Skip to content

Commit 3e99ec9

Browse files
committed
Merge branch 'master' into fix-trendmicro-links
2 parents 09bb0d2 + bb5a437 commit 3e99ec9

280 files changed

Lines changed: 21604 additions & 2615 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/api-security.yml‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
1-
name: 'API: Security'
1+
name: "API: Security"
22

33
on:
44
push:
55
branches:
6-
- 'master'
7-
- 'v5.*'
6+
- "master"
7+
- "v5.*"
88
pull_request:
99
branches:
10-
- 'master'
11-
- 'v5.*'
10+
- "master"
11+
- "v5.*"
1212

1313
concurrency:
1414
group: ${{ github.workflow }}-${{ github.ref }}
@@ -26,7 +26,7 @@ jobs:
2626
strategy:
2727
matrix:
2828
python-version:
29-
- '3.12'
29+
- "3.12"
3030
defaults:
3131
run:
3232
working-directory: ./api

‎.github/workflows/sdk-refresh-oci-regions.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,8 +57,6 @@ jobs:
5757
title: 'feat(oraclecloud): Update commercial regions'
5858
labels: |
5959
status/waiting-for-revision
60-
severity/low
61-
provider/oraclecloud
6260
no-changelog
6361
body: |
6462
### Description

‎.github/workflows/ui-tests.yml‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,35 @@ jobs:
4444
ui/README.md
4545
ui/AGENTS.md
4646
47+
- name: Get changed source files for targeted tests
48+
id: changed-source
49+
if: steps.check-changes.outputs.any_changed == 'true'
50+
uses: tj-actions/changed-files@e0021407031f5be11a464abee9a0776171c79891 # v47.0.1
51+
with:
52+
files: |
53+
ui/**/*.ts
54+
ui/**/*.tsx
55+
files_ignore: |
56+
ui/**/*.test.ts
57+
ui/**/*.test.tsx
58+
ui/**/*.spec.ts
59+
ui/**/*.spec.tsx
60+
ui/vitest.config.ts
61+
ui/vitest.setup.ts
62+
63+
- name: Check for critical path changes (run all tests)
64+
id: critical-changes
65+
if: steps.check-changes.outputs.any_changed == 'true'
66+
uses: tj-actions/changed-files@e0021407031f5be11a464abee9a0776171c79891 # v47.0.1
67+
with:
68+
files: |
69+
ui/lib/**
70+
ui/types/**
71+
ui/config/**
72+
ui/middleware.ts
73+
ui/vitest.config.ts
74+
ui/vitest.setup.ts
75+
4776
- name: Setup Node.js ${{ env.NODE_VERSION }}
4877
if: steps.check-changes.outputs.any_changed == 'true'
4978
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
@@ -83,6 +112,27 @@ jobs:
83112
if: steps.check-changes.outputs.any_changed == 'true'
84113
run: pnpm run healthcheck
85114

115+
- name: Run unit tests (all - critical paths changed)
116+
if: steps.check-changes.outputs.any_changed == 'true' && steps.critical-changes.outputs.any_changed == 'true'
117+
run: |
118+
echo "Critical paths changed - running ALL unit tests"
119+
pnpm run test:run
120+
121+
- name: Run unit tests (related to changes only)
122+
if: steps.check-changes.outputs.any_changed == 'true' && steps.critical-changes.outputs.any_changed != 'true' && steps.changed-source.outputs.all_changed_files != ''
123+
run: |
124+
echo "Running tests related to changed files:"
125+
echo "${{ steps.changed-source.outputs.all_changed_files }}"
126+
# Convert space-separated to vitest related format (remove ui/ prefix for relative paths)
127+
CHANGED_FILES=$(echo "${{ steps.changed-source.outputs.all_changed_files }}" | tr ' ' '\n' | sed 's|^ui/||' | tr '\n' ' ')
128+
pnpm exec vitest related $CHANGED_FILES --run
129+
130+
- name: Run unit tests (test files only changed)
131+
if: steps.check-changes.outputs.any_changed == 'true' && steps.critical-changes.outputs.any_changed != 'true' && steps.changed-source.outputs.all_changed_files == ''
132+
run: |
133+
echo "Only test files changed - running ALL unit tests"
134+
pnpm run test:run
135+
86136
- name: Build application
87137
if: steps.check-changes.outputs.any_changed == 'true'
88138
run: pnpm run build

‎.pre-commit-config.yaml‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,6 @@ repos:
8585
args: ["--directory=./"]
8686
pass_filenames: false
8787

88-
8988
- repo: https://github.com/hadolint/hadolint
9089
rev: v2.13.0-beta
9190
hooks:

‎AGENTS.md‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,8 @@ Use these skills for detailed patterns on-demand:
2424
| `zod-4` | New API (z.email(), z.uuid()) | [SKILL.md](skills/zod-4/SKILL.md) |
2525
| `zustand-5` | Persist, selectors, slices | [SKILL.md](skills/zustand-5/SKILL.md) |
2626
| `ai-sdk-5` | UIMessage, streaming, LangChain | [SKILL.md](skills/ai-sdk-5/SKILL.md) |
27+
| `vitest` | Unit testing, React Testing Library | [SKILL.md](skills/vitest/SKILL.md) |
28+
| `tdd` | Test-Driven Development workflow | [SKILL.md](skills/tdd/SKILL.md) |
2729

2830
### Prowler-Specific Skills
2931
| Skill | Description | URL |
@@ -56,8 +58,8 @@ When performing these actions, ALWAYS invoke the corresponding skill FIRST:
5658
| Add changelog entry for a PR or feature | `prowler-changelog` |
5759
| Adding DRF pagination or permissions | `django-drf` |
5860
| Adding new providers | `prowler-provider` |
59-
| Adding services to existing providers | `prowler-provider` |
6061
| Adding privilege escalation detection queries | `prowler-attack-paths-query` |
62+
| Adding services to existing providers | `prowler-provider` |
6163
| After creating/modifying a skill | `skill-sync` |
6264
| App Router / Server Actions | `nextjs-15` |
6365
| Building AI chat features | `ai-sdk-5` |
@@ -76,40 +78,51 @@ When performing these actions, ALWAYS invoke the corresponding skill FIRST:
7678
| Creating/updating compliance frameworks | `prowler-compliance` |
7779
| Debug why a GitHub Actions job is failing | `prowler-ci` |
7880
| Fill .github/pull_request_template.md (Context/Description/Steps to review/Checklist) | `prowler-pr` |
81+
| Fixing bug | `tdd` |
7982
| General Prowler development questions | `prowler` |
8083
| Implementing JSON:API endpoints | `django-drf` |
84+
| Implementing feature | `tdd` |
8185
| Inspect PR CI checks and gates (.github/workflows/*) | `prowler-ci` |
8286
| Inspect PR CI workflows (.github/workflows/*): conventional-commit, pr-check-changelog, pr-conflict-checker, labeler | `prowler-pr` |
8387
| Mapping checks to compliance controls | `prowler-compliance` |
8488
| Mocking AWS with moto in tests | `prowler-test-sdk` |
8589
| Modifying API responses | `jsonapi` |
90+
| Modifying component | `tdd` |
91+
| Refactoring code | `tdd` |
8692
| Regenerate AGENTS.md Auto-invoke tables (sync.sh) | `skill-sync` |
8793
| Review PR requirements: template, title conventions, changelog gate | `prowler-pr` |
8894
| Review changelog format and conventions | `prowler-changelog` |
8995
| Reviewing JSON:API compliance | `jsonapi` |
9096
| Reviewing compliance framework PRs | `prowler-compliance-review` |
9197
| Testing RLS tenant isolation | `prowler-test-api` |
98+
| Testing hooks or utilities | `vitest` |
9299
| Troubleshoot why a skill is missing from AGENTS.md auto-invoke | `skill-sync` |
93100
| Understand CODEOWNERS/labeler-based automation | `prowler-ci` |
94101
| Understand PR title conventional-commit validation | `prowler-ci` |
95102
| Understand changelog gate and no-changelog label behavior | `prowler-ci` |
96103
| Understand review ownership with CODEOWNERS | `prowler-pr` |
97104
| Update CHANGELOG.md in any component | `prowler-changelog` |
105+
| Updating README.md provider statistics table | `prowler-readme-table` |
106+
| Updating checks, services, compliance, or categories count in README.md | `prowler-readme-table` |
98107
| Updating existing Attack Paths queries | `prowler-attack-paths-query` |
99108
| Updating existing checks and metadata | `prowler-sdk-check` |
100109
| Using Zustand stores | `zustand-5` |
101110
| Working on MCP server tools | `prowler-mcp` |
102111
| Working on Prowler UI structure (actions/adapters/types/hooks) | `prowler-ui` |
112+
| Working on task | `tdd` |
103113
| Working with Prowler UI test helpers/pages | `prowler-test-ui` |
104114
| Working with Tailwind classes | `tailwind-4` |
105115
| Writing Playwright E2E tests | `playwright` |
106116
| Writing Prowler API tests | `prowler-test-api` |
107117
| Writing Prowler SDK tests | `prowler-test-sdk` |
108118
| Writing Prowler UI E2E tests | `prowler-test-ui` |
109119
| Writing Python tests with pytest | `pytest` |
120+
| Writing React component tests | `vitest` |
110121
| Writing React components | `react-19` |
111122
| Writing TypeScript types/interfaces | `typescript` |
123+
| Writing Vitest tests | `vitest` |
112124
| Writing documentation | `prowler-docs` |
125+
| Writing unit tests for UI | `vitest` |
113126

114127
---
115128

‎README.md‎

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -104,15 +104,15 @@ Every AWS provider scan will enqueue an Attack Paths ingestion job automatically
104104

105105
| Provider | Checks | Services | [Compliance Frameworks](https://docs.prowler.com/projects/prowler-open-source/en/latest/tutorials/compliance/) | [Categories](https://docs.prowler.com/projects/prowler-open-source/en/latest/tutorials/misc/#categories) | Support | Interface |
106106
|---|---|---|---|---|---|---|
107-
| AWS | 585 | 84 | 40 | 17 | Official | UI, API, CLI |
108-
| Azure | 169 | 22 | 17 | 13 | Official | UI, API, CLI |
109-
| GCP | 100 | 17 | 14 | 7 | Official | UI, API, CLI |
110-
| Kubernetes | 84 | 7 | 7 | 9 | Official | UI, API, CLI |
111-
| GitHub | 20 | 2 | 1 | 2 | Official | UI, API, CLI |
112-
| M365 | 72 | 7 | 4 | 4 | Official | UI, API, CLI |
113-
| OCI | 52 | 14 | 1 | 12 | Official | UI, API, CLI |
114-
| Alibaba Cloud | 64 | 9 | 2 | 9 | Official | UI, API, CLI |
115-
| Cloudflare | 29 | 3 | 0 | 5 | Official | CLI |
107+
| AWS | 572 | 83 | 41 | 17 | Official | UI, API, CLI |
108+
| Azure | 165 | 20 | 18 | 13 | Official | UI, API, CLI |
109+
| GCP | 100 | 13 | 15 | 11 | Official | UI, API, CLI |
110+
| Kubernetes | 83 | 7 | 7 | 9 | Official | UI, API, CLI |
111+
| GitHub | 21 | 2 | 1 | 2 | Official | UI, API, CLI |
112+
| M365 | 75 | 7 | 4 | 4 | Official | UI, API, CLI |
113+
| OCI | 51 | 13 | 3 | 12 | Official | UI, API, CLI |
114+
| Alibaba Cloud | 61 | 9 | 3 | 9 | Official | UI, API, CLI |
115+
| Cloudflare | 29 | 2 | 0 | 5 | Official | CLI, API |
116116
| IaC | [See `trivy` docs.](https://trivy.dev/latest/docs/coverage/iac/) | N/A | N/A | N/A | Official | UI, API, CLI |
117117
| MongoDB Atlas | 10 | 3 | 0 | 3 | Official | UI, API, CLI |
118118
| LLM | [See `promptfoo` docs.](https://www.promptfoo.dev/docs/red-team/plugins/) | N/A | N/A | N/A | Official | CLI |

‎api/AGENTS.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,13 +24,18 @@ When performing these actions, ALWAYS invoke the corresponding skill FIRST:
2424
| Creating ViewSets, serializers, or filters in api/ | `django-drf` |
2525
| Creating a git commit | `prowler-commit` |
2626
| Creating/modifying models, views, serializers | `prowler-api` |
27+
| Fixing bug | `tdd` |
2728
| Implementing JSON:API endpoints | `django-drf` |
29+
| Implementing feature | `tdd` |
2830
| Modifying API responses | `jsonapi` |
31+
| Modifying component | `tdd` |
32+
| Refactoring code | `tdd` |
2933
| Review changelog format and conventions | `prowler-changelog` |
3034
| Reviewing JSON:API compliance | `jsonapi` |
3135
| Testing RLS tenant isolation | `prowler-test-api` |
3236
| Update CHANGELOG.md in any component | `prowler-changelog` |
3337
| Updating existing Attack Paths queries | `prowler-attack-paths-query` |
38+
| Working on task | `tdd` |
3439
| Writing Prowler API tests | `prowler-test-api` |
3540
| Writing Python tests with pytest | `pytest` |
3641

‎api/CHANGELOG.md‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ All notable changes to the **Prowler API** are documented in this file.
77
### 🚀 Added
88

99
- OpenStack provider support [(#10003)](https://github.com/prowler-cloud/prowler/pull/10003)
10+
- PDF report for the CSA CCM compliance framework [(#10088)](https://github.com/prowler-cloud/prowler/pull/10088)
1011

1112
### 🔄 Changed
1213

@@ -19,10 +20,27 @@ All notable changes to the **Prowler API** are documented in this file.
1920
- Support CSA CCM 4.0 for the Oracle Cloud provider [(#10057)](https://github.com/prowler-cloud/prowler/pull/10057)
2021
- Support CSA CCM 4.0 for the Alibaba Cloud provider [(#10061)](https://github.com/prowler-cloud/prowler/pull/10061)
2122
- Attack Paths: Mark attack Paths scan as failed when Celery task fails outside job error handling [(#10065)](https://github.com/prowler-cloud/prowler/pull/10065)
23+
- Attack Paths: Remove legacy per-scan `graph_database` and `is_graph_database_deleted` fields from AttackPathsScan model [(#10077)](https://github.com/prowler-cloud/prowler/pull/10077)
24+
- Attack Paths: Add `graph_data_ready` field to decouple query availability from scan state [(#10089)](https://github.com/prowler-cloud/prowler/pull/10089)
25+
- AI agent guidelines with TDD and testing skills references [(#9925)](https://github.com/prowler-cloud/prowler/pull/9925)
26+
- Attack Paths: Upgrade Cartography from fork 0.126.1 to upstream 0.129.0 and Neo4j driver from 5.x to 6.x [(#10110)](https://github.com/prowler-cloud/prowler/pull/10110)
27+
28+
### 🐞 Fixed
29+
30+
- Attack Paths: Orphaned temporary Neo4j databases are now cleaned up on scan failure and provider deletion [(#10101)](https://github.com/prowler-cloud/prowler/pull/10101)
2231

2332
### 🔐 Security
2433

2534
- Bump `Pillow` to 12.1.1 (CVE-2021-25289) [(#10027)](https://github.com/prowler-cloud/prowler/pull/10027)
35+
- Remove safety ignore for CVE-2026-21226 (84420), fixed via `azure-core` 1.38.x [(#10110)](https://github.com/prowler-cloud/prowler/pull/10110)
36+
37+
---
38+
39+
## [1.19.3] (Prowler UNRELEASED)
40+
41+
### 🐞 Fixed
42+
43+
- GCP provider UID validation regex to allow domain prefixes [(#10078)](https://github.com/prowler-cloud/prowler/pull/10078)
2644

2745
---
2846

‎api/Dockerfile‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,13 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
2424
python3-dev \
2525
&& rm -rf /var/lib/apt/lists/*
2626

27+
# Cartography depends on `dockerfile` which has no pre-built arm64 wheel and requires Go to compile
28+
# hadolint ignore=DL3008
29+
RUN if [ "$(uname -m)" = "aarch64" ]; then \
30+
apt-get update && apt-get install -y --no-install-recommends golang-go \
31+
&& rm -rf /var/lib/apt/lists/* ; \
32+
fi
33+
2734
# Install PowerShell
2835
RUN ARCH=$(uname -m) && \
2936
if [ "$ARCH" = "x86_64" ]; then \

0 commit comments

Comments
 (0)