HomeReleasesChainguard Partners with AWS to Secure Open Source Supply Ch
Releases

Chainguard Partners with AWS to Secure Open Source Supply Chains

With more than 98% of malware arriving as pre-built packages lacking verified source code, the window for detection is often too narrow. Chainguard is now integrating its malware-free library catalog directly into AWS Security Hub Extended, shifting the industry standard from reactive scanning to proactive prevention of compromised dependencies.

Chainguard Partners with AWS to Secure Open Source Supply Chains

The partnership allows AWS customers to replace public open-source dependencies with hardened alternatives rebuilt within Chainguard’s isolated build environment. By utilizing the company's SLSA Level 3 verified build process, organizations can intercept malicious code before it reaches development pipelines or production systems. This integration addresses the escalating threat of AI-assisted attacks, which frequently exploit the trust inherent in public repositories like PyPI, Maven Central, and npm.

Beyond technical security, the collaboration streamlines procurement by allowing organizations to purchase Chainguard Libraries directly through existing AWS contracts. Users benefit from consolidated billing and centralized security findings formatted via the Open Cybersecurity Schema Framework. Patrick Donahue, Senior Vice President of Product at Chainguard, noted that this inclusion signals a shift toward treating supply chain integrity as a foundational requirement rather than an afterthought. Customers can now access these tools through the AWS Security Hub console to begin replacing vulnerable dependencies with signed, provenance-backed artifacts.

Comments (0)

Leave a comment

No comments yet. Be the first!