César Arroba
92216f1597
ci(release): auto-create minor release branch and lift freeze on publish
...
Create the minor release branch automatically in the release preparation workflow, check versions before creating it, match the version literally, and lift the release freeze when the release is published.
2026-10-08 12:47:38 +02:00
Pedro Martín
f418b32c81
fix(oci): use home region for identity bootstrap ( #12865 )
2026-09-29 17:50:54 +02:00
César Arroba
94899e20fd
ci(ui): pass E2E AWS credentials through env vars ( #12864 )
2026-09-22 10:42:40 +02:00
Alan Buscaglia and alejandrobailo
2198ba2d84
feat(ui): complete Registry provider onboarding for Private Cloud ( #12494 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2026-09-16 12:21:25 +02:00
StylusFrost and pedrooot
f9c02da90a
feat(aws): support the ISO partitions for region resolution and scanning ( #12759 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-09-10 17:15:13 +02:00
César Arroba
806be2d061
chore(ci): bump agilepathway/label-checker to v1.6.66 ( #12760 )
2026-09-08 11:58:06 +02:00
Rubén De la Torre Vico
f299e1d9ac
fix(mcp): patch the two high sqlite CVEs in the container image ( #12537 )
2026-08-25 17:41:44 +02:00
Pablo Fernandez Guerra (PFE)
ba564af4f4
fix(ci): unblock the Python runtime download in blocked-egress jobs ( #12490 )
2026-08-20 10:48:16 +02:00
Pablo Fernandez Guerra (PFE)
f807b22ea6
ci: lint .github markdown and fix the violations it exposed ( #12290 )
2026-08-17 13:00:32 +02:00
Pepe Fagoaga
b6e9967da6
fix(deps): make published wheels installable and add package checks ( #12467 )
2026-08-17 12:34:11 +02:00
Pepe Fagoaga
0d3ce45374
fix(pypi): bump to pypa/gh-action-pypi-publish v1.14.2 ( #12456 )
2026-08-14 14:57:07 +02:00
Hugo Pereira Brito
9daca2e4df
fix(ci): suppress Trivy go-git vulnerability temporarily ( #12405 )
2026-08-10 10:41:19 +01:00
César Arroba
a700865340
ci: always report from actionlint, skipping the work when nothing changed ( #12371 )
2026-08-06 12:53:43 +02:00
César Arroba
07faddd64e
ci: fix the remaining shellcheck findings and enable the check ( #12367 )
2026-08-06 12:35:55 +02:00
César Arroba
1b9a44b164
fix(ci): keep the cloud sync dispatch payload within the 10-property limit ( #12370 )
2026-08-06 12:31:37 +02:00
César Arroba
b684ad06f3
ci: forward stacked PR metadata in the cloud sync dispatch ( #12368 )
2026-08-06 12:24:48 +02:00
César Arroba
76d7a2882c
ci: quote the unquoted shell expansions in workflows ( #12365 )
2026-08-06 11:59:40 +02:00
César Arroba
31d8faccfa
ci: check GitHub Actions schemas with actionlint ( #12361 )
2026-08-06 11:01:53 +02:00
César Arroba
f3c602a5ac
feat(container): ship an SBOM and provenance with the published images ( #12352 )
2026-08-05 16:19:42 +02:00
César Arroba
3b577907e4
ci(container): gate Grype only on fixable findings, and comment results on the PR ( #12341 )
2026-08-05 10:23:29 +02:00
César Arroba
87bc1eceae
ci(container): scan images with Grype alongside Trivy, blocking on critical and high ( #12340 )
2026-08-04 18:49:53 +02:00
César Arroba
765a1596f9
chore(docs): sync Docker Hub repository overviews from a single source ( #12333 )
2026-08-04 16:53:59 +02:00
Rubén De la Torre Vico
138d643119
test(mcp): add test foundation for the MCP server ( #12291 )
2026-08-04 16:19:10 +02:00
César Arroba
aab8154139
ci(workflows): align container build-push workflows across api, ui, mcp and sdk ( #12310 )
2026-08-04 10:25:31 +02:00
Copilot and Pepe Fagoaga
e15f6970ef
fix(ci): use PROWLER_BOT_ACCESS_TOKEN for release freeze ( #12295 )
...
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-08-03 14:45:23 +02:00
Pablo Fernandez Guerra (PFE) and Pablo F.G
2db3bebd15
feat(ui): GCP org onboarding — canonical contract + shared lifecycle ( #12255 )
...
Co-authored-by: Pablo F.G <pablo.fernandez@prowler.com >
2026-07-31 13:30:46 +02:00
César Arroba
7275b46707
chore(ci): repin trivy-action to a resolvable tag ( #12257 )
2026-07-31 09:51:18 +02:00
stepsecurity-app[bot]
8abd72e857
feat(security): security best practices from StepSecurity ( #12254 )
...
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io >
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
2026-07-31 09:27:01 +02:00
Alan Buscaglia
7a62926a09
fix(ui): stabilize cloud e2e prerequisites ( #12024 )
2026-07-30 14:54:26 +02:00
stepsecurity-app[bot]
a57a507cee
feat(security): security best practices from StepSecurity ( #12232 )
...
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io >
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
2026-07-30 09:24:44 +02:00
Hugo Pereira Brito
1bb3fc9bda
ci: add release freeze gate ( #11621 )
2026-07-29 10:08:15 +01:00
f5fe9c7b40
ci(helm): publish immutable chart versions on release ( #12056 )
...
Co-authored-by: Cursor <cursoragent@cursor.com >
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-07-27 16:58:59 +02:00
César Arroba
98015dafef
ci(api): scan the SDK pin that ships, not the committed lock ( #12084 )
2026-07-22 12:08:40 +02:00
Pepe Fagoaga
7df1054966
chore(step-security): allow endpoints ( #11973 )
2026-07-14 12:02:35 +02:00
stepsecurity-app[bot]
c7583a5633
feat(security): security best practices from StepSecurity ( #11962 )
...
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io >
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
2026-07-14 08:17:06 +02:00
Hugo Pereira Brito
c6dae3a711
chore: remove __init__.py from test directories ( #10582 )
2026-07-13 15:09:42 +01:00
Hugo Pereira Brito
cef131812c
fix(ci): correct bot and dependency PR labeling ( #11425 )
2026-07-13 09:06:12 +01:00
Pepe Fagoaga
3c78a0df43
fix(changelog): correct fragments for the UI ( #11952 )
2026-07-13 09:31:57 +02:00
lydiavilchez
08ee83c572
fix(docs): use python3 and add CI check for provider cards hook ( #11930 )
2026-07-10 09:27:34 +02:00
stepsecurity-app[bot] and Pepe Fagoaga
2a077cae5e
feat(security): security best practices from StepSecurity ( #11937 )
...
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io >
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-07-10 09:00:40 +02:00
César Arroba
9d899ae0e2
ci: rename public ECR push-role secret to PUBLIC_ECR_PUSH_ROLE_ARN ( #11916 )
2026-07-09 11:27:55 +02:00
Pepe Fagoaga
c665005790
fix(workflow): bump AI issue triage ( #11896 )
2026-07-08 15:45:52 +02:00
UniCode and Daniel Barranquero
d874fc573d
feat(e2e): provider for e2e cloud ( #11654 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-07-08 14:21:27 +02:00
Adrián Peña
6c5f54808d
feat: add changelog fragments workflow ( #11572 )
2026-07-08 10:19:12 +02:00
César Arroba
76a2d7bfe6
ci: skip codeql and e2e on changelog-only changes ( #11867 )
2026-07-07 14:27:41 +02:00
renovate[bot]
ce80fcd430
chore(ci): update github-actions ( #11314 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-02 09:08:16 +02:00
César Arroba
050a5915ca
fix(ci): detect conflict markers in route-group paths and flag unmergeable PRs ( #11763 )
2026-07-01 17:50:33 +02:00
César Arroba
9a9cbc997b
ci(workflows): push SDK image to Public ECR via OIDC ( #11749 )
2026-06-30 21:17:57 +02:00
César Arroba
aec500ee3b
fix(ci): harden pull_request_target workflows (persist-credentials + toJson) ( #11747 )
2026-06-30 18:29:29 +02:00
César Arroba
8fbc721223
ci(workflows): allowlist nodejs.org and Iconify endpoints in UI tests harden-runner ( #11744 )
2026-06-30 17:43:02 +02:00