Summary
Would it be possible to add a local upgrade operation that updates action version tags in YAML and regenerates actions.lock in one invocation?
Current behavior
--relock refreshes locked SHAs for existing mutable refs. It does not select newer version tags or update uses: references.
Upgrading to a newer version therefore requires updating the YAML references separately before regenerating the lockfile.
Expected behavior
An upgrade operation would:
- Update action version references in workflows and local composite actions.
- Keep readable version tags in YAML, with resolved commit SHAs in actions.lock.
- Regenerate the affected lock entries, including the required transitive dependencies.
For example, upgrading actions/checkout@v7.0.0 to actions/checkout@v7.0.1 would update both the YAML reference and the corresponding lock entries.
Related context
PR #30 removed the previous update command during the transition to a detached lockfile and mentioned adding it separately.
Would a local upgrade operation still fit the intended scope of the project?
Summary
Would it be possible to add a local upgrade operation that updates action version tags in YAML and regenerates actions.lock in one invocation?
Current behavior
--relockrefreshes locked SHAs for existing mutable refs. It does not select newer version tags or updateuses:references.Upgrading to a newer version therefore requires updating the YAML references separately before regenerating the lockfile.
Expected behavior
An upgrade operation would:
For example, upgrading
actions/checkout@v7.0.0toactions/checkout@v7.0.1would update both the YAML reference and the corresponding lock entries.Related context
PR #30 removed the previous update command during the transition to a detached lockfile and mentioned adding it separately.
Would a local upgrade operation still fit the intended scope of the project?