Bumps the go-dependencies group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | codeberg.org/miekg/dns | `0.6.79` | `0.6.81` | | [github.com/anthropics/anthropic-sdk-go](https://github.com/anthropics/anthropic-sdk-go) | `1.45.0` | `1.48.0` | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.41.7` | `1.41.12` | | [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.14` | `1.32.23` | | [github.com/aws/aws-sdk-go-v2/service/bedrockruntime](https://github.com/aws/aws-sdk-go-v2) | `1.52.0` | `1.53.4` | | [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.101.0` | `1.103.2` | | [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) | `5.9.2` | `5.10.0` | | [github.com/sigstore/sigstore-go](https://github.com/sigstore/sigstore-go) | `1.1.4` | `1.2.0` | | [go.gearno.de/kit](https://github.com/gearnode/kit) | `0.10.0` | `0.11.0` | | [golang.org/x/sync](https://github.com/golang/sync) | `0.20.0` | `0.21.0` | | [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.280.0` | `0.283.0` | Updates `codeberg.org/miekg/dns` from 0.6.79 to 0.6.81 Updates `github.com/anthropics/anthropic-sdk-go` from 1.45.0 to 1.48.0 - [Release notes](https://github.com/anthropics/anthropic-sdk-go/releases) - [Changelog](https://github.com/anthropics/anthropic-sdk-go/blob/main/CHANGELOG.md) - [Commits](https://github.com/anthropics/anthropic-sdk-go/compare/v1.45.0...v1.48.0) Updates `github.com/aws/aws-sdk-go-v2` from 1.41.7 to 1.41.12 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.41.7...v1.41.12) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.14 to 1.32.23 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.14...config/v1.32.23) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.17 to 1.19.22 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.19.17...credentials/v1.19.22) Updates `github.com/aws/aws-sdk-go-v2/service/bedrockruntime` from 1.52.0 to 1.53.4 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.52.0...service/iot/v1.53.4) Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.101.0 to 1.103.2 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.101.0...service/s3/v1.103.2) Updates `github.com/jackc/pgx/v5` from 5.9.2 to 5.10.0 - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](https://github.com/jackc/pgx/compare/v5.9.2...v5.10.0) Updates `github.com/sigstore/sigstore-go` from 1.1.4 to 1.2.0 - [Release notes](https://github.com/sigstore/sigstore-go/releases) - [Commits](https://github.com/sigstore/sigstore-go/compare/v1.1.4...v1.2.0) Updates `go.gearno.de/kit` from 0.10.0 to 0.11.0 - [Changelog](https://github.com/gearnode/kit/blob/master/CHANGELOG.md) - [Commits](https://github.com/gearnode/kit/compare/v0.10.0...v0.11.0) Updates `go.opentelemetry.io/otel` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.43.0...v1.44.0) Updates `go.opentelemetry.io/otel/trace` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.43.0...v1.44.0) Updates `golang.org/x/sync` from 0.20.0 to 0.21.0 - [Commits](https://github.com/golang/sync/compare/v0.20.0...v0.21.0) Updates `google.golang.org/api` from 0.280.0 to 0.283.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.280.0...v0.283.0) Updates `github.com/aws/smithy-go` from 1.25.1 to 1.27.1 - [Release notes](https://github.com/aws/smithy-go/releases) - [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md) - [Commits](https://github.com/aws/smithy-go/compare/v1.25.1...v1.27.1) Updates `go.opentelemetry.io/otel/sdk` from 1.43.0 to 1.44.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.43.0...v1.44.0) --- updated-dependencies: - dependency-name: codeberg.org/miekg/dns dependency-version: 0.6.81 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/anthropics/anthropic-sdk-go dependency-version: 1.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-version: 1.41.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/config dependency-version: 1.32.23 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/credentials dependency-version: 1.19.22 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/service/bedrockruntime dependency-version: 1.53.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.103.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/sigstore/sigstore-go dependency-version: 1.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.gearno.de/kit dependency-version: 0.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/trace dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/sync dependency-version: 0.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: google.golang.org/api dependency-version: 0.283.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/aws/smithy-go dependency-version: 1.27.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: go.opentelemetry.io/otel/sdk dependency-version: 1.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Probo
Open-source GRC platform for engineers.
Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. It covers the full GRC lifecycle: risk identification, control tracking, vendor risk, data privacy, access reviews, audit programs, and document approval workflows. Every entity is accessible through a web console, a CLI, a Model Context Protocol (MCP) API, and a GraphQL API, so you can automate compliance work from code, scripts, or any LLM agent.
Why Probo?
- AI-native by design. 270+ MCP tools expose every entity and operation. Any MCP-compatible LLM agent can read and write your GRC data, draft policies, run risk assessments, and generate evidence packs.
- Full GRC coverage. Risk management, controls, vendor risk, data privacy (DPIA/TIA), access reviews, audit programs.
- Multiple interfaces. Web console,
prbCLI (44+ command groups), MCP API, GraphQL, and an n8n community node for no-code automation. - Open source and self-hostable. ISC licensed. Run it on your own infrastructure with Docker.
- Audit-ready. Policy-based RBAC, immutable audit logs, electronic document sign-off workflows, and evidence chains.
Capabilities
| Domain | Features |
|---|---|
| Risk Management | Risk register, inherent/residual scoring, treatment strategies (mitigate, accept, avoid, transfer), threat-based risk assessments |
| Controls & Frameworks | Control library with maturity levels, custom framework import/export, Statement of Applicability (SoA) |
| Vendor / Third-Party Risk | Vendor inventory, automated website risk assessment, DPA/BAA tracking, subprocessor discovery |
| Data Privacy | DPIA, Transfer Impact Assessments, processing activity records, data inventory, rights requests (SAR/erasure) |
| Access Reviews | Campaign management, per-entry access decisions, integration with SaaS, cloud infra, and source code sources |
| Audit Programs | Audit scoping, control mapping, finding tracking, report generation |
| Evidence & Measures | Evidence collection (files and URLs), implementation state tracking, task assignment |
| Document Management | Versioned documents, approval quorums, electronic signatures, PDF export, bulk operations |
| Compliance Page | Public compliance portal, NDA management, certification publishing, custom domain support |
| Cookie & Consent | Cookie banner management, tracker detection, consent records |
Interfaces
Web console
The primary interface for day-to-day GRC work. Runs at http://localhost:8080 in development.
CLI (prb)
A fully-featured command-line client for scripting, automation, and CI/CD integration. Covers all 44+ resource types available in the web console.
# Authenticate
prb auth login
# List open risks
prb risk list
# Create a measure and link evidence
prb measure create --name "MFA enforced on all production systems"
prb evidence create --measure <id> --file screenshot.png
# Manage vendor compliance
prb thirdpartymgmt vendor list
prb thirdpartymgmt risk-assessment create --vendor <id>
Run prb help for the full command reference.
MCP API
Probo exposes 270+ MCP tools covering every entity and operation in the platform. Any MCP-compatible LLM agent (Claude, Cursor, Continue, and others) can connect directly and interact with your compliance data.
The full MCP specification is at pkg/server/api/mcp/v1/specification.yaml.
n8n node
The @probo/n8n-nodes-probo community node brings Probo into n8n workflows for no-code automation of compliance tasks over the GraphQL API.
Quick Start
Prerequisites
| Tool | Version |
|---|---|
| Go | 1.26+ |
| Node.js | 22+ |
| Docker | latest |
| mkcert | latest |
Steps
# 1. Clone with submodules
git clone --recurse-submodules https://github.com/getprobo/probo.git
cd probo
# 2. Install dependencies
go mod download
npm ci
# 3. Start infrastructure services (PostgreSQL, object storage, etc.)
make stack-up
# 4. Build
make build
# 5. Generate the local dev config
make dev-config
# 6. Run the server
bin/probod -cfg-file cfg/dev.yaml
The web console is available at http://localhost:8080.
See CONTRIBUTING.md for the full development environment walkthrough, including the frontend dev server and code generation steps.
Tech Stack
| Layer | Technologies |
|---|---|
| Backend | Go, PostgreSQL |
| API | GraphQL, MCP |
| Frontend | React, TypeScript, Relay, TailwindCSS |
| Infrastructure | Docker, GitHub Actions |
| Observability | OpenTelemetry, Grafana, Prometheus, Loki, Tempo |
Contributing
Contributions are welcome. Read CONTRIBUTING.md before opening a pull request. All commits require a Developer Certificate of Origin (DCO) sign-off (git commit -s). No CLA required.
To report a security vulnerability, email security@probo.com rather than opening a public issue. See SECURITY.md for the full disclosure policy.
Community
- Discord - Get help, share feedback, and talk to the team
- Documentation
- Blog
- Twitter / X
- Website
License
Probo is ISC licensed.