Well-architected best practices for software supply chain security
Security Blog
This article provides best practices for defending against software supply chain attacks like Shai-Hulud, aligned with AWS Well-Architected Framework security principles.
- Use temporary credentials and least privilege access to limit credential exposure risk
- Implement defense in depth with multi-factor authentication and approval workflows
- Use AWS Signer for artifact signing with FIPS 140-3 Level 3 HSM protection
- Centralize dependency management via AWS CodeArtifact with upstream source blocking
- Verify npm provenance attestations for open source package integrity
- Scan dependencies continuously throughout development lifecycle with Amazon Inspector
- Detect behavioral anomalies and zero-day malicious packages via cross-account signals
- Configure CloudTrail logging and GuardDuty monitoring for anomalous activity detection
- Use SBOMs to quickly assess exposure and prioritize remediation during incidents
In summary, layered defenses combining temporary credentials, artifact signing, centralized package management, and continuous scanning significantly reduce supply chain attack impact.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 28
2024
2024
Securing Your Software Supply Chain with Amazon CodeCatalyst and Amazon Inspector
Mar 21
2024
2024
Improve the security of your software supply chain with Amazon CodeArtifact package group configuration
Sep 11
2025
2025
Introducing the AWS Well-Architected Supply Chain Lens: Accelerating Digital Supply Chain Transformation
Apr 22
2025
2025
SecurityScorecard and AWS Fast Track Supply Chain Risk Management
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.