Skip to content

chore(deps): bump actions/checkout from 6 to 7 - #28

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Open

chore(deps): bump actions/checkout from 6 to 7#28
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 19, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by CodeRabbit

  • Chores
    • Updated CI/CD workflow dependencies to latest versions for improved compatibility and security.

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 19, 2026
@coderabbitai

coderabbitai Bot commented Jun 19, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Three GitHub Actions workflow checkout steps are updated from actions/checkout@v6 to actions/checkout@v7: the phpstan job and ecs job in .github/workflows/static.yml, and the test job in .github/workflows/tests.yml.

Changes

Checkout Action Version Bump

Layer / File(s) Summary
Update actions/checkout to v7 across all workflows
.github/workflows/static.yml, .github/workflows/tests.yml
The phpstan job, ecs job, and test job each update their checkout step from actions/checkout@v6 to actions/checkout@v7.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

🐇 Hop, hop, a version bump so bright,
From v6 to v7 in the night,
Three little checkouts, all in a row,
Updated with care, watch the pipelines flow,
The rabbit approves — off we go! 🌟

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: updating actions/checkout from version 6 to version 7 across GitHub Actions workflows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/actions/checkout-7

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/static.yml:
- Line 17: The GitHub Actions workflow uses unpinned action references with
version tags (`actions/checkout@v7`), which poses a security risk as version
tags can be moved to point to malicious commits. Replace both occurrences of
`actions/checkout@v7` (at line 17 and line 38) with a pinned commit SHA
reference by visiting the actions/checkout releases page for v7.0.0, copying the
specific commit hash, and using the format `actions/checkout@<commit-sha>` with
a comment indicating the version like `# v7.0.0`. This ensures the workflow uses
an immutable reference that cannot be compromised by tag manipulation.

In @.github/workflows/tests.yml:
- Line 30: The actions/checkout@v7 reference in the workflow is using a version
tag instead of being pinned to a specific commit SHA, which poses a security
risk. Replace the version tag reference with a full-length commit SHA by
visiting the actions/checkout releases page for v7.0.0, finding the commit hash
link, and updating the uses statement to pin to that specific commit SHA rather
than the mutable version tag. This ensures the workflow uses an immutable
reference to the action.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f5d29cc6-debb-404c-aee9-e9802eb113c0

📥 Commits

Reviewing files that changed from the base of the PR and between 751c3ab and ec8792f.

📒 Files selected for processing (2)
  • .github/workflows/static.yml
  • .github/workflows/tests.yml

runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Pin actions/checkout to a specific commit SHA instead of using a version tag.

The static analysis tool (zizmor) flags both checkout steps as using unpinned action references. GitHub recommends pinning dependency versions to a specific commit SHA to prevent malicious code added to a new or updated branch or tag from being automatically used. In March 2025, the tj-actions/changed-files action used in tens of thousands of repositories was compromised; malicious code extracted CI runner secrets, and version tags were moved to point at the malicious commit; every workflow using a floating tag reference executed the malicious code automatically, while repositories pinned to specific commit hashes were unaffected.

📌 Fix: Pin to commit SHA with version comment

Replace each checkout reference with a pinned commit SHA. For example:

-      - uses: actions/checkout@v7
+      - uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0

To find the correct SHA for v7.0.0, visit the actions/checkout releases page and click the commit hash link.

Alternatively, use the GitHub CLI:

gh api repos/actions/checkout/commits/v7.0.0 --jq '.sha'

Also applies to: 38-38

🧰 Tools
🪛 zizmor (1.25.2)

[warning] 17-17: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 17-17: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/static.yml at line 17, The GitHub Actions workflow uses
unpinned action references with version tags (`actions/checkout@v7`), which
poses a security risk as version tags can be moved to point to malicious
commits. Replace both occurrences of `actions/checkout@v7` (at line 17 and line
38) with a pinned commit SHA reference by visiting the actions/checkout releases
page for v7.0.0, copying the specific commit hash, and using the format
`actions/checkout@<commit-sha>` with a comment indicating the version like `#
v7.0.0`. This ensures the workflow uses an immutable reference that cannot be
compromised by tag manipulation.

Source: Linters/SAST tools

steps:
- name: Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Pin actions/checkout to a specific commit SHA instead of using a version tag.

The static analysis tool (zizmor) flags this checkout step as using an unpinned action reference. Pinning an action to a full-length commit SHA is the most reliable way to use an immutable version of an action, and pinning to a specific SHA mitigates the risk of a bad actor changing a tag to point to malicious code.

📌 Fix: Pin to commit SHA with version comment

Replace the checkout reference with a pinned commit SHA:

       - name: Checkout code
-        uses: actions/checkout@v7
+        uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0

To find the correct SHA for v7.0.0, visit the actions/checkout releases page and click the commit hash link.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
uses: actions/checkout@v7
uses: actions/checkout@de0fac2e4500dabe0009e6a0797e74b61c1c2481 # v7.0.0
🧰 Tools
🪛 zizmor (1.25.2)

[warning] 29-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 30-30: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/tests.yml at line 30, The actions/checkout@v7 reference in
the workflow is using a version tag instead of being pinned to a specific commit
SHA, which poses a security risk. Replace the version tag reference with a
full-length commit SHA by visiting the actions/checkout releases page for
v7.0.0, finding the commit hash link, and updating the uses statement to pin to
that specific commit SHA rather than the mutable version tag. This ensures the
workflow uses an immutable reference to the action.

Source: Linters/SAST tools

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants