mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
185 KiB
185 KiB
Prowler SDK Changelog
All notable changes to the Prowler SDK are documented in this file.
[5.42.0] (Prowler v5.42.0)
🚀 Added
- AWS ISO partitions (
aws-iso,aws-iso-b,aws-iso-eandaws-iso-f) to the AWS service region matrix, generated from the endpoints data bundled with botocore (#12759) --aws-connect-timeoutand--aws-read-timeoutCLI flags, plusPROWLER_AWS_BOTO3_CONNECT_TIMEOUTandPROWLER_AWS_BOTO3_READ_TIMEOUTenvironment variables, to bound how long each AWS API call waits for an endpoint (#12774)
🔄 Changed
- AWS provider default Boto3 connect timeout lowered from 60 to 10 seconds, so scans in restricted-egress networks (VPC endpoints for a subset of services, GovCloud, private deployments) no longer spend 4 minutes per region on every service whose endpoint is unreachable (#12774)
🐞 Fixed
- Duplicate requirement ids, checks listed twice in a requirement and references to non-existent checks across compliance frameworks, now guarded by a catalog integrity test (#12717)
- Duplicate requirement
3.2.1in ProwlerThreatScore for Azure (SQL auditing retention is now3.2.4) and doubled check id in requirement1.2.1of ProwlerThreatScore for GCP (#12717) - Jira connection checks no longer log an error when a single project has no issue types visible to the integration user (typically a missing "create issue" permission on that project), a case the caller already treats as non-fatal (#12742)
Jira.test_connection()now fetches each project's issue types concurrently instead of one request at a time, so accounts with many Jira projects no longer take tens of seconds (unbounded, scaling with the project count) to verify the connection (#12742)AwsProvider.get_available_aws_service_regions()now returns an empty set for an unknown service or partition instead of raisingKeyError, so a service unavailable in the audited partition is skipped (#12759)AwsProvider.generate_regional_clients()now returns an empty dict instead ofNonewhen the regional clients cannot be built, a failure that surfaced later asAttributeError: 'NoneType' object has no attribute 'values'(#12759)AwsProvider.get_global_region()now returns a real region for each ISO partition instead of theaws-iso-globalpseudo endpoint, which collapsed the four partitions into one answer (#12759)- Bootstrap STS calls now use the session region when
PROWLER_AWS_PARTITIONis set and the region belongs to that partition, instead of always going to the partition's global STS region, which a deployment reached only through its own region's VPC endpoints cannot route to (#12764) - The Image provider now uses the directory named by
TRIVY_CACHE_DIRwhen one is set, instead of a fresh temporary directory it deletes afterwards, so a deployment can supply a vulnerability database it already holds and one with network access stops re-downloading the database for every image it scans (#12773) --aws-retries-max-attempts 0now disables Boto3 retries instead of being silently ignored in favour of the default of 3 (#12774)rolesanywhere_profile_restricts_session_permissions,iam_role_service_trust_restricts_source_to_accountandcodebuild_project_uses_allowed_github_organizationscrashing withTypeErrorwheniam:ListRolesis denied (#12785)
[5.41.0] (Prowler v5.41.0)
🚀 Added
memorydb_cluster_in_transit_encryption_enabledcheck for AWS provider, verifying MemoryDB clusters have in-transit encryption (TLS) enabled (#12246)elasticbeanstalk_environment_no_secrets_in_configurationcheck for AWS provider, scanning the option settings of every Elastic Beanstalk environment for hardcoded secrets (#12378)- CIS Google Workspace Foundations Benchmark v1.4.0 compliance framework (#12513)
Jira.send_finding()returns typed creation outcomes with the issue key, immutable ID and browse URL, and supports length-safe finding and delivery-attempt labels plus marker lookup for uncertain deliveries (#12539)Jira.get_issues_status()resolves issue references by immutable ID in batches and returns explicit open, done, moved, missing, forbidden or unknown outcomes without treating missing issues as deleted (#12539)guardduty_ai_protection_enabledcheck for AWS provider, flagging GuardDuty detectors without AI Protection, which analyzes AWS CloudTrail data events from Amazon Bedrock, Amazon Bedrock AgentCore and Amazon SageMaker AI; a detector that does not report the feature isMANUALrather thanFAIL(#12564)guardduty_runtime_monitoring_enabledcheck for AWS provider, flagging GuardDuty detectors without unified Runtime Monitoring, the only feature that covers Amazon EC2 instances and Amazon ECS on AWS Fargate tasks in addition to Amazon EKS (#12564)ecr_registry_enhanced_scanning_enabledcheck for AWS provider, verifying that the ECR registry scan type is enhanced (Amazon Inspector, covering programming language packages and continuous rescanning) instead of basic, and reporting MANUAL when the registry scanning configuration cannot be read (#12660)eks_cluster_vpc_cni_network_policy_enforcedcheck for AWS provider, flagging EKS clusters whose Amazon VPC CNI managed add-on does not enable Kubernetes network policy enforcement, and reporting MANUAL where the EKS API cannot show the setting (#12661)cloudwatch_log_group_agentcore_data_protection_policy_enabledcheck for AWS provider, verifying that Bedrock AgentCore log groups mask sensitive data with a CloudWatch Logs data protection policy (#12662)iam_policy_no_agentcore_workload_access_token_wildcardcheck for AWS provider, flagging customer-managed IAM policies that allowbedrock-agentcore:GetWorkloadAccessToken,GetWorkloadAccessTokenForJWTorGetWorkloadAccessTokenForUserIdon resources reaching workload identities other than the caller's own, which AWS documents as the only binding on the unverified user ID the token is issued for (#12664)iam_policy_passrole_to_bedrock_agentcore_restrictedcheck for AWS provider, flagging customer-managed IAM policies that allowiam:PassRoleover every role where the passed role can reach Bedrock AgentCore, so any principal holding the policy can run agent code under any role in the account (#12664)iam_role_service_trust_restricts_source_to_accountcheck for AWS provider, flagging IAM roles whose trust policy lets an AWS service principal assume the role without confining the request to a specific source account, including trust policies thatiam_role_cross_service_confused_deputy_preventiondoes not evaluate (#12664)PROWLER_IMAGE_PROVIDER_ALLOWED_PRIVATE_NETWORKSenvironment variable so the image provider can reach container registries on allowlisted private networks, keeping every other non-public address blocked (#12678)PROWLER_AWS_PARTITIONenvironment variable to select the AWS partition used for STS credential validation and scan bootstrap, with a clear error when the account belongs to a different partition (#12680)
🔄 Changed
- Google Workspace checks mapped to CIS evaluate the full audit procedure instead of a single condition, so Gmail spoofing actions, 2-Step Verification, password expiration and alert severity left on Google's defaults no longer pass (#12513)
security_login_challenges_configuredandsecurity_2sv_enforcedunmapped from CIS Google Workspace 4.1.4.1 and CISA SCuBA 0.6GWS.COMMONCONTROLS.1.1, whose Post-SSO verification and phishing-resistant MFA requirements neither check can prove (#12513)
🐞 Fixed
- GitHub repository discovery for unscoped scans now paginates beyond the first 100 accessible repositories instead of silently scanning only the first page (#12460)
rules_*_alert_configuredchecks no longer pass a rule whose delivery to the alert center is disabled, the setting behind the benchmark's "Ensure that Alerts is set to On" (#12513)security_password_policy_strongno longer fails a domain that never touched the password strength setting: Google enforces strong passwords by default, so an unset value is the secure default and not a missing configuration (#12513)security_2sv_enforcedandsecurity_2sv_hardware_keys_adminsreport MANUAL instead of judging domain-wide values that a group or a sub-organizational unit overrides, or that were dropped because the root organizational unit could not be resolved; a domain-wide failure is still reported as such, with the override noted (#12513)ecr_registry_scan_images_on_push_enabledno longer passes a registry whose scanning rules are allMANUAL, nor describes aCONTINUOUS_SCANregistry as scanning on push; each rule'sscanFrequencyis now read instead of inferred from a rule's presence (#12560)- CloudWatch log metric filter checks no longer crash with
AttributeErrorwhen the account has a metric filter whose log group was not retrieved (#12561) guardduty_eks_runtime_monitoring_enabledno longer reportsFAILfor detectors that use unified Runtime Monitoring; the GuardDuty service now reads theRUNTIME_MONITORINGfeature, which is mutually exclusive withEKS_RUNTIME_MONITORINGand already covers Amazon EKS (#12564)- Checks no longer report
FAILwhen the scanning identity lacks permissions, an API is not enabled or a feature is not licensed; they now emit a singleMANUALfinding naming what is required, across 28 M365, Azure, AWS and GCP checks (#12645) sagemaker_notebook_instance_without_direct_internet_access_configuredcheck logic to read theDirectInternetAccesssetting instead ofRootAccess, failing a notebook instance with direct internet access enabled even when root access is disabled (#12659)- Basic authentication fallback in the image provider when a registry rejects the negotiated bearer token, so registries like Harbor that guard catalog listing behind Basic can be enumerated (#12678)
- Registry catalog listing when the server answers with a Bearer challenge after negotiating Basic (or anonymous) authentication, switching to a bearer token obtained from the challenge instead of failing (#12678)
--registry-insecurenow propagates to Trivy viaTRIVY_INSECURE, so images in registries with self-signed certificates can be pulled and scanned, not just enumerated (#12678)- Registry scans in the Image provider now skip non-image OCI artifacts (Helm charts, cosign signatures, SBOM attestations) and no longer abort the whole scan when Trivy fails on a single discovered image; registry enumeration also runs in parallel instead of one request at a time (#12695)
[5.40.0] (Prowler v5.40.0)
🚀 Added
- NCSC Cyber Essentials 3.3 compliance framework with Azure provider coverage across the five Cyber Essentials themes (#11588)
oss_bucket_versioning_enabledcheck for Alibaba Cloud provider, verifying that OSS buckets have versioning enabled to allow recovery from accidental or malicious object overwrite and deletion (#11913)defender_domain_dmarc_records_publishedchecks that every Exchange Online domain publishes a DMARC record with an enforcing policy (p=quarantineorp=reject) (#11936)ske_cluster_no_public_endpointcheck for STACKIT provider, flagging SKE clusters whose Kubernetes API endpoint is reachable from the whole internet because the ACL extension is disabled or its allowed CIDR list contains0.0.0.0/0or::/0(#11943)oss_bucket_server_side_encryption_enabledcheck for Alibaba Cloud provider, verifying that OSS buckets have a default server-side encryption rule (AES256 or KMS) (#11981)organization_default_workflow_permissions_read_onlycheck for GitHub provider, verifying that organizations grant GitHub Actions workflows a read-only defaultGITHUB_TOKEN(#12122)ecr_repository_image_no_secretscheck for AWS provider, scanning the latest ECR repository image's configuration and filesystem layers for hardcoded secrets (#12123)repository_default_workflow_permissions_read_onlycheck for GitHub provider, verifying that repositories grant GitHub Actions workflows a read-only defaultGITHUB_TOKEN(#12143)vpc_security_group_open_egresscheck for Huawei Cloud provider: VPC security groups do not allow open egress to the internet (#12209)organization_actions_pull_request_approval_disabledcheck for GitHub provider, verifying that organizations prevent GitHub Actions from creating and approving pull requests (#12394)- Add the
iam_workload_identity_pool_provider_attribute_conditioncheck to flag GCP Workload Identity Federation providers that trust a multi-tenant issuer without an attribute condition restricting which external identities can impersonate federated principals (#12416) - Add the
rolesanywhere_profile_restricts_session_permissionscheck to flag AWS IAM Roles Anywhere profiles that reference an administrative role without scoping down the vended session with a session policy or managed policies (#12416) bedrock_guardrail_contextual_grounding_filter_enabled,bedrock_custom_model_encrypted_with_cmk,bedrock_knowledge_base_encrypted_with_cmkandbedrock_agent_role_not_shared_across_agentsare four new AWS Bedrock checks covering guardrail contextual grounding, custom model encryption, knowledge-base data-source encryption, and non-shared agent execution roles. (#12459)Clustercolumn in Kubernetes CIS, ISO27001, Prowler ThreatScore, and universal compliance outputs, populated with the resolved cluster name so multi-cluster scans can be told apart in the output (#12506)
🐞 Fixed
- Kubernetes
kubeletchecks no longer disappear from the scan withTypeError: 'NoneType' object is not iterablewhen akubelet-configConfigMap is broken: one with malformed YAML is logged and skipped while the valid ones are still evaluated, one without kubelet data is evaluated with an empty configuration instead of crashing the checks, and theapiserver,controllermanager,etcdandschedulerpod gatherers now always return a list (#12225) - IaC provider now raises typed
IacBaseExceptionerrors (repository clone, Trivy missing, scan and output processing failures) instead of callingsys.exit(1); the CLI still stops with the logged message, and API scans fail as regular task errors instead of aSystemExitescaping the worker (#12227) - CLI Slack integration (
--slack) no longer fails when a scan produces no findings: the pass and fail percentages are guarded against afindings_countof 0, which previously raisedZeroDivisionErrorand sentblocks=Noneto Slack instead of the summary (#12229) - AWS FSBP compliance mapping for
IAM.9andEKS.1referenced missing/renamed checks; both now point to their real, existing check IDs (#12372) ec2_securitygroup_not_usedno longer reports a false positive for security groups attached only to an AWS Batch compute environment, which holds them in configuration without creating a network interface while scaled down to zero instances (#12458)- Bedrock Agent ARNs are now built from the audited partition instead of a hardcoded
arn:aws:, so findings in GovCloud and China carry a resolvable ARN and--resource-arnscoping matches agents in those partitions. (#12459) push-to-cloudnow validates Private Cloud TLS certificates with the operating system trust store without changing provider HTTP clients (#12485)prowler.compliance.universalentry point directories are resolved through a single shared helper and deduplicated by resolved path, so a directory reached through two entry points is parsed once and a package that fails to import no longer hides the rest (#12536)- OSS bucket logging, versioning, default encryption and ACL configurations are now read correctly from the Alibaba Cloud SDK, so
oss_bucket_logging_enabled,oss_bucket_versioning_enabled,oss_bucket_server_side_encryption_enabledandoss_bucket_not_publicly_accessibleno longer report every bucket as unconfigured (#12546)
🔐 Security
openssl,libssl3t64andopenssl-provider-legacyupgraded to 3.5.7-1~deb13u2 in the SDK container image, patching ten high OpenSSL CVEs (#12549)
[5.39.1] (Prowler v5.39.1)
🐞 Fixed
- Bump alibabacloud-tea-openapi to 0.4.6, oci to 2.184.1 and pyopenssl to 26.4.0 so the published wheel installs with cryptography 50.0.0; 5.38.0 declared cryptography 50.0.0 while those packages capped it below 50, so pip could not install it and
pip install prowlersilently fell back to 5.37.1 (#12477) - Pin zstd to 1.5.7.2; 1.5.7.3 was yanked from PyPI as not thread safe (#12477)
- ECS task-definition checks no longer report PASS when
DescribeTaskDefinitionfails before container evidence is gathered (#12478) ses_identity_not_publicly_accessiblenow evaluates every SES identity authorization policy and marks mixed public Allow and Deny statements for manual review (#12480)
🔐 Security
- Trivy from v0.72.0 to v0.73.0 in the container image, fixing HIGH CVE-2026-46600 in the bundled
golang.org/x/net(#12445) - Trivy v0.74.0 and Debian util-linux 2.41.5-0+deb13u1 in the SDK container image, patching Go standard library vulnerabilities and CVE-2026-53615 (#12470)
[5.39.0] (Prowler v5.39.0)
🚀 Added
batch_job_definition_no_secretscheck for AWS provider, scanning Batch job definition environment variables and command parameters for hardcoded secrets (#12117)- 7 M365 Entra checks covering CIS Microsoft 365 Foundations Benchmark v7.0.0 password protection, default user permissions, and guest invitation domain restrictions (#12153)
- 7 M365 entra checks covering CIS Microsoft 365 Foundations Benchmark v7.0.0 Conditional Access (5.2.2.x) and idle session timeout controls (#12154)
entra_authentication_method_email_otp_disabled,entra_authentication_method_authenticator_show_context,entra_pim_global_administrator_approval_required,entra_pim_privileged_role_administrator_approval_required,entra_access_review_guest_users_configuredandentra_access_review_privileged_roles_configuredchecks for M365 provider covering CIS Microsoft 365 Foundations Benchmark v7.0.0 authentication method, PIM approval and access review controls (#12155)awslambda_layer_no_secrets_in_contentcheck for AWS provider, scanning Lambda layer package content for hardcoded secrets (#12233)- CMMC 2.0 universal compliance framework (
cmmc_2.0) with the 149 official requirements from 32 CFR Part 170 — Level 1 (15, 48 CFR 52.204-21), Level 2 (110, NIST SP 800-171 Rev 2) and Level 3 (24, NIST SP 800-172) — with AWS, Azure, GCP, Alibaba Cloud, Oracle Cloud and M365 check mappings and config guardrails (#12401)
🔄 Changed
- GitHub
organization_repository_creation_limitedcheck now reports low severity for FAIL findings when repository creation is provably limited to private/internal visibility, instead of always reporting high (#12164)
🔐 Security
- HTML report header now HTML-escapes every provider identity field across all 23 providers, closing a stored XSS in the header block (Secur0, CWE-79) that was left unaddressed by the earlier finding-row fix in #12221 (#12424)
[5.38.0] (Prowler v5.38.0)
🚀 Added
admincenter_shared_bookings_disabledcheck for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 control 1.3.9 (#12147)defender_priority_account_protection_enabledanddefender_strict_preset_security_policy_enabledchecks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 controls 2.4.1 and 2.4.2 (#12148)exchange_owa_mailbox_policy_personal_accounts_disabledandexchange_organization_reject_direct_send_enabledchecks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 controls 6.3.2 and 6.5.5 (#12149)teams_external_access_trial_tenants_blockedcheck for M365 provider, verifying that Teams external access with trial-only tenants is blocked, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 control 8.2.4 (#12151)entra_device_registration_join_restricted,entra_device_registration_max_devices_per_user_limited,entra_device_registration_global_admins_not_local_admins,entra_device_registration_registering_user_not_local_admin,entra_device_registration_laps_enabledandentra_policy_default_user_cannot_read_bitlocker_keyschecks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 device registration controls (5.1.4.x) (#12152)- The IAM privilege-escalation check now detects 22 additional pathfinding.cloud escalation paths across AWS Batch, Braket, CodeDeploy, Cognito Identity, ECS, EMR, EMR Serverless, GameLift, Glue, EC2 Image Builder, Kinesis Analytics, HealthOmics, EventBridge Scheduler, SSM Automation, Step Functions, IAM permissions boundaries, and IAM Identity Center (SSO) (#12237)
- Container images now ship an SBOM and build provenance as OCI attestations (#12352)
🔄 Changed
- Highlighted key security terms in the Risk description of 8 existing M365 checks (#12156)
- Moved the Trivy suppressions from the classic
.trivyignoreto.trivyignore.yaml, so each entry is scoped to the package it names instead of suppressing its CVE across the whole image (#12314) - The
securityhub_delegated_admin_enabled_all_regions,guardduty_delegated_admin_enabled_all_regionsandconfig_delegated_admin_and_org_aggregator_all_regionschecks now report MANUAL instead of FAIL when the delegated administrator status cannot be read and no independent misconfiguration is detected, which happens on member accounts that are not registered as delegated administrators because the API is restricted to the organization management account and to delegated administrator accounts (#12319) - Pin the container vulnerability scanner to Trivy v0.72.0, matching prowler-registry and partner-portal (#12346)
- Quote the unquoted shell expansions in the release and build workflows (#12365)
- Fix the remaining shellcheck findings in workflows and enable the check (#12367)
🐞 Fixed
- Spurious error log output from
Get-ApplicationAccessPolicyon M365 tenants without application access policies (#12149) - Secret checks no longer report credential-free JDBC connection strings as embedded credentials (#12288)
- A failed
ListOrganizationAdminAccountslookup in one region no longer marks the Security Hub delegated administrator status as undetermined in every other region (#12319) securityhub_delegated_admin_enabled_all_regionsno longer reports FAIL withdelegated administrator status could not be determinedon accounts that do have a Security Hub delegated administrator;ListOrganizationAdminAccountsresponses are now parsed with theAccountIdandStatusfields the API actually returns (#12319)guardduty_delegated_admin_enabled_all_regionsno longer reportsno delegated administrator configuredwhen the lookup was denied or failed, which asserted absence where there was only lack of visibility (#12319)- OCI Identity service no longer drops the whole dynamic groups, groups, policies or users listing when the OCI API returns null optional fields such as
matching_rule(#12327) - Alibaba Cloud STS credential validation retries transient connection failures and reports exhausted attempts as connection errors instead of invalid credentials (#12353)
🔐 Security
- Bumped the Compose DozerDB image from 5.26.3.0 to 5.26.27.0, which moves it off Debian 11 and onto Debian 13 (#12320)
- The SDK container image now verifies the checksum of every third-party binary it downloads (PowerShell, Trivy, zizmor) before installing it (#12334)
- Upgrade aiohttp to 3.14.3 to pick up the fix for CVE-2026-69244 (#12340)
- Upgrade cryptography to 50.0.0, closing CVE-2026-69247 and CVE-2026-69249 (#12356)
[5.37.1] (Prowler v5.37.1)
🔄 Changed
- Huawei Cloud exception codes moved from
19000-19007to20000-20007, resolving a collision with E2E Networks which reserves19000-19999(#12306)
🐞 Fixed
- Checks registered through the
prowler.checks.<provider>entry-point group can now run against built-in providers. The built-in probe in_resolve_check_moduleused a barefind_spec, which imports the parent package to search it and so raisedModuleNotFoundErrorfor a plug-in check instead of returningNone, aborting the lookup before the entry points were consulted. Such a check was discovered, listed and selected for execution, then silently produced no findings. (#12312) - Entra Conditional Access guest-user checks no longer report false FAILs: microsoft-kiota packages bumped to 1.9.10 so
guestOrExternalUserTypes(a flags enum Graph serializes as a comma-separated string) deserializes correctly instead of returning an empty list (#12315)
🔐 Security
- Bumped the Compose
postgresandvalkeyimages, clearing 10 critical CVEs (#12307) - Bumped PowerShell, Trivy, uv and
joserfcin the container images, clearing 14 high-severity CVEs from the SDK and API images (#12307) - Bumped
httplib2to 0.32.0 andpyasn1to 0.6.4 to resolve known CVEs (#12307) - The SDK container image now builds on Debian 13 (trixie), clearing the unfixable
libsqlite3-0andzlib1gcriticals (#12307) - Bumped
cryptographyto 48.0.1 to resolve GHSA-537c-gmf6-5ccf, along with theoci,alibabacloud-tea-openapi,darabonba-coreandpy-ocsf-modelsbumps it requires (#12307) - Removed
pipfrom the SDK container image, clearing two high-severity CVEs in the vendored copies ofsetuptoolsandmsgpack(#12307) - Removed
wget,gnupgandapt-transport-httpsfrom the SDK runtime image (#12307)
[5.37.0] (Prowler v5.37.0)
🚀 Added
- OCSF detection finding output now populates
finding_info.analyticas the Prowler check rule andfinding_info.attacksas MITRE ATT&CK technique and tactic objects for findings with MITRE-ATTACK compliance metadata (#11492) codecommitservice andcodecommit_repository_no_secretscheck for AWS provider, scanning files tracked at the tip of each repository's default branch for hardcoded secrets (#11846)- Huawei Cloud provider, with CTS, ECS, ELB, EVS, IAM, KMS, OBS, RDS, VPC and WAF services and a CIS 1.0 compliance benchmark (#11950)
glue_catalog_connection_no_secretscheck to detect secrets in Glue Data Catalog connection properties (#11963)ec2_instance_stopped_older_than_specific_dayscheck for AWS provider, detecting EC2 instances stopped longer than a configurable number of days (default 30) (#12076)sagemaker_endpoint_config_kms_encryption_enabledcheck verifying SageMaker endpoint configurations use a KMS key for storage volume encryption (#12118)- 11 AWS Nitro Enclaves security checks providing the first CSPM coverage for confidential computing workloads, covering both host environment (
ec2_confidential_workload_host_*) and KMS attestation policy (kms_key_enclave_*), fully passive via boto3 and CloudTrail LookupEvents (#12283)
🐞 Fixed
- Scan configuration schema no longer exposes SDK/CLI-only providers such as
e2enetworks; the aggregated schema served by/scan-configurations/schemanow includes only app providers (sdk_only = False) (#12094) - GCP Cloud Functions gen2 IAM policy retrieval now uses a per-request HTTP client, preventing a process crash from concurrent thread-unsafe
httplib2access when a project has several gen2 functions (#12107) - GCP firewall SSH and RDP checks now detect exposed target ports in any position within multi-port rules (#12115)
- Secret ignore patterns now use Kingfisher-compatible LF line indexing for scanned content containing ASCII control characters (#12141)
- Jira descriptions with inline code nested in bold or italic Markdown now render as valid ADF (#12158)
🔐 Security
- HTML reports escape provider-originated finding fields to prevent stored cross-site scripting through malicious cloud resource tags (#12221)
[5.36.0] (Prowler v5.36.0)
🚀 Added
sagemaker_notebook_instance_no_secretscheck for AWS provider, scanning SageMaker notebook instance lifecycle configuration scripts (OnCreateandOnStart) for hardcoded secrets such as API keys, passwords, tokens, and connection strings (#11843)
🔄 Changed
- Jira output rendering supports grouped Finding Group issues with caller-provided links and capped or uncapped finding copy (#12035)
🐞 Fixed
- Fix invalid escape sequence
SyntaxWarningraised on startup by the S3 bucket name validation regex (#12041) - Alibaba Cloud SSH and RDP security group checks no longer produce false negatives when allowed rules use capitalized
Policy="Accept"values (#12049)
[5.35.0] (Prowler v5.35.0)
🚀 Added
excluded_checksandexcluded_servicesin scan configurations to narrow the execution scope (#12028)
🔐 Security
- Jira tenant information requests validate site names and do not follow redirects (#12012)
[5.34.0] (Prowler v5.34.0)
🚀 Added
elbv2_listener_pqc_tls_enabledcheck for AWS provider, verifying that ELBv2 listeners use post-quantum TLS policies (#11254)iaas_server_public_ip_attachedcheck for STACKIT provider, flagging IaaS servers that have a public IP address directly attached to a network interface (#11549)- Changelog fragment workflow for SDK, API, UI, and MCP Server releases, including PR attribution, fragment validation, release compilation, and preserved section ordering (#11572)
- E2E Networks provider with 27 checks across compute nodes, networking, security groups, load balancers, block/file storage, and managed databases (#11654)
datapipeline_pipeline_no_secrets_in_definitioncheck for AWS provider, scanning Data Pipeline object fields, parameter objects, and parameter values for hardcoded secrets with Kingfisher (#11821)amplify_app_no_secrets_in_environmentcheck for AWS provider, scanning Amplify app and branch environment variables and build settings for hardcoded secrets (#11825)ec2_ami_account_block_public_accesscheck for AWS provider, verifying AMI block public access is enabled at the account level in each Region so AMIs cannot be shared publicly (#11828)core_readonly_root_filesystem_enabledcheck for Kubernetes provider, verifying that every container in each Pod explicitly setsreadOnlyRootFilesystem: truein its security context (#11835)core_minimize_hostpath_volume_mountscheck for Kubernetes provider, detecting Pods that usehostPathvolumes (#11837)app_function_ensure_http_is_redirected_to_httpscheck for Azure provider, verifying that Function Apps enforce HTTPS-only traffic (#11929)
🔄 Changed
- Add missing trailing newlines to compliance, region, and fixture data files for POSIX compliance (#11765)
- Oracle Cloud API key authentication now uses an internal bootstrap region when no explicit scan region filter is provided (#11853)
- Redesign the local dashboard sidebar and informational pages (#11972)
[5.33.2] (Prowler v5.33.2)
🐞 Fixed
- EC2 AMI loading now targets Amazon-owned AMIs used by audited instances, reducing AWS API calls during EC2 scans (#11958)
ec2_instance_account_imdsv2_enabledfindings now use regional resource ARNs, preventing findings from different AWS Regions from collapsing into one resource (#11966)
[5.33.1] (Prowler v5.33.1)
🐞 Fixed
- ECS task definition resource limits now select the latest task definitions by registration date instead of relying on ARN ordering (#11891)
dlm_ebs_snapshot_lifecycle_policy_existsno longer initializes the full EC2 inventory just to detect EBS snapshots, avoiding slow scans when checking DLM lifecycle policies (#11900)dms_instance_no_public_accessno longer initializes the full EC2 service when there are no DMS replication instances (#11902)organizations_scp_check_deny_regionsno longer reports falseFAILfor AWS Organizations that restrict regions with Allow-based SCPs; the Allow path now checks the statementEffectinstead of an always-false comparison that made it unreachable (#11915)- Jira issue creation failures now preserve safe structured response details from Jira (#11925)
- Azure Function App optional permission failures now log as warnings, and Function App environment variable fields use the correct spelling internally (#11926)
[5.33.0] (Prowler v5.33.0)
🐞 Fixed
- Azure resource group scoped scans now keep subscription entries when scoped resource listing fails, clarify helper documentation and test organization, and align the resource group documentation example with the described values (#11796)
- Azure
postgresql_flexible_server_log_retention_days_greater_3check now queries thelogfiles.retention_daysconfiguration parameter instead oflog_retention_days(which only exists on the retired Single Server), fixing falseFAILresults on every Flexible Server regardless of the actual retention value (#11761)
[5.32.1] (Prowler v5.32.1)
🐞 Fixed
KeyError: 'MANUAL'crash while rendering the compliance summary table (e.g. CIS Microsoft 365) when a framework has manual, checks-less requirements with a Level 1/Level 2 profile;MANUALfindings are now skipped in the PASS/FAIL section tally instead of raising (#11822)
[5.32.0] (Prowler v5.32.0)
🚀 Added
exchange_application_access_policy_restricts_mailbox_appscheck for M365 provider, verifying every service principal with Microsoft Graph application-level Exchange mailbox permissions is restricted by an Exchange Online Application Access Policy, preventing tenant-wide mailbox access by unscoped applications (#11247)- Per-requirement configuration validation for compliance frameworks via
ConfigRequirements, so a requirement is reported as FAIL when its configurable checks ran with a configuration too loose to satisfy it (applied across all compliance outputs: CSV, OCSF, and console tables) (#11669) entra_conditional_access_policy_explicitly_targets_azure_devopscheck for M365 provider, verifying at least one enabled Conditional Access policy explicitly includes the Azure DevOps cloud application instead of relying on a broad "All cloud apps" policy (#11182)entra_conditional_access_policy_no_exclusion_gapscheck for M365 provider, verifying every user, group, role, or application excluded from an enabled Conditional Access policy stays in scope of another enabled policy (#11577)entra_conditional_access_policy_groups_management_restrictedcheck for M365 provider, verifying every security group referenced by an enabled or report-only Conditional Access policy is management-restricted or role-assignable (#11342)stepfunctions_statemachine_encrypted_with_cmkcheck for AWS provider, verifying that each Step Functions state machine uses a customer-managed KMS key for encryption at rest rather than the default AWS-owned key (#11538)- CIS Controls v8.1 universal compliance framework mapping existing checks across 18 providers (AWS, Azure, GCP, Kubernetes, M365, GitHub, AlibabaCloud, OracleCloud, GoogleWorkspace, Okta, Cloudflare, Vercel, MongoDB Atlas, OpenStack, Linode, StackIT, NHN, and Scaleway) to the 18 CIS Critical Security Controls and their Safeguards (#11700)
- CIS Microsoft 365 Foundations Benchmark v7.0.0 compliance framework for the M365 provider (#11699)
waf_regional_webacl_logging_enabledcheck for AWS provider, verifying that each AWS WAF Classic Regional Web ACL has logging enabled to a Kinesis Data Firehose stream (#11539)sdk_onlyprovider property (defaulttrue) andProvider.get_app_providers(), so a provider (built-in or external) stays CLI/SDK-only and hidden from the app unless it declaressdk_only = False(#11427)Provider.get_scan_arguments(),Provider.get_connection_arguments()andProvider.get_credentials_schema()contract methods, so a provider persisted as a stored uid plus a secret dict can be constructed and validated programmatically (to be consumed by the API in a later change) (#11578)- Okta API request throttling to proactively stay under rate limits, configurable via
okta_requests_per_secondin the config file and the--okta-requests-per-secondCLI flag, plus configurable retries viaokta_max_retries/--okta-retries-max-attemptsas a safety net (#11702) - CIS Amazon Web Services Foundations Benchmark v7.0.0 compliance framework for the AWS provider, adding the new Organizations section (2.1.1-2.1.6), resource policy (2.21), web front-end access logging (4.10), and VPC Endpoints (6.8) recommendations (#11707)
- CIS Microsoft Azure Foundations Benchmark v6.0.0 compliance framework for the Azure provider (#11708)
- CIS Google Cloud Platform Foundation Benchmark v5.0.0 compliance framework for the GCP provider (#11714)
- CIS Kubernetes Benchmark v2.0.1 compliance framework for the Kubernetes provider (#11722)
- CIS GitHub Benchmark v1.2.0 compliance framework for the GitHub provider (#11719)
- AWS Bedrock AgentCore privilege escalation paths in the IAM privilege escalation checks, covering Runtime, Harness, Code Interpreter and Custom Browser (#11726)
--scan-secrets-validateflag andaws.secrets_validateconfiguration option to optionally validate the secrets discovered by the secret-scanning checks against the provider APIs; secrets confirmed to be live are reported as critical (#11694)apigateway_restapi_no_secrets_in_stage_variablescheck for AWS provider, scanning API Gateway REST API stage variables for hardcoded secrets such as passwords, API keys, and tokens (#11188)s3_bucket_object_publiccheck for AWS provider, spot-checking a configurable sample of object ACLs in each bucket and flagging objects granted to the AllUsers or AuthenticatedUsers groups; disabled by default and opted into via thes3_bucket_object_public_enabledconfiguration option (#9517)- Azure provider now supports
--azure-resource-groupto scope resource-level checks to specific resource groups across all accessible subscriptions (#10657)
🔄 Changed
- Replaced the
detect-secretslibrary with Kingfisher as the engine for the secret-scanning checks; scans run fully offline by default and obvious placeholder values are no longer reported as findings (#11694) - Removed the
detect_secrets_pluginsconfiguration option, which is no longer used by the new secret-scanning engine (#11694) awslambda_function_no_secrets_in_codenow supports asecrets_ignore_filesaudit-config option to skip files inside the deployment package by glob pattern (e.g.*.deps.json), suppressing .NET dependency-manifest false positives without masking real secrets (#11222)- AWS scans for EBS snapshots, Backup recovery points, CloudWatch log groups, Lambda functions, ECS task definitions, and CodeArtifact packages now support configurable resource analysis limits via
aws.max_scanned_resources_per_service; limits are disabled by default and only positive values cap analyzed resources (#11228)
🐞 Fixed
- GitHub
repository_has_codeowners_filecheck no longer flags archived repositories, since they are read-only and cannot be updated without first being unarchived, making the finding not actionable (#11735) - Report secret-scanning checks as
MANUALinstead ofPASSwhen the scanner fails (non-zero exit, timeout, unparseable output or missing binary), so a scanner failure is no longer indistinguishable from "no secrets found" (#11694) - Avoid a false
FAILincloudwatch_log_group_no_secrets_in_logswhen a multiline event's secrets are all removed bysecrets_ignore_patternsduring the rescan (#11694) - Key the
cloudwatch_log_group_no_secrets_in_logssecret scan by log group ARN instead of name, so same-named log groups and streams in different regions no longer collide and reuse each other's findings (#11694) - Compliance frameworks contributed by several external packages under the same provider are now merged instead of overwritten, so every entry-point directory a provider contributes is discovered (#11578)
- Azure PostgreSQL flexible server collection no longer drops the remaining servers in a subscription when one server fails to collect; the
connection_throttle.enableparameter (removed in PostgreSQL 16+) is treated as absent only when the Azure SDK reports it as not found, so unexpected lookup failures are not silently reported as throttling disabled (#11595) - Azure
keyvault_logging_enablednow accepts Key Vault diagnostic settings that enable the explicitAuditEventcategory, avoiding false failures when Azure returns category-based logs without category groups (#11660) - GitHub default branch protection checks now evaluate repository rulesets in addition to classic branch protection, avoiding false positives for repositories that enforce protection through rulesets (#11723)
- Okta, Alibaba Cloud and OpenStack scan-config sections are now validated against a registered schema instead of being silently accepted, so their configurable thresholds (session/idle timeouts, retention days, image-sharing and secret-scanning settings) log a warning and fall back to the built-in default whenever a value is out of range (#11725)
[5.31.1] (Prowler v5.31.1)
🐞 Fixed
- Alibaba Cloud
ram_password_policy_numberandcs_kubernetes_cluster_check_weeklychecks not being loaded due to missing implementation and package files (#11683)
[5.31.0] (Prowler v5.31.0)
🚀 Added
- Support for Python 3.13 (#9293)
securityhub_delegated_admin_enabled_all_regionscheck for AWS provider, verifying that Security Hub has a delegated administrator, is active in all opted-in regions, and has organization auto-enable on (#11259)config_delegated_admin_and_org_aggregator_all_regionscheck for AWS provider, verifying that AWS Config has a delegated administrator and an organization aggregator covering all AWS regions (#11259)sagemaker_clarify_existscheck for AWS provider (#11211)cloudsql_instance_high_availability_enabledcheck for GCP provider, verifying Cloud SQL primary instances useREGIONALavailability for automatic zone failover (#11024)cloudfunction_function_inside_vpccheck for GCP provider, verifying Cloud Functions have a Serverless VPC Access connector for private egress (#11021)cloudfunction_function_not_publicly_accessiblecheck for GCP provider, detecting Cloud Functions withallUsersorallAuthenticatedUsersIAM invocation bindings (#11022)secretmanager_secret_not_publicly_accessiblecheck for GCP provider, detecting Secret Manager secrets with public IAM bindings (#11025)secretmanager_secret_rotation_enabledcheck for GCP provider, verifying Secret Manager secrets have automatic rotation configured within 90 days (#11026)identity_storage_service_level_admins_scopedcheck for OCI provider CIS 3.1 control 1.15, ensuring storage service-level administrators exclude delete permissions (#11523)cosmosdb_account_automatic_failover_enabledcheck for Azure provider (#11031)cosmosdb_account_backup_policy_continuouscheck for Azure provider (#11032)cosmosdb_account_minimum_tls_versioncheck for Azure provider, verifying Cosmos DB accounts enforce TLS 1.2 or higher for client connections (#11033)cosmosdb_account_public_network_access_disabledcheck for Azure provider, verifying Cosmos DB accounts have public network access disabled so connectivity is restricted to private endpoints or VNet service endpoints (#11034)databricks_workspace_public_network_access_disabledcheck for Azure provider, verifying Databricks workspaces have public network access disabled so connectivity is restricted to Azure Private Link private endpoints (#11035)databricks_workspace_no_public_ip_enabledcheck for Azure provider, verifying Databricks workspaces use secure cluster connectivity (no public IP) so compute nodes are not assigned public IP addresses (#11036)defender_ensure_defender_cspm_is_oncheck for Azure provider, verifying Microsoft Defender Cloud Security Posture Management (CSPM) is enabled on the Standard tier (#11037)mysql_flexible_server_geo_redundant_backup_enabledcheck for Azure provider, verifying MySQL Flexible Servers have geo-redundant backup enabled so backups are replicated to the paired region (#11041)mysql_flexible_server_high_availability_enabledcheck for Azure provider, verifying MySQL Flexible Servers have high availability enabled for automatic failover to a standby replica (#11042)postgresql_flexible_server_geo_redundant_backup_enabledcheck for Azure provider, verifying PostgreSQL Flexible Servers have geo-redundant backup enabled so backups are replicated to the paired region (#11045)postgresql_flexible_server_high_availability_enabledcheck for Azure provider, verifying PostgreSQL Flexible Servers have high availability enabled for automatic failover to a standby replica (#11046)aks_cluster_azure_monitor_enabledcheck for Azure provider, verifying AKS clusters have Azure Monitor (Container Insights) enabled for metrics, logs, and alerting (#11029)aks_cluster_local_accounts_disabledcheck for Azure provider, verifying AKS clusters have local accounts disabled so authentication is forced through Microsoft Entra ID (#11030)network_subnet_nsg_associatedcheck for Azure provider, verifying virtual network subnets have a network security group associated to enforce traffic filtering (#11043)network_vnet_ddos_protection_enabledcheck for Azure provider, verifying virtual networks have Azure DDoS Network Protection enabled (#11044)entra_app_registration_credential_not_expiredcheck for Azure provider, verifying Entra ID app registration secrets and certificates are not expired, expiring within 30 days, or without an expiration date (#11038)entra_authentication_methods_policy_strong_auth_enforcedcheck for Azure provider, verifying the Entra ID authentication methods policy enforces MFA registration and enables at least one strong method (Microsoft Authenticator, FIDO2, or X.509 certificate) (#11039)entra_user_with_recent_sign_incheck for Azure provider, detecting stale enabled accounts that have not signed in within the last 90 days (requires Entra ID P1/P2 licensing for sign-in activity) (#11040)aks_cluster_auto_upgrade_enabledcheck for Azure provider (#11027)- Public
Provider.get_class()method that resolves a provider class by name for both built-in and external (entry-point) providers (#11398) - Jira timeout preventing the calls from hanging indefinitely when the Jira endpoint is unreachable or slow (#11602)
- TLS certificate verification in the
codepipeline_project_repo_privatecheck, which previously used an unverified SSL context, leaving the repository-visibility probe open to MITM tampering (#11603) - Support for Linode cloud provider, with compute, networking and administration services (#11633)
- DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) compliance coverage for the Azure provider, mapping existing Azure checks across the five DORA pillars (#11551)
- Rename DORA to DORA_2022_2554 to follow the naming _ in compliance frameworks (#11551)
entra_directory_sync_object_takeover_blockedcheck for the M365 provider, verifying that hybrid Entra tenants block cloud object takeover through both soft-match and hard-match directory synchronization (#11098)entra_conditional_access_policy_no_deleted_object_referencescheck for M365 provider (#11236)aks_cluster_defender_enabledcheck for Azure provider, verifying that AKS clusters have Microsoft Defender security monitoring enabled (#11028)recovery_vault_has_protected_itemscheck for Azure provider, verifying that Recovery Services vaults have at least one protected backup item (#11048)- DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) compliance coverage for the GCP provider, mapping existing GCP checks across the five DORA pillars (#11642)
- DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) compliance coverage for the Cloudflare provider, mapping existing Cloudflare edge/network checks across the applicable DORA pillars (#11645)
- DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) compliance coverage for the AlibabaCloud provider, mapping existing AlibabaCloud checks across the applicable DORA pillars (#11646)
cloudfront_distributions_pqc_tls_enabledcheck for AWS provider to verify CloudFront distributions enforce a post-quantum TLS 1.3 security policy (#11317)apigateway_domain_name_pqc_tls_enabledcheck for AWS provider to verify API Gateway custom domain names use a post-quantum TLS security policy (#11316)transfer_server_pqc_ssh_kex_enabledcheck for AWS provider to verify Transfer Family servers use a post-quantum hybrid SSH key exchange security policy (#11315)acmpca_certificate_authority_pqc_key_algorithmcheck and newacmpcaservice for AWS provider to verify AWS Private CA certificate authorities use a post-quantum (ML-DSA) key algorithm (#11318)rolesanywhere_trust_anchor_pqc_pkicheck and newrolesanywhereservice for AWS provider to verify IAM Roles Anywhere trust anchors are backed by a post-quantum (ML-DSA) PKI (#11319)- Kubernetes core checks for container CPU limits, CPU requests, memory limits, memory requests, fixed image tags, liveness probes, and readiness probes (#11373)
recovery_vault_backup_policy_retention_adequatecheck for Azure provider, verifying Recovery Services backup policies retain daily backups for at least 30 days (#11047)
🔄 Changed
- Replaced the unmaintained
awsiprangesdependency with a small standard-library helper for theroute53_dangling_ip_subdomain_takeovercheck (#9293)
🐞 Fixed
- Azure PostgreSQL flexible server inventory no longer aborts the whole subscription when the
connection_throttle.enableparameter is missing (e.g. PostgreSQL v18), and logs the expected "Entra ID authentication not enabled" case as a warning instead of an error, so servers are still scanned (#11045) iam_policy_allows_privilege_escalationnow includes theprivilege-escalationcategory (#11648)
🔐 Security
pytestfrom 8.3.5 to 9.0.3, patching a known vulnerability in the SDK test dependency (#11291)blackfrom 25.1.0 to 26.3.1, patching a known vulnerability in the SDK formatter dependency (#11290)microsoft-kiota-*to 1.9.9 andaiohttpto 3.14.0, patching known CVEs (#11596)- Container base image bumped to
python:3.12.13-slim-bookworm(patcheslibgnutls30CVE-2026-33845 and CVE-2026-42010) andtrivybumped to 0.71.0 (patches embeddedgolang.org/x/cryptoand Go stdlib CVEs);.trivyignoredocuments remaining bookworm criticals with no-fix or not-affected rationale (#11592)
[5.30.3] (Prowler v5.30.3)
🐞 Fixed
- CLI compliance summary tables no longer undercount findings mapped to multiple sections nor double-count a single finding mapped to several requirements within the same group/split, and the Provider column no longer leaks a value from another framework (#11567)
[5.30.2] (Prowler v5.30.2)
🐞 Fixed
- GCP
logging_log_metric_filter_and_alert_*checks now credit org-level aggregated sinks filtered to the Admin Activity audit stream (#11575) - A broken built-in provider no longer aborts the CLI when a different provider was invoked (#11618)
- GCP organization scans with
--organization-idno longer silently fall back to the credentials' host project when the Cloud Asset API call fails (#11280)
[5.30.0] (Prowler v5.30.0)
🚀 Added
- DISA Okta IDaaS STIG V1R2 compliance framework for the Okta provider, with a dedicated CSV output formatter and terminal summary table (#11428)
sagemaker_models_monitor_enabledcheck for AWS provider, verifying that each SageMaker monitoring schedule is in theScheduledstate so data and model drift is actively detected (#11278)- DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) universal compliance framework with AWS provider coverage across the five DORA pillars (#11131)
- Okta authenticator and password policy checks for STIG-aligned hardening requirements (#11465)
- Okta network zone check to detect whether anonymized proxy traffic is blocked (#11463)
- Okta API token checks for super admin ownership and network zone restrictions (#11464)
- Support for external/custom providers, checks, and compliance frameworks without modifying core code (#10700)
elbv2_alb_drop_invalid_header_fields_enabledcheck for AWS provider, verifying Application Load Balancers haverouting.http.drop_invalid_header_fields.enabledset totrueto mitigate HTTP desync attacks (AWS FSBP ELB.4) (#11471)user,systemlogandidpservice for Okta provider withuser_inactivity_automation_35d_enabled,systemlog_streaming_enabledandidp_smart_card_dod_approved_cachecks (#11496)- External multi-provider compliance frameworks can be registered via the
prowler.compliance.universalentry point group (#11490) - AWS AI Security Framework support in the CLI dashboard (#11475)
entra_service_principal_privileged_role_no_ownerscheck for M365 provider, failing when a service principal with a permanent Tier 0 directory role has owners on the service principal or its parent app registration (#11070)kms_key_rotation_max_90_dayscheck for GCP provider, verifying KMS customer-managed keys are rotated every 90 days or less in line with the CIS Benchmark (#11516)exchange_mailbox_primary_smtp_uses_custom_domaincheck for M365 provider (#11215)bedrock_agent_role_least_privilegecheck for AWS provider, flagging Bedrock Agent execution roles with full-access managed policies, broadResource:*inline statements, or missing permissions boundaries (#11335)- STACKIT ObjectStorage service with Object Lock, default retention policy, and access key expiration checks (#11397)
🐞 Fixed
load_and_validate_config_filenow unwraps namespaced config for every built-in and external provider, and no longer leaks the full file as the provider's config when the file is namespaced (#10700)entra_users_mfa_capableno longer flags pre-provisioned users with futureemployeeHireDate; future-hire date comparisons now tolerate naive datetimes (#11511)- M365 Admin Center group enumeration now follows Microsoft Graph pagination so group-scoped checks include groups beyond the first page (#11510)
- GCP
kms_key_rotation_enabledcheck now only verifies that automatic key rotation is enabled (any interval) instead of enforcing a 90-day period, resolving the mismatch between the check and its documentation; the CIS, Prowler ThreatScore, and CCC requirements that mandate a 90-day maximum were remapped to the newkms_key_rotation_max_90_dayscheck (#11516) - AWS CloudWatch log metric filter checks now validate
filterPatternclauses regardless of order (#11345) - AWS
bedrock_api_key_no_long_term_credentialsnow applies severity per finding (never-expires keys correctly flag as critical, no leak across findings) and aligns title and wording with AWS guidance to prefer short-term Bedrock API keys (#11526)
🔐 Security
dulwichfrom 0.23.0 to 1.2.5 andpyjwtfrom 2.12.1 to 2.13.0, patchingGHSA-897w-fcg9-f6xj(arbitrary file write) andPYSEC-2026-179(HMAC/JWK key confusion) (#11499)
[5.29.3] (Prowler v5.29.3)
🐞 Fixed
- GCP
logging_sink_creatednow recognizes organization-level aggregated sinks withincludeChildren=True, avoiding false failures for covered projects (#11355) - GCP
logging_log_metric_filter_and_alert_*checks now recognize organization-level aggregated sinks withincludeChildren=True, no longer false-failing projects covered by a central bucket-scoped metric + alert (#11488) - Jira integration no longer fails with
400 INVALID_INPUTwhen a finding has empty fields (#11474) - GCP
iam_service_account_unusednow passes disabled service accounts instead of failing them, since a disabled account cannot authenticate or be used (#11467)
[5.29.1] (Prowler v5.29.1)
🐞 Fixed
- OCSF output writer now re-raises I/O errors (e.g.
ENOSPC) instead of logging them per finding and leaving a truncated file (#11421)
[5.29.0] (Prowler v5.29.0)
🚀 Added
applicationservice for Okta provider withapplication_admin_console_session_idle_timeout_15min,application_admin_console_mfa_required,application_admin_console_phishing_resistant_authentication,application_dashboard_mfa_required,application_dashboard_phishing_resistant_authentication, andapplication_authentication_policy_network_zone_enforcedchecks (#11358)- AWS AI Security Framework compliance for AWS provider (#11353)
storage_account_public_network_access_disabledcheck for Azure provider and remapped the Azure CIS "Public Network Access is Disabled" requirements to it (#11334)- StackIT provider with service account key authentication (#9237)
- 8 Rules service checks for Google Workspace provider using the Cloud Identity Policy API (#11379)
- 12 Security service checks for Google Workspace provider using the Cloud Identity Policy API (#11356)
⚠️ Deprecated
s3_bucket_default_encryptioncheck for AWS provider since SSE-S3 is automatically applied to all S3 buckets by AWS as of January 5, 2023 and can no longer be disabled (#11230)
🐞 Fixed
- Broken documentation URLs in Google Workspace check metadata (#11405)
- ENS RD 311/2022 (AWS) compliance mapping:
vpc_different_regionswas uncorrectly mapped under themp.com.4family (Network segregation). That check is now mapped to a newop.cont.2.aws.vpc.1requirement under the Continuity of Service control (#11372) - Compliance CSV row count now matches the UI per requirement by sourcing rows from the framework JSON's
requirement.Checksinstead of the stalefinding.compliancesnapshot (#11370) - OpenStack provider exception codes moved from the
10000-10999range, shared with the AlibabaCloud provider, to the free17000-17999range to keep error codes unambiguous (#11382) - Azure provider authentication against sovereign clouds (
AzureChinaCloud,AzureUSGovernment) (#10284)
[5.28.1] (Prowler v5.28.1)
🐞 Fixed
compute_project_os_login_enabledandcompute_project_os_login_2fa_enabledchecks for GCP provider no longer false-FAIL on projects where theenable-oslogin/enable-oslogin-2fametadata is not set explicitly but is inherited automatically from theconstraints/compute.requireOsLoginorg policy. The policy controller writes the inherited value in lowercase ("true"), but the service-layer parser compared it to the uppercase string literal"TRUE". Comparison is now case-insensitive (#11341)storage_smb_channel_encryption_with_secure_algorithmcheck for Azure provider no longer passes when a storage account allows a weak SMB channel encryption algorithm (e.g.AES-128-CCM/AES-128-GCM) alongsideAES-256-GCM; it now requires every enabled algorithm to be in the recommended list, configurable viaazure.recommended_smb_channel_encryption_algorithms(defaults toAES-256-GCMonly, as required by CIS) (#11327)- Azure and M365 providers crashing with
RuntimeError: There is no current event loopon Python 3.12 when called from threads without an active event loop (e.g. Celery workers) (#11360)
[5.28.0] (Prowler v5.28.0)
🚀 Added
- Sites, Additional Google services, and Marketplace checks for Google Workspace provider using the Cloud Identity Policy API (#11281)
entra_app_registration_client_secret_unusedcheck for M365 provider (#11232)cloudsql_instance_cmek_encryption_enabledcheck for GCP provider (#11023)- Google Workspace Groups service with 3 new checks (#11186)
ses_identity_dkim_enabledcheck for AWS provider (#10923)sagemaker_models_registry_in_usecheck for AWS provider, verifying that at least one SageMaker Model Package Group has an approved model package to enforce ML governance workflows (#11196)signon_dod_warning_banner_configured,signon_global_session_lifetime_18h,signon_global_session_cookies_not_persistentandsignon_global_session_policy_network_zone_enforcedchecks for Okta provider (#11224)
🔄 Changed
OktaProvider.test_connectionaccepts an optionalprovider_id(org domain) and raisesOktaInvalidProviderIdError(14007) when it doesn't match the authenticated org — guards against stored UID drifting from the credentials' org (#11184)- Use single-quoted strings for credential variables in the M365 provider PowerShell session, following PowerShell best practices for literal values (#9997)
🐞 Fixed
- OCI Audit service configuration lookup when the configured region differs from the tenancy home region (#10347)
- Container image now uses an absolute
ENTRYPOINT(/home/prowler/.venv/bin/prowler) so it works under any runtime--workdir. The relative entrypoint was breaking the official GitHub Action (prowler-cloud/prowler@v5.27.0) and anydocker runwith a custom-w(#11313)
[5.27.1] (Prowler v5.27.1)
🐞 Fixed
s3_bucket_shadow_resource_vulnerabilityno longer emits a tautologicalPASSfinding for every bucket; a finding is now produced only when the bucket name matches one of the predictable service patterns (Glue, SageMaker, EMR, CodeStar) (#11220)sqlserver_tde_encrypted_with_cmkcheck for Azure provider no longer reports a falseFAILfor SQL Servers whose user databases are correctly encrypted with a customer-managed key, by excluding the systemmasterdatabase (always reports TDEDisabledand is not customer-controllable) from the TDE evaluation (#11233)
[5.27.0] (Prowler v5.27.0)
🚀 Added
- 6 Chat file sharing, external messaging, spaces, and apps access checks for Google Workspace provider using the Cloud Identity Policy API (#11126)
entra_service_principal_no_secrets_for_permanent_tier0_rolescheck for M365 provider (#10788)iam_user_access_not_stale_to_sagemakercheck for AWS provider with configurablemax_unused_sagemaker_access_days(default 90) (#11000)cloudtrail_bedrock_logging_enabledcheck for AWS provider (#10858)- Per-provider scan configuration schema with bounds validation that drops out-of-range values with a warning on config load (#11518)
- Okta provider with OAuth 2.0 authentication and
signon_global_session_idle_timeout_15mincheck (#11079) sagemaker_domain_sso_configuredcheck for AWS provider (#11094)- Scaleway provider with
iam_api_keys_no_root_ownedcheck (#11166)
🔄 Changed
entra_emergency_access_exclusioncheck for M365 provider now scopes the exclusion requirement to enabled Conditional Access policies with aBlockgrant control instead of every enabled policy, focusing on the lockout-relevant policy set (#10849)- AWS IAM customer-managed policy checks no longer emit
FAILon unattached policies unless--scan-unused-servicesis enabled (#11150) - Replace
poetrywithuvas package manager (#11162) - Replace
safetywithosv-scannerfor dependency vulnerability scanning in SDK CI and pre-commit (#11167)
🐞 Fixed
- Google Workspace Directory checks sharing a single resource row, causing the service field to be overwritten by the last check executed (#11176)
- Google Workspace Calendar and Drive services sharing a single resource row, causing the service field to be overwritten by the last check executed (#11161)
zone_waf_enabledcheck for Cloudflare provider now appends a plan-aware hint to the FAILstatus_extended: a possible-false-positive note on paid plans (Pro, Business, Enterprise) where the legacywafzone setting can readoffeven though WAF managed rulesets are deployed via the dashboard, and a "not available on the Cloudflare Free plan" note on Free zones (#9896)- Google Workspace Gmail checks sharing a single resource row, causing the service field to be overwritten by the last check executed (#11169)
- Google Workspace Drive and Calendar services missing server-side policy filters (#11195)
entra_users_mfa_capableandentra_break_glass_account_fido2_security_key_registeredreport a preventive FAIL per affected user (with the missing permission named) when the M365 service principal lacksAuditLog.Read.All, instead of mass false positives (#10907)- Duplicated GCP CIS requirements IDs (#11180)
VercelSession.tokenis now excluded from serialization and representation to prevent the Vercel API token from leaking through.dict(),.json()or logs (#11198)
[5.26.1] (Prowler v5.26.1)
🐞 Fixed
entra_users_mfa_capableno longer flags disabled guest users by requestingaccountEnabledanduserTypefrom Microsoft Graph via$selectand using Graph as the source of truth foraccount_enabled(EXOGet-Userdoes not return guest users) (#11002)
[5.26.0] (Prowler v5.26.0)
🚀 Added
bedrock_guardrails_configuredcheck for AWS provider (#10844)- Universal compliance with OCSF support (#10301)
- ASD Essential Eight Maturity Model compliance framework for AWS (Maturity Level One, Nov 2023) (#10808)
- Vercel checks to return personalized finding status extended depending on billing plan and classify them with billing-plan categories (#10663)
bedrock_prompt_management_existscheck for AWS provider (#10878)- 8 Gmail attachment safety and spoofing protection checks for Google Workspace provider using the Cloud Identity Policy API (#10980)
bedrock_prompt_encrypted_with_cmkcheck for AWS provider (#10905)
🔄 Changed
- Azure Network Watcher flow log checks now require workspace-backed Traffic Analytics for
network_flow_log_captured_sentand align metadata with VNet-compatible flow log guidance (#10645) - Azure compliance entries for legacy Network Watcher flow log controls now use retirement-aware guidance and point new deployments to VNet flow logs (#10937)
- AWS CodeBuild service now batches
BatchGetProjectsandBatchGetBuildscalls per region (up to 100 items per call) to reduce API call volume and prevent throttling-induced false positives incodebuild_project_not_publicly_accessible(#10639) display_compliance_tabledispatch switched from substringinchecks tostartswithto prevent false matches between similarly named frameworks (e.g.cisavscis) (#10301)- Restore the
ec2-imdsv1category for EC2 IMDS checks to keep Attack Surface and findings filters aligned (#10998) - Container image CVE findings and IaC findings now use official CVE, Prowler Hub, or GitHub Security Advisory URLs instead of Aqua advisory URLs in remediation and references; Trivy rule IDs map to Prowler Hub without the
AVD-prefix so links resolve (#10853)
🐞 Fixed
- AWS SDK test isolation: autouse
mock_awsfixture and leak detector inconftest.pyto prevent tests from hitting real AWS endpoints, with idempotent organization setup for tests callingset_mocked_aws_providermultiple times (#10605) - AWS
botouser agent extra is now applied to every client (#10944) - Image provider connection check no longer fails with a misleading
host='https'resolution error when the registry URL includes anhttp://orhttps://scheme prefix (#10950) - Azure subscriptions sharing the same display name are no longer collapsed into a single identity entry, so every subscription is scanned (#10718)
🔐 Security
- Parser-mismatch SSRF in image provider registry auth where crafted bearer-token realms and pagination links could force requests to internal addresses and leak credentials cross-origin (#10945)
cryptographyfrom 46.0.6 to 46.0.7 andtrivybinary from 0.69.2 to 0.70.0 in the SDK image for CVE-2026-39892 and CVE-2026-33186 (#10978)
[5.25.3] (Prowler v5.25.3)
🐞 Fixed
- Oracle Cloud identity scans known or supplied regions to better support non Ashburn tenancies (#10529)
[5.25.2] (Prowler v5.25.2)
🐞 Fixed
route53_dangling_ip_subdomain_takeovernow also flagsCNAMErecords pointing to S3 website endpoints whose buckets are missing from the account (#10920)- Duplicate Kubernetes RBAC findings when the same User or Group subject appeared in multiple ClusterRoleBindings (#10242)
- Match K8s RBAC rules by
apiGroup(#10969) - Return a compact actor name from CloudTrail
userIdentityevents (#10986)
[5.25.1] (Prowler v5.25.1)
🐞 Fixed
KeyErrorwhen generating compliance outputs after the CLI scan #10919- Kubernetes OCSF
provider_uidnow uses the cluster name in in-cluster mode (so--cluster-nameis correctly reflected in findings) and keeps the kubeconfig context in kubeconfig mode (#10483)
[5.25.0] (Prowler v5.25.0)
🚀 Added
--repo-list-fileCLI flag for GitHub provider to load repositories from a file (#10501)- SARIF output format for the IaC provider, enabling GitHub Code Scanning integration via
--output-formats sarif(#10626) repository_default_branch_dismisses_stale_reviewscheck for GitHub provider to ensure stale pull request approvals are dismissed when new commits are pushed (#10569)- Official Prowler GitHub Action (
prowler-cloud/prowler@5.25) for running scans in GitHub workflows with optional--push-to-cloudand SARIF upload to GitHub Code Scanning (#10872) - GitHub Actions service for scanning workflow security issues using zizmor (#10607)
secretsmanager_has_restrictive_resource_policycheck for AWS provider (#6985)
🐞 Fixed
- Alibaba Cloud CS service SDK compatibility, harden other services and improve documentation (#10871)
- AWS Organizations metadata retrieval for delegated administrator scans by using the assumed role session instead of the pre-assume credentials (#10894)
admincenter_groups_not_public_visibilitycheck for M365 provider evaluating Security and Distribution groups, now restricted to Microsoft 365 (Unified) groups per CIS M365 Foundations 1.2.1 (#10899)- Google Workspace check reports now store the actual domain or account resource subject instead of
provider.identity(#10901) entra_users_mfa_capableevaluating disabled guest accounts; CIS 5.2.3.4 only targets enabled member users (#10785)
[5.24.3] (Prowler v5.24.3)
🐞 Fixed
- CloudTrail resource timeline uses resource name as fallback in
LookupEvents(#10828) - Exclude
me-south-1andme-central-1from default AWS scans to prevent hangs when the host can't reach those regional endpoints (#10837)
[5.24.1] (Prowler v5.24.1)
🔄 Changed
msgraph-sdkfrom 1.23.0 to 1.55.0 andazure-mgmt-resourcefrom 23.3.0 to 24.0.0, removingmarshmallowas is a transitively dev dependency (#10733)
🐞 Fixed
- Cloudflare account-scoped API tokens failing connection test in the App with
CloudflareUserTokenRequiredError(#10723) prowler image --registry-listcrashes withAttributeErrorbecauseImageProvider.__init__returns early before registering the global provider (#10691)- Google Workspace Calendar checks false FAIL on unconfigured settings with secure Google defaults (#10726)
- Google Workspace Drive checks false FAIL on unconfigured settings with secure Google defaults (#10727)
- Cloudflare
validate_credentialscan hang in an infinite pagination loop when the SDK repeats accounts, blocking connection tests (#10771)
[5.24.0] (Prowler v5.24.0)
🚀 Added
entra_conditional_access_policy_directory_sync_account_excludedcheck for M365 provider (#10620)intune_device_compliance_policy_unassigned_devices_not_compliant_by_defaultcheck for M365 provider (#10599)entra_conditional_access_policy_all_apps_all_userscheck for M365 provider (#10619)bedrock_full_access_policy_attachedcheck for AWS provider (#10577)iam_role_access_not_stale_to_bedrockandiam_user_access_not_stale_to_bedrockchecks for AWS provider (#10536)iam_policy_no_wildcard_marketplace_subscribeandiam_inline_policy_no_wildcard_marketplace_subscribechecks for AWS provider (#10525)bedrock_vpc_endpoints_configuredcheck for AWS provider (#10591)exchange_organization_delicensing_resiliency_enabledcheck for M365 provider (#10608)entra_conditional_access_policy_mfa_enforced_for_guest_userscheck for M365 provider (#10616)entra_conditional_access_policy_corporate_device_sign_in_frequency_enforcedcheck for M365 provider (#10618)entra_conditional_access_policy_block_unknown_device_platformscheck for M365 provider (#10615)--excluded-regionCLI flag,PROWLER_AWS_DISALLOWED_REGIONSenvironment variable, andaws.disallowed_regionsconfig entry to skip specific AWS regions during scans (#10688)
🔄 Changed
- Bump Poetry to
2.3.4and consolidate SDK workflows onto thesetup-python-poetrycomposite action with opt-in lockfile regeneration (#10681) - Normalize Conditional Access platform values in Entra models and simplify platform-based checks (#10635)
🐞 Fixed
prowler image --registry-listcrashes withAttributeErrorbecauseImageProvider.__init__returns early before registering the global provider (#10691)- Vercel firewall config handling for team-scoped projects and current API response shapes (#10695)
- 9 Gmail checks for Google Workspace provider (
gmail_mail_delegation_disabled,gmail_shortener_scanning_enabled,gmail_external_image_scanning_enabled,gmail_untrusted_link_warnings_enabled,gmail_pop_imap_access_disabled,gmail_auto_forwarding_disabled,gmail_per_user_outbound_gateway_disabled,gmail_enhanced_pre_delivery_scanning_enabled,gmail_comprehensive_mail_storage_enabled) using the Cloud Identity Policy API (#10683)
[5.23.0] (Prowler v5.23.0)
🚀 Added
apikeys_api_restricted_with_gemini_apiandgemini_api_disabledchecks for GCP provider (#10280)cloudfront_distributions_logging_enableddetects Standard Logging v2 via CloudWatch Log Delivery (#10090)glue_etl_jobs_no_secrets_in_argumentscheck for plaintext secrets in AWS Glue ETL job arguments (#10368)awslambda_function_no_dead_letter_queue,awslambda_function_using_cross_account_layers, andawslambda_function_env_vars_not_encrypted_with_cmkchecks for AWS Lambda (#10381)entra_conditional_access_policy_mdm_compliant_device_requiredcheck for M365 provider (#10220)directory_super_admin_only_admin_rolescheck for Google Workspace provider (#10488)ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipcheck for AWS provider usingipaddress.is_globalfor accurate public IP detection (#10335)entra_conditional_access_policy_block_o365_elevated_insider_riskcheck for M365 provider (#10232)--resource-groupand--list-resource-groupsCLI flags to filter checks by resource group across all providers (#10479)- CISA SCuBA Google Workspace Baselines compliance (#10466)
- CIS Google Workspace Foundations Benchmark v1.3.0 compliance (#10462)
calendar_external_sharing_primary_calendar,calendar_external_sharing_secondary_calendar, andcalendar_external_invitations_warningchecks for Google Workspace provider using the Cloud Identity Policy API (#10597)- 11 Drive and Docs checks for Google Workspace provider (
drive_external_sharing_warn_users,drive_publishing_files_disabled,drive_sharing_allowlisted_domains,drive_warn_sharing_with_allowlisted_domains,drive_access_checker_recipients_only,drive_internal_users_distribute_content,drive_shared_drive_creation_allowed,drive_shared_drive_managers_cannot_override,drive_shared_drive_members_only_access,drive_shared_drive_disable_download_print_copy,drive_desktop_access_disabled) using the Cloud Identity Policy API (#10648) entra_conditional_access_policy_device_registration_mfa_requiredcheck andentra_intune_enrollment_sign_in_frequency_every_timeenhancement for M365 provider (#10222)entra_conditional_access_policy_block_elevated_insider_riskcheck for M365 provider (#10234)Vercelprovider support with 30 checks (#10189)internet-exposedcategory for 13 AWS checks (CloudFront, CodeArtifact, EC2, EFS, RDS, SageMaker, Shield, VPC) (#10502)stepfunctions_statemachine_no_secrets_in_definitioncheck for hardcoded secrets in AWS Step Functions state machine definitions (#10570)- CCC improvements with the latest checks and new mappings (#10625)
🔄 Changed
- Minimum Python version from 3.9 to 3.10 and updated classifiers to reflect supported versions (3.10, 3.11, 3.12) (#10464)
- Pin direct SDK dependencies to exact versions and rely on
poetry.lockartifact hashes for reproducible installs (#10593) - Sensitive CLI flags now warn when values are passed directly, recommending environment variables instead (#10532)
🐞 Fixed
- OCI mutelist support: pass
tenancy_idtois_finding_mutedand updateoraclecloud_mutelist_example.yamlto useAccountskey (#10566) returnstatements infinallyblocks replaced across IAM, Organizations, GCP provider, and custom checks metadata to stop silently swallowing exceptions (#10102)JiraConnectionnow includes issue types per project fetched duringtest_connection, fixingJiraInvalidIssueTypeErroron non-English Jira instances (#10534)--list-checksand--list-checks-jsonnow includethreat-detectioncategory checks in their output (#10578)- Missing
__init__.pyincodebuild_project_uses_allowed_github_organizationscheck preventing discovery by--list-checks(#10584) - Azure Key Vault checks emitting incorrect findings for keys, secrets, and vault logging (#10332)
is_policy_publicnow recognizeskms:CallerAccount,kms:ViaService,aws:CalledVia,aws:CalledViaFirst, andaws:CalledViaLastas restrictive condition keys, fixing false positives inkms_key_policy_is_not_publicand other checks that useis_condition_block_restrictive(#10600)_enabled_regionsempty-set bug inAwsProvider.generate_regional_clientscreating boto3 clients for all 36 AWS regions instead of the audited ones, causing random CI timeouts and slow test runs (#10598)- Retrieve only the latest version from a package in AWS CodeArtifact (#10243)
- AWS global services (CloudFront, Route53, Shield, FMS) now use the partition's global region instead of the profile's default region (#10458)
- Oracle Cloud
events_rule_idp_group_mapping_changesnow recognizes the CIS 3.1add/removeevent names to avoid false positives (#10416) - Oracle Cloud password policy checks now exclude immutable system-managed policies (
SimplePasswordPolicy,StandardPasswordPolicy) to avoid false positives (#10453) - Oracle Cloud
kms_key_rotation_enablednow checks current key version age to avoid false positives on vaults without auto-rotation support (#10450) - OCI filestorage, blockstorage, KMS, and compute services now honor
--regionfor scanning outside the tenancy home region (#10472) - OCI provider now supports multi-region filtering via
--region(#10473) prowler image --registryfailing withImageNoImagesProvidedErrordue to registry arguments not being forwarded toImageProviderininit_global_provider(#10470)- OCI multi-region support for identity client configuration in blockstorage, identity, and filestorage services (#10520)
- Google Workspace Calendar checks now filter for customer-level policies only, skipping OU and group overrides that could produce incorrect audit results (#10658)
🔐 Security
- Sensitive CLI flag values (tokens, keys, passwords) in HTML output "Parameters used" field now redacted to prevent credential leaks (#10518)
authlibbumped from 1.6.5 to 1.6.9 to fix CVE-2026-28802 (JWTalg: nonevalidation bypass) (#10579)cryptographybumped from 44.0.3 to 46.0.6 (CVE-2026-26007, CVE-2026-34073),ocito 2.169.0, andalibabacloud-tea-openapito 0.4.4 (#10535)aiohttpbumped from 3.13.3 to 3.13.5 to fix CVE-2026-34520 (the C parser accepted null bytes and control characters in response headers) (#10537)
[5.22.0] (Prowler v5.22.0)
🐞 Fixed
- Azure MySQL flexible server checks now compare configuration values case-insensitively to avoid false negatives when Azure returns lowercase values (#10396)
- Azure
vm_backup_enabledandvm_sufficient_daily_backup_retention_periodchecks now compare VM names case-insensitively to avoid false negatives when Azure stores backup item names in a different case (#10395) entra_non_privileged_user_has_mfaskips disabled users to avoid false positives (#10426)
[5.21.0] (Prowler v5.21.0)
🚀 Added
misconfigscanner as default for Image provider scans (#10167)entra_conditional_access_policy_device_code_flow_blockedcheck for M365 provider (#10218)- RBI compliance for the Azure provider (#10339)
-
entra_conditional_access_policy_require_mfa_for_admin_portalscheck for Azure provider and update CIS compliance (#10330) - CheckMetadata Pydantic validators (#8583)
organization_repository_deletion_limitedcheck for GitHub provider (#10185)- SecNumCloud 3.2 for the GCP provider (#10364)
- SecNumCloud 3.2 for the Azure provider (#10358)
- SecNumCloud 3.2 for the Alibaba Cloud provider (#10370)
- SecNumCloud 3.2 for the Oracle Cloud provider (#10371)
🔄 Changed
- Bump
pygithubfrom 2.5.0 to 2.8.0 to use native Organization properties - Update M365 SharePoint service metadata to new format (#9684)
- Update M365 Exchange service metadata to new format (#9683)
- Update M365 Teams service metadata to new format (#9685)
- Update M365 Entra ID service metadata to new format (#9682)
- Update ResourceType and Categories for Azure Entra ID service metadata (#10334)
- Update OCI Regions to include US DoD regions (#10375)
🐞 Fixed
- Route53 dangling IP check false positive when using
--regionflag (#9952) - RBI compliance framework support on Prowler Dashboard for the Azure provider (#10360)
- CheckMetadata strict validators rejecting valid external tool provider data (image, iac, llm) (#10363)
🔐 Security
- Bump
multipartto 1.3.1 to fix GHSA-p2m9-wcp5-6qw3 (#10331)
[5.20.0] (Prowler v5.20.0)
🚀 Added
entra_conditional_access_policy_approved_client_app_required_for_mobilecheck for M365 provider (#10216)entra_conditional_access_policy_compliant_device_hybrid_joined_device_mfa_requiredcheck for M365 provider (#10197)trusted_ipsconfigurable option foropensearch_service_domains_not_publicly_accessiblecheck to reduce false positives on IP-restricted policies (#8631)guardduty_delegated_admin_enabled_all_regionscheck for AWS provider (#9867)- OpenStack object storage service with 7 checks (#10258)
- AWS Organizations OU metadata (OU ID, OU path) in ASFF, OCSF and CSV outputs (#10283)
🔄 Changed
- Update Kubernetes API server checks metadata to new format (#9674)
- Update Kubernetes Controller Manager service metadata to new format (#9675)
- Update Kubernetes Core service metadata to new format (#9676)
- Update Kubernetes Kubelet service metadata to new format (#9677)
- Update Kubernetes RBAC service metadata to new format (#9678)
- Update Kubernetes Scheduler service metadata to new format (#9679)
- Update MongoDB Atlas Organizations service metadata to new format (#9658)
- Update MongoDB Atlas clusters service metadata to new format (#9657)
- Update GitHub Repository service metadata to new format (#9659)
- Update GitHub Organization service metadata to new format (#10273)
- Update Oracle Cloud Compute Engine service metadata to new format (#9371)
- Update Oracle Cloud Database service metadata to new format (#9372)
- Update Oracle Cloud File Storage service metadata to new format (#9374)
- Update Oracle Cloud Integration service metadata to new format (#9376)
- Update Oracle Cloud KMS service metadata to new format (#9377)
- Update Oracle Cloud Network service metadata to new format (#9378)
- Update Oracle Cloud Object Storage service metadata to new format (#9379)
- Update Oracle Cloud Events service metadata to new format (#9373)
- Update Oracle Cloud Identity service metadata to new format (#9375)
- Update Alibaba Cloud services metadata to new format (#10289)
- Update M365 Admin Center service metadata to new format (#9680)
- Update M365 Defender service metadata to new format (#9681)
- Update M365 Purview service metadata to new format (#9092)
[5.19.0] (Prowler v5.19.0)
🚀 Added
entra_authentication_method_sms_voice_disabledcheck for M365 provider (#10212)Google Workspaceprovider support with Directory service including 1 security check (#10022)entra_conditional_access_policy_app_enforced_restrictionscheck for M365 provider (#10058)entra_app_registration_no_unused_privileged_permissionscheck for M365 provider (#10080)defenderidentity_health_issues_no_opencheck for M365 provider (#10087)organization_verified_badgecheck for GitHub provider (#10033)- OpenStack provider
clouds_yaml_contentparameter for API integration (#10003) defender_safe_attachments_policy_enabledcheck for M365 provider (#9833)defender_safelinks_policy_enabledcheck for M365 provider (#9832)- CSA CCM 4.0 for the AWS provider (#10018)
- CSA CCM 4.0 for the GCP provider (#10042)
- CSA CCM 4.0 for the Azure provider (#10039)
- CSA CCM 4.0 for the Oracle Cloud provider (#10057)
- OCI regions updater script and CI workflow (#10020)
imageprovider for container image scanning with Trivy integration (#9984)- CSA CCM 4.0 for the Alibaba Cloud provider (#10061)
- ECS Exec (ECS-006) privilege escalation detection via
ecs:ExecuteCommand+ecs:DescribeTasks(#10066) --export-ocsfCLI flag to upload OCSF scan results to Prowler Cloud (#10095)scan_idfield in OCSFunmappedoutput for ingestion correlation (#10095)defenderxdr_endpoint_privileged_user_exposed_credentialscheck for M365 provider (#10084)defenderxdr_critical_asset_management_pending_approvalscheck for M365 provider (#10085)entra_seamless_sso_disabledcheck for M365 provider (#10086)- Registry scan mode for
imageprovider: enumerate and scan all images from OCI standard, Docker Hub, and ECR (#9985) - File descriptor limits (
ulimits) for Docker Compose worker services to preventToo many open fileserrors (#10107) - SecNumCloud compliance framework for the AWS provider (#10117)
- CIS 6.0 for the AWS provider (#10127)
entra_conditional_access_policy_require_mfa_for_management_apicheck for M365 provider (#10150)- OpenStack provider multiple regions support (#10135)
entra_break_glass_account_fido2_security_key_registeredcheck for M365 provider (#10213)entra_default_app_management_policy_enabledcheck for M365 provider (#9898)- OpenStack networking service with 6 security checks (#9970)
- OpenStack block storage service with 7 security checks (#10120)
- OpenStack compute service with 7 security checks (#9944)
- OpenStack image service with 6 security checks (#10096)
--provider-uidCLI flag for IaC provider, used ascloud.account.uidin OCSF output and required with--export-ocsf(#10233)unmapped.provider_uidfield in OCSF output to match CLI scan results with API provider entities during ingestion (#10231)unmapped.providerfield in OCSF output for provider name availability in non-cloud providers like Kubernetes (#10240)
🔄 Changed
- Update Azure Monitor service metadata to new format (#9622)
- GitHub provider enhanced documentation and
repository_branch_delete_on_merge_enabledlogic (#9830) - Parallelize Cloudflare zone API calls with threading to improve scan performance (#9982)
- Update GCP API Keys service metadata to new format (#9637)
- Update GCP BigQuery service metadata to new format (#9638)
- Update GCP Cloud SQL service metadata to new format (#9639)
- Update GCP Cloud Storage service metadata to new format (#9640)
- Update GCP Compute Engine service metadata to new format (#9641)
- Update GCP Dataproc service metadata to new format (#9642)
- Update GCP DNS service metadata to new format (#9643)
- Update GCP GCR service metadata to new format (#9644)
- Update GCP GKE service metadata to new format (#9645)
- Update GCP IAM service metadata to new format (#9646)
- Update GCP KMS service metadata to new format (#9647)
- Update GCP Logging service metadata to new format (#9648)
- Update Azure Key Vault service metadata to new format (#9621)
- Update Azure Entra ID service metadata to new format (#9619)
- Update Azure Virtual Machines service metadata to new format (#9629)
- Cloudflare provider credential validation with specific exceptions (#9910)
- Enhance AWS IAM privilege escalation detection with patterns from pathfinding.cloud library (#9922)
- Bump Trivy from 0.66.0 to 0.69.2 (#10210)
- Standardize GitHub and M365 provider account UIDs for consistent OCSF output (#10226)
- Standardize Cloudflare account and resource UIDs to prevent None values in findings (#10227)
🐞 Fixed
- Google Workspace provider
test_connection()missingprovider_idparameter for API integration (#10247) - Update AWS checks metadata URLs to replace deprecated Trend Micro CloudOne Conformity (EOL July 2026) with Vision One and remove docs.prowler.com references (#10068)
- Standardize resource_id values across Azure checks to use actual Azure resource IDs and prevent duplicate resource entries (#9994)
- VPC endpoint service collection filtering third-party services that caused AccessDenied errors on
DescribeVpcEndpointServicePermissions(#10152) - Handle serialization errors in OCSF output for non-serializable resource metadata (#10129)
- Respect
AWS_ENDPOINT_URLenvironment variable for STS session creation (#10228) - Help text and typos in CLI flags (#10040)
elbv2_insecure_ssl_ciphersfalse positive on AWS post-quantum (PQ) TLS policies likeELBSecurityPolicy-TLS13-1-2-PQ-2025-09(#10219)
🔐 Security
- Bumped
py-ocsf-modelsto 0.8.1 andcryptographyto 44.0.3 (#10059) - Harden GitHub Actions workflows against expression injection, add
persist-credentials: falseto checkout steps, and configure dependabot cooldown (#10200)
[5.18.3] (Prowler v5.18.3)
🐞 Fixed
pip install prowlerfailing on systems without C compiler due tonetifacestransitive dependency fromopenstacksdk(#10055)kms_key_not_publicly_accessiblefalse negative for specific KMS actions (e.g.,kms:DescribeKey,kms:Decrypt) with unrestricted principals (#10071)- Remove account_id and location for manual requirements in M365CIS (#10105)
[5.18.2] (Prowler v5.18.2)
🐞 Fixed
--repositoryand--organizationflags combined interaction in GitHub provider, qualifying unqualified repository names with organization (#10001)- HPACK library logging tokens in debug mode for Azure, M365, and Cloudflare providers (#10010)
🐞 Fixed
- Use
defusedxmlin the Alibaba Cloud OSS service to prevent XXE vulnerabilities when parsing XML responses (#9999)
[5.18.0] (Prowler v5.18.0)
🚀 Added
entra_emergency_access_exclusioncheck for M365 provider (#9903)defender_zap_for_teams_enabledcheck for M365 provider (#9838)compute_instance_suspended_without_persistent_diskscheck for GCP provider (#9747)codebuild_project_webhook_filters_use_anchored_patternscheck for AWS provider to detect CodeBreach vulnerability (#9840)defender_atp_safe_attachments_policy_enabledcheck for M365 provider (#9837)exchange_shared_mailbox_sign_in_disabledcheck for M365 provider (#9828)- CloudTrail Timeline abstraction for querying resource modification history (#9101)
- Cloudflare
--account-idfilter argument (#9894) entra_all_apps_conditional_access_coveragecheck for M365 provider (#9902)rds_instance_extended_supportcheck for AWS provider (#9865)OpenStackprovider support with Compute service including 1 security check (#9811)OpenStackdocumentation for the support in the CLI (#9848)- Add HIPAA compliance framework for the Azure provider (#9957)
- Cloudflare provider credentials as constructor parameters (
api_token,api_key,api_email) (#9907) - CIS 3.1 for the Oracle Cloud provider (#9971)
🔄 Changed
- Update Azure App Service service metadata to new format (#9613)
- Update Azure Application Insights service metadata to new format (#9614)
- Update Azure Container Registry service metadata to new format (#9615)
- Update Azure Cosmos DB service metadata to new format (#9616)
- Update Azure Databricks service metadata to new format (#9617)
- Parallelize Azure Key Vault vaults and vaults contents retrieval to improve performance (#9876)
- Update Azure IAM service metadata to new format (#9620)
- Update Azure Policy service metadata to new format (#9625)
- Update Azure MySQL service metadata to new format (#9623)
- Update Azure Defender service metadata to new format (#9618)
- Make AWS cross-account checks configurable through
trusted_account_idsconfig parameter (#9692) - Update Azure PostgreSQL service metadata to new format (#9626)
- Update Azure SQL Server service metadata to new format (#9627)
- Update Azure Network service metadata to new format (#9624)
- Update Azure Storage service metadata to new format (#9628)
🐞 Fixed
- Duplicated findings in
entra_user_with_vm_access_has_mfacheck when user has multiple VM access roles (#9914) - Jira integration failing with
INVALID_INPUTerror when sending findings with long resource UIDs exceeding 255-character summary limit (#9926) - CSV/XLSX download failure in dashboard (#9946)
[5.17.0] (Prowler v5.17.0)
Added
- AI Skills pack for AI coding assistants (Claude Code, OpenCode, Codex) following agentskills.io standard (#9728)
- Prowler ThreatScore for the Alibaba Cloud provider (#9511)
compute_instance_group_multiple_zonescheck for GCP provider (#9566)compute_instance_group_autohealing_enabledcheck for GCP provider (#9690)- Support AWS European Sovereign Cloud (#9649)
compute_instance_disk_auto_delete_disabledcheck for GCP provider (#9604)- Bedrock service pagination (#9606)
ResourceGroupfield to all check metadata for resource classification (#9656)compute_configuration_changescheck for GCP provider to detect Compute Engine configuration changes in Cloud Audit Logs (#9698)compute_instance_group_load_balancer_attachedcheck for GCP provider (#9695)Cloudflareprovider with critical security checks (#9423)- CloudFlare
TLS/SSL,recordsandemailchecks forzoneservice (#9424) compute_instance_single_network_interfacecheck for GCP provider (#9702)compute_image_not_publicly_sharedcheck for GCP provider (#9718)compute_snapshot_not_outdatedcheck for GCP provider (#9774)compute_project_os_login_2fa_enabledcheck for GCP provider (#9839)compute_instance_on_host_maintenance_migratecheck for GCP provider (#9834)- CIS 1.12 compliance framework for Kubernetes (#9778)
- CIS 6.0 for M365 provider (#9779)
- CIS 5.0 compliance framework for the Azure provider (#9777)
CloudflareBot protection, WAF, Privacy, Anti-Scraping and Zone configuration checks (#9425)Cloudflarewafanddns recordchecks (#9426)
Changed
- Update AWS Step Functions service metadata to new format (#9432)
- Update AWS Route 53 service metadata to new format (#9406)
- Update AWS SQS service metadata to new format (#9429)
- Update AWS Shield service metadata to new format (#9427)
- Update AWS Secrets Manager service metadata to new format (#9408)
- Improve SageMaker service tag retrieval with parallel execution (#9609)
- Update AWS Redshift service metadata to new format (#9385)
- Update AWS Storage Gateway service metadata to new format (#9433)
- Update AWS Well-Architected service metadata to new format (#9482)
- Update AWS SSM service metadata to new format (#9430)
- Update AWS Organizations service metadata to new format (#9384)
- Update AWS Resource Explorer v2 service metadata to new format (#9386)
- Update AWS SageMaker service metadata to new format (#9407)
- Update AWS Security Hub service metadata to new format (#9409)
- Update AWS SES service metadata to new format (#9411)
- Update AWS SSM Incidents service metadata to new format (#9431)
- Update AWS WorkSpaces service metadata to new format (#9483)
- Update AWS OpenSearch service metadata to new format (#9383)
- Update AWS VPC service metadata to new format (#9479)
- Update AWS Transfer service metadata to new format (#9434)
- Update AWS S3 service metadata to new format (#9552)
- Update AWS DataSync service metadata to new format (#8854)
- Update AWS RDS service metadata to new format (#9551)
- Update AWS Bedrock service metadata to new format (#8827)
- Update AWS IAM service metadata to new format (#9550)
- Enhance
user_registration_detailsperfomance and usermfaevaluation (#9236) - Update AWS Cognito service metadata to new format (#8853)
- Update AWS EC2 service metadata to new format (#9549)
- Update Azure AI Search service metadata to new format (#9087)
- Update Azure AKS service metadata to new format (#9611)
- Update Azure API Management service metadata to new format (#9612)
Fixed
Security
safetyto3.7.0andfilelockto3.20.3due to Safety vulnerability 82754 (CVE-2025-68146) (#9816)pyasn1to v0.6.2 to address CVE-2026-23490 (#9817)
[5.16.1] (Prowler v5.16.1)
Fixed
- ZeroDivision error from Prowler ThreatScore (#9653)
[5.16.0] (Prowler v5.16.0)
Added
privilege-escalationandec2-imdsv1categories for AWS checks (#9537)- Supported IaC formats and scanner documentation for the IaC provider (#9553)
Changed
- Update AWS Glue service metadata to new format (#9258)
- Update AWS Kafka service metadata to new format (#9261)
- Update AWS KMS service metadata to new format (#9263)
- Update AWS MemoryDB service metadata to new format (#9266)
- Update AWS Inspector v2 service metadata to new format (#9260)
- Update AWS Service Catalog service metadata to new format (#9410)
- Update AWS SNS service metadata to new format (#9428)
- Update AWS Trusted Advisor service metadata to new format (#9435)
- Update AWS WAF service metadata to new format (#9480)
- Update AWS WAF v2 service metadata to new format (#9481)
Fixed
- Fix typo
trustboundariescategory totrust-boundaries(#9536) - Fix incorrect
bedrock-agentregional availability, now using official AWS docs instead of copying frombedrock - Store MongoDB Atlas provider regions as lowercase (#9554)
- Store GCP Cloud Storage bucket regions as lowercase (#9567)
[5.15.1] (Prowler v5.15.1)
Fixed
- Fix false negative in AWS
apigateway_restapi_logging_enabledcheck by refining stage logging evaluation to ensure logging level is not set to "OFF" (#9304)
[5.15.0] (Prowler v5.15.0)
Added
cloudstorage_uses_vpc_service_controlscheck for GCP provider (#9256)- Alibaba Cloud provider with CIS 2.0 benchmark (#9329)
repository_immutable_releases_enabledcheck for GitHub provider (#9162)compute_instance_preemptible_vm_disabledcheck for GCP provider (#9342)compute_instance_automatic_restart_enabledcheck for GCP provider (#9271)compute_instance_deletion_protection_enabledcheck for GCP provider (#9358)- Add needed changes to AlibabaCloud provider from the API (#9485)
- Update SOC2 - Azure with Processing Integrity requirements (#9463)
- Update SOC2 - GCP with Processing Integrity requirements (#9464)
- Update SOC2 - AWS with Processing Integrity requirements (#9462)
- RBI Cyber Security Framework compliance for Azure provider (#8822)
Changed
- Update AWS Macie service metadata to new format (#9265)
- Update AWS Lightsail service metadata to new format (#9264)
- Update AWS GuardDuty service metadata to new format (#9259)
- Update AWS Network Firewall service metadata to new format (#9382)
- Update AWS MQ service metadata to new format (#9267)
- Update AWS Macie service metadata to new format (#9265)
- Update AWS Lightsail service metadata to new format (#9264)
Fixed
- Fix duplicate requirement IDs in ISO 27001:2013 AWS compliance framework by adding unique letter suffixes
- Removed incorrect threat-detection category from checks metadata (#9489)
- GCP
cloudstorage_uses_vpc_service_controlscheck to handle VPC Service Controls blocked API access (#9478)
[5.14.2] (Prowler v5.14.2)
Fixed
- Custom check folder metadata validation (#9335)
- Pin
alibabacloud-gateway-oss-utilto version 0.0.3 to address missing dependency (#9487)
[5.14.1] (Prowler v5.14.1)
Fixed
sharepoint_external_sharing_managedcheck to handle external sharing disabled at organization level (#9298)- Support multiple Exchange mailbox policies in M365
exchange_mailbox_policy_additional_storage_restrictedcheck (#9241)
[5.14.0] (Prowler v5.14.0)
Added
- GitHub provider check
organization_default_repository_permission_strict(#8785) - Add OCI mapping to scan and check classes (#8927)
codepipeline_project_repo_privatecheck for AWS provider (#5915)cloudstorage_bucket_versioning_enabledcheck for GCP provider (#9014)cloudstorage_bucket_soft_delete_enabledcheck for GCP provider (#9028)cloudstorage_bucket_logging_enabledcheck for GCP provider (#9091)cloudstorage_audit_logs_enabledcheck for GCP provider (#9220)cloudstorage_bucket_sufficient_retention_periodcheck for GCP provider (#9149)- C5 compliance framework for Azure provider (#9081)
- C5 compliance framework for the GCP provider (#9097)
organization_repository_creation_limitedcheck for GitHub provider (#8844)- HIPAA compliance framework for the GCP provider (#8955)
- Support PDF reporting for ENS compliance framework (#9158)
- PDF reporting for NIS2 compliance framework (#9170)
- Add organization ID parameter for MongoDB Atlas provider (#9167)
- Add multiple compliance improvements (#9145)
- Added validation for invalid checks, services, and categories in
load_checks_to_executefunction (#8971) - NIST CSF 2.0 compliance framework for the AWS provider (#9185)
- Add FedRAMP 20x KSI Low for AWS, Azure and GCP (#9198)
- Add verification for provider ID in MongoDB Atlas provider (#9211)
- Add Prowler ThreatScore for the K8S provider (#9235)
- Add
postgresql_flexible_server_entra_id_authentication_enabledcheck for Azure provider (#8764) - Add branch name to IaC provider region (#9296)
Changed
- Update AWS Direct Connect service metadata to new format (#8855)
- Update AWS DRS service metadata to new format (#8870)
- Update AWS DynamoDB service metadata to new format (#8871)
- Update AWS CloudWatch service metadata to new format (#8848)
- Update AWS EMR service metadata to new format (#9002)
- Update AWS EKS service metadata to new format (#8890)
- Update AWS Elastic Beanstalk service metadata to new format (#8934)
- Update AWS ElastiCache service metadata to new format (#8933)
- Update Kubernetes etcd service metadata to new format (#9096)
- Update MongoDB Atlas projects service metadata to new format (#9093)
- Update GitHub Organization service metadata to new format (#9094)
- Update AWS CodeBuild service metadata to new format (#8851)
- Update GCP Artifact Registry service metadata to new format (#9088)
- Update AWS EFS service metadata to new format (#8889)
- Update AWS EventBridge service metadata to new format (#9003)
- Update AWS Firehose service metadata to new format (#9004)
- Update AWS FMS service metadata to new format (#9005)
- Update AWS FSx service metadata to new format (#9006)
- Update AWS Glacier service metadata to new format (#9007)
- Update oraclecloud analytics service metadata to new format (#9114)
- Update AWS ELB service metadata to new format (#8935)
- Update AWS CodeArtifact service metadata to new format (#8850)
- Rename OCI provider to oraclecloud with oci alias (#9126)
- Remove unnecessary tests for M365_PowerShell module (#9204)
- Update AWS ELB v2 service metadata to new format (#9001)
- Update oraclecloud cloudguard service metadata to new format (#9223)
- Update oraclecloud blockstorage service metadata to new format (#9222)
- Update oraclecloud audit service metadata to new format (#9221)
- Raise ASFF output error for non-AWS providers (#9225)
- Update AWS ECR service metadata to new format (#8872)
- Update AWS ECS service metadata to new format (#8888)
- Update AWS Kinesis service metadata to new format (#9262)
- Update AWS DocumentDB service metadata to new format (#8862)
- Adapt IaC provider to be used in the Prowler App (#8751)
Fixed
- Check
check_namehas noresource_nameerror for GCP provider (#9169) - Depth Truncation and parsing error in PowerShell queries (#9181)
- False negative in
iam_role_cross_service_confused_deputy_preventioncheck (#9213) - Fix M365 Teams
--sp-env-authconnection error and enhanced timeout logging (#9191) - Rename
get_oci_assessment_summarytoget_oraclecloud_assessment_summaryin HTML output (#9200) - Fix Validation and other errors in Azure provider (#8915)
- Update documentation URLs from docs.prowler.cloud to docs.prowler.com (#9240)
- Refresh output report timestamps for each scan (#9272)
- Fix file name parsing for checks on Windows (#9268)
- Remove typo for Prowler ThreatScore - M365 (#9274)
- Point HTML logo to the one present in the Github repository (#9282)
[5.13.1] (Prowler v5.13.1)
Fixed
- Add
resource_namefor checks underloggingfor the GCP provider (#9023) - Fix
ec2_instance_with_outdated_amicheck to handle None AMIs (#9046) - Handle timestamp when transforming compliance findings in CCC (#9042)
- Update
resource_idfor admincenter service and avoid unnecessary msgraph requests (#9019) - Fix
firehose_stream_encrypted_at_restdescription and findings clarity (#9142)
[5.13.0] (Prowler v5.13.0)
Added
- Support for AdditionalURLs in outputs (#8651)
- Support for markdown metadata fields in Dashboard (#8667)
ec2_instance_with_outdated_amicheck for AWS provider (#6910)- LLM provider using
promptfoo(#8555) - Documentation for renaming checks (#8717)
- Add explicit "name" field for each compliance framework and include "FRAMEWORK" and "NAME" in CSV output (#7920)
- Add C5 compliance framework for the AWS provider (#8830)
- Equality validation for CheckID, filename and classname (#8690)
- Improve logging for Security Hub integration (#8608)
- Oracle Cloud provider with CIS 3.0 benchmark (#8893)
- Support for Atlassian Document Format (ADF) in Jira integration (#8878)
- Add Common Cloud Controls for AWS, Azure and GCP (#8000)
- Improve Provider documentation guide (#8430)
cloudstorage_bucket_lifecycle_management_enabledcheck for GCP provider (#8936)
Changed
- Update AWS Neptune service metadata to new format (#8494)
- Update AWS Config service metadata to new format (#8641)
- Update AWS Account service metadata to new format (#8715)
- Update AWS AccessAnalyzer service metadata to new format (#8688)
- Update AWS Api Gateway V2 service metadata to new format (#8719)
- Update AWS AppSync service metadata to new format (#8721)
- Update AWS ACM service metadata to new format (#8716)
- HTML output now properly renders markdown syntax in Risk and Recommendation fields (#8727)
- Update
motodependency from 5.0.28 to 5.1.11 (#7100) - Update AWS AppStream service metadata to new format (#8789)
- Update AWS API Gateway service metadata to new format (#8788)
- Update AWS Athena service metadata to new format (#8790)
- Update AWS CloudTrail service metadata to new format (#8831)
- Update AWS Auto Scaling service metadata to new format (#8824)
- Update AWS Backup service metadata to new format (#8826)
- Update AWS CloudFormation service metadata to new format (#8828)
- Update AWS Lambda service metadata to new format (#8825)
- Update AWS DLM service metadata to new format (#8860)
- Update AWS DMS service metadata to new format (#8861)
- Update AWS Directory Service service metadata to new format (#8859)
- Update AWS CloudFront service metadata to new format (#8829)
- Deprecate user authentication for M365 provider (#8865)
Fixed
- Fix SNS topics showing empty AWS_ResourceID in Quick Inventory output (#8762)
- Fix HTML Markdown output for long strings (#8803)
- Prowler ThreatScore scoring calculation CLI (#8582)
- Add missing attributes for Mitre Attack AWS, Azure and GCP (#8907)
- Fix KeyError in CloudSQL and Monitoring services in GCP provider (#8909)
- Fix Value Errors in Entra service for M365 provider (#8919)
- Fix ResourceName in GCP provider (#8928)
- Fix KeyError in
elb_ssl_listeners_use_acm_certificatecheck and handle None cluster version ineks_cluster_uses_a_supported_versioncheck (#8791) - Fix file extension parsing for compliance reports (#8791)
- Added user pagination to Entra and Admincenter services (#8858)
[5.12.1] (Prowler v5.12.1)
Fixed
- Replaced old check id with new ones for compliance files (#8682)
firehose_stream_encrypted_at_restcheck false positives and new api call in kafka service (#8599)- Replace defender rules policies key to use old name (#8702)
[5.12.0] (Prowler v5.12.0)
Added
- Add more fields for the Jira ticket and handle custom fields errors (#8601)
- Support labels on Jira tickets (#8603)
- Add finding url and tenant info inside Jira tickets (#8607)
- Get Jira Project's metadata (#8630)
- Get Jira projects from test_connection (#8634)
AdditionalUrlsfield in CheckMetadata (#8590)- Support color for MANUAL finidngs in Jira tickets (#8642)
--excluded-checks-fileflag (#8301)- Send finding in Jira integration with the needed values (#8648)
- Add language enforcement for Jira requests (#8674)
- MongoDB Atlas provider with 10 security checks (#8312)
clusters_authentication_enabled- Ensure clusters have authentication enabledclusters_backup_enabled- Ensure clusters have backup enabledclusters_encryption_at_rest_enabled- Ensure clusters have encryption at rest enabledclusters_tls_enabled- Ensure clusters have TLS authentication requiredorganizations_api_access_list_required- Ensure organization requires API access listorganizations_mfa_required- Ensure organization requires MFAorganizations_security_contact_defined- Ensure organization has security contact definedorganizations_service_account_secrets_expiration- Ensure organization has maximum period expiration for service account secretsprojects_auditing_enabled- Ensure database auditing is enabledprojects_network_access_list_exposed_to_internet- Ensure project network access list is not exposed to internet
Changed
- Rename ftp and mongo checks to follow pattern
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_*(#8293)
Fixed
- Renamed
AdditionalUrlstoAdditionalURLsfield in CheckMetadata (#8639) - TypeError from Python 3.9 in Security Hub module by updating type annotations (#8619)
- KeyError when SecurityGroups field is missing in MemoryDB check (#8666)
- NoneType error in Opensearch, Firehose and Cognito checks (#8670)
[5.11.0] (Prowler v5.11.0)
Added
- Certificate authentication for M365 provider (#8404)
vm_sufficient_daily_backup_retention_periodcheck for Azure provider (#8200)vm_jit_access_enabledcheck for Azure provider (#8202)- Bedrock AgentCore privilege escalation combination for AWS provider (#8526)
- Add User Email and APP name/installations information in GitHub provider (#8501)
- Remove standalone iam:PassRole from privesc detection and add missing patterns (#8530)
- Support session/profile/role/static credentials in Security Hub integration (#8539)
eks_cluster_deletion_protection_enabledcheck for AWS provider (#8536)- ECS privilege escalation patterns (StartTask and RunTask) for AWS provider (#8541)
- Resource Explorer enumeration v2 API actions in
cloudtrail_threat_detection_enumerationcheck (#8557) apim_threat_detection_llm_jackingcheck for Azure provider (#8571)- GCP
--skip-api-checkcommand line flag (#8575)
Changed
- Refine kisa isms-p compliance mapping (#8479)
- Improve AWS Security Hub region check using multiple threads (#8365)
Fixed
- Resource metadata error in
s3_bucket_shadow_resource_vulnerabilitycheck (#8572) - GitHub App authentication through API fails with auth_method validation error (#8587)
- AWS resource-arn filtering (#8533)
- GitHub App authentication for GitHub provider (#8529)
- List all accessible organizations in GitHub provider (#8535)
- Only evaluate enabled accounts in
entra_users_mfa_capablecheck (#8544) - GitHub Personal Access Token authentication fails without
user:emailscope (#8580)
[5.10.2] (Prowler v5.10.2)
Fixed
- Order requirements by ID in Prowler ThreatScore AWS compliance framework (#8495)
- Add explicit resource name to GCP and Azure Defender checks (#8352)
- Validation errors in Azure and M365 providers (#8353)
- Azure
app_http_logs_enabledcheck false positives (#8507) - Azure
storage_geo_redundant_enabledcheck false positives (#8504) - AWS
kafka_cluster_is_publiccheck false positives (#8514) - List all accessible repositories in GitHub (#8522)
- GitHub CIS 1.0 Compliance Reports (#8519)
[5.10.1] (Prowler v5.10.1)
Fixed
- Remove invalid requirements from CIS 1.0 for GitHub provider (#8472)
[5.10.0] (Prowler v5.10.0)
Added
bedrock_api_key_no_administrative_privilegescheck for AWS provider (#8321)bedrock_api_key_no_long_term_credentialscheck for AWS provider (#8396)- Support App Key Content in GitHub provider (#8271)
- CIS 4.0 for the Azure provider (#7782)
vm_desired_sku_sizecheck for Azure provider (#8191)vm_scaleset_not_emptycheck for Azure provider (#8192)- GitHub repository and organization scoping support with
--repository/respositoriesand--organization/organizationsflags (#8329) - GCP provider retry configuration (#8412)
s3_bucket_shadow_resource_vulnerabilitycheck for AWS provider (#8398)- Use
trivyas engine for IaC provider (#8466)
Changed
- Handle some AWS errors as warnings instead of errors (#8347)
- Revert import of
checkovpython library (#8385) - Updated policy mapping in ISMS-P compliance file for improved alignment (#8367)
Fixed
- False positives in SQS encryption check for ephemeral queues (#8330)
- Add protocol validation check in security group checks to ensure proper protocol matching (#8374)
- Add missing audit evidence for controls 1.1.4 and 2.5.5 for ISMS-P compliance. (#8386)
- Use the correct @staticmethod decorator for
set_identityandset_session_configmethods in AwsProvider (#8056) - Use the correct default value for
role_session_nameandsession_durationin AwsSetUpSession (#8056) - Use the correct default value for
role_session_nameandsession_durationin S3 (#8417) - GitHub App authentication fails to generate output files and HTML header sections (#8423)
- S3
test_connectionuses AWS S3 APIHeadBucketinstead ofGetBucketLocation(#8456) - Add more validations to Azure Storage models when some values are None to avoid serialization issues (#8325)
sns_topics_not_publicly_accessiblefalse positive withaws:SourceArnconditions (#8326)- Remove typo from description req 1.2.3 - Prowler ThreatScore M365 (#8384)
- Way of counting FAILED/PASS reqs from
kisa_isms_p_2023_awstable (#8382) - Use default tenant domain instead of first domain in list for Azure and M365 providers (#8402)
- Avoid multiple module error calls in M365 provider (#8353)
- Avoid sending errors to Sentry in M365 provider when user authentication fails (#8420)
- Tweaks from Prowler ThreatScore in order to handle the correct reqs (#8401)
- Make
setup_assumed_sessionstatic for the AWS provider (#8419)
[5.9.2] (Prowler v5.9.2)
Fixed
- Use the correct resource name in
defender_domain_dkim_enabledcheck (#8334)
[5.9.0] (Prowler v5.9.0)
Added
storage_smb_channel_encryption_with_secure_algorithmcheck for Azure provider (#8123)storage_smb_protocol_version_is_latestcheck for Azure provider (#8128)vm_backup_enabledcheck for Azure provider (#8182)vm_linux_enforce_ssh_authenticationcheck for Azure provider (#8149)vm_ensure_using_approved_imagescheck for Azure provider (#8168)vm_scaleset_associated_load_balancercheck for Azure provider (#8181)defender_attack_path_notifications_properly_configuredcheck for Azure provider (#8245)entra_intune_enrollment_sign_in_frequency_every_timecheck for M365 provider (#8223)- Support for remote repository scanning in IaC provider (#8193)
- Add
test_connectionmethod to GitHub provider (#8248)
Changed
- Refactor the Azure Defender get security contact configuration method to use the API REST endpoint instead of the SDK (#8241)
Fixed
- Title & description wording for
iam_user_accesskey_unusedcheck for AWS provider (#8233) - Add GitHub provider to lateral panel in documentation and change -h environment variable output (#8246)
- Show
M365_identity_typeandM365_identity_idin cloud reports (#8247) - Ensure
is_service_roleonly returnsTruefor service roles (#8274) - Update DynamoDB check metadata to fix broken link (#8273)
- Show correct count of findings in Dashboard Security Posture page (#8270)
- Add Check's metadata service name validator (#8289)
- Use subscription ID in Azure mutelist (#8290)
ServiceNamefield in Network Firewall checks metadata (#8280)- Update
entra_users_mfa_capablecheck to use the correct resource name and ID (#8288) - Handle multiple services and severities while listing checks (#8302)
- Handle
tenant_idfor M365 Mutelist (#8306) - Fix error in Dashboard Overview page when reading CSV files (#8257)
[5.8.1] (Prowler v5.8.1)
Fixed
- Detect wildcarded ARNs in sts:AssumeRole policy resources (#8164)
- List all streams and
firehose_stream_encrypted_at_restlogic (#8213) - Allow empty values for http_endpoint in templates (#8184)
- Convert all Azure Storage models to Pydantic models to avoid serialization issues (#8222)
[5.8.0] (Prowler v5.8.0)
Added
storage_geo_redundant_enabledcheck for Azure provider (#7980)storage_cross_tenant_replication_disabledcheck for Azure provider (#7977)- CIS 1.11 compliance framework for Kubernetes (#7790)
- Support
HTTPS_PROXYandK8S_SKIP_TLS_VERIFYin Kubernetes (#7720) - Weight for Prowler ThreatScore scoring (#7795)
entra_users_mfa_capablecheck for M365 provider (#7734)admincenter_organization_customer_lockbox_enabledcheck for M365 provider (#7732)admincenter_external_calendar_sharing_disabledcheck for M365 provider (#7733)- Level for Prowler ThreatScore in the accordion in Dashboard (#7739)
- CIS 4.0 compliance framework for GCP (7785)
repository_has_codeowners_filecheck for GitHub provider (#7752)repository_default_branch_requires_signed_commitscheck for GitHub provider (#7777)repository_inactive_not_archivedcheck for GitHub provider (#7786)repository_dependency_scanning_enabledcheck for GitHub provider (#7771)repository_secret_scanning_enabledcheck for GitHub provider (#7759)repository_default_branch_requires_codeowners_reviewcheck for GitHub provider (#7753)- NIS 2 compliance framework for AWS (#7839)
- NIS 2 compliance framework for Azure (#7857)
- Search bar in Dashboard Overview page (#7804)
- NIS 2 compliance framework for GCP (#7912)
storage_account_key_access_disabledcheck for Azure provider (#7974)storage_ensure_file_shares_soft_delete_is_enabledcheck for Azure provider (#7966)- Make
validate_mutelistmethod static insideMutelistclass (#7811) - Avoid bypassing IAM check using wildcards (#7708)
storage_blob_versioning_is_enablednew check for Azure provider (#7927)- New method to authenticate in AppInsights in check
app_function_application_insights_enabled(#7763) - ISO 27001 2022 for M365 provider (#7985)
codebuild_project_uses_allowed_github_organizationscheck for AWS provider (#7595)- IaC provider (#7852)
- Azure Databricks service integration for Azure provider, including the
databricks_workspace_vnet_injection_enabledcheck (#8008) databricks_workspace_cmk_encryption_enabledcheck for Azure provider (#8017)- Appication auth for PowerShell in M365 provider (#7992)
storage_account_default_to_entra_authorization_enabledcheck for Azure provider (#7981)- Improve overview page from Prowler Dashboard (#8118)
keyvault_ensure_public_network_access_disabledcheck for Azure provider (#8072)monitor_alert_service_health_existscheck for Azure provider (#8067)- Replace
Domain.Read.AllwithDirectory.Read.Allin Azure and M365 docs (#8075) - Refactor IaC provider to use Checkov as Python library (#8093)
- New check
codebuild_project_not_publicly_accessiblefor AWS provider (#8127)
Fixed
- Consolidate Azure Storage file service properties to the account level, improving the accuracy of the
storage_ensure_file_shares_soft_delete_is_enabledcheck (#8087) - Migrate Azure VM service and managed disk logic to Pydantic models for better serialization and type safety, and update all related tests to use the new models and fix UUID handling (#https://github.com/prowler-cloud/prowler/pull/8151)
organizations_scp_check_deny_regionscheck to pass when SCP policies have no statements (#8091)- Fix logic in VPC and ELBv2 checks (#8077)
- Retrieve correctly ECS Container insights settings (#8097)
- Fix correct handling for different accounts-dates in prowler dashboard compliance page (#8108)
- Handling of
block-project-ssh-keysin GCP checkcompute_instance_block_project_wide_ssh_keys_disabled(#8115) - Handle empty name in Azure Defender and GCP checks (#8120)
Changed
- Reworked
S3.test_connectionto match the AwsProvider logic (#8088)
Removed
- OCSF version number references to point always to the latest (#8064)
[5.7.5] (Prowler v5.7.5)
Fixed
- Use unified timestamp for all requirements (#8059)
- Add EKS to service without subservices (#7959)
apiserver_strong_ciphers_onlycheck for K8S provider (#7952)- Handle
0at the start and end of account uids in Prowler Dashboard (#7955) - Typo in PCI 4.0 for K8S provider (#7971)
- AWS root credentials checks always verify if root credentials are enabled (#7967)
- Github provider to
usagesection ofprowler -h: (#7906) network_flow_log_more_than_90_dayscheck to pass when retention policy is 0 days (#7975)- Update SDK Azure call for ftps_state in the App Service (#7923)
- Validate ResourceType in CheckMetadata (#8035)
- Missing ResourceType values in check's metadata (#8028)
- Avoid user requests in setup_identity app context and user auth log enhancement (#8043)
[5.7.3] (Prowler v5.7.3)
Fixed
- Automatically encrypt password in Microsoft365 provider (#7784)
- Remove last encrypted password appearances (#7825)
[5.7.2] (Prowler v5.7.2)
Fixed
M365_powershell test_credentialsto use sanitized credentials (#7761)admincenter_users_admins_reduced_license_footprintcheck logic to pass when admin user has no license (#7779)M365_powershellto close the PowerShell sessions in msgraph services (#7816)defender_ensure_notify_alerts_severity_is_highcheck to accept high or lower severity (#7862)- Replace
Directory.Read.Allpermission withDomain.Read.Allwhich is more restrictive (#7888) - Split calls to list Azure Functions attributes (#7778)
[5.7.0] (Prowler v5.7.0)
Added
- Update the compliance list supported for each provider from docs (#7694)
- Allow setting cluster name in in-cluster mode in Kubernetes (#7695)
- Prowler ThreatScore for M365 provider (#7692)
- GitHub provider (#5787)
repository_default_branch_requires_multiple_approvalscheck for GitHub provider (#6160)repository_default_branch_protection_enabledcheck for GitHub provider (#6161)repository_default_branch_requires_linear_historycheck for GitHub provider (#6162)repository_default_branch_disallows_force_pushcheck for GitHub provider (#6197)repository_default_branch_deletion_disabledcheck for GitHub provider (#6200)repository_default_branch_status_checks_requiredcheck for GitHub provider (#6204)repository_default_branch_protection_applies_to_adminscheck for GitHub provider (#6205)repository_branch_delete_on_merge_enabledcheck for GitHub provider (#6209)repository_default_branch_requires_conversation_resolutioncheck for GitHub provider (#6208)organization_members_mfa_requiredcheck for GitHub provider (#6304)- GitHub provider documentation and CIS v1.0.0 compliance (#6116)
- CIS 5.0 compliance framework for AWS (7766)
Fixed
- Update CIS 4.0 for M365 provider (#7699)
- Update and upgrade CIS for all the providers (#7738)
- Cover policies with conditions with SNS endpoint in
sns_topics_not_publicly_accessible(#7750) - Change severity logic for
ec2_securitygroup_allow_ingress_from_internet_to_all_portscheck (#7764)
[5.6.0] (Prowler v5.6.0)
Added
- SOC2 compliance framework to Azure (#7489)
- Check for unused Service Accounts in GCP (#7419)
- Powershell to Microsoft365 (#7331)
- Service Defender to Microsoft365 with one check for Common Attachments filter enabled in Malware Policies (#7425)
- Check for Outbound Antispam Policy well configured in service Defender for M365 (#7480)
- Check for Antiphishing Policy well configured in service Defender in M365 (#7453)
- Check for Notifications for Internal users enabled in Malware Policies from service Defender in M365 (#7435)
- Support CLOUDSDK_AUTH_ACCESS_TOKEN in GCP (#7495)
- Service Exchange to Microsoft365 with one check for Organizations Mailbox Auditing enabled (#7408)
- Check for Bypass Disable in every Mailbox for service Defender in M365 (#7418)
- New check
teams_external_domains_restricted(#7557) - New check
teams_email_sending_to_channel_disabled(#7533) - New check for External Mails Tagged for service Exchange in M365 (#7580)
- New check for WhiteList not used in Transport Rules for service Defender in M365 (#7569)
- Check for Inbound Antispam Policy with no allowed domains from service Defender in M365 (#7500)
- New check
teams_meeting_anonymous_user_join_disabled(#7565) - New check
teams_unmanaged_communication_disabled(#7561) - New check
teams_external_users_cannot_start_conversations(#7562) - New check for AllowList not used in the Connection Filter Policy from service Defender in M365 (#7492)
- New check for SafeList not enabled in the Connection Filter Policy from service Defender in M365 (#7492)
- New check for DKIM enabled for service Defender in M365 (#7485)
- New check
teams_meeting_anonymous_user_start_disabled(#7567) - New check
teams_meeting_external_lobby_bypass_disabled(#7568) - New check
teams_meeting_dial_in_lobby_bypass_disabled(#7571) - New check
teams_meeting_external_control_disabled(#7604) - New check
teams_meeting_external_chat_disabled(#7605) - New check
teams_meeting_recording_disabled(#7607) - New check
teams_meeting_presenters_restricted(#7613) - New check
teams_security_reporting_enabled(#7614) - New check
defender_chat_report_policy_configured(#7614) - New check
teams_meeting_chat_anonymous_users_disabled(#7579) - Prowler Threat Score Compliance Framework (#7603)
- Documentation for M365 provider (#7622)
- Support for M365 provider in Prowler Dashboard (#7633)
- New check for Modern Authentication enabled for Exchange Online in M365 (#7636)
- New check
sharepoint_onedrive_sync_restricted_unmanaged_devices(#7589) - New check for Additional Storage restricted for Exchange in M365 (#7638)
- New check for Roles Assignment Policy with no AddIns for Exchange in M365 (#7644)
- New check for Auditing Mailbox on E3 users is enabled for Exchange in M365 (#7642)
- New check for SMTP Auth disabled for Exchange in M365 (#7640)
- New check for MailTips full enabled for Exchange in M365 (#7637)
- New check for Comprehensive Attachments Filter Applied for Defender in M365 (#7661)
- Modified check
exchange_mailbox_properties_auditing_enabledto make it configurable (#7662) - snapshots to M365 documentation (#7673)
- support for static credentials for sending findings to Amazon S3 and AWS Security Hub (#7322)
- Prowler ThreatScore for M365 provider (#7692)
- Microsoft User and User Credential auth to reports (#7681)
Fixed
- Package name location in pyproject.toml while replicating for prowler-cloud (#7531)
- Remove cache in PyPI release action (#7532)
- The correct values for logger.info inside iam service (#7526)
- Update S3 bucket naming validation to accept dots (#7545)
- Handle new FlowLog model properties in Azure (#7546)
- Improve compliance and dashboard (#7596)
- Remove invalid parameter
create_file_descriptor(#7600) - Remove first empty line in HTML output (#7606)
- Remove empty files in Prowler (#7627)
- Ensure that ContentType in upload_file matches the uploaded file's format (#7635)
- Incorrect check inside 4.4.1 requirement for Azure CIS 2.0 (#7656)
- Remove muted findings on compliance page from Prowler Dashboard (#7683)
- Remove duplicated findings on compliance page from Prowler Dashboard (#7686)
- Incorrect values for Prowler Threatscore compliance LevelOfRisk inside requirements (#7667)
[5.5.1] (Prowler v5.5.1)
Fixed
- Default name to contacts in Azure Defender (#7483)
- Handle projects without ID in GCP (#7496)
- Restore packages location in PyProject (#7510)