Repository navigation
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two independent fixes for gen1->gen2 migration e2e failures. Neither is a migration-logic regression; the amplify-cli code is unchanged since the last green run in July. Both failures are environment-driven and were surfaced by external changes.
Fix 1 - AppSync ApiKey /Expires drift false positive (7 gen2_migration groups)
The gen2-migration drift gate flagged AWS::AppSync::ApiKey /Expires as drift. An ApiKey's Expires is createTime+validity set at deploy; the gate re-derives the expected Expires at a later lock time, so the two values legitimately differ by the deploy->lock elapsed time (observed ~20 min; e.g. deployed 1.7912736E+9 vs expected 1791274802). This is a benign time-relative difference, not schema drift. Adds a FALSE_POSITIVE_FILTER (isAppSyncApiKeyExpiresTimeRelativeDrift) that drops /Expires drift on AWS::AppSync::ApiKey when both values parse as epoch-like timestamps (> ~2020); no tolerance/closeness comparison, and the epoch guard prevents masking non-timestamp mutations.
Fix 2 - generated Gen2 app dependency float -> Cognito Invalid AttributeDataType (2 groups)
store_locator and fitness_tracker (the only apps with Cognito Lambda triggers, which drive a UserPool UPDATE) failed ampx sandbox with 'Invalid AttributeDataType input' on the UserPool. The generated app pins unbounded ^ ranges with no committed lockfile, so installs float per run; a newer @aws-amplify/auth-construct (1.12.0, via backend-auth 1.10.0 / backend >=1.25.0, published 2026-09-10) and/or aws-cdk-lib (floated to 2.271) emit a UserPool schema attribute the UPDATE path rejects. Pins @aws-amplify/backend ~1.23.0 and aws-cdk/aws-cdk-lib ~2.254.0 (the last-known-good July minors) so migrated apps resolve reproducibly. Other packages keep caret intentionally.
Testing
Unit: detect-stack-drift.test.ts 12/12; package.json.generator.test.ts 4/4. e2e: gen2-migration Linux split batch triggered (AmplifyCLI-E2E-Testing:70b94c16-5257-4c8b-b8ca-f9d75156c7e3), validation in progress.