Skip to content
Notifications
Clear all

What is the best way to handle scanning serverless functions?

2 Posts
2 Users
0 Reactions
25 Views
(@devops_rookie_2025)
Prominent Member
Joined: 4 months ago
Posts: 467
Topic starter   [#19072]

Hi everyone! 😊 I'm pretty new to the whole cloud security world and I'm trying to figure out the best practices for securing our serverless setup.

We're starting to use AWS Lambda more, and I'm a bit confused about how to properly scan these functions for vulnerabilities. I've used Tenable.io for our regular VMs, but serverless feels different. Should I be scanning the container image before deployment, the function's dependencies, or the runtime environment itself? And is there a way to automate this in a CI/CD pipeline?

Any beginner-friendly advice or examples on workflows would be super helpful! Thanks in advance to anyone who can share their experience.



   
Quote
(@jacksonw)
Estimable Member
Joined: 3 months ago
Posts: 63
 

I'm a product ops manager at a mid-sized SaaS company (80 people), and we run about 50 production Lambdas for background jobs and API endpoints.

Here's how I've evaluated scanning tools for our setup, focusing on what matters when you're starting out.

**Scan Target & Fit:** You need something that specifically handles the serverless function package. This means checking dependencies (like your `node_modules` or `requirements.txt`) for known CVEs. Some tools that are great for containers (like Snyk) also have a Lambda focus and can analyze that zip file before deployment.
**Real Pricing:** Most serverless scanners price per function per month. In my last shop, we saw a range from $5-15 per function/month for decent coverage. Watch out for vendors that charge for each scan instead of active functions; it adds up fast in CI/CD.
**CI/CD Integration:** The winner needs a simple plugin for your pipeline (GitHub Actions, CircleCI, etc.) that fails the build on high-severity vulns. We rejected a couple of options because they required a complex agent setup instead of a simple CLI step.
**The Honest Limitation:** Runtime scanning is tricky. Many tools only scan pre-deployment. Once the function is live, you can't traditionally scan it like a VM. The best you can do is monitor for anomalous behavior (like unexpected network calls) via something like AWS CloudTrail or a vendor's runtime agent, but that's a separate layer.

For a beginner, I'd start with **Snyk** if you're already using it for other projects, as it handles dependencies well. If your team is lean and wants the simplest "break the build" setup, tell us your deployment frequency and your current CI/CD tool. That's the deciding factor.


not a buyer, just a nerd


   
ReplyQuote