Skip to content

Prowler

v5.30.1 Bugfix

This release fixes issues for SREs watching stability and regressions.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

aws azure cis-benchmark cloud cloudsecurity compliance
+12 more
cspm security forensics gcp gdpr hardening iam multi-cloud python security-audit security-hardening security-tools

Summary

AI summary

Updates 🐞 Fixed, https://github.com/prowler-cloud/prowler/pull/11546, and UI across a mixed release.

Changes in this release

Bugfix Medium

Threat Map no longer shows an empty map for accounts with only Okta or Google Workspace scans.

Threat Map no longer shows an empty map for accounts with only Okta or Google Workspace scans.

Source: llm_adapter@2026-06-12

Confidence: high

Bugfix Medium

Compliance attributes requests now pass the selected scan, loading correct check IDs and findings for multi-provider frameworks.

Compliance attributes requests now pass the selected scan, loading correct check IDs and findings for multi-provider frameworks.

Source: llm_adapter@2026-06-12

Confidence: high

Bugfix Medium

Attack Paths `drop_subgraph` now deletes relationships before nodes, reducing memory usage on Neo4j for dense provider graphs.

Attack Paths `drop_subgraph` now deletes relationships before nodes, reducing memory usage on Neo4j for dense provider graphs.

Source: llm_adapter@2026-06-12

Confidence: high

Bugfix Medium

OCI scans now use API key credentials with the configured region instead of falling back to `~/.oci/config`.

OCI scans now use API key credentials with the configured region instead of falling back to `~/.oci/config`.

Source: llm_adapter@2026-06-12

Confidence: high

Full changelog

UI

🐞 Fixed

  • Threat Map no longer shows an empty map for accounts that only have Okta or Google Workspace scans (#11542)
  • Compliance attributes requests now pass the selected scan, so multi-provider universal frameworks (e.g. CSA CCM) load the check IDs of the scan's provider and Azure/GCP requirement details show their findings instead of appearing empty (#11546)

API

🐞 Fixed

  • compliance-overviews/attributes now resolves the provider from the scan, so multi-provider universal frameworks (e.g. CSA CCM) return the check IDs of the scan's provider and Azure/GCP requirement details show their findings instead of appearing empty (#11546)
  • Attack Paths: drop_subgraph now deletes relationships first and then nodes in batches, using less memory on Neo4j when clearing a dense provider graph (#11557)
  • OCI scans now use API key credentials with the configured region instead of falling back to /home/prowler/.oci/config (#11558)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Prowler

Get notified when new releases ship.

Sign up free

About Prowler

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

All releases →

Related context

Earlier breaking changes

  • v5.34.0 Renames UI integration enable flags to past tense (e.g., UI_SENTRY_ENABLE → UI_SENTRY_ENABLED).

Beta — feedback welcome: [email protected]