Neon Security & compliance Stability Releases

Postgres version end-of-life (< 14)

Part of the Cost & ops health check · fix arrives as a guide

What it is

The project runs Postgres 13 or older, which is past end of life.

Why it matters

End-of-life versions receive no security patches. New vulnerabilities in Postgres remain unfixed on your instance indefinitely, and the upgrade only gets larger the longer it waits.

How to fix it

Plan an upgrade to a supported major version, testing on a Neon branch first — branching makes this genuinely low-risk since you can validate against a copy of real data before switching.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.