Download Latest Version 4.43.0 source code.zip (4.2 MB) Google Add to Preferred Sources
Home / sf-core@4.42.0
Name Modified Size InfoDownloads / Week
Parent folder
4.42.0 source code.tar.gz 2026-09-09 3.0 MB
4.42.0 source code.zip 2026-09-09 4.6 MB
README.md 2026-09-09 14.5 kB
Totals: 3 Items   7.6 MB 2

4.42.0

Features

  • Non-bundled esbuild services are packaged like classic packaging, with TypeScript compiled in place. With build.esbuild.bundle: false, the Framework now packages your whole service the way classic packaging does: locally imported helper files are compiled and included (previously only each handler file was), JavaScript and other files are copied as they are, the project layout is preserved, and every compiled file is emitted in the module format its nearest package.json declares (.mts → .mjs, .cts → .cjs). A new build.esbuild.tsconfig option selects which TypeScript compiles, function-level build: false is accepted as a boolean, and files that esbuild plugins write into the build directory now ship in the artifact. Thanks @visrut-at-handldigital and @ewsbr for the reports. (#12744, [#13163], [#13850]) Read more in the Building guide.

    :::yaml build: esbuild: bundle: false # optional — tsconfig.json is picked up automatically; point at a build-specific # config (for example one that excludes tests/**) to narrow what gets compiled tsconfig: tsconfig.build.json

  • Compose: reference other services through the variable system, including services deployed to a different stage. A new service resolver reads a service's outputs in serverless-compose.yml: ${service:<service>.<Output>} resolves at the current stage and deploys that service first; a named instance with a stage pins the stage, so application services on personal stages can read a database service that lives once on a shared stage. References accept fallbacks and nesting like any other variable, configuration mistakes are reported before anything deploys, and the existing ${<service>.<Output>} form keeps working unchanged. (#13843) Read more in the Compose guide and try the shared-services Compose example.

    :::yaml

    serverless-compose.yml

    stages: default: resolvers: shared: type: service stage: shared-infra # the long-lived stage where orders-db lives

    services: orders-db: path: orders-db api: path: api params: tableName: ${service:orders-db.TableName} # same stage as this run; deploys orders-db first dbHost: ${shared:orders-db.Host} # read from orders-db@shared-infra, without deploying it here

  • AWS variable resolvers make fewer requests and retry throttling. ${cf:stackName.outputKey} now issues one DescribeStacks call per stack per run instead of one per referenced output — services deployed together with Compose share those calls, and cached reads are refreshed after each Compose service deploy — and ${aws:accountId} is resolved once per run. All AWS resolvers (${cf:}, ${ssm:}, ${s3:}, ${aws:accountId}) retry throttled requests with the AWS SDK's standard exponential backoff, up to 10 attempts by default; AWS_MAX_ATTEMPTS / AWS_RETRY_MODE and the matching ~/.aws/config keys take precedence. --verbose shows each retry, --debug prints a per-API request summary, and exhausted retries fail with a dedicated error naming the API, the attempts made, and the remediations. Expired credentials during variable resolution now produce the familiar "AWS credentials appear to have expired" message. (#13848) Read more in the CloudFormation outputs and SSM variable guides.

Note ${cf:stackName} without an output key is now rejected before any request is made (expected '<stackName>.<outputKey>'), instead of issuing a request and failing with a generic message. This also applies when a fallback is present: ${cf:stackName, 'default'} previously resolved to the fallback and now fails validation — write ${cf:stackName.outputKey, 'default'}.

  • Terraform state is read once per run. ${terraform:outputs:...} now downloads and parses each Terraform state once per run and shares it across every placeholder and every Compose service, instead of once per referenced output per service. The s3 backend retries throttled reads with the AWS SDK's standard backoff, resolves credentials once per process, and reads a state bucket in another region by following S3's redirect instead of failing with PermanentRedirect. Thanks @schammah for the detailed report. (#13844, [#13852]) Read more in the Terraform variables guide.

  • MCP servers run in Dev Mode. serverless dev now serves the MCP servers declared under mcp: requests hit the real deployed endpoint — streaming route, authorizer, OAuth discovery and state keys all live — and are answered by your local server module, with edits applied on the next request and no redeploy. The session banner lists each server's endpoint under mcp:, and every request is logged with its JSON-RPC method and target; a JSON-RPC error carried inside a 200 response is called out on the same line. (#13836) Read more in the serverless dev reference and the MCP servers guide; each MCP example now has a "Develop it live" section.

    :::text mcp: crm → https://abc123.execute-api.us-east-1.amazonaws.com/dev/crm/mcp ✔ Connected (Ctrl+C to cancel) → λ crm ── mcp tools/call get_weather ← λ crm (200) 640ms

  • Provisioned mode for sqs, kafka, and msk events. The new provisionedPollers event property enables AWS Lambda's provisioned mode for event source mappings: a dedicated pool of pollers with min/max bounds, plus group on kafka and msk to share poller capacity across mappings. provisionedPollers: false disables the mode on an existing mapping. Combining it with maximumConcurrency, or setting min above max, fails at packaging time instead of at deployment. Thanks @sra17 for the request. (#13024, [#13835]) Read more in the SQS, Kafka, and MSK event guides.

    :::yaml functions: worker: handler: handler.main events:

      - sqs:
          arn: arn:aws:sqs:us-east-1:123456789012:orders
          provisionedPollers:
            min: 2
            max: 50
    

Note Provisioned pollers are billed while the mapping exists. Removing the property does not disable the mode on an already-deployed mapping — set provisionedPollers: false to turn it off.

  • SnapStart for container-image functions. snapStart: true now documents and validates the container-image case: functions built on the AWS base images for Java 11+, Python 3.12+ and .NET 8+ need nothing else, other images declare readiness with the com.amazonaws.lambda.feature.snapstart="Allow" label or runtime hooks, and the guide explains how event sources reach the snapshot and what retained versions cost. Configuring snapStart with ephemeralStorageSize above 512 MB now fails at packaging, before any image is built or pushed. Thanks @iiro for the request. (#13834, [#13847]) Read more in the SnapStart section of the functions guide and try the container SnapStart example.

  • New Lambda runtimes, and durable functions on Java and .NET. The Amazon Linux 2023 Java runtimes java8.al2023, java11.al2023, and java17.al2023 — AWS's migration path off the Amazon Linux 2 Java runtimes — and the public-preview runtimes nodejs26.x and python3.15 are now accepted, including by invoke local. durableConfig now also works on Java 17+ and .NET 8+ runtimes. Thanks @mungojam for the request. (#13818, [#13819]) Read more in the functions guide.

    :::yaml functions: api: handler: com.example.Handler runtime: java17.al2023

Note nodejs26.x and python3.15 are public-preview runtimes on AWS and are not covered by AWS support or SLAs yet. Java and .NET runtimes do not include the durable execution SDK — ship it in your deployment package.

  • Sandboxes: customize the operator role. iam.operatorRole accepts the same customization object and external-role forms as iam.buildRole and iam.executionRole, which makes sandboxes on shared (RAM-shared) VPCs possible. Thanks @Hi-Fi for the contribution! (#13800, [#13808]) Read more in the Sandboxes guide.

    :::yaml sandboxes: api: artifact: ./app vpc: subnetIds: [subnet-0123456789abcdef0] securityGroupIds: [sg-0123456789abcdef0] iam: operatorRole: statements:

          - Effect: Allow
            Action: ec2:CreateNetworkInterface
            Resource: arn:aws:ec2:us-east-1:111122223333:subnet/subnet-0123456789abcdef0
    
  • Removed the serverless support command. The interactive support-ticket flow and the --summary / --ai / --github / --all report modes were built for a copy-paste workflow that AI coding assistants working directly in the service directory have replaced. serverless support now returns the standard command-not-found error, and the bug-report template asks for the framework version, a redacted serverless.yml, the command run, and its output instead. (#13820)

Bug Fixes

  • CloudFormation template URLs use regional S3 endpoints. Deployments passed the deployment bucket's template to CloudFormation through the legacy global s3.amazonaws.com endpoint. When CloudFormation's read of that template was denied by the caller's IAM policy, the failure surfaced as S3's redirect message ("The bucket you are attempting to access must be addressed using the specified endpoint") instead of the actual Access Denied. Template URLs now use s3.<region>.amazonaws.com, so the real cause is reported; --aws-s3-accelerate and the alerts external stack follow the same rule. (#6539, [#13829])
  • npm install no longer fails when the CLI download fails. The serverless npm package downloads the CLI during postinstall; blocked egress, an unconfigured proxy, or TLS interception previously aborted the whole npm install. The install now completes with a warning and the download is retried on the first serverless run, which still fails clearly if the download is impossible. Proxy settings from .npmrc (https-proxy, proxy, noproxy) are honored during installation when no proxy environment variables are set, error messages include the underlying network error, and a CLI terminated by a signal exits with 128 + signal instead of 0. (#13833) Read more in Installing behind a proxy or firewall.
  • --package paths at or above the service directory are rejected. serverless package --package . (or .., or an ancestor directory) emptied the service or parent directory before failing. Such paths now fail early with PACKAGE_PATH_CONTAINS_SERVICE and no files are touched; relative and sibling paths keep working. (#13853)
  • The credential-setup hint appears when no AWS credentials are found. With no provider.profile or --aws-profile configured, a missing-credentials error now ends with the setup hint ("Run serverless to set up AWS credentials…"); the hint stays off when a profile was chosen explicitly. (#13854)
  • A directory named like a configuration file no longer shadows the real one. A directory called serverless.yml next to a serverless.yaml file made the CLI pick the directory; only regular files are considered now. Thanks @cuishuang for the fix! (#13846)
  • Dev Mode labels SNS-triggered invocations correctly. Session logs showed aws:sqs: for SNS events; they now show aws:sns:. (#13836)
  • Resolver configuration errors show their intended messages again. Unknown keys in terraform, doppler, vault, and service resolver configurations report the allowed keys (for example Only 'bucket', 'key', and 'region' are allowed in the s3 backend configuration) instead of a generic "Unrecognized key". (#13852)
  • MCP server: the docs tool only reads inside the documentation directory, including through symbolic links; the service-summary tool's input schema now matches its implementation (cloudProvider), and service-wide error analysis includes Lambda log groups again. (#13851)

Maintenance

  • Bumped the AWS SDK group with 107 updates across three bumps (#13815, [#13823], [#13839])
  • Upgraded toml to v5 (#13838) — integer values in serverless.toml outside the 64-bit range now fail with a parse error instead of being silently rounded
  • Upgraded js-yaml to v4.3.2 (#13855)
  • Upgraded qs to v6.16.0 (#13827)
  • Upgraded fast-uri to v3.1.7 (#13831)
  • Upgraded undici to v6.28.1 (#13849)
  • Upgraded hono to v4.13.5 (#13805, [#13824])
  • Upgraded @aws-cdk/cloudformation-diff to v2.187.4 (#13814, [#13825])
  • Upgraded p-map to v7.0.7 (#13825)
  • Upgraded tsx to v4.23.13 (#13814, [#13825])
  • Upgraded dayjs to v1.11.23 (#13814)
  • Upgraded joi to v17.13.6 (#13814)
  • Upgraded eventsource-parser to v3.1.1 (#13814)
  • Upgraded @graphql-tools/merge to v9.2.3 (#13814)
  • Upgraded jackson-databind used by local Java invocation (#13813)
  • Upgraded jackson-core used by local Java invocation (#13811)
  • Upgraded jackson-datatype-joda used by local Java invocation (#13810)
  • Upgraded jest to v30.5.1 (#13840)
  • Upgraded lint-staged to v17.4.1 (#13840)
  • Upgraded eslint to v10.9.1 (#13824)
  • Upgraded globals to v17.11.0 (#13805)
  • Upgraded browserslist to v4.28.8 (#13822)
Source: README.md, updated 2026-09-09