serverless sf-core@4.41.0

sf-core@4.41.0

4.41.0

Added 1
  • Host MCP servers on AWS Lambda with a new `mcp` section in `serverless.yml` that deploys official MCP TypeScript SDK servers behind API Gateway with response streaming, OAuth protection, and shared REST API, stage, and custom domain with http functions
Changed 9
  • Upgraded AWS SDK group with 150 updates across four bumps
  • Upgraded glob to v13
  • Upgraded @hono/node-server to v2
  • Upgraded hono to v4.13
  • Upgraded @modelcontextprotocol/sdk
  • Upgraded fs-extra to v11.4
Fixed 9
  • Per-function artifacts are now included in change detection so deployments that only changed a prebuilt per-function `package.artifact` are no longer silently skipped
  • Compose `package` and `print` commands no longer wipe deployed service state and clear recorded outputs of already-deployed services
  • Files named like code modules no longer hijack project detection by restricting SAM/CloudFormation template detection to SAM-supported template extensions
  • esbuild `outExtension` is honored end-to-end through bundling, packaging, deployment, and `invoke local` with clear validation for unsupported mappings
  • esbuild config-file `sourcemap` setting now controls source-map support instead of force-enabling `--enable-source-maps` in the function's `NODE_OPTIONS`
  • Compose services with `packages: external` now resolve root dependencies that are hoisted to the Compose project root
Security 1
  • Upgraded brace-expansion to resolve CVE-2026-14257 and CVE-2026-69152

4.41.0

Features
  • Host MCP servers on AWS Lambda. A new mcp section in serverless.yml deploys official MCP TypeScript SDK servers behind API Gateway with response streaming. You write one SDK module; the Framework owns the endpoint, streaming, packaging, and the OAuth protected-resource discovery document. Servers can be protected with your own API Gateway authorizers or with the MCP SDK's built-in in-server token verification, and each server behaves as an ordinary function — logs, invoke, metrics, rollback, and deploy function work unchanged. MCP servers share one REST API, stage, and custom domain with each other and with http functions. Optional sealed request state lets tools round-trip data across elicitation retries without server-side storage. (#13778, #13784) Read more in the MCP servers guide and explore the MCP examples. A bundled serverless-mcp Agent Skill teaches AI coding agents (Claude Code, Codex, Cursor) how to build and operate MCP servers with the Framework — install it into your service with the agent skills install command:
serverless agent skills install
mcp:
  servers:
    crm:
      server: src/server.mjs
      authorizer:
        name: verifyToken
      oauthDiscovery:
        issuer: https://example.us.auth0.com

functions:
  verifyToken:
    handler: src/authorizer.handler
Bug Fixes
  • Per-function artifacts are now included in change detection. Deployments that only changed a prebuilt per-function package.artifact were silently skipped, so new code never shipped; the artifact content now participates in the change hash. (#13771)
  • Compose package and print no longer wipe deployed service state. Running a read-only command in a Compose project cleared the recorded outputs of already-deployed services, breaking later cross-service references and removals. Thanks @tmatilai for the detailed report. (#13437, #13792)
  • Files named like code modules no longer hijack project detection. A template.mjs in the project root made the CLI treat the directory as a SAM/CloudFormation project and hide normal commands; detection is now restricted to SAM-supported template extensions. Thanks @tomchiverton for the report. (#13738, #13739)
  • esbuild outExtension is honored end-to-end. Custom output extensions (e.g. .js.mjs) now flow through bundling, packaging, deployment, and invoke local, with clear validation for unsupported mappings. (#13740)
  • esbuild config-file sourcemap setting controls source-map support. With sourcemap: false in an esbuild config file, the Framework no longer force-enables --enable-source-maps in the function's NODE_OPTIONS. Thanks @maximepichou for the report. (#12997, #13741)
  • Compose services with packages: external resolve root dependencies. Dependencies hoisted to the Compose project root are now traced and packaged when a service's esbuild config marks packages external. Thanks @joe-price-jt for the report. (#12957, #13742)
  • Function URL invokeMode accepts any casing. Values like response_stream or Buffered are now normalized instead of failing validation. (#13756)
  • Sandbox dev images build for the Docker daemon's architecture. Dev images previously targeted the host architecture, producing emulated (slow or failing) containers when the daemon reported a different one. (#13787)
  • No spinner animations on zero-width terminals. CI providers that report a zero-column terminal (e.g. CircleCI) were flooded with spinner frames; animations now stay disabled there. Thanks @Kinnersley-Studio for the report. (#13786, #13788)
Maintenance
  • Bumped the AWS SDK group with 150 updates across four bumps (#13732, #13752, #13767, #13780)
  • Upgraded glob to v13 (#13766)
  • Upgraded @hono/node-server to v2 (#13763)
  • Upgraded hono to v4.13 (#13774, #13759)
  • Upgraded @modelcontextprotocol/sdk (#13759)
  • Upgraded fs-extra to v11.4 (#13769)
  • Upgraded find-my-way (#13745)
  • Upgraded ip-address to v10.4 (#13772)
  • Upgraded fast-uri (#13775)
  • Upgraded p-map (#13754)
  • Upgraded js-yaml to v4.3.1 (#13789)
  • Upgraded brace-expansion, resolving CVE-2026-14257 and CVE-2026-69152 (#13757, #13764, #13777)
  • Upgraded minimatch and undici (#13764)
  • Replaced lodash.uniqby with lodash's uniqBy (#13750)
  • Replaced sha256-file with node:crypto (#13748)
  • Removed the appdirectory dependency (#13749)
  • Removed the rimraf dependency from the installer (#13765)
  • Removed unused dependencies (#13747)
View original

Upgraded? How did it go?

Discussion