Skip to content

Bump js-yaml from 4.1.1 to 4.3.1 #70

Bump js-yaml from 4.1.1 to 4.3.1

Bump js-yaml from 4.1.1 to 4.3.1 #70

name: AWS Amplify PR Previews
on:
pull_request:
branches:
- main
types: [opened, synchronize, reopened, closed]
permissions:
id-token: write # Required for AWS OIDC authentication
contents: read # Required for checking out the repository
pull-requests: write # Required to post/update comments
# Cancel a stale run for this PR when a new commit is pushed, so we don't
# race a previous run to start/delete Amplify jobs on the same branch.
concurrency:
group: amplify-preview-${{ github.event.pull_request.number }}
cancel-in-progress: true
env:
AWS_REGION: us-west-2
# Amplify branch subdomains lowercase the branch name and replace '/' with '-'.
BRANCH_NAME: ${{ github.head_ref }}
jobs:
manage-preview:
# Skip PRs from forks: the IAM role's OIDC trust condition matches on the
# base repo regardless of head repo, so without this guard any external
# contributor's PR could trigger an AWS build on this public repo.
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
environment: veda
env:
AMPLIFY_APP_ID: ${{ vars.AMPLIFY_APP_ID }}
# The IAM role to assume to deploy the preview.
AMPLIFY_PREVIEW_ROLE: ${{ vars.AMPLIFY_PREVIEW_ROLE }}
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ vars.AMPLIFY_PREVIEW_ROLE }}
aws-region: ${{ env.AWS_REGION }}
# Handle PR Open or Sync: Deploy Preview
- name: Deploy Amplify PR Preview
id: deploy
if: github.event.action != 'closed'
run: |
APP_ID="$AMPLIFY_APP_ID"
# Check if the preview branch already exists in Amplify, if not, create it
aws amplify get-branch --app-id "$APP_ID" --branch-name "$BRANCH_NAME" || \
aws amplify create-branch --app-id "$APP_ID" --branch-name "$BRANCH_NAME" --stage PULL_REQUEST
# Amplify rejects StartJob if the branch already has a pending/running job
# (e.g. a rapid follow-up push). Stop it first so the new job can start.
ACTIVE_JOB_ID=$(aws amplify list-jobs --app-id "$APP_ID" --branch-name "$BRANCH_NAME" \
--query "jobSummaries[?status=='PENDING' || status=='PROVISIONING' || status=='RUNNING'].jobId | [0]" \
--output text)
if [ -n "$ACTIVE_JOB_ID" ] && [ "$ACTIVE_JOB_ID" != "None" ]; then
aws amplify stop-job --app-id "$APP_ID" --branch-name "$BRANCH_NAME" --job-id "$ACTIVE_JOB_ID"
fi
# Trigger the build job
JOB_ID=$(aws amplify start-job --app-id "$APP_ID" --branch-name "$BRANCH_NAME" \
--job-type RELEASE --query 'jobSummary.jobId' --output text)
echo "job_id=$JOB_ID" >> "$GITHUB_OUTPUT"
- name: Post initial preview comment
if: github.event.action != 'closed'
uses: actions/github-script@v7
id: initial-comment
with:
script: |
const marker = '<!-- amplify-pr-preview -->';
const branch = process.env.BRANCH_NAME.toLowerCase().replace(/\//g, '-');
const previewUrl = `https://${branch}.${process.env.AMPLIFY_APP_ID}.amplifyapp.com`;
const body = `${marker}\n🔄 **Amplify preview building...**\n\nPreview URL (not live yet): ${previewUrl}\n\n_This comment will update when the build completes._`;
const { data: comments } = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.pull_request.number,
});
const existing = comments.find((c) => c.body.includes(marker));
let commentId;
if (existing) {
await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: existing.id,
body,
});
commentId = existing.id;
} else {
const { data: comment } = await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.pull_request.number,
body,
});
commentId = comment.id;
}
core.setOutput('comment_id', commentId);
core.setOutput('preview_url', previewUrl);
- name: Wait for Amplify build
if: github.event.action != 'closed'
id: wait-build
env:
JOB_ID: ${{ steps.deploy.outputs.job_id }}
run: |
MAX_ATTEMPTS=20
ATTEMPT=0
STATUS="PENDING"
while [ $ATTEMPT -lt $MAX_ATTEMPTS ]; do
STATUS=$(aws amplify get-job --app-id "$AMPLIFY_APP_ID" \
--branch-name "$BRANCH_NAME" --job-id "$JOB_ID" \
--query 'job.summary.status' --output text)
echo "Attempt $ATTEMPT: $STATUS"
if [ "$STATUS" = "SUCCEED" ] || [ "$STATUS" = "FAILED" ] || [ "$STATUS" = "CANCELLED" ]; then
break
fi
ATTEMPT=$((ATTEMPT + 1))
sleep 30
done
echo "status=$STATUS" >> "$GITHUB_OUTPUT"
- name: Update preview comment
if: github.event.action != 'closed'
uses: actions/github-script@v7
with:
script: |
const marker = '<!-- amplify-pr-preview -->';
const status = '${{ steps.wait-build.outputs.status }}';
const previewUrl = '${{ steps.initial-comment.outputs.preview_url }}';
const consoleUrl = `https://console.aws.amazon.com/amplify/home?region=${process.env.AWS_REGION}#/${process.env.AMPLIFY_APP_ID}`;
const messages = {
SUCCEED: `${marker}\n✅ **Amplify preview ready**\n\n🔗 [Open preview](${previewUrl})\n\`${previewUrl}\``,
FAILED: `${marker}\n❌ **Amplify build failed**\n\nCheck the [Amplify console](${consoleUrl}) for logs.`,
CANCELLED: `${marker}\n⚠️ **Amplify build was cancelled.**`,
};
await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: ${{ steps.initial-comment.outputs.comment_id }},
body: messages[status] || `${marker}\n⏱️ **Build taking longer than expected.**\n\nExpected URL (may not be ready yet): ${previewUrl}`,
});
# Handle PR Close: Clean up resource
- name: Delete Amplify PR Preview
if: github.event.action == 'closed'
run: |
APP_ID="$AMPLIFY_APP_ID"
aws amplify delete-branch --app-id "$APP_ID" --branch-name "$BRANCH_NAME"