From 040a576445abd80e80eba160e4b329eeb12595b8 Mon Sep 17 00:00:00 2001 From: Kenichi Kamiya Date: Thu, 1 Oct 2026 00:46:11 +0900 Subject: [PATCH 1/2] Add --version to test in package managers Currently, there is no option to get the CLI version in a sadbox environment. "--no-fix --json" includes it in ".cli_version" filed, but it requires a real GitHub account. --- cmd/gh-actions-lock/root.go | 1 + 1 file changed, 1 insertion(+) diff --git a/cmd/gh-actions-lock/root.go b/cmd/gh-actions-lock/root.go index 7ce32bcb..e6f5c6a3 100644 --- a/cmd/gh-actions-lock/root.go +++ b/cmd/gh-actions-lock/root.go @@ -117,6 +117,7 @@ $ gh actions-lock --no-fix --json=valid,findings # All fields as JSON $ gh actions-lock --json `), + Version: cliVersion(), PreRunE: func(cmd *cobra.Command, args []string) error { if len(args) > 0 { opts.workflowPaths = args From 54363b71519965c3fa0f40fd2f6179a12254881d Mon Sep 17 00:00:00 2001 From: Kenichi Kamiya Date: Thu, 1 Oct 2026 01:23:25 +0900 Subject: [PATCH 2/2] Test --version flag on root command The new --version flag had no test coverage. Add a hermetic test to verify that it prints the version and exits without calling the resolver or touching workflows. Assisted-by: Antigravity:gemini-3.8-flash --- cmd/gh-actions-lock/root_test.go | 37 ++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/cmd/gh-actions-lock/root_test.go b/cmd/gh-actions-lock/root_test.go index 20473a6e..0f22c83c 100644 --- a/cmd/gh-actions-lock/root_test.go +++ b/cmd/gh-actions-lock/root_test.go @@ -1,7 +1,12 @@ package main import ( + "bytes" + "strings" "testing" + + "github.com/github/gh-actions-lock/internal/pinpool" + "github.com/github/gh-actions-lock/internal/resolve" ) func TestNewRootCmdSuppressesCobraUsageForHandledErrors(t *testing.T) { @@ -10,3 +15,35 @@ func TestNewRootCmdSuppressesCobraUsageForHandledErrors(t *testing.T) { t.Fatalf("expected root command to suppress Cobra usage/errors for handled failures") } } + +func TestNewRootCmd_Version(t *testing.T) { + var stdout, stderr bytes.Buffer + cmd := newRootCmd(func(string, *pinpool.Pool) (*resolve.Resolver, error) { + t.Fatalf("unexpected resolver call: --version must skip resolution") + return nil, nil + }) + cmd.SetOut(&stdout) + cmd.SetErr(&stderr) + cmd.SetArgs([]string{"--version"}) + + if err := cmd.Execute(); err != nil { + t.Fatalf("unexpected error: %v", err) + } + + if stderr.Len() != 0 { + t.Fatalf("expected empty stderr, got %q", stderr.String()) + } + + // We check the output shape ("actions-lock version \n") instead of + // comparing with cliVersion(). cliVersion() reads build info that can change + // across build setups, and calling it here would only repeat the code. + const prefix = "actions-lock version " + out := stdout.String() + if !strings.HasPrefix(out, prefix) || !strings.HasSuffix(out, "\n") { + t.Fatalf("unexpected output format: %q", out) + } + version := strings.TrimSuffix(strings.TrimPrefix(out, prefix), "\n") + if version == "" { + t.Fatalf("expected non-empty version in stdout: %q", out) + } +}