awslabs / awslabs/backstage-plugins-for-aws

feature: Security Hub plugin

Open
#2 0 comments 2 reactions 0 assignees View on GitHub
enhancement
Dominant language
TypeScript
Stars
159
Forks
48
Avg merge
3h 54m
Merged PRs (30d)
5

Description

### 🔖 Feature description

AWS Security Hub provides you with a comprehensive view of your security state in AWS and helps you assess your AWS environment against security industry standards and best practices. There should be a plugin that provides the ability to view AWS Security Hub findings related to specific entities. This should be designed to display as an additional tab on the entity page (similar to CI/CD).

Information provided should consist of:
1. Table of findings
2. Potentially some aggregations by dimensions such as severity, AWS account, region

Screenshot of prototype:

![security-hub-plugin](https://github.com/awslabs/backstage-plugins-for-aws/assets/808369/0717be3a-e07f-438a-96da-dae04e77415f)

### 🎤 Context

This would provide functionality similar to other security plugins such as:

https://github.com/deepan10/backstage-plugin-blackduck
https://github.com/snyk-tech-services/backstage-plugin-snyk

### ✌️ Possible Implementation

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's existing Backstage plugins and the linked Black Duck and Snyk plugin examples, then examine AWS Security Hub findings and entity-page integration. Done means an additional entity-page tab can display a findings table and, if supported by the design, aggregations by severity, AWS account, and region.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.