Automated Security Helper
What this system does
ASH coordinates source, dependency, infrastructure, and agent-workflow security across developer environments.
Why it matters
Advanced ASH into workspace-scale security orchestration, then strengthened the execution beneath it with a pinned multi-language scanner environment, correctly scoped ignore rules, stable finding paths, and explicit failure semantics.
- Shipped workspace planning and per-project execution, with aggregate results that retain project identity and workspace-level policy controls.
- Confined MCP scan targets to configured roots through canonical, symlink-aware containment and per-session isolation.
- Built a public execute-and-collect architecture with scanner sharding and deployable AgentCore, Fargate, Lambda, and CodePipeline targets.
- Added a hash-pinned Nix mode that supplies ten scanners across Linux and macOS, x86-64 and ARM, without requiring adopters to build a container image.
- Closed false-confidence paths by applying nested ignore rules to the correct subtree, reporting their effect, and making secret-finding paths stable across Windows drives.
- Made all-target scanner failures observable as execution errors and migrated the cdk-nag integration to its real 3.x policy-validation API.
- ReleaseASH v3.7.0 · workspace mode shipped (opens in a new tab)
- PR#456 · complete workspace stack · merged to main (opens in a new tab)
- PR#462 · stacked project execution series (opens in a new tab)
- PR#478 · stacked reporting and policy series (opens in a new tab)
Additional sources · 14
- PR#477 · confined MCP targets · merged (opens in a new tab)
- Capability#493 · agent-driven workspace scans over MCP (opens in a new tab)
- Prototype#494 · distributed execution and deployable targets (opens in a new tab)
- PR#499 · Python package coverage depth · merged (opens in a new tab)
- Capability#500 · TypeScript CI with pinned scope (opens in a new tab)
- PR#501 · nested ignore semantics and exclusion reporting · merged (opens in a new tab)
- PR#502 · stable detect-secrets scan roots · merged (opens in a new tab)
- PR#508 · pinned Nix scanner mode · merged (opens in a new tab)
- Capability#514 · cdk-nag 3.x and per-target failure reporting (opens in a new tab)
- PR#515 · dependency upgrade lanes by risk · merged (opens in a new tab)
- PR#331 · integrations for 15 agent platforms · merged (opens in a new tab)
- PR#440 · external scan assurance · merged (opens in a new tab)
- DocsASH documentation (opens in a new tab)
- RepositoryUpstream source (opens in a new tab)
Contribution focus
Workspace orchestration, reproducible toolchains, and scan integrityContributor and public maintainer activity · 2024–2026awslabs / automated-security-helper repository (opens in a new tab)Workspace mode shipped in v3.7.0 · pinned Nix scanner execution merged- Claude Opus 4.7321 related commits
- Claude Opus 5303 related commits
- Claude 3 Opus9 related commits
- Claude Opus 41 related commit
Explore the technical source mapRepositories, changes, commits, and files713 public records
Public source · Public repositoryThe public source root that anchors this contribution lineage.
- Changes
- 9
- Commits
- 198
- File records
- 505