✨ New features to highlight in this version
Enjoy them all now for free at https://cloud.prowler.com/
🔁 Findings — Re-check a Resource with a Partial Scan
Note
This feature is available exclusively in Prowler Cloud and Prowler Private Cloud with a subscription.
A resource that has just been fixed can be confirmed from the Findings page without waiting for the next full scan. Re-check resource is available in the actions menu of every resource row and in the resource detail drawer, and a hint icon next to Last seen opens it directly. It launches a partial scan that runs again only the checks that last reported on that resource; its findings update when the scan completes, and every other resource keeps the results of the latest full scan. Roles need the Manage Scans permission, and a re-check is refused while the provider has a scan running or queued.
Re-checked resources that now pass drop out of the finding groups list and its drill-down instead of opening a detail panel that still reports FAIL. Partial scans do not change overviews or compliance until the next full scan and produce no report files, so the Scans table marks them as Partial, offers no report download for them, and the per-scan Compliance selector leaves them out.
Partial scans can also be launched outside the Findings page:
- API:
POST /api/v1/scansaccepts up to 10 resources inresource_uids, and scans exposeis_partialwith afilter[is_partial]filter. - MCP Server:
prowler_trigger_scantakes aresource_uidsargument, andprowler_list_scansandprowler_get_scanreturnis_partial, with anis_partialfilter onprowler_list_scans. - Lighthouse AI: can launch a partial scan to re-check specific resources, such as confirming a remediation.
☁️ AWS — Connect an Account in One Step
The Add Provider wizard connects an AWS account in a single step. The account ID is read from the role ARN (or typed when using static access keys), the role is assumed with Prowler's own credentials, and the account, its credentials and the connection test are handled by one submit. A confirmed connection goes straight to the launch step. A refused connection stays on the form with the reason the API returned, so the fields can be fixed and retried without registering the account twice.
New tenants without providers now land on this wizard on their first sign-in instead of a welcome modal, and the sidebar action reads Add Provider until the first provider is connected.
Read more in the Getting Started with AWS documentation.
🔌 Connection Tests No Longer Give Up Early
The provider connection test no longer reports Max retries exceeded for checks that take longer than 30 seconds, such as networks where some AWS endpoints are unreachable. The UI now waits for the full time limit of the backend task, and if that is still exhausted it shows the provider's current connection state instead of a failure.
On the SDK side, STS calls after a role assumption reuse the region that answered, so an unreachable partition region is waited on once instead of twice. The new PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTS environment variable sets the Boto3 retries for deployments that build the AWS provider without CLI flags, next to the existing timeout variables; 0 disables retries.
Read more in the Boto3 configuration documentation.
🗄️ Self-Hosted — S3-Compatible Storage and Air-Gapped Deployments
DJANGO_OUTPUT_S3_AWS_ENDPOINT_URLpoints scan output uploads and downloads at S3-compatible object storage such as MinIO. Previously the only way to reach it was exporting process-wide AWS environment variables, which also hijacked unrelated AWS API calls such as role assumption for AWS providers.- Report downloads from a bucket with default SSE-KMS encryption no longer fail with
InvalidArgument: whenDJANGO_OUTPUT_S3_AWS_DEFAULT_REGIONis set, download URLs are signed with Signature Version 4 for that region. - Icons ship in the UI bundle instead of being fetched from
api.iconify.design, so pages render correctly without internet access. - Celery worker fatal errors are logged instead of silenced, and every long-running service in
docker-compose.ymlrestarts automatically after an unexpected crash.
📊 Consistent Latest Scan Across Endpoints
Every endpoint now resolves a provider's latest completed scan the same way, so overlapping scans no longer make findings, compliance and mute rules read from different scans. Providers whose latest completed scan has no completed_at timestamp are no longer missing from those endpoints, and resources no longer keep a stale failed findings count when a scoped or imported scan completes after a full scan.
🛠️ Prowler App Fixes
- API key authentication no longer locks the key row on every request, so a heavily used key no longer serializes all its requests;
last_used_atis updated at most once per minute. POST /api/v1/scansreturns the new scan ID intask_argsagain.- Provider deletion no longer fails when the provider has Attack Paths scans recorded on a sink that is no longer configured, such as Neptune after moving back to Neo4j.
- A periodic sweep drops orphaned Attack Paths temporary Neo4j databases left behind when a worker or Neo4j crashes mid-scan.
- Prowler Cloud: imported findings no longer stay stuck in
pendingwhen the ingestion worker picks up the job before it is committed, and a failed enqueue marks the ingestion as failed. - Prowler Cloud: the Lighthouse AI connection check reports a network failure as one, naming the endpoint it could not reach, instead of hitting a time limit that looked the same as a bad key.
- Prowler Cloud: the finding groups endpoints no longer query Manual Pass triages once per finding, and skip that overlay for tenants with no active Manual Pass.
- The Findings page renders a skeleton at once and streams the table before the filters, and the Finding Group options load when the dropdown opens.
- Mute rule creation errors show the API error message instead of the raw response body.
- The sidebar no longer throws a hydration error on full page loads for users who last used the chat mode.
🔐 Security Updates
DELETE /api/v1/tasks/{id}requires the permission of the operation that queued the task and rejects provider deletions, andGET /api/v1/taskshides tasks of providers outside the role's visibility.- The UI E2E workflow receives its AWS credentials through environment variables instead of template expansion.
See the full release notes on GitHub for the complete list of changes.
UI
🚀 Added
- Sidebar action reads Add Provider while the tenant has no providers (#12852)
🔄 Changed
- AWS accounts are connected in a single wizard step: the account is read from the role ARN, or typed for access keys, the role is assumed with Prowler's own credentials, and the credentials are stored and tested with the account (#12852)
- New tenants without providers land on the Add Provider wizard on first sign-in instead of a welcome modal (#12852)
- Findings page paints a skeleton at once and streams the table before the filters; the "Finding Group" options load in a single request when the dropdown opens (#12891)
🐞 Fixed
- Mute rule creation errors show the API error message instead of the raw JSON:API response body (#12853)
- Provider connection test no longer reports
Max retries exceededfor checks that take longer than 30 seconds, such as networks where some AWS endpoints are unreachable; the wait now covers the backend task's full time limit and falls back to the provider's current connection state if it is still exhausted (#12869) - Sidebar no longer throws a React hydration error on full page loads for users who last used the chat mode (#12873)
- Icons now ship in the UI bundle instead of being fetched from
api.iconify.design, so pages render correctly in air-gapped deployments (#12892)
API
🚀 Added
- Scan output uploads and downloads can now target S3-compatible object storage such as MinIO directly via
DJANGO_OUTPUT_S3_AWS_ENDPOINT_URL, instead of relying on process-wide AWS environment variables that also hijacked unrelated AWS API calls (#12871)
🔄 Changed
- Unify how every endpoint resolves a provider latest completed scan, so overlapping scans no longer make findings, compliance and mute rules read from different scans (#12858)
🐞 Fixed
- Celery loggers are now declared explicitly in
custom_logging.pyso fatal worker errors are no longer silenced bydisable_existing_loggers=True. All long-running services indocker-compose.ymlnow haverestart: unless-stoppedso containers recover automatically after unexpected crashes. (#12465) - Scan report downloads from an S3 bucket with default SSE-KMS encryption no longer fail with an
InvalidArgumenterror: whenDJANGO_OUTPUT_S3_AWS_DEFAULT_REGIONis set, presigned download URLs are signed with AWS Signature Version 4 for that region (#12746) - Adds a periodic sweep that drops orphaned Attack Paths temp Neo4j scan databases left behind when a worker or Neo4j crashes mid-scan, before they accumulate unbounded (#12832)
- Providers whose most recent completed scan has no
completed_attimestamp are no longer missing from every endpoint that reports a provider's latest scan, which now falls back to scan creation order instead of skipping the provider (#12858) - Resources no longer keep a stale failed findings count forever when a scoped or imported scan for the same provider completes after a full scan, which used to make the full scan skip its own cleanup (#12858)
POST /api/v1/scansagain returns the new scan id in the responsetask_args, which had been empty since the scan broker publish moved to transaction commit (#12878)- API key authentication no longer locks the key row on every request and now throttles
last_used_atupdates to once per 60 seconds, preventing a hot key from serializing all its requests onto a single locked row (#12882) - Provider deletion no longer fails when the provider has Attack Paths scans recorded on a sink that is no longer configured, such as Neptune after moving back to Neo4j (#12894)
🔐 Security
DELETE /api/v1/tasks/{id}requires the permission of the operation that queued the task and rejects provider deletions, andGET /api/v1/taskshides tasks of providers outside the visibility of the role (#12893)
SDK
🚀 Added
PROWLER_AWS_BOTO3_RETRIES_MAX_ATTEMPTSenvironment variable to set the Boto3 retries for deployments without CLI flags (#12870)
🐞 Fixed
- STS calls after role assumption use the answering region, avoiding a second wait for an unreachable partition region (#12870)
🔐 Security
- Pass the E2E AWS credentials to the UI E2E workflow through environment variables instead of template expansion (#12864)