No auth support is false. We support session out of the box and you're free to impl any auth scheme of your choosing.
Custom file format is being well addressed in other comments. If you don't like it thats fine: enjoy YAML elsewhere.
CORS could be implemented in the file format…I'm personally not a fan for a variety of reasons but its open source. PR's welcome.
Magic folders! Absolutely. Structure is a good thing.
I don't find this negative. Serverless framework is an abstraction that is easily as verbose as CF but I'm not interested in comparing to it because we have different goals. Serverless is an abstraction between clouds. If mulitcloud is your goal: use Serverless. SAM is a flavor of CF which is def less verbose but still very vendor specific and …wordy.
This isn't a 'pet framework of the month'. I do take mild offense to that. Development of .arc started in 2015 for begin.com and got met with some serious production traffic (from things like Techcrunch and Venturebeat). It held up beautifully. We decided to pivot from our original producton into CI/CD for arc with begin.com because it is clear to us that it is a better way to build serverless apps.
Architect was officially open sourced in July of 2017 and donated to the JS Foundation to demonstrate the long term commitment to it. Development has been very active since. I stand behind my work, dedication to open governance and approach we're taking and, I think, I have the track record to ask for the benefit of the doubt when I say that.