Skip to content

[scanner] pr-queue-hygiene.mjs is dead code: no workflow ever invokes it, so the 48h stale-PR gate never runs #454

Description

@hivecommons-hive

Finding

scripts/pr-queue-hygiene.mjs — the 48h stale-conflict gate that labels conflicting PRs needs-rebase-or-close and posts nag comments — is invoked by no workflow. It has been dead code since the day it landed.

  • grep -rn 'pr-queue-hygiene' .github/ → no matches (main @ 0fd5f8b).
  • git log --all -- '.github/workflows/*hygiene*' → empty: a hygiene workflow never existed.
  • The script's own usage comment claims the opposite: "Requires gh authenticated with pull-requests: write on this repo (as the workflow already grants)" — the workflow it references does not exist.
  • The repo has exactly 5 workflows (ci.yml, create-milestones.yml, deploy-gh-pages.yml, import-architectures.yml, refresh-community-people.yml); none runs it, and npm run pr-queue-hygiene is reachable from nothing.

Impact

Two rounds of hardening have landed (and a third is in flight) on a code path that never executes:

  1. ci: fix pr-queue-hygiene mergeable check to use per-PR API fetch #240 added the script (as ci: fix pr-queue-hygiene mergeable check…) with no workflow.
  2. fix: only honor pr-queue-hygiene conflict markers from the job's own bot #429 (merged 2026-09-21) fixed the spoofable-marker trust boundary from [sec-check] pr-queue-hygiene.mjs honors its first-conflict marker from any PR commenter: unauthenticated control over the 48h stale-conflict gate #427 — dead code.
  3. fix: clear stale pr-queue-hygiene conflict marker and paginate comments #433 (open, clean) fixes the stale-marker-clear and comment-pagination defects from pr-queue-hygiene: stale conflict marker never cleared on deconflict; comment lookup unpaginated #432 — will also land on dead code.

Meanwhile the queue problem the script exists to solve is real: #81 tracks 50+ stranded mergeable PRs, and the collision issues (#372–#380) document the churn an un-run hygiene job was supposed to tame. Every PR that stops conflicting keeps its stale marker forever; every PR conflicting >48h goes un-nagged; the needs-rebase-or-close label is never applied or removed.

Recommendation

Add .github/workflows/pr-queue-hygiene.yml, e.g.:

name: PR queue hygiene
on:
  schedule:
    - cron: '17 */6 * * *'
  workflow_dispatch:
permissions:
  pull-requests: write
  issues: write   # labels + comments
jobs:
  hygiene:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
      - run: node scripts/pr-queue-hygiene.mjs
        env:
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

First run should use DRY_RUN=1 to preview label/comment actions before going live.

Needs a human with maintainer credentials, or an agent whose App installation has Workflows read/write — the contributor-tier App token cannot push under .github/workflows/** (same constraint recorded in #428 / #444).


Filed by scanner agent (ACMM L4 — issues-only mode)

🐝 Hive Agent: scanner | Instance: hosted-available-lke648397-260827-5n31 | SHA: 0fd5f8b

— hive: agent=scanner backend=copilot model=kimi-k3

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/scannerApproved by a Hive merger/owner for auto-merge on green CIblockedWaiting on something outside this repository; not contributor work until a human clears the labelbugSomething isn't workinghive/hosted-available-lke648397-260827-5n31Approved by a Hive merger/owner for auto-merge on green CI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions