Bump actions/checkout from 6 to 7 - #101
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Kusari Analysis Results:
No pinned version dependency changes, code issues or exposed secrets detected! Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
| # Checkout the repository code to the runner. | ||
| - name: Checkout code | ||
| uses: actions/checkout@v6 | ||
| uses: actions/checkout@v7 |
There was a problem hiding this comment.
Unpinned action reference: actions/checkout is pinned to a mutable tag (@v7) rather than an immutable commit SHA. Pin the action to a full commit SHA to prevent supply chain attacks.
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
actions/checkout is referenced by the mutable tag @v7. This allows the action owner to silently redirect the tag to malicious code. Pin this action to a full 40-character commit SHA to ensure immutability.
|
|
||
| - name: Checkout | ||
| uses: actions/checkout@v6 | ||
| uses: actions/checkout@v7 |
There was a problem hiding this comment.
actions/checkout is pinned to the mutable tag @v7. Tags can be silently repointed to malicious code by the action owner. Pin this action to a full 40-character commit SHA to guarantee immutability and protect against supply-chain attacks.
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
actions/checkout is referenced using the mutable tag @v7. This tag can be repointed by the action owner at any time, enabling a supply-chain attack. Pin this action to a full 40-character commit SHA to ensure immutability.
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v6 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
The action actions/checkout@v7 uses a mutable tag. Tags can be repointed by the action owner at any time, enabling a supply-chain attack. Pin this action to a full 40-character commit SHA to ensure the exact version used cannot be altered without your knowledge.
| steps: | ||
| # Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it | ||
| - uses: actions/checkout@v6 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
The action actions/checkout@v7 uses a mutable version tag. Mutable tags can be silently repointed by the action owner, enabling a supply-chain attack. Pin this action to a full 40-character commit SHA. You can look up the correct SHA on the actions/checkout releases page on GitHub.
Updates to v7 sha pin Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Kusari PR Analysis rerun based on - 65dfd30 performed at: 2026-07-20T18:01:06Z - link to updated analysis |
Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Kusari PR Analysis rerun based on - 5ce5872 performed at: 2026-07-20T18:09:49Z - link to updated analysis |
Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Kusari PR Analysis rerun based on - 1a2b862 performed at: 2026-07-20T18:10:55Z - link to updated analysis |
Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Kusari PR Analysis rerun based on - 7210beb performed at: 2026-07-20T18:15:46Z - link to updated analysis |
Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Kusari PR Analysis rerun based on - 6c17b33 performed at: 2026-07-20T18:18:07Z - link to updated analysis |
Signed-off-by: Jeff Diecks <55294502+GeauxJD@users.noreply.github.com>
|
Kusari PR Analysis rerun based on - d75c5b9 performed at: 2026-07-20T18:49:50Z - link to updated analysis |
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)