-
Notifications
You must be signed in to change notification settings - Fork 0
fix(deps): update toniblyx/prowler docker tag to v5.16.1 #76
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
dev
Choose a base branch
from
renovate/toniblyx-prowler-5.x
base: dev
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Contributor
Author
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
8238903 to
37bfb6d
Compare
37bfb6d to
ce2f27e
Compare
d2a4abc to
f06c9ed
Compare
0558c00 to
ff99ee4
Compare
fa775f0 to
1967a23
Compare
da539fb to
2b69680
Compare
6945948 to
46cee20
Compare
46cee20 to
44930dc
Compare
44930dc to
c884fec
Compare
9fc8432 to
a2bcf4b
Compare
a2bcf4b to
2a29a7d
Compare
2a29a7d to
eb76ca7
Compare
eb76ca7 to
afdedce
Compare
afdedce to
219b799
Compare
219b799 to
13f1800
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.2.0->5.16.1Release Notes
prowler-cloud/prowler (toniblyx/prowler)
v5.16.1: Prowler 5.16.1Compare Source
UI
🔄 Changed
API
🔄 Changed
🐞 Fixed
SDK
🐞 Fixed
v5.16.0: Prowler 5.16.0Compare Source
✨ New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com
🤖 Lighthouse AI + MCP Server
This release introduces major improvements to Lighthouse AI, now powered by Prowler’s official MCP Server, significantly enhancing performance, reliability, and the quality of AI-driven interactions across the platform:
Together, these improvements make Lighthouse AI more robust, scalable, and capable of delivering actionable security and compliance insights through natural language.
🔇 Simple Mutelist
Findings can be muted after scanning from the finding table. A new page is available in /mutelist where the user can handle simple and advanced Mutelist configuration.
🗂️ Category Overview & Filtering
We've introduced a powerful new way to analyze your security posture by category. A new endpoint provides an overview of categories based on finding severities, giving you instant visibility into how different security domains are performing across your environment. Additionally, both
GET /findingsandGET /findings/latestendpoints now support category filtering, making it easier to drill down into specific security domains.📄 Enhanced PDF Reporting
PDF reports now include richer context with Account ID, Alias, and Provider Name directly in the reporting table. This makes exported reports more actionable and easier to share across teams, providing all the context needed without cross-referencing other sources.
⚡ Performance & Reliability Improvements
The
GET /overviews/attack-surfacesendpoint has been streamlined by removing related check IDs from the response, improving performance and reducing payload size. Additionally, scheduled scan tasks now have a more reliable initialization with optimized execution timing.🛡️ New AWS Security Categories
Two new AWS check categories have been added:
privilege-escalationandec2-imdsv1.These categories improve visibility into high-risk misconfigurations, helping teams more easily identify paths to privilege escalation and legacy EC2 Instance Metadata Service v1 usage.
🔄 Updated AWS Service Metadata
Multiple AWS services have been migrated to the new service metadata format, including Glue, Kafka, KMS, MemoryDB, Inspector v2, Service Catalog, SNS, Trusted Advisor, and WAF (v1 and v2).
These updates improve consistency, accuracy, and long-term maintainability across AWS checks.
🧹 Data & Category Consistency Fixes
Several fixes improve correctness and normalization across providers:
trust-boundariescategory naming.UI
🚀 Added
🔄 Changed
🐞 Fixed
API
🚀 Added
GET /findingsandGET /findings/latestscan now use the category filter (#9529)🔄 Changed
GET /overviews/attack-surfacesno longer returns the related check IDs (#9529)🐞 Fixed
scan_ida required filter in the compliance overview endpoint (#9560)SDK
🚀 Added
privilege-escalationandec2-imdsv1categories for AWS checks (#9537)🔄 Changed
🐞 Fixed
trustboundariescategory totrust-boundaries(#9536)bedrock-agentregional availability, now using official AWS docs instead of copying frombedrockMCP
🚀 Added
🔄 Changed
v5.15.1: Prowler 5.15.1Compare Source
UI
🔐 Security
API
🐞 Fixed
SDK
🐞 Fixed
apigateway_restapi_logging_enabledcheck by refining stage logging evaluation to ensure logging level is not set to "OFF" (#9304) - Thanks to @bota4gov5.15.0: Prowler 5.15.0Compare Source
✨ New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com
🎯 New Overview Experience
We've expanded and refined the Overview to give you a clearer, more actionable understanding of your cloud security posture at a glance. The new panels bring richer visual context, better prioritization cues, and faster navigation across your environments.
🚨 Attack Surface
Instantly understand your most exposed risks, including internet-facing resources, leaked secrets, privilege-escalation paths, and critical misconfigurations.
📡 Service Watchlist
A real-time view of your riskiest cloud services, helping you focus remediation on the areas with the highest impact.
📈 Findings Severity Over Time
Track how your security posture evolves. This panel visualizes severity trends (Critical, High, Medium, Low, Informational) across days, weeks, or months so you can measure progress and detect regressions.
🧬 Risk Pipeline
A complete flow of findings from their source providers (AWS, Azure, Google Cloud, Kubernetes, GitHub, Microsoft 365, OCI, IaC, MongoDB Atlas) into their severity levels. Ideal for understanding where risk originates and how it distributes across your environments.
🌍 Threat Map
A global, region-based view of findings to help you quickly pinpoint where misconfigurations occur geographically, with pass/fail ratios per region.
🧮 Risk Plot
A severity-weighted visualization of your Threat Score, enabling you to immediately identify high-risk environments and understand how critical findings influence overall exposure, not just by volume but by impact.
⏳ Navigation Loading Bar
To improve the overall user experience, we've introduced a new navigation loading bar. This subtle progress indicator replaces silent page transitions, giving users immediate feedback that something is happening in the background. It makes the interface feel faster, smoother, and more responsive, especially when loading large datasets.
🤖 MCP Server - Prowler Management
The Prowler MCP Server has been completely redesigned to give AI assistants and LLMs control over your Prowler environment. The new version introduces comprehensive tools for:
This enables powerful AI-driven security workflows. Ask your AI assistant to scan your accounts, identify critical findings, or generate compliance reports, all through natural language.
🌐 New Cloud Providers
🍃 MongoDB Atlas
MongoDB Atlas is now fully supported in the Prowler App, enabling you to assess and monitor the security posture of your managed database clusters directly from the UI.
☁️ Alibaba Cloud (CLI Only)
Alibaba Cloud is now available in the Prowler CLI. Full Prowler App support is coming in the next release!
See the 63 available checks in Prowler Hub
🤖 Lighthouse AI - Amazon Bedrock API Key Support
Lighthouse AI now supports Amazon Bedrock API key authentication as an alternative to IAM access keys. This simplifies onboarding by allowing users to authenticate with a single API key instead of managing IAM credentials. Both authentication methods (IAM Access Key Pair and Bedrock API Key) are fully supported.
Read more about it here.
📚 Compliance Improvements
🔒 CIS 2.0 for Alibaba Cloud
New CIS Alibaba Cloud Foundation Benchmark v2.0.0 compliance framework, providing comprehensive security configuration guidelines for Alibaba Cloud environments.
✅ SOC 2 Processing Integrity
Added Processing Integrity requirements to the SOC 2 compliance framework for AWS, Azure, and GCP providers, expanding coverage for data processing controls.
🏦 RBI Cyber Security Framework - Thanks to @KonstGolfi
New RBI Cyber Security Framework compliance support for Azure provider, helping organizations in the Indian financial sector meet regulatory requirements.
📦
pnpmMigrationThe UI has migrated from
npmtopnpmfor package management, bringing faster installs, stricter dependency resolution, and more consistent builds across environments.🔍 All Providers in Prowler Hub
Explore all Prowler security checks, compliance frameworks, and supported providers in one place at Prowler Hub. Browse checks by provider, search for specific security controls, and discover which compliance frameworks map to each check, all in a beautifully designed, searchable interface.
🧩 New Checks
GitHub - Repository
repository_immutable_releases_enabled- Thanks to @Sakeeb91GCP - Compute & CloudStorage
compute_instance_preemptible_vm_disabledcompute_instance_automatic_restart_enabledcompute_instance_deletion_protection_enabledcloudstorage_uses_vpc_service_controlsUI
🚀 Added
onRouterTransitionStart(#9465)🔄 Changed
🐞 Fixed
API
🚀 Added
GET /api/v1/overviews/findings_severity/timeseriesto retrieve daily aggregated findings by severity level (#9363)🔄 Changed
SDK
🚀 Added
cloudstorage_uses_vpc_service_controlscheck for GCP provider (#9256)repository_immutable_releases_enabledcheck for GitHub provider (#9162)compute_instance_preemptible_vm_disabledcheck for GCP provider (#9342)compute_instance_automatic_restart_enabledcheck for GCP provider (#9271)compute_instance_deletion_protection_enabledcheck for GCP provider (#9358)🔄 Changed
🐞 Fixed
cloudstorage_uses_vpc_service_controlscheck to handle VPC Service Controls blocked API access (#9478)MCP
🚀 Added
v5.14.2: Prowler 5.14.2Compare Source
UI
🐞 Fixed
🔒 Security
API
🐞 Fixed
SDK
🐞 Fixed
v5.14.1: Prowler 5.14.1Compare Source
API
🐞 Fixed
SDK
🐞 Fixed
sharepoint_external_sharing_managedcheck to handle external sharing disabled at organization level (#9298)exchange_mailbox_policy_additional_storage_restrictedcheck (#9241)v5.14.0: Prowler 5.14.0Compare Source
New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com
🤖 Lighthouse AI: Multi-LLM Support
Lighthouse AI now supports multiple AI providers, giving customers full flexibility over cost, performance, and data control. Supported model providers:
🌐 New Cloud Providers
☁️ Oracle Cloud Infrastructure (OCI)
Prowler App now supports OCI as a cloud provider with 51 checks and support for CIS OCI Foundations Benchmark v3.0.0. This allows you to analyze the security posture of your OCI tenants. See all check details in Prowler Hub.
For more details check our Getting Started with Oracle Cloud Infrastructure (OCI) guide.
🧱 Infrastructure-as-Code — Powered by Trivy
A brand-new IaC provider enables scanning for:
Powered by trivy, this provides policy-as-code scanning to detect misconfigurations before they are deployed.
For more details check our Getting Started with the IaC Provider guide.
🍃 MongoDB Atlas (API Only)
MongoDB Atlas is now available in the API and will have full support in the next release!
See the 10 available checks in Prowler Hub.
🎨 Prowler App - New UI
Prowler App has been refreshed with a more modern UI. The new layout improves navigation, readability, and performance across all the whole application.
📊 New Overview Experience
We’ve redesigned the Overview dashboard to show clearer security posture insights:
📰 RSS Feed for Updates
You can now subscribe to real-time release announcements and incident notifications via the new RSS feed integrated in the Latest Updates panel.
Performance Optimization
We've improved performance across all scan related tasks:
/metadataendpoint📚 Compliance Improvements
New Compliance Frameworks
Reporting Improvements
We've added PDF reporting for ENS, NIS2 and Prowler ThreatScore. Available in the Compliance page!
🐳 ARM images available in Docker Hub
Multi-architecture images (
linux/amd64andlinux/arm64) are now available for Prowler container images.Huge thanks to @sanchezpaco for this contribution!
🧩 New Checks
AWS - Code Pipeline
codepipeline_project_repo_private- Thanks to @yyyy7246GCP - Cloud Storage
cloudstorage_bucket_versioning_enabledcloudstorage_bucket_soft_delete_enabledcloudstorage_bucket_logging_enabledcloudstorage_audit_logs_enabledcloudstorage_bucket_sufficient_retention_periodAzure - Database for PostgreSQL flexible server
postgresql_flexible_server_entra_id_authentication_enabled- Thanks to @johannes-engler-mw📦 Resources – New Auditor Mode (API Only)
We’ve expanded the
/resourcesendpoint adding ametadatafield, containing the raw, unmodified response returned by the Cloud Provider API. This gives full transparency into what Prowler received from the Cloud Provider before any processing or normalization.🔥 ThreatScore for Kubernetes
ThreatScore is now available for the Kubernetes provider, offering instant visibility into the security posture of your clusters.
🛠️ Check Metadata
We're continuing standardizing the metadata format for dozens of AWS, GCP, GitHub, Kubernetes, OracleCloud, and MongoDB Atlas services improving consistency and maintainability.
UI
🚀 Added
🔄 Changed
API
🚀 Added
GET /api/v1/providerswith provider-type filters and optional pagination disable to support the new Overview filters (#8975)metadata,details, andpartitionattributes to/resourcesendpoint &details, andpartitionto/findingsendpoint (#9098)GET /api/v1/overview/regionsto retrieve aggregated findings data by region (#9273)🔄 Changed
GET /api/v1/overviews/servicesendpoint; returns latest scan data by default (#9248)🐛 Fixed
Providermodel to exclude soft-deleted entries, resolving duplicate errors when re-deleting providers (#9054)Security
SDK
🚀 Added
organization_default_repository_permission_strict(#8785)codepipeline_project_repo_privatecheck for AWS provider (#5915)cloudstorage_bucket_versioning_enabledcheck for GCP provider (#9014)cloudstorage_bucket_soft_delete_enabledcheck for GCP provider (#9028)cloudstorage_bucket_logging_enabledcheck for GCP provider (#9091)cloudstorage_audit_logs_enabledcheck for GCP provider (#9220)cloudstorage_bucket_sufficient_retention_periodcheck for GCP provider (#9149)organization_repository_creation_limitedcheck for GitHub provider (#8844)load_checks_to_executefunction (#8971)postgresql_flexible_server_entra_id_authentication_enabledcheck for Azure provider (#8764)🔄 Changed
🐛 Fixed
check_namehas noresource_nameerror for GCP provider (#9169)iam_role_cross_service_confused_deputy_preventioncheck (#9213)--sp-env-authconnection error and enhanced timeout logging (#9191)get_oci_assessment_summarytoget_oraclecloud_assessment_summaryin HTML output (#9200)MCP Server
🐛 Fixed
v5.13.1: Prowler 5.13.1Compare Source
API
🐞 Fixed
/api/v1/overviews/providerscollapses data by provider type so the UI receives a single aggregated record per cloud family even when multiple accounts exist (#9053)SDK
🐞 Fixed
resource_namefor checks underloggingfor the GCP provider (#9023)ec2_instance_with_outdated_amicheck to handle None AMIs (#9046)resource_idfor admincenter service and avoid unnecessary msgraph requests (#9019)v5.13.0: Prowler 5.13.0Compare Source
New features to highlight in this version
🤖 Prowler MCP Server: AI-Powered Security Operations
We've launched the Prowler MCP Server, a comprehensive Model Context Protocol (MCP) server that brings the entire Prowler ecosystem to AI assistants like Claude Desktop, Cursor, and other MCP-compatible tools.
You can test it right now in https://mcp.prowler.com/mcp
🎯 Key Capabilities
🔑 API Key Authentication
We've added native API key support for programmatic access to the Prowler API, making it easier to integrate with automation workflows and external tools.
Read more about it here https://docs.prowler.com/user-guide/providers/prowler-app-api-keys
📄 PDF Reports for Prowler ThreatScore
Compliance reporting just got more shareable — you can now export Prowler ThreatScore reports as professional PDF documents.
📰 New docs site!
Take a look at our new documentation at https://docs.prowler.com
We'd love to hear any feedback or suggestions for improvement you might have!
🔐 SAML Role Mapping Protection: Prevent Admin Lockout
We've added a safeguard for single-admin tenants using SAML role mapping to prevent accidental loss of administrative access.
🎯 Findings API: Filter by Provider ID
The Findings and Findings Severity Overview endpoints now support filtering by multiple provider IDs using the
provider_idandprovider_id__inparameters.⚡ Database Read Replica Support
We've added read replica support to improve query performance and horizontal scalability.
⭕ Oracle Cloud Infrastructure (OCI) Provider - CLI Only
We've added comprehensive support for Oracle Cloud Infrastructure with the CIS 3.0 benchmark, expanding our multi-cloud security coverage.
🤖 LLM Provider with Promptfoo - CLI Only
We've introduced AI security testing capabilities using promptfoo for comprehensive LLM red team evaluations.
🔧 New Checks
ec2_instance_with_outdated_amifor AWScloudstorage_bucket_lifecycle_management_enabledfor GCP📘 Multi-Cloud Compliance Frameworks
✅ New Metadata Format
We've standardized the metadata format across 15+ AWS services, making each field more comprehensive. Regarding remediation, we've included the NativeIaC and Terraform code within, therefore there's no need to check external sources.
📄 M365 Certificate Authentication
We have deprecated support for user and password authentication after Microsoft introduced mandatory interactive MFA for this type of sign-in. To ensure secure and seamless integration with Microsoft 365, and to provide an alternative to client secrets, we've added support for certificate-based authentication in Microsoft Entra.
This new method allows our integration to authenticate using trusted certificates instead of credentials, reducing the risk of credential exposure and improving reliability. Certificates offer a stronger and more stable authentication mechanism, ensuring secure access to Microsoft 365 resources while complying with modern identity and access management standards.
🔒 Security
MANAGE_ACCOUNTpermission is required to modify or read user permissions instead ofMANAGE_USERS.🚀 Frontend Stack Modernization
This release brings a full modernization of the frontend architecture — upgrading to the latest React, Next.js, and key UI libraries to enhance performance, compatibility, and developer experience.
🔧 Highlights
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.