build(deps): bump actions/checkout from 4.3.1 to 7.0.0#92
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.1 to 7.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v4.3.1...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Qodana Community for .NETIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked View the detailed Qodana reportTo be able to view the detailed Qodana report, you can either:
To get - name: 'Qodana Scan'
uses: JetBrains/qodana-action@v2026.1.3
with:
upload-result: trueContact Qodana teamContact us at qodana-support@jetbrains.com
|
| steps: | ||
| - name: Checkout Code | ||
| uses: actions/checkout@v7 | ||
| uses: actions/checkout@v7.0.0 |
There was a problem hiding this comment.
📝 Info: Pinning to v7.0.0 instead of v7 disables automatic patch updates
Several workflow files previously used actions/checkout@v7 (a major-version tag that floats to the latest v7.x.x release, automatically picking up patch and minor fixes). This PR pins them to actions/checkout@v7.0.0, which locks the version and means future patch releases (e.g., v7.0.1 with a bug fix) will not be picked up automatically. This is a trade-off: better reproducibility but no automatic security/bug-fix patches. The files using SHA pinning (auto-pr-from-main.yml, code-quality.yml) already had this trade-off before the PR.
Was this helpful? React with 👍 or 👎 to provide feedback.
| steps: | ||
| - name: 📥 Checkout Repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 | ||
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 |
There was a problem hiding this comment.
🔍 Two different referencing styles for the same action across workflows
After this PR, auto-pr-from-main.yml and code-quality.yml reference actions/checkout by commit SHA (@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0), while all other workflow files use the tag @v7.0.0. If the SHA does not correspond to the v7.0.0 tag, different workflows would silently use different checkout versions. This inconsistency was already present before the PR (some files used SHA 34e114876b..., others used @v7), so it's pre-existing. Consider standardizing on one style across all workflows for maintainability.
Was this helpful? React with 👍 or 👎 to provide feedback.



Bumps actions/checkout from 4.3.1 to 7.0.0.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)df4cb1cUpdate changelog for v6.0.3 (#2446)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)