Improve the security of your software supply chain with Amazon CodeArtifact package group configuration
AWS News Blog
The article discusses the new package group configuration capability in AWS CodeArtifact, a fully managed package repository service. This feature allows administrators to manage configuration for multiple packages in one place.
Specifically, the article covers:
- The importance of controlling how packages are updated in software supply chains to prevent supply chain attacks like typosquatting and dependency confusion.
- How CodeArtifact previously allowed configuring package origin controls only on a per-package basis, and the new package group configuration allows managing groups of packages using a pattern-based approach.
- A step-by-step example of how an administrator can create a package group for the Python boto3 package, allowing updates only from an internal upstream repository and blocking updates from external repositories and internal publishing.
- How package groups can help prevent dependency substitution attacks by blocking external packages that match a certain naming pattern.
- The availability of package groups across all AWS regions where CodeArtifact is available, at no additional cost.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 28
2024
2024
Securing Your Software Supply Chain with Amazon CodeCatalyst and Amazon Inspector
Jun 20
2024
2024
AWS CodeArtifact now supports Cargo, the Rust package manager
Jun 20
2024
2024
AWS CodeArtifact adds support for Rust packages with Cargo
Aug 23
2024
2024
Publish packages to AWS CodeArtifact using Amazon CodeCatalyst Actions
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.