Queries the GitHub tags API for repo, compares the newest semantic-
version tag against installed.version, and returns that version if it is
newer. Silently returns NULL on any failure (no network, rate limit,
unparseable response, non-interactive session) since this is a convenience
check and must never interrupt or slow down a script. Results are cached
on disk for cache.days so a session does not re-query GitHub every time
the package is attached.