Skip to content

chore(deps): bump actions/checkout from 2 to 7 - #887

Merged
Matobi98 merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Aug 5, 2026
Merged

chore(deps): bump actions/checkout from 2 to 7#887
Matobi98 merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 2 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 3, 2026
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v2...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7 branch from c47da69 to 76301e8 Compare August 5, 2026 14:07
@Matobi98

Matobi98 commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Tested actions/checkout v2→v7 on a fork branch: all 4 affected workflows ran successfully — Auto Check Lint (push, 25s), Auto Check Lint (pull_request, 27s), NodeJS CI (pull_request, 1m18s), and CodeQL (pull_request, 3m25s). Also manually tested /buy, /sell, and cooperative cancellation against the bot — no issues. The only breaking change in the v2→v7 range (blocking fork checkout on pull_request_target/workflow_run) doesn't apply, since none of our workflows use those triggers.

@Matobi98
Matobi98 merged commit 473b959 into main Aug 5, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/checkout-7 branch August 5, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant