- The problem : why supply chain attacks (SolarWinds, xz-utils, dependency confusion) matter for AWS workloads specifically, not just on-prem
- Mapping the chain : source → build → artifact → registry → deploy → runtime, and where AWS gives you native controls at each stage
- SBOM generation : CodeGuru / native tooling + open-source generators (Syft), where to store SBOMs (ECR, S3, artifact metadata)
For further actions, you may consider blocking this person and/or reporting abuse
Top comments (0)