Sitelet https://github.com/jeremydaly/lambda-api/releases
Skip to content

Releases: jeremydaly/lambda-api

v1.5.1

Choose a tag to compare

@naorpeled naorpeled released this 22 Aug 16:37
dbce417

What's Changed

Full Changelog: v1.5.0...v1.5.1

v1.5.0

Choose a tag to compare

@naorpeled naorpeled released this 08 Aug 16:40
6f45ad6

Highlights

Native ESM support is the headline of this release. lambda-api now ships a dual CommonJS/ES module build, so import createAPI from 'lambda-api' works without a bundler interop shim, while require() continues to work exactly as before.

This release also brings lambda-api's responses in line with RFC 9110: status codes that must not carry content no longer emit a response body. See Behavior changes below.

✨ Features

  • Dual CJS/ESM build — the package now publishes both CommonJS (dist/cjs) and ES module (dist/esm) output behind an exports map, with type definitions for each. Both entry points and the ./lib/* subpaths resolve correctly under either module system. (#326) — thanks @tomassabol!

    // ESM
    import createAPI from 'lambda-api';
    
    // CommonJS — unchanged
    const createAPI = require('lambda-api');

    The optional @aws-sdk/* S3 peer dependencies remain lazily loaded under both builds, so importing lambda-api without them installed still works for non-S3 consumers.

🐛 Bug Fixes

  • No response body for null-body status codes — responses with 1xx, 204, 205, or 304 status codes are now sent with an empty body, per RFC 9110. Previously res.sendStatus(204) emitted "No Content" as the body, and res.status(204).json({...}) passed the payload straight through. The check now lives in send(), so every response method inherits it. (#336, #342) — thanks @programmer4285 for the report and the initial fix!

⚠️ Behavior changes

  • Any body passed to send(), json(), jsonp(), html(), or sendFile() is discarded when the status code is 1xx, 204, 205, or 304. If you were relying on a body being returned with one of these codes — most likely res.status(204).json(...) — switch to 200 (or 202) to keep the payload.
  • res.sendStatus(204) and res.sendStatus(304) now return an empty body instead of "No Content" / "Not Modified".
  • UTILS.statusBodyLookup(), added during development of this release, was folded into UTILS.isNullBodyStatus() before shipping. It was never published, so no released version exposed it.

📚 Documentation

  • Clarified that the AWS S3 SDK packages are optional peer dependencies, only required if you use res.sendFile() with an s3:// path or res.getLink(). (#324)
  • Documented null-body status code behavior in the status() and sendStatus() sections. (#342)

🔧 CI / Internal

  • Benchmark suite comparing lambda-api against other Lambda web frameworks. (#327, closes #34)
  • Dual-package e2e coverage — new module-compat tests assert both the CJS and ESM outputs load and serve requests, plus a Layer 1 e2e runner and LocalStack suite.
  • CI restructured to build the dual package once on Node 20 and run the Node 14–22 test matrix against the prebuilt dist/, since the SWC toolchain requires Node >= 16.14 to build. Runtime support for Node 14 is unchanged.
  • GitHub Sponsors funding config. (#328)
  • Development dependency bumps: lodash (#329, #314), brace-expansion (#339), fast-xml-parser + @aws-sdk/client-s3 (#340, #313), @smithy/config-resolver (#341), minimatch (#305), flatted (#308), picomatch (#310), plus benchmark-only bumps (#333, #334, #337, #338). lambda-api has no runtime dependencies, so none of these affect installed consumers.

Full Changelog: v1.4.0...v1.5.0

v1.4.0

Choose a tag to compare

@naorpeled naorpeled released this 06 Jun 15:05
6993f0c

Highlights

Route-level generic request & response typing is the headline of this release: route handlers can now opt into strongly typed inputs and outputs that are enforced at compile time — with zero changes required to existing code.

✨ Features

  • Generic Request/Response typing for routes — Middleware, ErrorHandlingMiddleware, and HandlerFunction now accept <TRequest, TResponse> generics, and every route method (get, post, put, patch, delete, options, head, any, METHOD) plus use carries them through to your handlers. Response<TBody> enforces the response payload shape on send, json, and jsonp. Fully backward compatible — generics default to today's Request/Response. (#320)

    interface TypedRequest extends Request {
      params: { thingId: string };
    }
    
    api.get<TypedRequest, Response<{ hello: string }>>('/typed', (req, res) => {
      res.json({ hello: req.params.thingId }); // payload shape checked at compile time
    });

🔒 Security

  • Prototype pollution hardening in use() — middleware argument iteration moved from for-in to for-of, so enumerable Array.prototype methods added by third-party libraries can no longer leak into the args scan and trigger a spurious ConfigurationError: Middleware must have 3 or 4 parameters. (#321)

🐛 Bug Fixes

  • Middleware inheritance for base-pathed root (/) routes — when an API is configured with a base path, handlers registered on / now correctly inherit wildcard middleware, making /base-path/ behave consistently with its non-root siblings. (#319)

🔧 CI / Internal

  • npm release workflow — the published version is now stamped at publish time from the release tag, and a manual workflow_dispatch trigger allows publishing a specific version on demand. (#318)

Full Changelog: v1.3.0...v1.4.0

v1.3.0

Choose a tag to compare

@naorpeled naorpeled released this 01 Jun 18:04
3d4ea7a

What's Changed

  • fix(deps): mark S3 SDK peer deps as optional and raise floor by @naorpeled in #316

Full Changelog: v1.2.0...v1.3.0

v1.2.0

Choose a tag to compare

@naorpeled naorpeled released this 05 Apr 17:32
76dc359

What's Changed

  • test: cover index.d.ts with tests by @naorpeled in #283
  • fix(error-handling-middleware): handle string error as ApiError by @naorpeled in #287

Full Changelog: v1.1.2...v1.2.0

v1.1.2

Choose a tag to compare

@naorpeled naorpeled released this 06 Feb 16:49
ff4f496

What's Changed

Full Changelog: v1.1.1...v1.1.2

v1.1.1

Choose a tag to compare

@naorpeled naorpeled released this 05 Feb 19:46
1f9c70c

What's Changed

New Contributors

Full Changelog: v1.1.0...v1.1.1

v1.1.0

Choose a tag to compare

@naorpeled naorpeled released this 10 Jun 19:17
b2eb0a2

What's Changed

  • (feat): Lazy load S3 client by @perpil in #255
  • feat(Request/types): add multiValueHeaders type definition @guirisnik in #264
  • feat(Response): add setHeader as header fn alias by @naorpeled in #265
  • fix: invalid cookie parsing for the "=" character by @qgolsteyn in #271

New Contributors

Full Changelog: v1.0.3...v1.1.0

v1.0.3

Choose a tag to compare

@naorpeled naorpeled released this 11 Jul 21:24
ba18dcd

What's Changed

New Contributors

Full Changelog: v1.0.2...v1.0.3

v1.0.2

Choose a tag to compare

@naorpeled naorpeled released this 03 Jun 14:23
4ed0676

What's Changed

  • fix(s3-service/getObject): resolve wrong output type received in #236
  • fix(type-defs): resolve middleware missing in route methods in #238

Full Changelog: v1.0.1...v1.0.2