chore(deps): bump actions/checkout from 6 to 7 - #28
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
📝 WalkthroughWalkthroughThree GitHub Actions workflow checkout steps are updated from ChangesCheckout Action Version Bump
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/static.yml:
- Line 17: The GitHub Actions workflow uses unpinned action references with
version tags (`actions/checkout@v7`), which poses a security risk as version
tags can be moved to point to malicious commits. Replace both occurrences of
`actions/checkout@v7` (at line 17 and line 38) with a pinned commit SHA
reference by visiting the actions/checkout releases page for v7.0.0, copying the
specific commit hash, and using the format `actions/checkout@<commit-sha>` with
a comment indicating the version like `# v7.0.0`. This ensures the workflow uses
an immutable reference that cannot be compromised by tag manipulation.
In @.github/workflows/tests.yml:
- Line 30: The actions/checkout@v7 reference in the workflow is using a version
tag instead of being pinned to a specific commit SHA, which poses a security
risk. Replace the version tag reference with a full-length commit SHA by
visiting the actions/checkout releases page for v7.0.0, finding the commit hash
link, and updating the uses statement to pin to that specific commit SHA rather
than the mutable version tag. This ensures the workflow uses an immutable
reference to the action.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: f5d29cc6-debb-404c-aee9-e9802eb113c0
📒 Files selected for processing (2)
.github/workflows/static.yml.github/workflows/tests.yml
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
Pin actions/checkout to a specific commit SHA instead of using a version tag.
The static analysis tool (zizmor) flags both checkout steps as using unpinned action references. GitHub recommends pinning dependency versions to a specific commit SHA to prevent malicious code added to a new or updated branch or tag from being automatically used. In March 2025, the tj-actions/changed-files action used in tens of thousands of repositories was compromised; malicious code extracted CI runner secrets, and version tags were moved to point at the malicious commit; every workflow using a floating tag reference executed the malicious code automatically, while repositories pinned to specific commit hashes were unaffected.
📌 Fix: Pin to commit SHA with version comment
Replace each checkout reference with a pinned commit SHA. For example:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0To find the correct SHA for v7.0.0, visit the actions/checkout releases page and click the commit hash link.
Alternatively, use the GitHub CLI:
gh api repos/actions/checkout/commits/v7.0.0 --jq '.sha'Also applies to: 38-38
🧰 Tools
🪛 zizmor (1.25.2)
[warning] 17-17: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 17-17: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/static.yml at line 17, The GitHub Actions workflow uses
unpinned action references with version tags (`actions/checkout@v7`), which
poses a security risk as version tags can be moved to point to malicious
commits. Replace both occurrences of `actions/checkout@v7` (at line 17 and line
38) with a pinned commit SHA reference by visiting the actions/checkout releases
page for v7.0.0, copying the specific commit hash, and using the format
`actions/checkout@<commit-sha>` with a comment indicating the version like `#
v7.0.0`. This ensures the workflow uses an immutable reference that cannot be
compromised by tag manipulation.
Source: Linters/SAST tools
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v6 | ||
| uses: actions/checkout@v7 |
There was a problem hiding this comment.
Pin actions/checkout to a specific commit SHA instead of using a version tag.
The static analysis tool (zizmor) flags this checkout step as using an unpinned action reference. Pinning an action to a full-length commit SHA is the most reliable way to use an immutable version of an action, and pinning to a specific SHA mitigates the risk of a bad actor changing a tag to point to malicious code.
📌 Fix: Pin to commit SHA with version comment
Replace the checkout reference with a pinned commit SHA:
- name: Checkout code
- uses: actions/checkout@v7
+ uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0To find the correct SHA for v7.0.0, visit the actions/checkout releases page and click the commit hash link.
📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| uses: actions/checkout@v7 | |
| uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0 |
🧰 Tools
🪛 zizmor (1.25.2)
[warning] 29-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 30-30: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/tests.yml at line 30, The actions/checkout@v7 reference in
the workflow is using a version tag instead of being pinned to a specific commit
SHA, which poses a security risk. Replace the version tag reference with a
full-length commit SHA by visiting the actions/checkout releases page for
v7.0.0, finding the commit hash link, and updating the uses statement to pin to
that specific commit SHA rather than the mutable version tag. This ensures the
workflow uses an immutable reference to the action.
Source: Linters/SAST tools
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Summary by CodeRabbit