<feed xmlns='http://www.w3.org/2005/Atom'>
<title>maintainer-tools/github-action-approve.py, branch master</title>
<subtitle>Maintainer scripts for OpenWrt</subtitle>
<id>https://git.openwrt.org/maintainer-tools/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/maintainer-tools/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/maintainer-tools/'/>
<updated>2026-09-24T18:59:49Z</updated>
<entry>
<title>github-action-approve.py: add tool to approve pending workflow runs</title>
<updated>2026-09-24T18:59:49Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2026-08-12T00:10:33Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/maintainer-tools/commit/?id=5f3d959043eee05e3ff50af5029ae054068047ad'/>
<id>urn:sha1:5f3d959043eee05e3ff50af5029ae054068047ad</id>
<content type='text'>
Workflow runs of pull requests coming from a fork are held back until a
maintainer approves them. The web interface only offers an approval
button for the newest run of a pull request, so all older runs of the
same pull request stay pending forever and have to be approved one by
one. This adds a script which approves all of them.

The runs are approved with the official REST endpoint:

  POST /repos/{owner}/{repo}/actions/runs/{run_id}/approve

Matching the runs to a pull request needs some care. The pull_requests
list of a workflow run is empty when the run was triggered from a fork,
which is exactly the case for the runs which need an approval. The runs
are therefore matched on the head repository and the head branch of the
pull request. This also finds the runs of commits which were replaced by
a force push and are not part of the pull request any more.

A pending run is reported with status "completed" and conclusion
"action_required", so both are checked. Runs which are held back by an
environment protection rule use the pending_deployments endpoint
instead.

The token is taken from the GitHub CLI and the script waits one second
after the server confirmed an approval to not run into the secondary
rate limits.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
</feed>
