chore(deps-dev): bump serverless from 3.39.0 to 4.15.1
Open
Number: #416
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Contributor
Comments: 0
Association: Contributor
Comments: 0
Created:
June 02, 2025 at 01:04 PM UTC
(5 months ago)
(5 months ago)
Updated:
June 02, 2025 at 01:04 PM UTC
(5 months ago)
(5 months ago)
Labels:
dependencies javascript
dependencies javascript
Description:
Bumps serverless from 3.39.0 to 4.15.1.
Release notes
Sourced from serverless's releases.
4.15.1
Bug Fixes
- Serverless Framework
- Fixes an error when using dashboards with alerts plugin.
- Logs a warning instead of an error if the user is using the external alerts plugin.
4.15.0
Features
- Serverless Framework
- Update and add the cloudwatch alerts plugin into the core.
Bug Fixes
Serverless Framework
- Default to dev stage if user specified the stage option without a value
Serverless Container Framework
- Handle when containers are not running during rebuild
4.14.4
Bug Fixes
- Serverless Framework
- Skip AWS credentials check on the
packagecommand if a deployment bucket name is explicitly set viaprovider.deploymentBucket- Fix support for the
-sshortcut in certain cases- Fix handling of the service name when
serviceis provided as an object with anameproperty- Serverless Container Framework
- Fix wildcard domain detection in ACM and Route 53
4.14.3
Security Fixes
- Update Go version to address CVE-2025-22871, related to
net/httpin the Golang stdlib: We’ve reviewed the recent CVE, which generally affects the Go standard library in web servers and web-related functionalities. Since the Serverless Framework is a CLI tool does not rely on running a web server or handling web requests, users are not affected by this vulnerability. The CLI uses a small amount of Go to handle updating to the version set inframeworkCoreinserverless.yml. Our update process uses HTTPS with SSL/TLS to securely check for and install new versions, ensuring no risk of exploitation or malicious code injection. All dependencies have been audited, and no vulnerabilities were found. However, upgrading is always a best practice and, we recommend users upgrade to the latest version to ensure they’re on the most secure release. This can be done via theserverless upgradecommand, which will update the installer.4.14.2
Bug Fixes
- Serverless Framework
- Fixed an issue with proxy support (serverless/serverless#13062)
4.14.1
Bug Fixes
- Serverless Container Framework
- Pinned the Docker image builder version
4.14.0
Features
- Serverless Framework
- Support for Doppler secrets in Serverless Variables (docs)
service: my-service provider: environment: </tr></table>
... (truncated)
Commits
e2681bdchore: update readme to include serverless MCP and container framework1003a32docs: update SECURITY.md (#13026)ec4957fchore: automate CLA signing (#13019)c4cebaechore: automate CLA signing87b4f5bdocs: read license key from aws ssm (#12986)3f37cbadocs(dev-mode): added note regarding vpc (#12977)d262ac3feat: add support for ap-southeast-5 and ca-west-1 (#12981)2aea99dfix: correctly resolve layer package artifact and docker image paths (#12972)3704754fix(esbuild): track files added to the zip file (#12966)c9d519efeat: add support for provenance option in docker build (#12958)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
2
2
Additions:
+146
+146
Deletions:
-4704
-4704
Package Dependencies
Technical Details
| ID: | 1229166 |
| UUID: | 2560590997 |
| Node ID: | PR_kwDODg7v7s6Yn4SV |
| Host: | GitHub |
| Repository: | dbartholomae/middy-middleware-json-error-handler |
| Merge State: | Unknown |