Skip to main content
compliance · aws

Lambda functions still running on a runtime AWS has deprecated

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

ZopNight flags a Lambda function whose runtime identifier, such as `python3.9` or `nodejs18.x`, is past its AWS deprecation date. After deprecation AWS may stop applying security patches, then blocks function creation at least 30 days later and updates at least 60 days later. The function keeps running, and the finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates Lambda functions still running on a runtime AWS has deprecated.
Field Value
Rule IDsRC-155
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Thresholdruntime past deprecation date
SourceZopNight
Permissions usedlambda:ListFunctions · lambda:GetFunctionConfiguration

What happens to a function after its runtime is deprecated

Each Lambda runtime has a published end of life. The Lambda runtimes page explains that after deprecation AWS may no longer apply security patches or updates to that runtime, and the functions on it are no longer eligible for technical support. Deprecated runtimes are provided as-is.

The function does not stop. AWS says you can continue to invoke it indefinitely. What changes is your ability to touch it: at least 30 days after deprecation, Lambda starts blocking creation of new functions on the runtime, and at least 60 days after, it starts blocking code and configuration updates. You can still move a blocked function to a supported runtime, but rolling back may be refused. A function that needs an urgent fix after that date is stuck until it is upgraded.

Listing functions by runtime

Terminal window
aws lambda list-functions \
--query 'Functions[].[FunctionName,Runtime]' --output table

Compare the Runtime column with the deprecation table on the runtimes page. For one runtime:

Terminal window
aws lambda list-functions \
--query "Functions[?Runtime=='python3.9'].FunctionName"

Container-image functions have no Runtime value; their base image is managed in your image build.

How ZopNight decides a runtime is deprecated

During discovery ZopNight compares each function’s runtime identifier against a list of deprecated identifiers that it maintains from AWS’s published schedule, and records the result. The rule fires when that result says the runtime is deprecated, and shows the runtime name in the finding. The list includes current retirements such as nodejs18.x, python3.8 and dotnet6, and older identifiers like nodejs4.3 that existing functions can still run on.

Where the list can lag

Because the list is maintained against AWS’s schedule, a runtime whose deprecation date passed very recently may not be flagged yet. Check the AWS table directly for identifiers near their date. When the runtime flag is missing for a function, no finding is produced.

Risk rather than savings

The saving is $0. The rule is rated critical because an unpatched language runtime is a vulnerability you cannot fix in place, and the update block turns a routine change into an emergency migration.

Moving a function to a supported runtime

  1. Pick the target from the supported list, such as python3.13 or nodejs22.x.
  2. Update dependencies and test the code against the new language version; major versions are not guaranteed to be backward compatible.
  3. Deploy to a test alias or stage, then switch the runtime:
Terminal window
aws lambda update-function-configuration \
--function-name my-function --runtime python3.13
  1. Update the runtime in your infrastructure code too, so the next deploy does not revert it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·