Skip to content

Bump serverless from 4.42.0 to 4.43.0 in /serverless - #546

Merged
Tsingis merged 1 commit into
mainfrom
dependabot/npm_and_yarn/serverless/serverless-4.43.0
Oct 1, 2026
Merged

Tsingis merged 1 commit into
mainfrom
dependabot/npm_and_yarn/serverless/serverless-4.43.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps serverless from 4.42.0 to 4.43.0.

Release notes

Sourced from serverless's releases.

4.43.0

Features

  • AI coding agents can set up and use the Serverless Framework on their own. serverless agent setup installs the bundled Agent Skills — the serverless-framework skill into your home directory for every agent session, and the feature skills into the service you run it in — and prints an environment report: whether you are signed in, which AWS credentials a deploy would use (the resolver or profile, whether its SSO session has expired, and the stages it did not check), and whether the directory has a serverless.yml, each failing line with its one-line fix. It needs no sign-in and no AWS credentials, and it is safe to re-run. serverless agent docs prints the documentation that ships with the installed CLI, offline, and serverless agent skills list / serverless agent skills read print the bundled skills without installing them; these commands work anywhere, including next to a serverless.yml that does not load. Getting Started now has a prompt to paste into Claude Code, Codex, Cursor or any agent that runs terminal commands. (#13897) Read more in For AI coding agents, the agent setup, agent docs and agent skills references, and the Agent Skills guide.
serverless agent setup                          # skills + environment report
serverless agent setup --stage prod --dir claude # check another stage, write only .claude/skills
serverless agent docs providers/aws/guide/functions
serverless agent skills read serverless-upgrade

The bundled skills in this release:

  • serverless-framework (new) — start-here rules, a first-deploy checklist, and references for the CLI, the development workflow, multi-service projects, Python and serverless.yml.
  • serverless-upgrade (new) — upgrades v1–v3 services to v4 without changing what deploys: a before/after template comparison, required changes kept apart from optional improvements, and plugin replacements.
  • serverless-mcp and serverless-sandboxes — accuracy and clarity updates. Installed skills update themselves after the next command a newer Framework runs (the agent commands, --help and --version leave them alone).

Function packages leave out the skills that agent setup writes into a service (.claude/skills/serverless-* and .agents/skills/serverless-*), so they never reach your Lambda artifacts; other files in those directories are packaged as before, and package.patterns can include the skills again.

  • serverless login works without a terminal, and --org picks your default org. Run from an agent or a script, serverless login prints the sign-in URL and waits up to 10 minutes for you to open it; with an existing session it reports that session and exits. In CI without a key it fails at once and names SERVERLESS_ACCESS_KEY and SERVERLESS_LICENSE_KEY. serverless login --org <name> sets the default org, switching an existing session without signing in again. --help for built-in commands now works before signing in, and commands that need a sign-in say so in one line naming serverless login and both keys, without a stack trace. (#13897) Read more in the login reference and Running in your own CI/CD.
serverless login --org acme-platform
  • Sandboxes and agents inherit provider.environment, and sandbox environment variables accept CloudFormation references. A sandbox or agent now receives every provider.environment variable, with its own keys taking precedence, exactly as functions do. Sandbox values can be CloudFormation references (!Ref, !GetAtt, !ImportValue, !Sub, …) resolved when the stack deploys — previously they reached the image as the text [object Object] — and vpc.subnetIds / vpc.securityGroupIds accept the same shapes as a function's vpc, including a single !Split expression. serverless dev --sandbox runs the local container with the same merged environment. Thanks @​Hi-Fi for the report. (#13876, #13881) Read more in the Sandboxes guide and the agents runtime guide.
provider:
  environment:
    LOG_LEVEL: warn # now reaches every function, agent and sandbox
sandboxes:
  renderer:
    artifact: ./renderer
    environment:
      JOBS_TABLE: !Ref JobsTable # resolved at deploy time

Note A sandbox or agent in a service that already sets provider.environment receives those variables on its next deploy; each sandbox builds a new image version once.

  • Warnings for Lambda runtimes AWS has deprecated. package and deploy now warn when a function uses a runtime past its AWS deprecation date — for example nodejs20.x or python3.9 — and say when Lambda stops allowing new functions and updates on it. Services that set no runtime get nodejs20.x, the default, and see the warning too; set provider.runtime to a supported runtime such as nodejs24.x to clear it. (#13897) Read more in the functions guide.

Bug Fixes

  • Python dependencies keep their compiled bytecode on Lambda, cutting cold starts by about 40%. Every dependency .pyc that pip compiled was stale by the time it reached Lambda, because packaging pins every zip entry to a fixed date so unchanged code is not redeployed; Python recompiled all of them on every cold start. Dependencies are now installed with SOURCE_DATE_EPOCH set, so pip writes hash-based .pyc files that stay valid (Python 3.7 and later; a value you set yourself is kept). Existing projects get the new bytecode on their first package after upgrading: the requirements are installed once more, without serverless requirements cleanCache, and the next deploy updates each function's code once. Thanks @​juanjsebgarcia for the report, the measurements, and the fix! (#13889, #13888) Read more in the Python guide.
  • serverless remove empties versioned deployment buckets. A service using the in-stack deployment bucket with deploymentBucket.versioning: true — required by codeStorageMode: reference — ended in DELETE_FAILED, because the object versions stayed in the bucket. remove now deletes every version and delete marker of the service's artifacts, reads the bucket's real versioning state (including buckets where versioning was later suspended), pages through large deployment prefixes, and no longer touches the artifacts of a sibling stage such as dev2 when removing dev. The misleading "S3 bucket not found. Skipping S3 bucket objects removal" notices are gone. (#13878) Read more in the remove reference.
  • esbuild packaging works in git worktrees and submodules again. A service directory whose .git is a file failed with ENOTDIR: not a directory, stat '<service>/.git/**' when it used package.patterns or build.esbuild.bundle: false. Thanks @​jamesclancy for the report. (#13877, #13880)

... (truncated)

Commits
  • bd2e5cc chore: release 4.43.0 (#13899)
  • 9952cdf feat: onboard AI coding agents with agent setup, docs and bundled skills (#13...
  • df6c1dd docs(appsync): add missing Substitutions page (#13896)
  • e35dd3f fix(aws): fully empty versioned deployment buckets on remove (#13878)
  • 17f9e07 chore(deps-dev): bump the dev-dependencies group across 1 directory with 4 up...
  • adc76e3 chore(deps): bump the aws-sdk group across 1 directory with 34 updates (#13894)
  • be51f62 chore(deps): bump aws-actions/configure-aws-credentials (#13893)
  • 2808fed chore(deps): bump the aws-sdk group across 1 directory with 38 updates (#13891)
  • bf14c3b chore(bedrock-agentcore): remove in-repo examples and link the examples repos...
  • 1ddc660 chore(deps-dev): bump the dev-dependencies group across 1 directory with 2 up...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [serverless](https://github.com/serverless/serverless) from 4.42.0 to 4.43.0.
- [Release notes](https://github.com/serverless/serverless/releases)
- [Changelog](https://github.com/serverless/serverless/blob/main/RELEASE_PROCESS.md)
- [Commits](https://github.com/serverless/serverless/compare/sf-core@4.42.0...sf-core@4.43.0)

---
updated-dependencies:
- dependency-name: serverless
  dependency-version: 4.43.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@Tsingis
Tsingis merged commit 56ed30d into main Oct 1, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/serverless/serverless-4.43.0 branch October 1, 2026 19:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant