⚠️ MAJOR: Update actions/checkout action to v7 #297
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!297
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/actions-checkout-7.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v4→v7Release Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
v7.0.0Compare Source
v7Compare Source
v6.1.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v6 by @aiqiaoy in #2500https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: https://github.com/actions/checkout/compare/v6.0.3...v6.1.0
v6.0.3Compare Source
v6.0.2Compare Source
v6.0.1Compare Source
v6.0.0Compare Source
v6Compare Source
v5.1.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v5 by @aiqiaoy in #2501https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: https://github.com/actions/checkout/compare/v5.0.1...v5.1.0
v5.0.1Compare Source
v5.0.0Compare Source
v5Compare Source
This PR has been generated by Mend Renovate CLI.
Verified from the branch's own CI run (run 312, the one that loaded
actions/checkout@v7):ref=v7, ran under the runner'snode:22-bookwormjob image with no runtime warning. The declared Node 24 runtime is not enforced by forgejo-runner.fetch-depth: 0still gives gitleaks the full history: 763 commits scanned, no leaks.RUNNER_TEMPviaincludeIf, not.git/config'sextraheader, and the post step removes it. Nothing here depends on the old layout.pull_request_targetandworkflow_run; this workflow usespull_request.Nothing live is touched, no deploy on merge.