3 ms·
Amen. How many times did you update your Node.js AWS Lambdas or GCP Cloud Functions because of the Linux kernel CVE of the week? You didn't because all you're
by twistedpair 5y ago
Amen.
How many times did you update your Node.js AWS Lambdas or GCP Cloud Functions because of the Linux kernel CVE of the week? You didn't because all you're responsible for is your few lines of Node.js logic that kept on scaling and humming along. The cloud vendor cares for the rest.
- vinay_ys 5y agoJust because you didn't doesn't mean they did and you didn't actually have any vulnerabilities. There is no such provable attestation of security in serverless model.
- throwaway894345 5y ago> Lambda provides support for these runtimes by continuously scanning for and deploying compatible updates and security patches, and by performing other runtime maintenance activity. https://docs.aws.amazon.com/whitepapers/latest/security-overview-aws-lambda/runtime-maintenance-in-lambda.html https://docs.aws.amazon.com/whitepapers/latest/security-over... I'm not sure if that addresses your concern (maybe you're worried they're lying or they have a bug in their process)?