Skip to content

build(deps): bump actions/checkout from 4 to 7 - #206

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Closed

build(deps): bump actions/checkout from 4 to 7#206
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown

Bumps actions/checkout from 4 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 8, 2026
Jason-Vaughan added a commit that referenced this pull request Sep 8, 2026
Reconstruction of Dependabot's #204, #205, #206 and #207 on main: checkout
4 → 7, setup-python 5 → 7, upload-artifact 4 → 7, download-artifact 4 → 8.
Their branches were not merged, not checked out and not run locally — under
ADR-009 a bot's bytes get the same treatment as anyone else's.

The four land in one commit rather than four merges because two of them are
coupled. From upload v7 / download v8 the artifact actions share a direct
upload contract: upload can skip zipping via `archive: false`, and download
decides whether to decompress by sniffing Content-Type. Neither option is
used here, but bumping one side alone leaves a producer and a consumer of
that contract straddling it for as long as the other change sits unmerged.
The rule is recorded beside the steps, since a later session bumping one of
them is precisely who needs it.

The jumps look worse than they are. Three of the four crossed a major only
to move to Node 24 — a change the publishers themselves describe as "not a
breaking change per-se but we're treating it as such". Every real break
across the seven majors is gated behind an input this project does not set
or a trigger it does not use: download-artifact v5 changed the path layout
for artifacts fetched by ID and we fetch by name; setup-python v7 dropped
`pip-install`, never passed here; checkout v7 refuses to check out a fork PR
under `pull_request_target` or `workflow_run`, and neither workflow uses
either trigger. setup-python v7 also carries a commit called "remove EOL
Python versions", which is the one plausible way this breaks a five-version
matrix — reading its file list, it touches only that action's own CI
matrices and test fixtures, and nothing about which interpreters it installs.

download-artifact v8 promotes a digest mismatch from a warning to an error.
Taken deliberately rather than by omission: this is the one path that feeds
PyPI, and a corrupted dist should stop there.

checkout@v7 and setup-python@v7 are proven, not assumed — they touch ci.yml,
so the upstream PRs' own sandboxed runs exercised them green across Python
3.10 through 3.14. The artifact pair is not: it appears only in publish.yml,
which fires on `release: published`, so the green checks on #205 and #207 ran
the unchanged ci.yml and say nothing about it. The next release is its first
real exercise. Accepted because the usage is entirely default-shaped and the
failure would be a failed release job before PyPI receives anything.

Suite 805 green.
@Jason-Vaughan

Copy link
Copy Markdown
Owner

Superseded by #218, merged as 2ddb0f3.

This bump (actions/checkout 4 → 7) has shipped — re-implemented on main rather than merged from this branch, per the clean room standard in CONTRIBUTING.md. The version change is exactly the one proposed here; only the authorship of the bytes differs.

All four Actions majors were audited together and landed in a single commit, because upload-artifact v7 and download-artifact v8 share a direct-upload contract and merging them separately would have straddled it. The audit is summarised in #218.

Two follow-ups came out of it: #219 (pin actions to full SHAs rather than mutable major tags) and #220 (this ecosystem's grouping and PR-limit behaviour).

Closing as superseded — thanks, Dependabot.

@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/checkout-7 branch September 8, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant