Repository navigation
Bump actions/checkout from 4 to 7 - #100
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Resolved: the repository now defines the |
|
Checked against the actions/checkout v5-v7 release notes. None of the breaking changes affect these three workflows:
The bump also clears main's current
Unrelated, noticed while checking:
|
|
@bigsamich Thanks for checking the checkout changes against the actual workflows. I'm comfortable with the direction, subject to a refreshed branch and the required green check on that exact head. The stale-base result should not be the merge evidence. The Dependabot ecosystem correction belongs in #125; disabling persisted credentials where no subsequent step needs them is a useful separate hardening change. The fixes above are in progress. I'll post the changed commits and validation before requesting another code review. |
|
@bigsamich, #100 is refreshed against current Your runner and workflow compatibility review still applies. Credential persistence and Dependabot configuration are being handled in the focused #125 follow-up. This update is ready for another review. |
derekste
left a comment
There was a problem hiding this comment.
LGTM at ae99b01. The change remains limited to the three checkout action references. Checkout v7's runner requirements and fork-checkout restrictions are compatible with these workflows, and the current required build-test is green. Bobby's compatibility review and the refreshed-branch evidence are consistent with the diff. No critical blocker found.
Bumps actions/checkout from 4 to 7.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)df4cb1cUpdate changelog for v6.0.3 (#2446)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)