Skip to content

chore(deps): update actions/checkout action to v7.0.1 - #6453

Merged
thomhurst merged 1 commit into
mainfrom
renovate/actions-checkout-7.x
Jul 20, 2026
Merged

chore(deps): update actions/checkout action to v7.0.1#6453
thomhurst merged 1 commit into
mainfrom
renovate/actions-checkout-7.x

Conversation

@thomhurst

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v7.0.0v7.0.1

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@thomhurst thomhurst added dependencies Pull requests that update a dependency file PATCH renovate-bot labels Jul 20, 2026
@thomhurst
thomhurst enabled auto-merge (squash) July 20, 2026 15:18
@greptile-apps

greptile-apps Bot commented Jul 20, 2026

Copy link
Copy Markdown

Greptile Summary

This PR bumps actions/checkout from v7.0.0 to v7.0.1 across all 11 GitHub Actions workflow files. The patch release includes internal dependency updates and security-relevant fixes (escaping values passed to --unset, trimming only ASCII whitespace for branch names, and skipping unsafe PR checks when input is default).

  • All 11 workflow files receive the same mechanical version-string change (v7.0.0v7.0.1).
  • The upstream patch contains a fix for potential command injection via unescaped --unset arguments, making this update worth applying promptly.

Confidence Score: 5/5

Safe to merge — purely a patch version bump with no workflow logic changes.

Every change is a mechanical string replacement of the action version tag. The upstream patch brings security-relevant hardening (escaping values passed to --unset, ASCII-only whitespace trimming for branch names, skipping the unsafe-PR check when input is default) with no breaking changes. All 11 files are updated consistently.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/dotnet.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/speed-comparison.yml Bumps actions/checkout in 4 job steps from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/mock-benchmarks.yml Bumps actions/checkout in 2 job steps from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/codeql.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/claude-code-review.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/claude.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/cloudshop-example.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/deploy-pages-test.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/deploy-pages.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/dotnet-build-different-locale.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.
.github/workflows/link-check.yml Bumps actions/checkout from v7.0.0 to v7.0.1 — no functional change.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Renovate Bot] --> B[Detect actions/checkout\nv7.0.0 to v7.0.1]
    B --> C{Update 11 workflow files}
    C --> D[claude-code-review.yml]
    C --> E[claude.yml]
    C --> F[cloudshop-example.yml]
    C --> G[codeql.yml]
    C --> H[deploy-pages-test.yml]
    C --> I[deploy-pages.yml]
    C --> J[dotnet-build-different-locale.yml]
    C --> K[dotnet.yml]
    C --> L[link-check.yml]
    C --> M[mock-benchmarks.yml]
    C --> N[speed-comparison.yml]
    D --> O[actions/checkout at v7.0.1]
    E --> O
    F --> O
    G --> O
    H --> O
    I --> O
    J --> O
    K --> O
    L --> O
    M --> O
    N --> O
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
    A[Renovate Bot] --> B[Detect actions/checkout\nv7.0.0 to v7.0.1]
    B --> C{Update 11 workflow files}
    C --> D[claude-code-review.yml]
    C --> E[claude.yml]
    C --> F[cloudshop-example.yml]
    C --> G[codeql.yml]
    C --> H[deploy-pages-test.yml]
    C --> I[deploy-pages.yml]
    C --> J[dotnet-build-different-locale.yml]
    C --> K[dotnet.yml]
    C --> L[link-check.yml]
    C --> M[mock-benchmarks.yml]
    C --> N[speed-comparison.yml]
    D --> O[actions/checkout at v7.0.1]
    E --> O
    F --> O
    G --> O
    H --> O
    I --> O
    J --> O
    K --> O
    L --> O
    M --> O
    N --> O
Loading

Reviews (1): Last reviewed commit: "chore(deps): update actions/checkout act..." | Re-trigger Greptile

@thomhurst
thomhurst merged commit 50752dd into main Jul 20, 2026
14 of 15 checks passed
@thomhurst
thomhurst deleted the renovate/actions-checkout-7.x branch July 20, 2026 15:46
github-actions Bot pushed a commit to IntelliTect/CodingGuidelines that referenced this pull request Jul 27, 2026
Updated [TUnit.Core](https://github.com/thomhurst/TUnit) from 1.61.15 to
1.61.38.

<details>
<summary>Release notes</summary>

_Sourced from [TUnit.Core's
releases](https://github.com/thomhurst/TUnit/releases)._

## 1.61.38

<!-- Release notes generated using configuration in .github/release.yml
at v1.61.38 -->

## What's Changed
### Other Changes
* fix: apply 'unmanaged' constraint handling to remaining source
generators by @​thomhurst in
thomhurst/TUnit#6474
* feat: expose data source attributes on TestContext by @​thomhurst in
thomhurst/TUnit#6477
### Dependencies
* chore(deps): update tunit to 1.61.35 by @​thomhurst in
thomhurst/TUnit#6475


**Full Changelog**:
thomhurst/TUnit@v1.61.35...v1.61.38

## 1.61.35

<!-- Release notes generated using configuration in .github/release.yml
at v1.61.35 -->

## What's Changed
### Other Changes
* fix(mocks): omit 'struct' constraint when type parameter has
'unmanaged' constraint by @​thomhurst in
thomhurst/TUnit#6473
### Dependencies
* chore(deps): bump fast-uri from 3.1.2 to 3.1.4 in /docs by
@​dependabot[bot] in thomhurst/TUnit#6466
* chore(deps): update tunit to 1.61.29 by @​thomhurst in
thomhurst/TUnit#6467
* chore(deps): update dependency verify.tool to v0.8.0 by @​thomhurst in
thomhurst/TUnit#6470
* chore(deps): update dependency docusaurus-plugin-llms to ^0.5.1 by
@​thomhurst in thomhurst/TUnit#6472


**Full Changelog**:
thomhurst/TUnit@v1.61.29...v1.61.35

## 1.61.29

<!-- Release notes generated using configuration in .github/release.yml
at v1.61.29 -->

## What's Changed
### Other Changes
* perf: remove EnumerableAsyncProcessor dependency by @​thomhurst in
thomhurst/TUnit#6465
### Dependencies
* chore(deps): bump shell-quote from 1.8.4 to 1.10.0 in /docs by
@​dependabot[bot] in thomhurst/TUnit#6462
* chore(deps): bump body-parser from 1.20.5 to 1.20.6 in /docs by
@​dependabot[bot] in thomhurst/TUnit#6461
* chore(deps): bump webpack-dev-server from 5.2.5 to 5.2.6 in /docs by
@​dependabot[bot] in thomhurst/TUnit#6460
* chore(deps): update dependency microsoft.kiota.abstractions to v2 by
@​thomhurst in thomhurst/TUnit#6464
* chore(deps): update tunit to 1.61.23 by @​thomhurst in
thomhurst/TUnit#6463


**Full Changelog**:
thomhurst/TUnit@v1.61.23...v1.61.29

## 1.61.23

<!-- Release notes generated using configuration in .github/release.yml
at v1.61.23 -->

## What's Changed
### Other Changes
* fix(mocks): emit 'where T : default' for interface-constrained generic
methods by @​thomhurst in thomhurst/TUnit#6458
### Dependencies
* chore(deps): update tunit to 1.61.15 by @​thomhurst in
thomhurst/TUnit#6450
* chore(deps): update actions/checkout action to v7.0.1 by @​thomhurst
in thomhurst/TUnit#6453
* chore(deps): update verify to 31.26.0 by @​thomhurst in
thomhurst/TUnit#6454
* chore(deps): update verify to 31.27.0 by @​thomhurst in
thomhurst/TUnit#6457
* chore(deps): update react to ^19.2.8 by @​thomhurst in
thomhurst/TUnit#6459


**Full Changelog**:
thomhurst/TUnit@v1.61.15...v1.61.23

Commits viewable in [compare
view](thomhurst/TUnit@v1.61.15...v1.61.38).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=TUnit.Core&package-manager=nuget&previous-version=1.61.15&new-version=1.61.38)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file PATCH renovate-bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants