Why EOL mattersAn unsupported runtime creates more than a missing patch.
The Node.js project identifies several consequences of running an EOL line: no further vulnerability fixes, increasing tool-chain breakage, ecosystem drift as packages stop supporting the old runtime, and potential compliance concerns around unmaintained software. Those effects compound over time.
A service can appear healthy while its support position deteriorates. The application may still start, tests may still pass, and containers may still deploy, but the team loses a reliable upstream path when a runtime vulnerability, OpenSSL change, operating-system update, native module problem, or package compatibility issue appears.
Do not reduce lifecycle risk to the version printed by node --version on a web server. Node.js can exist in application containers, serverless functions, CI runners, JavaScript-based build actions, developer images, test infrastructure, static-site pipelines, desktop tooling, package scripts, internal CLIs, and third-party products. An upgrade program is incomplete until those locations are understood.