# serverless changelog > serverless release notes. - Vendor: serverless - Category: Frameworks & Libraries - Official site: https://serverless.com/ - Tracked by: What's New (https://whatsnew.fyi/product/serverless) - Harvested from: GitHub (serverless/serverless) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. ## Releases ### sf-core@4.40.0 — 4.40.0 - Date: 2026-07-22 - Version: sf-core@4.40.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.40.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.40.0 #### 4.40.0 ##### Features - **Lambda self-managed code storage.** Setting `provider.deploymentBucket.codeStorageMode: reference` makes Lambda run function and layer code directly from your deployment bucket instead of copying it into Lambda-managed storage, so your code no longer counts against the Lambda code storage quota. Every deployment pins each function and layer to the exact uploaded S3 object version, so later uploads never affect what runs. Because deployment artifacts back live Lambda versions in this mode, automatic post-deploy artifact cleanup is disabled — retire artifacts that no longer back any function or layer version with `serverless prune --includeArtifacts` (also available as `custom.prune.includeArtifacts`). Read more in the [deployment bucket guide](https://www.serverless.com/framework/docs/guides/deployment-bucket/) and the [prune CLI reference](https://www.serverless.com/framework/docs/providers/aws/cli-reference/prune), and see the [aws-node-self-managed-code-storage example](https://github.com/serverless/examples/tree/v4/aws-node-self-managed-code-storage). (#13725) ```yaml provider: deploymentBucket: codeStorageMode: reference # default: copy ``` ```bash #### Keep the 3 most recent function versions, then retire deployment #### artifacts that no longer back any surviving function or layer version serverless prune -n 3 --includeArtifacts ``` > **Note** > `reference` mode requires a versioned deployment bucket that Lambda is allowed to read. The Framework-managed deployment bucket is configured automatically; custom buckets are validated and the deployment stops with instructions when a prerequisite is missing. - **Compose: run a command on an exact subset of services.** The `--service` option now accepts a comma-separated list for `deploy`, `remove`, `info`, `print`, and `package`. The command runs on exactly the named services, ordered by `dependsOn`; services not named are left untouched, and their outputs stay available for `${param:...}` resolution — so a subset can reference services already deployed elsewhere. Read more in the [Compose guide](https://www.serverless.com/framework/docs/guides/compose). (#13705) ```bash serverless deploy --service=service-a,service-d --stage my-feature ``` - **Removed Serverless Container Framework and Serverless AI Framework.** These products are no longer part of the CLI. Projects with a `serverless.containers.*` or `serverless.ai.*` configuration file now get a clear error with guidance: pin `frameworkVersion: "4.39.0"` (the last version supporting them) and the CLI automatically runs that version for the project. (#13698) ```yaml frameworkVersion: '4.39.0' ``` ##### Bug Fixes - **Fixed corrupted bundles when multiple functions share a handler file.** The built-in esbuild packaging ran one build per function, so functions sharing a handler file wrote the same output concurrently — occasionally producing a corrupted bundle that failed at Lambda startup with `Runtime.UserCodeSyntaxError`. Each unique handler file is now built exactly once and reused across the functions that share it, which also removes the redundant rebuilds. (#13716, #13717) - Thanks @dekpient for the report! - **Fixed unchanged services being redeployed on every deploy.** Artifacts produced by the built-in esbuild packaging embedded fresh file timestamps on every build, so identical code always looked changed to deploy change detection. Archive entry timestamps are now pinned, identical content produces byte-identical artifacts, and unchanged deployments are skipped as intended. (#13696) - **Fixed the shared IAM role accumulating permissions for functions with dedicated roles.** When only some functions use per-function IAM roles, the shared execution role no longer collects event-source and feature grants belonging to functions that have their own role — previously its inline policy grew with every function and could exceed the IAM policy _[Truncated at 4000 characters — full notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.40.0]_ ### sf-core@4.39.0 — 4.39.0 - Date: 2026-07-08 - Version: sf-core@4.39.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.39.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.39.0 ##### Features - **Sandboxes — AWS Lambda MicroVMs.** First-class support for Firecracker-isolated, snapshot-booted virtual machines that you define declaratively and run on demand, with the serverless operational model (no clusters, pay per run). Define a sandbox from a local Dockerfile directory or a prebuilt `s3://` zip, and configure memory, environment, lifecycle hooks, tags, and VPC egress. `deploy`/`remove` build and tear down the image and supporting resources; IAM build/execution roles are generated for you, and observability — CloudWatch logs, metric filters, alarms, and a dashboard — is enabled by default and fully customizable. ```yaml sandboxes: echo: artifact: ./app # local directory that contains a Dockerfile ``` ```bash serverless invoke --sandbox echo # run it (with --method / --port) serverless logs --sandbox echo # fetch logs serverless dev --sandbox echo # local dev loop with hot reload ``` **Local development.** `serverless dev --sandbox ` builds and runs the sandbox container on your machine and hot-reloads it as you edit — no deploy needed to iterate. Requests are relayed to the locally running container, so you get the full run/inspect loop against your real sandbox definition before anything ships to AWS. See the [Sandboxes guide](https://www.serverless.com/framework/docs/providers/aws/guide/sandboxes) for the full configuration reference, and the [`serverless/examples` sandboxes directory](https://github.com/serverless/examples/tree/v4/sandboxes) for deploy-ready examples (minimal, complete, and a self-hosted environment for Claude Managed Agent). (#13663) - **`serverless agent` commands for AI coding agents.** A new command namespace purpose-built for agents (Claude Code, Codex, Cursor) working with a Serverless service. (#13673) - **[`serverless agent skills install`](https://www.serverless.com/framework/docs/providers/aws/cli-reference/agent-skills-install)** installs the bundled [Agent Skills](https://agentskills.io) into the service directory (`.claude/skills/`, `.agents/skills/`, or both — auto-detected), teaching agents how to work with the service. Idempotent, auto-refreshing when a newer CLI bundles newer skills, and ejectable per-skill. - **[`serverless agent inspect`](https://www.serverless.com/framework/docs/providers/aws/cli-reference/agent-inspect)** returns the live AWS configuration of a deployed service's resources in a single call — a categorized inventory by default, or expanded raw AWS responses filtered by category (`--functions`, `--api`, `--iam`, `--sandboxes`, `--all`, …) or by AWS service. Deterministic, pipe-safe JSON/YAML output, so an agent gets the whole logical-to-physical picture without issuing dozens of `aws describe-*` calls itself. ```bash serverless agent skills install serverless agent inspect --functions --api ``` See the [Agent Skills guide](https://www.serverless.com/framework/docs/guides/agent-skills) for how skills are discovered, updated, and ejected, and the [`agent inspect` reference](https://www.serverless.com/framework/docs/providers/aws/cli-reference/agent-inspect) for its full category and AWS-service filtering options. ##### Maintenance - Runtime dependency bumps: `@aws-sdk/util-arn-parser` (#13680), a batch of 11 patch-level updates (#13677), and other routine bumps (#13666). - Development and CI tooling: dev-dependency group updates (#13676), `lint-staged` 16 → 17 (#13678), and GitHub Actions bumps (#13667); constrained `https-proxy-agent` to a range that keeps Node 18 support (#13686). ### sf-core@4.38.1 — 4.38.1 - Date: 2026-06-19 - Version: sf-core@4.38.1 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.38.1 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.38.1 ##### Maintenance - **Upgraded undici to 6.27.0**, clearing security advisories reported against earlier versions of the bundled HTTP client: a Set-Cookie `SameSite` attribute downgrade ([GHSA-g8m3-5g58-fq7m](https://github.com/advisories/GHSA-g8m3-5g58-fq7m)), HTTP header injection via Set-Cookie percent-decoding ([GHSA-p88m-4jfj-68fv](https://github.com/advisories/GHSA-p88m-4jfj-68fv)), and a WebSocket client denial-of-service ([GHSA-vxpw-j846-p89q](https://github.com/advisories/GHSA-vxpw-j846-p89q)). (#13657) ### sf-core@4.38.0 — 4.38.0 - Date: 2026-06-17 - Version: sf-core@4.38.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.38.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.38.0 ##### Features - **Ruby 4.0 runtime support.** Functions can now target the `ruby4.0` Lambda runtime. (#13613) ```yaml provider: name: aws runtime: ruby4.0 ``` - **New `${aws:partition}` variable.** Resolves to the AWS partition for the deployment region (e.g. `aws`, `aws-cn`, `aws-us-gov`) with no network call or credentials required. Makes ARNs in your configuration portable across commercial, GovCloud, and China partitions. (#12441, #13633) ```yaml provider: iam: role: managedPolicies: - arn:${aws:partition}:iam::aws:policy/AmazonS3ReadOnlyAccess ``` - **AgentCore: Python 3.14 support.** Agent runtimes can now target `python3.14`. Runtime validation is also stronger, with supported runtimes validated against a single allowlist. (#13645) ```yaml # AgentCore agent configuration runtime: python3.14 ``` ##### Bug Fixes - **API Gateway custom stage now used for the service endpoint URL and stage tags.** When `provider.apiGateway.stage` is set to a value different from the deployment stage, the `ServiceEndpoint` output URL and the API Gateway stage tags now use that configured stage. Previously they used the deployment stage, producing an incorrect endpoint URL and attempting to tag a stage that did not exist. (#13636) ```yaml provider: apiGateway: stage: customstage # now reflected in ServiceEndpoint + stage tags ``` - **Variable resolution no longer drops placeholders during re-entrant resolution.** A JavaScript or TypeScript `${file(...)}` resolver that calls `resolveVariable()` or `resolveConfigurationProperty()` mid-resolution opens a nested resolution pass. Under certain async timing this could leave the outer resolution looking inactive, causing a later nested placeholder to be left unresolved. Each pass now preserves and restores its context so the full dependency chain resolves reliably. (#13635) - **AgentCore: unpinned the default Buildpacks builder image and added a `builder` override.** The previously hard-pinned `heroku/builder` digest is no longer used by default. (#13647, #13646) ##### Maintenance - Bumped the AWS SDK group with 34 updates (#13632) - Upgraded esbuild to 0.28.1 and tsx to 4.22.4 (#13610, #13644) - Upgraded Go to 1.26.4 and bumped `golang.org/x/sys` and `golang.org/x/mod` for the installer (#13618, #13614, #13650) - Upgraded the Jackson libraries (databind, core, annotations, datatype-joda) for the Java runtime wrapper (#13619, #13620, #13621, #13637, #13638, #13639, #13640) - Upgraded `graphql` to 16.14.0, `ajv` to 8.20.0, `zod` to 4.4.3, `semver` to 7.8.1, `hono`, `@grpc/grpc-js` to 1.14.4, and `eventsource-parser` to 3.1.0 (#13576, #13631, #13577, #13578, #13627, #13630, #13643, #13626) - Patched a uuid buffer-bounds advisory in the bedrock-agentcore examples (#13617) - Bumped grouped npm and GitHub Actions dependencies (#13649, #13648, #13641, #13622, #13624, #13625) ### sf-core@4.37.0 — 4.37.0 - Date: 2026-05-27 - Version: sf-core@4.37.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.37.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.37.0 ##### Features - **New `serverless diff` command for previewing changes against the deployed stack.** Packages the service locally and renders a structured diff — resources, IAM grants, security groups, parameters, outputs — against the CloudFormation stack currently in AWS. A `Function Code` section reports per-function code changes by comparing local zip hashes against each Lambda's `CodeSha256`. Especially useful in CI and PR-review workflows. `--json` emits a machine-readable summary; `--package ` reuses an existing artifact directory to skip the auto-package step. [Docs](https://www.serverless.com/framework/docs/providers/aws/cli-reference/diff). (#13602) ```bash serverless diff serverless diff --json serverless diff --package .serverless ``` - **TypeScript files supported in `${file()}` variable references.** The `${file(...)}` variable resolver now loads `.ts`, `.mts`, and `.cts` modules in addition to JavaScript, with no separate build step required. All export shapes — default object, async default function, named export, named-export function with property selector, and injected `resolveVariable` / `resolveConfigurationProperty` callbacks — behave identically across JavaScript and TypeScript sources. [Docs](https://www.serverless.com/framework/docs/guides/variables/file#reference-javascript-or-typescript-files). (#13590) ```ts // scripts/secrets.ts export const getSecrets = async () => ({ apiKey: process.env.API_KEY }) ``` ```yaml custom: secrets: ${file(./scripts/secrets.ts):getSecrets} ``` - **Custom `.env` file locations and explicit opt-out via `useDotenv`.** Previously a boolean. Now accepts a path or array of paths to load additional `.env` files alongside the local `.env` / `.env.${stage}` already loaded automatically — useful for monorepos sharing variables across services. `useDotenv: false` is now honored as the documented opt-out. Debug logging at `core:resolver:env` surfaces which files loaded and which keys came from each (visible with `SLS_DEBUG=*`; keys only, never values). [Docs](https://www.serverless.com/framework/docs/providers/aws/guide/serverless.yml#dotenv-files). Closes #10641. (#13597) ```yaml useDotenv: ../shared # load files from a sibling directory # useDotenv: # …or a list — earlier entries win # - ./overrides.env # - ../ # useDotenv: false # disable all .env loading ``` - **CloudWatch Logs Infrequent Access log class.** Opt-in `logs.logGroupClass: infrequent_access` at provider or function level provisions an Infrequent Access log group alongside the standard one, wires Lambda's `LoggingConfig.LogGroup` to write to it, and applies `DeletionPolicy: Retain` so its history survives stack updates and removals. The standard sibling is always created so pre-existing logs at the default path are preserved during migration. Services that do not opt in produce an identical CloudFormation template. [Docs](https://www.serverless.com/framework/docs/providers/aws/guide/functions#infrequent-access-log-class). Closes #12278. (#13601) ```yaml provider: logs: lambda: logGroupClass: infrequent_access # service-wide default functions: realTimeReports: handler: handler.reports logs: logGroupClass: standard # override per function ``` > **Note:** AWS does not allow the class of an existing log group to be changed in place. `serverless logs -f ` cannot read Infrequent Access groups — use CloudWatch Logs Insights instead. Once an IA log group has been retained out of the stack, re-enabling `infrequent_access` later for the same function will fail with `ResourceAlreadyExistsException` unless the orphaned group is first deleted or imported back into the stack. - **Cognito User Pool `PreTokenGeneration` V2_0 and V3_0 triggers.** New opt-in `lambdaVersion` property on the `cognitoUserPool` e _[Truncated at 4000 characters — full notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.37.0]_ ### sf-core@4.36.1 — 4.36.1 - Date: 2026-05-14 - Version: sf-core@4.36.1 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.36.1 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.36.1 ##### Bug Fixes - **Fixed framework hang during TypeScript configuration loading.** Services with multi-file TypeScript configurations (a `serverless.ts` that imports other `.ts` files via relative imports) could deadlock during command startup, most reliably reproduced in AWS CodeBuild. The framework now handles nested TypeScript imports without the deadlock. (#13574, #13581) - **Fixed esbuild version conflicts with the `serverless-esbuild` plugin.** Projects that pinned an `esbuild` version different from the framework's hit `Cannot start service: Host version "X.Y.Z" does not match binary version "A.B.C"` errors when running commands like `serverless invoke local`. Each esbuild instance now resolves its own platform binary independently, so both versions can coexist in the same project. (#13580, #13581) ##### Maintenance - Bumped the AWS SDK group with 30 updates (#13575) - Upgraded `protobufjs` from 7.5.5 to 7.5.7 (#13573) - Bumped `langsmith` across bedrock-agentcore JavaScript examples (#13579) ### sf-core@4.36.0 — 4.36.0 - Date: 2026-05-12 - Version: sf-core@4.36.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.36.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.36.0 ##### Features - **Faster, more reliable installs.** The Serverless Framework installer no longer needs to download dependencies from the npm registry at install time — everything required is pulled in a single download. Fresh installs also use less disk space (~42 MB saved per framework version). Existing projects work without changes. (#13514) > **Note**: Existing users on an older installer will automatically pick up this faster install path the next time they update or fetch a new framework version. To also get the disk-space savings, update the installer with `serverless update`, or reinstall the `serverless` npm package. ##### Bug Fixes - **Patched `urllib3` decompression-bomb vulnerability in Python test fixtures.** Bumped `urllib3` from 2.6.3 to 2.7.0 across all Python lockfiles (`poetry`, `pipenv`, `pip`, `uv` variants) to resolve [GHSA-mf9v-mfxr-j63j](https://github.com/advisories/GHSA-mf9v-mfxr-j63j). Affects only the test-suite Python environments — no impact on user deployments. (#13568) - **Patched a `net/http` infinite-loop CVE in the installer runtime.** Picks up the upstream fix for [CVE-2026-33814](https://nvd.nist.gov/vuln/detail/CVE-2026-33814) (HTTP/2 CONTINUATION-frame infinite loop when `SETTINGS_MAX_FRAME_SIZE=0`). All released installers are rebuilt against the patched toolchain. (#13560) ##### Maintenance - Patched additional moderate-severity dependency vulnerabilities: - Upgraded `hono` 4.12.14 → 4.12.18, `fast-uri` 3.0.6 → 3.1.2, `fast-xml-builder` 1.1.5 → 1.2.0, `ip-address` 10.1.0 → 10.2.0, and `express-rate-limit` 8.3.1 → 8.5.1 (#13564) - Bumped `fast-uri` across all 13 bedrock-agentcore JavaScript examples (#13561) - Bumped `fast-xml-builder` (along with two transitives) across all 13 bedrock-agentcore JavaScript examples (#13559) - Bumped the AWS SDK group with 31 updates from 3.1035.0 to 3.1041.0 (#13565) - Upgraded `mongodb` from 7.1.1 to 7.2.0 — adds support for MongoDB's Intelligent Workload Management (#13553) - Upgraded `simple-git` from 3.33.0 to 3.36.0 (#13555) - Bumped the patch-updates group: `@slack/web-api` 7.15.1 → 7.15.2, `fs-extra`, and `uuid` (#13567) - Bumped dev-dependencies group: `eslint` 10.2.1 → 10.3.0 and `globals` (#13566) - Bumped Jackson Java dependencies in `invoke-local` runtime wrappers: `jackson-core`, `jackson-databind`, `jackson-datatype-joda` (#13548, #13549, #13550) - Bumped `aws-actions/configure-aws-credentials` from v6.1.0 to v6.1.1 in CI workflows (#13563) - Added `toml` v4+ to the Dependabot ignore list to preserve Node.js 18 support (#13562) ### sf-core@4.35.1 — 4.35.1 - Date: 2026-05-06 - Version: sf-core@4.35.1 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.35.1 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.35.1 ##### Bug Fixes - **AppSync: `@canonical`, `@hidden`, and `@renamed` now work on field definitions.** The bundled Merged API directive stubs only declared the `OBJECT` location, so applying these directives to fields failed packaging with errors like `Directive "@canonical" may not be used on FIELD_DEFINITION.`. They're now declared as `OBJECT | FIELD_DEFINITION` to match AWS's documented surface. (#13533, #13542). Thanks @PatrykMilewski! ```graphql type Query { getMessage(id: ID!): Message @renamed(to: "getChatMessage") internalField: String @hidden } ``` - **Python: lambda layer is now built for layer-only services.** Services that declared `custom.pythonRequirements.layer` with no `functions:` block silently produced an empty CloudFormation stack. The runtime guard now also activates when `pythonRequirements.layer` is set and the provider runtime starts with `python`, restoring parity with the standalone `serverless-python-requirements` plugin. Heads up: services that previously hit this bug will now actually invoke pip on `serverless package`, so set `pythonBin` or use `dockerizePip` if the matching `pythonX.Y` binary isn't available locally. (#13541) ```yaml provider: runtime: python3.13 custom: pythonRequirements: layer: true ``` - **Python: zip entry paths are now normalized to forward slashes on Windows.** `globSync` was preserving Windows backslashes in ZIP archive entries, which broke the ZIP spec and caused import mismatches at runtime. Entries are now written with POSIX-style `/` separators on every platform, and `ci-python.yml` also runs Python tests on Windows when Python paths change. (#13307, #13383, #13546). Thanks @Tsingis! ##### Maintenance - Patched [GHSA-w5hq-g745-h8pq](https://github.com/advisories/GHSA-w5hq-g745-h8pq) (uuid v3/v5/v6 missing buffer bounds check) in the `langgraph-*` JavaScript example lockfiles under `bedrock-agentcore/examples/javascript/` by bumping nested `uuid` from 13.0.0 to 13.0.2. Lockfile-only, and these examples aren't shipped in the published package. (#13545) - Bumped `axios` from 1.15.0 to 1.15.2 (transitive, lockfile-only) for upstream security-hardening patches. (#13544) ### sf-core@4.35.0 — 4.35.0 - Date: 2026-04-30 - Version: sf-core@4.35.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.35.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.35.0 ##### Features - **Added uv dependency-group and optional-dependency controls for Python packaging.** Four new `custom.pythonRequirements` options let you control which extras and groups are included in the deployment package, mirroring the existing Poetry group support. `--no-dev` is always passed to keep dev dependencies out of Lambda packages by default; opt in via `uvWithGroups: [dev]` if needed. Read more in the [docs](https://www.serverless.com/framework/docs/providers/aws/guide/python#optional-dependencies-and-groups). (#13499, #13500) — Thanks @jax-b! ```yaml custom: pythonRequirements: uvOptionalDependencies: # → uv export --extra - heavy uvWithGroups: # → uv export --group - prod uvWithoutGroups: # → uv export --no-group - test uvOnlyGroups: # → uv export --only-group - lambda ``` ##### Bug Fixes - **Fixed `sls deploy --package` failure with the esbuild builder.** Esbuild zip artifacts are now written to `.serverless/.zip` instead of `.serverless/build/.zip`, matching the path that `extended-validate.js` reconstructs. The two-process `sls package` + `sls deploy --package .serverless` flow no longer fails with `MISSING_ARTIFACT_FILE`. The `.serverless/build/` directory remains the staging area for intermediate build artifacts (compiled JS, `package.json`, lockfiles, `node_modules`) — only the final zip moves up. (#12964, #13507) - **Fixed duplicate `PATH` entries from the binary installer script.** The installer used `$(grep -q ...)` command substitution to detect whether `.serverless/bin` was already in the shell config; because `-q` suppresses output, the substitution always returned an empty string and the condition was always true, so a new line was appended on every install. The script now checks the exit status directly and properly quotes `$SHELL_CONFIG`. (#13394, #13410) — Thanks @gaurav0909-max! ##### Maintenance - Patched moderate-severity security vulnerabilities: - Upgraded `fast-xml-parser` from 5.5.8 to 5.7.1 to patch [GHSA-gh4j-gqv2-49f6](https://github.com/advisories/GHSA-gh4j-gqv2-49f6) (XMLBuilder XML comment and CDATA injection via unescaped delimiters) (#13521) - Patched [GHSA-w5hq-g745-h8pq](https://github.com/advisories/GHSA-w5hq-g745-h8pq) (uuid v3/v5/v6 missing buffer bounds check) by bumping nested `uuid` versions and replacing `dockerode` 4.0.10 with 5.0.0, which drops the `uuid` dependency entirely (#13530) - Upgraded `follow-redirects` from 1.15.11 to 1.16.0, `hono` from 4.12.12 to 4.12.14, and `protobufjs` from 7.5.3 to 7.5.5 to pick up upstream vulnerability patches (#13516) - Upgraded `fastify` to 5.8.5 to patch [GHSA-247c-9743-5963](https://github.com/advisories/GHSA-247c-9743-5963) (CVE-2026-33806) and bumped `langsmith` from 0.5.6 to 0.5.18 across the `bedrock-agentcore` JS examples (#13496, #13513) - Bumped the AWS SDK group with 33 updates from 3.1017.0 to 3.1035.0 (#13526) and an additional 3 updates in `packages/framework-dist` (#13510) - Upgraded `https-proxy-agent` from 7.0.6 to 8.0.0 (major version bump — CJS to ESM conversion only, no API or behavior changes; transparent for the workspace which is already ESM) (#13535) - Upgraded `undici` from 6.24.1 to 6.25.0 in `packages/util` (#13536) and `packages/sf-core-installer` (#13519) - Upgraded `ws` from 8.19.0 to 8.20.0 (#13537) - Upgraded `@slack/web-api` from 7.14.1 to 7.15.1 (#13538) - Upgraded `@graphql-tools/merge` from 9.1.7 to 9.1.9 and bumped grouped patch updates including `adm-zip`, `eventsource-parser`, and `filesize` (#13532) - Upgraded `pytest` from 8.4.2 to 9.0.3 in the uv test fixtures (#13503) - Upgraded `golang.org/x/mod` from 0.34.0 to 0.35.0 in `binary-installer` (#13518) ### sf-core@4.34.0 — 4.34.0 - Date: 2026-04-10 - Version: sf-core@4.34.0 - Original notes: https://github.com/serverless/serverless/releases/tag/sf-core%404.34.0 - Permalink: https://whatsnew.fyi/product/serverless/releases/sf-core-4.34.0 ##### Features ###### Serverless Framework - **Added S3 Files support for Lambda file system configuration.** Lambda functions can now mount Amazon S3 Files in addition to EFS via `fileSystemConfig`. The file system type is auto-detected from literal ARNs; for CloudFormation references, specify `type: s3files` explicitly. The framework automatically generates the correct IAM permissions (`s3files:ClientMount`/`s3files:ClientWrite`) and validates VPC configuration. Fully backward compatible — existing EFS configurations work unchanged. Read more in the [docs](https://www.serverless.com/framework/docs/providers/aws/guide/functions#file-system-configuration). (#13493) ```yaml functions: hello: handler: handler.hello fileSystemConfig: localMountPath: /mnt/s3data arn: arn:aws:s3files:us-east-1:111111111111:file-system/fs-abc123/access-point/fsap-abc123 vpc: securityGroupIds: - sg-xxx subnetIds: - subnet-xxx ``` When using CloudFormation references, set the `type` explicitly: ```yaml functions: hello: handler: handler.hello fileSystemConfig: localMountPath: /mnt/s3data arn: !GetAtt MyS3FilesAccessPoint.AccessPointArn type: s3files vpc: securityGroupIds: - sg-xxx subnetIds: - subnet-xxx ``` ##### Bug Fixes ###### Serverless Framework - **Fixed `min-release-age` not being applied during framework distribution builds.** The root `.npmrc` was silently ignored by npm because it reads project config from the nearest `package.json` directory. Added per-package `.npmrc` files to `packages/framework-dist` and `packages/sf-core-installer` to enforce a 3-day cooldown on newly published dependencies. Also added `check-latest: true` to CI `setup-node` steps to ensure consistent npm versions across runners. (#13476) ##### Maintenance - Upgraded Go from 1.26.1 to 1.26.2 in `binary-installer` to fix 5 vulnerabilities in `std/crypto/tls`, `std/crypto/x509`, and `std/archive/tar` (#13492) - Upgraded `hono` to 4.12.12 and `@hono/node-server` to 1.19.13 to fix 6 security vulnerabilities including middleware bypass via repeated slashes (GHSA-wmmm-f939-6g9c, GHSA-92pp-h63x-v22m), path traversal in toSSG() (GHSA-xf4j-xp2r-rqqx), incorrect IP matching (GHSA-xpcf-pg52-r92g), and cookie handling bypasses (GHSA-26pp-8wgv-hjvm, GHSA-r5rp-j6wh-rvv4). Upgraded `Pygments` to 2.20.0 to fix a ReDoS vulnerability (#13489) - Upgraded eslint to v10 and @eslint/js to v10 (#13477)