News

A threat actor was able to exploit an inappropriately scoped GitHub token in the managed AWS CodeBuild development tool, and with that, commit malicious code into the extension's open source code ...
For example, you can use AWS CodeCommit, Amazon S3, or Amazon ECR to pull source code for your pipeline. You can use AWS CodeBuild to run builds and unit tests.