Skip to content

Prowler

v5.29.3 Bugfix

This release fixes issues for SREs watching stability and regressions.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

aws azure cis-benchmark cloud cloudsecurity compliance
+12 more
cspm security forensics gcp gdpr hardening iam multi-cloud python security-audit security-hardening security-tools

Summary

AI summary

Updates 🐞 Fixed, UI, and https://github.com/prowler-cloud/prowler/pull/11493 across a mixed release.

Changes in this release

Bugfix High

API startup no longer crashes when Neo4j is unreachable; connection becomes lazy on first use.

API startup no longer crashes when Neo4j is unreachable; connection becomes lazy on first use.

Source: llm_adapter@2026-06-09

Confidence: high

β€”
Bugfix Medium

Finding drawer tabs retain active tab styling when tooltip state changes.

Finding drawer tabs retain active tab styling when tooltip state changes.

Source: llm_adapter@2026-06-09

Confidence: high

β€”
Bugfix Medium

GCP `logging_sink_created` check now recognizes organization‑level aggregated sinks with `includeChildren=True`.

GCP `logging_sink_created` check now recognizes organization‑level aggregated sinks with `includeChildren=True`.

Source: llm_adapter@2026-06-09

Confidence: high

β€”
Bugfix Medium

GCP `logging_log_metric_filter_and_alert_*` checks now recognize organization‑level aggregated sinks with `includeChildren=True`.

GCP `logging_log_metric_filter_and_alert_*` checks now recognize organization‑level aggregated sinks with `includeChildren=True`.

Source: llm_adapter@2026-06-09

Confidence: high

β€”
Bugfix Medium

Jira integration no longer fails with `400 INVALID_INPUT` when a finding has empty fields.

Jira integration no longer fails with `400 INVALID_INPUT` when a finding has empty fields.

Source: llm_adapter@2026-06-09

Confidence: high

β€”
Bugfix Medium

GCP `iam_service_account_unused` check now passes disabled service accounts instead of failing them.

GCP `iam_service_account_unused` check now passes disabled service accounts instead of failing them.

Source: llm_adapter@2026-06-09

Confidence: high

β€”
Full changelog

UI

🐞 Fixed

  • Finding drawer tabs now keep the active tab text and underline styling when tooltip state changes (#11493)

API

🐞 Fixed

  • API startup no longer crashes when Neo4j is unreachable, as the Neo4j driver now connects lazily on first use rather than during app initialization (#11491)

SDK

🐞 Fixed

  • GCP logging_sink_created now recognizes organization-level aggregated sinks with includeChildren=True, avoiding false failures for covered projects (#11355)
  • GCP logging_log_metric_filter_and_alert_* checks now recognize organization-level aggregated sinks with includeChildren=True, no longer false-failing projects covered by a central bucket-scoped metric + alert (#11488)
  • Jira integration no longer fails with 400 INVALID_INPUT when a finding has empty fields (#11474)
  • GCP iam_service_account_unused now passes disabled service accounts instead of failing them, since a disabled account cannot authenticate or be used (#11467)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Prowler

Get notified when new releases ship.

Sign up free

About Prowler

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

All releases β†’

Related context

Earlier breaking changes

  • v5.34.0 Renames UI integration enable flags to past tense (e.g., UI_SENTRY_ENABLE β†’ UI_SENTRY_ENABLED).

Beta — feedback welcome: [email protected]