← Back to all sparks
P

Prowler

INFRA · APIS
Velocity6.3

Open-source cloud security assessment and compliance platform

Prowler is evolving from passive cloud scanner to AI-assisted remediation platform, with Lighthouse AI now delivering per-finding fix guidance.

cloud-securitycspmai-remediationcomplianceopen-source
Current state
Prowler ships open-source releases every one to two weeks, maintaining strong cadence across AWS, Azure, and GCP coverage. The commercial Cloud tier has become the innovation frontier — Lighthouse AI features arrive there first while the OSS core gets protocol and compliance work such as ISO partition support and configurable network timeouts. Weekly releases and a growing AI layer mark a product in active expansion.
Where it's heading
Lighthouse AI is the strategic bet: each release expands what the AI can do with a finding — first explanations, then contextual chat, now contextual fixes, triage verdicts, and systemic scope analysis. The product is moving toward AI-driven security posture management where human analysts confirm rather than investigate. The bifurcation between OSS platform coverage and Cloud AI features is deliberate and widening.
Prediction
The next move is likely AI-driven remediation automation — not just suggesting the fix but executing it with approval, using the Jira and Slack integrations already in place. The browser-based findings import also points toward a third-party data federation strategy.

Recent moves

  1. 3d ago

    Prowler 5.42.0

    ISO partition support removes a long-standing gap for GovCloud and air-gapped AWS deployments — teams running in aws-iso or similar partitions no longer need hand-edited region files. Configurable Boto3 timeouts fix hours-long scans on restricted networks by reducing the default connect timeout from 60s to 10s.

    View source ↗
  2. 12d ago

    Prowler 5.41.0

    Browser-based findings import lets teams ingest CLI or CI-produced OCSF reports into Prowler Cloud without leaving the UI, unifying findings from hybrid scan environments. The Jira integration extension builds on earlier finding group support, fitting the pattern of tightening the feedback loop between security findings and engineering workflows.

    View source ↗
  3. 17d ago

    Prowler 5.40.0

    Slack alert channel destinations bring Prowler's alerting into team communication workflows, a natural extension of the existing Jira integration. The Lighthouse AI Answer Feed begins surfacing AI-generated insights in a persistent feed, widening Lighthouse's footprint beyond on-demand queries.

    View source ↗
  4. 27d ago

    Prowler 5.39.1

    Dependency pinning and security container patches: zstd pinned to 1.5.7.2, Trivy updated to address CVE-2026-46600, and pyopenssl compatibility fixes that had blocked clean pip installs since 5.38.0. No user-visible capability changes.

    View source ↗
  5. 1mo ago

    Prowler 5.39.0

    ⚡ SPARK

    Lighthouse AI Finding Skills is the most substantive AI addition yet — moving from explaining findings to actively providing a contextual fix, a triage verdict, and a systemic scope check. Azure Management Group onboarding extends Cloud tier coverage to enterprise Azure hierarchies. Together these advance Prowler's push from passive scanner to active remediation assistant.

    View source ↗
  6. 1mo ago

    Prowler 5.38.0

    Compliance Watchlist gives teams a shared, pinned view of the frameworks they track, cutting through Prowler's growing compliance catalog. SAML SSO multi-domain support rounds out enterprise onboarding for organizations with multiple email domains — both are polish features that reduce friction for large-team rollouts.

    View source ↗