aws AWS Security Blog ·

AWS Security Hub Extended Adds Supply Chain Security Category

blogsecurityawsgaarchitectmedia
feature announcement

AWS Security Hub Extended now includes Supply Chain Security as its tenth category, integrating solutions from Chainguard and Socket. This addition addresses critical software supply chain risks highlighted by recent high-profile incidents, simplifying how enterprises acquire and manage protection for open-source dependencies. It allows customers to verify trusted components and block malicious packages at install time, with findings flowing into Security Hub via OCSF. The new category is available with pay-as-you-go pricing or private offers for existing AWS customers.

  • AWS Security Hub Extended adds Supply Chain Security category
  • Chainguard provides hardened open source dependencies
  • Socket blocks malicious packages at install time
  • Streamlined procurement and unified security findings
  • Future focus on cross-partner correlation and reduced friction
Features (1)
  • AWS Security Hub Extended adds Supply Chain Security category

    AWS Security Hub Extended now offers a Supply Chain Security category, addressing critical software supply chain risks with integrated solutions from partners Chainguard and Socket. This addition expands Security Hub Extended to 23 partners across 10 categories including endpoint, identity, and AI.

Enhancements (1)
  • Streamlined procurement and unified security findings

    All Security Hub Extended offerings feature pay-as-you-go pricing, a single bill, and optional private offers. Supply chain findings from partners integrate into Security Hub in OCSF for unified correlation and routing to existing downstream tools.

Notes (3)
  • Chainguard provides hardened open source dependencies

    Chainguard rebuilds open source dependencies from source using a verified build process, filtering unverified sources and ensuring malware-resistant, provenance-backed components for customer environments.

  • Socket blocks malicious packages at install time

    Socket analyzes the actual behavior of open source packages to block malicious dependencies during installation, identifying exploitable vulnerabilities via reachability analysis rather than relying solely on CVE databases.

  • Future focus on cross-partner correlation and reduced friction

    AWS plans to deepen integrations for Security Hub Extended, enabling cross-partner correlation to consolidate security signals and significantly reduce activation, deployment, and integration friction for customers.

Read the original announcement →

https://aws.amazon.com/blogs/security/security-hub-extended-adds-supply-chain-security-as-its-tenth-category/

Related releases