IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Chainguard joins AWS Security Hub for supply chain

Chainguard joins AWS Security Hub for supply chain

Wed, 5th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Chainguard has joined AWS Security Hub Extended as a supply chain partner, giving AWS customers access to Chainguard Libraries through the service.

The integration places Chainguard in the new Supply Chain category within AWS Security Hub Extended, allowing customers to bring its package catalogue into existing AWS security workflows. Users can buy the offering through existing AWS contracts, with Enterprise Discount Program terms applied where relevant, and view findings alongside other security alerts in Security Hub.

The move comes as companies face growing concern over attacks targeting open-source software dependencies. These attacks can insert malicious code into widely used packages that developers pull into applications, creating a route into corporate systems before security teams detect a problem.

Chainguard says its Libraries product is designed to replace packages from public repositories such as PyPI, Maven Central, and npm with alternatives rebuilt from verified source code. Those packages are produced in its own build environment rather than taken directly from public registries.

Security Hub Extended is AWS's broader marketplace and operational framework for security tools that run inside its cloud environment. By joining the service, Chainguard becomes one of the suppliers customers can activate from within the AWS console rather than through a separate buying process.

Open-source risk

The backdrop is a wider shift in cybersecurity from detecting threats after software enters an organisation to blocking suspect components earlier in the development chain. Open-source software underpins much of modern application development, but public package repositories have become a target for attackers seeking scale.

Chainguard argues that conventional scanning tools can miss the window when a malicious package is first published and quickly downloaded into software builds. It says more than 98% of malware ships as a pre-built package with no matching source code, making early verification of provenance more important than later inspection alone.

Its approach is to supply versions of common language dependencies rebuilt from source and accompanied by signed provenance and software bills of materials. The packages available through the AWS integration are rebuilt in a SLSA Level 3 build environment, according to Chainguard.

The AWS arrangement also changes how customers pay for and support the product. Rather than setting up a separate vendor relationship, customers can purchase through AWS and consolidate the spend into one bill while still relying on Chainguard's expertise for the software itself.

For enterprise users, the service also brings unified Level 1 support from AWS for Enterprise Support customers. Security findings are centralised using the Open Cybersecurity Schema Framework, allowing data from Chainguard to sit alongside findings from AWS and other partners in a common structure.

Patrick Donahue, Senior Vice President of Product at Chainguard, addressed the significance of the partnership in the context of open-source risk.

"Open source is the foundation the world's software is built on. When that ecosystem gets compromised, the blast radius is enormous," Donahue said.

He also linked the AWS listing to broader recognition of supply chain security concerns.

"AWS adding us as a partner for supply chain security with the Extended plan is a real signal that the industry is treating this problem with the seriousness it deserves. Chainguard delivers that protection to customers with open source that's trustworthy by default," Donahue said.

Buying route

The commercial element may prove as important as the technical integration for some buyers. Procurement teams often slow adoption of new security tools because separate contracts, reviews, and billing arrangements add time and cost, particularly when development teams want to move quickly.

By appearing inside AWS Security Hub Extended, Chainguard gains access to organisations that prefer to buy third-party security products through a cloud provider they already use. The setup also lets customers apply AWS spending commitments and discount structures, which can make a new product easier to justify within existing budgets.

Chainguard is one of a growing number of security suppliers trying to address weaknesses in the software supply chain before code reaches production systems. Its customer list includes large technology and industrial groups, reflecting stronger demand for tools that monitor or replace open-source components used in commercial software.

Customers using AWS Security Hub Extended can subscribe to Chainguard Libraries through the Extended plan and configure it within their environments, with findings then surfaced centrally through Security Hub.