Skip to content

chore(deps): bump actions/checkout from 6 to 7#69

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Open

chore(deps): bump actions/checkout from 6 to 7#69
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 20, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Vercel preview failed for 950b8ffc43b42bbebdcd917b0941338990733f5b

See the workflow run for details.

@greptile-apps

greptile-apps Bot commented Jun 20, 2026

Copy link
Copy Markdown

Greptile Summary

This is a Dependabot-generated bump of actions/checkout from v6 to v7 across all nine GitHub Actions workflow files. The key behavioral change in v7 is a security hardening that blocks checkout of fork PRs under pull_request_target and workflow_run triggers — none of the workflows in this repo use those triggers, so there is no functional impact.

  • Files that were already SHA-pinned (publish-pages.yaml, release-please.yml) are updated to the correct v7.0.0 commit SHA (9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0) with updated inline comments.
  • Files using floating version tags are uniformly updated from @v6 to @v7; storage-integration.yml moves from the more-specific @v6.0.2 to @v7, aligning it with the rest of the non-pinned workflows.

Confidence Score: 5/5

Safe to merge — a straightforward version bump with no functional changes to any workflow logic.

All nine workflows are updated consistently. The only behavioral change in v7 (blocking fork checkouts for pull_request_target/workflow_run triggers) does not apply here since every workflow uses push or pull_request triggers. SHA-pinned files have their commit hash and inline comments correctly updated to v7.0.0.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/ci.yml Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/deploy-vercel-preview.yml Bumps actions/checkout from @v6 to @v7; workflow uses pull_request trigger (not pull_request_target), so v7's new fork-blocking behavior has no impact
.github/workflows/deploy-vercel-staging.yml Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/deploy-vercel.yml Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/publish-pages.yaml Updates SHA-pinned checkout from v6.0.2 commit to v7.0.0 commit (9c091bb); comment correctly updated to # v7.0.0
.github/workflows/release-please.yml Updates both SHA-pinned checkout occurrences from v6.0.2 to v7.0.0 commit SHA; comments correctly reflect new version
.github/workflows/release.yml Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/self-deploy.yml Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/storage-integration.yml Bumps actions/checkout from @v6.0.2 to @v7, moving from a patch-pinned tag to a floating major tag — consistent with the other non-SHA-pinned workflows in the repo

Reviews (1): Last reviewed commit: "chore(deps): bump actions/checkout from ..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants