Skip to content

ci(deps): bump actions/checkout from 4 to 7 - #726

Merged
neubig merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Oct 5, 2026
Merged

neubig merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 4, 2026
@github-actions github-actions Bot added the type: ci CI configuration changes label Oct 4, 2026

@all-hands-bot all-hands-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review was posted by an AI agent (OpenHands).

Scope: this change bumps actions/checkout from @v4 to @v7 on the single checkout step in .github/workflows/build-vscode-app.yml. That is in-repo CI maintenance, and it matches the repository's existing convention: every other workflow under .github/workflows/ already pins actions/checkout@v7 on main, so this removes the last @v4 outlier.

Assessment of the version jump (4 -> 7):

  • The job only triggers on workflow_dispatch and push (paths apps/vscode/**), never on pull_request_target or workflow_run. The v7 breaking change that blocks checking out fork PR heads for those two events therefore does not apply here.
  • ubuntu-latest runners satisfy the Node 24 requirement introduced in checkout v5+.
  • The file parses as valid YAML, and the repository's focused checks pass locally: tests/test_workflow_sync.py and tests/test_vscode_app.py (4 passed). python scripts/sync_extensions.py --check reports no generated-artifact drift caused by this change.
  • Required status checks for main on this head (test, sync-extensions, validate-claude-code) are green.

Non-blocking observation: the sync-sdk-skill check on this head is failing, but it is not caused by this PR. The branch is based on 62f34e3, and main has since regenerated skills/openhands-sdk/SKILL.md via scripts/sync_openhands_sdk_skill.py; that file is byte-identical between the PR base and the head, and the diff touches only build-vscode-app.yml. Rebasing onto current main (or @dependabot rebase) clears the failure. sync-sdk-skill is not a required status check for main.

No material bugs, security problems, or design flaws found in the change.

✅ APPROVED

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7 branch from 0cb004e to 58a058e Compare October 4, 2026 17:26

@enyst enyst left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm an AI agent (Claude Code, based on Opus 5.5) helping Engel Nyst (@enyst) with project work.

Approving. This bumps the last actions/checkout@v4 under .github/workflows/ to @v7. build-vscode-app.yml arrived in #675 after #501 moved the other seven workflow files, which is why #501 missed it.

Adding to all-hands-bot's approval:

  • On this rebased head the updated action actually ran: Build VS Code App / package (a push event on the Dependabot branch) passed at 58a058e, and sync-sdk-skill, which failed on the head the bot reviewed, passes now.
  • v7.0.1 came out on 2026-07-20, well past the seven-day window.
  • There is no overlap with #358, which pins third-party actions in three other workflow files.

Heads-up for later, not for this PR: the composite actions under plugins/ (pr-review, qa-changes, release-notes, vulnerability-remediation) still use actions/checkout@v4, and Dependabot's directory: / doesn't scan them. Bumping them won't be mechanical. plugins/pr-review/action.yml checks out the PR head repository, which v7 blocks by default under pull_request_target, so that bump will need a deliberate decision.

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-7 branch from 58a058e to 02f6b92 Compare October 4, 2026 21:33
@neubig
neubig merged commit a242ccc into main Oct 5, 2026
12 checks passed
@neubig
neubig deleted the dependabot/github_actions/actions/checkout-7 branch October 5, 2026 01:13
@openhands-release-bot openhands-release-bot Bot added the released: v0.28.0 Shipped in v0.28.0 label Oct 5, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in v0.28.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code released: v0.28.0 Shipped in v0.28.0 type: ci CI configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants