AWS eyes AI-powered code remediation in Amazon CodeWhisperer update
New AI features for Amazon CodeWhisperer will streamline security scanning


Amazon CodeWhisperer users will now be able to leverage AI-powered code remediation tools as part of a raft of updates to the coding assistant.
The updates, unveiled ahead of AWS re:Invent 2023, will enable generative AI-powered code suggestions to help users remediate security and code quality issues.
AWS said the feature roll-out is part of a concerted focus to weed out hard-to-find security vulnerabilities that typically evade built-in security scans.
Built-in security scanning is performed to detect common issues, such as log injection risks or exposed credentials.
“These new enhancements to Amazon CodeWhisperer help to enable faster and more efficient software development by offloading undifferentiated work and delivering more automation, security, efficiency, and accelerated code delivery for customers, and provides this support in more places where developers love to work,” the firm said in a statement.
Supercharging security with Amazon CodeWhisperer
As part of the feature update, CodeWhisperer code suggestions will automatically remediate identified vulnerabilities.
During the scanning process, users will be presented with code suggestions that can be easily accepted to close vulnerabilities. The feature will be specifically tailored to users’ application code, AWS said, enabling users to "quickly accept fixes with confidence”.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
In a blog post, AWS’ Irshad Buchh said the tool will improve developer productivity by reducing the burden of manual code reviews, allowing them to focus on alternative tasks in their daily workflow.
RELATED RESOURCE
Read how organizations are accelerating the training and deployment of machine learning models at scale.
“Generative AI-powered code suggestions speed up the process of addressing security issues, so you can focus on higher-value work instead of manually reviewing code line by line to find the correct solution,” he said.
Security scanning in CodeWhisperer is already available for Java, Python, and JavaScript. Code suggestions to remediate vulnerabilities will be available for all three languages.
Infrastructure as Code announcements
In addition to AI-powered security scanning capabilities, CodeWhisperer will also offer support for Infrastructure as Code (IaC).
This will apply to AWSCloudFormation (YAML, JSON), AWS CDK (Typescript, Python), and HashiCorp Terraform (HCL).
Buchh said the update will streamline efficiency of IaC script development, enabling devs and DevOps teams to “write infrastructure code seamlessly”.
With support for multiple IaC languages, CodeWhisperer promotes collaboration and consistency across diverse teams,” he said. “This marks a significant advancement in cloud infrastructure development, offering a more streamlined and productive coding experience for users.”
CodeWhisperer is coming to Visual Studio
CodeWhisperer is also now available in Visual Studio 2022 in a preview, AWS confirmed.
The integration of the coding assistant within Visual Studio will enable developers to build applications faster by drawing on real-time code suggestions for C#, the firm said.
This roll-out will automatically flag code suggestions that resemble publicly available code, the firm said. This will include insights on repository URLs and licenses if code is highlighted as similar to public code.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
'Customers have been begging us to launch': AWS just rolled out Amazon Q Business in Europe – and it includes new data residency features
News AWS has announced the availability of its Amazon Q Business platform in Europe in a move sure to please sovereignty-conscious customers.
By George Fitzmaurice
-
AWS puts AI evolution front and center at re:Invent 2024
Analysis AWS re:Invent 2024 was a testament to the cloud giant’s commitment to AI diversification as it looks to take market share in the next era of AI
By George Fitzmaurice
-
AWS sharpens sustainability focus as AI environmental concerns rise
News The hyperscaler says sustainability plays a part in core decision-making in the age of AI
By George Fitzmaurice
-
AWS goes all in on AI agents with new features for Bedrock and Amazon Q
News Agentic customizability is coming to Bedrock and the Amazon Q developer assistant
By George Fitzmaurice
-
New AWS and Box collaboration brings AI models to enterprise content
News Box customers can now access Anthropic’s Claude and Amazon Titan foundation models within Box AI
By Daniel Todd
-
Databricks expands AWS partnership to drive generative AI capabilities
News The new agreement promises “unmatched scale and price performance” to help customers take genAI applications to market faster
By Daniel Todd
-
Amazon’s $4 billion investment in Anthropic faces UK competition probe – here’s what it means
News The CMA investigation into the Anthropic investment is the latest in a slew of probes by the competition regulator
By Emma Woollacott
-
Hyperscaler AI spending is getting out of control — and Microsoft says it could take 15 years for it to make good on investments
News Tech giants' results show billions being poured into AI infrastructure, but big leaps in revenue remain elusive
By Nicole Kobie