security-vulnerabilities

1 posts

aws

Proactively reduce tech debt autonomously with AWS Transform – continuous modernization (preview) | Amazon Web Services (opens in new tab)

AWS is previewing AWS Transform – continuous modernization, a capability designed to continuously detect, prioritize, and remediate technical debt across thousands of repositories. It replaces fragmented, manual tooling with configurable analysis, automated pull requests, and current compliance visibility. The goal is to help engineering and platform teams keep codebases modern as dependencies, frameworks, runtimes, and security requirements evolve. ## Continuous Technical Debt Analysis - Scans connected repositories against configurable organizational baselines. - Produces findings within hours, including: - End-of-life dependencies - Deprecated frameworks - Security and code-quality issues - Organization-specific technical debt patterns - Teams can define custom policies for approved libraries, internal standards, deprecated components, or preferred coding patterns. - Findings provide a current view of which repositories are behind baseline, by how much, and which files or components are affected. - This reduces reliance on manual status reports and periodic compliance checks. ## Autonomous Remediation - AWS Transform can automatically generate pull requests for affected repositories. - Built-in transformations support common tasks such as: - Java version upgrades - SDK migrations - Library updates - Custom transformations can be created for organization-specific modernization needs. - Teams retain control by reviewing and merging the generated pull requests or applying their own fixes. - Continuous analysis verifies when repositories return to compliance without requiring manual confirmation. ## Integrated Security Remediation - Integration with AWS Security Agent brings source-code security vulnerabilities into the same workflow. - Security findings appear alongside other technical debt in a prioritized list. - Remediation is delivered through pull requests rather than separate, disconnected security processes. ## Dashboard and Remediation Campaigns - The AWS Transform web application provides portfolio-level visibility across repositories. - Users can view finding severity, affected files, categories, repositories, and available remediation options. - Remediation campaigns track: - Pull requests created - Pull requests merged - Repositories restored to compliance - AWS Transform supports repositories connected from GitHub and local environments. ## Continuous Mode and Campaign Mode - **Continuous mode** handles recurring maintenance: - Dependency upgrades - Security patches - Runtime updates - Coding-standard enforcement - **Campaign mode** is intended for larger, project-based changes, such as migrating frameworks or upgrading a major runtime across hundreds of applications. - AWS Transform custom remains the flexible option for substantial modernization projects, while continuous modernization focuses on high-volume, ongoing maintenance. AWS Transform – continuous modernization is available in preview through the AWS Transform web application, AWS Transform Kiro Power, MCP, and skills for coding-agent integration. It is most useful for organizations that need automated, organization-wide visibility and pull-request-based remediation for continuously accumulating technical debt.