AWS Open Source Security

Committed to raising standards for the broader community

Overview

At AWS, security is our top priority. We work hard to make AWS the best place for customers to build and run open source software in the cloud. We are committed to raising the bar for open source security by developing key security-related technologies in collaboration with the community and by contributing code, resources, and talent to open source software.

We actively participate in open source foundations, trade associations, standard bodies, and regulatory organizations, with a goal of improving software supply chain security to benefit our customers and improve security posture across the industry.

Security frameworks and tools as open source

We work upstream and release security frameworks and tools as open source to improve security posture across the industry.

Shared learnings

We share AWS learnings and practices on consuming open source securely that you can leverage in your organization.

Powertools for AWS Lambda (Python)

Consider adopting Powertools for AWS Lambda (Python), a developer toolkit to implement serverless best practices and increase developer velocity.

Security Leadership

Learn about our approach to the Apache Log4j (Log4Shell) vulnerability and our guidance to help customers respond.

Security Practices

Learn more about the security practices we use via the GitHub repository, such as the recent security audit completed by the OpenSearch team at AWS.

Have Questions?

Connect with AWS Support
Contact Us »

Exploring security roles?
Apply today »

Want AWS Security updates?
Follow us on X »