Chainguard Partners with AWS Security Hub Extended
In a significant development for software supply chain security, Chainguard has announced its partnership with AWS Security Hub Extended. This collaboration is aimed at enhancing the safety of open source dependencies—an area increasingly vulnerable to cyber threats. Chainguard Libraries, a part of this offering, allows AWS customers to access pre-verified, malware-free software packages, effectively mitigating potential risks associated with compromised open source components.
As the landscape of cyber threats continues to evolve, particularly with the rise of AI-assisted attacks, organizations must contend with the alarming frequency and sophistication of these intrusions. According to recent studies, a staggering 98% of malware is often shipped as pre-built packages without any corresponding source code. This means that a malicious version of a package can be unwittingly integrated into development environments within hours, leading to widespread damage before conventional scanning tools can even detect it.
Chainguard tackles this industry weakness by securing software dependencies before they enter a customer's environment. Instead of relying on packages from public repositories, organizations using Chainguard can use refined open source software rebuilt from verified sources in an isolated factory environment. This proactive method of protection minimizes the chance of malicious packages impacting development workflows and end systems.
Patrick Donahue, Senior Vice President of Product at Chainguard, highlighted the significance of the partnership. He remarked, "Open source is the foundation the world's software is built on. When that ecosystem gets compromised, the blast radius is enormous. AWS adding us as a partner for supply chain security is a real signal that the industry is treating this problem with the seriousness it deserves. Chainguard delivers that protection to customers with open source that's trustworthy by default."
Through AWS Security Hub Extended, users can conveniently purchase Chainguard Libraries without requiring a long-term commitment. The collaboration significantly simplifies the procurement process, allowing companies to consolidate their solution usage into a single bill while maintaining access to the expertise of various providers. Moreover, customers benefit from centralized security findings that are aligned with the Open Cybersecurity Schema Framework (OCSF), ensuring a coherent approach to security across the board.
One noteworthy feature of the Chainguard Libraries is their potential to enhance developer productivity while simultaneously improving software supply chain security. All packages are meticulously rebuilt in a SLSA Level 3 build environment, accompanied by signed provenance and Software Bill of Materials (SBOM), ensuring that each component that enters a developer's toolkit has been thoroughly vetted for safety.
For individuals interested in leveraging Chainguard Libraries, the onboarding process through AWS Security Hub is straightforward. Users can log into their AWS console, select the Extended plan, and follow the guided experience to configure Chainguard Libraries seamlessly within their existing environments.
In summary, Chainguard's partnership with AWS Security Hub Extended represents a pivotal step in safeguarding the software supply chain. By prioritizing proactive measures in open source security, organizations can not only enhance their defenses against cyber threats but also maintain high productivity levels in their development teams. The move strengthens Chainguard's position as a valued ally in the ongoing fight for secure software development, earning it recognition among notable clients including Fortune 500 companies and industry leaders.
For further details on Chainguard Libraries, visit
chainguard.dev/libraries.