Skip to content

chore(github-tag): update tag actions/checkout to v7 - #381

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-7.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-7.x

Conversation

@renovate

@renovate renovate Bot commented Jul 4, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout action major v6.1.0 → v7.0.1

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • "every weekend,on Friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 4, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 🟢 6.6
Details
CheckScoreReason
Maintained🟢 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
actions/actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 🟢 6.6
Details
CheckScoreReason
Maintained🟢 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Packaging⚠️ -1packaging workflow not detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 5branch protection is not maximal on development and all release branches

Scanned Files

  • .github/workflows/deploy.yml
  • .github/workflows/update-db.yml

@renovate
renovate Bot force-pushed the renovate/actions-checkout-7.x branch from 8085502 to 87543cf Compare July 12, 2026 12:57
@renovate
renovate Bot force-pushed the renovate/actions-checkout-7.x branch 2 times, most recently from 9dec59b to 1c1c2aa Compare July 24, 2026 13:38
@renovate renovate Bot changed the title ci(github-tag): Update tag actions/checkout ( v6.0.3 ➔ v7.0.0 ) ci(github-tag): Update tag actions/checkout ( v6.1.0 ➔ v7.0.0 ) Jul 24, 2026
@renovate
renovate Bot force-pushed the renovate/actions-checkout-7.x branch 2 times, most recently from bd0685d to ee7a69b Compare July 30, 2026 14:02
@renovate
renovate Bot force-pushed the renovate/actions-checkout-7.x branch from ee7a69b to 1d47371 Compare August 3, 2026 15:42
@renovate renovate Bot changed the title ci(github-tag): Update tag actions/checkout ( v6.1.0 ➔ v7.0.0 ) ci(github-tag): Update tag actions/checkout ( v6.1.0 ➔ v7.0.1 ) Aug 3, 2026
@renovate renovate Bot changed the title ci(github-tag): Update tag actions/checkout ( v6.1.0 ➔ v7.0.1 ) chore(github-tag): update tag actions/checkout to v7 Aug 17, 2026
@renovate
renovate Bot force-pushed the renovate/actions-checkout-7.x branch from 1d47371 to a387b95 Compare September 10, 2026 21:11
@renovate
renovate Bot force-pushed the renovate/actions-checkout-7.x branch from a387b95 to 40ef994 Compare September 24, 2026 19:04
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 90aa060e-e334-4974-96cd-d1ecec68d8bc

📥 Commits

Reviewing files that changed from the base of the PR and between 6155c00 and 40ef994.

📒 Files selected for processing (9)
  • .github/workflows/auto-label.yml
  • .github/workflows/bandit.yml
  • .github/workflows/codeql.yml
  • .github/workflows/dependency-review.yml
  • .github/workflows/deploy.yml
  • .github/workflows/docker-test.yml
  • .github/workflows/release.yml
  • .github/workflows/todo-to-issue.yml
  • .github/workflows/update-db.yml

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The GitHub Actions workflows now pin actions/checkout to v7.0.1 instead of v6.1.0. Existing checkout settings and workflow behavior are otherwise unchanged.

Changes

Workflow checkout pin update

Layer / File(s) Summary
Update workflow checkout pins
.github/workflows/auto-label.yml, .github/workflows/bandit.yml, .github/workflows/codeql.yml, .github/workflows/dependency-review.yml, .github/workflows/deploy.yml, .github/workflows/docker-test.yml, .github/workflows/release.yml, .github/workflows/todo-to-issue.yml, .github/workflows/update-db.yml
Checkout steps now use the v7.0.1 commit instead of v6.1.0. Existing checkout settings remain unchanged.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Suggested reviewers: devsecninja

Merge Risk: ⚪ Minimal · up to 40ef9

The checkout action pins are updated, and the documented fork-event restriction does not affect these workflows. No material merge-blocking risk is evident.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: updating actions/checkout to v7. It is concise and related to the workflow changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants