name: Close stale issues

on:
  schedule:
    - cron: '17 5 * * *'   # daily, off-peak
  workflow_dispatch: {}

permissions:
  issues: write
  pull-requests: write

jobs:
  stale:
    runs-on: ubuntu-latest
    timeout-minutes: 15
    steps:
      # Pinned from actions/stale@v10; update deliberately when refreshing the policy.
      - uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93
        with:
          days-before-stale: 14
          days-before-close: 7
          # No stale or close messages (founder, 2026-09-22). An empty message
          # makes actions/stale label and close without commenting (it checks
          # `staleIssueMessage.length === 0` at the pinned SHA). The `stale`
          # label is the signal; any reply removes it before the close.
          stale-issue-message: ''
          close-issue-message: ''
          stale-issue-label: 'stale'
          only-labels: 'needs-info'
          exempt-issue-labels: 'pinned,keep-open,release-blocker,security'
          # Don't touch PRs — `actions/stale` defaults can be aggressive
          # there. We only want it for `needs-info` issues.
          days-before-pr-stale: -1
          days-before-pr-close: -1
          operations-per-run: 60