Blog · Cloud
Your Node.js 20 Lambda functions have been running without guaranteed patches since April
AWS deprecated the Node.js 20 runtime on Lambda on April 30, 2026: since then, AWS may no longer apply security patches to it, and those functions no longer have technical support. They keep running, but starting February 1, 2027 you won't be able to create them, and starting March 3 you won't be able to update them either. The day you need an urgent fix, you'll have to migrate first.

What deprecation changes
The Lambda documentation is blunt: after deprecation, AWS may stop applying security patches to the runtime, and deprecated runtimes are provided as is, with no guarantees. Functions can keep being invoked indefinitely, but they may run into performance or other issues, such as an expiring certificate, that stop them from working properly.
You can still create and update Node.js 20 functions today, though no longer from the console, only with the CLI, SAM, or CloudFormation. Starting February 1, 2027, creation is blocked, and starting March 3, so are code and configuration updates. After that date, the only change you can make is to switch the function to a supported runtime, and rolling back may be blocked.
Why jump to Node.js 24
Node.js 22 is set to be deprecated on April 30, 2027, with creation blocked on June 1 and updates blocked on July 1 of that year. Migrating to 22 buys you a few months. Node.js 24 is scheduled through April 30, 2028. AWS doesn't guarantee compatibility between major versions, so every jump needs testing.
There are notices: AWS emails the account's primary contact at least 180 days before deprecation and shows the affected functions in the Health Dashboard and in Trusted Advisor. But for functions packaged as container images there are no notices: the team has to track the date.