sf-core@4.41.0
4.41.0
Added 1
- Host MCP servers on AWS Lambda with a new `mcp` section in `serverless.yml` that deploys official MCP TypeScript SDK servers behind API Gateway with response streaming, OAuth protection, and shared REST API, stage, and custom domain with http functions
Changed 9
- Upgraded AWS SDK group with 150 updates across four bumps
- Upgraded glob to v13
- Upgraded @hono/node-server to v2
- Upgraded hono to v4.13
- Upgraded @modelcontextprotocol/sdk
- Upgraded fs-extra to v11.4
- Upgraded js-yaml to v4.3.1
- Replaced lodash.uniqby with lodash's uniqBy
- Replaced sha256-file with node:crypto
Fixed 9
- Per-function artifacts are now included in change detection so deployments that only changed a prebuilt per-function `package.artifact` are no longer silently skipped
- Compose `package` and `print` commands no longer wipe deployed service state and clear recorded outputs of already-deployed services
- Files named like code modules no longer hijack project detection by restricting SAM/CloudFormation template detection to SAM-supported template extensions
- esbuild `outExtension` is honored end-to-end through bundling, packaging, deployment, and `invoke local` with clear validation for unsupported mappings
- esbuild config-file `sourcemap` setting now controls source-map support instead of force-enabling `--enable-source-maps` in the function's `NODE_OPTIONS`
- Compose services with `packages: external` now resolve root dependencies that are hoisted to the Compose project root
- Function URL `invokeMode` accepts any casing and normalizes values like `response_stream` or `Buffered` instead of failing validation
- Sandbox dev images build for the Docker daemon's architecture instead of the host architecture
- No spinner animations on zero-width terminals to prevent CI providers from being flooded with spinner frames
Security 1
- Upgraded brace-expansion to resolve CVE-2026-14257 and CVE-2026-69152
4.41.0
Features
- Host MCP servers on AWS Lambda. A new
mcpsection inserverless.ymldeploys official MCP TypeScript SDK servers behind API Gateway with response streaming. You write one SDK module; the Framework owns the endpoint, streaming, packaging, and the OAuth protected-resource discovery document. Servers can be protected with your own API Gateway authorizers or with the MCP SDK's built-in in-server token verification, and each server behaves as an ordinary function —logs,invoke,metrics,rollback, anddeploy functionwork unchanged. MCP servers share one REST API, stage, and custom domain with each other and withhttpfunctions. Optional sealed request state lets tools round-trip data across elicitation retries without server-side storage. (#13778, #13784) Read more in the MCP servers guide and explore the MCP examples. A bundledserverless-mcpAgent Skill teaches AI coding agents (Claude Code, Codex, Cursor) how to build and operate MCP servers with the Framework — install it into your service with theagent skills installcommand:
serverless agent skills install
mcp:
servers:
crm:
server: src/server.mjs
authorizer:
name: verifyToken
oauthDiscovery:
issuer: https://example.us.auth0.com
functions:
verifyToken:
handler: src/authorizer.handler
Bug Fixes
- Per-function artifacts are now included in change detection. Deployments that only changed a prebuilt per-function
package.artifactwere silently skipped, so new code never shipped; the artifact content now participates in the change hash. (#13771) - Compose
packageandprintno longer wipe deployed service state. Running a read-only command in a Compose project cleared the recorded outputs of already-deployed services, breaking later cross-service references and removals. Thanks @tmatilai for the detailed report. (#13437, #13792) - Files named like code modules no longer hijack project detection. A
template.mjsin the project root made the CLI treat the directory as a SAM/CloudFormation project and hide normal commands; detection is now restricted to SAM-supported template extensions. Thanks @tomchiverton for the report. (#13738, #13739) - esbuild
outExtensionis honored end-to-end. Custom output extensions (e.g..js→.mjs) now flow through bundling, packaging, deployment, andinvoke local, with clear validation for unsupported mappings. (#13740) - esbuild config-file
sourcemapsetting controls source-map support. Withsourcemap: falsein an esbuild config file, the Framework no longer force-enables--enable-source-mapsin the function'sNODE_OPTIONS. Thanks @maximepichou for the report. (#12997, #13741) - Compose services with
packages: externalresolve root dependencies. Dependencies hoisted to the Compose project root are now traced and packaged when a service's esbuild config marks packages external. Thanks @joe-price-jt for the report. (#12957, #13742) - Function URL
invokeModeaccepts any casing. Values likeresponse_streamorBufferedare now normalized instead of failing validation. (#13756) - Sandbox dev images build for the Docker daemon's architecture. Dev images previously targeted the host architecture, producing emulated (slow or failing) containers when the daemon reported a different one. (#13787)
- No spinner animations on zero-width terminals. CI providers that report a zero-column terminal (e.g. CircleCI) were flooded with spinner frames; animations now stay disabled there. Thanks @Kinnersley-Studio for the report. (#13786, #13788)
Maintenance
- Bumped the AWS SDK group with 150 updates across four bumps (#13732, #13752, #13767, #13780)
- Upgraded glob to v13 (#13766)
- Upgraded @hono/node-server to v2 (#13763)
- Upgraded hono to v4.13 (#13774, #13759)
- Upgraded @modelcontextprotocol/sdk (#13759)
- Upgraded fs-extra to v11.4 (#13769)
- Upgraded find-my-way (#13745)
- Upgraded ip-address to v10.4 (#13772)
- Upgraded fast-uri (#13775)
- Upgraded p-map (#13754)
- Upgraded js-yaml to v4.3.1 (#13789)
- Upgraded brace-expansion, resolving CVE-2026-14257 and CVE-2026-69152 (#13757, #13764, #13777)
- Upgraded minimatch and undici (#13764)
- Replaced lodash.uniqby with lodash's uniqBy (#13750)
- Replaced sha256-file with node:crypto (#13748)
- Removed the appdirectory dependency (#13749)
- Removed the rimraf dependency from the installer (#13765)
- Removed unused dependencies (#13747)