Daniel Barranquero
bdae47d61b
feat: add changelog
2025-10-08 16:59:32 +02:00
Daniel Barranquero
e3a7d89948
fix(m365): attribute errors in defender, exchange and admincenter
2025-10-08 16:54:52 +02:00
Hugo Pereira Brito
c7d7ec9a3b
fix: add pagination for m365 and azure users retrieval ( #8858 )
2025-10-08 09:07:18 +02:00
Rubén De la Torre Vico
155a1813cc
chore(aws): enhance metadata for cloudformation service ( #8828 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-10-07 16:39:23 +02:00
Rubén De la Torre Vico
71e444d4ae
chore: improve API docs for Provider endpoints ( #8723 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-10-07 15:30:14 +02:00
Víctor Fernández Poyatos
42b7f0f1a9
fix(migrations): API key RLS migration ( #8863 )
2025-10-07 12:39:30 +02:00
Josema Camacho
5b3f0fbd7f
fix(doc): document about using the same .env as the code version ( #8804 )
2025-10-07 09:38:20 +02:00
Josema Camacho
06eb69e455
chore(security): update Django to 5.1.13 ( #8842 )
2025-10-07 09:38:11 +02:00
Rubén De la Torre Vico
338a11eaaf
chore(aws): enhance metadata for account service ( #8715 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-10-06 12:27:47 -05:00
Alejandro Bailo
8814a0710a
fix(scans): detail drawer fails after dependencies migration ( #8856 )
2025-10-06 17:52:38 +02:00
Chandrapal Badshah
76a55cdb54
fix: remove maxTokens for gpt-5 ( #8843 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-10-06 17:25:20 +02:00
Rubén De la Torre Vico
736badb284
chore(aws): enhance metadata for appstream service ( #8789 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2025-10-06 15:29:06 +02:00
Prowler Bot
37f77bb778
chore(regions_update): Changes in regions for AWS services ( #8847 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-10-06 08:23:03 -05:00
Daniel Barranquero
7e5e48c588
fix(changelog): duplicated v5.12.4 in SDK changelog ( #8852 )
2025-10-06 08:22:15 -05:00
Hugo Pereira Brito
5f0017046f
chore(findings): change References display in UI ( #8793 )
2025-10-06 14:04:20 +02:00
Víctor Fernández Poyatos
612d867838
fix(tests): Race condition on redundant API unit test ( #8849 )
2025-10-06 12:42:16 +02:00
Rubén De la Torre Vico
8c2668ebe4
chore: rename docs AGENTS ( #8846 )
2025-10-06 10:53:17 +02:00
Rubén De la Torre Vico
be4b1bd99b
chore: add first version of AGENTS.md ( #8799 )
2025-10-06 10:47:51 +02:00
Daniel Barranquero
502525eff1
fix(compliance): generate file extension correctly ( #8791 )
2025-10-06 10:27:16 +02:00
Rubén De la Torre Vico
09b5afe9c3
chore(aws): enhance metadata for awslambda service ( #8825 )
...
Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-10-03 13:48:55 +02:00
Víctor Fernández Poyatos
9a4fc784db
feat(api-keys): Add API Key support for the Prowler API ( #8805 )
2025-10-03 13:42:43 +02:00
Rubén De la Torre Vico
04177db648
chore(aws): enhance metadata for apigateway service ( #8788 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2025-10-03 11:49:33 +02:00
Alejandro Bailo
2408dbf855
chore(ui): upgrade zod v4, zustand v5, and ai sdk v5 ( #8801 )
2025-10-03 09:57:46 +02:00
Pepe Fagoaga
9c4a8782e4
fix(conflict-checker): fail on conflict ( #8840 )
2025-10-03 13:11:45 +05:45
dependabot[bot]
0d549ea39e
chore(deps): bump github/codeql-action from 3.29.7 to 3.30.5 ( #8812 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: César Arroba <cesar@prowler.com >
2025-10-02 10:36:02 +02:00
dependabot[bot]
0060081cad
chore(deps): bump peter-evans/repository-dispatch from 3.0.0 to 4.0.0 ( #8821 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:35:02 +02:00
dependabot[bot]
0c2d06dd9a
chore(deps): bump actions/setup-node from 4.4.0 to 5.0.0 ( #8819 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:34:21 +02:00
dependabot[bot]
14b9be4c47
chore(deps): bump tj-actions/changed-files from 46.0.5 to 47.0.0 ( #8814 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:33:13 +02:00
dependabot[bot]
6bac5650e6
chore(deps): bump aws-actions/configure-aws-credentials from 4.2.1 to 5.0.0 ( #8813 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:32:55 +02:00
dependabot[bot]
6170462a61
chore(deps): bump actions/github-script from 7.0.1 to 8.0.0 ( #8820 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:32:10 +02:00
dependabot[bot]
2ad5926b13
chore(deps): bump actions/setup-python from 5.6.0 to 6.0.0 ( #8818 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:31:20 +02:00
dependabot[bot]
a6ddc85e4c
chore(deps): bump codecov/codecov-action from 5.4.3 to 5.5.1 ( #8811 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:30:27 +02:00
dependabot[bot]
aceff35f29
chore(deps): bump peter-evans/find-comment from 3.1.0 to 4.0.0 ( #8817 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:29:46 +02:00
dependabot[bot]
3ae96c3aa6
chore(deps): bump actions/labeler from 5.0.0 to 6.0.1 ( #8816 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:28:56 +02:00
dependabot[bot]
0dcaaa9083
chore(deps): bump actions/cache from 4.2.3 to 4.3.0 ( #8815 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:28:43 +02:00
dependabot[bot]
323a7f0349
chore(deps): bump docker/login-action from 3.4.0 to 3.6.0 ( #8810 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:25:49 +02:00
dependabot[bot]
736cbea862
chore(deps): bump softprops/action-gh-release from 2.3.2 to 2.3.3 ( #8809 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:25:04 +02:00
dependabot[bot]
d3e290978e
chore(deps): bump actions/checkout from 4.2.2 to 5.0.0 ( #8808 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:24:41 +02:00
dependabot[bot]
9c91cfcb7d
chore(deps): bump trufflesecurity/trufflehog from 3.90.2 to 3.90.8 ( #8807 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-10-02 10:23:41 +02:00
Daniel Barranquero
e279f7fcfd
fix: handle eks cluster version and listener certificate arn not in acm ( #8802 )
2025-10-01 13:55:26 -04:00
Hugo Pereira Brito
a555cffebe
fix(html): preserve markdown formatting in read-more functionality ( #8803 )
2025-10-01 13:48:20 -04:00
César Arroba
49f5435392
chore(gha): check API changes for versioning ( #8532 )
2025-10-01 15:32:08 +02:00
Rubén De la Torre Vico
a087dd9b85
chore(aws): enhance metadata for accessanalyzer service ( #8688 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2025-10-01 15:05:44 +02:00
Rubén De la Torre Vico
6e89c301b2
chore(aws): enhance metadata for athena service ( #8790 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-10-01 13:59:03 +02:00
Pedro Martín
d5dac448a6
fix(m365): add framework and name for iso27001 ( #8792 )
2025-10-01 13:43:55 +02:00
Pepe Fagoaga
00e6eb35f1
fix(workflows): load latest SDK only for master ( #8796 )
2025-10-01 13:35:43 +05:45
Hugo Pereira Brito
cdb455b2b1
feat(aws): add new check ec2_instance_with_outdated_ami ( #6910 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-09-30 13:54:36 -04:00
Sergio Garcia
837c65ba23
chore(securityhub): improve logging for Security Hub integration ( #8608 )
2025-09-30 10:36:42 -04:00
OlmeNav
035293b612
feat: Verify that the CheckID is the same as the filename and classname in the Check class ( #8690 )
...
Co-authored-by: angelolmn <e.angelolm#go.ugr.es>
Co-authored-by: César Arroba <cesar@prowler.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-09-30 13:46:59 +02:00
Rubén De la Torre Vico
250b5df836
chore(aws): enhance metadata for acm service ( #8716 )
...
Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-09-30 13:33:09 +02:00
Josema Camacho
ec59dbc6ee
fix: move delete user 500 error fix to its right version ( #8787 )
2025-09-30 10:56:29 +02:00
Alan Buscaglia
4d5676f00e
feat: upgrade to React 19, Next.js 15, React Compiler, HeroUI and Tailwind 4 ( #8748 )
...
Co-authored-by: Alan Buscaglia <alanbuscaglia@MacBook-Pro.local >
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
Co-authored-by: César Arroba <cesar@prowler.com >
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com >
2025-09-30 09:59:51 +02:00
MustafaAamir
2a4b62527a
fix(tests_iam): AWS managed policies are isolated ( #8609 )
...
Co-authored-by: MustafaAamir <mustafa@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-09-30 13:44:03 +05:45
Josema Camacho
ec0341c696
fix(user): PermissionError, 500, when deleting user ( #8731 )
2025-09-30 09:49:33 +02:00
Rubén De la Torre Vico
2e5f3a5a66
feat(aws): enhance metadata for apigatewayv2 service ( #8719 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-09-29 12:35:05 -04:00
dependabot[bot]
231a5fab86
chore(deps-dev): bump authlib from 1.6.1 to 1.6.4 ( #8741 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-09-29 12:08:47 -04:00
Andoni Alonso
10319ea69d
docs(github): refactor getting started and auth ( #8767 )
2025-09-29 11:33:15 -04:00
Sergio Garcia
53bb5aff22
feat(llm): add LLM provider ( #8555 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-09-29 11:24:10 -04:00
Rubén De la Torre Vico
52a5fff61f
chore(aws): enhance metadata for appsync service ( #8721 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-09-29 16:36:43 +02:00
Andoni Alonso
f28754b883
docs(iac): refactor getting started and auth ( #8779 )
2025-09-29 15:41:25 +02:00
Pedro Martín
6fce797ca2
feat(compliance-mapper): add first version ( #8568 )
2025-09-29 15:40:29 +02:00
Adrián Jesús Peña Rodríguez
a1fd315104
ref(actions): remove xmlsec step ( #8482 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-09-29 13:04:33 +02:00
Prowler Bot
a91f0ac8b5
chore(regions_update): Changes in regions for AWS services ( #8777 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-09-29 16:27:27 +05:45
Andoni Alonso
2c96df05f4
docs(mongodbatlas): refactor getting started and auth ( #8776 )
2025-09-29 11:58:09 +02:00
Chandrapal Badshah
b57788c7b9
fix: update prowler package version in api ( #8778 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-29 11:44:45 +02:00
Pedro Martín
7431bab2a7
docs(threatscore): add info with Prowler ThreatScore ( #8711 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-09-29 11:17:05 +02:00
Andoni Alonso
a52697bfdf
docs(m365): refactor getting started and auth ( #8761 )
2025-09-29 10:01:40 +02:00
Alejandro Bailo
9dc2199381
feat(ui): add compliance_name ( #8775 )
2025-09-29 09:59:18 +02:00
Rubén De la Torre Vico
89db760b89
docs(mcp): add preview feature disclaimer ( #8774 )
2025-09-29 09:42:16 +02:00
Chandrapal Badshah
4356c1e186
fix(ui): update ui changelog ( #8771 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-26 17:08:17 +02:00
Rubén De la Torre Vico
e32cebc553
feat(mcp): add Dockerfile for MCP Server containerization ( #8768 )
2025-09-26 15:04:24 +02:00
Andoni Alonso
23e1cc281d
docs(azure): refactor getting started and auth ( #8754 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-09-26 15:02:57 +02:00
Josema Camacho
48d3fb4fe3
feat(doc): 📚 add documenation about JWT keys autogeneration ( #8766 )
2025-09-26 13:52:46 +05:45
César Arroba
ab727e6816
chore(gha): fix e2e workflow ( #8769 )
2025-09-25 22:13:53 +05:45
Rubén De la Torre Vico
23d882d7ab
feat(mcp): add Prowler App MCP Server ( #8744 )
2025-09-25 15:21:34 +02:00
Alejandro Bailo
59435167ea
fix(scans): update link disable condition for findings table ( #8762 )
2025-09-25 12:57:22 +02:00
Andoni Alonso
77cdd793f8
fix(aws): cover SNS ResourceID in Quick Inventory output ( #8763 )
2025-09-25 11:14:32 +02:00
Andoni Alonso
d13f3f0e0c
docs(gcp): refactor getting started and auth ( #8758 )
2025-09-25 10:19:01 +02:00
Víctor Fernández Poyatos
56821de2f4
feat(tasks): Move compliance tasks to compliance queue ( #8755 )
2025-09-24 14:00:17 +02:00
Daniel Barranquero
92190fa69f
feat(docs): add renaming checks to developer guide ( #8717 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-09-24 11:46:52 +02:00
Prowler Bot
85db7c5183
chore(regions_update): Changes in regions for AWS services ( #8736 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-09-24 10:38:12 +02:00
Josema Camacho
a55ac266bf
chore(django): update django to 5.1.12 due to security problems ( #8693 )
2025-09-23 16:35:25 +05:45
Andoni Alonso
90622e0437
docs: update Entra SSO SAML video link ( #8745 )
2025-09-23 12:43:51 +02:00
Pepe Fagoaga
81596250dc
fix(actions): lock poetry after changes ( #8477 )
2025-09-23 14:31:45 +05:45
Rubén De la Torre Vico
43db5fe527
feat(mcp): add basic logger ( #8740 )
2025-09-23 09:09:38 +02:00
Pepe Fagoaga
dfb479fa80
chore(readme): remove deprecations and fix typo ( #8739 )
2025-09-22 20:31:42 +05:45
Pedro Martín
aa88b453ff
fix(compliance): change order in models and remove prints ( #8738 )
2025-09-22 15:45:09 +02:00
Pedro Martín
fbda66c6d1
feat(compliance): add name for each compliance ( #7920 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-09-22 14:53:27 +02:00
Adrián Jesús Peña Rodríguez
2200e65519
feat(auth): add safeguards to prevent self-role removal and enforce MANAGE_ACCOUNT role presence ( #8729 )
2025-09-22 14:04:39 +02:00
Josema Camacho
b8537aa22d
feat(config): add generation for JWT keys if missing ( #8655 )
2025-09-22 13:14:54 +02:00
Rubén De la Torre Vico
cb4a5dec79
chore: set an appropiate User-Agent in requests ( #8724 )
2025-09-22 12:48:13 +02:00
Rubén De la Torre Vico
0286de7ce2
chore: add mcp_server component labeler configuration ( #8737 )
2025-09-22 15:40:23 +05:45
Pepe Fagoaga
b00602f109
fix(users): only list roles and memberships with manage_account ( #8281 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-09-22 11:25:24 +02:00
Adrián Jesús Peña Rodríguez
1cfae546a0
chore(deps): add markdown package version 3.9 to dependencies ( #8735 )
2025-09-22 10:44:26 +02:00
Sergio Garcia
05dae4e8d1
fix(iac): handle empty results ( #8733 )
2025-09-16 14:20:15 +02:00
dependabot[bot]
52ddaca4c5
chore(deps-dev): bump moto from 5.0.28 to 5.1.11 ( #7100 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-09-16 14:17:47 +02:00
Alejandro Bailo
940a1202b3
fix: handle 4XX and 204 properly ( #8722 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-09-15 17:07:15 +02:00
Prowler Bot
ec27451199
chore(regions_update): Changes in regions for AWS services ( #8728 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-09-15 15:02:37 +02:00
Sergio Garcia
60e06dcc6e
chore(html): support markdown in HTML ( #8727 )
2025-09-15 11:38:18 +02:00
Hugo Pereira Brito
7733aab088
feat: add additional_urls to finding details and markdown ( #8704 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-09-15 11:33:27 +02:00
Pepe Fagoaga
5c6fadcfe7
chore(changelog): remove whitespace in links ( #8712 )
2025-09-12 17:09:19 +05:45
César Arroba
1bdb314e2c
chore(gha): permissions missed for conflict checker action ( #8714 )
2025-09-12 12:37:12 +02:00
Rubén De la Torre Vico
5b0365947f
feat: add first Prowler MCP server version ( #8695 )
2025-09-12 09:56:36 +02:00
Daniel Barranquero
b512f6c421
fix(firehose): false positive in firehose_stream_encrypted_at_rest ( #8599 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-09-11 09:55:16 -04:00
Alejandro Bailo
c4a8771647
chore(dependencies): update package versions and track them ( #8696 )
2025-09-11 15:36:06 +02:00
Alejandro Bailo
6f967c6da7
fix(auth): validate email field ( #8698 )
2025-09-11 15:29:49 +02:00
Alejandro Bailo
82cd29d595
fix(auth): add method attribute to form for proper submission handling ( #8699 )
2025-09-11 15:02:36 +02:00
Daniel Barranquero
14c2334e1b
fix(defender): change policies rules key ( #8702 )
2025-09-11 13:46:21 +02:00
Rubén De la Torre Vico
3598514cb4
chore(aws/config): adapt metadata to new standarized format ( #8641 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2025-09-10 17:46:11 +02:00
Hugo Pereira Brito
c4ba061f30
chore(outputs): adapt to new metadata specification ( #8651 )
2025-09-10 17:21:19 +02:00
Chandrapal Badshah
f4530b21d2
fix(lighthouse): make Enter submit text ( #8664 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-10 16:34:35 +02:00
Chandrapal Badshah
3949ab736d
fix(lighthouse): allow scrolling during AI response streaming ( #8669 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-10 16:34:24 +02:00
sumit-tft
9da5066b18
feat(ui): add copy link icon to finding detail page ( #8685 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-09-10 16:30:16 +02:00
Rubén De la Torre Vico
941539616c
chore(aws/neptune): adapt some metadata fields to new format ( #8494 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2025-09-10 16:21:30 +02:00
sumit-tft
135fa044b7
feat(ui): Add Prowler Hub menu item with tooltip ( #8692 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-09-10 16:09:09 +02:00
Andoni Alonso
48913c1886
docs(aws): refactor getting started and auth ( #8683 )
2025-09-10 13:45:36 +02:00
Pedro Martín
ea20943f83
feat(actions): support dashboard changes in changelog ( #8694 )
2025-09-10 11:05:56 +02:00
Hugo Pereira Brito
2738cfd1bd
feat(dashboard): add Description and markdown support ( #8667 )
2025-09-10 10:53:53 +02:00
Rubén De la Torre Vico
265c3d818e
docs(developer-guide): enhance check metadata format ( #8411 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
2025-09-10 09:19:08 +02:00
Alejandro Bailo
c0a9fdf8c8
docs(jira): add comprehensive guide for Jira integration in Prowler App ( #8681 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-09-09 17:01:12 +02:00
Rubén De la Torre Vico
8b3335f426
chore: add metadata-review label for .metadata.json files ( #8689 )
2025-09-09 20:32:04 +05:45
Daniel Barranquero
252033d113
fix(compliance): replace old check id with new one ( #8682 )
2025-09-09 14:25:56 +02:00
Prowler Bot
0bc00dbca4
chore(release): Bump version to v5.13.0 ( #8679 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-09-09 16:36:22 +05:45
Adrián Jesús Peña Rodríguez
3f5178bffb
chore: update api changelog ( #8677 )
2025-09-09 10:23:55 +02:00
Josema Camacho
e08b272a1d
fix(login): add DRF throttle option for dj-rest-auth lib ( #8672 )
2025-09-09 09:34:02 +02:00
Pedro Martín
64c43a288d
feat(jira): add force accept language for requests ( #8674 )
2025-09-09 13:17:25 +05:45
Daniel Barranquero
74bf0e6b47
fix(aws): nonetype errors in opensearch, firehose and cognito ( #8670 )
2025-09-09 13:12:57 +05:45
Andoni Alonso
02b7c5328f
docs: update providers table ( #8676 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-09-09 09:25:20 +02:00
Alejandro Bailo
bb02004e7c
fix: social auth buttons showed for sign-up ( #8673 )
2025-09-09 09:23:56 +02:00
Andoni Alonso
82cf216a74
feat(mongodbatlas): add MongoDB Atlas provider PoC ( #8312 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-09-09 09:18:37 +02:00
Daniel Barranquero
7916425ed4
fix(memorydb): handle clusters with no security groups ( #8666 )
2025-09-08 15:05:13 -04:00
Andoni Alonso
d98063ed47
docs: add interface column to providers ( #8675 )
2025-09-08 15:03:17 -04:00
Andoni Alonso
27bf78a3a1
docs: update providers list ( #8671 )
2025-09-08 17:12:16 +02:00
Andoni Alonso
f50bd50d60
docs: add SSO with SAML Entra ID video link ( #8668 )
2025-09-08 14:57:38 +02:00
Alejandro Bailo
80665e0396
feat(ui): send a finding to Jira ( #8649 )
2025-09-08 14:15:23 +02:00
Pedro Martín
4b259fa8dd
chore(changelog): update with latest changes ( #8665 )
2025-09-08 17:24:31 +05:45
Hugo Pereira Brito
10db2ed6d8
chore(docs): add notes regarding gov accounts support ( #8656 )
2025-09-08 11:07:00 +02:00
Chandrapal Badshah
422a8a0f62
fix: change title in lighthouse settings ( #8615 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-08 10:34:09 +02:00
Daniel Barranquero
906a2cc651
fix(entra): add metadata description for check entra_admin_users_phishing_resistant_mfa_enabled ( #8654 )
2025-09-08 08:11:46 +02:00
Víctor Fernández Poyatos
43fe9c6860
feat(integrations): allow sending findings to Jira from the API ( #8645 )
2025-09-05 14:28:34 +02:00
Andoni Alonso
f87b2089fb
docs: remove llms.txt ( #8653 )
2025-09-05 17:08:42 +05:45
Samuele Pasini
1884874ab6
fix: typo ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_* CheckID ( #8294 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-09-05 13:16:12 +02:00
Andoni Alonso
cd6d29e176
docs: reorg tutorials ( #8652 )
2025-09-05 16:49:14 +05:45
Pedro Martín
0b7055e983
feat(jira): add send_finding method with specific finding fields ( #8648 )
2025-09-05 12:25:53 +02:00
Josema Camacho
ae53b76d78
feat(login): add DJANGO_THROTTLE_TOKEN_OBTAIN to main .env file ( #8650 )
2025-09-05 16:01:48 +05:45
Josema Camacho
406e473b5c
feat(login): add throttling option for the /api/v1/tokens endpoint ( #8647 )
2025-09-05 14:37:31 +05:45
Pedro Martín
1a2bf461f0
feat(jira): support labels in jira tickets ( #8603 )
2025-09-05 09:53:24 +02:00
Samuele Pasini
1b49c0b27f
feat: add --excluded-checks-file flag ( #8301 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2025-09-05 09:33:21 +02:00
Pablo Lara
12ada66978
feat: add status filter to /overviews endpoint ( #8186 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-09-04 18:46:14 +02:00
Alejandro Bailo
daa2536005
feat: Jira UI integration - pages and server actions ( #8640 )
2025-09-04 15:59:37 +02:00
Chandrapal Badshah
69a62db19a
chore: rename to lighthouse ai ( #8614 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-04 15:30:07 +05:45
Pedro Martín
79450d6977
fix(securityhub): resolve TypeError from Python3.9 ( #8619 )
...
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2025-09-03 17:52:09 +02:00
Víctor Fernández Poyatos
0463fd0830
refactor(integrations-jira): Move domain to credentials and retrieve metadata during connection test ( #8637 )
2025-09-03 17:24:42 +02:00
Alejandro Bailo
b15e3d339c
fix(saml): remove validation call on email domain change ( #8638 )
2025-09-03 17:04:51 +02:00
Pedro Martín
1fc12952ba
feat(jira): add color for manual status ( #8642 )
2025-09-03 16:53:31 +02:00
sumit-tft
088a6bcbda
feat(ui): handle no-permissions on scan page ( #8624 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-09-03 15:51:14 +02:00
Hugo Pereira Brito
a3b0bb6d4b
refactor(models): rename AdditionalUrls to AdditionalURLs ( #8639 )
2025-09-03 19:34:06 +05:45
Pedro Martín
3c819f8875
chore(changelog): update with latest changes ( #8636 )
2025-09-03 12:54:50 +02:00
Pedro Martín
cdf0292bbc
feat(jira): add get_metadata ( #8630 )
2025-09-03 10:59:07 +02:00
César Arroba
987121051b
chore(sdk): comment push readme to dockerhub steps ( #8628 )
2025-09-02 21:48:42 +05:45
Hugo Pereira Brito
c9ed7773d2
feat(models): add AdditionalUrls field to check metadata ( #8590 )
2025-09-02 21:27:21 +05:45
Pepe Fagoaga
fdf45aac51
fix(img): prowler architecture ( #8635 )
2025-09-02 21:15:40 +05:45
Alejandro Bailo
3ded224a4b
fix: new errors detected through the app ( #8629 )
2025-09-02 12:35:06 +02:00
sumit-tft
230a085c76
fix(ui): display NoProvidersAdded when no cloud providers are configured ( #8626 )
2025-09-02 12:33:58 +02:00
Chandrapal Badshah
8cd90e07dc
chore(ui): eslint nextjs files ( #8627 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-09-02 12:15:48 +02:00
Pedro Martín
06ded98d05
feat(jira): add data to table and error handling ( #8601 )
2025-09-02 11:48:52 +02:00
Pedro Martín
a5066326bd
chore(changelog): update with latests changes ( #8620 )
2025-09-02 11:27:13 +02:00
Alejandro Bailo
83a9ac2109
chore(ui): update CHANGELOG ( #8625 )
2025-09-02 10:45:34 +02:00
Alejandro Bailo
136eb4facd
feat: 50X errors handler ( #8621 )
2025-09-02 10:12:03 +02:00
Víctor Fernández Poyatos
d4eb4bdca7
feat(integrations): Support JIRA integration in the API ( #8622 )
2025-09-02 09:53:36 +02:00
Alejandro Bailo
665c9d878a
chore(ui): update Next.js and ESLint dependencies to version 14.2.32 ( #8623 )
2025-09-01 18:38:39 +02:00
Hugo Pereira Brito
a064e43302
chore(ui): render attributes as markdown ( #8604 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-09-01 16:43:36 +02:00
Daniel Barranquero
fdb76e7820
feat(docs): update mfa enforcement date for m365 ( #8610 )
2025-09-01 09:48:21 +02:00
Pepe Fagoaga
1259bb85e3
fix: remove dot ( #8613 )
2025-08-29 14:46:19 +05:45
Pepe Fagoaga
0db9ab91b2
chore(docs): review stats, imgs and update copy ( #8612 )
2025-08-29 14:44:01 +05:45
César Arroba
f6ea314ec0
chore(sdk): push readme file to docker hub ( #8611 )
2025-08-29 14:43:53 +05:45
Alejandro Bailo
9e02da342b
docs: Security Hub API and UI documentation ( #8576 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-08-28 20:43:42 +05:45
Prowler Bot
358d4239c7
chore(release): Bump version to v5.12.0 ( #8605 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-08-28 16:56:24 +02:00
Víctor Fernández Poyatos
b003fca377
fix(docs): remove empty sections ( #8600 )
2025-08-28 12:55:46 +02:00
Víctor Fernández Poyatos
b4deda3c3f
docs(api): fix API response samples ( #8592 )
2025-08-28 12:39:07 +02:00
Sergio Garcia
338bb74c0c
fix(azure): query API management logs with not empty operations ( #8598 )
2025-08-28 12:03:35 +02:00
Alejandro Bailo
7342a8901f
chore: update CHANGELOG.md for Prowler v5.11.0 release ( #8597 )
2025-08-28 11:43:24 +02:00
Sergio Garcia
f484b83f15
feat(azure): Add APIM threat detection for LLM jacking attacks ( #8571 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-08-28 11:42:07 +02:00
Adrián Jesús Peña Rodríguez
c69187f484
chore: prepare api changelog for 5.11 ( #8596 )
2025-08-28 10:25:08 +02:00
Alejandro Bailo
5038afeb26
fix(security-hub): copy updated ( #8594 )
2025-08-27 18:42:34 +02:00
Sergio Garcia
fce43cea16
chore: update changelog ( #8593 )
2025-08-27 17:57:07 +02:00
Andoni Alonso
43a14b89bc
fix(github): provider always scans user instead of organization when using provider UID ( #8587 )
2025-08-27 17:45:13 +02:00
Tom
24364bd73e
feat(gcp): Add support for skipping APIs check ( #8575 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2025-08-27 14:44:34 +02:00
Adrián Jesús Peña Rodríguez
a1abe6dd2d
fix(sh): reset regions information if connection fails ( #8588 )
2025-08-27 14:15:09 +02:00
César Arroba
25098bc82a
chore(gha): fix conflict checker action ( #8586 )
2025-08-27 13:41:39 +02:00
sumit-tft
20f2f45610
feat(ui): add S3 bucket link with folder for each integration ( #8554 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-08-27 12:40:37 +02:00
Alejandro Bailo
06c2608a05
feat(integrations): external links and copies changed ( #8574 )
2025-08-27 12:40:25 +02:00
Alejandro Bailo
329ac113f2
chore(docs): update CHANGELOG properly ( #8585 )
2025-08-27 11:57:12 +02:00
Hugo Pereira Brito
97179d2b43
fix(docs): incorrect permission in sp creation guide ( #8581 )
2025-08-27 11:01:37 +02:00
sumit-tft
8317ea783f
feat(ui): show all provider UIDs in scan page filter regardless of co… ( #8375 )
2025-08-27 10:50:16 +02:00
Andoni Alonso
65e7e89d61
fix(github): GitHub Personal Access Token authentication fails without user:email scope ( #8580 )
2025-08-27 09:57:32 +02:00
Víctor Fernández Poyatos
26a4dd4e8d
chore: bump h2 to 4.3.0 ( #8573 )
2025-08-26 15:17:06 +02:00
Alejandro Bailo
dab0cea2dd
feat(ui): Security Hub ( #8552 )
2025-08-26 14:30:45 +02:00
Daniel Barranquero
3b42eb3818
fix(s3): resource metadata error in s3_bucket_shadow_resource_vulnerability ( #8572 )
2025-08-26 13:30:49 +02:00
Prowler Bot
a5ba950627
chore(regions_update): Changes in regions for AWS services ( #8567 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-08-26 09:57:45 +02:00
Andoni Alonso
a1232446c1
docs: refactor several sections ( #8570 )
2025-08-26 09:55:18 +02:00
Pedro Martín
aa6f851887
docs(aws): deploying prowler iam roles across aws organizations ( #8427 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-08-26 09:45:14 +02:00
Adrián Jesús Peña Rodríguez
25f972e910
feat(sh): create asff of there is an enabled SecurityHub integration ( #8569 )
2025-08-25 16:58:21 +02:00
Pedro Martín
7216e5ce3d
chore(github): improve pull request template ( #7910 )
2025-08-25 16:22:55 +02:00
Adrián Jesús Peña Rodríguez
83242da0ab
feat(integrations): implement AWS Security Hub integration ( #8365 )
2025-08-25 15:53:48 +02:00
Alejandro Bailo
d457166a0c
fix(ui): AWS form selector default values ( #8553 )
2025-08-25 12:30:02 +02:00
Daniel Barranquero
88f38b2d2a
feat(docs): remove old requirements links ( #8561 )
2025-08-22 14:22:50 +02:00
Pepe Fagoaga
c2e0849d5f
fix(conflict-checker): use prowler-bot ( #8560 )
2025-08-22 17:27:44 +05:45
Andoni Alonso
1fdebfa295
docs: remove "Requirements" page ( #8559 )
2025-08-22 15:55:25 +05:45
Sergio Garcia
ea6d04ed3a
chore(securityhub): add static credentials and role assumption support ( #8539 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-08-22 11:58:35 +02:00
Sergio Garcia
2167683851
feat(aws): add Resource Explorer enumeration actions ( #8557 )
2025-08-22 11:47:51 +02:00
Pepe Fagoaga
6324be31ab
fix(api): poetry lock up to date with the SDK ( #8558 )
2025-08-22 11:05:14 +02:00
Alejandro Bailo
525f152e51
fix(ui): update authorization logic to match right paths ( #8556 )
2025-08-22 10:35:28 +02:00
Sergio Garcia
c3a2d79234
chore(iac): change engine to trivy ( #8466 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-08-22 10:17:51 +02:00
Andoni Alonso
cefa708322
docs: add provider bulk provisioning ( #8551 )
2025-08-21 16:33:45 +02:00
Andoni Alonso
1a9e14ab2a
chore(bulk-provisioning-tool): add script to bulk provision providers ( #8540 )
2025-08-21 13:11:46 +02:00
Chandrapal Badshah
b1c6094b6d
fix: Remove temperature for GPT-5 models ( #8550 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-21 12:40:49 +02:00
Pablo Lara
1038b11fe3
docs: update changelog ( #8549 )
2025-08-21 12:22:27 +02:00
Chandrapal Badshah
d54e3b25db
fix: Refactor getting lighthouse config ( #8546 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-21 11:14:21 +02:00
Pepe Fagoaga
6a8e8750bb
chore(actions): conflict checker ( #8547 )
2025-08-21 14:28:18 +05:45
Hugo Pereira Brito
ad3d4536fb
fix(m365): only evaluate enabled users in entra_users_mfa_capable ( #8544 )
2025-08-20 16:45:00 +02:00
Andoni Alonso
46c24055ee
docs: refactor Overview into several files ( #8543 )
2025-08-20 17:44:06 +05:45
Pepe Fagoaga
4c6a1592ac
chore(actions): update docs comment with link ( #8448 )
2025-08-20 17:42:32 +05:45
Hugo Pereira Brito
89e657561c
feat(github): add User Email and APP name/installations information ( #8501 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-20 12:26:38 +02:00
Hugo Pereira Brito
55099abc86
fix(organization): list all accessible organizations ( #8535 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-20 12:13:01 +02:00
Andoni Alonso
3c599a75cc
feat(iam): add ECS privilege escalation patterns to IAM checks ( #8541 )
2025-08-20 09:23:30 +02:00
Chandrapal Badshah
f77897f813
feat: gpt-5 and gpt-5-mini integration with lighthouse ( #8527 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-08-19 16:49:21 +02:00
Sergio Garcia
30518f2e0e
feat(aws): new check eks_cluster_deletion_protection_enabled ( #8536 )
2025-08-19 10:25:24 +02:00
Chandrapal Badshah
efdeb431ba
feat: Add resource agent to supervisor ( #8509 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-19 09:40:14 +02:00
Sergio Garcia
bb07cf9147
fix(aws): exact match in resource-arn filtering ( #8533 )
2025-08-18 12:11:13 +02:00
Prowler Bot
9214b5c26f
chore(regions_update): Changes in regions for AWS services ( #8531 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-08-18 11:58:41 +02:00
dependabot[bot]
d57df3cc28
chore(deps): bump actions/upload-artifact from 4.5.0 to 4.6.2 ( #8154 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-18 11:43:41 +02:00
Andoni Alonso
2f5fce41dc
feat(iam): remove standalone iam:PassRole from privesc detection and add missing patterns ( #8530 )
2025-08-18 11:35:14 +02:00
Chandrapal Badshah
6918a75449
fix: add business context to lighthouse chat ( #8528 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-18 09:49:23 +02:00
Pablo Lara
3aeaa3d992
feat(filters): improve provider connection filter UX ( #8520 )
2025-08-18 09:10:16 +02:00
Sergio Garcia
fd833eecf0
fix(github): solve Github APP auth method ( #8529 )
2025-08-18 08:35:19 +02:00
Andoni Alonso
39e4d20b24
feat(iam): add Bedrock AgentCore privilege escalation combo ( #8526 )
2025-08-15 13:25:15 +02:00
Sergio Garcia
dfdd45e4d0
fix(github): list all accessible repositories ( #8522 )
2025-08-14 10:38:38 +02:00
Hugo Pereira Brito
81478dfed3
fix(compliance): GitHub CIS 1.0 ( #8519 )
2025-08-13 16:45:36 +02:00
Chandrapal Badshah
2854f8405c
fix: simplify error handling to use only error.message ( #8518 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-13 10:59:47 +02:00
Jaen-923
0e1578cfbc
chore(aws): Refine kisa isms-p compliance mapping ( #8479 )
...
Co-authored-by: ghkim583 <203069125+ghkim583@users.noreply.github.com >
2025-08-13 09:08:37 +02:00
Hugo Pereira Brito
f5b1532647
fix(kafka): false positives in kafka_cluster_is_public check ( #8514 )
2025-08-13 09:05:09 +02:00
Sergio Garcia
d9f3a6b88e
docs(github): add Github onboarding documentation ( #8510 )
2025-08-12 17:11:30 +02:00
Hugo Pereira Brito
b0c386fc60
fix(app): fix false positives in app_http_logs_enabled ( #8507 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-08-12 14:47:17 +02:00
Hugo Pereira Brito
72b06261df
fix(storage): fall positives in storage_geo_redundant_enabled ( #8504 )
2025-08-12 12:30:43 +02:00
sumit-tft
1562b77581
fix(ui): redirection after deleting providers group and improve erro… ( #8389 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-08-12 11:31:45 +02:00
Daniel Barranquero
10e38ca407
fix: missing resource_name in GCP and Azure Defender checks ( #8352 )
2025-08-11 16:16:08 +02:00
Rubén De la Torre Vico
5842f2df37
feat(azure/vm): add new check vm_jit_access_enabled ( #8202 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-11 13:12:36 +02:00
Prowler Bot
8b3b9ffd99
chore(regions_update): Changes in regions for AWS services ( #8499 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-08-11 12:00:02 +02:00
Rubén De la Torre Vico
d238050065
feat(azure/vm): add new check vm_sufficient_daily_backup_retention_period ( #8200 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-11 11:44:45 +02:00
sumit-tft
5572d476ad
fix(ui): adjust table headers to be single-line and consistent ( #8480 )
2025-08-11 10:47:10 +02:00
sumit-tft
3c94d3a56f
fix(ui): disable See Compliance button until scan completes ( #8487 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-08-11 10:37:35 +02:00
Hugo Pereira Brito
85af4ff77c
feat(m365): add certificate auth method to cli ( #8404 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-08-11 09:47:56 +02:00
Daniel Barranquero
dcee114ef3
fix: validation errors in azure and m365 ( #8368 )
2025-08-11 09:42:30 +02:00
Pedro Martín
760723874c
fix(prowler-threatscore): order the requirements by id ( #8495 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-08-11 08:20:10 +02:00
Pedro Martín
c0a4898074
chore(changelog): update ( #8496 )
2025-08-11 07:48:23 +02:00
Alejandro Bailo
03c0533b58
feat(ui): overview charts display improved ( #8491 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-08-08 10:59:15 +02:00
sumit-tft
c8dcb0edb0
feat(ui): add GitHub submenu under High Risk Findings ( #8488 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-08-08 10:36:36 +02:00
Pablo Lara
82171ee916
docs: update changelog ( #8489 )
2025-08-08 10:20:53 +02:00
Pablo Lara
df4bf18b97
feat(ui): add Mutelist menu item under Configuration ( #8444 )
...
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com >
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-08-08 09:09:37 +02:00
Alejandro Bailo
94e60f7329
fix(ui): assume role fields shown ( #8484 )
2025-08-07 17:44:46 +02:00
Rubén De la Torre Vico
f1ba5abbec
chore(docs): update provider statistics in README.md ( #8483 )
...
Co-authored-by: Claude <noreply@anthropic.com >
2025-08-07 17:10:56 +02:00
Hugo Pereira Brito
6cc1a9a2cb
fix(compliance): delete invalid requirements for GitHub CIS 1.0 ( #8472 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-07 20:51:20 +07:00
Pablo Lara
31f98092bf
feat(ui): add provider type filter to providers page ( #8473 )
2025-08-07 14:34:04 +02:00
Pepe Fagoaga
85197036ca
chore(env): Update NEXT_PUBLIC_PROWLER_RELEASE_VERSION ( #8476 )
2025-08-07 17:50:18 +05:45
Pepe Fagoaga
be43025f00
fix(actions): always get latest SDK reference ( #8474 )
2025-08-07 17:38:40 +05:45
César Arroba
c6b34f0a85
chore(api): open PR with API prowler version ( #8475 )
2025-08-07 13:49:39 +02:00
Prowler Bot
675698a26a
chore(release): Bump version to v5.11.0 ( #8470 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-08-07 12:40:55 +02:00
Alejandro Bailo
8d9bf2384f
docs: S3 tutorial documentation ( #8414 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-08-07 16:04:42 +05:45
César Arroba
ff900a2a45
chore(gha): use prowler-bot for push in action ( #8469 )
2025-08-07 10:50:58 +02:00
César Arroba
a41663fb0d
chore(gha): fix release preparation workflow ( #8468 )
2025-08-07 10:41:16 +02:00
César Arroba
033e9fd58c
chore(gha): fix release preparation workflow ( #8467 )
2025-08-07 10:36:22 +02:00
sumit-tft
240b02b498
feat(ui): add SAML documentation link in config modal ( #8461 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com >
2025-08-07 10:23:07 +02:00
Rubén De la Torre Vico
87eb2dfdf7
chore(changelog): move fixes from version 5.9.3 to 5.10 ( #8464 )
2025-08-07 13:43:56 +05:45
Alejandro Bailo
b4d8d64f0e
feat: update AWS role credentials form to set default credentials typ… ( #8459 )
2025-08-07 09:54:48 +02:00
Pablo Lara
7944ebe83a
docs: update changelog ( #8462 )
2025-08-07 09:39:24 +02:00
Pepe Fagoaga
bd138114c9
fix: changelog check update messages ( #8465 )
2025-08-07 13:22:54 +05:45
Adrián Jesús Peña Rodríguez
d527a3f12b
chore: update changelog ( #8463 )
2025-08-07 09:35:16 +02:00
Pepe Fagoaga
260fada3eb
fix(s3): Use HeadBucket instead of GetBucketLocation ( #8456 )
2025-08-06 19:20:52 +05:45
Pepe Fagoaga
0ee0fc082a
chore(s3): remove trailing 's' from docs helper ( #8458 )
2025-08-06 14:21:39 +02:00
Hugo Pereira Brito
9d66d86f66
fix(docs): m365 requirements Needed permissions link ( #8457 )
2025-08-06 13:51:16 +02:00
Alejandro Bailo
825e53c38f
feat(ui): add a default Mutelist placeholder ( #8455 )
2025-08-06 13:11:31 +02:00
Daniel Barranquero
196c17d44d
feat(gcp): add retry to avoid quota limit errors ( #8412 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-08-06 16:59:41 +07:00
Andoni Alonso
fc69e195e4
fix(github): handle GithubAppIdentityInfo in output generation ( #8423 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-08-06 16:55:44 +07:00
Prowler Bot
5f53a9ec6f
chore(regions_update): Changes in regions for AWS services ( #8437 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-08-06 16:53:43 +07:00
dependabot[bot]
5e72a40898
chore(deps): bump github/codeql-action from 3.29.2 to 3.29.5 ( #8434 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-06 16:52:09 +07:00
dependabot[bot]
496ada3cba
chore(deps): bump trufflesecurity/trufflehog from 3.89.2 to 3.90.2 ( #8433 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-06 16:51:42 +07:00
Adrián Jesús Peña Rodríguez
481a43f3f6
chore(integrations): remove unnecessary error alerts ( #8453 )
2025-08-06 09:16:26 +02:00
Pepe Fagoaga
58298706d4
docs(saml): IdP initiated flow ( #8435 )
2025-08-06 12:46:18 +05:45
Pepe Fagoaga
e75a760da0
fix(ui): cfn quick link ( #8452 )
2025-08-05 22:42:57 +05:45
Pepe Fagoaga
c313757ef2
fix(templates): only one cloudformation template ( #8451 )
2025-08-05 18:17:50 +02:00
Adrián Jesús Peña Rodríguez
284678fe48
fix(export): remove static timestamp ( #8449 )
2025-08-05 18:12:04 +02:00
Alejandro Bailo
c3d25e6f39
feat(ui): S3 integrations pagination added ( #8450 )
2025-08-05 18:11:32 +02:00
Adrián Jesús Peña Rodríguez
a9d16bbbce
chore: change output folder ( #8447 )
2025-08-05 14:07:35 +02:00
Pepe Fagoaga
92bc992e7f
feat(s3): templates for permissions ( #8395 )
2025-08-05 17:36:04 +05:45
Alejandro Bailo
903e4f8b9f
feat(integrations): add enabled attribute to S3 integration ( #8446 )
2025-08-05 13:13:58 +02:00
Alejandro Bailo
2c09076f91
feat: output_directory default value added ( #8445 )
2025-08-05 12:20:31 +02:00
Adrián Jesús Peña Rodríguez
3d4902b057
feat(integrations): integrations enabled by default ( #8439 )
2025-08-05 11:25:42 +02:00
Chandrapal Badshah
b30eab7935
fix: Don't invoke tools if no providers or completed scans ( #8443 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-05 09:32:35 +02:00
sumit-tft
cf8402e013
feat(ui): add notification system ( #8394 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-08-05 09:06:15 +02:00
Pedro Martín
af8fbaf2cd
docs(mutelist): improve mutelist docs across all the providers ( #8397 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-08-05 08:38:50 +02:00
Alejandro Bailo
c748e57878
feat: manage integration permission behavior ( #8441 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-08-04 17:49:04 +02:00
Alejandro Bailo
a5187c6a42
feat(ui): S3 integration retouches ( #8438 )
2025-08-04 16:04:10 +02:00
Alejandro Bailo
e19ed30ac7
feat(UI): xml validation ( #8429 )
2025-08-04 12:09:18 +02:00
Hugo Pereira Brito
96ce1461b9
chore(sentry): add powershell user auth module connection errors to ignored list ( #8420 )
2025-08-04 11:58:05 +02:00
Alejandro Bailo
9da5fb67c3
feat(ui): S3 integration ( #8391 )
2025-08-04 11:43:14 +02:00
Chandrapal Badshah
eb1c1791e4
fix: clear only last message on error ( #8431 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-08-04 10:33:45 +02:00
Adrián Jesús Peña Rodríguez
581afd38e6
fix: add default values for S3 class ( #8417 )
...
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-01 13:50:51 +02:00
sumit-tft
19a735aafe
chore(ui): remove misconfigurations from Top Failed Findings in the s… ( #8426 )
2025-08-01 12:47:17 +02:00
Paul Negedu
2170fbb1ab
feat(aws): add s3_bucket_shadow_resource_vulnerability check ( #8398 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-08-01 18:26:03 +08:00
Pablo Lara
90c6c6b98d
feat: add new provider GitHub and update enum source of truth ( #8421 )
2025-08-01 10:03:47 +02:00
sumit-tft
02b416b4f8
chore(ui): remove browse all resources from the sidebar ( #8418 )
2025-07-31 16:13:30 +02:00
Hugo Pereira Brito
1022b5e413
chore(docs): add a step to check development guide ( #8416 )
2025-07-31 12:45:15 +02:00
Pablo Lara
d1bad9d9ab
chore: rename menu item ( #8415 )
2025-07-31 12:10:07 +02:00
Rubén De la Torre Vico
178f3850be
chore: add M365 provider to PR labeler ( #8406 )
2025-07-31 17:32:18 +08:00
Adrián Jesús Peña Rodríguez
d239d299e2
fix(s3): use enabled to filter ( #8409 )
2025-07-31 10:00:05 +02:00
Pepe Fagoaga
88fae9ecae
chore(ui): remove changelog entry ( #8410 )
2025-07-31 09:27:11 +02:00
Hugo Pereira Brito
a3bff9705c
fix(tests): github and iac providers arguments_test naming and structure ( #8408 )
2025-07-30 17:16:34 +02:00
César Arroba
75989b09d7
chore(gha): fix payload on merged PR action ( #8407 )
2025-07-30 16:59:40 +02:00
Pablo Lara
9a622f60fe
feat(providers): add GitHub provider support with credential types ( #8405 )
2025-07-30 15:55:40 +02:00
Rubén De la Torre Vico
7cd1966066
fix(azure,m365): use default tenant domain instead of first domain in list ( #8402 )
2025-07-30 13:23:25 +02:00
Pedro Martín
77e59203ae
feat(prowler-threatscore): remove and add requirements ( #8401 )
2025-07-30 13:09:51 +02:00
Chandrapal Badshah
0a449c7e13
fix(lighthouse): Display errors in Lighthouse & allow resending message ( #8358 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-07-30 12:32:48 +02:00
Adrián Jesús Peña Rodríguez
163fbaff19
feat(integrations): add s3 integration ( #8056 )
2025-07-30 12:05:46 +02:00
Sergio Garcia
7ec514d9dd
feat(aws): new check bedrock_api_key_no_long_term_credentials ( #8396 )
2025-07-30 17:04:16 +08:00
Hugo Pereira Brito
b63f70ac82
fix(m365): enhance execution to avoid multiple error calls ( #8353 )
2025-07-30 14:54:27 +08:00
Chandrapal Badshah
2c86b3a990
feat: Add lighthouse banner ( #8259 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-07-29 12:30:57 +02:00
Daniel Barranquero
12443f7cbb
feat(docs): update m365 and azure docs ( #8393 )
2025-07-29 11:58:03 +02:00
Rubén De la Torre Vico
3a8c635b75
docs(dev-guide): add generic best practices for checks and services ( #8074 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-07-29 11:04:26 +02:00
Rubén De la Torre Vico
8bc6e8b7ab
docs(getting-started): improve quality redrive ( #7963 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-07-29 11:04:12 +02:00
Rubén De la Torre Vico
9ca1899ebf
docs(tutorials): improve quality redrive ( #7915 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-07-29 11:03:52 +02:00
Sergio Garcia
1bdcf2c7f1
refactor(iac): revert importingcheckov as python library ( #8385 )
2025-07-29 15:55:28 +08:00
Pedro Martín
92a804bf88
fix(prowler-threatscore): remove typo from description req 1.2.3 - m365 ( #8384 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-28 23:55:38 +08:00
ghkim583
f85ad9a7a2
chore(aws): minor fixes for the kisa isms-p compliance ( #8386 )
2025-07-28 17:51:20 +02:00
Pedro Martín
308c778bad
fix(kisa): change the way of counting the PASS/FAILED reqs ( #8382 )
2025-07-28 21:56:58 +08:00
Jaen-923
ee06d3a68a
chore(aws): update kisa-isms-p compliance ( #8367 )
...
Co-authored-by: ghkim583 <203069125+ghkim583@users.noreply.github.com >
2025-07-28 21:55:50 +08:00
Andoni Alonso
8dc4bd0be8
feat(github): add repository and organization scoping support ( #8329 )
2025-07-28 21:43:41 +08:00
Pedro Martín
bf9e38dc5c
fix(docs): remove typo from getting started - github ( #8380 )
2025-07-28 20:18:13 +08:00
Aviad Levy
a85b89ffb5
fix(ec2): add check that protocol is matched in security group checks ( #8374 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-07-28 19:53:08 +08:00
César Arroba
87da11b712
chore(gha): delete repo limitation for bump workflow ( #8379 )
2025-07-28 13:22:19 +02:00
César Arroba
8b57f178e0
chore(gha): improve e2e pipeline ( #8378 )
2025-07-28 13:22:12 +02:00
Prowler Bot
7830ed8b9f
chore(regions_update): Changes in regions for AWS services ( #8376 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-07-28 17:56:48 +08:00
Kay Agahd
d4e66c4a6f
chore(sqs): clean up code ( #8366 )
2025-07-25 20:10:34 +08:00
Rubén De la Torre Vico
1cfe610d47
feat(azure/vm): add new check vm_scaleset_not_empty ( #8192 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-25 18:42:03 +08:00
Rubén De la Torre Vico
d9a9236ab7
feat(azure/vm): add new check vm_desired_sku_size ( #8191 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-25 17:51:01 +08:00
Hugo Pereira Brito
285aea3458
fix(docs): change Exchange Administrator role to Global Reader for M365 ( #8360 )
2025-07-25 15:45:30 +08:00
César Arroba
b051aeeb64
chore(gha): automate e2e tests with new workflow ( #8361 )
2025-07-24 16:54:01 +02:00
Pedro Martín
b99dce6a43
feat(azure): add CIS 4.0 ( #7782 )
2025-07-24 22:29:46 +08:00
Andoni Alonso
04749c1da1
fix(aws): sns_topics_not_publicly_accessible false positive with aws:SourceArn conditions ( #8340 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-07-24 18:03:30 +08:00
Chandrapal Badshah
44d70f8467
fix(lighthouse): update prompt and tool schema for checks tool ( #8265 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-07-24 10:50:36 +02:00
Andoni Alonso
95791a9909
chore(aws): replace known errors with warnings ( #8347 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-24 15:34:45 +08:00
sumit-tft
ad0b8a4208
feat(ui): create CustomLink component and refactor links to use it ( #8341 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-07-23 19:10:51 +02:00
Cole Murray
5669a42039
fix(wazuh): patch command injection vulnerability in prowler-wrapper.py ( #8331 )
...
Co-authored-by: Test User <test@example.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-07-23 16:06:55 +02:00
Kay Agahd
83b328ea92
fix(aws): avoid false positives in SQS encryption check for ephemeral queues ( #8330 )
...
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2025-07-23 21:03:02 +08:00
Alejandro Bailo
a6c88c0d9e
test: timeout updated for E2E ( #8351 )
2025-07-23 13:11:32 +02:00
Sergio Garcia
922f9d2f91
docs(gcp): update GCP permissions ( #8350 )
2025-07-23 17:43:42 +08:00
Rubén De la Torre Vico
a69d0d16c0
fix(azure/storage): handle when Azure API set values to None ( #8325 )
...
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-23 17:11:04 +08:00
Alejandro Bailo
676cc44fe2
feat: env keys behavior updated ( #8348 )
2025-07-23 10:44:28 +02:00
Alejandro Bailo
3840e40870
test(e2e): Sign-in ( #8337 )
...
Co-authored-by: César Arroba <cesar@prowler.com >
2025-07-22 18:04:54 +02:00
dependabot[bot]
ab2d57554a
chore(deps): bump form-data from 4.0.3 to 4.0.4 in /ui ( #8346 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-22 17:53:32 +02:00
César Arroba
cbb5b21e6c
chore(gha): e2e tests pipeline with API services ( #8338 )
2025-07-22 17:49:23 +02:00
Sergio Garcia
1efd5668ce
feat(api): add GitHub provider support ( #8271 )
2025-07-22 23:26:02 +08:00
Sergio Garcia
ca86aeb1d7
feat(aws): new check bedrock_api_key_no_administrative_privileges ( #8321 )
2025-07-22 22:06:17 +08:00
Víctor Fernández Poyatos
4f2a8b71bb
feat(performance): resources scenario ( #8345 )
2025-07-22 13:01:19 +02:00
Prowler Bot
3b0cb3db85
chore(regions_update): Changes in regions for AWS services ( #8333 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-07-22 17:23:24 +08:00
Víctor Fernández Poyatos
00c527ff79
chore: update Prowler changelog for v5.9.2 ( #8342 )
2025-07-22 10:53:22 +02:00
Víctor Fernández Poyatos
ab348d5752
feat(resources): Optimize findings prefetching during resource views ( #8336 )
2025-07-21 16:33:07 +02:00
Daniel Barranquero
dd713351dc
fix(defender): avoid duplicated findings in check defender_domain_dkim_enabled ( #8334 )
2025-07-21 13:07:26 +02:00
sumit-tft
fa722f1dc7
feat(ui): add 32-character limit validation for scan name in create a… ( #8319 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-07-21 10:00:25 +02:00
Pedro Martín
b0cc3978d0
feat(docs): add info about updating Prowler App ( #8320 )
2025-07-21 07:44:07 +02:00
César Arroba
aa843b823c
chore(gha): fix action version ( #8327 )
2025-07-18 15:00:32 +02:00
Víctor Fernández Poyatos
020edc0d1d
fix(tasks): calculate failed findings for resources during scan ( #8322 )
2025-07-18 13:19:22 +02:00
César Arroba
036da81bbd
chore(gha): fix api prowler version ( #8323 )
2025-07-18 12:43:38 +02:00
sumit-tft
4428bcb2c0
feat(ui): update step title and description in cloud provider update … ( #8303 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-07-18 10:11:44 +02:00
Prowler Bot
21de9a2f6f
chore(release): Bump version to v5.10.0 ( #8314 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-07-17 19:38:28 +02:00
Alejandro Bailo
231d933b9e
chore(docs): SAML documentation ( #8137 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-17 23:22:49 +05:45
Alejandro Bailo
2ad360a7f9
docs(ui): Mutelist documentation ( #8201 )
2025-07-17 23:15:20 +05:45
Víctor Fernández Poyatos
51b67f00d6
chore: update changelogs for v5.9.0 ( #8313 )
2025-07-17 17:15:58 +02:00
Pepe Fagoaga
ab378684ae
chore(ui): remove inventory group label ( #8311 )
2025-07-17 20:29:52 +05:45
Chandrapal Badshah
e89df617ef
chore(lighthouse): Rename to Lighthouse AI ( #8262 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-07-17 16:25:32 +02:00
Alejandro Bailo
8496a6b045
fix: muted filter removed from url when value is true ( #8310 )
2025-07-17 19:12:36 +05:45
Pepe Fagoaga
28f3cf363b
fix(actions): build API if the SDK changes ( #8309 )
2025-07-17 14:35:51 +02:00
Pepe Fagoaga
eb3d4b25e3
chore: improve info in the download button ( #8307 )
2025-07-17 16:38:45 +05:45
Rubén De la Torre Vico
1211fe706e
feat(azure/defender): add new check defender_attack_path_notifications_properly_configured ( #8245 )
2025-07-17 12:40:26 +02:00
Pedro Martín
c4a9280ebb
fix(m365): handle tenant_id in mutelist ( #8306 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-17 12:37:13 +02:00
Alejandro Bailo
0f12fb92ed
fix: Middleware redirection to /profile ( #8305 )
2025-07-17 11:49:24 +02:00
Víctor Fernández Poyatos
ee974a6316
feat(tasks): Improve memory usage and performance in overview tasks ( #8300 )
2025-07-17 10:49:25 +02:00
Pablo Lara
d004a0c931
feat(ui): Add resources view as inventory ( #7760 )
...
Co-authored-by: sumit_chaturvedi <chaturvedi.sumit@tftus.com >
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com >
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-07-17 10:01:05 +02:00
Pepe Fagoaga
087e01cc4f
fix(checks_loader): Handle multiple services and severities ( #8302 )
2025-07-17 13:39:29 +05:45
Pepe Fagoaga
74940e1fc4
fix(check_metadata): add service name validator ( #8289 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
2025-07-17 13:10:30 +05:45
Hugo Pereira Brito
19e35bf9a8
feat: add new check entra_intune_enrollment_sign_in_frequency_every_time ( #8223 )
2025-07-16 17:13:50 +02:00
César Arroba
7213187e6c
chore(gha): add target_commitish to the release creation step ( #8297 )
2025-07-16 16:07:06 +02:00
Pedro Martín
4b104e92f0
chore(prowler-threatscore): improve the way of calculating the score ( #8264 )
2025-07-16 15:26:44 +02:00
Hugo Pereira Brito
7179119b0e
fix(outputs): identity type and id for prowler cloud ( #8243 )
2025-07-16 15:23:46 +02:00
César Arroba
cf2738810a
chore(gha): prowler release preparation workflow ( #8268 )
2025-07-16 13:45:34 +02:00
Samuele Pasini
389216570a
fix: typo documentdb service name ( #8293 )
2025-07-16 18:39:19 +08:00
Alejandro Bailo
2becf45f33
feat: Next.js middleware improved ( #8295 )
2025-07-16 12:39:05 +02:00
Sergio Garcia
c32ce7eb97
fix(azure): use Subscription ID for mutelist ( #8290 )
2025-07-16 18:34:38 +08:00
sumit-tft
94e66a91a6
feat(ui): add link in Scans view to navigate to Compliance overview ( #8251 )
...
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com >
2025-07-16 12:34:21 +02:00
sumit-tft
1ac4417f74
feat(ui): add status column to findings table in compliance detail view ( #8244 )
...
Co-authored-by: Alejandro Bailo <59607668+alejandrobailo@users.noreply.github.com >
2025-07-16 12:23:40 +02:00
Hugo Pereira Brito
57c5f7c12d
fix(networkfirewall): ServiceName in checks metadata ( #8291 )
2025-07-16 16:59:42 +08:00
Alejandro Bailo
19203f92b3
feat: menu label hidden in side-menu if no items ( #8292 )
2025-07-16 14:37:56 +05:45
Alejandro Bailo
c5b1bf3e52
feat: allow to restrict routes based on permissions ( #8287 )
2025-07-16 14:21:45 +05:45
dependabot[bot]
f845176494
chore(deps): bump aiohttp from 3.11.18 to 3.12.14 in /api ( #8276 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-16 10:21:06 +02:00
Daniel Barranquero
f0ed866946
fix(entra): entra_users_mfa_capable check report ( #8288 )
2025-07-16 16:06:36 +08:00
Alejandro Bailo
834a7d3b69
fix(scans): capture 403 when no permissions ( #8280 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-15 21:43:50 +05:45
Pepe Fagoaga
24a50c6ac2
fix(schedules): returns 409 on conflict ( #8258 )
2025-07-15 21:29:05 +05:45
Víctor Fernández Poyatos
ec8afd773f
fix(overviews): apply RBAC to providers overview ( #8277 )
2025-07-15 17:31:25 +02:00
Rubén De la Torre Vico
a09be4c0ba
chore(azure/defender): get security contacts from API REST ( #8241 )
2025-07-15 16:37:43 +02:00
Andoni Alonso
4b62fdcf53
feat(iac): add support for remote repos ( #8193 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-07-15 22:08:27 +08:00
Kay Agahd
bf0013dae3
fix(aws): make is_service_role more restrictive to avoid false positives ( #8274 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-07-15 22:02:09 +08:00
Hugo Pereira Brito
c82cd5288c
feat(docs): add new docker pull issues section ( #7972 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-07-15 16:00:08 +02:00
Sergio Garcia
ad31a6b3f5
chore(hadolint): run only when necessary ( #8284 )
2025-07-15 21:53:05 +08:00
Rubén De la Torre Vico
20c7c9f8de
fix(dashboard): count rows in the CSV more efficiently ( #8257 )
2025-07-15 15:40:36 +02:00
Daniel Barranquero
0cfe41e452
fix(dynamodb): update broken link in dynamodb_tables_kms_cmk_encryption_enabled ( #8273 )
2025-07-15 14:54:14 +02:00
Hugo Pereira Brito
1b254feadc
feat(docs): add getting-started page ( #8275 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-07-15 14:11:20 +02:00
Matt Keeler
15954d8a01
fix: reword iam_user_accesskey_unused title & description ( #8233 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-15 20:02:34 +08:00
dependabot[bot]
ff122c9779
chore(deps): bump aiohttp from 3.12.13 to 3.12.14 ( #8278 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-15 19:45:03 +08:00
Daniel Barranquero
a012397e55
fix(dashboard): security posture showing incomplete data ( #8270 )
2025-07-15 13:19:55 +02:00
Sergio Garcia
7da6d7b5dd
chore(github): add test_connection function ( #8248 )
2025-07-15 17:01:40 +08:00
Víctor Fernández Poyatos
db6a27d1f5
feat(resources): latest and metadata endpoints and performance ( #8112 )
2025-07-14 18:02:06 +02:00
Alejandro Bailo
e07c833cab
feat: SAML toast error ( #8267 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-14 17:04:23 +02:00
Adrián Jesús Peña Rodríguez
728fc9d6ff
fix(saml): remove user in case of error ( #8260 )
2025-07-14 14:07:27 +02:00
Prowler Bot
cf9ff78605
chore(regions_update): Changes in regions for AWS services ( #8263 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-07-14 19:45:38 +08:00
Adrián Jesús Peña Rodríguez
a2faf548af
chore: update changelog ( #8255 )
2025-07-11 12:06:03 +02:00
Adrián Jesús Peña Rodríguez
8bcec4926b
fix: set lxml version ( #8253 )
2025-07-11 11:43:31 +02:00
Hugo Pereira Brito
a4e96f809b
fix(docs): GitHub provider mkdocs and -h ( #8246 )
2025-07-11 16:32:15 +08:00
Adrián Jesús Peña Rodríguez
fa27255dd7
chore(saml): redirect to login page on fail ( #8247 )
2025-07-11 09:22:38 +02:00
Pepe Fagoaga
05360e469f
chore(bump): add no-changelog label ( #8240 )
2025-07-10 19:14:37 +08:00
Hugo Pereira Brito
9d405ddcbd
fix: changelog entries with new specification ( #8232 )
2025-07-10 14:40:33 +05:45
Víctor Fernández Poyatos
430f831543
feat(exceptions): add custom error for provider connection during scans ( #8234 )
2025-07-10 14:13:19 +05:45
Pepe Fagoaga
da9d7199b7
chore(changelog): add missing entry from the password policy ( #8236 )
2025-07-10 09:07:04 +02:00
Pepe Fagoaga
d63a383ec6
feat(security): password strength ( #8225 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
2025-07-10 11:50:22 +05:45
Víctor Fernández Poyatos
55c226029e
feat(resources): optimize include parameters for resources view ( #8229 )
2025-07-09 16:16:56 +02:00
Alejandro Bailo
8d2f6aa30c
feat: Include/exclude muted findings ( #8228 )
2025-07-09 16:06:05 +02:00
Rubén De la Torre Vico
a319f80701
feat(storage): add new check storage_smb_protocol_version_is_latest ( #8128 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-09 17:28:00 +08:00
Adrián Jesús Peña Rodríguez
15a8671f0d
feat(saml): prevent duplicate SAML entityID configuration ( #8224 )
2025-07-09 09:50:22 +02:00
Rubén De la Torre Vico
d34e709d91
fix(azure/storage): use BaseModel for all Storage models ( #8222 )
2025-07-09 15:49:17 +08:00
Hugo Pereira Brito
ddc53c3c6d
fix(firehose): list all streams and fix firehose_stream_encrypted_at_rest logic ( #8213 )
2025-07-09 15:38:54 +08:00
Alejandro Bailo
a3aef18cfe
feat: Mutelist implementation ( #8190 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
Co-authored-by: Drew Kerrigan <drew@prowler.com >
2025-07-09 08:15:23 +02:00
Alejandro Bailo
49ca3ca325
fix: SAML 403 message ( #8221 )
2025-07-09 08:10:14 +02:00
Drew Kerrigan
89c67079a3
feat: Processors API endpoint, implement MuteList ( #7993 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-08 21:33:28 +05:45
Pepe Fagoaga
2de8075d87
fix(overview): use findings latest to get new ( #8219 )
2025-07-08 15:48:19 +02:00
Adrián Jesús Peña Rodríguez
e124275dbf
fix(saml): ensure SocialApp and SAMLDomainIndex are deleted with SAMLConfiguration ( #8210 )
2025-07-08 13:57:23 +02:00
Rubén De la Torre Vico
760d28e752
chore(deps): update dash libs ( #8215 )
2025-07-08 19:55:50 +08:00
Víctor Fernández Poyatos
3fb0733887
feat(tasks): create overview queue for summaries and overviews ( #8214 )
2025-07-08 13:53:23 +02:00
Pablo Lara
7de9a37edb
fix(api): make invitation email comparison case-insensitive ( #8206 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-08 16:39:27 +05:45
Pepe Fagoaga
fe00b788cc
fix: Remove type validation while updating provider credentials ( #8197 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-07-08 15:27:02 +05:45
Rubén De la Torre Vico
4c50f4d811
feat(azure/vm): add new check vm_backup_enabled ( #8182 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-08 17:01:22 +08:00
Rubén De la Torre Vico
c0c736bffe
chore: ignore some files from AI editors ( #8209 )
2025-07-08 10:43:38 +02:00
dependabot[bot]
a3aa7d0a63
chore(deps): bump python from 3.12.10-slim-bookworm to 3.12.11-slim-bookworm ( #8157 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-08 16:43:13 +08:00
Rubén De la Torre Vico
3ceb86c4d9
feat(azure/vm): add new check vm_scaleset_associated_load_balancer ( #8181 )
2025-07-08 16:40:43 +08:00
Rubén De la Torre Vico
3628e7b3e8
feat(azure/vm): add new check vm_ensure_using_approved_images ( #8168 )
2025-07-08 16:40:33 +08:00
Chandrapal Badshah
f29c2ac9f0
docs(lighthouse): Add Lighthouse Docs ( #8196 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-08 11:56:23 +05:45
Pablo Lara
b4927c3ad1
chore: Update CHANGELOG UI ( #8204 )
2025-07-07 17:54:44 +02:00
Adrián Jesús Peña Rodríguez
19f3c1d310
chore(saml): restore SAML button ( #8203 )
2025-07-07 17:34:05 +02:00
Adrián Jesús Peña Rodríguez
cd97e57521
fix(saml): restore SAML, deactivate urls, enable idp-initiate ( #8175 )
2025-07-07 16:42:11 +02:00
Hugo Pereira Brito
b38207507a
chore(docs): enhance M365 auth documentation ( #8199 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-07 22:01:41 +08:00
Rubén De la Torre Vico
ab96e0aac0
feat(azure/vm): add new check vm_linux_enforce_ssh_authentication ( #8149 )
2025-07-07 22:01:11 +08:00
Prowler Bot
4477cecc59
chore(regions_update): Changes in regions for AWS services ( #8198 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-07-07 18:04:49 +08:00
Pablo Lara
641d671312
chore: upgrade to Next.js 14.2.30 and lock TypeScript to 5.5.4 for ES… ( #8189 )
2025-07-04 13:20:30 +02:00
Víctor Fernández Poyatos
e7c2fa0699
fix(findings): avoid backfill on empty scans ( #8183 )
2025-07-04 12:24:49 +02:00
Pedro Martín
7eb08b0f14
fix(ec2): allow empty values for http_endpoint in templates ( #8184 )
2025-07-04 18:03:51 +08:00
Rubén De la Torre Vico
6f3112f754
feat(storage): add new check storage_smb_channel_encryption_with_secure_algorithm ( #8123 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-04 15:26:33 +08:00
Kay Agahd
f5ecae6da1
fix(iam): detect wildcarded ARNs in sts:AssumeRole policy resources ( #8164 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-03 23:09:48 +08:00
Prowler Bot
1c75f6b804
chore(release): Bump version to v5.9.0 ( #8178 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-07-03 23:08:37 +08:00
Daniel Barranquero
91b64d8572
chore(docs): update m365 docs for app auth in cloud ( #8147 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-07-03 23:08:15 +08:00
Pablo Lara
233ae74560
fix: disable dynamic filters for now ( #8177 )
2025-07-03 14:17:02 +02:00
Alejandro Bailo
fac97f9785
fix: remove duplicated calls during promise all resolving ( #8176 )
2025-07-03 14:02:57 +02:00
Pablo Lara
e81c7a3893
fix: bug when updating credentials for m365 ( #8173 )
2025-07-03 11:31:40 +02:00
Adrián Jesús Peña Rodríguez
d6f26df2e8
refactor(migrations): remove saml migrations ( #8167 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-07-02 17:23:08 +02:00
Sergio Garcia
ece74e15fd
chore(sdk): update changelog ( #8166 )
2025-07-02 16:11:48 +02:00
sumit-tft
eea6d07259
chore(ui): update capitalization of Sign In and Sign Up to match UI s… ( #8136 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-07-02 16:01:29 +02:00
Víctor Fernández Poyatos
4a6d7a5be2
chore: bump API changelog to v5.8.0 ( #8165 )
2025-07-02 16:00:43 +02:00
Alejandro Bailo
883c5d4e56
feat: client side validation ( #8161 )
2025-07-02 15:43:20 +02:00
Adrián Jesús Peña Rodríguez
f1f998c2fa
chore: update spec ( #8162 )
2025-07-02 13:19:57 +02:00
Adrián Jesús Peña Rodríguez
5276e38f1d
chore: disable SAML endpoints ( #8160 )
2025-07-02 12:51:57 +02:00
Pablo Lara
ad98a4747f
chore: Hide all SAML config for v5.8 ( #8159 )
2025-07-02 12:46:04 +02:00
Alejandro Bailo
5798321dc6
feat: saml e2e improvements ( #8158 )
2025-07-02 11:57:56 +02:00
dependabot[bot]
bf58728d29
chore(deps-dev): bump brace-expansion from 1.1.11 to 1.1.12 in /ui ( #8003 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-02 11:25:17 +02:00
Sergio Garcia
fcea3b6570
docs(iac): add documentation for IaC ( #8150 )
...
Co-authored-by: Rubén De la Torre Vico <rubendltv22@gmail.com >
2025-07-02 17:20:34 +08:00
Neil Millard
965111245a
feat(aws): add new check for Codebuild projects visibility ( #8127 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-07-02 17:20:15 +08:00
Rubén De la Torre Vico
f78a29206c
fix(azure): use Pydantic models in VM service and fix managed disk logic ( #8151 )
2025-07-02 16:23:51 +08:00
dependabot[bot]
c719d705e0
chore(deps): bump trufflesecurity/trufflehog from 3.88.35 to 3.89.2 ( #8156 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-02 15:36:10 +08:00
dependabot[bot]
8948ee6868
chore(deps): bump docker/setup-buildx-action from 3.10.0 to 3.11.1 ( #8153 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-02 15:29:21 +08:00
dependabot[bot]
24fb31e98f
chore(deps): bump github/codeql-action from 3.28.18 to 3.29.2 ( #8155 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-07-02 14:24:12 +08:00
Adrián Jesús Peña Rodríguez
c8b193e658
fix(saml): add user to SAML tenant ( #8152 )
2025-07-01 18:41:16 +02:00
Alejandro Bailo
6d27738c4d
fix: HotFIX related with ACS SAML url ( #8148 )
2025-07-01 13:10:46 +02:00
Adrián Jesús Peña Rodríguez
17b7becfdf
fix(saml): limit attributes length to satisfy the socialapp restriction ( #8145 )
2025-07-01 12:03:20 +02:00
Alejandro Bailo
cfa7f271d2
fix: Minor changes detected while SAML E2E ( #8146 )
2025-07-01 11:50:47 +02:00
Pedro Martín
e61a97cb65
fix(api): handle ISO27001 - M365 in exports ( #8143 )
2025-07-01 10:19:56 +02:00
Pablo Lara
cd4a1ad8a7
chore: clarify M365 context due to credential changes ( #8144 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-07-01 09:01:17 +02:00
Alejandro Bailo
e650d19a30
feat: enhance getScans API to support fields and include parameters; … ( #8140 )
2025-07-01 08:13:48 +02:00
Pedro Martín
f930739a3d
fix(ui): remove typo from compliance detailed view ( #8142 )
2025-06-30 18:03:45 +02:00
Sergio Garcia
89fc698a0e
fix(m365): handle none attribute in exchange transport rule ( #8141 )
2025-06-30 23:13:18 +08:00
Pablo Lara
6acb6bbf8e
docs: update changelog ( #8139 )
2025-06-30 16:34:03 +02:00
Alejandro Bailo
971424f822
fix: ACS dynamic url and password input visible in sign up ( #8131 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-06-30 16:17:34 +02:00
Adrián Jesús Peña Rodríguez
9ba1ae1ced
restore: change api redirect ( #8138 )
2025-06-30 16:15:25 +02:00
dependabot[bot]
062db4cc70
chore(deps): bump protobuf from 6.30.2 to 6.31.1 in /api ( #8053 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-30 21:05:10 +08:00
Pepe Fagoaga
dc4db10c41
fix(version): only for master branch ( #7850 )
2025-06-30 16:50:32 +05:45
Rubén De la Torre Vico
68a542ef64
chore(CHANGELOG): put all checks entries in same format ( #8134 )
2025-06-30 16:50:12 +05:45
Hugo Pereira Brito
32f3787e18
feat(m365powershell): add pwsh authentication via service principal ( #7992 )
...
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-30 18:42:18 +08:00
Víctor Fernández Poyatos
6792bea319
fix(compliance): Avoid initializing Prowler provider ( #8133 )
2025-06-30 12:14:03 +02:00
Prowler Bot
ae4b43c137
chore(regions_update): Changes in regions for AWS services ( #8132 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-06-30 17:53:21 +08:00
Rubén De la Torre Vico
d576c4f1c4
docs(developer-guide): add configurable checks documentation ( #8122 )
2025-06-30 16:47:27 +08:00
Pablo Lara
ddc0596aa2
chore: tweaks for SAML config in profile page ( #8130 )
2025-06-30 09:40:02 +02:00
Rubén De la Torre Vico
636bdb6d0a
docs(prowler-app): add new auth method for GCP ( #8129 )
2025-06-30 15:21:03 +08:00
Alejandro Bailo
4a839b0146
feat: update SAML login URL handling and redirect logic ( #8095 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-06-27 14:44:04 +02:00
Pablo Lara
73e244dce5
docs: update changelog ( #8125 )
2025-06-27 13:51:56 +02:00
Adrián Jesús Peña Rodríguez
d8ed70236b
refactor(s3): adapt test_connection to match AwsProvider ( #8088 )
2025-06-27 13:23:59 +02:00
Sergio Garcia
bcc96ab4f2
fix(gcp): handle case sensitivity in block-project-ssh-keys ( #8115 )
...
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
2025-06-27 19:03:51 +08:00
Alejandro Bailo
fd53a8c9d0
feat: Playright setup ( #8107 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
Co-authored-by: César Arroba <19954079+cesararroba@users.noreply.github.com >
2025-06-27 11:47:21 +02:00
Daniel Barranquero
7b58d1dd56
fix: checks with no resource name ( #8120 )
2025-06-27 17:40:43 +08:00
Víctor Fernández Poyatos
7858c147f7
fix(spec): API specification ( #8119 )
2025-06-27 10:49:36 +02:00
Alejandro Bailo
8e635b3bd4
feat: saml sso ui integration ( #8094 )
2025-06-27 10:45:21 +02:00
Pedro Martín
2e97e37316
feat(dashboard): improve overview page ( #8118 )
2025-06-27 15:41:48 +08:00
Pedro Martín
cd804836a1
docs(dev): add info about installing prowler for a branch ( #8116 )
2025-06-26 23:00:31 +08:00
Víctor Fernández Poyatos
d102ee2fd5
chore: ignore Flask Safety alert in API ( #8114 )
2025-06-26 16:02:39 +02:00
Pedro Martín
325e5739a2
fix(compliance): handle latest assessment date for each account ( #8108 )
2025-06-26 17:48:35 +08:00
Sergio Garcia
98da3059b4
refactor(iac): import checkov python library ( #8093 )
2025-06-25 21:36:21 +08:00
Chandrapal Badshah
80fd5d1ba6
fix: update lighthouse chat page name ( #8106 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-06-25 12:48:20 +02:00
Jack Holloway
85242c7909
fix(aws): retrieve correctly ECS Container insights settings ( #8097 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-25 15:54:20 +08:00
Daniel Barranquero
ea6ab406c8
fix(organizations): Key Error: Statement in check organizations_scp_deny_regions ( #8091 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-25 15:23:38 +08:00
Rubén De la Torre Vico
cbf2a28bac
feat(azure): add new check keyvault_access_only_through_private_endpoints ( #8072 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-24 22:04:02 +08:00
Adrián Jesús Peña Rodríguez
5b1e7bb7f9
fix(saml): avoid IndexError when some attributes are not specified ( #8089 )
2025-06-24 15:55:01 +02:00
crr
e108b2caed
fix(aws): fix logic in VPC and ELBv2 checks ( #8077 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-24 19:13:54 +08:00
Rubén De la Torre Vico
df1abb2152
feat(azure): add new check monitor_alert_service_health_exists ( #8067 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-24 18:04:20 +08:00
Rubén De la Torre Vico
e0465f2aa2
fix(azure): consolidate file share properties to the storage account level ( #8087 )
2025-06-24 17:37:05 +08:00
Drew Kerrigan
51467767cd
fix: allow raising exceptions from validate_mutelist ( #8086 )
2025-06-24 13:14:46 +05:45
Pablo Lara
bc71e7fb3b
chore: set filters panel to be always open by default ( #8085 )
2025-06-23 15:05:53 +02:00
sumit-tft
6a331c05e8
fix(ui): resolve accessibility warnings for Sheet and SVG elements ( #8019 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-23 13:25:05 +02:00
César Arroba
7ab503a096
chore(gha): avoid comment on PRs for check-changelog workflow ( #8084 )
2025-06-23 13:17:03 +02:00
César Arroba
b368190c9f
chore(gha): avoid comment on PRs for check-changelog workflow ( #8083 )
2025-06-23 19:13:13 +08:00
Víctor Fernández Poyatos
8915fdff18
fix(scan): set scheduler_task to null when removing periodic tasks ( #8082 )
2025-06-23 12:53:58 +02:00
Víctor Fernández Poyatos
9bf108e9cc
tests(compliance): add performance tests for compliance ( #8073 )
2025-06-23 12:09:30 +02:00
Prowler Bot
87708e39cf
chore(regions_update): Changes in regions for AWS services ( #8079 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-06-23 17:54:27 +08:00
César Arroba
44927c44e9
chore(gha): add permissions on check-changelog workflow ( #8080 )
2025-06-23 11:49:48 +02:00
dependabot[bot]
71aa29cf24
chore(deps): bump urllib3 from 1.26.20 to 2.5.0 ( #8063 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-23 17:49:20 +08:00
Víctor Fernández Poyatos
aa14daf0db
fix(schema): API reference documentation ( #8078 )
2025-06-23 11:04:25 +02:00
Daniel Barranquero
eb5dbab86e
feat(docs): update Azure and M365 docs with needed permissions ( #8075 )
2025-06-23 10:12:11 +02:00
Víctor Fernández Poyatos
223aab8ece
chore(API): skip safety vulnerabilities related to asteval ( #8076 )
2025-06-20 14:28:23 +02:00
César Arroba
3ec57340a0
chore(gha): check changelog when label is added or deleted ( #8071 )
2025-06-20 16:35:19 +05:45
Pablo Lara
80d73cc05b
feat: integrate Google Tag Manager manually to avoid ORB blocking ( #8070 )
2025-06-20 12:47:17 +02:00
César Arroba
94f02df11e
chore(gha): check changelog changes on pull request ( #7991 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-06-19 14:51:59 +05:45
Pepe Fagoaga
c454ceb296
fix(changelog): Add missing entries ( #8066 )
2025-06-19 14:12:39 +05:45
Pepe Fagoaga
76ec13a1d6
chore(ocsf): remove version number and point to the latest ( #8064 )
2025-06-19 13:33:28 +05:45
Pepe Fagoaga
783b6ea982
chore(api): clean up old files ( #8051 )
2025-06-19 11:57:48 +05:45
Alejandro Bailo
6b7b700a98
feat: filters relationships in findings and scans page ( #8046 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-18 17:19:41 +02:00
César Arroba
b3f2a1c532
chore(ui): add NEXT_PUBLIC_GOOGLE_TAG_MANAGER_ID variable on Dockerfile ( #8061 )
2025-06-18 16:31:55 +02:00
Sergio Garcia
c4e1bd3ed2
fix: add missing changelog compliance timestamps ( #8060 )
2025-06-18 16:28:48 +02:00
Sergio Garcia
d0d4e0d483
fix(compliance): use unified timestampt for all requirements ( #8052 )
2025-06-18 22:00:51 +08:00
Pablo Lara
14a9f0e765
feat: add Google Tag Manager integration ( #8058 )
2025-06-18 15:47:48 +02:00
Rubén De la Torre Vico
b572575c8d
feat(azure): add new check iam_role_user_access_admin_restricted ( #8040 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-18 21:24:23 +08:00
Rubén De la Torre Vico
a626e41162
docs: add provider-specific developer guide sections ( #7996 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-06-18 21:20:33 +08:00
Hugo Pereira Brito
22343faa1e
feat(storage): add new check storage_default_to_entra_authorization_enabled ( #7981 )
2025-06-18 21:16:07 +08:00
Hugo Pereira Brito
c5b37887ef
chore: add pr to changelog ( #8054 )
2025-06-18 14:32:21 +02:00
Rubén De la Torre Vico
f9aed36d0b
feat(azure): add new check databricks_workspace_cmk_encryption_enabled ( #8017 )
2025-06-18 18:36:37 +08:00
Hugo Pereira Brito
facc0627d7
feat(azure): add new check storage_geo_redundant_enabled ( #7980 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-18 18:10:02 +08:00
Rubén De la Torre Vico
76f0d890e9
feat(azure): add Databricks service and check for workspace VNet injection ( #8008 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-18 17:38:09 +08:00
Hugo Pereira Brito
7de7122c3b
fix(m365): avoid user requests in setup_identity app context and user auth log enhancement ( #8043 )
2025-06-18 11:27:11 +02:00
Hugo Pereira Brito
1b73ab2fe4
feat(storage): add new check storage_cross_tenant_replication_disabled ( #7977 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-18 15:54:13 +08:00
Rubén De la Torre Vico
cc8f6131e6
feat(azure): add new check storage_blob_versioning_is_enabled ( #7927 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-18 15:46:38 +08:00
Andoni Alonso
dfd5c9aee7
feat(aws): add check to ensure Codebuild Github projects are only use allowed Github orgs ( #7595 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-18 00:17:18 +08:00
dependabot[bot]
3986bf3f42
chore(deps): bump asteval from 1.0.5 to 1.0.6 ( #8049 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-18 00:11:18 +08:00
Sergio Garcia
c45ef1e286
chore(deps): update requests dependency ( #8048 )
2025-06-18 00:04:09 +08:00
dependabot[bot]
8d8f498dc2
chore(deps): bump asteval from 1.0.5 to 1.0.6 ( #8047 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-17 23:32:13 +08:00
Sergio Garcia
c4bd9122d4
feat(IaC): PoC for IaC Security Scanner ( #7852 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-06-17 23:23:25 +08:00
dependabot[bot]
644cdc81b9
chore(deps): bump requests from 2.32.3 to 2.32.4 in /api ( #7986 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-17 16:46:29 +02:00
Pablo Lara
e5584f21b3
feat: make user and password fields optional but mutually required fo… ( #8044 )
2025-06-17 14:46:00 +02:00
Rubén De la Torre Vico
b868d39bef
chore(deps): add pre-commit as a dev dependency ( #8042 )
2025-06-17 18:54:32 +08:00
Alejandro Bailo
ef9809f61f
fix: correct parenthesis around the render condition ( #8041 )
2025-06-17 12:22:17 +02:00
Alejandro Bailo
9a04ca3611
feat: touching up compliances views ( #8022 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-17 11:23:14 +02:00
Pedro Martín
1c9b3a1394
feat(m365): add ISO 27001 2022 compliance framework ( #7985 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-17 17:04:36 +08:00
dependabot[bot]
5ee7bd6459
chore(deps): bump protobuf from 6.30.2 to 6.31.1 ( #8037 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-17 16:31:04 +08:00
Chandrapal Badshah
05d2b86ba8
feat(lighthouse): update NextJS logic to work with latest APIs ( #8033 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-06-17 10:25:37 +02:00
Andoni Alonso
84c30af6f8
chore(sentry): handle exceptions ignores not based in ClassNames ( #8034 )
2025-06-17 09:42:24 +02:00
dcanotrad
e8a829b75e
docs(dev-guide): improve quality redrive ( #7718 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: Rubén De la Torre Vico <rubendltv22@gmail.com >
2025-06-17 09:28:22 +02:00
Sergio Garcia
a0d169470d
chore(metadata): add validator for ResourceType ( #8035 )
2025-06-17 00:06:32 +08:00
Rubén De la Torre Vico
1fd6046511
chore: add missing init file to check repository_secret_scanning_enabled ( #8029 )
2025-06-16 21:31:18 +08:00
Sergio Garcia
524455b0f3
fix(metadata): add missing ResourceType values ( #8028 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-06-16 21:30:55 +08:00
Víctor Fernández Poyatos
e6e1e37c1e
fix(findings): exclude blank resource types from metadata endpoints ( #8027 )
2025-06-16 18:19:21 +05:45
Prowler Bot
2914510735
chore(regions_update): Changes in regions for AWS services ( #8026 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-06-16 19:00:06 +08:00
Rubén De la Torre Vico
7e43c7797f
fix(eks): add EKS to service without subservices ( #7959 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-16 16:46:48 +08:00
Rubén De la Torre Vico
6954ef880e
fix(azure): add new way to auth against App Insight ( #7763 )
2025-06-16 16:46:36 +08:00
Chandrapal Badshah
5f5e7015a9
feat(lighthouse): Add django endpoints to store config ( #7848 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
Co-authored-by: Víctor Fernández Poyatos <vicferpoy@gmail.com >
2025-06-16 10:11:57 +02:00
Andoni Alonso
bfafa518b1
feat(aws): avoid bypassing IAM check using wildcards ( #7708 )
2025-06-16 07:42:01 +02:00
Hugo Pereira Brito
e34e59ff2d
fix(network): allow 0 as compliant value ( #7926 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-13 19:50:19 +08:00
Daniel Barranquero
7f80d2db46
fix(app): change api call for ftps_state ( #7923 )
2025-06-13 19:28:55 +08:00
sumit-tft
4a2a3921da
feat(UI): Add Provider detail component in Findings, Scan details ( #7968 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-13 12:17:18 +02:00
Pedro Martín
e26b2e6527
feat(api): handle MitreAttack compliance requirements ( #7987 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-06-13 10:26:34 +02:00
Mitchell @ Securemetrics
954814c1d7
feat(contrib): add PowerBI integration ( #7826 )
...
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
2025-06-13 09:55:07 +02:00
Andoni Alonso
113224cbd9
chore: update CHANGELOG ( #8015 )
2025-06-13 15:38:56 +08:00
Andoni Alonso
f5f1fce779
fix(iam): check always if root credentials are present ( #7967 )
2025-06-12 17:48:09 +02:00
Pepe Fagoaga
0ba9383202
chore(changelog): make all consistent ( #8010 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-12 20:09:01 +05:45
Adrián Jesús Peña Rodríguez
8e9a9797c7
fix(export): add name sanitization ( #8007 )
2025-06-12 20:02:18 +05:45
Pablo Lara
2b4e6bffae
chore: update package-lock after lighthouse was merged ( #8011 )
2025-06-12 15:32:58 +02:00
Chandrapal Badshah
74f7a86c2b
feat(lighthouse): Add chat interface ( #7878 )
...
Co-authored-by: Chandrapal Badshah <12944530+Chan9390@users.noreply.github.com >
2025-06-12 15:19:41 +02:00
Pablo Lara
e218435b2f
fix: improve error handling in UpdateViaCredentialsForm with early re… ( #7988 )
2025-06-12 11:39:49 +02:00
Prowler Bot
5ec34ad5e7
chore(regions_update): Changes in regions for AWS services ( #7973 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-06-12 17:24:15 +08:00
Pedro Martín
c4b0859efd
fix(dashboard): handle account uids with 0 at start and end ( #7955 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-12 17:21:52 +08:00
Pedro Martín
1241a490f9
fix(kubernetes): change object type to set for apiserver check ( #7952 )
2025-06-12 17:02:48 +08:00
Pedro Martín
4ec498a612
fix(k8s): remove typo for PCI 4.0 compliance framework ( #7971 )
2025-06-12 16:41:58 +08:00
Pedro Martín
119c5e80a9
feat(gcp): add NIS 2 compliance framework ( #7912 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-06-12 16:40:33 +08:00
sumit-tft
d393bc48a2
fix(PRWLR-7380): button nesting hydration error ( #7998 )
2025-06-12 10:02:20 +02:00
Daniel Barranquero
e09e3855b1
fix(gcp): remove azure video from gcp docs ( #8001 )
2025-06-12 09:54:25 +02:00
Alejandro Bailo
8751615faa
feat: MittreAtack compliance detailed view ( #8002 )
2025-06-12 09:27:47 +02:00
Prowler Bot
e7c17ab0b3
chore(regions_update): Changes in regions for AWS services ( #7898 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-06-12 15:14:28 +08:00
dependabot[bot]
f05d3eb334
chore(deps): bump trufflesecurity/trufflehog from 3.88.26 to 3.88.35 ( #7896 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-12 15:14:02 +08:00
dependabot[bot]
cf449d4607
chore(deps): bump aws-actions/configure-aws-credentials from 4.1.0 to 4.2.1 ( #7895 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-12 15:13:35 +08:00
dependabot[bot]
b338ac9add
chore(deps): bump codecov/codecov-action from 5.4.2 to 5.4.3 ( #7894 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-12 15:13:12 +08:00
dependabot[bot]
366d2b392a
chore(deps): bump docker/build-push-action from 6.16.0 to 6.18.0 ( #7893 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-12 15:12:52 +08:00
dependabot[bot]
41fc536b44
chore(deps): bump github/codeql-action from 3.28.16 to 3.28.18 ( #7892 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-06-12 15:12:28 +08:00
Adrián Jesús Peña Rodríguez
e042445ecf
fix(migration): create site stuff before socialaccount ( #7999 )
2025-06-11 13:34:21 +02:00
Víctor Fernández Poyatos
c17129afe3
revert: RLS transactions handling and DB custom backend ( #7994 )
2025-06-11 14:47:10 +05:45
Alejandro Bailo
4876d8435c
feat: generic compliance detailed view ( #7990 )
2025-06-11 09:40:53 +02:00
Pedro Martín
1bd0d774e5
feat(mutelist): make validate_mutelist method static ( #7811 )
2025-06-11 11:33:49 +05:45
Alejandro Bailo
c119cece89
feat: ThreatScore compliance detailed view ( #7979 )
2025-06-10 10:43:27 +02:00
Adrián Jesús Peña Rodríguez
e24b211d22
feat(sso): add sso with saml to API ( #7822 )
2025-06-10 10:17:54 +02:00
Hugo Pereira Brito
c589c95727
feat(storage): add new check storage_account_key_access_disabled ( #7974 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-06-10 08:23:09 +02:00
Hugo Pereira Brito
7e4f1a73bf
feat(storage): add new check storage_ensure_file_shares_soft_delete_is_enabled ( #7966 )
2025-06-10 08:09:11 +02:00
Pepe Fagoaga
4d00aece45
chore(changelog): move entry for their version ( #7969 )
2025-06-09 21:50:13 +05:45
Hugo Pereira Brito
49aaf011aa
fix(parser): add GitHub provider to prowler -h usage section ( #7906 )
2025-06-09 17:47:29 +02:00
Adrián Jesús Peña Rodríguez
898934c7f8
chore: update django version ( #7984 )
2025-06-09 17:33:16 +02:00
Pepe Fagoaga
81c4b5a9c1
chore(api): Delete old docker compose file ( #7982 )
2025-06-09 21:01:52 +05:45
Pepe Fagoaga
fe31656ffe
fix(k8s): return a session if using kubeconfig_content ( #7953 )
2025-06-09 19:11:59 +05:45
Hugo Pereira Brito
359059dee6
fix(docs): add Organization.Read.All to M365 provider requirements ( #7961 )
2025-06-09 12:11:14 +02:00
Alejandro Bailo
2eaa37921d
feat: KISA detailed view ( #7965 )
2025-06-09 09:29:34 +02:00
Pablo Lara
3a99909b75
chore: align Next.js version to 14.2.29 across Prowler and Cloud ( #7962 )
2025-06-06 13:54:42 +02:00
Pablo Lara
2ecd9ad2c5
docs: update changelog ( #7960 )
2025-06-06 13:17:38 +02:00
Alejandro Bailo
50dc396aa3
feat: scan id filter drowpdown ( #7949 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-06 12:38:14 +02:00
Andoni Alonso
acf333493a
chore(api): reorder docker layers to speed up build times ( #7957 )
2025-06-06 10:42:14 +02:00
Pedro Martín
bd6272f5a7
feat(docs): add information about tenants and read-only roles ( #7956 )
2025-06-06 10:14:33 +02:00
Pepe Fagoaga
8c95e1efaf
chore: update API changelog for v5.7.3 ( #7948 )
2025-06-05 15:54:36 +02:00
Hugo Pereira Brito
845a0aa0d5
fix(changelog): add entries for password encryption in v5.7.3 ( #7939 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-06-05 14:23:12 +02:00
Hugo Pereira Brito
75a11be9e6
fix(docs): add final permission assignments example ( #7943 )
2025-06-05 18:07:43 +05:45
Hugo Pereira Brito
a778d005b6
fix(docs): add mfa warning for users ( #7924 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-06-05 17:55:27 +05:45
Pedro Martín
1281f4ec5e
chore(changelog): update following the correct format ( #7908 )
2025-06-05 17:52:36 +05:45
Víctor Fernández Poyatos
6332427e5e
fix(compliance): add manual status to requirements ( #7938 )
2025-06-05 10:54:51 +02:00
Alejandro Bailo
d89df83904
fix: Improve the perfomance removing regions heatmap ( #7934 )
2025-06-05 08:13:47 +02:00
Víctor Fernández Poyatos
be420afebc
feat(database): handle already closed connections ( #7935 )
2025-06-04 16:09:36 +02:00
Adrián Jesús Peña Rodríguez
fb914a2c90
revert: remove get_with_retry ( #7932 )
2025-06-04 15:01:47 +02:00
Pablo Lara
4ac3cfc33d
docs: update changelog ( #7931 )
2025-06-04 13:54:25 +02:00
Alejandro Bailo
c74360ab63
fix: clear filters sync ( #7928 )
2025-06-04 13:32:52 +02:00
Alejandro Bailo
4dc4d82d42
feat: aws-well-architected compliance detailed view ( #7925 )
2025-06-04 12:26:27 +02:00
Víctor Fernández Poyatos
6e7a32cb51
revert(views): calling order to initial view method ( #7921 )
2025-06-03 16:38:00 +02:00
Alejandro Bailo
49e501c4be
feat: CIS compliance detail view ( #7913 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-06-03 15:47:46 +02:00
Víctor Fernández Poyatos
9ee78fe65f
fix(views): calling order to initial view method ( #7918 )
2025-06-03 13:34:44 +02:00
Víctor Fernández Poyatos
7a0549d39c
fix(rls): Apply persistent RLS transactions ( #7916 )
2025-06-03 13:10:41 +02:00
Alejandro Bailo
3e8c86d880
feat: ISO compliance detail view ( #7897 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-06-03 09:20:52 +02:00
Pablo Lara
e34c18757d
fix: Fix named export for addCredentialsServiceAccountFormSchema ( #7909 )
2025-06-03 08:33:24 +02:00
Alejandro Bailo
5c1a47d108
feat: compliance detail view + ENS ( #7853 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-06-02 18:20:22 +02:00
Víctor Fernández Poyatos
59c51d5a4a
feat(compliance): Rework compliance overviews ( #7877 )
2025-06-02 17:06:24 +02:00
Pedro Martín
66aa67f636
feat(changelog): update version with fixes ( #7904 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-06-02 12:32:45 +02:00
Pablo Lara
bdda377482
docs: update the changelog ( #7901 )
2025-06-02 11:49:04 +02:00
Hugo Pereira Brito
aa11ed70bd
chore(docs): replace old permission images ( #7900 )
2025-06-02 11:47:11 +02:00
Adrián Jesús Peña Rodríguez
0580dca6cf
fix: set user_id for tenant operations ( #7890 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-06-02 11:06:49 +02:00
Pablo Lara
678ef0ab5a
feat(providers): setup workflow to support new GCP credential method ( #7872 )
2025-06-02 10:23:39 +02:00
César Arroba
4888c27713
chore: fix commit sha when a pr is merged ( #7889 )
2025-05-30 17:40:57 +05:45
Hugo Pereira Brito
b256c10622
chore: replace Directory.Read.All permission to Domain.Read.All for Azure ( #7888 )
2025-05-30 10:24:49 +02:00
Adrián Jesús Peña Rodríguez
878e4e0bbc
fix: add new get method to avoid race conditions when creating async tasks ( #7876 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-05-30 10:07:32 +02:00
Hugo Pereira Brito
6c3653c483
fix(docs): remove warning of encrypted password for cloud ( #7886 )
2025-05-30 12:01:32 +04:00
Daniel Barranquero
71ac703e6f
fix(api): connection correctly reflected ( #7831 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-05-29 20:23:15 +05:45
Sergio Garcia
a89e3598f2
fix(gcp): test connection by verifying token ( #7882 )
2025-05-29 13:20:53 +02:00
Alison Vilela
5d043cc929
fix(awslambda): aws service awslambda not working ( #7869 )
2025-05-29 12:50:23 +05:45
Pepe Fagoaga
921f94ebbf
fix(k8s): UID validation for valid context names ( #7871 )
2025-05-29 12:32:57 +05:45
sumit-tft
48c9ed8a79
fix(ui): increase limit to retrieve more than 10 scan list ( #7865 )
2025-05-29 07:52:36 +02:00
Hugo Pereira Brito
12987ec9f9
fix(admincenter): service and group visibility ( #7870 )
2025-05-28 16:48:49 +02:00
Hugo Pereira Brito
40b90ed063
fix(tests): typo in m365 domain test ( #7866 )
2025-05-28 16:43:58 +02:00
Alejandro Bailo
60314e781f
feat: enhance CustomDropdownFilter ( #7868 )
2025-05-28 16:30:28 +02:00
Harsh Kumar
bc56d48595
feat(dashboard): add client-side search functionality to findings table ( #7804 )
...
Co-authored-by: Harsh Kumar <harsh.k@cybersecurist.com >
2025-05-28 11:44:01 +02:00
Pedro Martín
2d71cef3d5
feat(azure): add NIS 2 compliance framework ( #7857 )
2025-05-28 11:35:40 +02:00
Daniel Barranquero
41f6637497
fix(defender): update defender_ensure_notify_alerts_severity_is_high logic ( #7862 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-28 10:32:44 +02:00
Pedro Martín
c2e54bbbcc
fix(threatscore): remove compliance name in tests to remove dummy files ( #7859 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-28 10:03:20 +02:00
sumit-tft
df8aacd09d
fix(ui): Added missing icons (kisa, prowlerThreat) on compliance page ( #7860 )
2025-05-28 09:51:28 +02:00
Matt Keeler
2dd6be59b9
fix(m365): add compliantDevice grant control support ( #7844 )
2025-05-28 09:05:00 +02:00
Hugo Pereira Brito
9e8e3eb0e6
fix(m365): update documentation ( #7823 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-05-28 08:52:03 +02:00
Sergio Garcia
3728430f8c
chore: update README ( #7842 )
...
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
2025-05-27 14:25:37 +02:00
sumit-tft
ea97de7f43
fix(ui): updated to use the correct message when download report clicked ( #7758 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-05-27 10:51:08 +02:00
Rubén De la Torre Vico
f254a4bc0d
feat(app): split SDK App service calls ( #7778 )
2025-05-27 09:52:50 +02:00
Pedro Martín
66acfd8691
feat(aws): add NIS2 compliance framework ( #7839 )
2025-05-27 09:35:57 +02:00
Matt Keeler
02ca82004f
fix(typo): minor language updates ( #7843 )
2025-05-27 09:26:51 +02:00
Rubén De la Torre Vico
60b5a79b27
fix(vpc): change the ServiceName from EC2 to VPC ( #7840 )
2025-05-26 17:52:59 +02:00
Sergio Garcia
be1e3e942b
feat(api): support GCP Service Account key ( #7824 )
...
Co-authored-by: Sergio Garcia <38561120+garcitm@users.noreply.github.com >
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-05-26 15:42:39 +02:00
Sergio Garcia
3658e85cfc
chore(github): add Branch class ( #7838 )
2025-05-26 14:34:44 +02:00
Adrián Jesús Peña Rodríguez
15e4d1acce
refactor(reports): change API response message when tasks are running ( #7837 )
2025-05-26 12:20:05 +02:00
Andoni Alonso
44afd9ed31
fix: repository repository_dependency_scanning_enabled check logic ( #7834 )
2025-05-26 10:44:19 +02:00
Andoni Alonso
4f099c5663
refactor(github): use owner instead of repository in findings attributes ( #7833 )
2025-05-26 10:40:41 +02:00
Andoni Alonso
eaec683eb9
feat(repositoy): add new check repository_inactive_not_archived ( #7786 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-26 10:39:09 +02:00
Adrián Jesús Peña Rodríguez
50bcd828e9
fix(reports): change invalid search term for tasks ( #7830 )
2025-05-26 10:24:11 +02:00
Alejandro Bailo
91545e409e
feat: change tenant name in /profile page ( #7829 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-05-23 14:45:28 +02:00
Alejandro Bailo
33031d2c96
feat: implement provider UID extraction and mapping in scans pages ( #7820 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-05-23 13:42:35 +02:00
Hugo Pereira Brito
1b42dda817
fix(formSchemas): encrypted password typo ( #7828 )
2025-05-23 12:52:17 +02:00
Hugo Pereira Brito
f726d964a8
fix(m365): remove last encrypted password appearances ( #7825 )
2025-05-23 12:27:57 +02:00
Hugo Pereira Brito
36aaec8a55
chore(m365powershell): manage encryption from plaintext password ( #7784 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2025-05-22 17:36:58 +02:00
Andoni Alonso
99164ce93e
feat(repository): add new check repository_default_branch_requires_signed_commits ( #7777 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-22 12:45:13 +02:00
Andoni Alonso
7ebc5d3c31
feat(repository): add new check repository_dependency_scanning_enabled ( #7771 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-22 12:22:59 +02:00
Andoni Alonso
06ff3db8af
feat(repository): add new check repository_secret_scanning_enabled ( #7759 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-22 11:23:42 +02:00
Alejandro Bailo
c44ea3943e
feat: resources in finding tables ( #7813 )
2025-05-22 08:58:25 +02:00
Andoni Alonso
d036e0054b
feat(repository): add new check repository_default_branch_requires_codeowners_review ( #7753 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-21 16:18:55 +02:00
Pedro Martín
f72eb7e212
fix(files): remove empty files ( #7819 )
2025-05-21 16:15:04 +02:00
Andoni Alonso
62dcbc2961
feat(repository): add new check repository_has_codeowners_file ( #7752 )
2025-05-21 15:28:30 +02:00
Hugo Pereira Brito
dddec4c688
fix(m365): add powershell.close() to msgraph services ( #7816 )
2025-05-21 15:13:03 +02:00
Sergio Garcia
6d00554082
chore(readme): add Prowler Hub link ( #7814 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-05-21 17:46:54 +05:45
Pedro Martín
65d3fcee4c
feat(prowler-threatscore): add Weight field inside req ( #7795 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-21 12:57:10 +02:00
Pedro Martín
16cd0e4661
feat(prowler_threatscore): add a level for accordion in dashboard ( #7739 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-21 12:46:47 +02:00
Hugo Pereira Brito
6e184dae93
fix(admincenter): admincenter_users_admins_reduced_license_footprint logic ( #7779 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-21 12:46:35 +02:00
Pablo Lara
118f3d163d
docs: update changelog UI ( #7808 )
2025-05-21 12:39:48 +02:00
Pedro Martín
7d84d67935
feat(gcp): add CIS 4.0 compliance framework ( #7785 )
2025-05-21 12:38:34 +02:00
Víctor Fernández Poyatos
1c1c58c975
feat(findings): Add new index for finding UID lookup ( #7800 )
2025-05-21 11:56:54 +02:00
Andoni Alonso
31ea672c61
fix: move changes to release 5.8 ( #7801 )
2025-05-21 11:45:54 +02:00
Toni de la Fuente
7016779b8e
chore(README): update README.md ( #7799 )
2025-05-21 11:31:23 +02:00
Pedro Martín
4e958fdf39
feat(kubernetes): add CIS 1.11 compliance framework ( #7790 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-21 11:09:47 +02:00
Pedro Martín
c6259b6c75
fix(dashboard): remove typo from subscribe cards ( #7792 )
2025-05-21 11:08:52 +02:00
Sergio Garcia
021e243ada
feat(kubernetes): support HTTPS_PROXY and K8S_SKIP_TLS_VERIFY ( #7720 )
2025-05-21 10:49:18 +02:00
Alejandro Bailo
acdf420941
feat: profile page ( #7780 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-05-21 10:47:32 +02:00
Hugo Pereira Brito
4e84507130
feat(entra): add new check entra_users_mfa_capable ( #7734 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-05-21 10:31:56 +02:00
Prowler Bot
2a61610fec
chore(regions_update): Changes in regions for AWS services ( #7774 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-05-21 10:29:08 +02:00
Daniel Barranquero
9b127eba93
feat(admincenter): add new check admincenter_external_calendar_sharing_disabled ( #7733 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-05-21 09:14:45 +02:00
Hugo Pereira Brito
1a89d65516
fix(m365powershell): add sanitize to test_credentials ( #7761 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-05-21 08:49:04 +02:00
Daniel Barranquero
84749df708
feat(admincenter): add new check admincenter_organization_customer_lockbox_enabled ( #7732 )
...
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-05-21 08:48:36 +02:00
Pepe Fagoaga
6f7cd85a18
chore(backport): create label on minor release ( #7791 )
2025-05-21 12:14:30 +05:45
Alejandro Bailo
ad39061e1a
fix: retrieve more than 10 providers ( #7793 )
2025-05-21 08:07:43 +02:00
Pablo Lara
615bacccaf
chore: tweak some wording for consistency ( #7794 )
2025-05-21 07:59:53 +02:00
Prowler Bot
b3a2479fab
chore(release): Bump version to v5.8.0 ( #7788 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-05-20 22:27:21 +05:45
sumit-tft
871c877a33
fix: AWS I AM role validation when field is empty ( #7787 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-05-20 11:25:40 +02:00
Pedro Martín
7fd58de3bf
feat(export): support m365 - prowler threatscore ( #7783 )
2025-05-19 15:59:42 +02:00
Víctor Fernández Poyatos
40f24b4d70
fix(providers): Fix m365 UID validation ( #7781 )
2025-05-19 13:34:46 +02:00
Adrián Jesús Peña Rodríguez
d8f80699d4
chore: update api changelog ( #7775 )
2025-05-19 14:52:32 +05:45
Pablo Lara
f24d0efc77
docs: update changelog ( #7773 )
2025-05-19 14:34:28 +05:45
Hugo Pereira Brito
a18dd76a5a
chore(m365): accept all tenant domains in authentication ( #7746 )
2025-05-19 13:53:54 +05:45
Pedro Martín
a2362b4bbc
fix(cis): rename and add sections and subsections ( #7738 )
2025-05-19 09:42:04 +02:00
Pedro Martín
e5f1c2b19c
feat(aws): add CIS 5.0 compliance framework ( #7766 )
2025-05-19 09:41:56 +02:00
Pedro Martín
0490ab6944
docs(checks): improve docs related with checks ( #7768 )
2025-05-19 09:17:14 +02:00
Sergio Garcia
97baa8a1e6
chore(ec2): improve severity logic in SG all ports open check ( #7764 )
2025-05-16 15:09:48 +02:00
Hugo Pereira Brito
637ebdc3db
feat(repository): add new check repository_branch_delete_on_merge_enabled ( #6209 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-16 15:03:37 +02:00
Hugo Pereira Brito
451b36093f
feat(repository): add new check repository_default_branch_requires_conversation_resolution ( #6208 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-16 14:57:15 +02:00
Víctor Fernández Poyatos
beb0457aff
fix(findings): Fix latest metadata backfill condition and optimization ( #7765 )
2025-05-16 14:50:40 +02:00
Víctor Fernández Poyatos
0335ea4e0b
fix(findings): Fix latest metadata backfill condition ( #7762 )
2025-05-16 12:41:12 +02:00
sumit-tft
355abca5a3
fix(ui): Removed the alias if not available in findings detail page ( #7751 )
2025-05-16 09:02:47 +02:00
sumit-tft
7d69cc4cd9
fix: Updated the high risk section provider icons to make it consistent ( #7706 )
2025-05-16 08:53:34 +02:00
Hugo Pereira Brito
cdc4b362a4
feat(repository): add new check repository_default_branch_protection_applies_to_admins ( #6205 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-16 08:29:45 +02:00
Pablo Lara
6417e6bbba
feat: use getFindingsLatest when no scan or date filters are applied ( #7756 )
2025-05-16 08:18:12 +02:00
Víctor Fernández Poyatos
b810d45d34
feat(findings): Add /findings/latest and /findings/metadata/latest endpoints ( #7743 )
2025-05-15 16:08:09 +02:00
Ogonna Iwunze
f5a2695c3b
fix(check): Add support for condition with restriction on SNS endpoint ( #7750 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-15 16:00:00 +02:00
Hugo Pereira Brito
977c788fff
feat(repository): add new check repository_default_branch_status_checks_required ( #6204 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-15 15:33:49 +02:00
Hugo Pereira Brito
21f8b5dbad
fix(check): add missing __init__.py files ( #7748 )
2025-05-15 11:22:58 +02:00
Hugo Pereira Brito
1c874d1283
feat(repository): add new check repository_default_branch_deletion_disabled ( #6200 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-15 08:33:36 +02:00
Hugo Pereira Brito
8f9bdae2b7
feat(repository): add new check repository_default_branch_disallows_force_push ( #6197 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-14 16:48:47 +02:00
Pablo Lara
600813fb99
fix: force z-index componet select provider ( #7744 )
...
Co-authored-by: StylusFrost <pm.diaz.pena@gmail.com >
2025-05-14 15:19:41 +02:00
Hugo Pereira Brito
5a9ccd60a0
feat(repository): add new check repository_default_branch_requires_linear_history ( #6162 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-14 14:37:27 +02:00
Hugo Pereira Brito
beb7a53efe
feat(repository): add new check repository_default_branch_protection_enabled ( #6161 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-14 13:42:59 +02:00
Hugo Pereira Brito
8431ce42a1
feat(organization): add new check organization_members_mfa_required ( #6304 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-14 13:29:08 +02:00
Pablo Lara
c5a9b63970
fix: UID Filter Improvement ( #7741 )
...
Co-authored-by: sumit_chaturvedi <chaturvedi.sumit@tftus.com >
2025-05-14 11:36:27 +02:00
Hugo Pereira Brito
a765c1543e
feat: add GitHub provider documentation and CIS v1.0.0 compliance ( #6116 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-14 10:47:33 +02:00
Hugo Pereira Brito
484a773f5b
feat(github): add new service Organization ( #6300 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-14 10:40:26 +02:00
Hugo Pereira Brito
9ecf570790
feat(github): add new check repository_code_changes_multi_approval_requirement ( #6160 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-14 10:06:52 +02:00
Adrián Jesús Peña Rodríguez
f8c840f283
fix: ensure proper folder creation ( #7729 )
2025-05-14 10:02:41 +02:00
Pepe Fagoaga
deec9efa97
feat(ui): Add AWS CloudFormation Quick Link to deploy the IAM Role ( #7735 )
2025-05-14 09:30:01 +02:00
César Arroba
2ee62cca8e
chore: add ref on checkout step ( #7740 )
2025-05-14 12:24:49 +05:45
Hugo Pereira Brito
413b948ca0
feat(github): add GitHub provider ( #5787 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-13 15:28:01 +02:00
Pablo Lara
d548e869fa
docs: update changelog ( #7731 )
2025-05-13 13:41:41 +02:00
Sergio Garcia
5c8919372c
fix(deps): solve h11 package vulnerability ( #7728 )
2025-05-13 13:29:22 +02:00
Sergio Garcia
9baac9fd89
fix(deps): solve h11 package vulnerability ( #7696 )
2025-05-13 13:10:06 +02:00
sumit-tft
252b664e49
fix: Added filter to get connected providers only for banner to show ( #7723 )
2025-05-13 12:58:23 +02:00
Víctor Fernández Poyatos
496e0f1e0a
fix(overviews): Split in n queries to use database indexes for providers ( #7725 )
2025-05-13 12:34:14 +02:00
dependabot[bot]
80342d612f
chore(deps): bump h11 from 0.14.0 to 0.16.0 in /api ( #7610 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-05-13 12:15:14 +02:00
Pablo Lara
02d7eaf268
chore: bump tailwind-merge from 2.5.3 to 3.2.0 ( #7722 )
2025-05-13 09:27:27 +02:00
Hugo Pereira Brito
1a8df3bf18
fix(defender): enhance policies checks logic ( #7666 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-12 17:02:30 +02:00
Pablo Lara
16f2209d3f
chore: add M365 to scan page filters ( #7704 )
2025-05-12 16:20:07 +02:00
Pablo Lara
70e22af550
chore(deps): upgrade recharts from 2.13.0-alpha.4 to 2.15.2 ( #7717 )
2025-05-12 16:09:54 +02:00
Sergio Garcia
44f26bc0d5
chore(docs): quality redrive to README.md ( #7616 )
...
Co-authored-by: dcanotrad <168282715+dcanotrad@users.noreply.github.com >
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-05-12 15:23:14 +02:00
Alejandro Bailo
a19f5d9a9a
feat: scan label validation ( #7693 )
2025-05-12 15:07:44 +02:00
Hugo Pereira Brito
b78f53a722
chore(findings): enhance m365 authentication method information ( #7681 )
2025-05-12 18:31:32 +05:45
Víctor Fernández Poyatos
c20f07ced4
feat(findings): Improve performance on /findings/metadata, /overviews and filters ( #7690 )
2025-05-12 14:34:37 +02:00
Hugo Pereira Brito
7c3a53908b
chore(compliance): update CIS 4.0 for M365 ( #7699 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-12 12:59:50 +02:00
Pepe Fagoaga
ea3c71e22c
fix(bump-version): bump for fix also in minors ( #7712 )
2025-05-12 12:45:17 +02:00
Pedro Martín
40eaa79777
docs(compliance): update compliance page with latest changes ( #7694 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-12 12:37:43 +02:00
Prowler Bot
aa8119970e
chore(regions_update): Changes in regions for AWS services ( #7709 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-05-12 12:37:21 +02:00
Pepe Fagoaga
55fc8cb55b
chore(api): Set tab name for API reference ( #7713 )
2025-05-12 16:16:29 +05:45
Andoni Alonso
abf51eceee
fix(typo): rename generate_compliance_json_from_csv_threatscore ( #7698 )
2025-05-12 12:29:30 +02:00
Pedro Martín
458c51dda3
feat(m365): add Prowler Threatscore ( #7692 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-12 12:28:50 +02:00
Sergio Garcia
c8d2a44ab0
feat(kubernetes): allow setting cluster name in in-cluster mode ( #7695 )
2025-05-12 12:28:04 +02:00
César Arroba
0a71628298
chore: add pass PR url ( #7711 )
2025-05-12 11:55:00 +02:00
Pablo Lara
60e0040577
fix: move ProviderType to shared types and update usages ( #7710 )
2025-05-12 11:54:42 +02:00
Alejandro Bailo
5c375d63c5
feat: Horizontal bar chart ( #7680 )
2025-05-12 11:14:10 +02:00
Adrián Jesús Peña Rodríguez
4d84529ba2
docs: update the download export documentation ( #7682 )
2025-05-12 14:45:53 +05:45
Prowler Bot
0737d9e8bb
chore(release): Bump version to v5.7.0 ( #7697 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-05-12 14:41:28 +05:45
Alejandro Bailo
50c5294bc0
feat: accordion component ( #7700 )
2025-05-12 14:17:40 +05:45
Hugo Pereira Brito
f63e9e5e77
fix(m365): invalid user credentials exception ( #7677 )
2025-05-12 13:22:13 +05:45
Hugo Pereira Brito
3cab52772c
feat(m365): add categories for tenant type e3 and e5 ( #7691 )
2025-05-09 08:11:44 +02:00
Pepe Fagoaga
81aa035451
chore(changelog): prepare for v5.6.0 ( #7688 )
2025-05-08 16:49:56 +05:45
Pedro Martín
899f31f1ee
fix(prowler_threatscore): fine-tune LevelOfRisk ( #7667 )
2025-05-08 15:23:31 +05:45
Pedro Martín
e142a9e0f4
fix(dashboard): drop duplicates for rows ( #7686 )
2025-05-08 14:20:19 +05:45
Sergio Garcia
ed26c2c42c
fix(mutelist): properly handle wildcards and regex ( #7685 )
2025-05-08 12:10:55 +05:45
Pedro Martín
1017510a67
fix(dashboard): remove muted findings on compliance page ( #7683 )
2025-05-07 13:52:14 -04:00
Adrián Jesús Peña Rodríguez
bfa16607b0
feat: add compliance to API report files and its endpoint ( #7653 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-05-07 20:44:58 +05:45
Hugo Pereira Brito
4c874b68f5
fix(metadata): typo in defender_chat_report_policy_configured ( #7678 )
2025-05-07 09:30:49 -04:00
Sergio Garcia
9458e2bbc4
fix(inspector2): handle error when getting active findings ( #7670 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-07 14:39:34 +02:00
Alejandro Bailo
2da7b926ed
feat: add DeltaIndicator in new findings ( #7676 )
2025-05-07 17:59:56 +05:45
Daniel Barranquero
8d4f0ab90a
feat(docs): add snapshots to M365 docs ( #7673 )
2025-05-07 12:19:10 +02:00
Hugo Pereira Brito
83aefc42c1
fix(powershell): remove platform-specific execution ( #7675 )
2025-05-07 11:44:13 +02:00
Alejandro Bailo
a6489f39fd
refactor(finding-detail): remove "Next Scan" field ( #7674 )
2025-05-07 14:39:35 +05:45
Pablo Lara
15c34952cf
docs: update changelog ( #7672 )
2025-05-07 09:43:17 +02:00
Alejandro Bailo
d002f2f719
feat: diff between providers actions depending on their secrets ( #7669 )
2025-05-07 09:35:53 +02:00
Sergio Garcia
8530676419
chore(actions): run tests in dependabot updates ( #7671 )
2025-05-07 11:43:01 +05:45
Pedro Martín
fe5a78e4d4
feat(aws): add static credentials for S3 and SH ( #7322 )
2025-05-06 17:55:53 +02:00
Pablo Lara
d823b2b9de
chore: tweaks for m365 provider ( #7668 )
2025-05-06 17:06:44 +02:00
Alejandro Bailo
3b17eb024c
feat: add delta attribute in findings detail view with and finding id to the url ( #7654 )
2025-05-06 16:52:15 +02:00
Pablo Lara
87951a8371
feat(compliance): add a button to download the report in compliance card ( #7665 )
2025-05-06 14:44:02 +02:00
Andoni Alonso
e5ca51d1e7
feat(teams): add new checks teams_security_reporting_enabled and defender_chat_report_policy_configured ( #7614 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com >
2025-05-06 11:30:00 +02:00
Daniel Barranquero
e2fd3fe36e
feat(defender): add new check defender_malware_policy_comprehensive_attachments_filter_applied ( #7661 )
2025-05-06 10:29:36 +02:00
Daniel Barranquero
6b0d73d7f9
feat(exchange): make exchange_user_mailbox_auditing_enabled check configurable ( #7662 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-05 15:16:41 -04:00
Hugo Pereira Brito
7eec60f4d9
feat(m365): ensure all forms of mail forwarding are blocked or disabled ( #7658 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-05-05 11:21:14 -04:00
Daniel Barranquero
9d788af932
docs(m365): add documentation for m365 ( #7622 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-05 16:46:32 +02:00
Pedro Martín
bbc0388d4d
chore(changelog): update with latest PR ( #7628 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-05 10:40:59 -04:00
Pedro Martín
887db29d96
feat(dashboard): support m365 provider ( #7633 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-05-05 10:38:06 -04:00
dependabot[bot]
ae74cab70a
chore(deps): bump docker/build-push-action from 6.15.0 to 6.16.0 ( #7650 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-05-05 09:58:38 -04:00
Prowler Bot
e6d48c1fa4
chore(regions_update): Changes in regions for AWS services ( #7657 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-05-05 09:56:16 -04:00
dependabot[bot]
d5ab72a97c
chore(deps): bump github/codeql-action from 3.28.15 to 3.28.16 ( #7649 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-05-05 09:54:34 -04:00
dependabot[bot]
473631f83b
chore(deps): bump trufflesecurity/trufflehog from 3.88.23 to 3.88.26 ( #7648 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-05-05 09:54:16 -04:00
drewadwade
a580b1ee04
fix(azure): CIS v2.0 4.4.1 Uses Wrong Check ( #7656 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2025-05-05 15:53:55 +02:00
dependabot[bot]
844dd5ba95
chore(deps): bump actions/setup-python from 5.5.0 to 5.6.0 ( #7647 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-05-05 09:53:40 -04:00
sumit-tft
44f8e4c488
feat(ui): Page size for datatables ( #7634 )
2025-05-05 15:42:06 +02:00
Alejandro Bailo
180eb61fee
fix: error about page number persistence when filters change ( #7655 )
2025-05-05 12:23:04 +02:00
Andoni Alonso
9828824b73
chore(sentry): attach stacktrace to logging events ( #7598 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-05-05 10:38:57 +02:00
Daniel Barranquero
c938a25693
feat(exchange): add new check exchange_organization_modern_authentication_enabled ( #7636 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-02 12:44:39 +02:00
Daniel Barranquero
cccd69f27c
feat(exchange): add new check exchange_roles_assignment_policy_addins_disabled ( #7644 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-02 11:58:56 +02:00
Daniel Barranquero
3949806b5d
feat(exchange): add new check exchange_mailbox_properties_auditing_e3_enabled ( #7642 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-02 10:48:30 +02:00
Daniel Barranquero
e7d249784d
feat(exchange): add new check exchange_transport_config_smtp_auth_disabled ( #7640 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-02 09:05:53 +02:00
Daniel Barranquero
25b1efe532
feat(exchange): add new check exchange_organization_mailtips_enabled ( #7637 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-05-02 08:46:14 +02:00
Adrián Jesús Peña Rodríguez
c289ddacf2
feat: add m365 to API ( #7563 )
...
Co-authored-by: Andoni A <14891798+andoniaf@users.noreply.github.com >
2025-04-30 17:09:47 +02:00
Hugo Pereira Brito
3fd9c51086
feat(m365): automate PowerShell modules installation ( #7618 )
...
Co-authored-by: Andoni A <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-04-30 16:41:59 +02:00
Pedro Martín
de01087246
fix(s3): add ContentType in upload_file ( #7635 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-04-30 19:48:23 +05:45
Pablo Lara
fe42bb47f7
fix: set correct default value for session duration ( #7639 )
2025-04-30 13:00:45 +02:00
Víctor Fernández Poyatos
c56bd519bb
test(performance): Add base framework for API performance tests ( #7632 )
2025-04-30 12:36:25 +02:00
Daniel Barranquero
79b29d9437
feat(exchange): add new check exchange_mailbox_policy_additional_storage_restricted ( #7638 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-04-30 12:05:41 +02:00
Pedro Martín
82eecec277
feat(sharepoint): add new check related with OneDrive Sync ( #7589 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2025-04-30 11:43:41 +02:00
Pedro Martín
ceacd077d2
fix(typos): remove unneeded files ( #7627 )
2025-04-29 13:24:24 +05:45
Pepe Fagoaga
5a0fb13ece
fix(run-sh): Use poetry's env ( #7621 )
2025-04-29 13:01:12 +05:45
Erlend Ekern
78439b4c0c
chore(dockerfile): add image source as docker label ( #7617 )
2025-04-29 13:00:47 +05:45
Pedro Martín
06f94f884f
feat(compliance): add new Prowler Threat Score Compliance Framework ( #7603 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-28 09:57:52 +02:00
dependabot[bot]
b8836c6404
chore(deps): bump @babel/runtime from 7.24.7 to 7.27.0 in /ui ( #7502 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-28 08:49:33 +02:00
Andoni Alonso
ac79b86810
feat(teams): add new check teams_meeting_presenters_restricted ( #7613 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-25 14:34:05 -04:00
Andoni Alonso
793c2ae947
feat(teams): add new check teams_meeting_recording_disabled ( #7607 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-25 12:35:54 -04:00
Andoni Alonso
cdcc5c6e35
feat(teams): add new check teams_meeting_external_chat_disabled ( #7605 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-25 11:30:38 -04:00
Andoni Alonso
51db81aa5c
feat(teams): add new check teams_meeting_external_control_disabled ( #7604 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-25 10:59:36 -04:00
Hugo Pereira Brito
a51a185f49
fix(powershell): handle m365 provider execution and logging ( #7602 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-25 10:44:25 -04:00
Hugo Pereira Brito
90453fd07e
feat(teams): add new check teams_meeting_chat_anonymous_users_disabled ( #7579 )
...
Co-authored-by: Andoni A <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-25 09:29:24 -04:00
Pablo Lara
d740bf84c3
feat: add new M365 to the provider overview table ( #7615 )
2025-04-25 15:24:47 +02:00
Pedro Martín
d13d2677ea
fix(compliance): improve compliance and dashboard ( #7596 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-24 13:28:18 -04:00
dependabot[bot]
b076c98ba1
chore(deps): bump h11 from 0.14.0 to 0.16.0 ( #7609 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-24 13:19:11 -04:00
Hugo Pereira Brito
d071dea7f7
feat(teams): add new check teams_meeting_dial_in_lobby_bypass_disabled ( #7571 )
...
Co-authored-by: Andoni A <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-24 13:05:52 -04:00
Hugo Pereira Brito
d9782c7b8a
feat(teams): add new check teams_meeting_external_lobby_bypass_disabled ( #7568 )
...
Co-authored-by: Andoni A <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-24 12:13:42 -04:00
Pedro Martín
f85450d0b5
fix(html): remove first empty line ( #7606 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-24 11:23:24 -04:00
Pepe Fagoaga
b129326ed6
chore(actions): Bump Prowler version on release ( #7560 )
2025-04-24 10:25:36 -04:00
Hugo Pereira Brito
eaf0d06b63
chore(m365): add test_connection function ( #7541 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-24 10:20:58 -04:00
Pedro Martín
87f3e0a138
fix(nhn): remove unneeded parameter ( #7600 )
2025-04-24 13:21:52 +02:00
Daniel Barranquero
8e3c856a14
feat(exchange): add new check exchange_external_email_tagging_enabled ( #7580 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-23 14:11:39 -04:00
Daniel Barranquero
12c2439196
feat(exchange): add new check exchange_transport_rules_whitelist_disabled ( #7569 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-23 13:47:51 -04:00
Daniel Barranquero
deb1e0ff34
feat(defender): Add new check defender_antispam_policy_inbound_no_allowed_domains ( #7500 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-23 13:29:24 -04:00
Hugo Pereira Brito
808e8297b0
feat(teams): add new check teams_meeting_anonymous_user_start_disabled ( #7567 )
2025-04-23 10:31:17 -04:00
Hugo Pereira Brito
738ce56955
fix(docs): overview m365 auth ( #7588 )
2025-04-23 09:58:32 -04:00
Sergio Garcia
190fd0b93c
fix(scan): handle cloud provider errors and ignore expected sentry noise ( #7582 )
2025-04-23 09:58:04 -04:00
Pablo Lara
ca6df26918
chore: remove deprecated launch scan page from old 4-step workflow ( #7592 )
2025-04-23 15:13:05 +02:00
Pablo Lara
bcfeb97e4a
feat(m365): add the new provider m365 - UI part ( #7591 )
2025-04-23 14:23:33 +02:00
Hugo Pereira Brito
0234957907
feat(teams): add new check teams_meeting_anonymous_user_join_disabled ( #7565 )
...
Co-authored-by: Andoni A <14891798+andoniaf@users.noreply.github.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 16:02:16 -04:00
Hugo Pereira Brito
8713b74204
feat(teams): add new check teams_external_users_cannot_start_conversations ( #7562 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 14:36:54 -04:00
Hugo Pereira Brito
cbaddad358
feat(teams): add new check teams_unmanaged_communication_disabled ( #7561 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 13:25:30 -04:00
Hugo Pereira Brito
2379544425
feat(teams): add new check teams_external_domains_restricted ( #7557 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-22 13:04:51 -04:00
Hugo Pereira Brito
29fefba62e
fix(teams): teams_email_sending_to_channel_disabled docstrings ( #7559 )
2025-04-22 12:57:18 -04:00
Daniel Barranquero
098382117e
feat(defender): add new check defender_antispam_connection_filter_policy_safe_list_off ( #7494 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 12:52:34 -04:00
Daniel Barranquero
d816d73174
feat(defender): add new check defender_antispam_connection_filter_policy_empty_ip_allowlist ( #7492 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 12:28:18 -04:00
Matt Keeler
30eb78c293
fix(aws): use correct ports in ec2_instance_port_cifs_exposed_to_internet recommendation ( #7574 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 12:24:12 -04:00
Daniel Barranquero
a671b092ee
feat(defender): add new check defender_domain_dkim_enabled ( #7485 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 11:15:33 -04:00
Pepe Fagoaga
0edf199282
fix(actions): Include files within providers for SDK tests ( #7577 )
2025-04-22 10:28:43 -04:00
Andoni Alonso
2478555f0e
fix(aws): update bucket naming validation to accept dots ( #7545 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 10:06:14 -04:00
Daniel Barranquero
b07080245d
feat(defender): add new check defender_antispam_outbound_policy_configured ( #7480 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-22 09:58:07 -04:00
Pepe Fagoaga
2ebf217bb0
fix(k8s): Remove command as it is not needed ( #7570 )
2025-04-22 09:33:40 -04:00
Prowler Bot
bb527024d9
chore(regions_update): Changes in regions for AWS services ( #7550 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-22 09:32:22 -04:00
Sergio Garcia
e897978c3e
fix(azure): handle new FlowLog properties ( #7546 )
2025-04-22 09:21:17 -04:00
Pepe Fagoaga
00f1c02532
chore(tests): Split by provider in the SDK ( #7564 )
2025-04-22 16:46:15 +05:45
César Arroba
348d1a2fda
chore: pass labels on PR merge trigger ( #7558 )
2025-04-21 16:43:40 +02:00
César Arroba
f1df8ba458
chore: revert pass labels ( #7556 )
2025-04-21 12:46:42 +02:00
César Arroba
b5ea418933
chore: pass labels as json is required ( #7555 )
2025-04-21 12:10:18 +02:00
César Arroba
734fa5a4e6
chore: fix merged PR action, incorrect order on payload ( #7554 )
2025-04-21 12:03:14 +02:00
César Arroba
08f6d4b69b
chore: pass labels ( #7553 )
2025-04-21 11:57:50 +02:00
César Arroba
29d3bb9f9a
chore: fix json body ( #7552 )
2025-04-21 15:01:03 +05:45
César Arroba
4d217e642b
chore: fix trigger ( #7551 )
2025-04-21 14:56:17 +05:45
César Arroba
bd56e03991
chore(gha): trigger cloud pull-request when a PR is merged ( #7212 )
2025-04-21 14:54:22 +05:45
Felix Dreissig
0b6aa0ddcd
fix(aws): remove SHA-1 from ACM insecure key algorithms ( #7547 )
2025-04-18 16:25:44 -04:00
Daniel Barranquero
4f3496194d
feat(defender): add new check defender_antiphishing_policy_configured ( #7453 )
2025-04-18 12:42:19 -04:00
Daniel Barranquero
d09a680aaa
feat(defender): add new check defender_malware_policy_notifications_internal_users_malware_enabled ( #7435 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-18 11:08:05 -04:00
Daniel Barranquero
56d7431d56
feat(defender): add service and new check defender_malware_policy_common_attachments_filter_enabled ( #7425 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-17 13:33:43 -04:00
Daniel Barranquero
abae5f1626
feat(exchange): add new check exchange_mailbox_audit_bypass_disabled ( #7418 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-16 14:06:32 -04:00
Daniel Barranquero
7d0e94eecb
feat(exchange): add service and new check exchange_organization_mailbox_auditing_enabled ( #7408 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-16 12:19:06 -04:00
Hugo Pereira Brito
23b65c7728
feat(teams): add new check teams_email_sending_to_channel_disabled ( #7533 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-16 11:13:55 -04:00
Sergio Garcia
aa3182ebc5
feat(gcp): support CLOUDSDK_AUTH_ACCESS_TOKEN ( #7495 )
2025-04-16 10:35:04 -04:00
Sergio Garcia
32d27df0ba
chore(regions): change interval to weekly ( #7539 )
2025-04-16 09:35:30 -04:00
Prowler Bot
6439f0a5f3
chore(regions_update): Changes in regions for AWS services ( #7538 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-16 09:25:29 -04:00
Sergio Garcia
19476632ff
chore(dependabot): change settings ( #7536 )
2025-04-16 11:26:57 +05:45
Pedro Martín
d4c12e4632
fix(iam): change some logger.info values ( #7526 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-04-15 13:25:37 -04:00
Hugo Pereira Brito
52bd48168f
feat: adapt Microsoft365 provider to use PowerShell ( #7331 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-15 13:24:09 -04:00
Bogdan A
c0d935e232
docs(gcp): update required permissions for GCP ( #7488 )
2025-04-15 10:23:45 -04:00
Pepe Fagoaga
24dfd47329
fix(pypi): package name location in pyproject.toml while replicating for prowler-cloud ( #7531 )
2025-04-15 20:01:27 +05:45
dependabot[bot]
fbae338689
chore(deps): bump python from 3.12.9-alpine3.20 to 3.12.10-alpine3.20 ( #7520 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-15 09:26:04 -04:00
dependabot[bot]
186fd88f8c
chore(deps): bump codecov/codecov-action from 5.4.0 to 5.4.2 ( #7522 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-15 09:25:44 -04:00
dependabot[bot]
14ff34c00a
chore(deps): bump actions/setup-node from 4.3.0 to 4.4.0 ( #7521 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-15 09:25:23 -04:00
Prowler Bot
a66fa394d3
chore(regions_update): Changes in regions for AWS services ( #7527 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-15 09:20:20 -04:00
Pepe Fagoaga
931766fe08
chore(action): Remove cache in PyPI release ( #7532 )
2025-04-15 18:58:26 +05:45
Pepe Fagoaga
c134914896
revert: fix(findings): increase uid max length to 600 ( #7528 )
2025-04-15 15:54:32 +05:45
Pepe Fagoaga
25dac080a5
chore(changelog): prepare for 5.5.1 ( #7523 )
2025-04-15 11:46:20 +05:45
Sergio Garcia
910d39eee4
chore(sdk): update changelog ( #7512 )
2025-04-15 11:19:50 +05:45
Pepe Fagoaga
d604ae5569
fix(pyproject): Restore packages location ( #7510 )
2025-04-14 16:50:50 -04:00
Bogdan A
42f46b0fb1
feat(gcp): add check for unused Service Accounts ( #7419 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-14 11:53:54 -04:00
Pepe Fagoaga
abb5864224
chore(release): bump for 5.6.0 ( #7503 )
2025-04-14 11:50:46 -04:00
Prowler Bot
2e2a2bd89a
chore(regions_update): Changes in regions for AWS services ( #7491 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-14 10:29:19 -04:00
Sergio Garcia
f8ee841921
fix(gcp): handle projects without ID ( #7496 )
2025-04-14 10:25:54 -04:00
Pedro Martín
ceda8c76d2
feat(azure): add SOC2 compliance framework ( #7489 )
2025-04-14 10:16:20 -04:00
Pedro Martín
afe0b7443f
fix(defender): add default name to contacts ( #7483 )
2025-04-14 10:16:07 -04:00
Prowler Bot
9b773897d2
chore(regions_update): Changes in regions for AWS services ( #7487 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-14 09:53:40 -04:00
Pedro Martín
d6ec4c2c96
feat(sdk): add changelog file ( #7499 )
2025-04-14 09:22:50 -04:00
Prowler Bot
14ef169e99
chore(regions_update): Changes in regions for AWS services ( #7497 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-14 09:22:21 -04:00
Pepe Fagoaga
22141f9706
fix(findings): increase uid max length to 600 ( #7498 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-04-14 17:46:13 +05:45
Pablo Lara
a5c6fee5b4
fix: update redirect URL for SSO ( #7493 )
2025-04-11 18:25:28 +05:45
Pablo Lara
d3a5a5c0a1
fix: resolve social login issue in AuthForm on sign-up page ( #7490 )
2025-04-11 09:59:10 +02:00
dependabot[bot]
5d81869de4
chore(deps): bump tj-actions/changed-files from 46.0.4 to 46.0.5 ( #7486 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-09 22:31:33 -04:00
Pepe Fagoaga
73ebf95d89
chore(changelog): Prepare for v5.5.0 ( #7484 )
2025-04-09 20:50:56 +05:45
Sergio Garcia
9f4574f4ff
fix: handle errors in AWS and Azure ( #7482 )
2025-04-09 20:19:38 +05:45
Pedro Martín
cb239b20ab
fix(aws): add default session_duration ( #7479 )
2025-04-09 19:19:17 +05:45
eeche
3ef79588b4
feat(NHN): add NHN cloud provider with 6 checks ( #6870 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-04-09 09:13:24 -04:00
Prowler Bot
61000e386b
chore(regions_update): Changes in regions for AWS services ( #7478 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-09 09:11:29 -04:00
Pablo Lara
53cb57901f
fix: fix TS type for session duration ( #7481 )
2025-04-09 13:44:53 +02:00
Pedro Martín
993ff4d78e
feat(gcp): add SOC2 compliance framework ( #7476 )
2025-04-08 15:04:08 -04:00
Drew Kerrigan
8fb10fbbf7
fix(ui): Remove UTC from timestamps in app ( #7474 )
2025-04-08 17:43:44 +02:00
Pablo Lara
11e834f639
feat: update the NextJS version to the latest ( #7473 )
2025-04-08 17:40:39 +02:00
Prowler Bot
62bf2fbb9c
chore(regions_update): Changes in regions for AWS services ( #7467 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-08 10:21:42 -04:00
dependabot[bot]
e57930d6c2
chore(deps): bump github/codeql-action from 3.28.13 to 3.28.15 ( #7463 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-08 09:38:18 -04:00
Pepe Fagoaga
e0c417a466
fix(action): Use poetry > v2 ( #7472 )
2025-04-08 18:34:24 +05:45
Sergio Garcia
b55f8efed1
fix: handle errors in AWS, Azure, and GCP ( #7456 )
2025-04-08 18:05:43 +05:45
Pablo Lara
7cbc60d977
feat: add link with the service status using static icon ( #7468 )
2025-04-08 12:06:21 +02:00
Adrián Jesús Peña Rodríguez
5b7912b558
fix(provider): disable periodic task on views before deleting ( #7466 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-04-08 15:35:22 +05:45
Pedro Martín
57fca3e54d
fix(soc2_aws): update compliance and remove some requirements ( #7452 )
2025-04-07 15:47:19 -04:00
Pedro Martín
e31c27b123
fix(gcp): handle logic for empty project names ( #7436 )
2025-04-07 11:51:15 -04:00
Sergio Garcia
74f1da818e
fix(gcp): ignore redirect balancers and add regional ones ( #7442 )
2025-04-07 11:47:02 -04:00
Pedro Martín
910cfa601b
fix(aws): add resource arn for transit gateways ( #7447 )
2025-04-07 11:46:53 -04:00
dependabot[bot]
fe321c3f8a
chore(deps): bump tj-actions/changed-files from 46.0.3 to 46.0.4 ( #7443 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-07 09:11:54 -04:00
Prowler Bot
43de0d405f
chore(regions_update): Changes in regions for AWS services ( #7446 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-07 09:11:23 -04:00
dependabot[bot]
ac6ed31c8e
chore(deps): bump trufflesecurity/trufflehog from 3.88.22 to 3.88.23 ( #7444 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-07 09:11:07 -04:00
Prowler Bot
9d47437de4
chore(regions_update): Changes in regions for AWS services ( #7445 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-07 09:10:49 -04:00
Pablo Lara
eb7a62ff77
refactor: extract common auth headers into reusable helper ( #7439 )
2025-04-07 08:16:55 +02:00
Pedro Martín
67bc16b46d
fix(defender): add default resource name in contacts ( #7438 )
2025-04-04 09:35:11 -04:00
Sergio Garcia
8552a578a0
fix(aws): solve multiple errors ( #7431 )
2025-04-04 09:34:58 -04:00
Sergio Garcia
a5d277e045
fix(docs): solve broken links ( #7432 )
2025-04-04 09:15:48 -04:00
Adrián Jesús Peña Rodríguez
6dbf2ac606
feat: add missing SDK fields to API findings and resources ( #7318 )
2025-04-04 14:57:49 +02:00
Prowler Bot
b1569ac2f3
chore(regions_update): Changes in regions for AWS services ( #7434 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-04 08:36:23 -04:00
dependabot[bot]
3d0145b522
chore(deps): bump trufflesecurity/trufflehog from 3.88.20 to 3.88.22 ( #7433 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-04-04 08:34:51 -04:00
Pedro Martín
44174526d6
docs: add onboarding information step by step for each provider ( #7362 )
2025-04-04 13:00:43 +02:00
Pablo Lara
0fd395ea83
fix: correct fetch variable name from invitations to roles ( #7437 )
2025-04-04 12:08:57 +02:00
dependabot[bot]
5e9d4a80a1
chore(deps): bump msgraph-sdk from 1.18.0 to 1.23.0 ( #7128 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-04-04 11:27:39 +02:00
Pedro Martín
e4d234fe03
fix(azure): remove resource_name inside the Check_Report ( #7420 )
2025-04-03 11:35:02 -04:00
Prowler Bot
3202184718
chore(regions_update): Changes in regions for AWS services ( #7424 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-03 09:39:00 -04:00
Sergio Garcia
41e576f4f1
fix(gcp): make logging sink check at project level ( #7421 )
2025-04-03 09:37:46 -04:00
Pepe Fagoaga
d8dce07019
chore(deletion): Add environment variable for batch size ( #7423 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-04-03 15:31:13 +05:45
Prowler Bot
2b0a3144c7
chore(regions_update): Changes in regions for AWS services ( #7417 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-04-02 09:59:08 -04:00
dependabot[bot]
62fbce0b5e
chore(deps): bump azure-identity from 1.19.0 to 1.21.0 ( #7192 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-04-02 11:16:47 +02:00
Pedro Martín
5a59bb335c
fix(resources): add the correct id and names for resources ( #7410 )
2025-04-01 20:30:37 +02:00
Sergio Garcia
2719991630
fix(report): log as error when Resource ID or Name do not exist ( #7411 )
2025-04-01 20:24:18 +02:00
Daniel Barranquero
6a3b8c4674
feat(entra): add new check entra_admin_users_cloud_only ( #7286 )
2025-04-01 19:14:15 +02:00
dependabot[bot]
191fbf0177
chore(deps): bump azure-mgmt-applicationinsights from 4.0.0 to 4.1.0 ( #7161 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-04-01 14:55:37 +02:00
Víctor Fernández Poyatos
228dd2952a
fix(scans): Handle duplicated scan tasks ( #7401 )
2025-04-01 11:55:14 +02:00
dependabot[bot]
97db38aa25
chore(deps): bump azure-mgmt-containerregistry from 10.3.0 to 12.0.0 ( #7025 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-04-01 10:29:31 +02:00
Pedro Martín
dc953a6e22
docs(python): add annotations about Python version ( #7402 )
2025-03-31 18:14:59 +02:00
Bogdan A
51e796a48d
feat(gcp): add check for dormant (unused) SA keys ( #7348 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2025-03-31 18:14:21 +02:00
Hugo Pereira Brito
024f1425df
feat(entra): add new check entra_legacy_authentication_blocked ( #7240 )
2025-03-31 18:12:26 +02:00
Hugo Pereira Brito
a7ed610da9
feat(entra): add new check entra_users_mfa_enabled ( #7228 )
2025-03-31 17:54:52 +02:00
Hugo Pereira Brito
7ba99f22cd
feat(entra): add new check entra_admin_users_phishing_resistant_mfa_enabled ( #7211 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-03-31 17:52:28 +02:00
Hugo Pereira Brito
b8ce09ec34
fix(entra): check name and logic of entra_admin_users_have_mfa_enabled ( #7230 )
2025-03-31 17:50:51 +02:00
Daniel Barranquero
c243110a49
feat(entra): add new check entra_policy_guest_invite_only_for_admin_roles ( #7241 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-03-31 14:53:50 +02:00
Daniel Barranquero
ee27636f32
fix(redshift): validation error for Cluster.multi_az ( #7381 )
2025-03-31 13:55:48 +02:00
dependabot[bot]
f2f41c9c44
chore(deps): bump azure-mgmt-resource from 23.2.0 to 23.3.0 ( #7054 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-03-31 13:29:49 +02:00
Daniel Barranquero
9312890e6a
feat(entra): add new check entra_policy_guest_users_access_restrictions ( #7234 )
2025-03-31 12:45:26 +02:00
Daniel Barranquero
9578281b4f
feat(entra): add new check entra_policy_restricts_user_consent_for_apps ( #7225 )
2025-03-31 12:32:51 +02:00
Víctor Fernández Poyatos
08690068fc
feat(findings): Handle muted findings in API and UI ( #7378 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-03-31 12:25:58 +02:00
Hugo Pereira Brito
e06a33de84
feat(entra): add new check entra_managed_device_required_for_mfa_registration ( #7203 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-31 12:24:47 +02:00
Prowler Bot
6a3db10fda
chore(regions_update): Changes in regions for AWS services ( #7395 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-03-31 10:18:53 +02:00
Andoni Alonso
bbed445efa
chore(sentry): ignore exception when aws service not available in a region ( #7352 )
2025-03-31 10:13:19 +02:00
dependabot[bot]
9d65fb0bf2
chore(deps): bump trufflesecurity/trufflehog from 3.88.18 to 3.88.20 ( #7394 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-31 10:12:55 +02:00
Prowler Bot
34f03ca110
chore(regions_update): Changes in regions for AWS services ( #7391 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-03-27 11:10:07 +01:00
Daniel Barranquero
87c038f0c2
fix(rds): hundle Certificate rds-ca-2019 not found ( #7383 )
2025-03-27 11:09:33 +01:00
dependabot[bot]
b3014f03b1
chore(deps): bump actions/setup-python from 5.4.0 to 5.5.0 ( #7390 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-27 09:13:50 +01:00
Daniel Barranquero
d39598c9fc
fix(stepfunctions): Nonetype object has no attribute level ( #7386 )
2025-03-26 19:39:27 +01:00
Daniel Barranquero
5ea9106259
fix(fms): resource metadata could not be converted to dict ( #7379 )
2025-03-26 19:25:00 +01:00
Prowler Bot
bcc0b59de1
chore(regions_update): Changes in regions for AWS services ( #7382 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-03-26 12:52:35 +01:00
Daniel Barranquero
5d6ed640f0
fix(vm): handle Nonetype is not iterable for extensions ( #7360 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-03-25 12:25:15 +01:00
Sergio Garcia
dd1cc2d025
fix(s3): handle None S3 account public access block ( #7350 )
2025-03-25 11:39:19 +01:00
Andoni Alonso
52e5cc23e4
fix(storagegateway): describe smb/nfs share per region ( #7374 )
2025-03-25 10:35:37 +01:00
Pablo Lara
76a8e2be1f
chore: tweak for button see findings ( #7369 )
2025-03-25 09:52:36 +01:00
Andoni Alonso
d989425490
fix(vm): handle NoneType accessing security_profile ( #7221 )
2025-03-25 09:33:00 +01:00
Hugo Pereira Brito
1e324b7ed2
fix(network): handle Nonetype is not iterable for security groups ( #7208 )
2025-03-25 09:28:37 +01:00
Sergio Garcia
e68aa62f94
fix(iam): handle none SAML Providers ( #7359 )
2025-03-25 09:24:32 +01:00
Daniel Barranquero
332b98a1ab
fix(iam): handle UnboundLocalError cannot access local variable 'report' ( #7361 )
2025-03-25 09:22:35 +01:00
Pablo Lara
dd05ef7974
chore(scans): properly enable link to findings when scan is completed ( #7368 )
2025-03-25 08:45:37 +01:00
dependabot[bot]
d6862766d3
chore(deps): bump github/codeql-action from 3.28.12 to 3.28.13 ( #7367 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-25 12:43:02 +05:45
dependabot[bot]
f52d005e2d
chore(deps): bump tj-actions/changed-files from 46.0.1 to 46.0.3 ( #7363 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-25 12:42:50 +05:45
Víctor Fernández Poyatos
bf475234a5
build(api): Force django-allauth==65.4.1 ( #7358 )
2025-03-24 17:39:47 +01:00
Pablo Lara
cd5985c056
docs: update readme ( #7357 )
2025-03-24 15:41:35 +01:00
Pablo Lara
ce33dbf823
chore(findings): apply default filter to show failed findings ( #7356 )
2025-03-24 15:38:09 +01:00
Pablo Lara
0a9d0688a7
docs(changelog): document addition of download column in scans table … ( #7354 )
2025-03-24 15:28:13 +01:00
Pablo Lara
24784f2ce5
feat(scans): add download button column for completed scans in table ( #7353 )
2025-03-24 15:22:36 +01:00
Víctor Fernández Poyatos
7a1e611b88
ref(providers): Refactor provider deletion functions ( #7349 )
2025-03-24 14:39:14 +01:00
Pepe Fagoaga
3073150008
chore(next): Remove x-powered-by header ( #7346 )
2025-03-24 16:17:18 +05:45
Jonny
9923def4cb
chore(awslambda): update obsolete lambda runtimes ( #7330 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-24 11:21:01 +01:00
Víctor Fernández Poyatos
a7f612303f
feat(compliance): Add endpoint to retrieve compliance overviews metadata ( #7333 )
2025-03-24 10:34:43 +01:00
Pablo Lara
64c2a2217a
docs: update changelog with Next.js security patch ( #7339 ) ( #7341 )
2025-03-24 09:59:59 +01:00
Pablo Lara
4689d7a952
chore: upgrade Next.js to 14.2.25 to fix auth middleware vulnerability ( #7339 )
2025-03-24 09:48:41 +01:00
Prowler Bot
87cd143967
chore(regions_update): Changes in regions for AWS services ( #7219 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-24 09:46:57 +01:00
Prowler Bot
e37fd05d58
chore(regions_update): Changes in regions for AWS services ( #7246 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-24 09:46:26 +01:00
Prowler Bot
acc708bda5
chore(regions_update): Changes in regions for AWS services ( #7250 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-24 09:46:08 +01:00
Prowler Bot
c7460bb69c
chore(regions_update): Changes in regions for AWS services ( #7334 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-03-24 09:35:47 +01:00
Pepe Fagoaga
84b273dab9
fix(action): Use Poetry v2 ( #7329 )
2025-03-20 18:49:32 +01:00
Prowler Bot
bb7ce2157e
chore(regions_update): Changes in regions for AWS services ( #7323 )
...
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com >
2025-03-20 18:10:28 +05:45
Pepe Fagoaga
07b9e1d3a4
chore(api): Update CHANGELOG ( #7325 )
2025-03-20 15:22:00 +05:45
Pepe Fagoaga
96a879d761
fix(scan_id): Read the ID from the Scan object ( #7324 )
2025-03-20 15:18:31 +05:45
Pepe Fagoaga
283127c3f4
chore(aws-regions): remove backport to v3 ( #7319 )
2025-03-19 22:14:41 +05:45
dependabot[bot]
beeee80a0b
chore(deps): bump github/codeql-action from 3.28.11 to 3.28.12 ( #7321 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-19 22:14:23 +05:45
Pepe Fagoaga
06b62826b4
chore(dependabot): disable for v3 ( #7316 )
2025-03-19 21:56:52 +05:45
Pedro Martín
d0736af209
fix(gcp): make provider id mandatory in test_connection ( #7296 )
2025-03-19 18:33:49 +05:45
Pablo Lara
716c8c1a5f
docs: add social login images and update documentation ( #7314 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-03-19 17:16:37 +05:45
Pepe Fagoaga
e6cdda1bd9
chore(dependabot): Disable for API and UI ( #7300 )
2025-03-19 14:46:11 +05:45
Pedro Martín
2747a633bc
fix(k8s): remove typos from PCI 4.0 ( #7294 )
2025-03-19 09:31:40 +01:00
Pepe Fagoaga
74118f5cfe
chore(social-login): improve copy when not enabled ( #7295 )
2025-03-19 13:36:22 +05:45
dependabot[bot]
598bdf28bb
chore(deps): bump trufflesecurity/trufflehog from 3.88.17 to 3.88.18 ( #7297 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-19 12:31:52 +05:45
Pepe Fagoaga
d75f681c87
chore(security): Configure HTTP Security Headers ( #7220 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-03-18 17:49:12 +01:00
Pepe Fagoaga
c7956ede6a
chore(security): Add HTTP Security Headers ( #7289 )
2025-03-18 17:44:57 +01:00
Pablo Lara
64f5a69e84
fix: prevent SSR mismatch in OAuth URL generation ( #7288 )
2025-03-18 17:22:29 +01:00
dependabot[bot]
bfb15c34b8
chore(deps): bump azure-mgmt-containerservice from 34.0.0 to 34.1.0 ( #6989 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-03-18 17:14:25 +01:00
Pablo Lara
638b3ac0cd
chore(providers): change wording when adding a new provider ( #7280 )
2025-03-18 21:50:56 +05:45
Daniel Barranquero
9d6147a037
fix(route53): solve false positive in route53_public_hosted_zones_cloudwatch_logging_enabled ( #7201 )
2025-03-18 16:54:49 +01:00
Pepe Fagoaga
802c786ac2
fix(test-connection): Handle provider without secret ( #7283 )
2025-03-18 21:34:36 +05:45
Pepe Fagoaga
c8be8dbd9a
fix(aws-regions): Use @prowler-bot as author ( #7285 )
2025-03-18 20:27:19 +05:45
Pablo Lara
7053b2bb37
chore: add env vars for social login ( #7257 )
...
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com >
2025-03-18 13:43:46 +01:00
Prowler Bot
447bf832cd
chore(regions_update): Changes in regions for AWS services ( #7281 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-18 17:35:44 +05:45
Pablo Lara
7c4571b55e
feat(providers): add component to render a link to the documentation ( #7282 )
2025-03-18 12:05:38 +01:00
dependabot[bot]
eb7c16aba5
chore(deps): bump azure-mgmt-storage from 21.2.1 to 22.1.1 ( #7098 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-03-18 11:06:46 +01:00
Adrián Jesús Peña Rodríguez
b09e83b171
chore: add api reference to download report section ( #7243 )
2025-03-18 14:54:13 +05:45
Hugo Pereira Brito
bb149a30a7
fix(microsoft365): typo Microsoft365NotTenantIdButClientIdAndClienSecretError ( #7244 )
2025-03-17 21:16:47 +05:45
Pablo Lara
d5be35af49
chore: Rename keyServer and extract to helper ( #7256 )
2025-03-17 21:11:27 +05:45
Pedro Martín
f6aa56d92b
fix(.env): remove spaces ( #7255 )
2025-03-17 20:48:55 +05:45
Pedro Martín
6a4df15c47
fix(prowler): change from prowler.py to prowler-cli.py ( #7253 )
2025-03-17 15:44:15 +01:00
Pablo Lara
72de5fdb1b
chore: update git ignore file ( #7254 )
2025-03-17 14:53:58 +01:00
Pedro Martín
a7f55d06af
feat(jira): add basic auth method ( #7233 )
2025-03-17 14:31:35 +01:00
Pepe Fagoaga
97da78d4e7
fix(backport): Use container tagged version ( #7252 )
2025-03-17 18:19:43 +05:45
Pepe Fagoaga
c4f6161c73
chore(security): Pin actions to the Full-Length Commit SHA ( #7249 )
2025-03-17 17:11:28 +05:45
Pablo Lara
db7ffea24d
chore: add env var for social login ( #7251 )
2025-03-17 10:23:01 +01:00
Prowler Bot
489b5abf82
chore(regions_update): Changes in regions for AWS services ( #7237 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-17 13:47:56 +05:45
Prowler Bot
3a55c2ee07
chore(regions_update): Changes in regions for AWS services ( #7245 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-17 12:34:44 +05:45
Pedro Martín
64d866271c
fix(scan): add compliance info inside finding ( #5649 )
2025-03-17 12:18:00 +05:45
Pablo Lara
1ab2a80eab
chore: improve UX when social login is not enabled ( #7242 )
2025-03-15 12:12:30 +01:00
Pablo Lara
89d4c521ba
chore(social-login): disable social login buttons when env vars are not set ( #7238 )
2025-03-14 11:32:22 +01:00
Pablo Lara
f2e19d377a
chore(social-login): rename env.vars for social login ( #7232 )
2025-03-13 17:07:17 +01:00
Pablo Lara
2b7b887b87
chore: social auth is algo in sign-up page ( #7231 )
2025-03-13 14:20:09 +01:00
Pablo Lara
44c70b5d01
chore: remove unused regions ( #7229 )
2025-03-13 13:57:16 +01:00
Pablo Lara
7514484c42
chore: change wording for launching a single scan ( #7226 )
2025-03-13 13:48:01 +01:00
Adrián Jesús Peña Rodríguez
9594c4c99f
fix: add a handled response in case local files are missing ( #7183 )
2025-03-13 13:47:00 +01:00
Pablo Lara
56445c9753
chore: update changelog ( #7223 )
2025-03-13 13:39:26 +01:00
Adrián Jesús Peña Rodríguez
07419fd5e1
fix(exports): change the way to remove the local export files after s3 upload ( #7172 )
2025-03-13 13:37:17 +01:00
Pablo Lara
2e4dd12b41
feat(social-login): social login with Google is working ( #7218 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-03-13 12:52:30 +01:00
Víctor Fernández Poyatos
fed2046c49
fix(migrations): add through parameter to integration.providers ( #7222 )
2025-03-13 12:47:34 +01:00
Pepe Fagoaga
db79db4786
fix(pyproject): Rename prowler.py ( #7217 )
2025-03-13 16:53:38 +05:45
Víctor Fernández Poyatos
6f027e3c57
feat(integrations): Added new endpoints to allow configuring integrations ( #7167 )
2025-03-12 19:57:55 +05:45
Daniel Barranquero
bdb877009f
feat(entra): add new check entra_admin_mfa_enabled_for_administrative_roles ( #7181 )
...
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-12 14:47:29 +01:00
Sergio Garcia
6564ec1ff5
fix(cloudwatch): handle None metric alarms ( #7205 )
2025-03-12 14:44:36 +01:00
Pedro Martín
443dc067b3
feat(kubernetes): add ISO 27001 2022 compliance framework ( #7204 )
2025-03-12 14:24:53 +01:00
Hugo Pereira Brito
6221650c5f
feat(entra): add new check entra_identity_protection_sign_in_risk_enabled ( #7171 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-12 13:53:47 +01:00
Andoni Alonso
034d0fd1f4
refactor(check): add docstrings and improve report handling ( #7113 )
2025-03-12 13:38:42 +01:00
Hugo Pereira Brito
e617ff0460
feat(docs): add microsoft365 configurable checks ( #7200 )
2025-03-12 12:52:35 +01:00
Hugo Pereira Brito
4b1ed607a7
feat(entra): add new check entra_identity_protection_user_risk_enabled ( #7126 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-12 12:44:31 +01:00
Pepe Fagoaga
137365a670
chore(poetry): Upgrade to v2 ( #7112 )
2025-03-12 17:28:34 +05:45
Hugo Pereira Brito
1891a1b24f
feat(entra): add new check entra_managed_device_required_for_authentication ( #7115 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-12 11:34:14 +01:00
Daniel Barranquero
e57e070866
feat(entra): add new check entra_password_hash_sync_enabled ( #7061 )
2025-03-12 11:31:49 +01:00
dependabot[bot]
66998cd1ad
chore(deps): bump google-api-python-client from 2.162.0 to 2.163.0 ( #7191 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-12 11:25:24 +01:00
Prowler Bot
c0b1833446
chore(regions_update): Changes in regions for AWS services ( #7197 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-12 11:25:06 +01:00
Pablo Lara
329a72c77c
chore: update changelog ( #7199 )
2025-03-12 10:12:33 +01:00
Pablo Lara
2610ee9d0c
feat(invitations): Disable editing for accepted invites ( #7198 )
2025-03-12 10:06:46 +01:00
Pablo Lara
a13ca9034e
chore(scans): rename type to trigger ( #7196 )
2025-03-12 09:47:02 +01:00
Pablo Lara
5d1abb3689
chore: auto refresh if the state is also available ( #7195 )
2025-03-12 09:33:24 +01:00
Pablo Lara
e1d1c6d154
styles: tweaks styles ( #7194 )
2025-03-12 09:23:02 +01:00
Pablo Lara
e18e0e7cd4
chore(launch-scan): update wording ( #7193 )
2025-03-12 08:20:15 +01:00
Pablo Lara
eaf3d07a3f
chore: update the changelog ( #7190 )
2025-03-12 08:15:28 +01:00
Hugo Pereira Brito
c88ae32b7f
feat(microsoft365): add new check entra_admin_users_sign_in_frequency_enabled ( #7020 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-03-11 19:18:33 +01:00
Pablo Lara
605613e220
feat(scans): allow running a scan once ( #7188 )
2025-03-11 17:47:47 +01:00
Sergio Garcia
d2772000ec
chore(sentry): ignore new exceptions in Sentry ( #7187 )
2025-03-11 17:46:14 +01:00
Adrián Jesús Peña Rodríguez
42939a79f5
docs: add users, invitations and RBAC ( #7109 )
2025-03-11 21:59:04 +05:45
Daniel Barranquero
ed17931117
feat(entra): add new check entra_dynamic_group_for_guests_created ( #7168 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-03-11 16:21:17 +01:00
Daniel Barranquero
66df5f7a1c
chore(providers): enhance Remediation.Code.CLI field from check's metadata ( #7094 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com >
2025-03-11 16:15:58 +01:00
Pedro Martín
fc6e6696e5
feat(gcp): add ISO 27001 2022 compliance framework ( #7185 )
2025-03-11 15:16:40 +01:00
Sergio Garcia
465748c8a1
chore(sentry): ignore expected errors in GCP API ( #7184 )
2025-03-11 14:32:37 +01:00
Pedro Martín
e59cd71bbf
fix(azure): add remaining checks for reqA.5.25 ( #7182 )
2025-03-11 14:16:10 +01:00
Daniel Barranquero
8a76fea310
feat(entra): add new check entra_admin_consent_workflow_enabled ( #7110 )
2025-03-11 13:18:17 +01:00
Adrián Jesús Peña Rodríguez
0e46be54ec
docs: add generate_output documentation ( #7122 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-03-11 17:23:32 +05:45
Pedro Martín
dc81813fdf
fix(ens): remove and change duplicated ids ( #7165 )
2025-03-11 11:35:31 +01:00
Hugo Pereira Brito
eaa0df16bb
refactor(microsoft365): resource metadata assertions ( #7169 )
2025-03-11 11:30:37 +01:00
Pedro Martín
c23e911028
feat(azure): add ISO 27001 2022 compliance framework ( #7170 )
2025-03-11 11:29:40 +01:00
dependabot[bot]
06b96a1007
chore(deps): bump tzlocal from 5.3 to 5.3.1 ( #7162 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-11 11:17:50 +01:00
Prowler Bot
fa545c591f
chore(regions_update): Changes in regions for AWS services ( #7177 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-11 11:17:27 +01:00
dependabot[bot]
e828b780c7
chore(deps): bump trufflesecurity/trufflehog from 3.88.15 to 3.88.16 ( #7174 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-11 11:16:57 +01:00
Harshit Raj Singh
eca8c5cabd
feat(aws): AWS Found Sec Best Practices & PCI DSS v3.2.1 upgrade ( #7017 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2025-03-11 09:31:16 +01:00
Pablo Lara
b7bce6008f
fix: tweak z-index for custom inputs ( #7166 )
2025-03-10 11:55:04 +01:00
Pablo Lara
2fdf89883d
feat(scans): improve scan launch provider selection ( #7164 )
2025-03-10 10:05:33 +01:00
dependabot[bot]
6c5d4bbaaa
chore(deps): bump django from 5.1.5 to 5.1.7 in /api ( #7145 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-10 09:50:09 +01:00
Gary Mclean
cb2f926d4f
fix(azure): correct check title for SQL Server Unrestricted ( #7123 )
2025-03-07 18:24:24 +01:00
ryan-stavella
12c01b437e
fix(metadata): typo in ec2_securitygroup_allow_wide_open_public_ipv4 ( #7116 )
2025-03-07 15:28:08 +01:00
dependabot[bot]
3253a58942
chore(deps-dev): bump mock from 5.1.0 to 5.2.0 ( #7099 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-07 15:01:43 +01:00
Kay Agahd
199f7f14ea
fix(doc): event_time has been changed to time_dt but was not documented ( #7136 )
2025-03-07 14:36:51 +01:00
Andoni Alonso
d42406d765
fix(metadata): match type with check results ( #7111 )
2025-03-07 14:34:07 +01:00
Kay Agahd
2276ffb1f6
fix(aws): ecs_task_definitions_no_environment_secrets.metadata.json ( #7135 )
2025-03-07 14:31:03 +01:00
dependabot[bot]
218fb3afb0
chore(deps): bump jinja2 from 3.1.5 to 3.1.6 ( #7151 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-07 14:27:29 +01:00
Prowler Bot
a9fb890979
chore(regions_update): Changes in regions for AWS services ( #7108 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-07 14:06:28 +01:00
Prowler Bot
54ebf5b455
chore(regions_update): Changes in regions for AWS services ( #7119 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-07 14:04:48 +01:00
dependabot[bot]
c9a0475aa8
chore(deps-dev): bump mkdocs-git-revision-date-localized-plugin from 1.3.0 to 1.4.1 ( #7129 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-07 14:03:44 +01:00
Prowler Bot
5567d9f88c
chore(regions_update): Changes in regions for AWS services ( #7131 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-07 13:19:08 +01:00
dependabot[bot]
56f3e661ae
chore(deps): bump trufflesecurity/trufflehog from 3.88.14 to 3.88.15 ( #7127 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-07 13:17:45 +01:00
César Arroba
1aa4479a10
chore: increase release to 5.5.0 ( #7143 )
2025-03-07 13:16:24 +01:00
Prowler Bot
7b625d0a91
chore(regions_update): Changes in regions for AWS services ( #7146 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-07 13:15:51 +01:00
Pablo Lara
fd0529529d
chore: update changelog ( #7149 )
2025-03-07 11:47:23 +01:00
Pablo Lara
af43191954
fix: tweaks for compliance cards ( #7147 )
2025-03-07 11:32:58 +01:00
Pablo Lara
2ce2ca7c91
feat: add changelog ( #7141 )
2025-03-06 16:46:55 +01:00
Víctor Fernández Poyatos
a0fc3db665
fix(overviews): manage overview exceptions and use batch_size with bulk ( #7140 )
2025-03-06 15:35:29 +01:00
César Arroba
feb458027f
chore(ui-gha): delete double quotes on prowler version ( #7139 )
2025-03-06 19:48:53 +05:45
Pablo Lara
e5a5b7af5c
fix(groups): display uid if alias is missing ( #7137 )
2025-03-06 14:37:36 +01:00
Pablo Lara
ad456ae2fe
fix(credentials): adjust helper links to fit width ( #7133 )
2025-03-06 11:42:26 +01:00
Pepe Fagoaga
690cb51f6c
revert(findings): change uid from varchar to text ( #7132 )
2025-03-06 16:24:35 +05:45
dependabot[bot]
14aaa2f376
chore(deps): bump jinja2 from 3.1.5 to 3.1.6 in /api ( #7130 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-06 09:39:24 +01:00
César Arroba
6e47ca2c41
chore(ui-gha): add version prefix ( #7125 )
2025-03-05 21:13:24 +05:45
Víctor Fernández Poyatos
0d99d2be9b
fix(reports): Fix task kwargs and result ( #7124 )
2025-03-05 21:10:44 +05:45
César Arroba
c322ef00e7
chore(ui): add prowler version on build ( #7120 )
2025-03-05 20:46:16 +05:45
Pablo Lara
3513421225
feat(compliance): new compliance selector ( #7118 )
2025-03-05 15:12:10 +01:00
Víctor Fernández Poyatos
b0e6bfbefe
chore(api): Update changelog ( #7090 )
2025-03-04 17:44:34 +01:00
dependabot[bot]
f7a918730e
chore(deps-dev): bump pytest from 8.3.4 to 8.3.5 ( #7097 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-03-04 09:16:05 +01:00
Pablo Lara
cef33319c5
chore(ui): update label from 'Select a scan job' to 'Select a cloud p… ( #7107 )
2025-03-04 09:11:39 +01:00
Pablo Lara
2036a59210
fix(roles): show the correct error message ( #7089 )
2025-03-03 15:46:02 +01:00
Pablo Lara
e5eccb6227
fix: bug with create role and unlimited visibility checkbox ( #7088 )
2025-03-03 15:45:39 +01:00
Sergio Garcia
48c2c8567c
feat(aws): add fixers for threat detection checks ( #7085 )
2025-03-03 14:20:23 +01:00
Pablo Lara
bbeef0299f
feat(version): add prowler version to the sidebar ( #7086 )
2025-03-03 13:40:09 +01:00
Pablo Lara
bec5584d63
chore: Update the latest table findings with the most recent changes ( #7084 )
2025-03-03 13:16:30 +01:00
Pablo Lara
bdc759d34c
feat(sidebar): sidebar with new functionalities ( #7018 )
2025-03-03 12:30:28 +01:00
Prowler Bot
8db442d8ba
chore(regions_update): Changes in regions for AWS services ( #7067 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-03-03 09:29:48 +01:00
Sergio Garcia
9e7a0d4175
fix(threat detection): run single threat detection check ( #7065 )
2025-02-28 13:51:07 +01:00
Pepe Fagoaga
9c33b3f5a9
refactor(stats): Use Finding instead of Check_Report ( #7053 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2025-02-28 10:54:48 +01:00
Pepe Fagoaga
7e7e2c87dc
chore(examples): Scan AWS ( #7064 )
2025-02-28 15:25:10 +05:45
Sergio Garcia
2f741f35a8
chore(gcp): enhance GCP APIs logic ( #7046 )
2025-02-28 14:55:43 +05:45
dependabot[bot]
c411466df7
chore(deps): bump trufflesecurity/trufflehog from 3.88.13 to 3.88.14 ( #7063 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-28 09:10:47 +01:00
Daniel Barranquero
9679939307
feat(m365): add sharepoint service with 4 checks ( #7057 )
...
Co-authored-by: MarioRgzLpz <mariorgzlpz1809@gmail.com >
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-27 18:15:17 +01:00
Pedro Martín
8539423b22
feat(docs): add info related with sts assume role and regions ( #7062 )
2025-02-27 17:40:31 +01:00
Daniel Barranquero
81edafdf09
fix(azure): handle account not supporting Blob ( #7060 )
2025-02-27 13:20:56 +01:00
Sergio Garcia
e0a262882a
fix(ecs): ensure unique finding id in ECS checks ( #7059 )
2025-02-27 13:02:22 +01:00
Prowler Bot
89237ab99e
chore(regions_update): Changes in regions for AWS services ( #7056 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-27 11:00:13 +01:00
Hugo Pereira Brito
0f414e451e
feat(microsoft365): add new check entra_policy_ensure_default_user_cannot_create_tenants ( #6918 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-27 10:31:02 +01:00
Pablo Lara
1180522725
feat(exports): download scan exports ( #7006 )
2025-02-27 14:08:12 +05:45
Pepe Fagoaga
81c7ebf123
fix(env): UI version must be stable ( #7055 )
2025-02-27 13:32:53 +05:45
Víctor Fernández Poyatos
258f05e6f4
fix(migrations): Fix migration dependency order ( #7051 )
2025-02-26 17:26:21 +01:00
Víctor Fernández Poyatos
53efb1c153
feat(labeler): apply label on migration changes ( #7052 )
2025-02-26 17:03:12 +01:00
Pepe Fagoaga
26014a9705
fix(findings): change uid from varchar to text ( #7048 )
2025-02-26 21:17:16 +05:45
Víctor Fernández Poyatos
00ef037e45
feat(findings): Add Django management command to populate database with dummy data ( #7049 )
2025-02-26 16:15:37 +01:00
Adrián Jesús Peña Rodríguez
669ec74e67
feat(export): add API export system ( #6878 )
2025-02-26 15:49:44 +01:00
dependabot[bot]
c4528200b0
chore(deps-dev): bump black from 24.10.0 to 25.1.0 ( #6733 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-26 11:38:09 +01:00
Daniel Barranquero
ba7cd0250a
fix(elasticache): improve logic in elasticache_redis_cluster_backup_enabled ( #7042 )
2025-02-26 10:31:14 +01:00
Rubén De la Torre Vico
c5e97678a1
fix(azure): migrate resource models to avoid using SDK defaults ( #6880 )
2025-02-26 09:54:53 +01:00
Pedro Martín
337a46cdcc
feat(aws): add ISO 27001 2022 compliance framework ( #7035 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-26 08:34:08 +01:00
Hugo Pereira Brito
7f74b67f1f
chore(iam): enhance iam_role_cross_service_confused_deputy_prevention recommendation ( #7023 )
2025-02-26 07:37:57 +01:00
Prowler Bot
5dcc48d2e5
chore(regions_update): Changes in regions for AWS services ( #7034 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-26 07:30:07 +01:00
Prowler Bot
8b04aab07d
chore(regions_update): Changes in regions for AWS services ( #7015 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-26 07:29:42 +01:00
dependabot[bot]
eab4f6cf2e
chore(deps): bump google-api-python-client from 2.161.0 to 2.162.0 ( #7037 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-26 07:25:14 +01:00
Hugo Pereira Brito
7f8d623283
refactor(microsoft365): CheckReportMicrosoft365 and resource metadata ( #6952 )
2025-02-26 07:24:54 +01:00
Víctor Fernández Poyatos
dbffed8f1f
feat(findings): Optimize findings endpoint ( #7019 )
2025-02-25 12:41:47 +01:00
Pepe Fagoaga
7e3688fdd0
chore(action): Conventional Commit Check ( #7033 )
2025-02-25 09:51:55 +01:00
dependabot[bot]
2e111e9ad3
chore(deps): bump trufflesecurity/trufflehog from 3.88.12 to 3.88.13 ( #7026 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-25 14:34:24 +05:45
Pedro Martín
6d6070ff3f
feat(outputs): add sample outputs ( #6945 )
2025-02-25 14:33:16 +05:45
Pedro Martín
391bbde353
fix(cis): show report table on the CLI ( #6979 )
2025-02-25 14:28:58 +05:45
Pedro Martín
3c56eb3762
feat(azure): add PCI DSS 4.0 ( #6982 )
2025-02-25 14:27:50 +05:45
Pedro Martín
7c14ea354b
feat(kubernetes): add PCI DSS 4.0 ( #7013 )
2025-02-25 14:27:14 +05:45
Pedro Martín
c96aad0b77
feat(dashboard): take the latest finding uid by timestamp ( #6987 )
2025-02-25 14:25:03 +05:45
Víctor Fernández Poyatos
a9dd3e424b
feat(tasks): add deletion queue for deletion tasks ( #7022 )
2025-02-24 18:02:52 +01:00
Pedro Martín
8a144a4046
feat(gcp): add PCI DSS 4.0 ( #7010 )
2025-02-21 16:19:20 +05:30
Prowler Bot
75f86d7267
chore(regions_update): Changes in regions for AWS services ( #7011 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-21 15:37:15 +05:30
dependabot[bot]
bbf875fc2f
chore(deps-dev): bump mkdocs-material from 9.6.4 to 9.6.5 ( #7007 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-21 14:28:18 +05:30
Raj Chowdhury
59d491f61b
fix(typo): solve typo in dashboard.md ( #7009 )
2025-02-21 14:17:08 +05:30
dependabot[bot]
ed640a1324
chore(deps): bump trufflesecurity/trufflehog from 3.88.11 to 3.88.12 ( #7008 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-21 14:16:15 +05:30
César Arroba
e86fbcaef7
feat(api): setup sentry for OSS API ( #6874 )
2025-02-20 23:08:01 +05:45
Pablo Lara
7f48212054
chore(users): renaming the account now triggers a re-render in the sidebar ( #7005 )
2025-02-20 16:58:45 +01:00
dependabot[bot]
a2c5c71baf
chore(deps): bump python from 3.12.8-alpine3.20 to 3.12.9-alpine3.20 ( #6882 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-20 21:11:45 +05:30
dependabot[bot]
b904f81cb9
chore(deps): bump tzlocal from 5.2 to 5.3 ( #6932 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-20 21:10:46 +05:30
dependabot[bot]
d64fe374dd
chore(deps): bump cryptography from 43.0.1 to 44.0.1 in /api ( #7001 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-20 12:55:36 +01:00
Hugo Pereira Brito
fe25e7938e
docs(tutorials): update all deprecated poetry shell references ( #7002 )
2025-02-20 17:04:19 +05:45
Prowler Bot
931df361bf
chore(regions_update): Changes in regions for AWS services ( #6998 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-20 15:52:36 +05:30
Pedro Martín
d7c45f4aee
chore(github): add compliance to PR labeler ( #6996 )
2025-02-20 14:50:43 +05:30
Pedro Martín
5e5bef581b
fix(soc2_aws): remove duplicated checks ( #6995 )
2025-02-20 14:38:26 +05:30
Hugo Pereira Brito
2d9e95d812
docs(installation): add warning for poetry shell deprecation in README ( #6983 )
2025-02-20 14:19:35 +05:45
Pablo Lara
e5f979d106
chore(findings): add 'Status Extended' attribute to finding details ( #6997 )
2025-02-20 09:33:03 +01:00
Sergio Garcia
c7a5815203
fix(deps): update vulnerable cryptography dependency ( #6993 )
2025-02-20 12:18:15 +05:30
Pedro Martín
03e268722e
feat(aws): add PCI DSS 4.0 ( #6949 )
2025-02-20 11:07:06 +05:30
dependabot[bot]
78a2774329
chore(deps): bump trufflesecurity/trufflehog from 3.88.9 to 3.88.11 ( #6988 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-20 11:04:15 +05:30
dependabot[bot]
c1b5ab7f53
chore(deps): bump kubernetes from 32.0.0 to 32.0.1 ( #6992 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-20 10:46:19 +05:30
Sergio Garcia
b861d97ad4
fix(report): remove invalid resources in report ( #6852 )
2025-02-19 21:27:52 +05:45
Pablo Lara
f3abcc9dd6
feat(scans): update the progress for executing scans ( #6972 )
2025-02-19 16:10:29 +01:00
César Arroba
cab13fe018
chore(gha): trigger API or UI deployment when push to master ( #6946 )
2025-02-19 18:08:51 +05:45
Prowler Bot
cc4b19c7ce
chore(regions_update): Changes in regions for AWS services ( #6978 )
2025-02-19 11:04:45 +01:00
Pablo Lara
a754d9aee5
fix(roles): handle empty response in deleteRole and ensure revalidation ( #6976 )
2025-02-19 09:03:49 +01:00
Pedro Martín
22b54b2d8d
feat(aws): add compliance CIS 4.0 ( #6937 )
2025-02-19 08:23:49 +05:30
dependabot[bot]
d12ca6301a
chore(deps-dev): bump flake8 from 7.1.1 to 7.1.2 ( #6954 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-19 08:09:58 +05:30
Hugo Pereira Brito
bc1b2ad9ab
test(cloudfront): add name retrieval test for cloudfront bucket domains ( #6969 )
2025-02-19 08:08:55 +05:30
Pepe Fagoaga
1782ab1514
fix(ocsf): Adapt for 1.4.0 ( #6971 )
2025-02-19 08:06:13 +05:30
Prowler Bot
0384fc50e3
chore(regions_update): Changes in regions for AWS services ( #6968 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-18 18:40:01 +05:30
dependabot[bot]
cc46dee9ee
chore(deps-dev): bump bandit from 1.8.2 to 1.8.3 ( #6955 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-18 18:39:10 +05:30
Hugo Pereira Brito
ed5a0ae45a
fix(cloudfront): Incorrect bucket name retrievement ( #6947 )
2025-02-17 17:08:28 +01:00
Prowler Bot
928ccfefb8
chore(regions_update): Changes in regions for AWS services ( #6944 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-17 16:55:15 +01:00
dependabot[bot]
7f6bfb7b3e
chore(deps): bump trufflesecurity/trufflehog from 3.88.8 to 3.88.9 ( #6943 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-17 16:54:52 +01:00
Rubén De la Torre Vico
bcbc9bf675
fix(gcp): Correct false positive when sslMode=ENCRYPTED_ONLY in CloudSQL ( #6936 )
2025-02-14 15:16:21 -05:00
dependabot[bot]
0ec4366f4c
chore(deps): bump google-api-python-client from 2.160.0 to 2.161.0 ( #6933 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-14 10:09:33 -05:00
César Arroba
ff72b7eea1
fix(gha): fix short sha step ( #6939 )
2025-02-14 19:11:26 +05:45
César Arroba
a32ca19251
chore(gha): add tag for api and ui images on push to master ( #6920 )
2025-02-14 18:01:22 +05:45
Pablo Lara
b79508956a
fix(issue pages): apply sorting by default in issue pages ( #6934 )
2025-02-14 10:32:34 +01:00
dependabot[bot]
d76c5bd658
chore(deps): bump trufflesecurity/trufflehog from 3.88.7 to 3.88.8 ( #6931 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-13 18:17:25 -05:00
Kay Agahd
580e11126c
fix(aws): codebuild service threw KeyError for projects type CODEPIPELINE ( #6919 )
2025-02-13 12:22:09 -05:00
Sergio Garcia
736d40546a
fix(gcp): handle DNS Managed Zone with no DNSSEC ( #6924 )
2025-02-13 12:18:50 -05:00
dependabot[bot]
88810d2bb5
chore(deps-dev): bump mkdocs-material from 9.6.3 to 9.6.4 ( #6913 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-13 11:36:07 -05:00
Víctor Fernández Poyatos
3a8f4d2ffb
feat(social-login): Add social login integration for Google and Github OAuth providers ( #6906 )
2025-02-13 16:54:38 +01:00
Sergio Garcia
1fe125a65f
chore(docs): external K8s cluster Prowler App credentials ( #6921 )
2025-02-13 09:46:05 -05:00
Kay Agahd
0ff4df0836
fix(aws): SNS threw IndexError if SubscriptionArn is PendingConfirmation ( #6896 )
2025-02-13 09:34:48 -05:00
Pedro Martín
16b4775e2d
fix(gcp): remove typos on CIS 3.0 ( #6917 )
2025-02-13 13:48:19 +01:00
dependabot[bot]
c3a13b8a29
chore(deps): bump trufflesecurity/trufflehog from 3.88.6 to 3.88.7 ( #6915 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-12 19:15:03 -05:00
Sergio Garcia
d1053375b7
fix(aws): handle AccessDenied when retrieving resource policy ( #6908 )
...
Co-authored-by: Pedro Martín <pedromarting3@gmail.com >
2025-02-12 15:31:26 -05:00
César Arroba
0fa4538256
fix(gha): fix test build containers on pull requests actions ( #6909 )
2025-02-12 23:26:54 +05:45
Ogonna Iwunze
738644f288
fix(kms): Amazon KMS API call error handling ( #6843 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-12 10:09:15 -05:00
dependabot[bot]
2f80b055ac
chore(deps-dev): bump coverage from 7.6.11 to 7.6.12 ( #6897 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-12 10:08:26 -05:00
Prowler Bot
fd62a1df10
chore(regions_update): Changes in regions for AWS services ( #6900 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-12 10:06:42 -05:00
César Arroba
a85d0ebd0a
chore(api): test build container image on pull request ( #6850 )
2025-02-12 15:44:05 +05:45
César Arroba
2c06902baa
chore(ui): test build container image on pull request ( #6849 )
2025-02-12 15:43:22 +05:45
Pepe Fagoaga
76ac6429fe
chore(version): Update version to 5.4.0 ( #6894 )
2025-02-11 17:51:08 -05:00
dependabot[bot]
43cae66b0d
chore(deps-dev): bump coverage from 7.6.10 to 7.6.11 ( #6887 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-10 19:30:36 -05:00
dependabot[bot]
dacddecc7d
chore(deps): bump trufflesecurity/trufflehog from 3.88.5 to 3.88.6 ( #6888 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-10 18:15:25 -05:00
Mario Rodriguez Lopez
dcb9267c2f
feat(microsof365): Add documentation and compliance file ( #6195 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com >
2025-02-10 11:13:06 -05:00
Víctor Fernández Poyatos
ff35fd90fa
chore(api): Update changelog and specs ( #6876 )
2025-02-10 12:06:34 +01:00
Víctor Fernández Poyatos
7469377079
chore: Add needed steps for API in PR template ( #6875 )
2025-02-10 15:20:09 +05:45
Pepe Fagoaga
c8441f8d38
fix(kubernetes): Change UID validation ( #6869 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-02-10 14:55:24 +05:45
Pepe Fagoaga
abf4eb0ffc
chore: Rename dashboard table latest findings ( #6873 )
...
Co-authored-by: Pablo Lara <larabjj@gmail.com >
2025-02-10 09:55:44 +01:00
dependabot[bot]
93717cc830
chore(deps-dev): bump mkdocs-material from 9.6.2 to 9.6.3 ( #6871 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-07 18:24:49 -05:00
Sergio Garcia
b629bc81f8
docs(eks): add documentation about EKS onboarding ( #6853 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-02-07 10:59:01 -05:00
Pedro Martín
f628897fe1
fix(dashboard): adjust the bar chart display ( #6690 )
2025-02-07 10:05:30 -05:00
Prowler Bot
54b82a78e3
chore(regions_update): Changes in regions for AWS services ( #6858 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-07 10:02:28 -05:00
Víctor Fernández Poyatos
377faf145f
feat(findings): Use ArrayAgg and subqueries on metadata endpoint ( #6863 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-02-07 19:36:01 +05:45
Kay Agahd
69e316948f
fix(aws): key error for detect-secrets ( #6710 )
2025-02-07 14:48:16 +01:00
Pablo Lara
62cbff4f53
feat: implement new functionality with inserted_at__gte in findings a… ( #6864 )
2025-02-07 14:25:25 +01:00
Víctor Fernández Poyatos
5582265e9d
docs: Add details about user creation in Prowler app ( #6862 )
2025-02-07 13:29:25 +01:00
dependabot[bot]
fb5ea3c324
chore(deps): bump microsoft-kiota-abstractions from 1.9.1 to 1.9.2 ( #6856 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-07 11:07:43 +01:00
Víctor Fernández Poyatos
9b5f676f50
feat(findings): Require date filters for findings endpoints ( #6800 )
2025-02-07 13:54:55 +05:45
Pranay Girase
88cfc0fa7e
fix(typo): typos in Dashboard and Report in HTML ( #6847 )
2025-02-06 10:42:31 -05:00
Prowler Bot
665bfa2f13
chore(regions_update): Changes in regions for AWS services ( #6848 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-06 08:46:32 -05:00
dependabot[bot]
b89b1a64f4
chore(deps): bump trufflesecurity/trufflehog from 3.88.4 to 3.88.5 ( #6844 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-05 18:02:42 -05:00
Sergio Garcia
9ba657c261
fix(kms): handle error in DescribeKey function ( #6839 )
2025-02-05 14:03:31 -05:00
Mario Rodriguez Lopez
bce958b8e6
feat(entra): add new check entra_thirdparty_integrated_apps_not_allowed ( #6357 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-05 12:45:48 -05:00
Daniel Barranquero
914012de2b
fix(cloudfront): fix false positive in s3 origins ( #6823 )
2025-02-05 12:39:49 -05:00
Ogonna Iwunze
8d1c476aed
feat(kms): add kms_cmk_not_multi_region AWS check ( #6794 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-05 11:20:29 -05:00
Gary Mclean
567c729e9e
fix(findings) Spelling mistakes correction ( #6822 )
2025-02-05 10:26:50 -05:00
Kay Agahd
3f03dd20e4
fix(aws) wording of report.status_extended in awslambda_function_not_publicly_accessible ( #6824 )
2025-02-05 10:23:52 -05:00
Daniel Barranquero
1c778354da
fix(directoryservice): handle ClientException ( #6781 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-05 10:22:32 -05:00
Prowler Bot
3a149fa459
chore(regions_update): Changes in regions for AWS services ( #6821 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-02-05 09:19:56 -05:00
Mario Rodriguez Lopez
f3b121950d
feat(entra): add new entra service for Microsoft365 ( #6326 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-04 19:47:14 -05:00
Mario Rodriguez Lopez
43c13b7ba1
feat(microsoft365): add new check admincenter_settings_password_never_expire ( #6023 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-04 17:24:11 -05:00
dependabot[bot]
9447b33800
chore(deps): bump kubernetes from 31.0.0 to 32.0.0 ( #6678 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-04 17:22:51 -05:00
Hugo Pereira Brito
2934752eeb
fix(elasticache): InvalidReplicationGroupStateFault error ( #6815 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-04 14:28:31 -05:00
dependabot[bot]
dd6d8c71fd
chore(deps-dev): bump moto from 5.0.27 to 5.0.28 ( #6804 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-02-04 12:58:48 -05:00
Pablo Lara
80267c389b
style(forms): improve spacing consistency ( #6814 )
2025-02-04 13:20:24 +01:00
Pablo Lara
acfbaf75d5
chore(forms): improvements to the sign-in and sign-up forms ( #6813 )
2025-02-04 12:46:07 +01:00
Pedro Martín
5f54377407
chore(aws_audit_manager_control_tower_guardrails): add checks to reqs ( #6699 )
2025-02-03 14:59:08 -05:00
Drew Kerrigan
552aa64741
docs(): add description of changed and new delta values to prowler app tutorial ( #6801 )
2025-02-03 20:51:03 +01:00
dependabot[bot]
d64f611f51
chore(deps): bump pytz from 2024.2 to 2025.1 ( #6765 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-03 12:48:18 -05:00
dependabot[bot]
a96cc92d77
chore(deps-dev): bump mkdocs-material from 9.5.50 to 9.6.2 ( #6799 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-03 11:37:02 -05:00
dependabot[bot]
3858cccc41
chore(deps-dev): bump pylint from 3.3.3 to 3.3.4 ( #6721 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-03 10:32:42 -05:00
Pedro Martín
072828512a
fix(cis_1.5_aws): add checks to needed reqs ( #6695 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-02-03 10:32:20 -05:00
Pedro Martín
a73ffe5642
fix(cis_1.4_aws): add checks to needed reqs ( #6696 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-02-03 10:32:10 -05:00
Pablo Lara
8e784a5b6d
feat(scans): show scan details right after launch ( #6791 )
2025-02-03 16:08:47 +01:00
dependabot[bot]
1b6f9332f1
chore(deps): bump trufflesecurity/trufflehog from 3.88.2 to 3.88.4 ( #6760 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-03 09:35:53 -05:00
secretcod3r
db8b472729
fix(gcp): fix wrong provider value in check ( #6691 )
2025-02-03 09:29:08 -05:00
Pedro Martín
867b371522
fix(cis_2.0_aws): add checks to needed reqs ( #6694 )
2025-02-03 09:28:04 -05:00
dependabot[bot]
c0d7c9fc7d
chore(deps): bump google-api-python-client from 2.159.0 to 2.160.0 ( #6720 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-02-03 09:27:17 -05:00
Pablo Lara
bb4685cf90
fix(findings): remove default status filtering ( #6784 )
2025-02-03 15:20:18 +01:00
Pablo Lara
6a95426749
fix(findings): order findings by inserted_at DESC ( #6782 )
2025-02-03 11:51:07 +01:00
Víctor Fernández Poyatos
ef6af8e84d
feat(schedules): Rework daily schedule to always show the next scan ( #6700 )
2025-02-03 11:08:27 +01:00
Víctor Fernández Poyatos
763130f253
fix(celery): Kill celery worker process after every task to release memory ( #6761 )
2025-01-31 19:30:08 +05:45
Hugo Pereira Brito
1256c040e9
fix: microsoft365 mutelist ( #6724 )
2025-01-31 12:32:39 +01:00
dependabot[bot]
18b7b48a99
chore(deps): bump microsoft-kiota-abstractions from 1.6.8 to 1.9.1 ( #6734 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-31 10:07:17 +01:00
Pepe Fagoaga
627c11503f
fix(db_event): Handle other events ( #6754 )
2025-01-30 21:46:43 +05:45
Víctor Fernández Poyatos
712ba84f06
feat(scans): Optimize read queries during scans ( #6753 )
2025-01-30 20:51:12 +05:45
Pepe Fagoaga
5186e029b3
fix(set_report_color): Add more details to error ( #6751 )
2025-01-30 20:48:51 +05:45
Pablo Lara
5bfaedf903
fix: Enable hot reloading when using Docker Compose for UI ( #6750 )
2025-01-30 14:05:39 +01:00
Víctor Fernández Poyatos
5061da6897
feat(findings): Improve /findings/metadata performance ( #6748 )
2025-01-30 13:31:43 +01:00
Pepe Fagoaga
c159a28016
fix(neptune): correct service name ( #6743 )
2025-01-30 17:16:18 +05:45
Pepe Fagoaga
82a1b1c921
fix(finding): raise when generating invalid findings ( #6738 )
2025-01-30 15:59:38 +05:45
Pepe Fagoaga
bf2210d0f4
fix(acm): Key Error DomainName ( #6739 )
2025-01-30 15:54:31 +05:45
Kay Agahd
8f0772cb94
fix(aws): iam_user_with_temporary_credentials resource in OCSF ( #6697 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2025-01-30 15:28:21 +05:45
Pepe Fagoaga
5b57079ecd
fix(sns): Add region to subscriptions ( #6731 )
2025-01-30 14:38:21 +05:45
Matt Johnson
350d759517
chore: Update Google Analytics ID across all docs.prowler.com sites. ( #6730 )
2025-01-30 12:47:01 +05:45
Pablo Lara
edd793c9f5
fix(scans): change label for next scan ( #6725 )
2025-01-29 10:46:49 +01:00
Víctor Fernández Poyatos
545c2dc685
fix(migrations): Use indexes instead of constraints to define an index ( #6722 )
2025-01-29 14:24:04 +05:45
Víctor Fernández Poyatos
84955c066c
revert: Update Django DB manager to use psycopg3 and connection pooling ( #6717 )
2025-01-28 22:15:01 +05:45
Víctor Fernández Poyatos
06dd03b170
fix(scan-summaries): Improve efficiency on providers overview ( #6716 )
2025-01-28 21:56:29 +05:45
Pedro Martín
47bc2ed2dc
fix(defender): add field to SecurityContacts ( #6693 )
2025-01-28 15:52:56 +01:00
Pablo Lara
44281afc54
fix(scans): filters and sorting for scan table ( #6713 )
2025-01-28 13:26:31 +01:00
Víctor Fernández Poyatos
4d2859d145
fix(scans, findings): Improve API performance ordering by inserted_at instead of id ( #6711 )
2025-01-28 16:41:58 +05:45
Pablo Lara
45d44a1669
fix: fixed bug when opening finding details while a scan is in progress ( #6708 )
2025-01-28 06:58:18 +01:00
dependabot[bot]
ddd83b340e
chore(deps): bump uuid from 10.0.0 to 11.0.5 in /ui ( #6516 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-26 13:39:42 +01:00
Mario Rodriguez Lopez
ccdb54d7c3
feat(m365): add Microsoft 365 provider ( #5902 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
Co-authored-by: HugoPBrito <hugopbrit@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-24 13:14:17 -05:00
Rubén De la Torre Vico
bcc246d950
fix(cloudsql): add trusted client certificates case for cloudsql_instance_ssl_connections ( #6682 )
2025-01-24 10:42:45 -05:00
dependabot[bot]
62139e252a
chore(deps): bump azure-mgmt-web from 7.3.1 to 8.0.0 ( #6680 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-24 12:40:11 +01:00
dependabot[bot]
86950c3a0a
chore(deps): bump msgraph-sdk from 1.17.0 to 1.18.0 ( #6679 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-24 10:47:09 +01:00
dependabot[bot]
f4865ef68d
chore(deps): bump azure-storage-blob from 12.24.0 to 12.24.1 ( #6666 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-24 09:44:16 +01:00
Pepe Fagoaga
ea7209e7ae
chore: bump for next minor ( #6672 )
2025-01-23 13:13:08 -05:00
Hugo Pereira Brito
998c551cf3
fix(cloudwatch): NoneType object is not iterable ( #6671 )
2025-01-23 12:27:07 -05:00
Paolo Frigo
e6f29b0116
docs: update # of checks, services, frameworks and categories ( #6528 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-23 11:11:03 -05:00
Pepe Fagoaga
eb90bb39dc
chore(api): Bump to v1.3.0 ( #6670 )
2025-01-23 21:25:29 +05:45
Pepe Fagoaga
ad189b35ad
chore(scan): Remove ._findings ( #6667 )
2025-01-23 20:43:02 +05:45
Pablo Lara
7d2989a233
chore: adjust DateWithTime component height when used with InfoField ( #6669 )
2025-01-23 15:18:24 +01:00
Pablo Lara
862137ae7d
chore(scans): improve scan details ( #6665 )
2025-01-23 13:20:41 +01:00
Pedro Martín
c86e082d9a
feat(detect-secrets): get secrets plugins from config.yaml ( #6544 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-01-23 17:18:19 +05:45
Sergio Garcia
80fe048f97
feat(resource metadata): add resource metadata to JSON OCSF ( #6592 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2025-01-23 16:06:30 +05:45
dependabot[bot]
f2bffb3ce7
chore(deps): bump azure-mgmt-containerservice from 33.0.0 to 34.0.0 ( #6630 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-22 16:37:07 -05:00
dependabot[bot]
cbe2f9eef8
chore(deps): bump azure-mgmt-compute from 33.1.0 to 34.0.0 ( #6628 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-22 20:00:56 +01:00
Pepe Fagoaga
688f41f570
fix(templates): Customize principals and add validation ( #6655 )
2025-01-22 21:47:57 +05:45
Anton Rubets
a29197637e
chore(helm): Add prowler helm support ( #6580 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-22 10:55:26 -05:00
Prowler Bot
7a2712a37f
chore(regions_update): Changes in regions for AWS services ( #6652 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-22 09:30:03 -05:00
dependabot[bot]
189f5cfd8c
chore(deps): bump boto3 from 1.35.94 to 1.35.99 ( #6651 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-22 09:29:41 -05:00
Kay Agahd
e509480892
fix: add detector and line number of potential secret ( #6654 )
2025-01-22 20:13:23 +05:45
Pepe Fagoaga
7f7955351a
chore(pre-commit): poetry checks for API and SDK ( #6658 )
2025-01-22 20:05:26 +05:45
Pepe Fagoaga
46f1db21a8
chore(api): Use prowler from master ( #6657 )
2025-01-22 20:05:02 +05:45
Pablo Lara
fbe7bc6951
feat(providers): show the cloud formation and terraform template links on the form ( #6660 )
2025-01-22 14:49:38 +01:00
Pablo Lara
f658507847
feat(providers): make external id field mandatory in the aws role secret form ( #6656 )
2025-01-22 12:45:31 +01:00
dependabot[bot]
374078683b
chore(deps-dev): bump moto from 5.0.16 to 5.0.27 ( #6632 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-21 13:56:06 -05:00
dependabot[bot]
114c4e0886
chore(deps): bump botocore from 1.35.94 to 1.35.99 ( #6520 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-21 09:17:18 -05:00
Pablo Lara
67c62766d4
fix(filters): fix dynamic filters ( #6642 )
2025-01-21 13:33:27 +01:00
dependabot[bot]
3f2947158d
chore(deps): bump prowler from 5.1.1 to 5.1.4 in /api ( #6641 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-21 14:27:59 +05:45
dependabot[bot]
278a7cb356
chore(deps-dev): bump mkdocs-material from 9.5.49 to 9.5.50 ( #6631 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-20 18:31:44 -05:00
Rubén De la Torre Vico
890158a79c
fix(OCSF): fix OCSF output when timestamp is UNIX format ( #6606 )
2025-01-20 17:11:28 -05:00
Rubén De la Torre Vico
4dc1602b77
fix: update Azure CIS with existing App checks ( #6611 )
2025-01-20 15:12:00 -05:00
Kay Agahd
bbba0abac9
fix(aws): list tags for DocumentDB clusters ( #6605 )
2025-01-20 15:10:58 -05:00
Prowler Bot
d04fd807c6
chore(regions_update): Changes in regions for AWS services ( #6599 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-20 15:09:35 -05:00
Pablo Lara
3456df4cf1
fix(snippet-id): improve provider ID readability in tables ( #6615 )
2025-01-20 17:23:19 +01:00
Pablo Lara
f56aaa791e
chore(RBAC): add permission's info ( #6612 )
2025-01-20 16:14:48 +01:00
Adrián Jesús Peña Rodríguez
465a758770
fix(rbac): remove invalid required permission ( #6608 )
2025-01-20 15:21:52 +01:00
Pablo Lara
0f7c0c1b2c
fix(RBAC): tweaks for edit role form ( #6609 )
2025-01-20 14:09:16 +01:00
Adrián Jesús Peña Rodríguez
bf8d10b6f6
feat(api): restrict the deletion of users, only the user of the request can be deleted ( #6607 )
2025-01-20 13:26:47 +01:00
Pablo Lara
20d04553d6
fix(RBAC): restore manage_account permission for roles ( #6602 )
2025-01-20 11:35:29 +01:00
Daniel Barranquero
b56d62e3c4
fix(sqs): fix flaky test ( #6593 )
2025-01-17 11:48:39 -05:00
Hugo Pereira Brito
9a332dcba1
chore(services): delete all comment headers ( #6585 )
2025-01-17 08:21:28 -05:00
Hugo Pereira Brito
166d9f8823
fix(apigatewayv2): managed exception NotFoundException ( #6576 )
2025-01-17 08:17:51 -05:00
Prowler Bot
42f5eed75f
chore(regions_update): Changes in regions for AWS services ( #6577 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-17 08:17:00 -05:00
Rubén De la Torre Vico
01a7db18dd
fix: add missing Check_Report_Azure parameters ( #6583 )
2025-01-17 08:16:43 -05:00
Pablo Lara
d4507465a3
fix(providers): update the label and placeholder based on the cloud provider ( #6581 )
2025-01-17 12:28:38 +01:00
Pablo Lara
3ac92ed10a
fix(findings): remove filter delta_in applied by default ( #6578 )
2025-01-17 11:03:12 +01:00
Pablo Lara
43c76ca85c
feat(findings): add first seen in findings details ( #6575 )
2025-01-17 10:19:10 +01:00
dependabot[bot]
54d87fa96a
chore(deps): bump prowler from 5.0.2 to 5.1.1 in /api ( #6573 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-17 13:26:07 +05:45
Daniel Barranquero
f041f17268
fix(gcp): fix flaky tests from dns service ( #6569 )
2025-01-16 14:49:25 -05:00
dependabot[bot]
31c80a6967
chore(deps): bump msgraph-sdk from 1.16.0 to 1.17.0 ( #6547 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-16 12:55:30 -05:00
Rubén De la Torre Vico
783ce136f4
feat(network): extract Network resource metadata automated ( #6555 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-16 12:41:02 -05:00
Rubén De la Torre Vico
f829145781
feat(storage): extract Storage resource metadata automated ( #6563 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-16 11:44:43 -05:00
Rubén De la Torre Vico
389337f8cd
feat(vm): extract VM resource metadata automated ( #6564 )
2025-01-16 11:16:02 -05:00
Pedro Martín
a0713c2d66
fix(cis): add subsections if needed ( #6559 )
2025-01-16 11:10:54 -05:00
Rubén De la Torre Vico
f94d3cbce4
feat(sqlserver): extract SQL Server resource metadata automated ( #6562 )
2025-01-16 10:47:21 -05:00
Daniel Barranquero
8d8994b468
feat(aws): include resource metadata to remaining checks ( #6551 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-16 10:44:14 -05:00
Rubén De la Torre Vico
784a9097a5
feat(postgresql): extract PostgreSQL resource metadata automated ( #6560 )
2025-01-16 10:37:55 -05:00
Pedro Martín
b9601626e3
fix(detect_secrets): refactor logic for detect-secrets ( #6537 )
2025-01-16 21:15:44 +05:45
Rubén De la Torre Vico
dc80b011f2
feat(policy): extract Policy resource metadata automated ( #6558 )
2025-01-16 10:29:28 -05:00
Rubén De la Torre Vico
ee7d32d460
feat(entra): extract Entra resource metadata automated ( #6542 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-16 10:24:53 -05:00
Rubén De la Torre Vico
43fd9ee94e
feat(monitor): extract monitor resource metadata automated ( #6554 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-16 10:16:19 -05:00
Víctor Fernández Poyatos
8821a91f3f
feat(db): Update Django DB manager to use psycopg3 and connection pooling ( #6541 )
2025-01-16 15:29:02 +01:00
Rubén De la Torre Vico
98d9256f92
feat(mysql): extract MySQL resource metadata automated ( #6556 )
2025-01-16 09:24:06 -05:00
Rubén De la Torre Vico
b35495eaa7
feat(keyvault): extract KeyVault resource metadata automated ( #6553 )
2025-01-16 09:17:36 -05:00
Rubén De la Torre Vico
74d6b614b3
feat(iam): extract IAM resource metadata automated ( #6552 )
2025-01-16 09:05:23 -05:00
Sergio Garcia
dd63c16a74
fix(gcp): iterate through service projects ( #6549 )
...
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2025-01-16 08:52:52 -05:00
Pablo Lara
4280266a96
fix(dep): address compatibility issues ( #6543 )
2025-01-16 14:28:49 +01:00
Hugo Pereira Brito
b1f02098ff
feat(aws): include resource metadata in services from r* to s* ( #6536 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-15 18:10:53 -05:00
Pedro Martín
95189b574a
feat(gcp): add resource metadata to report ( #6500 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-15 18:09:35 -05:00
Hugo Pereira Brito
c5d23503bf
feat(aws): include resource metadata in services from a* to b* ( #6504 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-15 18:03:37 -05:00
Daniel Barranquero
77950f6069
chore(aws): add resource metadata to services from t to w ( #6546 )
2025-01-15 17:22:08 -05:00
Daniel Barranquero
ec5f2b3753
chore(aws): add resource metadata to services from f to o ( #6545 )
2025-01-15 17:15:50 -05:00
Rubén De la Torre Vico
9e7104fb7f
feat(defender): extract Defender resource metadata in automated way ( #6538 )
2025-01-15 12:14:24 -05:00
Rubén De la Torre Vico
6b3b6ca45e
feat(appinsights): extract App Insights resource metadata in automated way ( #6540 )
2025-01-15 11:45:23 -05:00
Hugo Pereira Brito
20b8b0b24e
feat: add resource metadata to emr_cluster_account_public_block_enabled ( #6539 )
2025-01-15 11:44:51 -05:00
Sergio Garcia
4e11540458
feat(kubernetes): add resource metadata to report ( #6479 )
2025-01-15 11:36:09 -05:00
Hugo Pereira Brito
ee87f2676d
feat(aws): include resource metadata in services from d* to e* ( #6532 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-15 10:05:04 -05:00
Daniel Barranquero
74a90aab98
feat(aws): add resource metadata to all services starting with c ( #6493 )
2025-01-15 09:04:19 -05:00
Rubén De la Torre Vico
48ff9a5100
feat(cosmosdb): extract CosmosDB resource metadata in automated way ( #6533 )
2025-01-15 08:51:48 -05:00
Rubén De la Torre Vico
3dfd578ee5
feat(containerregistry): extract Container Registry resource metadata in automated way ( #6530 )
2025-01-15 08:51:16 -05:00
Rubén De la Torre Vico
0db46cdc81
feat(azure-app): extract Web App resource metadata in automated way ( #6529 )
2025-01-15 08:48:36 -05:00
Prowler Bot
fdac58d031
chore(regions_update): Changes in regions for AWS services ( #6526 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-15 08:46:35 -05:00
dependabot[bot]
df9d4ce856
chore(deps): bump google-api-python-client from 2.158.0 to 2.159.0 ( #6521 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-15 08:33:47 -05:00
Pedro Martín
e6ae4e97e8
docs(readme): update pr template to add check for readme ( #6531 )
2025-01-15 12:12:45 +01:00
Adrián Jesús Peña Rodríguez
10a4c28922
feat(finding): add first_seen attribute ( #6460 )
2025-01-15 11:25:41 +01:00
dependabot[bot]
8a828c6e51
chore(deps): bump django from 5.1.4 to 5.1.5 in /api ( #6519 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-15 10:52:11 +01:00
Víctor Fernández Poyatos
d7b40905ff
feat(findings): Add resource_tag filters for findings endpoint ( #6527 )
2025-01-15 10:30:36 +01:00
Adrián Jesús Peña Rodríguez
f9a3b5f3cd
feat(provider-secret): make existing external_id field mandatory ( #6510 )
2025-01-15 10:14:44 +01:00
Pablo Lara
b73b89242f
feat(filters): add resource type filter for findings ( #6524 )
2025-01-15 08:40:53 +01:00
dependabot[bot]
23a0f6e8de
chore(deps-dev): bump eslint-config-prettier from 9.1.0 to 10.0.1 in /ui ( #6518 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-15 06:55:25 +01:00
Pedro Martín
87967abc3f
feat(kubernetes): add CIS 1.10 compliance ( #6508 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-14 14:16:00 -05:00
Rubén De la Torre Vico
ce60c286dc
feat(aks): use Check_Report_Azure constructor properly in AKS checks ( #6509 )
2025-01-14 14:14:02 -05:00
Pepe Fagoaga
90fd9b0eb8
chore(version): set next minor ( #6511 )
2025-01-14 14:06:24 -05:00
Prowler Bot
ca262a6797
chore(regions_update): Changes in regions for AWS services ( #6495 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-14 12:43:44 -05:00
Rubén De la Torre Vico
c056d39775
feat(aisearch): use Check_Report_Azure constructor properly in AISearch checks ( #6506 )
2025-01-14 12:37:01 -05:00
johannes-engler-mw
1c4426ea4b
fix(Azure TDE): add filter for master DB ( #6351 )
2025-01-14 12:34:52 -05:00
Pedro Martín
36520bd7a1
feat(azure): add CIS 3.0 for Azure ( #5226 )
2025-01-14 12:07:22 -05:00
Pepe Fagoaga
badf0ace76
feat(prowler-role): Add templates to deploy it in AWS ( #6499 )
2025-01-14 12:04:20 -05:00
Rubén De la Torre Vico
f1f61249e0
feat(azure): include resource metadata in Check_Report_Azure ( #6505 )
2025-01-14 11:32:40 -05:00
dependabot[bot]
b371cac18c
chore(deps): bump jinja2 from 3.1.4 to 3.1.5 ( #6457 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-14 10:03:45 -05:00
Víctor Fernández Poyatos
1846535d8d
feat(findings): add /findings/metadata to retrieve dynamic filters information ( #6503 )
2025-01-14 15:30:03 +01:00
dependabot[bot]
d7d9118b9b
chore(deps-dev): bump bandit from 1.8.0 to 1.8.2 ( #6485 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-14 08:49:37 -05:00
Pablo Lara
a65ca72177
chore(groups): Enable updating groups without roles or providers ( #6498 )
2025-01-14 11:16:13 +01:00
Pablo Lara
1108d90768
chore(roles): prevent capitalization of provider groups and roles ( #6497 )
2025-01-14 10:41:08 +01:00
Adrián Jesús Peña Rodríguez
6715aa351f
fix(rbac): block admin role deletion ( #6470 )
2025-01-14 10:27:41 +01:00
dependabot[bot]
851497eb0a
chore(deps): bump @radix-ui/react-slot from 1.1.0 to 1.1.1 in /ui ( #6481 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-14 10:25:14 +01:00
dependabot[bot]
3bb4663e3e
chore(deps-dev): bump eslint-plugin-import from 2.29.1 to 2.31.0 in /ui ( #6482 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-14 10:24:31 +01:00
Pablo Lara
6953fcf6b5
chore(rbac): tweaks role permissions ( #6496 )
2025-01-14 10:23:23 +01:00
Adrián Jesús Peña Rodríguez
ab844eee3f
ref(rbac): disable some checks ( #6471 )
2025-01-14 09:33:15 +01:00
Pedro Martín
708e06aa3b
fix(iso27001-2013): add ReqId and ReqDescription in output ( #6405 )
2025-01-13 13:14:09 -05:00
Prowler Bot
aa8b8bbcae
chore(regions_update): Changes in regions for AWS services ( #6459 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-13 12:41:11 -05:00
Pablo Lara
0ce1e15c2c
styles(invitations): tweak styles for invitation details box ( #6475 )
2025-01-13 18:32:33 +01:00
Pablo Lara
105a83d946
fix(invitation): correct the URL used to share an invitation ( #6472 )
2025-01-13 17:27:10 +01:00
Pedro Martín
e9a885a54d
feat(compliance): add CIS 3.0 for gcp ( #6463 )
2025-01-13 10:59:53 -05:00
Pablo Lara
0a8759ee06
chore(manage-groups): tweaks for provider manage groups ( #6468 )
2025-01-13 16:39:14 +01:00
Prowler Bot
33ec21bbac
chore(regions_update): Changes in regions for AWS services ( #6458 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-13 10:37:43 -05:00
dependabot[bot]
7c00f65ecc
chore(deps): bump @radix-ui/react-toast from 1.2.1 to 1.2.4 in /ui ( #6445 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-13 15:55:56 +01:00
Rubén De la Torre Vico
7777c8f135
fix(vpc): add new principal wildcard verification ( #6461 )
2025-01-13 09:49:10 -05:00
dependabot[bot]
2386490002
chore(deps-dev): bump openapi-schema-validator from 0.6.2 to 0.6.3 ( #6454 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-13 09:36:31 -05:00
Pepe Fagoaga
b620f12027
chore(rls): Add tenant_id filters in views and improve querysets ( #6211 )
...
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com >
2025-01-13 11:37:40 +01:00
Rubén De la Torre Vico
00722181ad
docs(azure): improve tutorials for Prowler App ( #6210 )
2025-01-13 09:59:58 +01:00
Sergio Garcia
15e888a939
feat(ec2): include resource metadata in Check_Report ( #6440 )
2025-01-13 13:04:55 +05:45
dependabot[bot]
43fa600f1c
chore(deps): bump date-fns from 3.6.0 to 4.1.0 in /ui ( #6444 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-11 08:35:18 +01:00
dependabot[bot]
2e4b5399c9
chore(deps): bump lucide-react from 0.417.0 to 0.471.0 in /ui ( #6456 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-11 08:34:47 +01:00
Prowler Bot
62cbb442e8
chore(regions_update): Changes in regions for AWS services ( #6448 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-10 11:36:43 -05:00
Pedro Martín
b0fe696935
refactor(mutelist): use jsonschema on mutelist ( #6264 )
2025-01-10 20:04:20 +05:45
Matt Johnson
42dbefbb31
feat: New gen-ai category for all relevant checks. ( #6450 )
2025-01-10 08:57:20 -05:00
Daniel Barranquero
f3dbe28681
fix(codeartifact): fix flaky tests ( #6449 )
2025-01-10 18:16:00 +05:45
Pedro Martín
6a5f1a7839
docs(integrations): add integrations docs ( #6269 )
2025-01-10 17:00:20 +05:45
Pedro Martín
3b70f9fed4
docs(outputs): add custom outputs formats documentation ( #6386 )
2025-01-10 16:54:50 +05:45
dependabot[bot]
7eb01aaa5c
chore(deps-dev): bump safety from 3.2.3 to 3.2.9 in /api ( #6431 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-10 16:31:19 +05:45
dependabot[bot]
1e27e52fba
chore(deps-dev): bump vulture from 2.11 to 2.14 in /api ( #6426 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-10 15:14:55 +05:45
dependabot[bot]
16d73619e4
chore(deps): bump boto3 from 1.35.93 to 1.35.94 ( #6410 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-09 19:29:59 -05:00
dependabot[bot]
bc82696f15
chore(deps): bump google-api-python-client from 2.157.0 to 2.158.0 ( #6442 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-09 18:16:23 -05:00
dependabot[bot]
fdb90623fc
chore(deps): bump trufflesecurity/trufflehog from 3.88.1 to 3.88.2 ( #6446 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-09 17:52:12 -05:00
Prowler Bot
5fa62a9770
chore(regions_update): Changes in regions for AWS services ( #6399 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-09 14:57:30 -05:00
Pablo Lara
8f3df7e45d
fix(BC: NextUI): fix BC from NextUI, resolve ESLint warnings and optimize hooks dependencies ( #6404 )
2025-01-09 17:37:33 +01:00
dependabot[bot]
bb417587ae
chore(deps-dev): bump @iconify/react from 5.0.1 to 5.2.0 in /ui ( #6421 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-09 17:05:11 +01:00
dependabot[bot]
6b6e12cea3
chore(deps): bump jinja2 from 3.1.4 to 3.1.5 in /api ( #6316 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-09 20:39:02 +05:45
Pepe Fagoaga
65e70b2ca4
chore(dependabot): Review for API and UI ( #6402 )
2025-01-09 20:28:26 +05:45
Pepe Fagoaga
94d25f6f6a
chore(containers): Build stable for API and UI ( #6395 )
2025-01-09 20:24:57 +05:45
Sergio Garcia
4bcf036831
fix(iam): handle non existing MFA devices ( #6396 )
2025-01-09 09:23:05 -05:00
dependabot[bot]
901bc69a7d
chore(deps): bump django from 5.1.1 to 5.1.4 in /api ( #6376 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-09 13:36:58 +01:00
Adrián Jesús Peña Rodríguez
465217442b
fix(api): change the inserted_at.lte unittest ( #6403 )
2025-01-09 13:12:55 +01:00
Pablo Lara
e6b40358aa
feat(update-credentials): add explanation text for the current behavior ( #6400 )
2025-01-09 11:13:36 +01:00
Daniel Barranquero
9d48f7286a
fix(cloudformation): fix flaky tests ( #6398 )
2025-01-09 15:30:11 +05:45
Prowler Bot
80311d3837
chore(regions_update): Changes in regions for AWS services ( #6390 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-08 12:28:24 -05:00
Pedro Martín
f501149068
fix(pre-commit): add api needed excludes ( #6393 )
2025-01-08 16:34:55 +01:00
dependabot[bot]
750de62828
chore(deps): bump botocore from 1.35.93 to 1.35.94 ( #6388 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-08 10:32:34 -05:00
Pablo Lara
d2f338ceb6
feat(scans): add new component - alert bar
2025-01-08 11:01:52 +01:00
dependabot[bot]
e8d66979b3
chore(deps): bump azure-mgmt-network from 28.0.0 to 28.1.0 ( #6296 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 16:09:53 -05:00
Sergio Garcia
b5180389f8
feat(aws): add new check cloudformation_stack_cdktoolkit_bootstrap_version ( #6323 )
2025-01-07 14:52:55 -05:00
dependabot[bot]
fbd5235e15
chore(deps): bump msgraph-sdk from 1.15.0 to 1.16.0 ( #6350 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 13:56:02 -05:00
dependabot[bot]
afd2267c26
chore(deps): bump microsoft-kiota-abstractions from 1.6.7 to 1.6.8 ( #6347 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 11:40:57 -05:00
dependabot[bot]
9e798ababd
chore(deps): bump google-api-python-client from 2.156.0 to 2.157.0 ( #6349 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 10:40:20 -05:00
Prowler Bot
e9f2fc8ee1
chore(regions_update): Changes in regions for AWS services ( #6382 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-07 10:11:24 -05:00
dependabot[bot]
12198b4f06
chore(deps): bump boto3 from 1.35.87 to 1.35.93 ( #6381 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 09:20:20 -05:00
Adrián Jesús Peña Rodríguez
15fae4d8f8
fix(ci): move poetry deprecated command to new one ( #6384 )
2025-01-07 12:38:33 +01:00
dependabot[bot]
3de3fed858
chore(deps): bump next from 14.2.12 to 14.2.22 in /ui ( #6356 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 12:29:06 +01:00
dependabot[bot]
1bf4255d93
chore(deps): bump cookie and next-auth in /ui ( #5880 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2025-01-07 12:03:45 +01:00
dependabot[bot]
b91a132e61
chore(deps): bump azure-mgmt-compute from 33.0.0 to 33.1.0 ( #6219 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-07 12:02:47 +01:00
dependabot[bot]
39302c9e93
chore(deps): bump botocore from 1.35.88 to 1.35.93 ( #6373 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2025-01-06 22:59:41 -05:00
dependabot[bot]
65e21c4268
chore(deps): bump trufflesecurity/trufflehog from 3.88.0 to 3.88.1 ( #6372 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-01-06 18:06:28 -05:00
Rubén De la Torre Vico
3d6a6a9fec
fix(aws): add missing sqs service without subservice ( #6352 )
2025-01-06 12:48:18 -05:00
Rubén De la Torre Vico
d185902c86
docs: add new format CloudFormation for ResourceType in check metadata ( #6353 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2025-01-06 10:25:00 -05:00
Prowler Bot
8ce4ad83ed
chore(regions_update): Changes in regions for AWS services ( #6329 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2025-01-06 10:16:57 -05:00
dependabot[bot]
89620a96bc
chore(deps): bump botocore from 1.35.87 to 1.35.88 ( #6321 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-27 12:21:12 -05:00
dependabot[bot]
f1c008f934
chore(deps-dev): bump coverage from 7.6.9 to 7.6.10 ( #6322 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-27 09:59:40 -05:00
dependabot[bot]
4d688c9b47
chore(deps): bump boto3 from 1.35.85 to 1.35.87 ( #6320 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-26 19:01:01 -05:00
dependabot[bot]
db5481cc9c
chore(deps-dev): bump pylint from 3.3.2 to 3.3.3 ( #6317 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-26 13:50:20 -05:00
dependabot[bot]
ce9a5e6484
chore(deps): bump botocore from 1.35.85 to 1.35.87 ( #6307 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-26 09:18:02 -05:00
Víctor Fernández Poyatos
550165b42b
feat(compliance): generate compliance reports for GCP scans using API ( #6318 )
2024-12-26 13:31:20 +01:00
Prowler Bot
080551132a
chore(regions_update): Changes in regions for AWS services ( #6299 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-23 08:35:48 -05:00
dependabot[bot]
0a61848365
chore(deps): bump boto3 from 1.35.83 to 1.35.85 ( #6295 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-23 07:41:45 -05:00
dependabot[bot]
fcb9ca7795
chore(deps): bump trufflesecurity/trufflehog from 3.87.2 to 3.88.0 ( #6298 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-23 07:41:23 -05:00
Víctor Fernández Poyatos
71c58cee9e
fix(migrations): fix django migration order dependency ( #6302 )
2024-12-23 12:26:00 +01:00
Sergio Garcia
c811b6715d
fix(gha): run API and UI tests in correct versions ( #6294 )
2024-12-23 11:47:51 +01:00
Kay Agahd
231829d8cd
fix(aws): disallow child-accounts to overwrite policy for ai_services_opt_out ( #6229 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2024-12-20 11:04:42 -05:00
dependabot[bot]
dbd2f8becb
chore(deps): bump botocore from 1.35.83 to 1.35.85 ( #6276 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-20 09:47:05 -05:00
Prowler Bot
cc04e6614e
chore(regions_update): Changes in regions for AWS services ( #6282 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-20 09:46:55 -05:00
Pablo Lara
a5c5ed614c
chore(menu): add API reference link to the sidebar ( #6287 )
2024-12-20 15:04:29 +01:00
Víctor Fernández Poyatos
ea13241317
fix(users): fix /users/me behavior when having more than 1 users in the same tenant ( #6284 )
2024-12-20 09:01:23 -05:00
Sergio Garcia
a377a9ff6a
chore(gha): solve pypi release github action ( #6278 )
2024-12-20 08:57:29 -05:00
Víctor Fernández Poyatos
f7e510b333
fix(db-utils): fix batch_delete function ( #6283 )
2024-12-20 08:55:21 -05:00
Pablo Lara
4472b80f1c
chore(findings): remove delta new as filter by default in findings ( #6280 )
2024-12-20 09:36:01 +01:00
dependabot[bot]
577eb3eec9
chore(deps): bump msgraph-sdk from 1.14.0 to 1.15.0 ( #6250 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-20 09:34:46 +01:00
dependabot[bot]
1ed6a1a40f
chore(deps): bump trufflesecurity/trufflehog from 3.87.1 to 3.87.2 ( #6279 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-19 17:51:41 -05:00
Sergio Garcia
fe4cd1cddf
fix(aws): add missing region to Backup Recovery Point ( #6273 )
2024-12-19 16:08:22 -05:00
Pablo Lara
6d7a8c8130
feat(roles): RBAC functionality ( #6201 )
2024-12-19 18:35:10 +01:00
dependabot[bot]
3057aeeacf
chore(deps): bump slack-sdk from 3.33.5 to 3.34.0 ( #6254 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-19 12:27:35 -05:00
Sergio Garcia
bb5b63f62f
fix(aws): solve None type errors ( #6268 )
2024-12-19 11:32:33 -05:00
Prowler Bot
58cd944618
chore(regions_update): Changes in regions for AWS services ( #6262 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-19 10:05:09 -05:00
Daniel Barranquero
5964b68c86
feat(codeartifact): add new fixer codeartifact_packages_external_public_publishing_disabled_fixer ( #6263 )
2024-12-19 10:05:01 -05:00
Pepe Fagoaga
c87aaeba04
chore(api): Use prowler ^5.0 ( #6266 )
2024-12-19 09:40:51 -05:00
dependabot[bot]
6e361005dc
chore(deps): bump trufflesecurity/trufflehog from 3.87.0 to 3.87.1 ( #6249 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-19 09:02:44 -05:00
dependabot[bot]
f5ab254bc5
chore(deps): bump microsoft-kiota-abstractions from 1.6.6 to 1.6.7 ( #6233 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-19 09:02:01 -05:00
dependabot[bot]
298392b409
chore(deps): bump google-api-python-client from 2.155.0 to 2.156.0 ( #6252 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-19 11:10:10 +01:00
Twodragon
74a2bf0721
feat(prowler-docker): Run Prowler docker with AWS SSO ( #5867 )
...
Co-authored-by: twodragon114 <twodragon114@gmail.com >
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2024-12-19 10:55:15 +01:00
dependabot[bot]
ddc5dc0316
chore(deps): bump boto3 from 1.35.81 to 1.35.83 ( #6253 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-19 09:45:16 +01:00
Pepe Fagoaga
d3af947553
fix(gha): make conditional job for checking the repo ( #6255 )
2024-12-19 14:19:41 +05:45
Pepe Fagoaga
36bb2509ac
docs: add note about platform flag in docker ( #6256 )
2024-12-19 14:18:16 +05:45
Pepe Fagoaga
e4c2b0c2d3
chore: skip action on .env changes ( #6257 )
2024-12-19 14:17:56 +05:45
Víctor Fernández Poyatos
ac5260ad43
feat(celery): Add configurable broker visibility timeout setting ( #6245 )
2024-12-19 00:03:11 +05:45
Adrián Jesús Peña Rodríguez
33857109c9
ref(rbac): enable relationship creation when objects is created ( #6238 )
2024-12-18 16:45:32 +01:00
Pepe Fagoaga
8cc8f76204
fix(.env): remove comment ( #6230 )
2024-12-18 20:36:03 +05:45
Pedro Martín
8f3229928e
chore(config): set default values for empty config fields ( #6225 )
2024-12-18 09:48:32 -05:00
Pedro Martín
2551992fd8
fix(docs): change typo from provideruid in k8s ( #6239 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2024-12-18 09:02:44 -05:00
Prowler Bot
eb1decfce1
chore(regions_update): Changes in regions for AWS services ( #6237 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-18 08:51:22 -05:00
Pepe Fagoaga
fd5e7b809f
docs: add note about containers arch ( #6236 )
2024-12-18 11:09:35 +01:00
dependabot[bot]
1ac681226d
chore(deps): bump botocore from 1.35.81 to 1.35.83 ( #6232 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-17 18:52:46 -05:00
dependabot[bot]
366940298d
chore(deps): bump trufflesecurity/trufflehog from 3.86.1 to 3.87.0 ( #6234 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-17 18:51:32 -05:00
Adrián Jesús Peña Rodríguez
fa400ded7d
ref(rbac): improve rbac implementation for views ( #6226 )
2024-12-17 18:11:48 +01:00
dependabot[bot]
ec9455ff75
chore(deps): bump boto3 from 1.35.80 to 1.35.81 ( #6218 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-17 11:32:30 -05:00
Daniel Barranquero
2183f31ff5
feat(ec2): add new fixers for internet exposed ports ( #6223 )
2024-12-17 10:04:00 -05:00
Prowler Bot
67257a4212
chore(regions_update): Changes in regions for AWS services ( #6222 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-17 10:00:52 -05:00
Pedro Martín
001fa60a11
feat(mutelist): add description field ( #6221 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2024-12-17 15:13:55 +01:00
Víctor Fernández Poyatos
0ec3ed8be7
feat(services): Add GET /overviews/services to API ( #6029 )
2024-12-17 08:47:44 +01:00
dependabot[bot]
3ed0b8a464
chore(deps-dev): bump mkdocs-material from 9.5.48 to 9.5.49 ( #6217 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-17 08:42:55 +01:00
Pedro Martín
fd610d44c0
refactor(gcp): use always <client>.region for checks ( #6206 )
2024-12-16 18:21:42 -05:00
Adrián Jesús Peña Rodríguez
b8cc4b4f0f
feat(stepfunctions): add stepfunctions service and check stepfunctions_statemachine_logging_enabled ( #5466 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
Co-authored-by: Rubén De la Torre Vico <rubendltv22@gmail.com >
2024-12-16 11:34:02 -05:00
Pedro Martín
396e51c27d
feat(gcp): add service account credentials ( #6165 )
2024-12-16 10:11:32 -05:00
Daniel Barranquero
36e61cb7a2
feat(ec2): add new fixer ec2_ami_public_fixer ( #6177 )
2024-12-16 10:09:14 -05:00
Daniel Barranquero
78c6484ddb
feat(cloudtrail): add new fixer cloudtrail_logs_s3_bucket_is_not_publicly_accessible_fixer ( #6174 )
2024-12-16 10:05:34 -05:00
Daniel Barranquero
3f1e90a5b3
feat(s3): add new fixer s3_bucket_policy_public_write_access_fixer ( #6173 )
2024-12-16 10:01:38 -05:00
dependabot[bot]
e1bfec898f
chore(deps): bump botocore from 1.35.80 to 1.35.81 ( #6199 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-16 09:57:03 -05:00
dependabot[bot]
b5b816dac9
chore(deps): bump boto3 from 1.35.79 to 1.35.80 ( #6198 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-16 07:51:44 -05:00
Pepe Fagoaga
57854f23b7
chore(rls): rename tenant_transaction to rls_transaction ( #6202 )
2024-12-16 12:27:55 +01:00
Rubén De la Torre Vico
9d7499b74f
fix(azure): custom Prowler Role for Azure assignableScopes ( #6149 )
2024-12-16 08:34:17 +01:00
dependabot[bot]
5b0b85c0f8
chore(deps): bump actions/setup-node from 3 to 4 ( #5893 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-13 14:57:27 +01:00
Pedro Martín
f7e8df618b
chore(labeler): add provider github ( #6194 )
2024-12-13 09:43:49 -04:00
Adrián Jesús Peña Rodríguez
d00d254c90
feat(api): RBAC system ( #6114 )
2024-12-13 14:14:40 +01:00
dependabot[bot]
f9fbde6637
chore(deps): bump botocore from 1.35.79 to 1.35.80 ( #6172 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-13 13:20:40 +01:00
Sergio Garcia
7b1a0474db
fix(aws): set unique resource IDs ( #6152 )
2024-12-13 13:00:38 +01:00
Pepe Fagoaga
da4f9b8e5f
fix(RLS): enforce config security ( #6066 )
2024-12-13 12:55:09 +01:00
Pepe Fagoaga
32f69d24b6
fix: dependabot syntax ( #6181 )
2024-12-13 12:20:43 +01:00
Pepe Fagoaga
d032a61a9e
chore(dependabot): Add docker ( #6180 )
2024-12-13 12:13:53 +01:00
dependabot[bot]
07e0dc2ef5
chore(deps): bump cross-spawn from 7.0.3 to 7.0.6 in /ui ( #5881 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2024-12-13 08:25:57 +01:00
dependabot[bot]
9e175e8504
chore(deps): bump nanoid from 3.3.7 to 3.3.8 in /ui ( #6110 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-13 07:59:50 +01:00
dependabot[bot]
6b8a434cda
chore(deps): bump boto3 from 1.35.78 to 1.35.79 ( #6171 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-13 07:58:58 +01:00
Pepe Fagoaga
554491a642
chore(gha): build and push OSS UI ( #6168 )
2024-12-12 19:10:44 +01:00
Pedro Martín
dc4e2f3c85
feat(GHA): build containers for API ( #6032 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2024-12-12 19:05:25 +01:00
Daniel Barranquero
7d2c50991b
feat(s3): add new fixer s3_bucket_public_access_fixer ( #6164 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2024-12-12 12:17:41 -04:00
Pedro Martín
83c204e010
fix(rds): add invalid SG to status_extended ( #6157 )
2024-12-12 11:51:09 -04:00
dependabot[bot]
316eb049dd
chore(deps): bump botocore from 1.35.78 to 1.35.79 ( #6153 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-12 11:29:23 -04:00
Daniel Barranquero
be347b2428
feat(ec2): add new check ec2_launch_template_imdsv2_required ( #6139 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2024-12-12 11:27:20 -04:00
Daniel Barranquero
a90c772827
feat(s3): add new fixer s3_bucket_public_list_acl_fixer ( #6166 )
2024-12-12 11:16:46 -04:00
Daniel Barranquero
26c70976c0
feat(s3): add new fixer s3_bucket_public_write_acl_fixer ( #5855 )
2024-12-12 11:10:43 -04:00
dependabot[bot]
657310dc25
chore(deps): bump boto3 from 1.35.77 to 1.35.78 ( #6154 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-12 10:39:22 -04:00
Daniel Barranquero
6e595eaf92
feat(ec2): add new fixer ec2_instance_port_cifs_exposed_to_internet_fixer ( #6159 )
2024-12-12 09:22:56 -04:00
Prowler Bot
997831e33d
chore(regions_update): Changes in regions for AWS services ( #6158 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-12 09:10:46 -04:00
dependabot[bot]
5920cdc48f
chore(deps): bump trufflesecurity/trufflehog from 3.86.0 to 3.86.1 ( #6156 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-12 09:10:20 -04:00
dependabot[bot]
971e73f9cb
chore(deps): bump google-api-python-client from 2.154.0 to 2.155.0 ( #6155 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-12 09:09:51 -04:00
Mads Brouer Lundholm
bd9673c9de
fix(aurora): Add default ports to the check of using non default ports ( #5821 )
...
Co-authored-by: Mads Rantala Lundholm <mao@bankdata.dk >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2024-12-11 13:01:45 -04:00
johannes-engler-mw
eded97d735
feat(azure): check for minimal TLS version for Azure SQL server ( #5745 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
2024-12-11 16:37:53 +01:00
Daniel Barranquero
fdb1956b0b
feat(opensearch): add new fixer opensearch_service_domains_not_publicly_accessible_fixer ( #5926 )
2024-12-11 11:29:48 -04:00
Daniel Barranquero
a915c04e9e
fix(autoscaling): autoscaling_group_launch_configuration_requires_imdsv2 fails if Launch Template is used ( #6111 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2024-12-11 11:18:30 -04:00
Daniel Barranquero
07178ac69a
feat(glacier): add new fixer glacier_vaults_policy_public_access_fixer ( #5950 )
2024-12-11 11:10:12 -04:00
Daniel Barranquero
9b434d4856
feat(ecr): add new fixer ecr_repositories_not_publicly_accessible_fixer ( #5923 )
2024-12-11 10:42:11 -04:00
dependabot[bot]
0758e97628
chore(deps): bump botocore from 1.35.77 to 1.35.78 ( #6132 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-11 10:19:37 -04:00
Sergio Garcia
b486007f95
fix(README): show latest release ( #6145 )
2024-12-11 10:19:06 -04:00
dependabot[bot]
0c0887afef
chore(deps): bump trufflesecurity/trufflehog from 3.85.0 to 3.86.0 ( #6130 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-11 09:29:14 -04:00
dependabot[bot]
805ed81031
chore(deps): bump boto3 from 1.35.76 to 1.35.77 ( #6131 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-11 09:26:07 -04:00
Prowler Bot
ec3fddf5b1
chore(regions_update): Changes in regions for AWS services ( #6136 )
...
Co-authored-by: MrCloudSec <38561120+MrCloudSec@users.noreply.github.com >
2024-12-11 09:25:17 -04:00
Rubén De la Torre Vico
d7b0bc02ba
feat(app): add support for TLS 1.3 to Web Apps check ( #6004 )
2024-12-11 13:14:29 +01:00
Pablo Lara
4d1c8eae8f
feat(users): user detail can be edited now properly ( #6135 )
2024-12-11 10:05:30 +01:00
Sergio Garcia
989ccf4ae3
fix(iam): set unique resource id for each user access key ( #6128 )
2024-12-11 09:13:49 +01:00
Pedro Martín
9c089756c3
fix(compliance_tables): add correct values for findings ( #6122 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2024-12-10 15:40:45 -04:00
Hugo Pereira Brito
8d4b0914a8
fix(aws): get firewall manager managed rule groups ( #6119 )
2024-12-10 15:34:22 -04:00
Hugo Pereira Brito
1ae3f89aab
fix(aws): check AWS Owned keys in firehose_stream_encrypted_at_rest ( #6108 )
2024-12-10 13:42:13 -04:00
Daniel Barranquero
b984f0423a
feat(sqs): add new fixer sqs_queues_not_publicly_accessible_fixer ( #5911 )
...
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com >
2024-12-10 12:26:42 -04:00
Sergio Garcia
f2f196cfcd
fix(aws): set IAM identity as resource in threat detection ( #6048 )
2024-12-10 17:03:01 +01:00
dependabot[bot]
6471d936bb
chore(deps): bump msgraph-sdk from 1.12.0 to 1.14.0 ( #5957 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-10 11:42:40 -04:00
Adrián Jesús Peña Rodríguez
21bbdccc41
fix(deploy): temporal fix for the alpine-python segmentation fault ( #6109 )
2024-12-10 16:27:52 +01:00
Sergio Garcia
48946fa4f7
fix(gcp): make sure default project is active ( #6097 )
2024-12-10 11:06:48 -04:00
dependabot[bot]
9312dda7c2
chore(deps): bump microsoft-kiota-abstractions from 1.6.2 to 1.6.6 ( #6038 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-10 10:37:04 -04:00
dependabot[bot]
e3013329ee
chore(deps): bump botocore from 1.35.76 to 1.35.77 ( #6098 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-10 09:26:36 -04:00
Sergio Garcia
38a0d2d740
fix(aws): set same severity for EC2 IMDSv2 checks ( #6046 )
2024-12-10 08:55:41 +01:00
Mario Rodriguez Lopez
5c2adf1e14
docs(unitesting): Make some fixes to the documentation ( #6102 )
2024-12-10 08:51:19 +01:00
Daniel Barranquero
7ddd2c04c8
feat(awslambda): add new fixer awslambda_function_not_publicly_accessible_fixer ( #5840 )
2024-12-09 12:28:42 -04:00
Pepe Fagoaga
9a55632d8e
fix(backport): more than one backport tag is allowed ( #6090 )
2024-12-09 17:19:33 +01:00
dependabot[bot]
f8b4427505
chore(deps-dev): bump vulture from 2.13 to 2.14 ( #6068 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-09 11:10:41 -04:00
Sergio Garcia
f1efc1456d
chore(dependabot): change interval of PRs ( #6086 )
2024-12-09 15:46:28 +01:00
Sergio Garcia
2ea5851b67
docs(api): add commands to run API scheduler ( #6085 )
2024-12-09 10:34:02 -04:00
dependabot[bot]
a3051bc4e3
chore(deps-dev): bump mkdocs-material from 9.5.47 to 9.5.48 ( #6073 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-09 10:14:08 -04:00
Pepe Fagoaga
d454427b8b
fix(backport): remove v from branch prefix ( #6081 )
2024-12-09 10:13:20 -04:00
Pepe Fagoaga
4b41bd6adf
chore(containers): support for v4.6 branch ( #6063 )
...
Co-authored-by: MrCloudSec <hello@mistercloudsec.com >
2024-12-09 09:23:06 -04:00
Pepe Fagoaga
cdd044d120
chore(dependabot): Update for UI and v4 ( #6062 )
2024-12-09 09:15:03 -04:00
Pepe Fagoaga
213a793fbc
chore(actions): standardize names ( #6059 )
2024-12-09 09:14:06 -04:00
Pepe Fagoaga
a8a567c588
docs: Prowler SaaS -> Cloud and add missing compliance ( #6061 )
2024-12-09 09:12:54 -04:00
Pepe Fagoaga
fefe89a1ed
fix(backport): Add action to detect labels ( #5270 )
2024-12-09 09:12:08 -04:00
Sergio Garcia
493fe2d523
docs(env): move warning about env files ( #6049 )
2024-12-09 11:11:05 +01:00
dependabot[bot]
d8fc830f1d
chore(deps): bump boto3 from 1.35.71 to 1.35.76 ( #6054 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-09 10:11:51 +01:00
Pepe Fagoaga
b6c3ba0f0d
chore: delete unneeded requirements file ( #6056 )
2024-12-09 09:07:10 +01:00
dependabot[bot]
32cd39d158
chore(deps-dev): bump coverage from 7.6.8 to 7.6.9 ( #6053 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 20:29:06 -04:00
dependabot[bot]
203275817f
chore(deps-dev): bump pytest from 8.3.3 to 8.3.4 ( #5992 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 12:53:11 -04:00
dependabot[bot]
c05c3396b5
chore(deps-dev): bump mkdocs-material from 9.5.46 to 9.5.47 ( #5988 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 11:56:37 -04:00
dependabot[bot]
8f172aec8a
chore(deps-dev): bump pylint from 3.3.1 to 3.3.2 ( #5993 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 11:04:28 -04:00
dependabot[bot]
263a7e2134
chore(deps): bump botocore from 1.35.71 to 1.35.76 ( #6037 )
2024-12-06 09:41:57 -04:00
dependabot[bot]
a2ea216604
chore(deps): bump slack-sdk from 3.33.4 to 3.33.5 ( #6039 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 08:44:00 -04:00
dependabot[bot]
77c572f990
chore(deps): bump trufflesecurity/trufflehog from 3.84.1 to 3.85.0 ( #6040 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 08:38:14 -04:00
Prowler Bot
bb0c346c4d
chore(regions_update): Changes in regions for AWS services ( #6041 )
...
Co-authored-by: sergargar <38561120+sergargar@users.noreply.github.com >
2024-12-06 08:38:03 -04:00
Daniel Barranquero
2ce8e1fd21
fix(backup): modify list recovery points call ( #5996 )
2024-12-06 08:35:29 -04:00
Pepe Fagoaga
ecfd94aeb1
fix(codecov): create components ( #6028 )
2024-12-05 16:35:56 +01:00
Pedro Martín
eddc672264
chore(version): update prowler version ( #6027 )
2024-12-05 13:51:13 +01:00
Pedro Martín
8c71a39487
docs(prowler-app): add link to https://api.prowler.com/api/v1/docs ( #6016 )
2024-12-05 11:01:51 +01:00
Pedro Martín
ff0ac27723
docs(index): update index with images ( #6015 )
2024-12-05 11:01:42 +01:00
Víctor Fernández Poyatos
ad7134d283
fix(tenant): fix delete tenants behavior ( #6013 )
2024-12-04 13:57:16 +01:00
Pablo Lara
58723ae52e
fix(invitations): remove wrong url ( #6005 )
2024-12-03 21:08:31 +01:00