Skip to content

ci: auto-delete head branch after merging automation PRs - #63

Merged
SilverKnightKMA merged 1 commit into
mainfrom
ci/delete-automation-branch
Jul 20, 2026
Merged

SilverKnightKMA merged 1 commit into
mainfrom
ci/delete-automation-branch

Conversation

@SilverKnightKMA

Copy link
Copy Markdown
Owner

Why

GitHub's repo-level delete_branch_on_merge setting is not honored when PRs are auto-merged via GraphQL (gh pr merge --auto). As a result, automation branches like automated/update-managed-tools accumulate as dangling refs after every weekly merge (see cli/cli#9073).

This is why the branch keeps showing up in git log --graph after PRs like #62 are merged.

What

Add .github/workflows/delete-branch-on-close.yml — a pull_request_target workflow that deletes the head branch when an automation PR closes as merged.

Scope (safe by design):

  • Only deletes branches in the same repository (fork branches are skipped).
  • Only deletes branches matching automation prefixes (automated/*, dependabot/*, deps/*, chore/*) or authored by trusted automation bots (dependabot[bot], app/dependabot, github-actions[bot]).
  • Idempotent: if the branch is already gone, the step is a no-op.
  • Concurrency-grouped per PR to avoid races.

Verification

  • YAML syntax validated locally.
  • Logic mirrors the manual cleanup done for PR chore: update managed mounted tools #62 (which left origin/automated/update-managed-tools dangling until deleted via REST API).

GitHub's repo-level delete_branch_on_merge setting is not honored when
PRs are auto-merged via GraphQL (gh pr merge --auto), so automation
branches like automated/update-managed-tools accumulate as dangling refs
after every weekly merge (see cli/cli#9073).

Add a pull_request_target workflow that deletes the head branch when an
automation PR closes as merged. Scope is limited to same-repo branches
with automation prefixes or trusted bot authors; fork branches are
skipped and deletion is idempotent.
Copilot AI review requested due to automatic review settings July 20, 2026 10:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@SilverKnightKMA
SilverKnightKMA merged commit 1f9c7d5 into main Jul 20, 2026
6 of 7 checks passed
@SilverKnightKMA
SilverKnightKMA deleted the ci/delete-automation-branch branch July 20, 2026 10:54
SilverKnightKMA added a commit that referenced this pull request Jul 20, 2026
The root cause of lingering branches was NOT that delete_branch_on_merge
fails with auto-merge (that was my earlier, incorrect diagnosis). The
repo setting works fine for Dependabot PRs, which use unique branch
names per version bump.

The real issue: update-managed-tools.yml reused a fixed branch name
'automated/update-managed-tools' across every weekly cron run. When that
PR was merged and auto-deleted, the next cron push recreated the same
branch, so it always appeared to linger.

Switch to a run-id-suffixed branch name so each PR maps to a one-shot
branch that GitHub's delete_branch_on_merge removes cleanly, matching
the Dependabot pattern.

Also drop the redundant delete-branch-on-close.yml workflow added in
#63 - it is no longer needed now that the actual root cause is fixed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants