What is being deprecated?
Python 3.9 Lambda runtime (Amazon Linux 2) was deprecated on 2025-12-15 (no further security patches). Per the AWS Lambda runtime deprecation table, AWS blocks creating new python3.9 functions on 2027-02-01 and blocks updating existing ones on 2027-03-03. Functions keep running, but become unpatched and unmodifiable after the block dates.
| Next tracked milestone | 2027-02-01 (155 days from build date 2026-08-30) |
|---|---|
| Service | AWS Lambda |
| Affected resources | function |
| Severity | high |
| Migration kit | python-pivot (free, MIT) |
| Primary source | https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html |
The published service dates and status above use the cited provider source. Recheck it before production planning because future dates can change.
Migration checks
When moving away from this runtime or operating-system release, verify these configured concerns in your own workload. A listed concern is not proof that every workload is affected. [provider status source]
- distutils module removed
- imp module removed
- collections.Mapping deprecated
- Native wheels may not be available
Investigate with the free python-pivot CLI
The MIT-licensed kits have different commands and coverage. Start with local help and the kit README; use fixture or dry-run modes before any command that accepts credentials or an apply flag.
Install from this repository
Keep dependencies isolated and inspect the available commands before running a scan.
python3 -m venv .venv
.venv/bin/pip install -e kits/python-pivot
.venv/bin/python-pivot --help
Review exact matches
Treat matches as migration evidence to verify. A static scanner cannot infer live resource counts, traffic, exploitability, or business impact.
Preview a specific migration command
Follow the selected kit's README. Review the diff and run the application's own tests before using an apply or deploy option.
Use your existing release controls
Deploy through your tested CI, canary, monitoring, and rollback process. The scanner does not certify a production rollout.
Need repository evidence for this migration?
Audit PDF
Static scan of one repository ZIP or source file with exact file/line evidence, observed reach, remediation order, configured references, and explicit limitations. 30-day money-back guarantee.
Check Audit v2 availabilityRun the free scan first · see a sample →
Prefer a 10-second check? Paste your config into the free AWS EOL checker. Pasted input is not uploaded; bounded first-party usage events may be sent.
Frequently asked questions
What is the next tracked milestone?
2027-02-01. Python 3.9 Lambda runtime (Amazon Linux 2) was deprecated on 2025-12-15 (no further security patches). Per the AWS Lambda runtime deprecation table, AWS blocks creating new python3.9 functions on 2027-02-01 and blocks updating existing ones on 2027-03-03. Functions keep running, but become unpatched and unmodifiable after the block dates. [provider status source]
What should I verify before changing the workload?
Validate these configured checks against your code and current upstream documentation: distutils module removed; imp module removed; collections.Mapping deprecated; Native wheels may not be available. A listed check is not proof that the workload is affected.
Which AWS services does this affect?
AWS Lambda — specifically function resources.
Is there a free way to migrate?
Yes — the python-pivot CLI is MIT-licensed and free for local use. Audit v2 is an optional paid repository evidence artifact when its live safety gate is open. EOLkits does not currently sell managed migrations or automated pull requests.