Solutions  ·  2026-07-31

AWS ships npm/pip dependency cooldown defaults for Amazon Linux to blunt supply-chain attacks

SolutionsMedium impactGlobal
AWS published (July 29, 2026) guidance and packaging support (Amazon Linux 2023, NodeJS 24/npm 11.10+, Python 3.14/pip 26.1+) for a one-line 'dependency cooldown' config that skips newly-published npm/PyPI package versions for 24 hours by default, citing that every recent major supply-chain incident (axios, Bitwarden CLI, TanStack, node-ipc) would have been blocked by this window.
A simple, low-friction default that directly mitigates the fast-moving package-poisoning campaigns (including AI-coding-agent-targeted worms like Miasma) increasingly hitting npm/PyPI, and is now baked into Amazon Linux defaults rather than left to individual teams.
Any team running Amazon Linux 2023 build/CI environments with npm or pip should adopt the cooldown default immediately; broadly relevant given AI coding agents' heavy dependency-installation activity.
AWS Security Blog
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →