chore(deps): bump actions/checkout from 4 to 7 - #3
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
📝 WalkthroughWalkthroughThe CI validation, build, and release workflows update ChangesCheckout action upgrade
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Line 15: Add persist-credentials: false to every actions/checkout step:
.github/workflows/ci.yml lines 15-15 and 28-28, and
.github/workflows/release.yml line 11-11. Keep the existing checkout versions
and job behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 316a8f51-102f-4e62-9bc4-450580493721
📒 Files selected for processing (2)
.github/workflows/ci.yml.github/workflows/release.yml
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== ci.yml ==\n'
nl -ba .github/workflows/ci.yml | sed -n '1,220p'
printf '\n== release.yml ==\n'
nl -ba .github/workflows/release.yml | sed -n '1,220p'Repository: ePlus-DEV/wxt-extension-template
Length of output: 224
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== search for git/github auth usage in workflows ==\n'
rg -n "git (push|fetch|pull|submodule)|gh |github.token|GITHUB_TOKEN|persist-credentials|checkout@v" .github/workflowsRepository: ePlus-DEV/wxt-extension-template
Length of output: 414
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== ci.yml ==\n'
nl -ba .github/workflows/ci.yml | sed -n '1,220p'
printf '\n== release.yml ==\n'
nl -ba .github/workflows/release.yml | sed -n '1,220p'
printf '\n== workflow auth usage search ==\n'
rg -n "git (push|fetch|pull|submodule)|gh |github.token|GITHUB_TOKEN|persist-credentials|checkout@v" .github/workflowsRepository: ePlus-DEV/wxt-extension-template
Length of output: 224
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== ci.yml ==\n'
cat -n .github/workflows/ci.yml | sed -n '1,220p'
printf '\n== release.yml ==\n'
cat -n .github/workflows/release.yml | sed -n '1,220p'
printf '\n== git/auth-related references in workflows ==\n'
rg -n "git (push|fetch|pull|submodule)|gh |github.token|GITHUB_TOKEN|persist-credentials|checkout@" .github/workflowsRepository: ePlus-DEV/wxt-extension-template
Length of output: 2284
Disable checkout credential persistence here.
All three jobs only install, build, test, or publish artifacts; none need git auth after checkout. Add persist-credentials: false to each actions/checkout step.
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 15-15: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
📍 Affects 2 files
.github/workflows/ci.yml#L15-L15(this comment).github/workflows/ci.yml#L28-L28.github/workflows/release.yml#L11-L11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml at line 15, Add persist-credentials: false to every
actions/checkout step: .github/workflows/ci.yml lines 15-15 and 28-28, and
.github/workflows/release.yml line 11-11. Keep the existing checkout versions
and job behavior unchanged.
Source: Linters/SAST tools
Bumps actions/checkout from 4 to 7.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Summary by CodeRabbit