Skip to content

build(deps): bump actions/checkout from 4.3.1 to 6.0.2#21

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/actions/checkout-6.0.2
Open

build(deps): bump actions/checkout from 4.3.1 to 6.0.2#21
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/actions/checkout-6.0.2

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps actions/checkout from 4.3.1 to 6.0.2.

Release notes

Sourced from actions/checkout's releases.

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.1 to 6.0.2.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@34e1148...de0fac2)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 21, 2026
@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes. Give us feedback

Copy link
Copy Markdown

@codacy-production codacy-production Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR cannot be merged as it attempts to update the 'actions/checkout' action to a non-existent version (6.0.2). The current latest stable major version is v4. Referencing an invalid version will cause all modified workflows to fail. Additionally, the intent to move to a (theoretical) v6 involves a major change in credential persistence—moving from the local git config to $RUNNER_TEMP—which requires a minimum GitHub Runner version of 2.329.0 and may break downstream steps relying on standard git configuration.

About this PR

  • Major version upgrades for actions/checkout (v4+) change how credentials are persisted, moving them to $RUNNER_TEMP instead of the local git config. This requires a minimum runner version of v2.329.0. Ensure your environment meets this requirement and that no downstream steps depend on credentials being in the git config.

Test suggestions

  • Verify successful repository checkout in the 'deleted-files.yml' workflow using v6.0.2.
  • Verify successful repository checkout and persistence of 'fetch-depth' behavior in the readability report workflow.
  • Verify that the GitHub Runner version is at least 2.329.0 to support the new credential persistence mechanism in v6.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify successful repository checkout in the 'deleted-files.yml' workflow using v6.0.2.
2. Verify successful repository checkout and persistence of 'fetch-depth' behavior in the readability report workflow.
3. Verify that the GitHub Runner version is at least 2.329.0 to support the new credential persistence mechanism in v6.
Low confidence findings
  • The PR lacks automated validation to verify that the workflows remain functional after the version update. Given the potential for breaking changes in credential handling, verification steps are necessary.

🗒️ Improve review quality by adding custom instructions

steps:
- name: Checkout repo with history
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

The version v6.0.2 for actions/checkout does not exist. The latest major version is v4. Using a non-existent version will cause the workflow to fail. Try running the following prompt in your coding agent: > Update all actions/checkout references to the latest v4 release SHA and version tag.

steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

The version v6.0.2 for actions/checkout does not exist. The latest major version is v4. Using a non-existent version will cause the workflow to fail. Try running the following prompt in your coding agent: > Update all actions/checkout references to the latest v4 release SHA and version tag.

steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

The version v6.0.2 for actions/checkout does not exist. The latest major version is v4. Using a non-existent version will cause the workflow to fail. Try running the following prompt in your coding agent: > Update all actions/checkout references to the latest v4 release SHA and version tag.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants