AWS Certified DevOps Engineer – ProfessionalSDLC AutomationHard

A development team is using AWS CodePipeline for their CI/CD workflow. They need to ensure that their application's dependencies (e.g., npm packages, Maven artifacts) are automatically kept up-to-date with the latest security patches and minor version releases without manual intervention. This process should also trigger a new pipeline execution to validate the updated dependencies. Which approach should they use?

  1. AConfigure AWS Systems Manager Automation to periodically update dependency versions in the source code.
  2. BUse a dedicated tool or custom script, triggered by a scheduled Amazon EventBridge rule, to update dependency manifests and commit changes to CodeCommit.
  3. CSet up a daily CodeBuild job to manually update dependency versions in the buildspec.yml.
  4. DManually monitor dependency vulnerabilities and update them only when critical patches are released.
Show answer & explanation

Correct answer: B. Use a dedicated tool or custom script, triggered by a scheduled Amazon EventBridge rule, to update dependency manifests and commit changes to CodeCommit.

A dedicated tool or custom script, triggered by a scheduled EventBridge rule, can automate the process of checking for new dependency versions/patches, updating manifest files (e.g., package.json, pom.xml), committing these changes back to CodeCommit, and thereby triggering a new pipeline execution. This provides a fully automated and auditable process.

Why the other options are wrong

  • A. Systems Manager Automation is more suited for operational tasks on instances, not for programmatically updating source code dependency manifests and committing them to a Git repository to trigger a CI/CD pipeline.
  • C. Manually updating dependency versions, even if automated by a CodeBuild job, is not ideal as it still requires explicit version changes in `buildspec.yml` rather than managing the dependency manifest itself.
  • D. Manual monitoring and updating is not an automated approach and is prone to delays and human error, failing to meet the requirement for automatic updates and immediate validation.

Automated Dependency Updates

The practice of using automated tools and processes to regularly check for, update, and validate new versions or security patches for application dependencies.

  • Reduces security risks by keeping dependencies current.
  • Ensures compatibility through automated CI/CD validation.
  • Requires tools to interact with package managers and source control.

Memory trick: EventBridge triggers the bot to update your deps and push the changes.

More SDLC Automation questions