Securing Your Software Supply Chain with Amazon CodeCatalyst and Amazon Inspector
DevOps & Developer Productivity Blog
This article discusses how to secure your software supply chain by integrating DevSecOps practices into the development pipeline using Amazon CodeCatalyst and Amazon Inspector.
Specifically, the article covers:
- Introduction to Amazon CodeCatalyst and the benefits of DevSecOps
- Generating a software bill of materials (SBOM) using the Amazon Inspector Scan action in CodeCatalyst
- Scanning the SBOM for vulnerabilities using Amazon Inspector
- Step-by-step walkthrough of adding the Inspector Scan action to a CodeCatalyst workflow
- Viewing the SBOM and vulnerability report artifacts after running the workflow
- Cleanup instructions for deleting the deployed resources
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Mar 21
2024
2024
Improve the security of your software supply chain with Amazon CodeArtifact package group configuration
Jun 17
2025
2025
Amazon Inspector launches code security to shift security left in development
Jun 6
2024
2024
Amazon Inspector container image scanning is now available for Amazon CodeCatalyst and GitHub actions
May 26
2026
2026
Well-architected best practices for software supply chain security
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.