Skip to content

Bump actions/checkout from 4.2.2 to 7.0.1 - #116

Merged
stevebeattie merged 3 commits into
mainfrom
dependabot/github_actions/actions/checkout-7.0.1
Sep 28, 2026
Merged

stevebeattie merged 3 commits into
mainfrom
dependabot/github_actions/actions/checkout-7.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4.2.2 to 7.0.1.

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4.2.2...3d3c42e)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 24, 2026
stevebeattie and others added 2 commits September 28, 2026 13:58
actions/checkout v7 refuses to check out fork pull request code in a
pull_request_target workflow unless allow-unsafe-pr-checkout is set, so
after the bump the signing test would fail for every approved fork PR.
This PR's own CI can't show that: pull_request_target runs use the base
branch's workflow, still on checkout v4.2.2.

Set allow-unsafe-pr-checkout on the pull_request_target checkout only,
with the reasoning next to it: fork PRs already wait for acceptance-tests
environment approval before this job runs.

Also turn off setup-go's default caching. pull_request_target runs share
the default branch's cache scope, so an approved fork PR could otherwise
write a Go cache that main and release runs later restore.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The fork-PR test job waits for acceptance-tests environment approval, but
checked out refs/pull/N/merge, a moving ref. Commits pushed between the
triggering event and a reviewer approving the pending run would be the
code that runs under that approval (time-of-check/time-of-use; CodeQL
actions/untrusted-checkout-toctou).

Check out github.event.pull_request.head.sha instead, the immutable
commit of the event being approved, as terraform-provider-chainguard
does. The job now tests the PR head rather than its merge with main.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@stevebeattie
stevebeattie requested a review from egibs September 28, 2026 21:24
@stevebeattie
stevebeattie enabled auto-merge (squash) September 28, 2026 21:24
@stevebeattie
stevebeattie merged commit 3324ed9 into main Sep 28, 2026
12 checks passed
@stevebeattie
stevebeattie deleted the dependabot/github_actions/actions/checkout-7.0.1 branch September 28, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants