← Docs
Constraining updates to a semver range
Between full tracking and opting out entirely, you can also cap re-pinning to a semver range. Append ActionLock: <range> to a pinned line's comment instead of no-op:
- uses: actions/setup-node@f1015b3489dcd52c087c02c8f8cd1a8f6a3edb6d # v3 ActionLock: ~3.8
On each staleness re-check, ActionLock looks up the action's own published tags and re-pins to the highest version matching the range — ~3.8 allows patch releases within 3.8.x, but never bumps to 3.9.0. Standard npm-style range syntax is supported (^4, ~4.1, 4.1.x, an exact version, and more). An unrecognized or invalid range is treated the same as no-op — ActionLock fails closed rather than silently falling back to unrestricted tracking.