Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package arkade for openSUSE:Factory checked in at 2026-09-21 12:10:05 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/arkade (Old) and /work/SRC/openSUSE:Factory/.arkade.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "arkade" Mon Sep 21 12:10:05 2026 rev:93 rq:1379211 version:0.11.126 Changes: -------- --- /work/SRC/openSUSE:Factory/arkade/arkade.changes 2026-08-29 17:43:59.416500840 +0200 +++ /work/SRC/openSUSE:Factory/.arkade.new.383539/arkade.changes 2026-09-21 12:10:13.015675842 +0200 @@ -1,0 +2,6 @@ +Sun Sep 20 07:36:50 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 0.11.126: + * Vendor gha-bump v0.0.7 + +------------------------------------------------------------------- Old: ---- arkade-0.11.125.obscpio New: ---- arkade-0.11.126.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ arkade.spec ++++++ --- /var/tmp/diff_new_pack.6Egmps/_old 2026-09-21 12:10:14.346731224 +0200 +++ /var/tmp/diff_new_pack.6Egmps/_new 2026-09-21 12:10:14.347731266 +0200 @@ -17,7 +17,7 @@ Name: arkade -Version: 0.11.125 +Version: 0.11.126 Release: 0 Summary: Open Source Kubernetes Marketplace License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.6Egmps/_old 2026-09-21 12:10:14.411733929 +0200 +++ /var/tmp/diff_new_pack.6Egmps/_new 2026-09-21 12:10:14.415734095 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/alexellis/arkade.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/0.11.125</param> + <param name="revision">refs/tags/0.11.126</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.6Egmps/_old 2026-09-21 12:10:14.440735135 +0200 +++ /var/tmp/diff_new_pack.6Egmps/_new 2026-09-21 12:10:14.445735343 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/alexellis/arkade</param> <param name="changesrevision">37af31c7b58de8f16a10067051e3bbe7ecb6aa79</param></service><service name="tar_scm"> <param name="url">https://github.com/alexellis/arkade.git</param> - <param name="changesrevision">33a2800b924945754376c0a24189ed5d41ef3af7</param></service></servicedata> + <param name="changesrevision">4414c15437e0d787b5130c717b1f266cfb6f9a3f</param></service></servicedata> (No newline at EOF) ++++++ arkade-0.11.125.obscpio -> arkade-0.11.126.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/arkade-0.11.125/cmd/gha/gha.go new/arkade-0.11.126/cmd/gha/gha.go --- old/arkade-0.11.125/cmd/gha/gha.go 2026-08-28 15:22:25.000000000 +0200 +++ new/arkade-0.11.126/cmd/gha/gha.go 2026-08-29 09:36:17.000000000 +0200 @@ -27,16 +27,19 @@ func MakeBump() *cobra.Command { var command = &cobra.Command{ Use: "bump", - Short: "Upgrade actions in GitHub Actions workflow files to the latest major version", + Short: "Upgrade actions in GitHub Actions workflow files to the latest versions", Aliases: []string{"u"}, - Long: `Upgrade actions in GitHub Actions workflow files to the latest major version. + Long: `Upgrade actions in GitHub Actions workflow files to the latest version. Processes all workflow YAML files in .github/workflows/ or a single file. -Only bumps major versions (e.g. actions/checkout@v3 to actions/checkout@v4). +Floating major tags are bumped per major version (e.g. actions/checkout@v3 +to actions/checkout@v4) and stay floating. Exact pins, including tags +without a "v" prefix, are bumped to the full latest release (e.g. +alexellis/[email protected] to 0.5.0). -Only versioned tags can be bumped. If an action is pinned to @master, -move it onto a tag once (e.g. checkout@v1) and bump will keep it current -from then on. +Only versioned tags can be bumped. If an action is pinned to @master or +@main, move it onto a tag once (e.g. checkout@v1) and bump will keep it +current from then on. `, Example: ` # Upgrade all workflows in the current directory arkade gha bump diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/arkade-0.11.125/go.mod new/arkade-0.11.126/go.mod --- old/arkade-0.11.125/go.mod 2026-08-28 15:22:25.000000000 +0200 +++ new/arkade-0.11.126/go.mod 2026-08-29 09:36:17.000000000 +0200 @@ -21,7 +21,7 @@ require ( github.com/Masterminds/semver v1.5.0 - github.com/alexellis/gha-bump v0.0.6 + github.com/alexellis/gha-bump v0.0.7 github.com/ulikunitz/xz v0.5.16 ) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/arkade-0.11.125/go.sum new/arkade-0.11.126/go.sum --- old/arkade-0.11.125/go.sum 2026-08-28 15:22:25.000000000 +0200 +++ new/arkade-0.11.126/go.sum 2026-08-29 09:36:17.000000000 +0200 @@ -6,6 +6,8 @@ github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330/go.mod h1:EeXLSmvkiUDzy3ut257lc0f+uoehgAU9NXsC+/i1ySg= github.com/alexellis/gha-bump v0.0.6 h1:s4isGq/UwLdvd6wDLJBcYrynY5KgQme4nH8spxQ/82o= github.com/alexellis/gha-bump v0.0.6/go.mod h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM= +github.com/alexellis/gha-bump v0.0.7 h1:O9mKDn9eMyeo6mCG38Y//1r2EmgIGQRGwr9eRIWoSR4= +github.com/alexellis/gha-bump v0.0.7/go.mod h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM= github.com/alexellis/go-execute/v2 v2.2.1 h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI= github.com/alexellis/go-execute/v2 v2.2.1/go.mod h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ= github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/arkade-0.11.125/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go new/arkade-0.11.126/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go --- old/arkade-0.11.125/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 2026-08-28 15:22:25.000000000 +0200 +++ new/arkade-0.11.126/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 2026-08-29 09:36:17.000000000 +0200 @@ -119,7 +119,7 @@ return files, nil } -// ProcessWorkflow parses a workflow and suggests major version upgrades. +// ProcessWorkflow parses a workflow and suggests version upgrades. func ProcessWorkflow(data []byte, client *http.Client, verbose bool) (map[string]string, error) { workflow, err := parseWorkflow(data) if err != nil { @@ -174,7 +174,7 @@ } if len(uses) > 0 { - newVer, err := suggestMajorUpgrade(client, uses) + newVer, err := suggestUpgrade(client, uses) if err != nil { return nil, err } @@ -199,18 +199,23 @@ return content } -// suggestMajorUpgrade suggests the latest major version for an action. -func suggestMajorUpgrade(client *http.Client, uses string) (string, error) { +// suggestUpgrade suggests the latest version for an action. +// Floating major tags (e.g. checkout@v4) only move when the major version +// changes and stay floating, while exact pins (e.g. [email protected], +// commonly without a "v" prefix) are bumped to the full latest tag. +func suggestUpgrade(client *http.Client, uses string) (string, error) { ownerRepo, currentVer, ok := strings.Cut(uses, "@") - if !ok || currentVer == "master" { + if !ok { return "", nil } owner, repo, ok := strings.Cut(ownerRepo, "/") - if !ok { + if !ok || strings.HasPrefix(ownerRepo, "./") { return "", nil } - if !strings.HasPrefix(currentVer, "v") { + oldSemver, err := semver.NewVersion(currentVer) + if err != nil { + // branch names (main, master) and SHA pins cannot be bumped return "", nil } @@ -219,20 +224,24 @@ return "", err } - oldSemver, err := semver.NewVersion(currentVer) - if err != nil { - return "", err - } newSemver, err := semver.NewVersion(version) if err != nil { - return "", err + // the upstream's latest tag is not semver, skip + return "", nil } - if newSemver.Major() > oldSemver.Major() { - return fmt.Sprintf("v%d", newSemver.Major()), nil + if !newSemver.GreaterThan(oldSemver) { + return "", nil + } + + if strings.HasPrefix(currentVer, "v") { + if newSemver.Major() > oldSemver.Major() { + return fmt.Sprintf("v%d", newSemver.Major()), nil + } + return "", nil } - return "", nil + return version, nil } // getLatestVersion fetches the latest release version from GitHub. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/arkade-0.11.125/vendor/modules.txt new/arkade-0.11.126/vendor/modules.txt --- old/arkade-0.11.125/vendor/modules.txt 2026-08-28 15:22:25.000000000 +0200 +++ new/arkade-0.11.126/vendor/modules.txt 2026-08-29 09:36:17.000000000 +0200 @@ -7,7 +7,7 @@ # github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330 ## explicit; go 1.24.0 github.com/alexellis/fstail/pkg/fstail -# github.com/alexellis/gha-bump v0.0.6 +# github.com/alexellis/gha-bump v0.0.7 ## explicit; go 1.25.0 github.com/alexellis/gha-bump/pkg/ghabump # github.com/alexellis/go-execute/v2 v2.2.1 ++++++ arkade.obsinfo ++++++ --- /var/tmp/diff_new_pack.6Egmps/_old 2026-09-21 12:10:15.424776079 +0200 +++ /var/tmp/diff_new_pack.6Egmps/_new 2026-09-21 12:10:15.430776328 +0200 @@ -1,5 +1,5 @@ name: arkade -version: 0.11.125 -mtime: 1787923345 -commit: 33a2800b924945754376c0a24189ed5d41ef3af7 +version: 0.11.126 +mtime: 1787988977 +commit: 4414c15437e0d787b5130c717b1f266cfb6f9a3f ++++++ gha-bump.tar.gz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/gha-bump/README.md new/gha-bump/README.md --- old/gha-bump/README.md 2026-03-23 23:08:06.000000000 +0100 +++ new/gha-bump/README.md 2026-08-29 09:34:32.000000000 +0200 @@ -33,13 +33,20 @@ - name: Checkout code - uses: actions/checkout@v2 + uses: actions/checkout@v4 + - name: Upload release assets +- uses: alexellis/[email protected] ++ uses: alexellis/[email protected] ``` +Floating major tags (e.g. `checkout@v4`) are only bumped when the major +version changes, and stay floating. Exact pins (e.g. +`[email protected]`) are bumped to the full latest release, and tags +without a `v` prefix are supported. + Caveats: -* Does not modify the `master` tag if used for an action - `actions/checkout@master` - so set it to `v1` and then let it get upgraded +* Does not modify the `master`/`main` branch tags if used for an action - `actions/checkout@master` - so set it to `v1` and then let it get upgraded * Ignores actions which have been pinned with a SHA - `actions/checkout@sha1234567890` -* Ignores actions without a semver-like `v` prefix - `alexellis/[email protected]` ## Contributing and feature requests diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/gha-bump/main.go new/gha-bump/main.go --- old/gha-bump/main.go 2026-03-23 23:08:06.000000000 +0100 +++ new/gha-bump/main.go 2026-08-29 09:34:32.000000000 +0200 @@ -17,11 +17,14 @@ var rootCmd = &cobra.Command{ Use: "gha-bump", - Short: "Upgrade GitHub Actions workflow files to latest major versions", - Long: `Upgrade actions in GitHub Actions workflow files to the latest major version. + Short: "Upgrade GitHub Actions workflow files to the latest versions", + Long: `Upgrade actions in GitHub Actions workflow files to the latest version. Processes all workflow YAML files in .github/workflows/ or a single file. -Only bumps major versions (e.g. actions/checkout@v3 to actions/checkout@v4). +Floating major tags are bumped per major version (e.g. actions/checkout@v3 +to actions/checkout@v4) and stay floating. Exact pins, including tags +without a "v" prefix, are bumped to the full latest release (e.g. +alexellis/[email protected] to 0.5.0). `, Example: ` # Upgrade all workflows in the current directory gha-bump diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/gha-bump/pkg/ghabump/ghabump.go new/gha-bump/pkg/ghabump/ghabump.go --- old/gha-bump/pkg/ghabump/ghabump.go 2026-03-23 23:08:06.000000000 +0100 +++ new/gha-bump/pkg/ghabump/ghabump.go 2026-08-29 09:34:32.000000000 +0200 @@ -119,7 +119,7 @@ return files, nil } -// ProcessWorkflow parses a workflow and suggests major version upgrades. +// ProcessWorkflow parses a workflow and suggests version upgrades. func ProcessWorkflow(data []byte, client *http.Client, verbose bool) (map[string]string, error) { workflow, err := parseWorkflow(data) if err != nil { @@ -174,7 +174,7 @@ } if len(uses) > 0 { - newVer, err := suggestMajorUpgrade(client, uses) + newVer, err := suggestUpgrade(client, uses) if err != nil { return nil, err } @@ -199,18 +199,23 @@ return content } -// suggestMajorUpgrade suggests the latest major version for an action. -func suggestMajorUpgrade(client *http.Client, uses string) (string, error) { +// suggestUpgrade suggests the latest version for an action. +// Floating major tags (e.g. checkout@v4) only move when the major version +// changes and stay floating, while exact pins (e.g. [email protected], +// commonly without a "v" prefix) are bumped to the full latest tag. +func suggestUpgrade(client *http.Client, uses string) (string, error) { ownerRepo, currentVer, ok := strings.Cut(uses, "@") - if !ok || currentVer == "master" { + if !ok { return "", nil } owner, repo, ok := strings.Cut(ownerRepo, "/") - if !ok { + if !ok || strings.HasPrefix(ownerRepo, "./") { return "", nil } - if !strings.HasPrefix(currentVer, "v") { + oldSemver, err := semver.NewVersion(currentVer) + if err != nil { + // branch names (main, master) and SHA pins cannot be bumped return "", nil } @@ -219,20 +224,24 @@ return "", err } - oldSemver, err := semver.NewVersion(currentVer) - if err != nil { - return "", err - } newSemver, err := semver.NewVersion(version) if err != nil { - return "", err + // the upstream's latest tag is not semver, skip + return "", nil } - if newSemver.Major() > oldSemver.Major() { - return fmt.Sprintf("v%d", newSemver.Major()), nil + if !newSemver.GreaterThan(oldSemver) { + return "", nil + } + + if strings.HasPrefix(currentVer, "v") { + if newSemver.Major() > oldSemver.Major() { + return fmt.Sprintf("v%d", newSemver.Major()), nil + } + return "", nil } - return "", nil + return version, nil } // getLatestVersion fetches the latest release version from GitHub. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/gha-bump/pkg/ghabump/ghabump_test.go new/gha-bump/pkg/ghabump/ghabump_test.go --- old/gha-bump/pkg/ghabump/ghabump_test.go 1970-01-01 01:00:00.000000000 +0100 +++ new/gha-bump/pkg/ghabump/ghabump_test.go 2026-08-29 09:34:32.000000000 +0200 @@ -0,0 +1,145 @@ +package ghabump + +import ( + "fmt" + "net/http" + "strings" + "testing" +) + +type stubTransport struct { + tag string +} + +func (s stubTransport) RoundTrip(req *http.Request) (*http.Response, error) { + loc := fmt.Sprintf("https://github.com/owner/repo/releases/tag/%s", s.tag) + return &http.Response{ + StatusCode: http.StatusFound, + Status: "302 Found", + Proto: "HTTP/1.1", + Header: http.Header{"Location": []string{loc}}, + Body: http.NoBody, + }, nil +} + +func stubClient(latestTag string) *http.Client { + return &http.Client{ + CheckRedirect: func(req *http.Request, via []*http.Request) error { + return http.ErrUseLastResponse + }, + Transport: stubTransport{tag: latestTag}, + } +} + +func Test_SuggestUpgrade(t *testing.T) { + tests := []struct { + name string + uses string + latest string + expected string + }{ + { + name: "floating major tag bumps on major version", + uses: "actions/checkout@v3", + latest: "v4.2.2", + expected: "v4", + }, + { + name: "floating major tag stays put on minor release", + uses: "actions/checkout@v4", + latest: "v4.3.0", + expected: "", + }, + { + name: "exact pin with v prefix stays put within major", + uses: "actions/[email protected]", + latest: "v1.9.0", + expected: "", + }, + { + name: "exact pin with v prefix bumps to floating major", + uses: "actions/[email protected]", + latest: "v2.0.0", + expected: "v2", + }, + { + name: "v-less exact pin bumps to latest full tag", + uses: "alexellis/[email protected]", + latest: "0.5.0", + expected: "0.5.0", + }, + { + name: "v-less exact pin bumps on patch release", + uses: "alexellis/[email protected]", + latest: "0.5.1", + expected: "0.5.1", + }, + { + name: "v-less exact pin already at latest", + uses: "alexellis/[email protected]", + latest: "0.5.0", + expected: "", + }, + { + name: "branch pin master is skipped", + uses: "actions/checkout@master", + latest: "v4.2.2", + expected: "", + }, + { + name: "branch pin main is skipped", + uses: "actions/checkout@main", + latest: "v4.2.2", + expected: "", + }, + { + name: "SHA pin is skipped", + uses: "actions/checkout@a1234567890abcdef1234567890abcdef1234567", + latest: "v4.2.2", + expected: "", + }, + { + name: "local composite action is skipped", + uses: "./.github/actions/test@v1", + latest: "v2.0.0", + expected: "", + }, + } + + for _, tc := range tests { + t.Run(tc.name, func(t *testing.T) { + got, err := suggestUpgrade(stubClient(tc.latest), tc.uses) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + if got != tc.expected { + t.Fatalf("expected %q got %q", tc.expected, got) + } + }) + } +} + +func Test_ApplyReplacements(t *testing.T) { + workflow := `name: build +on: push +jobs: + build: + steps: + - uses: alexellis/[email protected] + - uses: actions/checkout@v3 +` + + replacements := map[string]string{ + "alexellis/[email protected]": "0.5.0", + "actions/checkout@v3": "v4", + } + + updated := ApplyReplacements([]byte(workflow), replacements) + + if !strings.Contains(updated, "alexellis/[email protected]") { + t.Fatalf("expected upload-assets to be bumped, got:\n%s", updated) + } + if !strings.Contains(updated, "actions/checkout@v4") { + t.Fatalf("expected checkout to be bumped, got:\n%s", updated) + } +} ++++++ vendor.tar.gz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/go.mod new/go.mod --- old/go.mod 2026-08-29 09:07:38.632695204 +0200 +++ new/go.mod 2026-09-20 09:43:22.630842092 +0200 @@ -21,7 +21,7 @@ require ( github.com/Masterminds/semver v1.5.0 - github.com/alexellis/gha-bump v0.0.6 + github.com/alexellis/gha-bump v0.0.7 github.com/ulikunitz/xz v0.5.16 ) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/go.sum new/go.sum --- old/go.sum 2026-08-29 09:07:38.632695204 +0200 +++ new/go.sum 2026-09-20 09:43:22.629842089 +0200 @@ -4,8 +4,8 @@ github.com/Masterminds/semver/v3 v3.5.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330 h1:M7Yh2fMnNuNWFTeQ0clLP7jdIJNLwVTgEDvWPtN8mL0= github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330/go.mod h1:EeXLSmvkiUDzy3ut257lc0f+uoehgAU9NXsC+/i1ySg= -github.com/alexellis/gha-bump v0.0.6 h1:s4isGq/UwLdvd6wDLJBcYrynY5KgQme4nH8spxQ/82o= -github.com/alexellis/gha-bump v0.0.6/go.mod h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM= +github.com/alexellis/gha-bump v0.0.7 h1:O9mKDn9eMyeo6mCG38Y//1r2EmgIGQRGwr9eRIWoSR4= +github.com/alexellis/gha-bump v0.0.7/go.mod h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM= github.com/alexellis/go-execute/v2 v2.2.1 h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI= github.com/alexellis/go-execute/v2 v2.2.1/go.mod h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ= github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go new/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go --- old/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 2026-08-29 09:07:40.288394633 +0200 +++ new/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 2026-09-20 09:43:24.262632987 +0200 @@ -119,7 +119,7 @@ return files, nil } -// ProcessWorkflow parses a workflow and suggests major version upgrades. +// ProcessWorkflow parses a workflow and suggests version upgrades. func ProcessWorkflow(data []byte, client *http.Client, verbose bool) (map[string]string, error) { workflow, err := parseWorkflow(data) if err != nil { @@ -174,7 +174,7 @@ } if len(uses) > 0 { - newVer, err := suggestMajorUpgrade(client, uses) + newVer, err := suggestUpgrade(client, uses) if err != nil { return nil, err } @@ -199,18 +199,23 @@ return content } -// suggestMajorUpgrade suggests the latest major version for an action. -func suggestMajorUpgrade(client *http.Client, uses string) (string, error) { +// suggestUpgrade suggests the latest version for an action. +// Floating major tags (e.g. checkout@v4) only move when the major version +// changes and stay floating, while exact pins (e.g. [email protected], +// commonly without a "v" prefix) are bumped to the full latest tag. +func suggestUpgrade(client *http.Client, uses string) (string, error) { ownerRepo, currentVer, ok := strings.Cut(uses, "@") - if !ok || currentVer == "master" { + if !ok { return "", nil } owner, repo, ok := strings.Cut(ownerRepo, "/") - if !ok { + if !ok || strings.HasPrefix(ownerRepo, "./") { return "", nil } - if !strings.HasPrefix(currentVer, "v") { + oldSemver, err := semver.NewVersion(currentVer) + if err != nil { + // branch names (main, master) and SHA pins cannot be bumped return "", nil } @@ -219,20 +224,24 @@ return "", err } - oldSemver, err := semver.NewVersion(currentVer) - if err != nil { - return "", err - } newSemver, err := semver.NewVersion(version) if err != nil { - return "", err + // the upstream's latest tag is not semver, skip + return "", nil } - if newSemver.Major() > oldSemver.Major() { - return fmt.Sprintf("v%d", newSemver.Major()), nil + if !newSemver.GreaterThan(oldSemver) { + return "", nil + } + + if strings.HasPrefix(currentVer, "v") { + if newSemver.Major() > oldSemver.Major() { + return fmt.Sprintf("v%d", newSemver.Major()), nil + } + return "", nil } - return "", nil + return version, nil } // getLatestVersion fetches the latest release version from GitHub. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/vendor/modules.txt new/vendor/modules.txt --- old/vendor/modules.txt 2026-08-29 09:07:40.402698806 +0200 +++ new/vendor/modules.txt 2026-09-20 09:43:24.614847938 +0200 @@ -7,7 +7,7 @@ # github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330 ## explicit; go 1.24.0 github.com/alexellis/fstail/pkg/fstail -# github.com/alexellis/gha-bump v0.0.6 +# github.com/alexellis/gha-bump v0.0.7 ## explicit; go 1.25.0 github.com/alexellis/gha-bump/pkg/ghabump # github.com/alexellis/go-execute/v2 v2.2.1 ++++++ vendor_go_modules.sh ++++++ --- /var/tmp/diff_new_pack.6Egmps/_old 2026-09-21 12:10:16.302812612 +0200 +++ /var/tmp/diff_new_pack.6Egmps/_new 2026-09-21 12:10:16.307812820 +0200 @@ -39,11 +39,6 @@ ls -lah echo "##########" -echo "Cloning gha-bump" -GHABUMP_COMMIT="$(awk '/^require github.com\/alexellis\/gha-bump/ {print $NF}' go.mod)" -git clone https://github.com/alexellis/gha-bump ../gha-bump || exit 25 - -echo "##########" echo "Vendoring the go modules" go mod tidy go mod download || exit 33
