Skip to content

build(deps): bump actions/checkout from 6 to 7#75

Merged
sjsyrek merged 1 commit into
mainfrom
dependabot/github_actions/main/actions/checkout-7
Jun 26, 2026
Merged

build(deps): bump actions/checkout from 6 to 7#75
sjsyrek merged 1 commit into
mainfrom
dependabot/github_actions/main/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 23, 2026
sjsyrek added a commit that referenced this pull request Jun 26, 2026
)

Resolve the four advisories reported by `npm audit --audit-level=moderate
--omit=dev` (the CI audit gate) with lockfile-only transitive updates; no
package.json ranges change:

- brace-expansion 5.0.5 -> 5.0.6 (GHSA-jxxr-4gwj-5jf2, ReDoS)
- form-data -> 4.0.6 (GHSA-hmw2-7cc7-3qxx, CRLF injection)
- ws 8.20.0 -> 8.21.0 (GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p)

Production `npm audit` is back to zero vulnerabilities, unblocking the
audit check on the open Dependabot PRs (#75, #76). Type-check, lint,
build, and the full test suite (5493 tests) pass.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
@sjsyrek

sjsyrek commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/main/actions/checkout-7 branch from fad6924 to a2d6c32 Compare June 26, 2026 07:07
@sjsyrek sjsyrek merged commit 0423d80 into main Jun 26, 2026
3 checks passed
@dependabot dependabot Bot deleted the dependabot/github_actions/main/actions/checkout-7 branch June 26, 2026 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant