mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
93c9470eb6 | ||
|
|
ab325c9099 | ||
|
|
6fe8646903 | ||
|
|
9b0c4a0073 |
@@ -158,7 +158,7 @@ SENTRY_RELEASE=local
|
||||
# REO_DEV_CLIENT_ID=
|
||||
|
||||
#### Prowler release version ####
|
||||
NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.35.0
|
||||
NEXT_PUBLIC_PROWLER_RELEASE_VERSION=v5.35.1
|
||||
|
||||
# Social login credentials
|
||||
SOCIAL_GOOGLE_OAUTH_CALLBACK_URL="${AUTH_URL}/api/auth/callback/google"
|
||||
|
||||
+2
-2
@@ -45,7 +45,7 @@ dependencies = [
|
||||
"gunicorn==26.0.0",
|
||||
"uvloop==0.22.1",
|
||||
"lxml==6.1.0",
|
||||
"prowler @ git+https://github.com/prowler-cloud/prowler.git@master",
|
||||
"prowler @ git+https://github.com/prowler-cloud/prowler.git@v5.35",
|
||||
"psycopg2-binary==2.9.9",
|
||||
"pytest-celery[redis] (==1.3.0)",
|
||||
"sentry-sdk[django] (==2.56.0)",
|
||||
@@ -71,7 +71,7 @@ name = "prowler-api"
|
||||
package-mode = false
|
||||
# Needed for the SDK compatibility
|
||||
requires-python = ">=3.11,<3.13"
|
||||
version = "1.36.0"
|
||||
version = "1.36.1"
|
||||
|
||||
# Shared ruff baseline (kept in sync with mcp_server/pyproject.toml).
|
||||
# target-version tracks this project's lowest supported Python.
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
openapi: 3.0.3
|
||||
info:
|
||||
title: Prowler API
|
||||
version: 1.36.0
|
||||
version: 1.36.1
|
||||
description: |-
|
||||
Prowler API specification.
|
||||
|
||||
|
||||
Generated
+3
-3
@@ -4674,7 +4674,7 @@ wheels = [
|
||||
[[package]]
|
||||
name = "prowler"
|
||||
version = "5.35.0"
|
||||
source = { git = "https://github.com/prowler-cloud/prowler.git?rev=master#f5ea116763aeffede9f399c8934fc280eaccd315" }
|
||||
source = { git = "https://github.com/prowler-cloud/prowler.git?rev=v5.35#1459046985908c099bd2b2e279530e8a47bccdf8" }
|
||||
dependencies = [
|
||||
{ name = "alibabacloud-actiontrail20200706" },
|
||||
{ name = "alibabacloud-credentials" },
|
||||
@@ -4762,7 +4762,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "prowler-api"
|
||||
version = "1.36.0"
|
||||
version = "1.36.1"
|
||||
source = { virtual = "." }
|
||||
dependencies = [
|
||||
{ name = "cartography" },
|
||||
@@ -4862,7 +4862,7 @@ requires-dist = [
|
||||
{ name = "matplotlib", specifier = "==3.10.8" },
|
||||
{ name = "neo4j", specifier = "==6.1.0" },
|
||||
{ name = "openai", specifier = "==1.109.1" },
|
||||
{ name = "prowler", git = "https://github.com/prowler-cloud/prowler.git?rev=master" },
|
||||
{ name = "prowler", git = "https://github.com/prowler-cloud/prowler.git?rev=v5.35" },
|
||||
{ name = "psycopg2-binary", specifier = "==2.9.9" },
|
||||
{ name = "pytest-celery", extras = ["redis"], specifier = "==1.3.0" },
|
||||
{ name = "reportlab", specifier = "==4.4.10" },
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Alibaba Cloud SSH and RDP security group checks no longer produce false negatives when allowed rules use capitalized `Policy="Accept"` values
|
||||
@@ -49,7 +49,7 @@ class _MutableTimestamp:
|
||||
|
||||
timestamp = _MutableTimestamp(datetime.today())
|
||||
timestamp_utc = _MutableTimestamp(datetime.now(timezone.utc))
|
||||
prowler_version = "5.35.0"
|
||||
prowler_version = "5.35.1"
|
||||
html_logo_url = "https://github.com/prowler-cloud/prowler/"
|
||||
square_logo_img = "https://raw.githubusercontent.com/prowler-cloud/prowler/dc7d2d5aeb92fdf12e8604f42ef6472cd3e8e889/docs/img/prowler-logo-black.png"
|
||||
aws_logo = "https://user-images.githubusercontent.com/38561120/235953920-3e3fba08-0795-41dc-b480-9bea57db9f2e.png"
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@ class ecs_securitygroup_restrict_rdp_internet(Check):
|
||||
|
||||
for ingress_rule in security_group.ingress_rules:
|
||||
# Check if rule allows traffic (policy == "accept")
|
||||
if ingress_rule.get("policy", "accept") != "accept":
|
||||
if str(ingress_rule.get("policy", "accept")).lower() != "accept":
|
||||
continue
|
||||
|
||||
# Check protocol (tcp for RDP)
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@ class ecs_securitygroup_restrict_ssh_internet(Check):
|
||||
|
||||
for ingress_rule in security_group.ingress_rules:
|
||||
# Check if rule allows traffic (policy == "accept")
|
||||
if ingress_rule.get("policy", "accept") != "accept":
|
||||
if str(ingress_rule.get("policy", "accept")).lower() != "accept":
|
||||
continue
|
||||
|
||||
# Check protocol (tcp for SSH)
|
||||
|
||||
+1
-1
@@ -125,7 +125,7 @@ maintainers = [{name = "Prowler Engineering", email = "engineering@prowler.com"}
|
||||
name = "prowler"
|
||||
readme = "README.md"
|
||||
requires-python = ">=3.10,<3.14"
|
||||
version = "5.35.0"
|
||||
version = "5.35.1"
|
||||
|
||||
[project.scripts]
|
||||
prowler = "prowler.__main__:prowler"
|
||||
|
||||
+2
-2
@@ -37,7 +37,7 @@ class TestEcsSecurityGroupRestrictRdpInternet:
|
||||
"ip_protocol": "tcp",
|
||||
"source_cidr_ip": "0.0.0.0/0",
|
||||
"port_range": "3389/3389",
|
||||
"policy": "accept",
|
||||
"policy": "Accept",
|
||||
}
|
||||
],
|
||||
)
|
||||
@@ -80,7 +80,7 @@ class TestEcsSecurityGroupRestrictRdpInternet:
|
||||
"ip_protocol": "tcp",
|
||||
"source_cidr_ip": "10.0.0.0/24",
|
||||
"port_range": "3389/3389",
|
||||
"policy": "accept",
|
||||
"policy": "Accept",
|
||||
}
|
||||
],
|
||||
)
|
||||
|
||||
+2
-2
@@ -37,7 +37,7 @@ class TestEcsSecurityGroupRestrictSSHInternet:
|
||||
"ip_protocol": "tcp",
|
||||
"source_cidr_ip": "0.0.0.0/0",
|
||||
"port_range": "22/22",
|
||||
"policy": "accept",
|
||||
"policy": "Accept",
|
||||
}
|
||||
],
|
||||
)
|
||||
@@ -81,7 +81,7 @@ class TestEcsSecurityGroupRestrictSSHInternet:
|
||||
"ip_protocol": "tcp",
|
||||
"source_cidr_ip": "10.0.0.0/24",
|
||||
"port_range": "22/22",
|
||||
"policy": "accept",
|
||||
"policy": "Accept",
|
||||
}
|
||||
],
|
||||
)
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
AWS Organizations setup modal now shows the "Enter a valid Organizational Unit or Root ID" hint in the error color, clarifying why the deployment button is disabled
|
||||
@@ -486,7 +486,7 @@ export function OrgSetupForm({
|
||||
</Button>
|
||||
)}
|
||||
{!isOrgUnitIdValid && (
|
||||
<p className="text-text-neutral-tertiary text-xs leading-5">
|
||||
<p className="text-text-error-primary text-xs leading-5">
|
||||
Enter a valid Organizational Unit or Root ID above to enable
|
||||
deployment.
|
||||
</p>
|
||||
|
||||
Reference in New Issue
Block a user