Skip to content

Bump actions/checkout from 5.0.1 to 7.0.1 - #612

Merged
Adam Rudell (arudell) merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.1
Aug 12, 2026
Merged

Bump actions/checkout from 5.0.1 to 7.0.1#612
Adam Rudell (arudell) merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 5.0.1 to 7.0.1.

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 21, 2026
Copilot AI review requested due to automatic review settings July 21, 2026 04:52
@dependabot
dependabot Bot requested a review from a team as a code owner July 21, 2026 04:52
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 21, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates GitHub Actions workflows to use actions/checkout v7.0.1 (mostly via pinned commit SHA) for consistency and to pick up the latest patch fixes.

Changes:

  • Bump actions/checkout from v7.0.0 to v7.0.1 across multiple workflows using pinned SHAs.
  • Update the DevSkim workflow’s actions/checkout reference from @v7 to @v7.0.1.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
.github/workflows/server2019-sdntest.yml Updates checkout action to v7.0.1 pinned SHA.
.github/workflows/server2019-sdntest-pr.yml Updates checkout action to v7.0.1 pinned SHA for PR runs.
.github/workflows/scorecards.yml Updates checkout action to v7.0.1 pinned SHA in scorecards job.
.github/workflows/powershell.yml Updates checkout action to v7.0.1 pinned SHA for PowerShell CI.
.github/workflows/devskim.yml Changes checkout from major tag to patched tag (not SHA-pinned).
.github/workflows/dependency-review.yml Updates checkout action to v7.0.1 pinned SHA for dependency review.
.github/workflows/build-pipeline.yml Updates checkout action to v7.0.1 pinned SHA in build pipeline.

Comment thread .github/workflows/devskim.yml
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.1 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v5.0.1...v7.0.1)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump actions/checkout from 7.0.0 to 7.0.1 Bump actions/checkout from 5.0.1 to 7.0.1 Jul 28, 2026
Copilot AI review requested due to automatic review settings July 28, 2026 22:23
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7.0.1 branch from 2de211e to e1b356c Compare July 28, 2026 22:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated no new comments.

Comments suppressed due to low confidence (2)

.github/workflows/devskim.yml:27

  • This workflow uses a mutable tag (@v7.0.1) while the other workflows pin actions/checkout by commit SHA. For supply-chain integrity and reproducibility, pin actions/checkout here to the same v7.0.1 commit SHA used elsewhere (and keep the version comment if desired).
        uses: actions/checkout@v7.0.1

.github/workflows/pester-tests.yml:26

  • This changes actions/checkout from v5.0.1 to v7.0.1 (major-version upgrade) specifically for the Pester workflow, which can introduce behavior/runtime expectation changes compared to other jobs. If the repo intentionally standardizes on a major version per workflow, consider aligning all workflows on the same major version upgrade rationale and documenting the reason for the major bump (or upgrading any remaining older-version usages consistently).
        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

@arudell
Adam Rudell (arudell) merged commit 5e6cea5 into main Aug 12, 2026
8 checks passed
@arudell
Adam Rudell (arudell) deleted the dependabot/github_actions/actions/checkout-7.0.1 branch August 12, 2026 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants