Skip to content

chore: bump actions/checkout from 6 to 7 - #722

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.0
Open

chore: bump actions/checkout from 6 to 7#722
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot
dependabot Bot requested a review from a team as a code owner June 18, 2026 22:33
@cursor

cursor Bot commented Jun 18, 2026

Copy link
Copy Markdown

PR Summary

Low Risk
Dependency-only CI change; v7’s stricter PR checkout rules are unlikely to affect these workflows’ current trigger patterns.

Overview
Upgrades actions/checkout across CI workflows from v6 to v7 (mostly pinned 3d3c42e… / v7.0.1; instrumented-tests, release-draft, and release-publish use @v7).

Touches PR, daily, kit build, instrumented, and release pipelines only—no SDK or app code.

v7 tightens checkout behavior (e.g. blocking unsafe fork-PR checkout on pull_request_target / workflow_run); these workflows use standard pull_request / push checkout, so behavior should stay the same aside from the dependency upgrade.

Reviewed by Cursor Bugbot for commit 8e2d758. Bugbot is set up for automated code reviews on this repo. Configure here.

@sonarqubecloud

Copy link
Copy Markdown

@jamesnrokt

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore: bump actions/checkout from 6.0.3 to 7.0.0 chore: bump actions/checkout from 6 to 7 Jul 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7.0.0 branch from 44f1ec8 to 8e2d758 Compare July 29, 2026 21:10
@sonarqubecloud

Copy link
Copy Markdown

@thomson-t

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants