Conversation
The Spec Update workflow opens a PR, arms auto-merge, and finishes green
regardless of the outcome, so a PR that stalls (failing CI, merge conflict,
review required, auto-merge disabled) sits open silently. This scheduled
watchdog asserts 'no automated-spec-update PR is still open past a grace
window' and fails loudly when violated.
Uses only the built-in GITHUB_TOKEN (no new credential). Slack delivery is via
the GitHub Slack app by subscribing to this workflow's scheduled runs:
/github subscribe <owner>/<repo> workflows:{name:"Spec Update Watchdog" event:"schedule"}
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #602 +/- ##
=======================================
Coverage 65.34% 65.34%
=======================================
Files 36 36
Lines 68053 68053
Branches 4909 4909
=======================================
Hits 44468 44468
Misses 23330 23330
Partials 255 255
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Contributor
Author
|
Superseded by a centralized Spec Update Watchdog in dropbox/dropbox-api-spec, which checks all SDK repos from one place (reusing the existing sdk-updater app token via AWS OIDC). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The
Spec Updateworkflow opens a PR, arms auto-merge (gh pr merge --auto), and then finishes green regardless of the outcome. If the PR later stalls — failing CI, merge conflict,REVIEW_REQUIRED, auto-merge silently not armed — it just sits open and nothing signals it. That's how the 2026-09-29 spec updates went unmerged across several repos unnoticed.Subscribing to CI-failure notifications doesn't cover this: it only sees check failures (not conflicts / review blocks), fires on ephemeral PR branches the default subscription filter can't match, and is noisy across all PRs.
What this does
A scheduled watchdog that asserts the end-state invariant: no
automated-spec-updatePR is still open past a grace window.workflow_dispatch.automated-spec-updatelabel using only the built-inGITHUB_TOKEN(pull-requests: read) — no new credential.GRACE_MINUTES(60) so a run legitimately mid-CI doesn't trip it.Notifications
Delivery rides the GitHub Slack app (no secret in the job). Subscribe once per repo in the target channel:
(
event:"schedule"matters — the defaultpull_requestfilter wouldn't match a cron run.)Notes