fix(deps): update toniblyx/prowler docker tag to v5.38.0 - #76
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update toniblyx/prowler docker tag to v5.38.0#76renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
from
January 30, 2025 05:10
8238903 to
37bfb6d
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
from
January 30, 2025 18:36
37bfb6d to
ce2f27e
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
7 times, most recently
from
February 8, 2025 01:25
d2a4abc to
f06c9ed
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
3 times, most recently
from
February 10, 2025 14:10
0558c00 to
ff99ee4
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
6 times, most recently
from
February 18, 2025 01:44
fa775f0 to
1967a23
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
8 times, most recently
from
February 25, 2025 12:55
da539fb to
2b69680
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
4 times, most recently
from
March 15, 2025 21:18
91269de to
48c03c7
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
3 times, most recently
from
March 20, 2025 15:43
59c0042 to
432cab4
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
3 times, most recently
from
March 24, 2025 05:51
9dc50c7 to
da11635
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
11 times, most recently
from
March 30, 2025 22:53
8ac9a46 to
3b37972
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
4 times, most recently
from
April 2, 2025 23:00
cd60360 to
d72cb90
Compare
renovate
Bot
force-pushed
the
renovate/toniblyx-prowler-5.x
branch
from
April 3, 2025 15:19
d72cb90 to
aa3f405
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.2.0→5.38.0Release Notes
prowler-cloud/prowler (toniblyx/prowler)
v5.38.0: Prowler 5.38.0Compare Source
✨ New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com/
📌 Compliance Watchlist
Compliance Watchlist keeps the frameworks an organization tracks in one shared list. Pin frameworks from any compliance view, manage several at once through a searchable catalog, and filter the Compliance section to show only the pinned frameworks.
The Overview page now reports the latest score for every pinned framework, while finding details highlight the watched frameworks associated with each check. Universal frameworks remain a single watchlist entry across provider views, keeping the organization's priorities consistent everywhere.
Read more in the Compliance Watchlist documentation.
🔐 SAML SSO - Multiple Email Domains
One SAML configuration can now authorize a primary email domain and up to 19 additional domains through the same Identity Provider. Every domain shares one stable Assertion Consumer Service (ACS) URL based on the primary domain, so subsidiaries, acquired companies, regional domains, and multiple brands no longer require separate tenants or duplicated SAML applications.
Domain ownership remains tenant-bound throughout the authentication flow. During service provider-initiated sign-in, the discovery domain and the domain asserted by the Identity Provider must resolve to the same tenant before provisioning continues.
Read more in the SAML SSO documentation.
👥 User Sign-In Methods
The Users table now shows each account's sign-in methods as tags, including email/password, Google, GitHub, SAML with linked domains, and Partner SSO. Accounts without a reported method display a placeholder.
🕸️ Attack Paths - Expanded AWS Privilege-Escalation Coverage
Attack Paths adds 20 AWS privilege-escalation queries from pathfinding.cloud, while
iam_policy_allows_privilege_escalationgains 22 additional escalation combinations.The new coverage includes service
iam:PassRolepaths across AWS Batch, Braket, Cognito Identity, ECS, EMR, EMR Serverless, GameLift, Glue, EC2 Image Builder, Kinesis Analytics, HealthOmics, EventBridge Scheduler, Systems Manager, and Step Functions. It also covers existing-resource abuse, permissions-boundary removal, role assumption, and IAM Identity Center permission-set policy injection.The query catalog now exposes each AWS query's outcome category, distinguishing code execution, privilege escalation, public exposure, and resource inventory.
Explore the full Attack Paths query catalog at Prowler Hub.
Read more in the Attack Paths documentation.
🔍 Checks
Microsoft 365
Twelve new checks expand the coverage of CIS Microsoft 365 Foundations Benchmark v7.0.0:
Explore all Microsoft 365 checks at Prowler Hub.
🔐 Security
aiohttpwas upgraded to 3.14.3 to address CVE-2026-69244.cryptographywas upgraded to 50.0.0 to address CVE-2026-69247 and CVE-2026-69249.UI
🚀 Added
🔄 Changed
Add Providerwizard documentation link targeting each provider's credentials section and selected authentication method (#12218)🐞 Fixed
/complianceno longer fails while compliance overview data is still being generated (#12358)Client SecretandRefresh Tokenlabels in the GCP organization authentication form (#12362)🔐 Security
apk upgradefrom the UI image and moved the base digest forward instead, so the image is reproducible from its pin rather than from whatever Alpine serves at build time (#12313)API
🚀 Added
🔄 Changed
🐞 Fixed
errnoin Sentry, soENOSPC,ENOENTandEACCESno longer share a single issue (#12142)@masternow that the dependency bumps have landed there, and regenerated the lock. The API image no longer builds against a temporary integration branch (#12309)🔐 Security
SDK
🚀 Added
admincenter_shared_bookings_disabledcheck for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 control 1.3.9 (#12147)defender_priority_account_protection_enabledanddefender_strict_preset_security_policy_enabledchecks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 controls 2.4.1 and 2.4.2 (#12148)exchange_owa_mailbox_policy_personal_accounts_disabledandexchange_organization_reject_direct_send_enabledchecks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 controls 6.3.2 and 6.5.5 (#12149)teams_external_access_trial_tenants_blockedcheck for M365 provider, verifying that Teams external access with trial-only tenants is blocked, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 control 8.2.4 (#12151)entra_device_registration_join_restricted,entra_device_registration_max_devices_per_user_limited,entra_device_registration_global_admins_not_local_admins,entra_device_registration_registering_user_not_local_admin,entra_device_registration_laps_enabledandentra_policy_default_user_cannot_read_bitlocker_keyschecks for M365 provider, covering CIS Microsoft 365 Foundations Benchmark v7.0.0 device registration controls (5.1.4.x) (#12152)🔄 Changed
.trivyignoreto.trivyignore.yaml, so each entry is scoped to the package it names instead of suppressing its CVE across the whole image (#12314)securityhub_delegated_admin_enabled_all_regions,guardduty_delegated_admin_enabled_all_regionsandconfig_delegated_admin_and_org_aggregator_all_regionschecks now report MANUAL instead of FAIL when the delegated administrator status cannot be read and no independent misconfiguration is detected, which happens on member accounts that are not registered as delegated administrators because the API is restricted to the organization management account and to delegated administrator accounts (#12319)🐞 Fixed
Get-ApplicationAccessPolicyon M365 tenants without application access policies (#12149)ListOrganizationAdminAccountslookup in one region no longer marks the Security Hub delegated administrator status as undetermined in every other region (#12319)securityhub_delegated_admin_enabled_all_regionsno longer reports FAIL withdelegated administrator status could not be determinedon accounts that do have a Security Hub delegated administrator;ListOrganizationAdminAccountsresponses are now parsed with theAccountIdandStatusfields the API actually returns (#12319)guardduty_delegated_admin_enabled_all_regionsno longer reportsno delegated administrator configuredwhen the lookup was denied or failed, which asserted absence where there was only lack of visibility (#12319)matching_rule(#12327)🔐 Security
MCP
🚀 Added
🔄 Changed
prowler_send_findings_to_jiranow reportssafe_to_retryon every outcome, true only when Prowler knows no Jira work item was created: a dispatch the API refused is retryable, one that failed on the server or got no answer is not (#12343)prowler_list_integrationsno longer requests theconfigurationit discards, now that the API tolerates a sparse fieldset without it (#12343)🔐 Security
v5.37.1: Prowler 5.37.1Compare Source
UI
🐞 Fixed
sharp's nativelibvipslibrary, so every image was served unoptimized (#12307)🔐 Security
sharpis pinned to 0.35.3, clearing the image's remaining CVEs (#12307)API
🐞 Fixed
guestOrExternalUserTypes(a flags enum Graph serializes as a comma-separated string) deserializes correctly instead of returning an empty list (#12315)🔐 Security
workosandpyopensslso the API can move tocryptography48.0.1 (#12311)gnupgandapt-transport-httpsfrom the API container image (#12311)git; removing it also droppedperl,perl-modules,libperlandliberror-perl, clearing 12 critical CVEs. Onlyperl-baseremains, which Debian marks Essential and cannot be removed (#12311)pipfrom the API container image, clearing two high-severity CVEs in the vendored copies ofsetuptoolsandmsgpack(#12311)pillowto 12.3.0,httplib2to 0.32.0 andpyasn1to 0.6.4 to resolve known CVEs (#12311)SDK
🔄 Changed
19000-19007to20000-20007, resolving a collision with E2E Networks which reserves19000-19999(#12306)🐞 Fixed
prowler.checks.<provider>entry-point group can now run against built-in providers. The built-in probe in_resolve_check_moduleused a barefind_spec, which imports the parent package to search it and so raisedModuleNotFoundErrorfor a plug-in check instead of returningNone, aborting the lookup before the entry points were consulted. Such a check was discovered, listed and selected for execution, then silently produced no findings. (#12312)guestOrExternalUserTypes(a flags enum Graph serializes as a comma-separated string) deserializes correctly instead of returning an empty list (#12315)🔐 Security
postgresandvalkeyimages, clearing 10 critical CVEs (#12307)joserfcin the container images, clearing 14 high-severity CVEs from the SDK and API images (#12307)httplib2to 0.32.0 andpyasn1to 0.6.4 to resolve known CVEs (#12307)libsqlite3-0andzlib1gcriticals (#12307)cryptographyto 48.0.1 to resolve GHSA-537c-gmf6-5ccf, along with theoci,alibabacloud-tea-openapi,darabonba-coreandpy-ocsf-modelsbumps it requires (#12307)pipfrom the SDK container image, clearing two high-severity CVEs in the vendored copies ofsetuptoolsandmsgpack(#12307)wget,gnupgandapt-transport-httpsfrom the SDK runtime image (#12307)MCP
🔐 Security
fastmcpand pinnedcryptography,joserfc,mcpandpython-multipart, clearing all 7 high-severity CVEs from the MCP image (#12307)v5.37.0: Prowler 5.37.0Compare Source
✨ New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com
💬 Lighthouse AI — Context-Aware Chat and a Bigger Toolbox
Lighthouse AI is now aware of your working context when in Prowler Cloud. Messages carry page-aware context — the page you are on, the finding or resource open in the side panel, and its metadata — so "explain this" just works, and each page offers concise contextual suggestions to start from.
Lighthouse also gained access to every tool family the Prowler MCP server advertises: scan configurations, scan scheduling, finding triage, alert rules and recipients, integrations, users, and roles. Every action remains gated by RBAC: Lighthouse AI can only do what the user asking could do themselves.
Read more in the Lighthouse AI documentation.
🔌 Prowler MCP — Integrations, Users, and Roles
Prowler MCP gained three tool families, available on both the Cloud and the self-hosted Local MCP Server:
Read more in the Prowler MCP tools reference.
☁️ Prowler MCP — Cloud-Only Tools
A new
prowler_cloud_*namespace adds 32 tools so your AI assistant can run Prowler Cloud workflows end to end instead of only reading from them:Read more in the Prowler Cloud MCP tools reference.
🧭 Compliance — Grouped by provider of the same type
One framework, every provider, a single answer. Building on the cross-provider-type roll-up, the Compliance section now groups compliance for all providers of the same type: a single-provider framework — CIS AWS, CIS GCP, ENS for Azure — is aggregated across the latest completed scan of every provider of that type. Each framework card rolls up into a consolidated posture with a per-provider breakdown, a findings drill-down, and a combined executive PDF report. Requirement status follows the same strict precedence (FAIL over PASS over MANUAL), so one failing provider flags the requirement for the whole estate.
The Compliance tabs were also renamed to say what they aggregate: "Per Scan" is now Single Scan, "Cross-Provider" is now Multiple Scans, and Compliance lands on Multiple Scans by default.
Read more in the Cross-Provider Compliance documentation.
☁️ GCP Organization Onboarding
Onboarding an entire Google Cloud organization is now a single guided flow. Provide an organization-level credential and Prowler discovers the full hierarchy, every folder and project. Pick the folders and projects to onboard from a selection tree, set custom aliases, test the connection, and launch: each selected project is registered as a provider, with no need to add them one by one. Post-onboarding management is covered too, including credential replacement and organization-wide deletion.
Read more in the GCP Organizations documentation.
🕸️ Attack Paths — More Privilege Escalation Queries
Attack Paths adds four AWS privilege-escalation detection queries from pathfinding.cloud. Thanks to @paramanandmallik!
The query info panel now links every query to its page on Prowler Hub, and the IAM privilege-escalation queries were reworked to run efficiently on accounts with many IAM roles, users, or groups, fixing runtime errors and timeouts on large graphs.
Read more in the Attack Paths documentation.
🛡️ AWS Confidential Computing — Nitro Enclaves Checks
Prowler adds the first CSPM coverage for confidential computing workloads on AWS, with 11 new checks for Nitro Enclaves, developed together with Guillermo Ruiz from AWS.
ec2_confidential_workload_host_*checks for the parent instance: IMDSv2 not enforced, public IP exposure, unrestricted ingress, exposed vsock proxy ports, and hosts not running.kms_key_enclave_*checks for the key policies gating enclave secrets: attestation not enforced or bypassable, missing deployment binding, debug-mode attestations, PCR mismatches, and unknown enclave images.All checks are fully passive, using AWS APIs and CloudTrail with no instance access or SSM agent required, and are mapped across 23 compliance frameworks, including NIST 800-53 Rev 5, PCI-DSS v4.0, ISO 27001:2022, SOC 2, HIPAA, and MITRE ATT&CK.
Read more about it this blog post.
Try them out now at cloud.prowler.com!
🏢 New Provider — Huawei Cloud
Prowler now scans Huawei Cloud, with 25 checks across ten services: CTS, ECS, ELB, EVS, IAM, KMS, OBS, RDS, VPC, and WAF, plus the CIS Huawei Cloud Foundations Benchmark 1.0 compliance framework. Thanks to @tomitobio for their 1st provider in Prowler!
To scan a Huawei Cloud account, export the IAM user's access key credentials and run Prowler CLI:
Read more in the Huawei Cloud documentation. Explore all Huawei Cloud checks at Prowler Hub.
🔍 Checks
AWS
codecommit_repository_no_secrets, alongside the newcodecommitservice, scans files tracked at the tip of each repository's default branch for hardcoded secrets. Thanks to @Sid-0602!glue_catalog_connection_no_secretsdetects secrets in Glue Data Catalog connection properties. Thanks to @l46983284-cpu, @Rishi943, and @UTKARSH698!ec2_instance_stopped_older_than_specific_daysdetects EC2 instances stopped longer than a configurable number of days (default 30). Thanks to @Nithin078!sagemaker_endpoint_config_kms_encryption_enabledverifies SageMaker endpoint configurations use a KMS key for storage volume encryption. Thanks to @Nithin078 and @l46983284-cpu!Read more in the AWS documentation.
Explore all AWS checks at Prowler Hub.
📤 OCSF Output — MITRE ATT&CK Enrichment
OCSF detection finding output now populates
finding_info.analyticwith the Prowler check rule andfinding_info.attackswith MITRE ATT&CK technique and tactic objects for findings with MITRE ATT&CK compliance metadata. Thanks to @AlexanderSanin!🐞 Fixed
userTypeattribute and without an existing role now receive a least-privilegeread_onlyfallback role, so role-dependent operations continue to work without granting management permissions.🔐 Security
401, and user deletion revokes the user's API keys across all their tenants.🙌 External Contributors
Thank you to our community contributors for this release!
codecommitservice andcodecommit_repository_no_secretscheck (#11846)glue_catalog_connection_no_secretscheck (#11963)ec2_instance_stopped_older_than_specific_days(#12076) andsagemaker_endpoint_config_kms_encryption_enabled(#12118, co-authored with @l46983284-cpu) checksUI
🚀 Added
promo_codeandutm_*params across auth redirects, sign-in/sign-up links, Google/GitHub OAuth callbacks, andPOST /users(#12269)🔄 Changed
/compliancenow lands on the Multiple Scans tab; links carrying ascanIdkeep opening Single Scan (#12086)🐞 Fixed
API
🚀 Added
🐞 Fixed
task_argsserialization no longer returns HTTP 500 errors when Celery truncates stored task keyword arguments (#12165)401instead of an unhandledAttributeError, and user deletion now revokes the user's API keys across all their tenants (#12210)userTypeattribute and without an existing role in the SAML tenant now receive a least-privilegeread_onlyfallback role; a numeric suffix is used when that name belongs to a role with different permissions (#12223)configurationno longer returns HTTP 500 errors when the tenant has a Jira integration (#12261)🔐 Security
SDK
🚀 Added
finding_info.analyticas the Prowler check rule andfinding_info.attacksas MITRE ATT&CK technique and tactic objects for findings with MITRE-ATTACK compliance metadata (#11492)codecommitservice andcodecommit_repository_no_secretscheck for AWS provider, scanning files tracked at the tip of each repository's default branch for hardcoded secrets (#11846)glue_catalog_connection_no_secretscheck to detect secrets in Glue Data Catalog connection properties (#11963)ec2_instance_stopped_older_than_specific_dayscheck for AWS provider, detecting EC2 instances stopped longer than a configurable number of days (default 30) (#12076)sagemaker_endpoint_config_kms_encryption_enabledcheck verifying SageMaker endpoint configurations use a KMS key for storage volume encryption (#12118)ec2_confidential_workload_host_*) and KMS attestation policy (kms_key_enclave_*), fully passive via boto3 and CloudTrail LookupEvents (#12283)🐞 Fixed
e2enetworks; the aggregated schema served by/scan-configurations/schemanow includes only app providers (sdk_only = False) (#12094)httplib2access when a project has several gen2 functions (#12107)🔐 Security
MCP
🚀 Added
prowler_list_users,prowler_get_user, andprowler_get_current_userfor listing tenant users with their emails and identifying the authenticated user (#12088)prowler_list_roles,prowler_get_role,prowler_get_user_roles, andprowler_set_user_rolefor browsing roles and setting the role a user holds (#12088)🔄 Changed
prowler_cloud_*tools available on the hosted Prowler MCP (alerts, findings triage, scan scheduling, scan configurations), and corrects the Prowler Hub check count and the scan orchestration capabilities (#12266)🐞 Fixed
DELETE /mcp; the server now runs stateless (#12235)prowler_list_integrationsfailing with a 500 error on tenants with a Jira integration, caused by the request leavingconfigurationout of the sparse fieldset (#12259)v5.36.0: Prowler 5.36.0Compare Source
✨ New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com
🎫 Finding Groups - Jira
Selected Findings, Finding Groups, and mixed selections can now be sent to Jira. When you select multiple findings, choose between one grouped issue or separate issues. Generated issues keep their Prowler context with deep links and filter details, while the UI provides clear dispatch and failure feedback.
Read more in our Jira integration documentation.
🕸️ Attack Paths - Queries
Prowler Cloud now records which built-in Attack Paths queries returned data at the end of each scan. The query selector hides confirmed-empty queries for the selected scan, so you can focus on paths that exist without opening blank graph views. Errored, unknown, and parameterized queries remain available when they still require investigation or input.
All Attack Paths queries are now published on Prowler Hub, where you can browse the full catalog.
Read more in our Attack Paths documentation.
🧑🏫 New Tutorials: Connect Your AI Agents to Prowler Cloud
New tutorials walk you through connecting your own AI agents to Prowler Cloud, so they can query your security posture and act on it programmatically.
Read more in our AI agents documentation.
☁️ Region-less Oracle Cloud Infrastructure Setup
Oracle Cloud Infrastructure (OCI) provider credentials no longer require a region. Existing clients can still send the legacy
regionfield for compatibility, but the API ignores it before storing credentials or starting a scan. This removes an unnecessary step from OCI onboarding.Read more in our OCI documentation.
🔍 Checks
AWS
sagemaker_notebook_instance_no_secretsscans theOnCreateandOnStartlifecycle scripts of SageMaker notebook instances for hardcoded API keys, passwords, tokens, connection strings, and other secrets. Thanks to @kiranrajsg!Read more in our AWS documentation.
Explore all AWS checks at Prowler Hub.
🔐 Security
npmCLI was removed from the UI container image, eliminating the bundlednode-tarCVE-2026-59873 and reducing exposure to future bundled npm vulnerabilities.@vitest/browserfile-access permission bypass. These are development dependencies and have no runtime impact.legacy auth-provider.config.cmd-pathcommand authentication, closing a command-execution bypass. GHSA-ccqh-6cjc-wp4jnext-authwas updated from 5.0.0-beta.30 to 5.0.0-beta.32, patching two critical Auth.js advisories: existence-based authorization checks that could fail open when a provider is misconfigured, and a homoglyph@bypass in email address normalization. The bump also pulls in the patched@auth/core0.41.3 transitively.🙌 External Contributors
Thank you to our community contributors for this release!
sagemaker_notebook_instance_no_secretscheck (#11843)Policy="Accept"values correctly (#12049)SyntaxWarningat startup (#12041)UI
🚀 Added
🐞 Fixed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.