health_checks #14927
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: health_checks | |
| on: | |
| pull_request: | |
| branches: | |
| - main | |
| - hotfix | |
| - feature/** | |
| - snapshot/iac-hosting | |
| schedule: | |
| # Run every two hours. A single run takes about 40min so we should | |
| # get about 10 runs per day. If at least one of them succeeds, we are happy. | |
| # taking into account that | |
| # 1) scheduled runs may not fire at exact prescribed time; | |
| # 2) transient failures may happen and auto recover; | |
| - cron: '0 */2 * * *' | |
| workflow_dispatch: | |
| inputs: | |
| desired-cdk-lib-version: | |
| description: 'AWS CDK Lib version (exact or tag). Defaults to package-locked version.' | |
| required: false | |
| type: string | |
| include-package-manager-e2e-tests: | |
| description: 'Include package manager e2e tests?' | |
| required: false | |
| type: boolean | |
| default: true | |
| include-create-amplify-e2e-tests: | |
| description: 'Include create-amplify e2e tests?' | |
| required: false | |
| type: boolean | |
| default: true | |
| include-macos: | |
| description: 'Include MacOS?' | |
| required: false | |
| type: boolean | |
| default: true | |
| include-windows: | |
| description: 'Include Windows?' | |
| required: false | |
| type: boolean | |
| default: true | |
| node: | |
| description: 'Node versions list (as JSON array).' | |
| required: false | |
| type: string | |
| default: '["22", "24", "26"]' | |
| workflow_call: | |
| inputs: | |
| desired-cdk-lib-version: | |
| description: 'AWS CDK Lib version (exact or tag). Defaults to package-locked version.' | |
| required: false | |
| type: string | |
| include-package-manager-e2e-tests: | |
| description: 'Include package manager e2e tests?' | |
| required: false | |
| type: boolean | |
| default: true | |
| include-create-amplify-e2e-tests: | |
| description: 'Include create-amplify e2e tests?' | |
| required: false | |
| type: boolean | |
| default: true | |
| include-macos: | |
| description: 'Include MacOS?' | |
| required: false | |
| type: boolean | |
| default: true | |
| include-windows: | |
| description: 'Include Windows?' | |
| required: false | |
| type: boolean | |
| default: true | |
| node: | |
| description: 'Node versions list (as JSON array).' | |
| required: false | |
| type: string | |
| default: '["22", "24", "26"]' | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| env: | |
| # Health checks can run on un-released code. Often work in progress. | |
| # Disable data from there. | |
| AMPLIFY_DISABLE_TELEMETRY: true | |
| jobs: | |
| # This workflow may be called by variety of events. | |
| # This steps resolves and applies appropriate defaults depending on the trigger. | |
| resolve_inputs: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| cdk_lib_version: ${{ steps.resolve_inputs.outputs.cdk_lib_version }} | |
| cdk_cli_version: ${{ steps.resolve_inputs.outputs.cdk_cli_version }} | |
| os: ${{ steps.resolve_inputs.outputs.os }} | |
| os_for_e2e: ${{ steps.resolve_inputs.outputs.os_for_e2e }} | |
| node: ${{ steps.resolve_inputs.outputs.node }} | |
| steps: | |
| - name: Resolve Inputs | |
| id: resolve_inputs | |
| # This is intentionally in pure bash to make this job independent of repo checkout and fast. | |
| run: | | |
| if [ -z "${{ inputs.desired-cdk-lib-version }}" ]; then | |
| echo "cdk_lib_version=FROM_PACKAGE_LOCK" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "cdk_lib_version=$(npm view aws-cdk-lib@${{ inputs.desired-cdk-lib-version }} version)" >> "$GITHUB_OUTPUT" | |
| fi | |
| # Build JSON array in readable way in bash... | |
| os='["ubuntu-latest"' | |
| os_for_e2e='["ubuntu-latest"' | |
| if [ "${{ inputs.include-macos }}" != "false" ]; then | |
| os+=', "macos-14"' | |
| os_for_e2e+=', "macos-14-xlarge"' | |
| fi | |
| if [ "${{ inputs.include-windows }}" != "false" ]; then | |
| os+=', "windows-2025"' | |
| os_for_e2e+=', "windows-2025"' | |
| fi | |
| os+=']' | |
| os_for_e2e+=']' | |
| echo "os=$os" >> "$GITHUB_OUTPUT" | |
| echo "os_for_e2e=$os_for_e2e" >> "$GITHUB_OUTPUT" | |
| if [ -z "${{ inputs.node }}" ]; then | |
| echo 'node=["22", "24", "26"]' >> "$GITHUB_OUTPUT" | |
| else | |
| echo 'node=${{ inputs.node }}' >> "$GITHUB_OUTPUT" | |
| fi | |
| - run: echo cdk_lib_version set to ${{ steps.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: echo cdk_cli_version set to ${{ steps.resolve_inputs.outputs.cdk_cli_version }} | |
| - run: echo os set to ${{ steps.resolve_inputs.outputs.os }} | |
| - run: echo os_for_e2e set to ${{ steps.resolve_inputs.outputs.os_for_e2e }} | |
| - run: echo node set to ${{ steps.resolve_inputs.outputs.node }} | |
| install: | |
| strategy: | |
| matrix: | |
| # Windows install must happen on the same worker size as subsequent jobs. | |
| # Larger workers use different drive (C: instead of D:) to check out project and NPM installation | |
| # creates file system links that include drive letter. | |
| # Changing between standard and custom workers requires full install cache invalidation | |
| os: ${{ fromJSON(needs.resolve_inputs.outputs.os) }} | |
| node: ${{ fromJSON(needs.resolve_inputs.outputs.node) }} | |
| # Always include Node 22 and Ubuntu. Non-testing jobs depend on it | |
| # (they restore the Node-22-keyed install/build cache produced here). | |
| include: | |
| - os: ubuntu-latest | |
| node: 22 | |
| runs-on: ${{ matrix.os }} | |
| needs: | |
| - resolve_inputs | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: ${{ matrix.node }} | |
| - uses: ./.github/actions/install_with_cache | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| build: | |
| strategy: | |
| matrix: | |
| node: ${{ fromJSON(needs.resolve_inputs.outputs.node) }} | |
| # Always include Node 22. Non-testing jobs depend on it | |
| # (they restore the Node-22-keyed build cache produced here). | |
| include: | |
| - node: 22 | |
| runs-on: ubuntu-latest | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: ${{ matrix.node }} | |
| - uses: ./.github/actions/build_with_cache | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| test_with_coverage: | |
| needs: | |
| - build | |
| - resolve_inputs | |
| strategy: | |
| matrix: | |
| os: ${{ fromJSON(needs.resolve_inputs.outputs.os) }} | |
| node: ${{ fromJSON(needs.resolve_inputs.outputs.node) }} | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: ${{ matrix.node }} | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npm run set-script-shell | |
| - run: npm run test:coverage:threshold | |
| test_scripts: | |
| needs: | |
| - build | |
| - resolve_inputs | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: | | |
| npm run set-script-shell | |
| npm run test:scripts | |
| test_with_baseline_dependencies: | |
| needs: | |
| - install | |
| - resolve_inputs | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - name: Pin some dependencies to nearest patch and rebuild | |
| run: | | |
| npx tsx scripts/set_baseline_dependency_versions.ts | |
| npm install | |
| # print out diff for auditing or troubleshooting | |
| git diff | |
| npm run build | |
| - name: Run unit and integration tests | |
| run: | | |
| npm run set-script-shell | |
| npm run test | |
| check_api_changes: | |
| if: github.event_name == 'pull_request' | |
| needs: | |
| - build | |
| - resolve_inputs | |
| runs-on: ubuntu-latest | |
| # 120: accommodates the raised per-attempt timeout below plus one retry | |
| # (see the nick-fields/retry step). | |
| timeout-minutes: 120 | |
| steps: | |
| - name: Checkout pull request ref | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| # Warm the shared verdaccio proxy cache so the ~27 per-package installs | |
| # below are served from disk instead of each cold-proxying the full | |
| # amplify dependency graph from the network. | |
| - name: Warm verdaccio cache | |
| uses: ./.github/actions/warm_verdaccio_cache | |
| with: | |
| node-version: 22 | |
| - name: Publish packages locally | |
| timeout-minutes: 5 | |
| env: | |
| # Point verdaccio at the same shared storage the warm cache restores, | |
| # so third-party deps are reused across runs. Must match the path in | |
| # warm_verdaccio_cache and NpmProxyController (rooted at RUNNER_TEMP). | |
| VERDACCIO_STORAGE_PATH: ${{ runner.temp }}/amplify-e2e-verdaccio-shared-storage | |
| run: | | |
| # On a warm cross-run cache the workspace packages from a previous run | |
| # already exist in storage; remove them so publish:local can re-publish | |
| # the same versions without an EPUBLISHCONFLICT. Third-party packages | |
| # (everything else) are kept warm. | |
| npx tsx scripts/clean_workspace_packages_from_verdaccio_storage.ts "$VERDACCIO_STORAGE_PATH" | |
| npm run start:npm-proxy | |
| # keep git diff with version increment to make sure test projects resolve right version | |
| npm run publish:local -- --keepGitDiff | |
| - name: Checkout base branch | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| with: | |
| path: base-branch-content | |
| ref: ${{ github.event.pull_request.base.sha }} | |
| - name: Check API changes with retry | |
| uses: nick-fields/retry@v3 | |
| with: | |
| # 50 (was 20): the validator spins up one throwaway project PER | |
| # workspace package (~27), each doing a real `npm install` of the full | |
| # amplify dependency graph from the local proxy. All validations PASS, | |
| # but the aggregate install time lands right at the old 20-min | |
| # per-attempt cap, so nick-fields/retry killed a run that had actually | |
| # finished validating every package (and each retry restarts all ~27 | |
| # installs from scratch, so retries can't make incremental progress). | |
| # 50 min gives a passing attempt comfortable headroom; max_attempts 2 | |
| # keeps the worst case within the 120-min job cap. | |
| timeout_minutes: 50 | |
| max_attempts: 2 | |
| retry_wait_seconds: 30 | |
| command: | | |
| mkdir -p api-validation-projects | |
| npx tsx scripts/check_api_changes.ts base-branch-content api-validation-projects | |
| handle_dependabot_version_update: | |
| if: github.event_name == 'pull_request' && github.event.pull_request.user.login == 'dependabot[bot]' | |
| runs-on: ubuntu-latest | |
| needs: | |
| - build | |
| - resolve_inputs | |
| permissions: | |
| # This is required so that this job can add the 'run-e2e' label and push to the pull request | |
| pull-requests: write | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - name: Handle Dependabot version update pull request | |
| run: | | |
| npm run update:create-amplify-deps | |
| npm run lint:fix | |
| npx tsx scripts/dependabot_handle_version_update.ts "$BASE_SHA" | |
| env: | |
| BASE_SHA: ${{ github.event.pull_request.base.sha }} | |
| # The dependabot_handler_version_update script needs to add the 'run-e2e' pull request label | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| do_include_e2e: | |
| needs: | |
| - install | |
| - resolve_inputs | |
| runs-on: ubuntu-latest | |
| permissions: | |
| # This is required so that the step can read the labels on the pull request | |
| pull-requests: read | |
| env: | |
| # The do_include_e2e script needs to query pull request labels | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| outputs: | |
| run_e2e: ${{ steps.check.outputs.run_e2e }} | |
| include_package_manager_e2e: ${{ steps.check_package_manager.outputs.include_package_manager_e2e }} | |
| include_create_amplify_e2e: ${{ steps.check_create_amplify.outputs.include_create_amplify_e2e }} | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - name: Check if any E2E tests should run | |
| id: check | |
| run: | | |
| run_e2e=$(npx tsx scripts/do_include_e2e.ts) | |
| echo "run_e2e=$run_e2e" >> "$GITHUB_OUTPUT" | |
| - run: echo run_e2e set to ${{ steps.check.outputs.run_e2e }} | |
| - name: Check if Package Manager E2E tests should be included | |
| id: check_package_manager | |
| run: | | |
| if [ -z "${{ inputs.include-package-manager-e2e-tests }}" ]; then | |
| echo "include_package_manager_e2e=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "include_package_manager_e2e=${{ inputs.include-package-manager-e2e-tests }}" >> "$GITHUB_OUTPUT" | |
| fi | |
| - run: echo include_package_manager_e2e set to ${{ steps.check_package_manager.outputs.include_package_manager_e2e }} | |
| - name: Check if Create Amplify E2E tests should be included | |
| id: check_create_amplify | |
| run: | | |
| if [ -z "${{ inputs.include-create-amplify-e2e-tests }}" ]; then | |
| echo "include_create_amplify_e2e=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "include_create_amplify_e2e=${{ inputs.include-create-amplify-e2e-tests }}" >> "$GITHUB_OUTPUT" | |
| fi | |
| - run: echo include_create_amplify_e2e set to ${{ steps.check_create_amplify.outputs.include_create_amplify_e2e }} | |
| e2e_iam_access_drift: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| runs-on: ubuntu-latest | |
| # 180 (was 120): this job runs TWO full create-amplify installs + two live | |
| # deploys per attempt and retries up to 5x. The create-amplify install is | |
| # currently ~26-30 min in CI (heavy upstream-bundled data/graphql | |
| # constructs), so a passing attempt lands at ~1h53m — just past the 120-min | |
| # cap. Give headroom so the winning attempt can finish and report. Also | |
| # failing on main (pre-existing flake), tracked separately from this PR. | |
| timeout-minutes: 180 | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| # This checkout is needed for the setup_baseline_version action to run `checkout` inside | |
| # See https://github.com/actions/checkout/issues/692 | |
| - name: Checkout version for baseline | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - name: Setup baseline version | |
| uses: ./.github/actions/setup_baseline_version | |
| id: setup_baseline_version | |
| with: | |
| node_version: 22 | |
| - name: Checkout current version | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| # Warm the shared verdaccio proxy cache so the first create-amplify install | |
| # is served from disk instead of a cold ~20-min re-proxy. This test opts | |
| # into NpmProxyController's preserveThirdPartyCache. | |
| - name: Warm verdaccio cache | |
| uses: ./.github/actions/warm_verdaccio_cache | |
| with: | |
| node-version: 22 | |
| - name: Run e2e iam access drift test | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| # This test does two create-amplify installs + two live deploys per | |
| # attempt; a single PASSING attempt currently measures ~47 min (heavy | |
| # upstream-bundled data/graphql install is ~18 min each). The 40-min | |
| # default per-attempt timeout guillotines even the winning attempt, so | |
| # the job never reports success. Raise to 55 min: enough headroom for | |
| # the ~47-min run, still safely under the 60-min MaxSessionDuration cap | |
| # on the re-assumed per-attempt credentials. | |
| attempt_timeout_minutes: 55 | |
| run: npm run test:dir packages/integration-tests/lib/test-e2e/iam_access_drift.test.js | |
| env: | |
| BASELINE_DIR: ${{ steps.setup_baseline_version.outputs.baseline_dir }} | |
| e2e_amplify_outputs_backwards_compatibility: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| runs-on: ubuntu-latest | |
| # 240 (was 180): a single attempt's natural runtime was MEASURED at ~60-65 | |
| # min (3 full ~16-20 min installs of the ~450 MB bundled data/graphql | |
| # constructs + 2 deploys + generate/assert), so attempt_timeout below is | |
| # raised to 75 min. 240 keeps room for ~2 such attempts + retry delays. | |
| # WORKAROUND until the upstream bundled-install cost is reduced | |
| # (amplify-category-api#3514); the unpack is the irreducible cost here. | |
| timeout-minutes: 240 | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| # This checkout is needed for the setup_baseline_version action to run `checkout` inside | |
| # See https://github.com/actions/checkout/issues/692 | |
| - name: Checkout version for baseline | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - name: Setup baseline version | |
| uses: ./.github/actions/setup_baseline_version | |
| id: setup_baseline_version | |
| with: | |
| node_version: 22 | |
| - name: Checkout current version | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| # Warm the shared verdaccio proxy cache so the first create-amplify install | |
| # is served from disk instead of a cold ~20-min re-proxy. This test opts | |
| # into NpmProxyController's preserveThirdPartyCache. | |
| - name: Warm verdaccio cache | |
| uses: ./.github/actions/warm_verdaccio_cache | |
| with: | |
| node-version: 22 | |
| - name: Run e2e amplify outputs backwards compatibility test | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| # MEASURED: one full attempt needs ~60-65 min (3 full installs that | |
| # each re-unpack the ~450 MB bundled data/graphql constructs, + 2 | |
| # deploys + generate/assert). Give it 75 min of headroom. | |
| # Because that exceeds the e2e roles' default 1h credential lifetime, | |
| # request a longer 90-min (5400s) session so credentials outlive the | |
| # attempt instead of expiring mid-run (ExpiredToken). NOTE: STS caps | |
| # this at the ROLE's MaxSessionDuration — this only fully takes effect | |
| # once the e2e roles' MaxSessionDuration is raised to >=5400 in the | |
| # account; until then the re-assume falls back to 3600. WORKAROUND | |
| # until the upstream bundled-install cost is reduced | |
| # (amplify-category-api#3514). | |
| attempt_timeout_minutes: 75 | |
| credential_duration_seconds: 5400 | |
| run: npm run test:dir packages/integration-tests/lib/test-e2e/amplify_outputs_backwards_compatibility.test.js | |
| env: | |
| BASELINE_DIR: ${{ steps.setup_baseline_version.outputs.baseline_dir }} | |
| e2e_hosting: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 120 | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - name: Run e2e hosting tests | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| attempt_timeout_minutes: 120 | |
| run: npm run test:dir packages/integration-tests/lib/test-e2e/hosting.test.js | |
| env: | |
| AMPLIFY_BACKEND_TESTS_HOSTING_TEST_BRANCH_NAME: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.ref || github.ref_name }} | |
| AMPLIFY_BACKEND_TESTS_HOSTING_TEST_COMMIT_SHA: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }} | |
| e2e_generate_deployment_tests_matrix: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| runs-on: ubuntu-latest | |
| outputs: | |
| matrix: ${{ steps.generateMatrix.outputs.matrix }} | |
| timeout-minutes: 5 | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: echo "$(npx tsx scripts/generate_sparse_test_matrix.ts 'packages/integration-tests/lib/test-e2e/deployment/*.deployment.test.js' '${{ needs.resolve_inputs.outputs.node }}' '${{ needs.resolve_inputs.outputs.os_for_e2e }}')" | |
| - name: Generate matrix with retry | |
| id: generateMatrix | |
| uses: nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: 5 | |
| max_attempts: 3 | |
| retry_wait_seconds: 10 | |
| command: echo "matrix=$(npx tsx scripts/generate_sparse_test_matrix.ts 'packages/integration-tests/lib/test-e2e/deployment/*.deployment.test.js' '${{ needs.resolve_inputs.outputs.node }}' '${{ needs.resolve_inputs.outputs.os_for_e2e }}')" >> "$GITHUB_OUTPUT" | |
| e2e_deployment: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| strategy: | |
| # will finish running other test matrices even if one fails | |
| fail-fast: false | |
| matrix: ${{ fromJson(needs.e2e_generate_deployment_tests_matrix.outputs.matrix) }} | |
| runs-on: ${{ matrix.os }} | |
| name: e2e_deployment ${{ matrix.displayNames }} ${{ matrix.node-version }} ${{ matrix.os }} | |
| timeout-minutes: ${{ matrix.os == 'windows-2025' && 160 || 120 }} | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - e2e_generate_deployment_tests_matrix | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| # Exclude install paths from Windows Defender scanning (no-op off Windows) | |
| # so the e2e npm installs aren't throttled by per-file scans. | |
| - uses: ./.github/actions/disable_windows_defender_for_installs | |
| - name: Run e2e deployment tests | |
| run: | | |
| # Setup node and restore cache | |
| echo "Setting up Node.js and restoring cache..." | |
| # Run the e2e deployment tests using the action | |
| echo "Running e2e deployment tests..." | |
| # This will be handled by the composite action call below | |
| exit 0 | |
| - name: Execute e2e deployment tests | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: ${{ matrix.node-version }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| link_cli: true | |
| attempt_timeout_minutes: ${{ matrix.os == 'windows-2025' && 35 || 25 }} | |
| run: npm run test:dir ${{ matrix.testPaths }} | |
| e2e_generate_sandbox_tests_matrix: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| runs-on: ubuntu-latest | |
| outputs: | |
| matrix: ${{ steps.generateMatrix.outputs.matrix }} | |
| timeout-minutes: 5 | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: echo "$(npx tsx scripts/generate_sparse_test_matrix.ts 'packages/integration-tests/lib/test-e2e/sandbox/*.sandbox.test.js' '${{ needs.resolve_inputs.outputs.node }}' '${{ needs.resolve_inputs.outputs.os_for_e2e }}')" | |
| - name: Generate matrix with retry | |
| id: generateMatrix | |
| uses: nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: 5 | |
| max_attempts: 3 | |
| retry_wait_seconds: 10 | |
| command: echo "matrix=$(npx tsx scripts/generate_sparse_test_matrix.ts 'packages/integration-tests/lib/test-e2e/sandbox/*.sandbox.test.js' '${{ needs.resolve_inputs.outputs.node }}' '${{ needs.resolve_inputs.outputs.os_for_e2e }}')" >> "$GITHUB_OUTPUT" | |
| e2e_sandbox: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| strategy: | |
| # will finish running other test matrices even if one fails | |
| fail-fast: false | |
| matrix: ${{ fromJson(needs.e2e_generate_sandbox_tests_matrix.outputs.matrix) }} | |
| runs-on: ${{ matrix.os }} | |
| name: e2e_sandbox ${{ matrix.displayNames }} ${{ matrix.node-version }} ${{ matrix.os }} | |
| timeout-minutes: ${{ matrix.os == 'windows-2025' && 160 || 120 }} | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - e2e_generate_sandbox_tests_matrix | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| # Exclude install paths from Windows Defender scanning (no-op off Windows). | |
| - uses: ./.github/actions/disable_windows_defender_for_installs | |
| - name: Run e2e sandbox tests with retry | |
| run: | | |
| # This step will be handled by the composite action below | |
| echo "Preparing to run e2e sandbox tests with retry..." | |
| exit 0 | |
| - name: Execute e2e sandbox tests | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: ${{ matrix.node-version }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| link_cli: true | |
| attempt_timeout_minutes: ${{ matrix.os == 'windows-2025' && 35 || 25 }} | |
| run: npm run test:dir ${{ matrix.testPaths }} | |
| e2e_notices: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| strategy: | |
| # will finish running other test matrices even if one fails | |
| fail-fast: false | |
| matrix: | |
| os: ${{ fromJSON(needs.resolve_inputs.outputs.os) }} | |
| runs-on: ${{ matrix.os }} | |
| name: e2e_notices ${{ matrix.os }} | |
| timeout-minutes: ${{ matrix.os == 'windows-2025' && 8 || 5 }} | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: cd packages/cli && npm link | |
| - name: Run e2e notices tests | |
| uses: nick-fields/retry@v3 | |
| with: | |
| timeout_minutes: ${{ matrix.os == 'windows-2025' && 8 || 5 }} | |
| max_attempts: 3 | |
| retry_wait_seconds: 30 | |
| command: npm run test:dir packages/integration-tests/lib/test-e2e/notices.test.js | |
| e2e_backend_output: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 120 | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - name: Run e2e backend output tests | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| link_cli: true | |
| attempt_timeout_minutes: 25 | |
| run: npm run test:dir packages/integration-tests/lib/test-e2e/backend_output.test.js | |
| e2e_create_amplify: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' && needs.do_include_e2e.outputs.include_create_amplify_e2e == 'true' | |
| strategy: | |
| # will finish running other test matrices even if one fails | |
| fail-fast: false | |
| matrix: | |
| os: ${{ fromJSON(needs.resolve_inputs.outputs.os) }} | |
| node-version: ${{ fromJSON(needs.resolve_inputs.outputs.node) }} | |
| # skip multiple node version test on other os | |
| exclude: | |
| - os: macos-14 | |
| node-version: 24 | |
| - os: windows-2025 | |
| node-version: 22 | |
| - os: macos-14 | |
| node-version: 26 | |
| - os: windows-2025 | |
| node-version: 26 | |
| runs-on: ${{ matrix.os }} | |
| # windows-2025: the create-amplify install is markedly slower on Windows | |
| # (NTFS file-op + AV-scan overhead) and the cold install has hit the old | |
| # 40-min cap. 60 min gives headroom until the warm verdaccio cache | |
| # (warm_verdaccio_cache step) fully takes effect on cross-run cache hits. | |
| timeout-minutes: ${{ matrix.os == 'windows-2025' && 60 || 25 }} | |
| needs: | |
| - do_include_e2e | |
| - build | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| # Exclude install paths from Windows Defender real-time scanning (no-op on | |
| # Linux/macOS). The create-amplify install unpacks the ~225 MB bundled | |
| # graphql-api-construct/data-construct packages; Defender's per-file-close | |
| # scan is the main reason the windows-2025 install is ~2x slower. | |
| - uses: ./.github/actions/disable_windows_defender_for_installs | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: ${{ matrix.node-version }} | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: ${{ matrix.node-version }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: cd packages/cli && npm link | |
| - name: Reset git tree after npm link | |
| # `npm link` rewrites package.json/package-lock.json (and can touch other | |
| # workspace manifests). Reset the whole tree to a pristine checkout so the | |
| # verdaccio warm-cache + local publish steps below see no diff — those | |
| # steps are sensitive to any working-tree change, so a full reset is | |
| # intentional here rather than scoping to specific paths. | |
| run: git checkout . | |
| # Warm the shared verdaccio proxy cache so the create-amplify install is | |
| # served from disk instead of a cold re-proxy from the network. This is | |
| # the dominant cost of this job, especially on the slower windows-2025 | |
| # runner where the cold install has hit the per-job timeout. | |
| - name: Warm verdaccio cache | |
| uses: ./.github/actions/warm_verdaccio_cache | |
| with: | |
| node-version: ${{ matrix.node-version }} | |
| - name: Run e2e create-amplify tests | |
| run: npm run test:dir packages/integration-tests/lib/test-e2e/create_amplify.test.js | |
| e2e_package_manager: | |
| if: needs.do_include_e2e.outputs.run_e2e == 'true' && needs.do_include_e2e.outputs.include_package_manager_e2e == 'true' | |
| strategy: | |
| # will finish running other test matrices even if one fails | |
| fail-fast: false | |
| matrix: | |
| os: ${{ fromJSON(needs.resolve_inputs.outputs.os) }} | |
| pkg-manager: [npm, yarn-classic, yarn-modern, pnpm] | |
| node-version: ['22'] | |
| env: | |
| PACKAGE_MANAGER: ${{ matrix.pkg-manager }} | |
| runs-on: ${{ matrix.os }} | |
| timeout-minutes: ${{ matrix.os == 'windows-2025' && 180 || 120 }} | |
| needs: | |
| - build | |
| - do_include_e2e | |
| - resolve_inputs | |
| permissions: | |
| # these permissions are required for the configure-aws-credentials action to get a JWT from GitHub | |
| id-token: write | |
| contents: read | |
| steps: | |
| - name: Checkout aws-amplify/amplify-backend repo | |
| uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 | |
| # Exclude install paths from Windows Defender scanning (no-op off Windows). | |
| - uses: ./.github/actions/disable_windows_defender_for_installs | |
| - name: Run e2e package manager tests with retry | |
| run: | | |
| # This step will be handled by the composite action below | |
| echo "Preparing to run e2e package manager tests with retry..." | |
| exit 0 | |
| - name: Execute e2e package manager tests | |
| uses: ./.github/actions/run_with_e2e_account | |
| with: | |
| e2e_test_accounts: ${{ vars.E2E_TEST_ACCOUNTS }} | |
| node_version: ${{ matrix.node-version }} | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| shell: bash | |
| on_retry_command: git clean -f -d | |
| attempt_timeout_minutes: ${{ matrix.os == 'windows-2025' && 40 || 25 }} | |
| run: PACKAGE_MANAGER=${{matrix.pkg-manager}} npm run test:dir packages/integration-tests/src/package_manager_sanity_checks.test.ts | |
| lint: | |
| runs-on: ubuntu-latest | |
| needs: | |
| - build | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npm run lint | |
| env: | |
| # Lint job requires ~14 GB heap to avoid OOM. | |
| # see https://nodejs.org/api/cli.html#--max-old-space-sizesize-in-megabytes | |
| NODE_OPTIONS: '--max-old-space-size=14782' | |
| check_dependencies: | |
| runs-on: ubuntu-latest | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| # - run: npm run check:dependencies | |
| check_tsconfig_refs: | |
| runs-on: ubuntu-latest | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npm run check:tsconfig-refs | |
| check_api_extract: | |
| runs-on: ubuntu-latest | |
| needs: | |
| - build | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npm run check:api | |
| env: | |
| # Cap heap per process; the concurrent_workspace_script limits parallelism | |
| # to avoid OOM when multiple api-extractor instances run simultaneously. | |
| # see https://nodejs.org/api/cli.html#--max-old-space-sizesize-in-megabytes | |
| NODE_OPTIONS: '--max-old-space-size=4096' | |
| check_create_amplify_deps: | |
| runs-on: ubuntu-latest | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npm run check:create-amplify-deps | |
| docs_build_and_publish: | |
| if: ${{ github.event_name == 'push' && github.ref_name == 'main' }} | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| needs: | |
| - build | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npm run docs | |
| - uses: peaceiris/actions-gh-pages@4f9cc6602d3f66b9c108549d475ec49e8ef4d45e # version 4.0.0 | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| publish_dir: ./docs | |
| publish_branch: docs | |
| check_pr_size: | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: git fetch origin | |
| - run: npm run diff:check "$BASE_SHA" | |
| env: | |
| BASE_SHA: ${{ github.event.pull_request.base.sha }} | |
| check_pr_changesets: | |
| if: github.event_name == 'pull_request' && github.event.pull_request.user.login != 'github-actions[bot]' | |
| runs-on: ubuntu-latest | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| with: | |
| # fetch full history so that changeset can properly compute divergence point | |
| fetch-depth: 0 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - name: Validate that PR has changeset | |
| run: npx --package @changesets/cli -- changeset status --since origin/"$BASE_REF" | |
| env: | |
| BASE_REF: ${{ github.event.pull_request.base.ref }} | |
| - name: Validate changeset is not missing packages | |
| run: npx tsx scripts/check_changeset_completeness.ts "$BASE_SHA" | |
| env: | |
| BASE_SHA: ${{ github.event.pull_request.base.sha }} | |
| # - name: Validate that changeset has necessary dependency updates | |
| # run: | | |
| # npx --package @changesets/cli -- changeset version | |
| # npm update | |
| # npm run check:dependencies | |
| check_package_versions: | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| needs: | |
| - install | |
| - resolve_inputs | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - run: npx --verbose --package @changesets/cli -- changeset version | |
| - run: npm run check:package-versions | |
| update_package_versions: | |
| # only runs when merging a PR into main | |
| if: ${{ github.event_name == 'push' && (github.ref_name == 'main' || github.ref_name == 'hotfix') }} | |
| needs: | |
| - install | |
| - resolve_inputs | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_install_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - id: is_version_packages_commit | |
| run: echo "is_version_packages_commit=$(npx tsx scripts/is_version_packages_commit.ts)" >> "$GITHUB_OUTPUT" | |
| - name: Create or update Version Packages PR | |
| # if this push is NOT merging a version packages PR, then we update/create the version packages PR | |
| if: ${{ steps.is_version_packages_commit.outputs.is_version_packages_commit == 'false' }} | |
| uses: changesets/action@aba318e9165b45b7948c60273e0b72fce0a64eb9 # version 1.4.7 | |
| with: | |
| createGithubReleases: false | |
| # this should never be called, but if something happens and it does get called, this ensures that a premature publish won't happen | |
| publish: echo Cannot publish during update version step | |
| env: | |
| # we are also omitting the NPM_TOKEN here to eliminate the possibility of publishing to NPM during this step | |
| # we still need the GITHUB_TOKEN so that the version packages PR can be updated | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| publish_package_versions: | |
| if: ${{ github.event_name == 'push' && (github.ref_name == 'main' || github.ref_name == 'hotfix') }} | |
| needs: | |
| - test_with_coverage | |
| - e2e_package_manager | |
| - e2e_deployment | |
| - e2e_sandbox | |
| - e2e_notices | |
| - e2e_create_amplify | |
| - e2e_hosting | |
| - resolve_inputs | |
| runs-on: ubuntu-latest | |
| environment: release | |
| permissions: | |
| id-token: write | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 22 | |
| - uses: ./.github/actions/restore_build_cache | |
| with: | |
| node-version: 22 | |
| cdk-lib-version: ${{ needs.resolve_inputs.outputs.cdk_lib_version }} | |
| - id: is_version_packages_commit | |
| run: echo "is_version_packages_commit=$(npx tsx scripts/is_version_packages_commit.ts)" >> "$GITHUB_OUTPUT" | |
| - uses: ./.github/actions/setup_node | |
| with: | |
| node-version: 24 | |
| - name: Publish packages | |
| # if this push is merging a version packages PR, then we publish the new versions | |
| if: ${{ steps.is_version_packages_commit.outputs.is_version_packages_commit == 'true' }} | |
| id: changeset_publish | |
| uses: changesets/action@aba318e9165b45b7948c60273e0b72fce0a64eb9 # version 1.4.7 | |
| with: | |
| publish: npm run publish | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| NPM_TRUSTED_PUBLISHER: 'true' | |
| - name: Update hotfix branch | |
| if: ${{ steps.changeset_publish.outputs.published == 'true' && github.ref_name == 'main' }} | |
| run: git push origin main:hotfix --force | |
| codeql: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| with: | |
| # Minimal depth 2 so we can checkout the commit before possible merge commit. | |
| fetch-depth: 2 | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@8fcfedf57053e09257688fce7a0beeb18b1b9ae3 # version 2.17.2 | |
| with: | |
| languages: javascript | |
| queries: +security-and-quality | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@8fcfedf57053e09257688fce7a0beeb18b1b9ae3 # version 2.17.2 | |
| with: | |
| category: /language:javascript | |
| dependency-review: | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # version 4.1.4 | |
| - name: Dependency Review | |
| id: dep-review | |
| continue-on-error: true | |
| uses: actions/dependency-review-action@0c155c5e8556a497adf53f2c18edabf945ed8e70 # version 4.3.2 | |
| with: | |
| config-file: ./.github/dependency_review_config.yml | |
| - name: Check dependency review result | |
| if: always() | |
| shell: bash | |
| run: | | |
| # Truncate step summary to avoid GitHub's 1MB upload limit | |
| if [ -f "$GITHUB_STEP_SUMMARY" ]; then | |
| summary_size=$(wc -c < "$GITHUB_STEP_SUMMARY") | |
| if [ "$summary_size" -gt 1000000 ]; then | |
| head -c 900000 "$GITHUB_STEP_SUMMARY" > /tmp/truncated_summary.md | |
| printf '\n\n---\n⚠️ Summary was truncated because it exceeded the 1MB GitHub limit.\n' >> /tmp/truncated_summary.md | |
| cp /tmp/truncated_summary.md "$GITHUB_STEP_SUMMARY" | |
| fi | |
| fi | |
| # Inspect action outputs to determine if real dependency issues were found. | |
| # The dep-review step may fail solely because the step summary exceeded | |
| # GitHub's 1MB upload limit. We only want to fail this job when the action | |
| # detected actual dependency problems (vulnerabilities, license issues, or | |
| # denied packages). | |
| has_issues=false | |
| vulnerable='${{ steps.dep-review.outputs.vulnerable-changes }}' | |
| if [ -n "$vulnerable" ] && [ "$vulnerable" != "[]" ]; then | |
| echo "::error::Dependency review found vulnerable packages." | |
| has_issues=true | |
| fi | |
| # Note: invalid-license-changes check intentionally omitted. | |
| # In a monorepo, workspace packages with bumped versions trigger false-positive | |
| # license detection failures because they are not published to npm. The action | |
| # itself still enforces allow-licenses via the config file; this custom step | |
| # only needs to catch vulnerabilities and denied packages. | |
| denied='${{ steps.dep-review.outputs.denied-changes }}' | |
| if [ -n "$denied" ] && [ "$denied" != "[]" ]; then | |
| echo "::error::Dependency review found denied packages." | |
| has_issues=true | |
| fi | |
| if [ "$has_issues" = "true" ]; then | |
| exit 1 | |
| fi | |
| if [ "${{ steps.dep-review.outcome }}" = "failure" ]; then | |
| echo "::warning::Dependency review step failed (likely due to step summary size limit). Check logs for details." | |
| fi | |
| echo "✅ Dependency review passed — no vulnerable or denied packages found" |