chore(deps): bump actions/checkout from 6 to 7 - #1157
Merged
Merged
Conversation
Contributor
|
This PR is stale because it has been open 7 days with no activity. Remove stale label or comment or this will be closed in 3 days. |
Member
|
@dependabot rebase |
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions/checkout-7
branch
from
July 14, 2026 13:19
44a03a3 to
0fa5c72
Compare
tbille
approved these changes
Jul 14, 2026
8 of 11 tasks
pull Bot
pushed a commit
to pepe57/any-llm
that referenced
this pull request
Aug 3, 2026
…mozilla-ai#1216) actions/checkout v7.0.0 began refusing to check out fork PR code from a pull_request_target workflow (actions/checkout#2454). tests-integration.yaml picked that up via the v6 to v7 dependabot bump in mozilla-ai#1157, so since 2026-07-14 labeling a fork PR failed at checkout in determine-jobs-to-run and both test jobs were skipped. Found on mozilla-ai#1202, the first fork PR labeled since the bump. Set allow-unsafe-pr-checkout: true on the three checkout steps that pass a fork head, with a note at the top of the file recording why the opt-in is acceptable and what it does not cover. Dropping the ref: inputs would also satisfy the action but would test main instead of the PR. Narrow permissions: pull-requests: write is granted only on remove-label, leaving the jobs that execute fork code with contents: read. Set persist-credentials: false on all three checkouts so the token is not left in .git/config for that code to read. The label gate is any member at triage or above, not write access; the workflow does not verify the labeler's permission level. Recorded in the file rather than enforced. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)