chore(actions): add pr-check-compliance-mapping action#10526
Merged
Conversation
Contributor
|
✅ All necessary |
Contributor
|
✅ Conflict Markers Resolved All conflict markers have been successfully resolved in this pull request. |
cesararroba
approved these changes
Mar 31, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
pr-check-compliance-mapping.yml) that detects when a PR introduces new checks and verifies whether they have been mapped to compliance framework requirements within the same PRneeds-compliance-reviewlabel when new checks are not referenced in any modified compliance JSONno-compliance-checklabelWhy
When a new check is added to Prowler, it should be evaluated for inclusion in one or more compliance framework requirements (e.g., CIS, ISO 27001, MITRE ATT&CK). Each compliance JSON in
prowler/compliance/<provider>/contains aChecksarray per requirement that maps checks to framework controls. Without an automated reminder, new checks can be merged without compliance mappings, leaving frameworks incomplete.How it works
.metadata.jsonfiles underprowler/providers/**/services/**/(indicates a new check)CheckIDfrom each metadata file and the provider from the file pathneeds-compliance-reviewlabel accordinglyThis action is non-blocking — it alerts but does not prevent merging.
Steps to review
Please add a detailed description of how to review this PR.
Checklist
Community Checklist
SDK/CLI
UI
API
License
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.