AWS Security ChangesHomeSearch

AWS linux: AL2027 enables npm/pip dependency cooldowns by default

Service: linux · 2026-09-27 · Documentation medium

File: linux/al2027/ug/compare-with-al2023.md · Type: supply-chain

Summary

Documents that AL2027 turns on dependency cooldowns for npm and pip by default, delaying installation of recently published packages to allow detection of malicious packages, and links to supply chain protection docs.

Security assessment

Describes a default-on supply chain protection (dependency cooldown) that mitigates malicious/compromised package publication; it is security best-practice documentation with config impact, not a fix for a specific disclosed vulnerability.

Evidence

+AL2027 turns on dependency cooldowns for _npm_ and _pip_ by default. Dependency cooldowns delay the installation of recently published packages, giving the security community time to detect and remove malicious packages before they reach your systems. The cooldowns were available in AL2023 (npm since release 2023.11, pip since 2023.12) but required manual configuration. For more information, see [Supply chain protection for package managers](./security-features.html#supply-chain-protection).

Diff

diff --git a/linux/al2027/ug/compare-with-al2023.md b/linux/al2027/ug/compare-with-al2023.md
index c38d6a2d4..e368cf067 100644
--- a//linux/al2027/ug/compare-with-al2023.md
+++ b//linux/al2027/ug/compare-with-al2023.md
@@ -39,0 +40,2 @@ LLVM 22 is built from a single unified SRPM. The separate `clang`, `lld`, and `l
+AL2027 turns on dependency cooldowns for _npm_ and _pip_ by default. Dependency cooldowns delay the installation of recently published packages, giving the security community time to detect and remove malicious packages before they reach your systems. The cooldowns were available in AL2023 (npm since release 2023.11, pip since 2023.12) but required manual configuration. For more information, see [Supply chain protection for package managers](./security-features.html#supply-chain-protection).
+