Skip to content

build(deps): bump actions/checkout from 4.2.2 to 7.0.1#111

Merged
steipete merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.1
Jul 21, 2026
Merged

build(deps): bump actions/checkout from 4.2.2 to 7.0.1#111
steipete merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4.2.2 to 7.0.1.

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 20, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 20, 2026 18:57
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 20, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7.0.1 branch from 131dde3 to 3eeb0a0 Compare July 21, 2026 02:18
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v4.2.2...v7.0.1)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@steipete
steipete force-pushed the dependabot/github_actions/actions/checkout-7.0.1 branch from 3eeb0a0 to c549006 Compare July 21, 2026 02:24
@steipete
steipete merged commit 71c26e9 into main Jul 21, 2026
5 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/checkout-7.0.1 branch July 21, 2026 02:29
@steipete

Copy link
Copy Markdown
Contributor

Landed with the Dependabot author preserved.

Verified on the byte-identical reviewed patch and final exact head c549006957e0bb3c4ca427b3225abf6a5457f385:

  • v7.0.1 is the latest stable checkout release; tag v7 and v7.0.1 both resolve to signed commit 3d3c42e5aac5ba805825da76410c181273ba90b1
  • upstream action uses Node 24; minimum runner is v2.327.1
  • 24 of 25 changed sites already used actions/checkout@v7, so pinning v7.0.1 does not change their effective runtime; the updater's GitHub-hosted runner is v2.335.1
  • no affected workflow uses pull_request_target or workflow_run, so v7's unsafe-fork default does not break an existing checkout contract
  • all 12 workflows parsed; all 25 checkout refs match the intended tag/SHA; actionlint passed
  • all extracted translation shell blocks passed bash syntax; 79/79 i18n control-plane tests passed
  • AutoReview: clean, no accepted/actionable findings (0.99 confidence)

Hosted exact-head proof after the final sync rebase:

  • Docs Code CI run 29795734320: passed, including checkout, install, Worker dry-run, shell build/smoke, and browser visual smoke
  • CodeQL run 29795734316: Actions and JavaScript/TypeScript analyzers passed
  • Mintlify deployment: skipped; no deploy/translation/production workflow was dispatched

Rebase merge commit 71c26e9e51f99318c7a7f9c7ef62628442b0b555 retains dependabot[bot] as author. The landed tree is byte-equivalent to the reviewed PR head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant