On October 1 the PSF shipped the final Python 3.10 release. The interpreter on your Ubuntu 22.04 box will keep running, but it will never be patched again — here's how to find every copy hiding in your fleet and plan a boring, safe upgrade.

Yesterday the Python release team dropped five versions at once: 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8. Most of them are routine security refreshes. One of them is a funeral: 3.10.22 is the final release of the 3.10 series, full stop. After five years, there will be no more security updates, ever. If you're still on 3.10, the PSF's message is polite but blunt — plan your upgrade.

What "end of life" actually means (and what it doesn't)

EOL upstream is not the same as EOL on your box, and the distinction matters for your planning. Ubuntu 22.04 LTS ships Python 3.10 as its system default and Canonical's security team backports critical fixes into the distro package until April 2027. So your /usr/bin/python3 keeps getting distro-level attention for a while longer.

But that cover has hard edges:

  • The source-only trap. 3.10.22 ships as source only — there were no binary installers after 3.10.11. If your deployment installs Python from python.org builds, pinned Docker images, or deadsnakes, there is no patched binary to grab. Ever.
  • Venvs and containers don't inherit distro backports. Your distro-patched interpreter doesn't fix the python:3.10-slim image your app actually runs in, or the virtualenv on the box you set up in 2023 and never touched.
  • Security content keeps coming for everyone else. This same release batch fixed real things: a tarfile extraction-filter bypass (CVE-2026-82049), an ssl hostname-validation gap (CVE-2026-19553), unbounded zipfile decompression (CVE-2026-15310). The next wave of those will patch 3.11–3.14 and leave 3.10 exposed.

Step one: find every copy

3.10 survives by being invisible. Before choosing a target version, take an inventory:

# Every interpreter on the box
which -a python3 && python3 --version

# Shebangs and hardcoded paths pointing at 3.10
grep -rE '#!.*python3\.10|python3\.10' /etc /opt /usr/local/bin 2>/dev/null

# Containers pinned to 3.10
docker images | grep -E '3\.10'

# systemd units and cron jobs invoking it directly
grep -r 'python3.10' /etc/cron* /etc/systemd/system 2>/dev/null

Pay special attention to the things you set up once and forgot: CI pipelines with a pinned setup-python version, internal tooling, and that one cron job written by someone who left in 2024.

Step two: pick a target that isn't already half-dead

Not all supported versions are equally good destinations:

  • 3.11 — security-fix-only until October 2027. Migrating here is moving into a house with the demolition date already posted.
  • 3.12 — security support until October 2028. The boring, safe target. Full binary installers exist.
  • 3.13 — 3.13.16 was its last full maintenance release; future 3.13 releases are security-only. Fine as a target, know what you're getting.
  • 3.14 — current, fully supported. Best if your dependencies have wheels for it.

For most fleets, 3.12 or 3.13 is the right call: maximum support runway, minimum drama.

One migration gotcha worth knowing

From this same batch of release notes: on 3.10–3.12, a missing hostname with check_hostname enabled in ssl emitted a DeprecationWarning; on 3.13 and later it raises ValueError. If any of your code talks TLS with sketchy hostname plumbing, run your test suite under -W error::DeprecationWarning on 3.10 first and fix what screams. That warning was the release team telling you, years ago, exactly what was coming.

The honest close

Five years is a generous runway, and nobody was ambushed — the EOL date was published when 3.10 shipped. The real cost was never the upgrade itself; it was the inventory you never did. Find the interpreters, pick the boring target, rebuild the venvs, run the tests. Do it this quarter, while 3.10.22 is fresh and your memory of where things live is fresh too.


Sources: Python Insider — "Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8 are now available!" (Oct 1, 2026)