Turn it on
1
Run smartcloud on a schedule
The sweep runs only on
schedule and workflow_dispatch events. Make sure your workflow has both:.github/workflows/smartcloud.yml
2
Give the job write access to issues and pull requests
Locking needs
issues: write for issues and pull-requests: write for pull requests. The workflow token has both with the permissions in Getting started.3
Add a lock section
.github/smartcloud.yml
4
Run it once by hand
Run the workflow from the Actions tab and read the job summary. With the action’s
dryRun: true input, it lists what it would lock without locking anything.Options
A pull request counts as closed whether it was merged or not.
Complete example
.github/smartcloud.yml
How it works
- smartcloud searches the repository for closed, unlocked issues and pull requests closed more than
afterDaysago, one search for each kind inon. - Items with an
exempt.labelslabel are skipped. - For each other item, smartcloud posts
comment, addslabel, and then locks the conversation withreason. The comment and label come first, while the thread is still open to them.
roles.trustedBots counts.
GitHub’s search returns at most 1,000 items for each kind. A repository with a larger backlog of closed, unlocked threads is worked through over several sweeps.
Each item is locked on its own. When GitHub fails on one, the sweep records an error naming it and carries on with the rest.
What you will see on GitHub
- On the item: your
comment, yourlabel, and the conversation locked, with GitHub’s “locked as resolved” (or yourreason) note. - Check run:
smartcloud / lock, concludingsuccesswhen every item was locked andfailurewhen any could not be. See check runs. - Job summary: each comment, label and lock, as a list of changes.
Forks and restricted runs
Scheduled and manually dispatched runs never come from a fork, so the feature never runs with a fork’s read-only token. It works with the plain workflow token. In a restricted run, a write GitHub refuses is skipped and listed under Restricted access in the job summary.Troubleshooting
Nothing is locked on pull request or push runs
Nothing is locked on pull request or push runs
The sweep runs only on
schedule and workflow_dispatch. Add a schedule, or run the workflow by hand.Error: #123 was not locked: ...
Error: #123 was not locked: ...
GitHub refused or failed that item. Usually the job is missing
issues: write (for issues) or pull-requests: write (for pull requests). The rest of the sweep carried on, and the next sweep tries again.Some old items are still unlocked
Some old items are still unlocked
GitHub’s search returns at most 1,000 items of each kind per sweep, so a large backlog takes several sweeps. Search
results can also lag a few minutes behind recent closes.
The config is rejected: reason
The config is rejected: reason
reason accepts only resolved, off-topic, too heated (with the space) or spam.