Skip to content

Bump the "container" group with 1 update across multiple ecosystems - #85

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/container-c863bb128a
Open

Bump the "container" group with 1 update across multiple ecosystems#85
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/container-c863bb128a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the container group in /container with 2 updates: @aws-sdk/region-config-resolver and serverless.

Updates @aws-sdk/region-config-resolver from 3.972.15 to 3.972.46

Changelog

Sourced from @​aws-sdk/region-config-resolver's changelog.

3.972.46 (2026-08-11)

Chores

3.972.45 (2026-08-04)

Chores

  • region-config-resolver: update dependencies.

3.972.44 (2026-08-03)

Chores

  • region-config-resolver: update dependencies.

3.972.43 (2026-07-31)

Chores

  • region-config-resolver: update dependencies.

3.972.42 (2026-07-29)

Chores

  • region-config-resolver: update dependencies.

3.972.41 (2026-07-28)

Chores

  • region-config-resolver: update dependencies.

3.972.40 (2026-07-27)

Chores

  • region-config-resolver: update dependencies.

3.972.39 (2026-07-24)

Chores

  • region-config-resolver: update dependencies.

3.972.38 (2026-07-21)

Chores

... (truncated)

Commits

Updates serverless from 3.40.0 to 4.41.0

Release notes

Sourced from serverless's releases.

4.41.0

Features

  • Host MCP servers on AWS Lambda. A new mcp section in serverless.yml deploys official MCP TypeScript SDK servers behind API Gateway with response streaming. You write one SDK module; the Framework owns the endpoint, streaming, packaging, and the OAuth protected-resource discovery document. Servers can be protected with your own API Gateway authorizers or with the MCP SDK's built-in in-server token verification, and each server behaves as an ordinary function — logs, invoke, metrics, rollback, and deploy function work unchanged. MCP servers share one REST API, stage, and custom domain with each other and with http functions. Optional sealed request state lets tools round-trip data across elicitation retries without server-side storage. (#13778, #13784) Read more in the MCP servers guide and explore the MCP examples. A bundled serverless-mcp Agent Skill teaches AI coding agents (Claude Code, Codex, Cursor) how to build and operate MCP servers with the Framework — install it into your service with the agent skills install command:
serverless agent skills install
mcp:
  servers:
    crm:
      server: src/server.mjs
      authorizer:
        name: verifyToken
      oauthDiscovery:
        issuer: https://example.us.auth0.com
functions:
verifyToken:
handler: src/authorizer.handler

Bug Fixes

  • Per-function artifacts are now included in change detection. Deployments that only changed a prebuilt per-function package.artifact were silently skipped, so new code never shipped; the artifact content now participates in the change hash. (#13771)
  • Compose package and print no longer wipe deployed service state. Running a read-only command in a Compose project cleared the recorded outputs of already-deployed services, breaking later cross-service references and removals. Thanks @​tmatilai for the detailed report. (#13437, #13792)
  • Files named like code modules no longer hijack project detection. A template.mjs in the project root made the CLI treat the directory as a SAM/CloudFormation project and hide normal commands; detection is now restricted to SAM-supported template extensions. Thanks @​tomchiverton for the report. (#13738, #13739)
  • esbuild outExtension is honored end-to-end. Custom output extensions (e.g. .js.mjs) now flow through bundling, packaging, deployment, and invoke local, with clear validation for unsupported mappings. (#13740)
  • esbuild config-file sourcemap setting controls source-map support. With sourcemap: false in an esbuild config file, the Framework no longer force-enables --enable-source-maps in the function's NODE_OPTIONS. Thanks @​maximepichou for the report. (#12997, #13741)
  • Compose services with packages: external resolve root dependencies. Dependencies hoisted to the Compose project root are now traced and packaged when a service's esbuild config marks packages external. Thanks @​joe-price-jt for the report. (#12957, #13742)
  • Function URL invokeMode accepts any casing. Values like response_stream or Buffered are now normalized instead of failing validation. (#13756)
  • Sandbox dev images build for the Docker daemon's architecture. Dev images previously targeted the host architecture, producing emulated (slow or failing) containers when the daemon reported a different one. (#13787)
  • No spinner animations on zero-width terminals. CI providers that report a zero-column terminal (e.g. CircleCI) were flooded with spinner frames; animations now stay disabled there. Thanks @​Kinnersley-Studio for the report. (#13786, #13788)

Maintenance

... (truncated)

Commits
  • d20837c chore: release 4.41.0 (#13793)
  • 7c8c59f fix(compose): stop package and print from wiping deployed service state (#13792)
  • d9d6868 ci(binary-installer): sign windows binary with Azure Artifact Signing (#13791)
  • 8ae60cd chore(deps): bump js-yaml from 3.15.0 to 3.15.1 (#13790)
  • 5931987 chore(deps): bump js-yaml from 4.3.0 to 4.3.1 (#13789)
  • 4b3753a feat(mcp): user-supplied authorizers and OAuth discovery for MCP servers (#13...
  • 183f25e fix(sandboxes): build dev images for the Docker daemon's architecture (#13787)
  • 469e819 fix(cli): never enable spinner animations on zero-width terminals (#13788)
  • 7fbc70d chore(deps): bump the aws-sdk group across 1 directory with 37 updates (#13780)
  • 4da6754 chore(deps): bump tsx in the patch-updates group across 1 directory (#13782)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for serverless since your current version.

Install script changes

This version modifies postinstall script that runs during installation. Review the package contents before updating.


Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
serverless [< 5, > 4.41.0]

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the container group in /container with 2 updates: [@aws-sdk/region-config-resolver](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/region-config-resolver) and [serverless](https://github.com/serverless/serverless).


Updates `@aws-sdk/region-config-resolver` from 3.972.15 to 3.972.46
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/region-config-resolver/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/region-config-resolver)

Updates `serverless` from 3.40.0 to 4.41.0
- [Release notes](https://github.com/serverless/serverless/releases)
- [Changelog](https://github.com/serverless/serverless/blob/main/RELEASE_PROCESS.md)
- [Commits](https://github.com/serverless/serverless/compare/v3.40.0...sf-core@4.41.0)

---
updated-dependencies:
- dependency-name: "@aws-sdk/region-config-resolver"
  dependency-version: 3.972.46
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: container
- dependency-name: serverless
  dependency-version: 4.41.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: container
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 17, 2026
@luhenry

luhenry commented Aug 17, 2026

Copy link
Copy Markdown
Member

@dependabot ignore serverless major version

@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you about version 4.x.x of serverless again, unless you unignore it.

@luhenry

luhenry commented Aug 17, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

1 similar comment
@luhenry

luhenry commented Aug 17, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant