Skip to content

v0.4.0: --pin-only

Choose a tag to compare

@cosmichackerx cosmichackerx released this 02 Oct 20:40
· 15 commits to main since this release
6bb9349

What's new

  • --pin-only (issue #7): replaces tag refs by the commit SHA they point to today, with the most specific release on that commit as a comment. Same major, no upgrade; branch refs, existing SHAs, local and docker actions are untouched and listed on stderr. Idempotent; --dry-run prints a unified diff that git apply accepts; CRLF safe.
  • --fix and --pin-only share one edit planner (no change to --fix behaviour; the existing tests still pass).

Verified

  • 65 tests pass; CI green on Ubuntu, Windows and macOS (Node 20/22/24).
  • Live check against github.com: actions/checkout@v4 resolved to the commit that v4.4.0 points to (confirmed with git ls-remote), actions/setup-node@v4.1.0 to its tag commit; the output passes git apply --check.

Not verified

  • Only the first 300 tags of a repository are searched; a moving tag can change between the lookup and the merge.
  • Marketplace listing remains a manual step for the repository owner.