AWS Security ChangesHomeSearch

AWS linux: AL2027 adds supply chain protection (dependency cooldowns) for npm/pip

Service: linux · 2026-09-27 · Documentation medium

File: linux/al2027/ug/security-features.md · Type: supply-chain

Summary

Adds a new section documenting default dependency cooldown configurations for npm (min-release-age=1 in /etc/npmrc) and pip (uploaded-prior-to=P1D in /etc/pip.conf) that delay installation of recently published packages, plus a compile-time hardening link and SELinux wording tweak.

Security assessment

Documents a new default hardening feature that mitigates supply-chain attacks (malicious/compromised packages) by delaying installs of newly published npm/pip packages; it is security best-practice documentation rather than a fix for a specific vulnerability.

Evidence

AL2027 ships default configurations, known as dependency cooldowns, that delay the installation of recently published packages through _npm_ and _pip_. Dependency cooldowns give the security community time to detect and remove malicious packages before they reach your systems.

Diff

diff --git a/linux/al2027/ug/security-features.md b/linux/al2027/ug/security-features.md
index 4ac9a9d0a..36ff992d2 100644
--- a//linux/al2027/ug/security-features.md
+++ b//linux/al2027/ug/security-features.md
@@ -7 +7 @@
-SELinux enforcing by defaultPost-Quantum Cryptography (PQC) by DefaultSSH server defaultManage updatesSecurity in the cloud
+SELinux enforcing by defaultPost-Quantum Cryptography (PQC) by DefaultSSH server defaultSupply chain protection for package managersManage updatesSecurity in the cloud
@@ -15 +15 @@ AL2027 is currently available for preview. It is intended for evaluation and tes
-AL2027 includes several security enhancements over AL2023
+AL2027 includes several security enhancements over AL2023. For the compile-time hardening flags applied to all packages, see [Compile-time hardening](./compile-time-hardening.html).
@@ -24,0 +25,2 @@ AL2027 includes several security enhancements over AL2023
+  * Supply chain protection for package managers
+
@@ -36 +38 @@ The SELinux mandatory access control policies define permissions for users, proc
-By default, SELinux is enabled and set to `enforcing` mode in AL2027. This means that SELinux security policy is fully enforced, in contrast with permissive mode (default in AL2023) where permission denials are logged but not enforced.
+By default, SELinux is enabled and set to `enforcing` mode in AL2027. This is in contrast with `permissive` mode (default in AL2023) where permission denials are logged but not enforced.
@@ -73,0 +76,13 @@ For more information, see [Default SSH server configuration](./ssh-config.html).
+## Supply chain protection for package managers
+
+AL2027 ships default configurations, known as dependency cooldowns, that delay the installation of recently published packages through _npm_ and _pip_. Dependency cooldowns give the security community time to detect and remove malicious packages before they reach your systems.
+
+  * **npm** : `min-release-age=1` is set in the system-wide npm configuration file `/etc/npmrc`, so `npm install` skips package versions published less than one day ago. To override, use `--min-release-age=0` or set the option in a project-level `.npmrc`. For details, see [Security best practices](./nodejs-security.html).
+
+  * **pip** : `uploaded-prior-to = P1D` is set in `/etc/pip.conf`, so `pip install` skips package versions published less than one day ago. To override, use `--uploaded-prior-to=P0D` or edit `/etc/pip.conf` directly.
+
+
+
+
+For more information, see [Secure your npm and pip package updates in Amazon Linux](https://aws.amazon.com/blogs/security/secure-your-npm-and-pip-package-updates-in-amazon-linux/) on the AWS Security Blog.
+
@@ -90 +105 @@ SELinux
-Networking service
+Compile-time hardening