Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 6. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v3...v6) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
There was a problem hiding this comment.
Pull request overview
Updates the repository’s GitHub Actions workflows to use actions/checkout@v6, aligning checkout behavior and runtime support with the latest major version of the action.
Changes:
- Bump
actions/checkouttov6across all workflows that check out the repository. - Standardize checkout version usage across deploy, security scan, self-healing, and auto-deploy workflows.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| .github/workflows/self-healing.yml | Updates both checkout steps to actions/checkout@v6. |
| .github/workflows/security-scan.yml | Updates checkout steps used by CodeQL and dependency scan jobs to v6. |
| .github/workflows/deploy.yml | Updates checkout in the deploy job from v3 to v6. |
| .github/workflows/auto-deploy.yml | Updates all checkout steps across auto-deploy jobs to v6. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
Consider pinning actions/checkout to a full commit SHA (or at least a specific v6.x.y tag) instead of the moving v6 major tag to reduce supply-chain risk and avoid unexpected behavior changes when v6 is advanced.
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v3 | ||
| - uses: actions/checkout@v6 |
There was a problem hiding this comment.
Consider pinning actions/checkout to a full commit SHA (or at least a specific v6.x.y tag) instead of the moving v6 major tag to reduce supply-chain risk and avoid unexpected behavior changes when v6 is advanced.
| - uses: actions/checkout@v6 | |
| - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # actions/checkout@v4.1.7 |
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
Consider pinning actions/checkout to a full commit SHA (or at least a specific v6.x.y tag) instead of the moving v6 major tag to reduce supply-chain risk and avoid unexpected behavior changes when v6 is advanced.
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
Consider pinning actions/checkout to a full commit SHA (or at least a specific v6.x.y tag) instead of the moving v6 major tag to reduce supply-chain risk and avoid unexpected behavior changes when v6 is advanced.
Bumps actions/checkout from 3 to 6.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)08c6903Prepare v5.0.0 release (#2238)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)