mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
The `pull_request: closed` cleanup is the fast path, not a guarantee: GitHub does not run that workflow when the head ref is already gone at event time, which is what Dependabot does when it supersedes one of its own PRs. 15 `test-pr-<n>` drafts had been orphaned that way, 13 of them Dependabot's. Add a daily scheduled (and manually dispatchable) sweep to the same workflow. It lists every draft tagged `^test-pr-[0-9]+$`, asks GitHub for that PR's live state, and deletes only when the PR reports closed. It fails closed: a PR lookup error leaves the draft untouched, a failed release listing fails the job rather than sweeping a short list, and only a confirmed HTTP 404 excuses a failed delete — `gh api` exits 1 for every failure alike, so the re-check reads the response status instead of the exit code. Workflow permissions drop to `contents: read`; the event job keeps `actions: write` + `contents: write`, the sweep takes only `contents: write`. No new actions. Docs: new "Rolling test drafts" section in docs/architecture/release-pipeline.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>