Skip to content

Bump actions/checkout from 6 to 7 - #1445

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/checkout-7
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Security review is clear for River's current hosted configuration; this PR is superseded and should remain unmerged.

Upgrade

  • actions/checkout: v6 → v7
  • Reviewed River head: f2268d7c1f77e15e18bbb386f54f2b5ee7eb97d0
  • Target action tag resolves to canonical upstream commit 3d3c42e5aac5ba805825da76410c181273ba90b1.

Security review

  • Inputs/outputs, Node 24 and checkout credential scope remain unchanged. Reviewed ESM/toolkit and Octokit changes, authentication/temporary-file cleanup, git argument escaping, new response-parsing utilities, production graph churn and the generated bundle. The unsafe-fork-checkout guard also exists in the current v6 ref; River uses ordinary push/pull_request default-repository checkouts.
  • Independently verified 33 relevant published npm tarballs across the Actions group against registry/upstream-lock SHA512 integrity. No same-version integrity rewrites or non-registry sources were found. Toolkit provenance subject digests match the inspected artifacts; signature/transparency chains were not independently verified. Target release commits have GitHub-valid signatures.
  • No action-specific public advisory found. This does not establish that bundled dependencies are advisory-free.

Compatibility verification

  • Master 81c96bfe8167ab90a5009dad6098195b9857cb62 already contains every requested reference update through #1459, including additional workflows added since this stale PR. No remaining upgrade from this PR needs merging.
  • No action entrypoint was executed locally. Hosted checkout/cache/toolchain semantics require GitHub runners; stale failing checks, where present, are not treated as a passing gate. This is a comment-only supersession decision.

Residual risk

  • Bundled undici advisories affect retry/WebSocket/cookie/blob APIs unused on the reviewed checkout paths. Upstream issue 2573 requires an earlier attacker-controlled checkout destination; River has one checkout per fresh hosted job and no custom checkout path. Generated code was not rebuilt or exhaustively audited. Major tags and the target release remain mutable.

@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml.

@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Superseded by #1459: master already contains this exact Actions upgrade. Dependabot cannot rebase this older PR because its configuration entry changed, so closing it as redundant. The dependency security review is recorded above.

@bgentry bgentry closed this Oct 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/checkout-7 branch October 8, 2026 01:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant