ci(deps): bump actions/checkout from 4 to 7 - #726
Conversation
all-hands-bot
left a comment
There was a problem hiding this comment.
This review was posted by an AI agent (OpenHands).
Scope: this change bumps actions/checkout from @v4 to @v7 on the single checkout step in .github/workflows/build-vscode-app.yml. That is in-repo CI maintenance, and it matches the repository's existing convention: every other workflow under .github/workflows/ already pins actions/checkout@v7 on main, so this removes the last @v4 outlier.
Assessment of the version jump (4 -> 7):
- The job only triggers on
workflow_dispatchandpush(pathsapps/vscode/**), never onpull_request_targetorworkflow_run. The v7 breaking change that blocks checking out fork PR heads for those two events therefore does not apply here. ubuntu-latestrunners satisfy the Node 24 requirement introduced in checkout v5+.- The file parses as valid YAML, and the repository's focused checks pass locally:
tests/test_workflow_sync.pyandtests/test_vscode_app.py(4 passed).python scripts/sync_extensions.py --checkreports no generated-artifact drift caused by this change. - Required status checks for
mainon this head (test,sync-extensions,validate-claude-code) are green.
Non-blocking observation: the sync-sdk-skill check on this head is failing, but it is not caused by this PR. The branch is based on 62f34e3, and main has since regenerated skills/openhands-sdk/SKILL.md via scripts/sync_openhands_sdk_skill.py; that file is byte-identical between the PR base and the head, and the diff touches only build-vscode-app.yml. Rebasing onto current main (or @dependabot rebase) clears the failure. sync-sdk-skill is not a required status check for main.
No material bugs, security problems, or design flaws found in the change.
✅ APPROVED
0cb004e to
58a058e
Compare
There was a problem hiding this comment.
I'm an AI agent (Claude Code, based on Opus 5.5) helping Engel Nyst (@enyst) with project work.
Approving. This bumps the last actions/checkout@v4 under .github/workflows/ to @v7. build-vscode-app.yml arrived in #675 after #501 moved the other seven workflow files, which is why #501 missed it.
Adding to all-hands-bot's approval:
- On this rebased head the updated action actually ran:
Build VS Code App / package(a push event on the Dependabot branch) passed at58a058e, andsync-sdk-skill, which failed on the head the bot reviewed, passes now. - v7.0.1 came out on 2026-07-20, well past the seven-day window.
- There is no overlap with #358, which pins third-party actions in three other workflow files.
Heads-up for later, not for this PR: the composite actions under plugins/ (pr-review, qa-changes, release-notes, vulnerability-remediation) still use actions/checkout@v4, and Dependabot's directory: / doesn't scan them. Bumping them won't be mechanical. plugins/pr-review/action.yml checks out the PR head repository, which v7 blocks by default under pull_request_target, so that bump will need a deliberate decision.
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
58a058e to
02f6b92
Compare
|
🚀 Released in v0.28.0. |
Bumps actions/checkout from 4 to 7.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)