AWS Security ChangesHomeSearch

AWS lambda: Clarify durable function version pinning and $LATEST replay risk

Service: lambda · 2026-09-27 · Documentation low

File: lambda/latest/dg/durable-invoking.md

Summary

Rewrites guidance on durable execution version pinning, adds a new section warning that $LATEST executions can resume on updated code causing non-determinism errors or silent failures, and tightens the recommendation to use numbered versions/aliases in production.

Security assessment

The change documents a correctness/reliability concern (non-determinism and silent failures when $LATEST code changes mid-execution) rather than a vulnerability, credential, or access-control issue. It is operational guidance with no concrete security fix.

Evidence

+Executions started with the `$LATEST` qualifier are not pinned to a fixed copy of your code. If you update your function code while an execution is paused, the execution resumes on the new code rather than the version that it started on.

Diff

diff --git a/lambda/latest/dg/durable-invoking.md b/lambda/latest/dg/durable-invoking.md
index 9cd88d9a2..4844b97f8 100644
--- a//lambda/latest/dg/durable-invoking.md
+++ b//lambda/latest/dg/durable-invoking.md
@@ -77 +77,7 @@ Durable functions require qualified identifiers for invocation. You must invoke
-This requirement ensures that durable executions remain consistent throughout their lifecycle. When a durable execution starts, it's pinned to the specific function version. If your function pauses and resumes hours or days later, Lambda invokes the same version that started the execution, ensuring code consistency across the entire workflow.
+This requirement ensures that durable executions remain consistent throughout their lifecycle. When a durable execution starts, it's pinned to the function version that started it. If your function pauses and resumes hours or days later, Lambda invokes that same version, so publishing a new version affects only new executions. Similarly, when you update an alias, new executions use the new version, and in-progress executions continue on the version they started on.
+
+###### $LATEST executions can resume on updated code
+
+Executions started with the `$LATEST` qualifier are not pinned to a fixed copy of your code. If you update your function code while an execution is paused, the execution resumes on the new code rather than the version that it started on.
+
+Your code might no longer process the saved execution state in the same way, leading to non-determinism errors or silent failures. For more information about writing functions that replay safely, see [Function versions and aliases](./durable-best-practices.html#durable-versioning).
@@ -81 +87 @@ This requirement ensures that durable executions remain consistent throughout th
-Use numbered versions or aliases for production durable functions rather than `$LATEST`. Numbered versions are immutable and support deterministic replay. Optionally, aliases provide a stable reference that you can update to point to new versions without changing invocation code. When you update an alias, new executions use the new version, while in-progress executions continue with their original version. You may use `$LATEST` for prototyping or to shorten deployment times during development, understanding that executions might not replay correctly (or even fail) if the underlying code changes during running executions.
+Use numbered versions or aliases for production durable functions rather than `$LATEST`. Numbered versions are immutable and support deterministic replay. Optionally, aliases provide a stable reference that you can update to point to new versions without changing invocation code. Use `$LATEST` only for prototyping or to shorten deployment times during development, because executions might not replay correctly if the code changes while they run.