Chainguard has launched the Chainguard Libraries service via AWS Security Hub Extended as a partner in the new Supply Chain category, thereby allowing AWS customers to bolster software supply chain security through the use of malware-free, secure-by-default replacement packages for any public open source dependencies. This will allow companies to avoid getting compromised open source packages into their development, CI/CD, and production environments in light of the rising threat posed by more and more sophisticated malware that utilizes artificial intelligence. Unlike most scanning tools, which only find out about threats after the malicious packages have been distributed, Chainguard rebuilds open source packages from trusted source code in an isolated environment called the Chainguard Factory.
Also Read: BorgWarner Expands High-Voltage Inverter Program with Major European Automaker
Through AWS Security Hub Extended, customers can purchase Chainguard Libraries using existing AWS contracts, consolidate billing, access centralized security findings using the Open Cybersecurity Schema Framework (OCSF), and receive unified Level 1 support for Enterprise Support plans. The integration is designed to reduce procurement complexity while improving visibility and protection against software supply chain threats without disrupting developer productivity. “Open source is the foundation the world’s software is built on. When that ecosystem gets compromised, the blast radius is enormous,” said Patrick Donahue, Senior Vice President of Product, Chainguard. “AWS adding us as a partner for supply chain security with the Extended plan is a real signal that the industry is treating this problem with the seriousness it deserves. Chainguard delivers that protection to customers with open source that’s trustworthy by default.”



