mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
10 KiB
10 KiB
Prowler MCP Server Changelog
All notable changes to the Prowler MCP Server are documented in this file.
[0.12.2] (Prowler v5.43.0)
🔐 Security
- Bumped
anyioto 4.14.2 to resolve CVE-2026-63374 (#12848)
[0.12.1] (Prowler v5.42.0)
🔐 Security
libuuidupgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410 (#12780)
[0.12.0] (Prowler v5.41.0)
🚀 Added
- Prowler App tools now report a failure as an MCP tool execution error (
isError: true, explanation incontent) instead of as a successful result carrying an{"error": ...}object, which clients and models read as a success (#12532)
🔄 Changed
prowler_get_compliance_framework_state_detailsnow rejects a call that passes bothscan_idandprovider_idinstead of silently ignoring the provider, which could report on a scan belonging to a different provider than the one that was asked about (#12532)
🐞 Fixed
prowler_hub_get_check_codeandprowler_hub_get_check_fixernow report a check ID that belongs to another provider as such, naming that provider, instead of reporting the ID as one that does not exist (#12533)prowler_docs_searchno longer reports a failed search as zero matches or an unreadable answer as a bad search term, andprowler_docs_get_documentno longer reports a failed fetch as a missing page (#12534)
[0.11.0] (Prowler v5.40.0)
🚀 Added
- Failures shared by every tool - a rejected credential, a missing permission, a rate limit, an outage, an unreachable API, a bad argument - are now explained with a message that says what went wrong and what to do about it (#12531)
🐞 Fixed
prowler_docs_searchreturns results again: it calls the search endpoint docs.prowler.com moved to, since the one it used no longer exists, and each result now names the page's title, the section it matched and a URL anchored at that section (#12578)
🔐 Security
- Stop relaying upstream response bodies to agents: a failed request now reaches the caller as a sentence this server wrote, with the full body kept to the logs, so a gateway error page or a debug traceback can no longer be replayed into a model's context (#12531)
sqlite-libsupgraded to 3.53.4-r0 in the container image, patching CVE-2026-11822 and CVE-2026-11824 (#12537)libcrypto3andlibssl3upgraded to 3.5.8-r0 in the container image, patching CVE-2026-14456 (#12547)
[0.10.0] (Prowler v5.38.0)
🚀 Added
- Test foundation for the MCP server with shared fixtures, JSON:API builders, mocked HTTP transports and CI coverage reporting (#12291)
- Test coverage for the integrations tools and models, pinning the connection-check choreography and the Jira dispatch retry safety (#12343)
- Container images now ship an SBOM and build provenance as OCI attestations (#12352)
🔄 Changed
prowler_send_findings_to_jiranow reportssafe_to_retryon every outcome, true only when Prowler knows no Jira work item was created: a dispatch the API refused is retryable, one that failed on the server or got no answer is not (#12343)prowler_list_integrationsno longer requests theconfigurationit discards, now that the API tolerates a sparse fieldset without it (#12343)
🔐 Security
- Upgrade cryptography to 50.0.0, closing CVE-2026-69247 and CVE-2026-69249 (#12356)
[0.9.1] (Prowler v5.37.1)
🔐 Security
- Bumped
fastmcpand pinnedcryptography,joserfc,mcpandpython-multipart, clearing all 7 high-severity CVEs from the MCP image (#12307)
[0.9.0] (Prowler v5.37.0)
🚀 Added
- Read-only user management tools
prowler_list_users,prowler_get_user, andprowler_get_current_userfor listing tenant users with their emails and identifying the authenticated user (#12088) - RBAC role tools
prowler_list_roles,prowler_get_role,prowler_get_user_roles, andprowler_set_user_rolefor browsing roles and setting the role a user holds (#12088) - Integrations tools to manage Amazon S3, AWS Security Hub and Jira integrations, and to send findings to Jira (#12138)
🔄 Changed
- README now documents the Cloud-only
prowler_cloud_*tools available on the hosted Prowler MCP (alerts, findings triage, scan scheduling, scan configurations), and corrects the Prowler Hub check count and the scan orchestration capabilities (#12266)
🐞 Fixed
- Memory leak in HTTP mode caused by streamable-HTTP sessions being retained for the process lifetime when clients never sent
DELETE /mcp; the server now runs stateless (#12235) prowler_list_integrationsfailing with a 500 error on tenants with a Jira integration, caused by the request leavingconfigurationout of the sparse fieldset (#12259)
[0.8.0] (Prowler v5.35.0)
🔄 Changed
- Core Prowler tool namespace from the
prowler_app_*prefix toprowler_*(#12017)
[0.7.2] (Prowler v5.28.1)
🐞 Fixed
- Preserve authorization header in HTTP mode (#11366)
[0.7.1] (Prowler v5.28.0)
🔐 Security
fastmcpfrom 2.14.0 to 3.2.4 for GHSA-5h2m-4q8j-pqpj, GHSA-rww4-4w9c-7733, and GHSA-vv7q-7jx5-f767, which also pulls fixedjaraco.context,python-multipart,starlette, and drops the vulnerablelupa/urllib3transitive deps (#11284)
[0.7.0] (Prowler v5.27.0)
🚀 Added
- Finding Groups tools (#11140)
🔐 Security
cryptographyfrom 46.0.1 to 47.0.0 (transitive) for CVE-2026-39892 and CVE-2026-26007 / CVE-2026-34073 (#10978)
[0.6.0] (Prowler v5.23.0)
🚀 Added
- Resource events tool to get timeline for a resource (who, what, when) (#10412)
🔄 Changed
- Pin
httpxdependency to exact version for reproducible installs (#10593)
🔐 Security
authlibbumped from 1.6.5 to 1.6.9 to fix CVE-2026-28802 (JWTalg: nonevalidation bypass) (#10579)
[0.5.0] (Prowler v5.21.0)
🚀 Added
- Attack Path tool to get Neo4j DB schema (#10321)
[0.4.0] (Prowler v5.19.0)
🚀 Added
- Attack Paths tools to list scans, discover queries, and run Cypher queries against Neo4j (#10145)
[0.3.0] (Prowler v5.16.0)
🚀 Added
- MCP Server tools for Prowler Compliance Framework Management (#9568)
🔄 Changed
- API base URL environment variable to include complete path (#9542)
- Prowler Hub and Docs tools format standardized for AI optimization (#9578)
[0.2.0] (Prowler v5.15.0)
🚀 Added
- MCP Server tools for Prowler Findings and Compliance, replacing all Prowler App MCP tools (#9300)
- MCP Server tools for Prowler Providers Management (#9350)
- MCP Server tools for Prowler Resources Management (#9380)
- MCP Server tools for Prowler Scans Management (#9509)
- MCP Server tools for Prowler Muting Management (#9510)
[0.1.1] (Prowler v5.14.0)
🐞 Fixed
- Documentation MCP Server to return list of dictionaries (#9205)
[0.1.0] (Prowler v5.13.0)
🚀 Added
- Initial release of Prowler MCP Server (#8695)
- Appropriate user-agent in requests (#8724)
- Basic logger functionality (#8740)
- MCP Server for Prowler Cloud and Prowler App (Self-Managed) APIs (#8744)
- HTTP transport support (#8784)
- MCP Server for Prowler Documentation (#8795)
- API key support for STDIO mode and enhanced HTTP mode authentication (#8823)
- Health check endpoint (#8905)
- Prowler Documentation MCP Server updated to use Mintlify API (#8916)
- Custom production deployment using uvicorn (#8958)