AWS linux: AL2027 adds supply chain protection (dependency cooldowns) for npm/pip
Summary
Adds a new section documenting default dependency cooldown configurations for npm (min-release-age=1 in /etc/npmrc) and pip (uploaded-prior-to=P1D in /etc/pip.conf) that delay installation of recently published packages, plus a compile-time hardening link and SELinux wording tweak.
Security assessment
Documents a new default hardening feature that mitigates supply-chain attacks (malicious/compromised packages) by delaying installs of newly published npm/pip packages; it is security best-practice documentation rather than a fix for a specific vulnerability.
Evidence
AL2027 ships default configurations, known as dependency cooldowns, that delay the installation of recently published packages through _npm_ and _pip_. Dependency cooldowns give the security community time to detect and remove malicious packages before they reach your systems.
Diff
diff --git a/linux/al2027/ug/security-features.md b/linux/al2027/ug/security-features.md index 4ac9a9d0a..36ff992d2 100644 --- a//linux/al2027/ug/security-features.md +++ b//linux/al2027/ug/security-features.md @@ -7 +7 @@ -SELinux enforcing by defaultPost-Quantum Cryptography (PQC) by DefaultSSH server defaultManage updatesSecurity in the cloud +SELinux enforcing by defaultPost-Quantum Cryptography (PQC) by DefaultSSH server defaultSupply chain protection for package managersManage updatesSecurity in the cloud @@ -15 +15 @@ AL2027 is currently available for preview. It is intended for evaluation and tes -AL2027 includes several security enhancements over AL2023 +AL2027 includes several security enhancements over AL2023. For the compile-time hardening flags applied to all packages, see [Compile-time hardening](./compile-time-hardening.html). @@ -24,0 +25,2 @@ AL2027 includes several security enhancements over AL2023 + * Supply chain protection for package managers + @@ -36 +38 @@ The SELinux mandatory access control policies define permissions for users, proc -By default, SELinux is enabled and set to `enforcing` mode in AL2027. This means that SELinux security policy is fully enforced, in contrast with permissive mode (default in AL2023) where permission denials are logged but not enforced. +By default, SELinux is enabled and set to `enforcing` mode in AL2027. This is in contrast with `permissive` mode (default in AL2023) where permission denials are logged but not enforced. @@ -73,0 +76,13 @@ For more information, see [Default SSH server configuration](./ssh-config.html). +## Supply chain protection for package managers + +AL2027 ships default configurations, known as dependency cooldowns, that delay the installation of recently published packages through _npm_ and _pip_. Dependency cooldowns give the security community time to detect and remove malicious packages before they reach your systems. + + * **npm** : `min-release-age=1` is set in the system-wide npm configuration file `/etc/npmrc`, so `npm install` skips package versions published less than one day ago. To override, use `--min-release-age=0` or set the option in a project-level `.npmrc`. For details, see [Security best practices](./nodejs-security.html). + + * **pip** : `uploaded-prior-to = P1D` is set in `/etc/pip.conf`, so `pip install` skips package versions published less than one day ago. To override, use `--uploaded-prior-to=P0D` or edit `/etc/pip.conf` directly. + + + + +For more information, see [Secure your npm and pip package updates in Amazon Linux](https://aws.amazon.com/blogs/security/secure-your-npm-and-pip-package-updates-in-amazon-linux/) on the AWS Security Blog. + @@ -90 +105 @@ SELinux -Networking service +Compile-time hardening