shiichan

AWS Security Hub Extended adds supply chain security as its 10th category!

Hi, I'm Shii-chan! Today's news touches something every developer relies on daily: open-source libraries. Let's dive in!

AWS What's New aws.amazon.com

What was announced?

According to AWS's What's New, AWS Security Hub Extended now includes Supply Chain Security as its 10th security category. The two new curated partners are Chainguard and Socket.

This means you can now detect and block malicious dependencies before they're built into your applications. Activation follows the same streamlined process as every other Extended category, with the same pay-as-you-go pricing.

Why it matters

Developers now adopt open-source libraries at scale as a matter of course. But that scale makes it harder for security teams to verify that every package entering their environment is actually trustworthy and free of malicious code.

Supply chain attacks — where malicious code is smuggled in disguised as a legitimate package or library — are especially hard to catch once they've already made it deep into your build. That's exactly why catching them at the dependency stage, before they're built in, matters so much.

What changes

Security teams can now bring Chainguard's and Socket's detection capabilities directly into Security Hub Extended. Activation works the same way as other categories, and billing stays consolidated under your existing AWS bill, so there's no new vendor contract or separate invoice to manage.

Security Hub Extended is a plan that lets you cover areas like endpoint, identity, email, network, data, browser, cloud, AI, and security operations by combining curated partner solutions. Adding supply chain to that list means security teams now have broader coverage across the areas they need to watch.

Dive Deep

Here are the concrete details from the announcement:

  • New category: Supply Chain Security (the 10th category in Security Hub Extended)
  • New partners: Chainguard, Socket
  • Total partner count: with this addition, the Extended plan now includes 23 curated partner solutions in total
  • Finding format: findings from all partner solutions are emitted in the Open Cybersecurity Schema Framework (OCSF) and automatically aggregated in AWS Security Hub
  • Pricing and commitment: same pay-as-you-go pricing as other Extended categories, with no required long-term commitments, and everything appears on a single AWS bill
  • Availability: available today in all AWS Commercial Regions where Security Hub is available

AWS says it plans to keep expanding the Extended plan based on customer feedback, so it'll be interesting to see which category comes next.

Wrap-up

  • AWS Security Hub Extended adds Supply Chain Security as its 10th category
  • New curated partners: Chainguard and Socket
  • Detects and blocks malicious open-source dependencies before they're built into applications
  • Findings are unified in OCSF and automatically aggregated into Security Hub
  • Total curated partners now at 23, still under a single bill with pay-as-you-go pricing and no long-term commitment
  • Available today across AWS Commercial Regions

This update is especially relevant if you're a security team wrestling with open-source dependency risk, or an engineer already using Security Hub!