Lambda functions still running on a runtime AWS has deprecated
What does ZopNight detect here?
ZopNight flags a Lambda function whose runtime identifier, such as `python3.9` or `nodejs18.x`, is past its AWS deprecation date. After deprecation AWS may stop applying security patches, then blocks function creation at least 30 days later and updates at least 60 days later. The function keeps running, and the finding carries a $0 saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-155 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | runtime past deprecation date |
| Source | ZopNight |
| Permissions used | lambda:ListFunctions · lambda:GetFunctionConfiguration |
Where it applies
What happens to a function after its runtime is deprecated
Each Lambda runtime has a published end of life. The Lambda runtimes page explains that after deprecation AWS may no longer apply security patches or updates to that runtime, and the functions on it are no longer eligible for technical support. Deprecated runtimes are provided as-is.
The function does not stop. AWS says you can continue to invoke it indefinitely. What changes is your ability to touch it: at least 30 days after deprecation, Lambda starts blocking creation of new functions on the runtime, and at least 60 days after, it starts blocking code and configuration updates. You can still move a blocked function to a supported runtime, but rolling back may be refused. A function that needs an urgent fix after that date is stuck until it is upgraded.
Listing functions by runtime
aws lambda list-functions \ --query 'Functions[].[FunctionName,Runtime]' --output tableCompare the Runtime column with the deprecation table on the runtimes page. For one runtime:
aws lambda list-functions \ --query "Functions[?Runtime=='python3.9'].FunctionName"Container-image functions have no Runtime value; their base image is managed in your image build.
How ZopNight decides a runtime is deprecated
During discovery ZopNight compares each function’s runtime identifier against a list of deprecated
identifiers that it maintains from AWS’s published schedule, and records the result. The rule fires
when that result says the runtime is deprecated, and shows the runtime name in the finding. The list
includes current retirements such as nodejs18.x, python3.8 and dotnet6, and older identifiers
like nodejs4.3 that existing functions can still run on.
Where the list can lag
Because the list is maintained against AWS’s schedule, a runtime whose deprecation date passed very recently may not be flagged yet. Check the AWS table directly for identifiers near their date. When the runtime flag is missing for a function, no finding is produced.
Risk rather than savings
The saving is $0. The rule is rated critical because an unpatched language runtime is a vulnerability you cannot fix in place, and the update block turns a routine change into an emergency migration.
Moving a function to a supported runtime
- Pick the target from the supported list, such as
python3.13ornodejs22.x. - Update dependencies and test the code against the new language version; major versions are not guaranteed to be backward compatible.
- Deploy to a test alias or stage, then switch the runtime:
aws lambda update-function-configuration \ --function-name my-function --runtime python3.13- Update the runtime in your infrastructure code too, so the next deploy does not revert it.