This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
ReleasePort's take
Moderate signalThe Vitest toolchain was upgraded from versionβ―4.0.18 toβ―4.1.8, resolving two critical pnpm audit advisories.
Why it matters: Critical security fixes are applied by upgrading Vitest; operators should adopt the update immediately.
Summary
AI summaryUpdates https://github.com/prowler-cloud/prowler/pull/11424, π Fixed, and π Changed across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Vitest toolchain upgraded from 4.0.18 to 4.1.8 clearing two critical pnpm audit advisories Vitest toolchain upgraded from 4.0.18 to 4.1.8 clearing two critical pnpm audit advisories Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Feature | Low |
Account and provider-type selector triggers now show the provider icon with a non-deduped icon stack Account and provider-type selector triggers now show the provider icon with a non-deduped icon stack Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
| Bugfix | Medium |
Add Provider modal now closes without reloading the providers page Add Provider modal now closes without reloading the providers page Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Users page shows "Delete User" only on current user's row Users page shows "Delete User" only on current user's row Source: llm_adapter@2026-06-03 Confidence: high |
β |
Full changelog
UI
π Changed
- Account and provider-type selector triggers now show the provider icon, with a non-deduped icon stack (#11424)
π Fixed
- Add Provider modal now closes without reloading the providers page (#11424)
- Users page now shows the "Delete User" action only on the current user's row, matching the backend rule that a user can only delete their own account (#11447)
π Security
- Vitest toolchain upgraded
4.0.18β4.1.8to clear two criticalpnpm auditadvisories (#11424)
Security Fixes
- Vitest upgraded from 4.0.18 to 4.1.8 to clear two critical pnpm audit advisories
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Prowler
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Related context
Related tools
Beta — feedback welcome: [email protected]