Skip to content

Bump actions/checkout from 6 to 7#40

Merged
masih merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Jul 24, 2026
Merged

Bump actions/checkout from 6 to 7#40
masih merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 29, 2026
@cursor

cursor Bot commented Jun 29, 2026

Copy link
Copy Markdown

PR Summary

Low Risk
Version-only CI dependency bump with no workflow logic changes; checkout v7’s fork-PR restrictions do not apply to this pull_request-only workflow.

Overview
Updates three actions/checkout steps in .github/workflows/ai-review.yml from v6 to v7: preflight (sparse checkout of sei-protocol/uci prompts), and the Codex and Cursor scout jobs (PR merge ref checkouts). Checkout inputs (ref, fetch-depth, persist-credentials, etc.) are unchanged.

This aligns the AI review reusable workflow with checkout v7 (dependency/ESM updates and stricter defaults around unsafe fork-PR checkouts on pull_request_target / workflow_run). This workflow is already gated to pull_request only, so that behavior change should not affect these steps.

Reviewed by Cursor Bugbot for commit 14e0e1c. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7 branch from 21ebf58 to 14e0e1c Compare July 24, 2026 14:17
@masih
masih merged commit 9537329 into main Jul 24, 2026
1 check passed
@masih
masih deleted the dependabot/github_actions/actions/checkout-7 branch July 24, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant