chore(deps): bump actions/checkout from 4.3.1 to 7.0.0#98
chore(deps): bump actions/checkout from 4.3.1 to 7.0.0#98dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.1 to 7.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v4.3.1...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Greptile SummaryThis PR updates
Confidence Score: 5/5Safe to merge — all changes are a mechanical version bump with no logic modifications. All five workflow files consistently update a single dependency version string. The mirror.yml SHA pin is correctly updated to the v7.0.0 HEAD commit. None of the repo's workflows use pull_request_target or workflow_run, so the one behavioral change introduced in v7 (blocking fork PR checkouts on those triggers) has no effect here. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Workflow Triggered] --> B{Which workflow?}
B --> C["ci.yml (pull_request / push)"]
B --> D["codeql.yml (schedule / push)"]
B --> E["dependabot-fmt.yml (pull_request)"]
B --> F["mirror.yml (push / workflow_dispatch)"]
B --> G["release.yml (push)"]
C --> H["actions/checkout v7.0.0 floating tag"]
D --> H
E --> H
G --> H
F --> I["actions/checkout SHA-pinned v7.0.0"]
H --> J[Continue workflow steps]
I --> J
style I fill:#d4edda,stroke:#28a745
style H fill:#d4edda,stroke:#28a745
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
A[Workflow Triggered] --> B{Which workflow?}
B --> C["ci.yml (pull_request / push)"]
B --> D["codeql.yml (schedule / push)"]
B --> E["dependabot-fmt.yml (pull_request)"]
B --> F["mirror.yml (push / workflow_dispatch)"]
B --> G["release.yml (push)"]
C --> H["actions/checkout v7.0.0 floating tag"]
D --> H
E --> H
G --> H
F --> I["actions/checkout SHA-pinned v7.0.0"]
H --> J[Continue workflow steps]
I --> J
style I fill:#d4edda,stroke:#28a745
style H fill:#d4edda,stroke:#28a745
Reviews (1): Last reviewed commit: "chore(deps): bump actions/checkout from ..." | Re-trigger Greptile |
Bumps actions/checkout from 4.3.1 to 7.0.0.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)df4cb1cUpdate changelog for v6.0.3 (#2446)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)