Skip to content

chore(deps): bump actions/checkout from 4.3.1 to 7.0.0#98

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.0
Open

chore(deps): bump actions/checkout from 4.3.1 to 7.0.0#98
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4.3.1 to 7.0.0.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.1 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v4.3.1...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 23, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@greptile-apps

greptile-apps Bot commented Jun 23, 2026

Copy link
Copy Markdown

Greptile Summary

This PR updates actions/checkout from v6.0.3 to v7.0.0 across all five GitHub Actions workflow files. The change is straightforward and consistent.

  • All five workflow files are updated: ci.yml (4 jobs), codeql.yml, dependabot-fmt.yml, mirror.yml, and release.yml.
  • mirror.yml correctly updates its SHA-pinned reference (34e114876b0b...9c091bb21b7c1...) to match the v7.0.0 HEAD commit, preserving the security-conscious pinning pattern that was already in place.
  • The key breaking change in v7 — blocking fork PR checkouts for pull_request_target and workflow_run triggers — does not affect this repository, as none of the workflows use those event triggers.

Confidence Score: 5/5

Safe to merge — all changes are a mechanical version bump with no logic modifications.

All five workflow files consistently update a single dependency version string. The mirror.yml SHA pin is correctly updated to the v7.0.0 HEAD commit. None of the repo's workflows use pull_request_target or workflow_run, so the one behavioral change introduced in v7 (blocking fork PR checkouts on those triggers) has no effect here.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/ci.yml Updates 4 checkout steps from v6.0.3 to v7.0.0; all use floating tag references, consistent with prior pattern
.github/workflows/mirror.yml Updates SHA-pinned checkout from v4 commit to v7.0.0 HEAD commit; SHA-pin pattern correctly preserved
.github/workflows/dependabot-fmt.yml Updates checkout to v7.0.0; uses pull_request trigger (not pull_request_target), so v7's fork-blocking change is not a concern
.github/workflows/codeql.yml Single checkout step updated to v7.0.0; no functional impact
.github/workflows/release.yml Single checkout step updated to v7.0.0; no functional impact

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Workflow Triggered] --> B{Which workflow?}
    B --> C["ci.yml (pull_request / push)"]
    B --> D["codeql.yml (schedule / push)"]
    B --> E["dependabot-fmt.yml (pull_request)"]
    B --> F["mirror.yml (push / workflow_dispatch)"]
    B --> G["release.yml (push)"]

    C --> H["actions/checkout v7.0.0 floating tag"]
    D --> H
    E --> H
    G --> H
    F --> I["actions/checkout SHA-pinned v7.0.0"]

    H --> J[Continue workflow steps]
    I --> J

    style I fill:#d4edda,stroke:#28a745
    style H fill:#d4edda,stroke:#28a745
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
    A[Workflow Triggered] --> B{Which workflow?}
    B --> C["ci.yml (pull_request / push)"]
    B --> D["codeql.yml (schedule / push)"]
    B --> E["dependabot-fmt.yml (pull_request)"]
    B --> F["mirror.yml (push / workflow_dispatch)"]
    B --> G["release.yml (push)"]

    C --> H["actions/checkout v7.0.0 floating tag"]
    D --> H
    E --> H
    G --> H
    F --> I["actions/checkout SHA-pinned v7.0.0"]

    H --> J[Continue workflow steps]
    I --> J

    style I fill:#d4edda,stroke:#28a745
    style H fill:#d4edda,stroke:#28a745
Loading

Reviews (1): Last reviewed commit: "chore(deps): bump actions/checkout from ..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants