Download Latest Version 4.41.0 source code.zip (4.2 MB)
Email in envelope

Get an email when there's a new version of Serverless Framework

Home / sf-core@4.41.0
Name Modified Size InfoDownloads / Week
Parent folder
4.41.0 source code.tar.gz 2026-08-10 2.8 MB
4.41.0 source code.zip 2026-08-10 4.2 MB
README.md 2026-08-10 5.1 kB
Totals: 3 Items   7.0 MB 0

4.41.0

Features

  • Host MCP servers on AWS Lambda. A new mcp section in serverless.yml deploys official MCP TypeScript SDK servers behind API Gateway with response streaming. You write one SDK module; the Framework owns the endpoint, streaming, packaging, and the OAuth protected-resource discovery document. Servers can be protected with your own API Gateway authorizers or with the MCP SDK's built-in in-server token verification, and each server behaves as an ordinary function — logs, invoke, metrics, rollback, and deploy function work unchanged. MCP servers share one REST API, stage, and custom domain with each other and with http functions. Optional sealed request state lets tools round-trip data across elicitation retries without server-side storage. (#13778, [#13784]) Read more in the MCP servers guide and explore the MCP examples. A bundled serverless-mcp Agent Skill teaches AI coding agents (Claude Code, Codex, Cursor) how to build and operate MCP servers with the Framework — install it into your service with the agent skills install command:

    :::bash serverless agent skills install

    :::yaml mcp: servers: crm: server: src/server.mjs authorizer: name: verifyToken oauthDiscovery: issuer: https://example.us.auth0.com

    functions: verifyToken: handler: src/authorizer.handler

Bug Fixes

  • Per-function artifacts are now included in change detection. Deployments that only changed a prebuilt per-function package.artifact were silently skipped, so new code never shipped; the artifact content now participates in the change hash. (#13771)
  • Compose package and print no longer wipe deployed service state. Running a read-only command in a Compose project cleared the recorded outputs of already-deployed services, breaking later cross-service references and removals. Thanks @tmatilai for the detailed report. (#13437, [#13792])
  • Files named like code modules no longer hijack project detection. A template.mjs in the project root made the CLI treat the directory as a SAM/CloudFormation project and hide normal commands; detection is now restricted to SAM-supported template extensions. Thanks @tomchiverton for the report. (#13738, [#13739])
  • esbuild outExtension is honored end-to-end. Custom output extensions (e.g. .js.mjs) now flow through bundling, packaging, deployment, and invoke local, with clear validation for unsupported mappings. (#13740)
  • esbuild config-file sourcemap setting controls source-map support. With sourcemap: false in an esbuild config file, the Framework no longer force-enables --enable-source-maps in the function's NODE_OPTIONS. Thanks @maximepichou for the report. (#12997, [#13741])
  • Compose services with packages: external resolve root dependencies. Dependencies hoisted to the Compose project root are now traced and packaged when a service's esbuild config marks packages external. Thanks @joe-price-jt for the report. (#12957, [#13742])
  • Function URL invokeMode accepts any casing. Values like response_stream or Buffered are now normalized instead of failing validation. (#13756)
  • Sandbox dev images build for the Docker daemon's architecture. Dev images previously targeted the host architecture, producing emulated (slow or failing) containers when the daemon reported a different one. (#13787)
  • No spinner animations on zero-width terminals. CI providers that report a zero-column terminal (e.g. CircleCI) were flooded with spinner frames; animations now stay disabled there. Thanks @Kinnersley-Studio for the report. (#13786, [#13788])

Maintenance

  • Bumped the AWS SDK group with 150 updates across four bumps (#13732, [#13752], [#13767], [#13780])
  • Upgraded glob to v13 (#13766)
  • Upgraded @hono/node-server to v2 (#13763)
  • Upgraded hono to v4.13 (#13774, [#13759])
  • Upgraded @modelcontextprotocol/sdk (#13759)
  • Upgraded fs-extra to v11.4 (#13769)
  • Upgraded find-my-way (#13745)
  • Upgraded ip-address to v10.4 (#13772)
  • Upgraded fast-uri (#13775)
  • Upgraded p-map (#13754)
  • Upgraded js-yaml to v4.3.1 (#13789)
  • Upgraded brace-expansion, resolving CVE-2026-14257 and CVE-2026-69152 (#13757, [#13764], [#13777])
  • Upgraded minimatch and undici (#13764)
  • Replaced lodash.uniqby with lodash's uniqBy (#13750)
  • Replaced sha256-file with node:crypto (#13748)
  • Removed the appdirectory dependency (#13749)
  • Removed the rimraf dependency from the installer (#13765)
  • Removed unused dependencies (#13747)
Source: README.md, updated 2026-08-10