scan-unused-services ( #11150 )
2026-05-14 08:10:20 +01:00
Daniel Barranquero
4dd5baadf6
feat(okta): add provider to the SDK with 1 security check ( #11079 )
2026-05-13 15:57:57 +02:00
abdou and Hugo P.Brito
7f3dcdf02f
fix(m365): surface AuditLog.Read.All permission errors instead of false positives ( #10907 )
...
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-12 18:22:19 +01:00
Hugo Pereira Brito and Hugo P.Brito
1b99550572
feat(m365): add entra_service_principal_no_secrets_for_permanent_tier0_roles security check ( #10788 )
...
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home >
2026-05-12 10:45:32 +01:00
Hugo Pereira Brito
80482da1cb
refactor(m365): scope entra_emergency_access_exclusion to Block-grant policies ( #10849 )
2026-05-12 10:40:46 +01:00
Hugo Pereira Brito
1b0e12ec51
fix(m365): exclude disabled guest users from entra_users_mfa_capable ( #11002 )
2026-05-12 08:35:24 +01:00
Daniel Barranquero
759f7b84d6
feat(aws): add cloudtrail_bedrock_logging_enabled security check ( #10858 )
2026-05-11 17:11:49 +02:00
Hugo Pereira Brito and Hugo P.Brito
0b26c1a39c
feat(aws): add iam_user_access_not_stale_to_sagemaker security check ( #11000 )
...
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home >
2026-05-11 16:34:18 +02:00
Daniel Barranquero
73c0305dc4
feat(aws): add bedrock_prompt_encrypted_with_cmk security check ( #10905 )
2026-05-11 10:32:44 +02:00
lydiavilchez
962ebac8e4
feat(googleworkspace): add Gmail consequence-based checks for attachment safety and spoofing ( #10980 )
2026-05-07 16:50:36 +02:00