Skip to content

Releases: prowler-cloud/prowler

Prowler 3.16.7 - Back in the Village

03 Jun 19:38
3.16.7
9af6ffd
Compare
Choose a tag to compare

What's Changed

Chores

  • chore(backport): include latest changes of v4 by @sergargar in #4159
    • fix(defender): Add new parameter required by new API version (#4147)
    • chore(iam): Downgrade AWS IAM check severity (#4149)
    • fix(rds): use correct API call for cluster parameters (#4150)
    • fix(dependencies): ignore jinja vulnerability (#4154)
    • fix(cloudtrail): trail.region must be home region (#4153)
    • fix(trustedadvisor): handle AccessDenied exception (#4158)

Full Changelog: 3.16.6...3.16.7

Prowler 3.16.6 - Back in the Village

30 May 16:46
3.16.6
fbe6a30
Compare
Choose a tag to compare

What's Changed

Fixes

Chores

  • chore(backport): put latest changes of v4 to v3 by @sergargar in #4144
    • chore(aws): Add failed_checks to track (#4018)
    • feat(rds): Add AWS RDS clusters to transport encryption check (#4028)
    • fix(gcp): handle projects API Call error (#4055)
    • fix(doc): mapping of extra748 and add extra74 (#4059)
    • chore(IAM): Improve IAM checks for Azure (#4061)
    • chore(regions_update): Changes in regions for AWS services. (#4071)
    • chore(slack): change Slack channel name env variable (#4080)
    • fix(rds): solve ParameterValue KeyError (#4085)
    • fix(opensearch): handle non existing SAMLOptions in domain (#4086)
    • fix(rds): ParameterValue MySQL and MariaDB RDS Instances (#4116)
    • chore(regions_update): Changes in regions for AWS services. (#4126)
    • chore(cloudformation): Update related URL (#4134)
    • chore(vpc): add scan unused services logic to VPC checks (#4137)
    • fix(allowlist): return False if something fails (#4140)
    • fix(outputs): fill compliance field for outputs (#4054)
    • chore(ec2): add scan unused services logic to SG check (#4138)

Dependencies

  • chore(deps): bump azure-mgmt-resource from 23.0.1 to 23.1.1 by @dependabot in #3998
  • chore(deps): bump microsoft-kiota-abstractions from 1.3.2 to 1.3.3 by @dependabot in #4097
  • chore(deps-dev): bump coverage from 7.5.1 to 7.5.2 by @dependabot in #4099
  • chore(deps-dev): bump moto from 5.0.7 to 5.0.8 by @dependabot in #4100
  • chore(deps): bump boto3 from 1.34.105 to 1.34.109 by @dependabot in #4101
  • chore(deps-dev): bump docker from 7.0.0 to 7.1.0 by @dependabot in #4102
  • chore(deps): bump google-api-python-client from 2.129.0 to 2.130.0 by @dependabot in #4098
  • chore(deps): bump botocore from 1.34.109 to 1.34.113 by @dependabot in #4103
  • chore(deps): bump azure-mgmt-network from 25.3.0 to 25.4.0 by @dependabot in #4105

Full Changelog: 3.16.5...3.16.6

Prowler 4.2.1 - 2 Minutes to Midnight

29 May 18:28
4.2.1
f93b36e
Compare
Choose a tag to compare

What's Changed

Fixes

  • fix(rds): solve TypeError and make Certificate class by @sergargar in #4122
  • fix(readme): solve logo in GitHub app by @sergargar in #4128
  • fix(readme): resize logo by @sergargar in #4129
  • fix(eventbridge): solve import function in check by @sergargar in #4121

Chores

  • chore(version): update Prowler version by @sergargar in #4120
  • chore(readme): update AWS count checks by @sergargar in #4119
  • chore(regions_update): Changes in regions for AWS services. by @jfagoagas in #4126

Full Changelog: 4.2.0...4.2.1

Prowler 4.2.0 - 2 Minutes to Midnight

28 May 16:59
4.2.0
37e2c1f
Compare
Choose a tag to compare

The blind men shout,
"Let the creatures out! We'll show the unbelievers"

Here we have Prowler 4.2.0 - 2 Minutes to Midnight 🚀 bringing a new look for Prowler with this Iron Maiden song.

New features to highlight in this version

🥳 New Prowler logo
This version comes with a new look of Prowler thanks to the new logo:
Prowler_Black

💪🏼 55 New AWS checks
Prowler is improving its AWS coverage by including 55 new checks for Kafka, Lightsail, Storage Gateway, DynamoDB, Cognito, EC2, EventBridge, SNS and RDS.
Special thanks to our external contributors @madereddy, @rieck-srlabs and @Davidm4r for doing new checks 🙌
See all the new available checks with prowler aws --list-checks

📝 HTML output is back!
We have listened you and as our community is always first, we brought our HTML back 😄
Get it again with prowler <provider> -M/--output-formats html

✍️ Custom Checks Metadata
Now you can override the all the metadata fields from a check using the --custom-checks-metadata-file custom_checks_metadata.yaml flag.

See more in https://docs.prowler.cloud/en/latest/tutorials/custom-checks-metadata/

🔧 Other issues and bug fixes solved for all the cloud providers

Features

  • feat(aws): Add new kafka service by @puchy22 in #4001
  • feat(aws): Lightsail new service and checks by @puchy22 in #3919
  • feat(aws): New Storage Gateway FileShare KMS CMK Check by @madereddy in #4082
  • feat(aws): new dynamodb_table_cross_account_access check by @sergargar in #3932
  • feat(cognito): Add new checks related with cognito service by @pedrooot in #3898
  • feat(compliance): Update RBI compliance framework by @pedrooot in #4026
  • feat(custom-checks-metadata): add new fields by @pedrooot in #3976
  • feat(dashboard): add idgrupocontrol description in compliance page for ens by @pedrooot in #3910
  • feat(dashboard): add more fields to dashboard overview component by @pedrooot in #4084
  • feat(dashboard): Improve table overview by @pedrooot in #4015
  • feat(dashboard): Multiple changes in compliance page by @pedrooot in #4051
  • feat(ec2): Add 2 new checks + fixers related with EC2 service by @pedrooot in #3827
  • feat(ec2): add EC2 Security group check to verify if at least one port is opened by @sergargar in #3962
  • feat(ec2): New EC2 AWS check (#852) by @rieck-srlabs in #4076
  • feat(ec2): add checks for EC2 instances with exposed ports to the internet by @sergargar in #4029
  • feat(eventbridge): add EventBridge checks by @sergargar in #4020
  • feat(json-ocsf): Add new fields for py-ocsf 0.1.0 by @pedrooot in #3853
  • feat(Kafka): New Kafka AWS checks by @puchy22 in #4021
  • feat(kubernetes): Handle empty --kubeconfig-file by @pedrooot in #3980
  • feat(logo): add new Prowler logo! by @sergargar in #4090
  • feat(output): Add HTML outputs to Prowler by @pedrooot in #4005
  • feat(rds): Add AWS RDS clusters to transport encryption check by @madereddy in #4028
  • feat(rds): Add RDS certificate expiration check by @madereddy in #4002
  • feat(sns): sns topics no http subscriptions by @Davidm4r in #4095

Fixes

  • fix(actions): Don't need expressions within if by @jfagoagas in #3733
  • fix(aws_lambda): Update obsolete lambda runtimes by @pedrooot in #3735
  • fix(ulimit): import library only in windows by @sergargar in #3738
  • fix(download): remove dataframe index from download in dashboard by @pedrooot in #3739
  • fix(json-ocsf): add check_id field in json-ocsf output by @pedrooot in #3740
  • fix(json-ocsf): Add missing fields for JSON-OCSF by @pedrooot in #3745
  • fix(ocsf): Include check_id as metadata.event_code by @jfagoagas in #3748
  • fix(json-ocsf): Remove risk field from unmapped by @pedrooot in #3759
  • fix(wafv2): Handle WAFNonexistentItemException by @pedrooot in #3761
  • fix(compliance): Add muted info to compliance outputs by @pedrooot in #3751
  • fix(mutelist): if all fails are muted do exit 0 by @jfagoagas in #3754
  • fix(ocsf): Add compliance by @jfagoagas in #3753
  • fix(rds): ParameterValue MySQL and MariaDB RDS Instances by @sansns in #4116
  • fix(security-hub): MUTED -> WARNING by @jfagoagas in #3768
  • fix(slack): Use global provider object by @jfagoagas in #3770
  • fix(trufflehog): fix GitHub action of TruffleHog by @sergargar in #3775
  • fix(table-overview): Multiple changes on dashboard table from overview by @pedrooot in #3773
  • fix(utils): import libraries when needed by @sergargar in #3805
  • fix(network_azure): handle capitalized protocols in security group rules by @pedrooot in #3808
  • fix(execute_check): Handle ModuleNotFoundError by @jfagoagas in #3812
  • fix(overview-table): change font in overview table by @pedrooot in #3815
  • fix(dashboard): fix error in windows for csvreader by @pedrooot in #3806
  • fix(ocsf): Add resource details to data by @jfagoagas in #3819

Chores

  • chore(aws): Add failed_checks to track by @kagahd in #4018
  • chore(aws): cleanup aws test cases and standardize checks by @madereddy in #4053
  • chore(aws): cleanup aws test cases by @madereddy in #4049
  • chore(check): global_provider is not needed here by @jfagoagas in #3828
  • chore(CLI): start working on CLI by @pedrooot in #4067
  • chore(compliance): change security group any port check by @sergargar in #4019
  • chore(docs): remove unnecessary line by @sergargar in #3933
  • chore(docs): solve some issues by @sergargar in #3868
  • chore(docs): update BridgeCrew links in metadata to our local docs link by @sergargar in #3858
  • chore(docs): add mapping of CSV headers with providers by @sergargar in #4118
  • chore(docs): Update docs related with the Prowler Dashboard by @pedrooot in #4113
  • chore(execute_checks): remove mutelist since it is within the provider by @jfagoagas in #4052
  • chore(gcp): handle list projects API call errors by @sergargar in #3849
  • chore(get_tagged_resources): Add return value type hint by @mlmerchant in #3860
  • chore(global_provider): Move methods to class as static by @jfagoagas in #3896
  • chore(IAM): Improve IAM checks for Azure by @puchy22 in #4061
  • chore(issue-template): Modify issue template to add logs by @pedrooot in #3924
  • chore(labeler): Add cli label by @jfagoagas in #4069
  • chore(logo): resize logo in README and update favicon and architecture by @sergargar in #4092
  • chore(logo-dashboard): update logo in dashboard by @pedrooot in #4088
  • chore(logo-html): update html logo by @pedrooot in #4089
  • chore(mitre azure): add mapping to mitre for azure provider by @n4ch04 in #3857
  • chore(mitre gcp): add mitre mapping for gcp by @n4ch04 in #3899
  • chore(mutelist): improve default AWS mutelist with ControlTower by @sergargar in #3904
  • ch...
Read more

Prowler 3.16.5 - Back in the Village

21 May 17:44
3.16.5
7a290e7
Compare
Choose a tag to compare

What's Changed

Chores

  • chore(backport): include latest changes of v4 in v3 by @sergargar in #4027
    • fix(rds): add ReadReplicaSourceDBInstanceIdentifier to db_instance (#3912)
    • feat(ec2): add EC2 Security group check to verify if at least one port is open (#3962)
    • chore(regions_update): Changes in regions for AWS services. (#3965)
    • chore(rds): support more AWS RDS DB Instance engines in encryption check (#3968)
    • chore(regions_update): Changes in regions for AWS services. (#3971)
    • chore(deps): remove mrestazure deprecated (#3974)
    • chore(regions_update): Changes in regions for AWS services. (#4009)
    • fix(elasticache): make previous comprobations for subnet (#4014)
    • chore(regions_update): Changes in regions for AWS services. (#4017)
    • chore(compliance): change security group any port check. (#4019)
    • chore(regions_update): Changes in regions for AWS services. (#4023)
  • chore(safety-v3): ignore pip vulnerability by @sergargar in #4008

Dependencies

Full Changelog: 3.16.4...3.16.5

Prowler 3.16.4 - Back in the Village

08 May 10:20
3.16.4
0f2dfd3
Compare
Choose a tag to compare

What's Changed

Chores

  • chore(v3): backport latest v4 changes by @sergargar in #3916

    • test(gcp): Add new services tests to GCP (#3796)
    • fix(aws): not show findings when AccessDenieds (#3803)
    • fix(metadata): remove semicolons from metadata texts (#3830)
    • chore(regions_update): Changes in regions for AWS services. (#3848)
    • chore(gcp): handle list projects API call errors (#3849)
    • chore(regions_update): Changes in regions for AWS services. (#3855)
    • fix(KeyError): handle CacheSubnetGroupName keyError (#3856)
    • chore(docs): update BridgeCrew links in metadata to our local docs li…
    • chore(regions_update): Changes in regions for AWS services. (#3862)
    • fix(efs): check all public conditions (#3872)
    • docs(unit-testing): Add GCP services documentation (#3901)
    • fix(vpc): solve subnet route key error (#3902)
    • fix(vpc): solve AWS principal key error (#3903)
    • fix(ec2): handle non-existing private ip (#3906)
    • chore(regions_update): Changes in regions for AWS services. (#3908)
    • test(gcp): Add Compute client the project_ids parameter (#3918)
    • chore(regions_update): Changes in regions for AWS services. (#3915)
    • fix(efs): change public EFS check metadata (#3917)
    • chore(regions_update): Changes in regions for AWS services. (#3929)
  • chore(backport): Add latest changes by @jfagoagas in #3960

    • chore(regions_update): Changes in regions for AWS services. (#3957)
    • fix(s3): Handle if regional client is present (#3959)

Fixes

  • fix(aws): Extend opensearch_service_domains_use_cognito_authentication_for_kibana with SAML by @kagahd in #3861
  • fix(html): Produce valid HTML output in Prowler v3 by @rieck-srlabs in #3863

Dependencies

Full Changelog: 3.16.3...3.16.4

Prowler 3.16.3 - Back in the Village

24 Apr 08:59
3.16.3
3521514
Compare
Choose a tag to compare

What's Changed

Fixes

  • fix(trufflehog): fix GitHub action of TruffleHog by @sergargar in #3774

Chores

  • chore(release): 3.16.2 by @jfagoagas in #3771
  • chore(CODEOWNERS): Add prowler-dev for v3 by @jfagoagas in #3776
  • chore(deps): bump botocore from 1.34.77 to 1.34.84 by @dependabot in #3784
  • chore(deps): bump trufflesecurity/trufflehog from 3.72.0 to 3.73.0 by @dependabot in #3787
  • chore(deps-dev): bump black from 24.3.0 to 24.4.0 by @dependabot in #3781
  • chore(deps): bump azure-identity from 1.15.0 to 1.16.0 by @dependabot in #3785
  • chore(deps): bump boto3 from 1.34.77 to 1.34.84 by @dependabot in #3790
  • chore(deps-dev): bump mkdocs-material from 9.5.17 to 9.5.18 by @dependabot in #3792
  • chore(backport): include latest changes of v4 in v3 by @sergargar in #3825
    ** chore(rds): improve rds public instance check by @sergargar in #3797
    ** chore(ec2): improve handling of ENIs by @sergargar in #3798
    ** docs(developer guide): fix broken link by @mlmerchant in #3799
    ** fix(network_azure): handle capitalized protocols in security group rules by @pedrooot in #3808
    ** chore(vpc): improve public subnet logic by @sergargar in #3814
    ** fix(aws): Include record names for dangling IPs by @rieck-srlabs in #3821
    ** fix(aws): Corrects privilege escalation vectors by @rieck-srlabs in #3823
  • chore(backport): include latest changes to version 3 by @sergargar in #3846
  • chore(deps): bump msgraph-sdk from 1.2.0 to 1.3.0 by @dependabot in #3838
  • chore(deps): bump botocore from 1.34.84 to 1.34.89 by @dependabot in #3841
  • chore(deps): bump azure-mgmt-containerservice from 29.1.0 to 30.0.0 by @dependabot in #3839
  • chore(deps): bump google-api-python-client from 2.125.0 to 2.127.0 by @dependabot in #3843

Full Changelog: 3.16.2...3.16.3

Prowler 4.1.0 - Aces High

19 Apr 06:44
4.1.0
ebf9be3
Compare
Choose a tag to compare

There goes the siren that warns of the air raid
There comes the sound of the guns sending flak
Out for the scramble we've got to get airborne
Got to get up for the coming attack

Here we have Prowler 4.1.0 Aces High 🚀 ready to help you improve your Cloud security with this Iron Maiden song.

New features to highlight in this version

🖊️ GCP flags to list, exclude/include Project IDs

  • Now the --project-ids flag allows you to use *, as a prefix or suffix, to include the project ids you want to scan.
  • The --list-project-ids allows you to copy and paste values and know the accessible projects to be scanned with the provided crendentials.
  • The --excluded-project-ids flag allows you to exclude the projects to be scanned and it also accepts *.

🔨 13 new fixers (remediations) for AWS

  • We have included 13 new fixers for services like Access Analyzer, CloudTrail, GuardDuty, KMS, Security Hub and IAM. You can get all the available fixers with prowler aws --list-fixers then go per check to remediate the failed findings by prowler aws --check guardduty_is_enabled --fixer.
  • Some of those fixers are configurable using the fixer_config.yaml file present in the prowler/config folder. You can read more about the fixer and how to configure it here

📘 New fields for the OCSF Detection Finding

  • We have included the check_id, compliance and all the Prowler check's metadata within the OCSF Detection Finding that Prowler generates in the .ocsf.json output file. You can read more about this finding format here.

🔧 Other issues and bug fixes solved for all the cloud providers

Features

  • feat(gcp): improve Google Projects scan customization by @sergargar in #3741

Fixes

  • fix(actions): Don't need expressions within if by @jfagoagas in #3733
  • fix(aws_lambda): Update obsolete lambda runtimes by @pedrooot in #3735
  • fix(ulimit): import library only in windows by @sergargar in #3738
  • fix(download): remove dataframe index from download in dashboard by @pedrooot in #3739
  • fix(json-ocsf): add check_id field in json-ocsf output by @pedrooot in #3740
  • fix(json-ocsf): Add missing fields for JSON-OCSF by @pedrooot in #3745
  • fix(ocsf): Include check_id as metadata.event_code by @jfagoagas in #3748
  • fix(json-ocsf): Remove risk field from unmapped by @pedrooot in #3759
  • fix(wafv2): Handle WAFNonexistentItemException by @pedrooot in #3761
  • fix(compliance): Add muted info to compliance outputs by @pedrooot in #3751
  • fix(mutelist): if all fails are muted do exit 0 by @jfagoagas in #3754
  • fix(ocsf): Add compliance by @jfagoagas in #3753
  • fix(security-hub): MUTED -> WARNING by @jfagoagas in #3768
  • fix(slack): Use global provider object by @jfagoagas in #3770
  • fix(trufflehog): fix GitHub action of TruffleHog by @sergargar in #3775
  • fix(table-overview): Multiple changes on dashboard table from overview by @pedrooot in #3773
  • fix(utils): import libraries when needed by @sergargar in #3805
  • fix(network_azure): handle capitalized protocols in security group rules by @pedrooot in #3808
  • fix(execute_check): Handle ModuleNotFoundError by @jfagoagas in #3812
  • fix(overview-table): change font in overview table by @pedrooot in #3815
  • fix(dashboard): fix error in windows for csvreader by @pedrooot in #3806
  • fix(ocsf): Add resource details to data by @jfagoagas in #3819

Chores

  • chore(version): update Prowler version by @sergargar in #3730
  • chore(regions_update): Changes in regions for AWS services. by @n4ch04 in #3746
  • chore(dashboard): Use Prowler CLI parser by @jfagoagas in #3722
  • chore(regions_update): Changes in regions for AWS services. by @n4ch04 in #3755
  • chore(regions_update): Changes in regions for AWS services. by @n4ch04 in #3765
  • chore(fixer): improve fixer logic and include more by @sergargar in #3750
  • chore(rds): improve rds public instance check by @sergargar in #3797
  • chore(ec2): improve handling of ENIs by @sergargar in #3798
  • chore(aws): Add CloudTrail Threat Detection tests by @pedrooot in #3804
  • chore(fixer): add more fixers by @sergargar in #3772
  • chore(vpc): improve public subnet logic by @sergargar in #3814
  • chore(codeowners): Add prowler-dev team by @jfagoagas in #3763

Dependencies

Documentation

  • docs(dashboard): Indicate how to change port by @jfagoagas in #3729
  • docs(dashboard): format list by @jfagoagas in #3732
  • docs: readme points to docs.prowler.com to learn everything by @jfagoagas in #3707
  • chore(docs): Support toggle light/dark mode by @puchy22 in #3744
  • docs(outputs): update docs for v4 outputs by @pedrooot in #3734
  • docs(threat-detection): Add threat-detection docs by @pedrooot in #3757
  • docs(compliance): Change images for compliance by @pedrooot in #3760
  • docs(devel-guide): Adding some improves and clarifications to developer guide by @puchy22 in #3749
  • docs(devel-guide): Add provider section and remove audit_info section by @puchy22 in #3756
  • docs(unit-testing): Update the unit testing section by @puchy22 in #3764
  • docs(developer guide): fix broken link by @mlmerchant in #3799
  • docs(ocsf): Add missing fields to the example by @jfagoagas in #3816

New Contributors

Full Changelog: 4.0.1...4.1.0

Prowler 3.16.2 - Back in the Village

15 Apr 08:10
3.16.2
51136fe
Compare
Choose a tag to compare

What's Changed

Fixes

  • fix(aws_lambda): Update obsolete lambda runtimes for v3 by @pedrooot in #3736
  • fix(wafv2): Handle WAFNonexistentItemException v3 by @pedrooot in #3762

Chores

Full Changelog: 3.16.1...3.16.2

Prowler 4.0.1 - The Trooper

09 Apr 10:27
4.0.1
5e52ed8
Compare
Choose a tag to compare

What's Changed

Fixes

  • fix(actions): use LATEST_TAG for v4 by @jfagoagas in #3703
  • fix(args): Handle default argument by @jfagoagas in #3674
  • fix(compliance): add field ModoEjecucion in csv output for ENS by @pedrooot in #3719
  • fix(dashboard): add correct label for each dropdown by @pedrooot in #3700
  • fix(dashboard): Add multiple dashboard fixes by @pedrooot in #3714
  • fix(dockerfile): add missing path to build by @jfagoagas in #3680
  • fix(ens): add dependencias field ENS rd2022 compliance by @pedrooot in #3701
  • fix(gcp): add project id to outputs by @sergargar in #3711
  • fix(k8s): improve kubernetes deployment by @sergargar in #3713
  • fix(k8s): sanitize context syntax only for output file names by @sergargar in #3689
  • fix(service_name): fix typo in ServiceName field by @pedrooot in #3723

Chores

  • chore(action): update python version to 3.12 in GH action by @sergargar in #3705
  • chore(actions): Run for master and v3 by @jfagoagas in #3685
  • chore(Azure): Optimize Entra service to use async funcs by @puchy22 in #3706
  • chore(dependabot): Add v3 label by @jfagoagas in #3698
  • chore(dependabot): Run also for v3 branch by @jfagoagas in #3683
  • chore(dispatch): just for v3 by @jfagoagas in #3712
  • chore(Dockerfile): remove deprecated dash dependencies by @sergargar in #3708
  • chore(Dockerfile): update Python version to 3.12 by @sergargar in #3699
  • chore(docs): update CloudShell scripts by @sergargar in #3687
  • chore(merge): include latest changes of v3 by @sergargar in #3686
  • chore(mutelist): remove space within mutelist name by @sergargar in #3690
  • chore(regions): Add backport-v3 label by @jfagoagas in #3684
  • chore(regions_update): Changes in regions for AWS services. by @n4ch04 in #3693
  • chore(regions_update): Changes in regions for AWS services. by @n4ch04 in #3727

Documentation

  • docs(dashboard): improve dashboard documentation by @pedrooot in #3688
  • docs(images): fix images link in documentation by @sergargar in #3709
  • docs(mutelist): remove MUTED and explain new fields by @jfagoagas in #3726

Dependencies

  • build(deps): Update boto3 to version 1.34.77 by @sergargar in #3669
  • chore(deps): bump botocore from 1.34.77 to 1.34.80 by @dependabot in #3715
  • chore(deps): bump google-api-python-client from 2.124.0 to 2.125.0 by @dependabot in #3678
  • chore(deps): bump kubernetes from 28.1.0 to 29.0.0 by @dependabot in #3679
  • chore(deps): bump trufflesecurity/trufflehog from 3.71.2 to 3.72.0 by @dependabot in #3677
  • chore(deps-dev): bump moto from 5.0.4 to 5.0.5 by @dependabot in #3681

Full Changelog: 4.0.0...4.0.1