Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package arkade for openSUSE:Factory checked 
in at 2026-09-21 12:10:05
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/arkade (Old)
 and      /work/SRC/openSUSE:Factory/.arkade.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "arkade"

Mon Sep 21 12:10:05 2026 rev:93 rq:1379211 version:0.11.126

Changes:
--------
--- /work/SRC/openSUSE:Factory/arkade/arkade.changes    2026-08-29 
17:43:59.416500840 +0200
+++ /work/SRC/openSUSE:Factory/.arkade.new.383539/arkade.changes        
2026-09-21 12:10:13.015675842 +0200
@@ -1,0 +2,6 @@
+Sun Sep 20 07:36:50 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 0.11.126:
+  * Vendor gha-bump v0.0.7
+
+-------------------------------------------------------------------

Old:
----
  arkade-0.11.125.obscpio

New:
----
  arkade-0.11.126.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ arkade.spec ++++++
--- /var/tmp/diff_new_pack.6Egmps/_old  2026-09-21 12:10:14.346731224 +0200
+++ /var/tmp/diff_new_pack.6Egmps/_new  2026-09-21 12:10:14.347731266 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           arkade
-Version:        0.11.125
+Version:        0.11.126
 Release:        0
 Summary:        Open Source Kubernetes Marketplace
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.6Egmps/_old  2026-09-21 12:10:14.411733929 +0200
+++ /var/tmp/diff_new_pack.6Egmps/_new  2026-09-21 12:10:14.415734095 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/alexellis/arkade.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/0.11.125</param>
+    <param name="revision">refs/tags/0.11.126</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.6Egmps/_old  2026-09-21 12:10:14.440735135 +0200
+++ /var/tmp/diff_new_pack.6Egmps/_new  2026-09-21 12:10:14.445735343 +0200
@@ -3,6 +3,6 @@
                 <param name="url">https://github.com/alexellis/arkade</param>
               <param 
name="changesrevision">37af31c7b58de8f16a10067051e3bbe7ecb6aa79</param></service><service
 name="tar_scm">
                 <param 
name="url">https://github.com/alexellis/arkade.git</param>
-              <param 
name="changesrevision">33a2800b924945754376c0a24189ed5d41ef3af7</param></service></servicedata>
+              <param 
name="changesrevision">4414c15437e0d787b5130c717b1f266cfb6f9a3f</param></service></servicedata>
 (No newline at EOF)
 

++++++ arkade-0.11.125.obscpio -> arkade-0.11.126.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/arkade-0.11.125/cmd/gha/gha.go 
new/arkade-0.11.126/cmd/gha/gha.go
--- old/arkade-0.11.125/cmd/gha/gha.go  2026-08-28 15:22:25.000000000 +0200
+++ new/arkade-0.11.126/cmd/gha/gha.go  2026-08-29 09:36:17.000000000 +0200
@@ -27,16 +27,19 @@
 func MakeBump() *cobra.Command {
        var command = &cobra.Command{
                Use:     "bump",
-               Short:   "Upgrade actions in GitHub Actions workflow files to 
the latest major version",
+               Short:   "Upgrade actions in GitHub Actions workflow files to 
the latest versions",
                Aliases: []string{"u"},
-               Long: `Upgrade actions in GitHub Actions workflow files to the 
latest major version.
+               Long: `Upgrade actions in GitHub Actions workflow files to the 
latest version.
 
 Processes all workflow YAML files in .github/workflows/ or a single file.
-Only bumps major versions (e.g. actions/checkout@v3 to actions/checkout@v4).
+Floating major tags are bumped per major version (e.g. actions/checkout@v3
+to actions/checkout@v4) and stay floating. Exact pins, including tags
+without a "v" prefix, are bumped to the full latest release (e.g.
+alexellis/[email protected] to 0.5.0).
 
-Only versioned tags can be bumped. If an action is pinned to @master,
-move it onto a tag once (e.g. checkout@v1) and bump will keep it current
-from then on.
+Only versioned tags can be bumped. If an action is pinned to @master or
+@main, move it onto a tag once (e.g. checkout@v1) and bump will keep it
+current from then on.
 `,
                Example: `  # Upgrade all workflows in the current directory
   arkade gha bump
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/arkade-0.11.125/go.mod new/arkade-0.11.126/go.mod
--- old/arkade-0.11.125/go.mod  2026-08-28 15:22:25.000000000 +0200
+++ new/arkade-0.11.126/go.mod  2026-08-29 09:36:17.000000000 +0200
@@ -21,7 +21,7 @@
 
 require (
        github.com/Masterminds/semver v1.5.0
-       github.com/alexellis/gha-bump v0.0.6
+       github.com/alexellis/gha-bump v0.0.7
        github.com/ulikunitz/xz v0.5.16
 )
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/arkade-0.11.125/go.sum new/arkade-0.11.126/go.sum
--- old/arkade-0.11.125/go.sum  2026-08-28 15:22:25.000000000 +0200
+++ new/arkade-0.11.126/go.sum  2026-08-29 09:36:17.000000000 +0200
@@ -6,6 +6,8 @@
 github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330/go.mod 
h1:EeXLSmvkiUDzy3ut257lc0f+uoehgAU9NXsC+/i1ySg=
 github.com/alexellis/gha-bump v0.0.6 
h1:s4isGq/UwLdvd6wDLJBcYrynY5KgQme4nH8spxQ/82o=
 github.com/alexellis/gha-bump v0.0.6/go.mod 
h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM=
+github.com/alexellis/gha-bump v0.0.7 
h1:O9mKDn9eMyeo6mCG38Y//1r2EmgIGQRGwr9eRIWoSR4=
+github.com/alexellis/gha-bump v0.0.7/go.mod 
h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM=
 github.com/alexellis/go-execute/v2 v2.2.1 
h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI=
 github.com/alexellis/go-execute/v2 v2.2.1/go.mod 
h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ=
 github.com/cespare/xxhash/v2 v2.3.0 
h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs=
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/arkade-0.11.125/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 
new/arkade-0.11.126/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go
--- 
old/arkade-0.11.125/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 
    2026-08-28 15:22:25.000000000 +0200
+++ 
new/arkade-0.11.126/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 
    2026-08-29 09:36:17.000000000 +0200
@@ -119,7 +119,7 @@
        return files, nil
 }
 
-// ProcessWorkflow parses a workflow and suggests major version upgrades.
+// ProcessWorkflow parses a workflow and suggests version upgrades.
 func ProcessWorkflow(data []byte, client *http.Client, verbose bool) 
(map[string]string, error) {
        workflow, err := parseWorkflow(data)
        if err != nil {
@@ -174,7 +174,7 @@
                        }
 
                        if len(uses) > 0 {
-                               newVer, err := suggestMajorUpgrade(client, uses)
+                               newVer, err := suggestUpgrade(client, uses)
                                if err != nil {
                                        return nil, err
                                }
@@ -199,18 +199,23 @@
        return content
 }
 
-// suggestMajorUpgrade suggests the latest major version for an action.
-func suggestMajorUpgrade(client *http.Client, uses string) (string, error) {
+// suggestUpgrade suggests the latest version for an action.
+// Floating major tags (e.g. checkout@v4) only move when the major version
+// changes and stay floating, while exact pins (e.g. [email protected],
+// commonly without a "v" prefix) are bumped to the full latest tag.
+func suggestUpgrade(client *http.Client, uses string) (string, error) {
        ownerRepo, currentVer, ok := strings.Cut(uses, "@")
-       if !ok || currentVer == "master" {
+       if !ok {
                return "", nil
        }
        owner, repo, ok := strings.Cut(ownerRepo, "/")
-       if !ok {
+       if !ok || strings.HasPrefix(ownerRepo, "./") {
                return "", nil
        }
 
-       if !strings.HasPrefix(currentVer, "v") {
+       oldSemver, err := semver.NewVersion(currentVer)
+       if err != nil {
+               // branch names (main, master) and SHA pins cannot be bumped
                return "", nil
        }
 
@@ -219,20 +224,24 @@
                return "", err
        }
 
-       oldSemver, err := semver.NewVersion(currentVer)
-       if err != nil {
-               return "", err
-       }
        newSemver, err := semver.NewVersion(version)
        if err != nil {
-               return "", err
+               // the upstream's latest tag is not semver, skip
+               return "", nil
        }
 
-       if newSemver.Major() > oldSemver.Major() {
-               return fmt.Sprintf("v%d", newSemver.Major()), nil
+       if !newSemver.GreaterThan(oldSemver) {
+               return "", nil
+       }
+
+       if strings.HasPrefix(currentVer, "v") {
+               if newSemver.Major() > oldSemver.Major() {
+                       return fmt.Sprintf("v%d", newSemver.Major()), nil
+               }
+               return "", nil
        }
 
-       return "", nil
+       return version, nil
 }
 
 // getLatestVersion fetches the latest release version from GitHub.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/arkade-0.11.125/vendor/modules.txt 
new/arkade-0.11.126/vendor/modules.txt
--- old/arkade-0.11.125/vendor/modules.txt      2026-08-28 15:22:25.000000000 
+0200
+++ new/arkade-0.11.126/vendor/modules.txt      2026-08-29 09:36:17.000000000 
+0200
@@ -7,7 +7,7 @@
 # github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330
 ## explicit; go 1.24.0
 github.com/alexellis/fstail/pkg/fstail
-# github.com/alexellis/gha-bump v0.0.6
+# github.com/alexellis/gha-bump v0.0.7
 ## explicit; go 1.25.0
 github.com/alexellis/gha-bump/pkg/ghabump
 # github.com/alexellis/go-execute/v2 v2.2.1

++++++ arkade.obsinfo ++++++
--- /var/tmp/diff_new_pack.6Egmps/_old  2026-09-21 12:10:15.424776079 +0200
+++ /var/tmp/diff_new_pack.6Egmps/_new  2026-09-21 12:10:15.430776328 +0200
@@ -1,5 +1,5 @@
 name: arkade
-version: 0.11.125
-mtime: 1787923345
-commit: 33a2800b924945754376c0a24189ed5d41ef3af7
+version: 0.11.126
+mtime: 1787988977
+commit: 4414c15437e0d787b5130c717b1f266cfb6f9a3f
 

++++++ gha-bump.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/gha-bump/README.md new/gha-bump/README.md
--- old/gha-bump/README.md      2026-03-23 23:08:06.000000000 +0100
+++ new/gha-bump/README.md      2026-08-29 09:34:32.000000000 +0200
@@ -33,13 +33,20 @@
   - name: Checkout code
 -   uses: actions/checkout@v2
 +   uses: actions/checkout@v4
+  - name: Upload release assets
+-   uses: alexellis/[email protected]
++   uses: alexellis/[email protected]
 ```
 
+Floating major tags (e.g. `checkout@v4`) are only bumped when the major
+version changes, and stay floating. Exact pins (e.g.
+`[email protected]`) are bumped to the full latest release, and tags
+without a `v` prefix are supported.
+
 Caveats:
 
-* Does not modify the `master` tag if used for an action - 
`actions/checkout@master` - so set it to `v1` and then let it get upgraded
+* Does not modify the `master`/`main` branch tags if used for an action - 
`actions/checkout@master` - so set it to `v1` and then let it get upgraded
 * Ignores actions which have been pinned with a SHA - 
`actions/checkout@sha1234567890`
-* Ignores actions without a semver-like `v` prefix - 
`alexellis/[email protected]`
 
 ## Contributing and feature requests
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/gha-bump/main.go new/gha-bump/main.go
--- old/gha-bump/main.go        2026-03-23 23:08:06.000000000 +0100
+++ new/gha-bump/main.go        2026-08-29 09:34:32.000000000 +0200
@@ -17,11 +17,14 @@
 
        var rootCmd = &cobra.Command{
                Use:   "gha-bump",
-               Short: "Upgrade GitHub Actions workflow files to latest major 
versions",
-               Long: `Upgrade actions in GitHub Actions workflow files to the 
latest major version.
+               Short: "Upgrade GitHub Actions workflow files to the latest 
versions",
+               Long: `Upgrade actions in GitHub Actions workflow files to the 
latest version.
 
 Processes all workflow YAML files in .github/workflows/ or a single file.
-Only bumps major versions (e.g. actions/checkout@v3 to actions/checkout@v4).
+Floating major tags are bumped per major version (e.g. actions/checkout@v3
+to actions/checkout@v4) and stay floating. Exact pins, including tags
+without a "v" prefix, are bumped to the full latest release (e.g.
+alexellis/[email protected] to 0.5.0).
 `,
                Example: `  # Upgrade all workflows in the current directory
   gha-bump
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/gha-bump/pkg/ghabump/ghabump.go 
new/gha-bump/pkg/ghabump/ghabump.go
--- old/gha-bump/pkg/ghabump/ghabump.go 2026-03-23 23:08:06.000000000 +0100
+++ new/gha-bump/pkg/ghabump/ghabump.go 2026-08-29 09:34:32.000000000 +0200
@@ -119,7 +119,7 @@
        return files, nil
 }
 
-// ProcessWorkflow parses a workflow and suggests major version upgrades.
+// ProcessWorkflow parses a workflow and suggests version upgrades.
 func ProcessWorkflow(data []byte, client *http.Client, verbose bool) 
(map[string]string, error) {
        workflow, err := parseWorkflow(data)
        if err != nil {
@@ -174,7 +174,7 @@
                        }
 
                        if len(uses) > 0 {
-                               newVer, err := suggestMajorUpgrade(client, uses)
+                               newVer, err := suggestUpgrade(client, uses)
                                if err != nil {
                                        return nil, err
                                }
@@ -199,18 +199,23 @@
        return content
 }
 
-// suggestMajorUpgrade suggests the latest major version for an action.
-func suggestMajorUpgrade(client *http.Client, uses string) (string, error) {
+// suggestUpgrade suggests the latest version for an action.
+// Floating major tags (e.g. checkout@v4) only move when the major version
+// changes and stay floating, while exact pins (e.g. [email protected],
+// commonly without a "v" prefix) are bumped to the full latest tag.
+func suggestUpgrade(client *http.Client, uses string) (string, error) {
        ownerRepo, currentVer, ok := strings.Cut(uses, "@")
-       if !ok || currentVer == "master" {
+       if !ok {
                return "", nil
        }
        owner, repo, ok := strings.Cut(ownerRepo, "/")
-       if !ok {
+       if !ok || strings.HasPrefix(ownerRepo, "./") {
                return "", nil
        }
 
-       if !strings.HasPrefix(currentVer, "v") {
+       oldSemver, err := semver.NewVersion(currentVer)
+       if err != nil {
+               // branch names (main, master) and SHA pins cannot be bumped
                return "", nil
        }
 
@@ -219,20 +224,24 @@
                return "", err
        }
 
-       oldSemver, err := semver.NewVersion(currentVer)
-       if err != nil {
-               return "", err
-       }
        newSemver, err := semver.NewVersion(version)
        if err != nil {
-               return "", err
+               // the upstream's latest tag is not semver, skip
+               return "", nil
        }
 
-       if newSemver.Major() > oldSemver.Major() {
-               return fmt.Sprintf("v%d", newSemver.Major()), nil
+       if !newSemver.GreaterThan(oldSemver) {
+               return "", nil
+       }
+
+       if strings.HasPrefix(currentVer, "v") {
+               if newSemver.Major() > oldSemver.Major() {
+                       return fmt.Sprintf("v%d", newSemver.Major()), nil
+               }
+               return "", nil
        }
 
-       return "", nil
+       return version, nil
 }
 
 // getLatestVersion fetches the latest release version from GitHub.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/gha-bump/pkg/ghabump/ghabump_test.go 
new/gha-bump/pkg/ghabump/ghabump_test.go
--- old/gha-bump/pkg/ghabump/ghabump_test.go    1970-01-01 01:00:00.000000000 
+0100
+++ new/gha-bump/pkg/ghabump/ghabump_test.go    2026-08-29 09:34:32.000000000 
+0200
@@ -0,0 +1,145 @@
+package ghabump
+
+import (
+       "fmt"
+       "net/http"
+       "strings"
+       "testing"
+)
+
+type stubTransport struct {
+       tag string
+}
+
+func (s stubTransport) RoundTrip(req *http.Request) (*http.Response, error) {
+       loc := fmt.Sprintf("https://github.com/owner/repo/releases/tag/%s";, 
s.tag)
+       return &http.Response{
+               StatusCode: http.StatusFound,
+               Status:     "302 Found",
+               Proto:      "HTTP/1.1",
+               Header:     http.Header{"Location": []string{loc}},
+               Body:       http.NoBody,
+       }, nil
+}
+
+func stubClient(latestTag string) *http.Client {
+       return &http.Client{
+               CheckRedirect: func(req *http.Request, via []*http.Request) 
error {
+                       return http.ErrUseLastResponse
+               },
+               Transport: stubTransport{tag: latestTag},
+       }
+}
+
+func Test_SuggestUpgrade(t *testing.T) {
+       tests := []struct {
+               name     string
+               uses     string
+               latest   string
+               expected string
+       }{
+               {
+                       name:     "floating major tag bumps on major version",
+                       uses:     "actions/checkout@v3",
+                       latest:   "v4.2.2",
+                       expected: "v4",
+               },
+               {
+                       name:     "floating major tag stays put on minor 
release",
+                       uses:     "actions/checkout@v4",
+                       latest:   "v4.3.0",
+                       expected: "",
+               },
+               {
+                       name:     "exact pin with v prefix stays put within 
major",
+                       uses:     "actions/[email protected]",
+                       latest:   "v1.9.0",
+                       expected: "",
+               },
+               {
+                       name:     "exact pin with v prefix bumps to floating 
major",
+                       uses:     "actions/[email protected]",
+                       latest:   "v2.0.0",
+                       expected: "v2",
+               },
+               {
+                       name:     "v-less exact pin bumps to latest full tag",
+                       uses:     "alexellis/[email protected]",
+                       latest:   "0.5.0",
+                       expected: "0.5.0",
+               },
+               {
+                       name:     "v-less exact pin bumps on patch release",
+                       uses:     "alexellis/[email protected]",
+                       latest:   "0.5.1",
+                       expected: "0.5.1",
+               },
+               {
+                       name:     "v-less exact pin already at latest",
+                       uses:     "alexellis/[email protected]",
+                       latest:   "0.5.0",
+                       expected: "",
+               },
+               {
+                       name:     "branch pin master is skipped",
+                       uses:     "actions/checkout@master",
+                       latest:   "v4.2.2",
+                       expected: "",
+               },
+               {
+                       name:     "branch pin main is skipped",
+                       uses:     "actions/checkout@main",
+                       latest:   "v4.2.2",
+                       expected: "",
+               },
+               {
+                       name:     "SHA pin is skipped",
+                       uses:     
"actions/checkout@a1234567890abcdef1234567890abcdef1234567",
+                       latest:   "v4.2.2",
+                       expected: "",
+               },
+               {
+                       name:     "local composite action is skipped",
+                       uses:     "./.github/actions/test@v1",
+                       latest:   "v2.0.0",
+                       expected: "",
+               },
+       }
+
+       for _, tc := range tests {
+               t.Run(tc.name, func(t *testing.T) {
+                       got, err := suggestUpgrade(stubClient(tc.latest), 
tc.uses)
+                       if err != nil {
+                               t.Fatalf("unexpected error: %v", err)
+                       }
+                       if got != tc.expected {
+                               t.Fatalf("expected %q got %q", tc.expected, got)
+                       }
+               })
+       }
+}
+
+func Test_ApplyReplacements(t *testing.T) {
+       workflow := `name: build
+on: push
+jobs:
+  build:
+    steps:
+      - uses: alexellis/[email protected]
+      - uses: actions/checkout@v3
+`
+
+       replacements := map[string]string{
+               "alexellis/[email protected]": "0.5.0",
+               "actions/checkout@v3":           "v4",
+       }
+
+       updated := ApplyReplacements([]byte(workflow), replacements)
+
+       if !strings.Contains(updated, "alexellis/[email protected]") {
+               t.Fatalf("expected upload-assets to be bumped, got:\n%s", 
updated)
+       }
+       if !strings.Contains(updated, "actions/checkout@v4") {
+               t.Fatalf("expected checkout to be bumped, got:\n%s", updated)
+       }
+}

++++++ vendor.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/go.mod new/go.mod
--- old/go.mod  2026-08-29 09:07:38.632695204 +0200
+++ new/go.mod  2026-09-20 09:43:22.630842092 +0200
@@ -21,7 +21,7 @@
 
 require (
        github.com/Masterminds/semver v1.5.0
-       github.com/alexellis/gha-bump v0.0.6
+       github.com/alexellis/gha-bump v0.0.7
        github.com/ulikunitz/xz v0.5.16
 )
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/go.sum new/go.sum
--- old/go.sum  2026-08-29 09:07:38.632695204 +0200
+++ new/go.sum  2026-09-20 09:43:22.629842089 +0200
@@ -4,8 +4,8 @@
 github.com/Masterminds/semver/v3 v3.5.0/go.mod 
h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM=
 github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330 
h1:M7Yh2fMnNuNWFTeQ0clLP7jdIJNLwVTgEDvWPtN8mL0=
 github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330/go.mod 
h1:EeXLSmvkiUDzy3ut257lc0f+uoehgAU9NXsC+/i1ySg=
-github.com/alexellis/gha-bump v0.0.6 
h1:s4isGq/UwLdvd6wDLJBcYrynY5KgQme4nH8spxQ/82o=
-github.com/alexellis/gha-bump v0.0.6/go.mod 
h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM=
+github.com/alexellis/gha-bump v0.0.7 
h1:O9mKDn9eMyeo6mCG38Y//1r2EmgIGQRGwr9eRIWoSR4=
+github.com/alexellis/gha-bump v0.0.7/go.mod 
h1:DoVZXvmzy/SjVJcIkdPQEgUFGJc/aZEXM4Rmi//HpBM=
 github.com/alexellis/go-execute/v2 v2.2.1 
h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI=
 github.com/alexellis/go-execute/v2 v2.2.1/go.mod 
h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ=
 github.com/cespare/xxhash/v2 v2.3.0 
h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs=
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go 
new/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go
--- old/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go     
2026-08-29 09:07:40.288394633 +0200
+++ new/vendor/github.com/alexellis/gha-bump/pkg/ghabump/ghabump.go     
2026-09-20 09:43:24.262632987 +0200
@@ -119,7 +119,7 @@
        return files, nil
 }
 
-// ProcessWorkflow parses a workflow and suggests major version upgrades.
+// ProcessWorkflow parses a workflow and suggests version upgrades.
 func ProcessWorkflow(data []byte, client *http.Client, verbose bool) 
(map[string]string, error) {
        workflow, err := parseWorkflow(data)
        if err != nil {
@@ -174,7 +174,7 @@
                        }
 
                        if len(uses) > 0 {
-                               newVer, err := suggestMajorUpgrade(client, uses)
+                               newVer, err := suggestUpgrade(client, uses)
                                if err != nil {
                                        return nil, err
                                }
@@ -199,18 +199,23 @@
        return content
 }
 
-// suggestMajorUpgrade suggests the latest major version for an action.
-func suggestMajorUpgrade(client *http.Client, uses string) (string, error) {
+// suggestUpgrade suggests the latest version for an action.
+// Floating major tags (e.g. checkout@v4) only move when the major version
+// changes and stay floating, while exact pins (e.g. [email protected],
+// commonly without a "v" prefix) are bumped to the full latest tag.
+func suggestUpgrade(client *http.Client, uses string) (string, error) {
        ownerRepo, currentVer, ok := strings.Cut(uses, "@")
-       if !ok || currentVer == "master" {
+       if !ok {
                return "", nil
        }
        owner, repo, ok := strings.Cut(ownerRepo, "/")
-       if !ok {
+       if !ok || strings.HasPrefix(ownerRepo, "./") {
                return "", nil
        }
 
-       if !strings.HasPrefix(currentVer, "v") {
+       oldSemver, err := semver.NewVersion(currentVer)
+       if err != nil {
+               // branch names (main, master) and SHA pins cannot be bumped
                return "", nil
        }
 
@@ -219,20 +224,24 @@
                return "", err
        }
 
-       oldSemver, err := semver.NewVersion(currentVer)
-       if err != nil {
-               return "", err
-       }
        newSemver, err := semver.NewVersion(version)
        if err != nil {
-               return "", err
+               // the upstream's latest tag is not semver, skip
+               return "", nil
        }
 
-       if newSemver.Major() > oldSemver.Major() {
-               return fmt.Sprintf("v%d", newSemver.Major()), nil
+       if !newSemver.GreaterThan(oldSemver) {
+               return "", nil
+       }
+
+       if strings.HasPrefix(currentVer, "v") {
+               if newSemver.Major() > oldSemver.Major() {
+                       return fmt.Sprintf("v%d", newSemver.Major()), nil
+               }
+               return "", nil
        }
 
-       return "", nil
+       return version, nil
 }
 
 // getLatestVersion fetches the latest release version from GitHub.
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/vendor/modules.txt new/vendor/modules.txt
--- old/vendor/modules.txt      2026-08-29 09:07:40.402698806 +0200
+++ new/vendor/modules.txt      2026-09-20 09:43:24.614847938 +0200
@@ -7,7 +7,7 @@
 # github.com/alexellis/fstail v0.0.0-20260301203901-2641eb3ce330
 ## explicit; go 1.24.0
 github.com/alexellis/fstail/pkg/fstail
-# github.com/alexellis/gha-bump v0.0.6
+# github.com/alexellis/gha-bump v0.0.7
 ## explicit; go 1.25.0
 github.com/alexellis/gha-bump/pkg/ghabump
 # github.com/alexellis/go-execute/v2 v2.2.1

++++++ vendor_go_modules.sh ++++++
--- /var/tmp/diff_new_pack.6Egmps/_old  2026-09-21 12:10:16.302812612 +0200
+++ /var/tmp/diff_new_pack.6Egmps/_new  2026-09-21 12:10:16.307812820 +0200
@@ -39,11 +39,6 @@
 ls -lah
 
 echo "##########"
-echo "Cloning gha-bump"
-GHABUMP_COMMIT="$(awk '/^require github.com\/alexellis\/gha-bump/ {print $NF}' 
go.mod)"
-git clone https://github.com/alexellis/gha-bump ../gha-bump || exit 25
-
-echo "##########"
 echo "Vendoring the go modules"
 go mod tidy
 go mod download || exit 33

Reply via email to