Schedule icon
Webhook icon
Request icon
Script icon
If icon
SlackIncomingWebhook icon
Log icon

Audit and Alert on Stale GitHub Pull Requests

Audit open GitHub pull requests for inactivity, enforce review SLAs, export a markdown report artifact, and send actionable Slack alerts.

Categories
BusinessInfrastructureinfrastructure

Pull request inertia quietly undermines engineering delivery. Open pull requests that sit without reviewer feedback or author follow-up create merge conflicts, stale context, and contributor friction. While bots can auto-close stale issues, engineering leads and team maintainers need actionable operational visibility into neglected pull requests before closing them.

This blueprint implements an automated SLA monitor for GitHub pull requests. It polls the repository via the GitHub REST API, calculates inactivity periods against an SLA threshold while ignoring draft pull requests, compiles a downloadable markdown audit report artifact, and dispatches a structured summary to Slack when attention is needed.

How it works

  1. fetch_open_prs (io.kestra.plugin.core.http.Request) invokes the GitHub API endpoint /repos/{repository}/pulls sorted by oldest update timestamp, using your scoped GITHUB_TOKEN secret.
  2. analyze_pull_requests (io.kestra.plugin.scripts.python.Script) parses the JSON payload in a lightweight container, measures elapsed days since the last activity, skips draft PRs, and generates an internal markdown audit report stale-pr-report.md. It emits summary statistics via Kestra outputs.
  3. evaluate_stale_prs (io.kestra.plugin.core.flow.If) evaluates whether any pull requests breached the inactivity SLA and whether Slack alerts are enabled.
  4. When stale pull requests are present, alert_stale_prs (io.kestra.plugin.slack.notifications.SlackIncomingWebhook) delivers a Slack alert with PR numbers, titles, authors, and dormancy durations. When the repository is clean, log_healthy logs the status.
  5. The errors block alerts the team via Slack if GitHub API connectivity fails or credentials expire.
  6. Triggers: ships with a weekday morning Schedule (disabled by default) and an authenticated Webhook trigger for manual or CI/CD invocation.

What you get

  • Proactive visibility into dormant pull requests before code branches go stale.
  • Automated generation of a downloadable stale-pr-report.md artifact stored in Kestra.
  • Rich Slack notifications with direct links to stale PRs, usernames, and idle day counts.
  • Configurable dormancy thresholds and pull request evaluation limits.

Who it's for

  • Engineering managers and team leads maintaining review SLAs.
  • Open source maintainers tracking community contributor pull requests.
  • DevOps and Platform teams looking for zero-maintenance CI/CD workflow hygiene.

Why orchestrate this with Kestra

Instead of deploying custom cron daemons or writing brittle GitHub Actions scripts that run across dozens of individual repositories, Kestra centralizes pull request auditing in a single declarative workflow. You gain execution histories, retries, downloadable artifact storage, and flexible triggering across schedules or webhooks.

Prerequisites

  • A GitHub Personal Access Token (PAT) with repo or public_repo read scope.
  • A Slack Incoming Webhook URL.

Secrets

  • GITHUB_TOKEN: GitHub personal access token used to query the repository pull requests API.
  • SLACK_WEBHOOK_URL: Slack incoming webhook URL for delivery alerts and failure notifications.

Quick start

  1. Add GITHUB_TOKEN and SLACK_WEBHOOK_URL to your Kestra namespace secrets.
  2. Configure the repository input with your target repository (e.g. owner/repo).
  3. Adjust stale_days to match your team's code review SLA (default is 5 days).
  4. Click Execute in Kestra UI to run a manual verification.
  5. Enable the scheduled_audit trigger to automate weekday morning checks.

How to extend

  • Add an automated label (e.g. stale) directly on the GitHub PR using io.kestra.plugin.github.issues.AddLabels.
  • Route alerts to Microsoft Teams or Discord using their respective notification plugins.
  • Store historical audit metrics in DuckDB or PostgreSQL to track review velocity over time.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.