Skip to content

build(deps): bump actions/checkout from 4.3.1 to 7.0.0#92

Merged
afonsoft merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.0
Jul 14, 2026
Merged

build(deps): bump actions/checkout from 4.3.1 to 7.0.0#92
afonsoft merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4.3.1 to 7.0.0.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Open in Devin Review

Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.1 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v4.3.1...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 13, 2026
@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

Qodana Community for .NET

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked

View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/qodana-action@v2026.1.3
        with:
          upload-result: true
Contact Qodana team

Contact us at qodana-support@jetbrains.com

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Open in Devin Review

steps:
- name: Checkout Code
uses: actions/checkout@v7
uses: actions/checkout@v7.0.0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Pinning to v7.0.0 instead of v7 disables automatic patch updates

Several workflow files previously used actions/checkout@v7 (a major-version tag that floats to the latest v7.x.x release, automatically picking up patch and minor fixes). This PR pins them to actions/checkout@v7.0.0, which locks the version and means future patch releases (e.g., v7.0.1 with a bug fix) will not be picked up automatically. This is a trade-off: better reproducibility but no automatic security/bug-fix patches. The files using SHA pinning (auto-pr-from-main.yml, code-quality.yml) already had this trade-off before the PR.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

steps:
- name: 📥 Checkout Repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Two different referencing styles for the same action across workflows

After this PR, auto-pr-from-main.yml and code-quality.yml reference actions/checkout by commit SHA (@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0), while all other workflow files use the tag @v7.0.0. If the SHA does not correspond to the v7.0.0 tag, different workflows would silently use different checkout versions. This inconsistency was already present before the PR (some files used SHA 34e114876b..., others used @v7), so it's pre-existing. Consider standardizing on one style across all workflows for maintainability.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@afonsoft
afonsoft merged commit 5ea9a2b into main Jul 14, 2026
27 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/checkout-7.0.0 branch July 14, 2026 23:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant