REPOMATIC-SYNC-ACTION-PINS(1) REPOMATIC-SYNC-ACTION-PINS(1)

repomatic sync-action-pins - Bump SHA-pinned GitHub Actions to their latest release

repomatic sync-action-pins [OPTIONS]

Bump SHA-pinned GitHub Actions across `.github/` to their latest release.

Scans workflow and composite-action files for
`uses: owner/repo@<sha> # vX.Y.Z` pins, resolves each action's latest
release passing the [tool.repomatic] minimum-release-age cooldown to its
commit SHA, and rewrites the SHA and version comment. repomatic's own
reusable-workflow refs are left to `repomatic init`.

Write a markdown report (version table) to this file.
Fetch release notes from GitHub (markdown, appended after the table).
Report newer releases withheld by the minimum-release-age cooldown.
Format for --output. github-actions produces format for PR template consumption in workflows.
Show this message and exit.

Write a markdown report (version table) to this file.
Fetch release notes from GitHub (markdown, appended after the table).
Report newer releases withheld by the minimum-release-age cooldown.
Format for --output. github-actions produces format for PR template consumption in workflows.
Show this message and exit.

0
Success.
1
A runtime error, or an aborted prompt (Ctrl-C, a declined confirmation).
2
A usage error: unknown option, invalid value, missing operand, or an unparsable configuration file.

Bump every SHA-pinned action past the cooldown

repomatic sync\-action\-pins

Kevin Deldycke

2026-09-14 7.15.1.dev0