Well-architected best practices for software supply chain security | Amazon Web Services

General News

Summary

AWS outlines Well-Architected best practices to harden the software supply chain after recent npm attacks like Shai-Hulud and Chalk/Debug. The post recommends defense-in-depth controls for both maintainers and consumers, including temporary credentials, least privilege, MFA, and multi-approval workflows. It promotes artifact signing (AWS Signer and Amazon ECR managed signing), centralized dependency management (AWS CodeArtifact), continuous scanning with Amazon Inspector, provenance attestations, SBOMs, and centralized logging with GuardDuty and CloudTrail. These measures aim to reduce credential sprawl, detect malicious or sleeper packages earlier, and limit blast radius across developer environments and CI/CD pipelines.

Classifications

industries
Entertainment
applications
Audit

AskAI Classifications

Labels
SaaS Shipping Software Inventory Management Software

Linked Companies

Amazon
$1B+
Npmjs
$1M to $5M
Kiro
n/a