You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by @dependabot[bot] in actions/checkout#2458
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
This is a Dependabot-generated bump of actions/checkout from v6 to v7 across all nine GitHub Actions workflow files. The key behavioral change in v7 is a security hardening that blocks checkout of fork PRs under pull_request_target and workflow_run triggers — none of the workflows in this repo use those triggers, so there is no functional impact.
Files that were already SHA-pinned (publish-pages.yaml, release-please.yml) are updated to the correct v7.0.0 commit SHA (9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0) with updated inline comments.
Files using floating version tags are uniformly updated from @v6 to @v7; storage-integration.yml moves from the more-specific @v6.0.2 to @v7, aligning it with the rest of the non-pinned workflows.
Confidence Score: 5/5
Safe to merge — a straightforward version bump with no functional changes to any workflow logic.
All nine workflows are updated consistently. The only behavioral change in v7 (blocking fork checkouts for pull_request_target/workflow_run triggers) does not apply here since every workflow uses push or pull_request triggers. SHA-pinned files have their commit hash and inline comments correctly updated to v7.0.0.
No files require special attention.
Important Files Changed
Filename
Overview
.github/workflows/ci.yml
Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/deploy-vercel-preview.yml
Bumps actions/checkout from @v6 to @v7; workflow uses pull_request trigger (not pull_request_target), so v7's new fork-blocking behavior has no impact
.github/workflows/deploy-vercel-staging.yml
Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/deploy-vercel.yml
Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/publish-pages.yaml
Updates SHA-pinned checkout from v6.0.2 commit to v7.0.0 commit (9c091bb); comment correctly updated to # v7.0.0
.github/workflows/release-please.yml
Updates both SHA-pinned checkout occurrences from v6.0.2 to v7.0.0 commit SHA; comments correctly reflect new version
.github/workflows/release.yml
Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/self-deploy.yml
Bumps actions/checkout from @v6 to @v7 (floating major tag)
.github/workflows/storage-integration.yml
Bumps actions/checkout from @v6.0.2 to @v7, moving from a patch-pinned tag to a floating major tag — consistent with the other non-SHA-pinned workflows in the repo
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code
0 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)