Repository navigation
Bump actions/checkout from 6 to 7 - #1445
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
bgentry
left a comment
There was a problem hiding this comment.
🤖 Codex review: Security review is clear for River's current hosted configuration; this PR is superseded and should remain unmerged.
Upgrade
actions/checkout:v6→v7- Reviewed River head:
f2268d7c1f77e15e18bbb386f54f2b5ee7eb97d0 - Target action tag resolves to canonical upstream commit
3d3c42e5aac5ba805825da76410c181273ba90b1.
Security review
- Inputs/outputs, Node 24 and checkout credential scope remain unchanged. Reviewed ESM/toolkit and Octokit changes, authentication/temporary-file cleanup, git argument escaping, new response-parsing utilities, production graph churn and the generated bundle. The unsafe-fork-checkout guard also exists in the current v6 ref; River uses ordinary push/pull_request default-repository checkouts.
- Independently verified 33 relevant published npm tarballs across the Actions group against registry/upstream-lock SHA512 integrity. No same-version integrity rewrites or non-registry sources were found. Toolkit provenance subject digests match the inspected artifacts; signature/transparency chains were not independently verified. Target release commits have GitHub-valid signatures.
- No action-specific public advisory found. This does not establish that bundled dependencies are advisory-free.
Compatibility verification
- Master
81c96bfe8167ab90a5009dad6098195b9857cb62already contains every requested reference update through #1459, including additional workflows added since this stale PR. No remaining upgrade from this PR needs merging. - No action entrypoint was executed locally. Hosted checkout/cache/toolchain semantics require GitHub runners; stale failing checks, where present, are not treated as a passing gate. This is a comment-only supersession decision.
Residual risk
- Bundled undici advisories affect retry/WebSocket/cookie/blob APIs unused on the reviewed checkout paths. Upstream issue 2573 requires an earlier attacker-controlled checkout destination; River has one checkout per fresh hosted job and no custom checkout path. Generated code was not rebuilt or exhaustively audited. Major tags and the target release remain mutable.
|
@dependabot rebase |
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
|
Superseded by #1459: master already contains this exact Actions upgrade. Dependabot cannot rebase this older PR because its configuration entry changed, so closing it as redundant. The dependency security review is recorded above. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)