4.41.0
Features
- Host MCP servers on AWS Lambda. A new
mcp section in serverless.yml deploys official MCP TypeScript SDK servers behind API Gateway with response streaming. You write one SDK module; the Framework owns the endpoint, streaming, packaging, and the OAuth protected-resource discovery document. Servers can be protected with your own API Gateway authorizers or with the MCP SDK's built-in in-server token verification, and each server behaves as an ordinary function — logs, invoke, metrics, rollback, and deploy function work unchanged. MCP servers share one REST API, stage, and custom domain with each other and with http functions. Optional sealed request state lets tools round-trip data across elicitation retries without server-side storage. (#13778, #13784) Read more in the MCP servers guide and explore the MCP examples. A bundled serverless-mcp Agent Skill teaches AI coding agents (Claude Code, Codex, Cursor) how to build and operate MCP servers with the Framework — install it into your service with the agent skills install command:
serverless agent skills install
mcp:
servers:
crm:
server: src/server.mjs
authorizer:
name: verifyToken
oauthDiscovery:
issuer: https://example.us.auth0.com
functions:
verifyToken:
handler: src/authorizer.handler
Bug Fixes
- Per-function artifacts are now included in change detection. Deployments that only changed a prebuilt per-function
package.artifact were silently skipped, so new code never shipped; the artifact content now participates in the change hash. (#13771)
- Compose
package and print no longer wipe deployed service state. Running a read-only command in a Compose project cleared the recorded outputs of already-deployed services, breaking later cross-service references and removals. Thanks @tmatilai for the detailed report. (#13437, #13792)
- Files named like code modules no longer hijack project detection. A
template.mjs in the project root made the CLI treat the directory as a SAM/CloudFormation project and hide normal commands; detection is now restricted to SAM-supported template extensions. Thanks @tomchiverton for the report. (#13738, #13739)
- esbuild
outExtension is honored end-to-end. Custom output extensions (e.g. .js → .mjs) now flow through bundling, packaging, deployment, and invoke local, with clear validation for unsupported mappings. (#13740)
- esbuild config-file
sourcemap setting controls source-map support. With sourcemap: false in an esbuild config file, the Framework no longer force-enables --enable-source-maps in the function's NODE_OPTIONS. Thanks @maximepichou for the report. (#12997, #13741)
- Compose services with
packages: external resolve root dependencies. Dependencies hoisted to the Compose project root are now traced and packaged when a service's esbuild config marks packages external. Thanks @joe-price-jt for the report. (#12957, #13742)
- Function URL
invokeMode accepts any casing. Values like response_stream or Buffered are now normalized instead of failing validation. (#13756)
- Sandbox dev images build for the Docker daemon's architecture. Dev images previously targeted the host architecture, producing emulated (slow or failing) containers when the daemon reported a different one. (#13787)
- No spinner animations on zero-width terminals. CI providers that report a zero-column terminal (e.g. CircleCI) were flooded with spinner frames; animations now stay disabled there. Thanks @Kinnersley-Studio for the report. (#13786, #13788)
Maintenance