Home icon

Beyond compute: Shifting vulnerability detection left with Amazon Inspector code security capabilities

Security Blog



AWS has expanded Amazon Inspector's capabilities to provide comprehensive code security analysis, introducing three new features to help detect vulnerabilities earlier in the software development lifecycle:

  • Static Application Security Testing (SAST) to analyze source code for potential vulnerabilities
  • Software Composition Analysis (SCA) to identify risks in software dependencies
  • Infrastructure as Code (IaC) scanning to detect security misconfigurations in infrastructure templates

Key benefits include:

  • Native integration with GitHub and GitLab
  • Supports multiple programming languages and environments
  • Customizable scan configurations (on-demand, scheduled, change-based)
  • Provides code fix recommendations directly in pull requests
  • Unified dashboard for tracking vulnerabilities across repositories

The new capabilities aim to help security and development teams collaborate more effectively, reducing security risks and remediation costs throughout the software development process.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 17
2025
Amazon Inspector launches code security to shift security left in development
Feb 14
2025
Amazon Inspector enhances the security engine for container images scanning
Mar 18
2026
Amazon Inspector expands agentless EC2 scanning and introduces Windows KB-based findings
Sep 30
2024
Amazon Inspector enhances engine for Lambda standard scanning

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.