Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jan 5, 2026

Bumps actions/checkout from 4 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.1

What's Changed

Full Changelog: actions/checkout@v4...v4.3.1

v4.3.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

v4.1.5

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Greptile Summary

Updated actions/checkout from v4 to v6 across all 4 workflow files (8 total checkout steps). This is a standard dependency update generated by Dependabot.

Key changes in v6:

  • Node.js 24 runtime support
  • Improved credential handling (credentials now stored in $RUNNER_TEMP instead of directly in .git/config)
  • Requires minimum Actions Runner v2.327.1 (v2.329.0 for Docker container scenarios)

Files affected:

  • .github/workflows/deploy.yml - 1 checkout step updated
  • .github/workflows/generate-summaries.yml - 1 checkout step updated
  • .github/workflows/pr-checks.yml - 4 checkout steps updated
  • .github/workflows/run-pipelines.yml - 2 checkout steps updated

All workflows use standard checkout configurations without special credential handling or Docker containers, so the v6 changes are fully compatible. GitHub-hosted runners already meet the minimum version requirements.

Confidence Score: 5/5

  • Safe to merge - standard dependency update with no breaking changes
  • This is a straightforward version bump of a well-maintained GitHub official action. All workflows use standard checkout configurations, and GitHub-hosted runners already meet the minimum version requirements for v6.
  • No files require special attention

Important Files Changed

Filename Overview
.github/workflows/deploy.yml Updated actions/checkout from v4 to v6 - straightforward version bump, no compatibility issues
.github/workflows/generate-summaries.yml Updated actions/checkout from v4 to v6 - straightforward version bump, no compatibility issues
.github/workflows/pr-checks.yml Updated actions/checkout from v4 to v6 across 4 checkout steps - straightforward version bump, no compatibility issues
.github/workflows/run-pipelines.yml Updated actions/checkout from v4 to v6 across 2 checkout steps - straightforward version bump, no compatibility issues

Sequence Diagram

sequenceDiagram
    participant GHA as GitHub Actions Runner
    participant CO as actions/checkout@v6
    participant Repo as Repository
    participant RT as $RUNNER_TEMP
    
    Note over GHA,Repo: Dependency Update: v4 → v6
    
    GHA->>CO: Invoke checkout action
    CO->>Repo: Clone repository
    
    alt v6 Credential Handling
        CO->>RT: Store credentials in $RUNNER_TEMP
        Note over RT: Improved security isolation
    else v4 Credential Handling (old)
        CO->>Repo: Store credentials in .git/config
        Note over Repo: Direct git config modification
    end
    
    CO->>GHA: Repository checked out
    Note over GHA: Node.js 24 runtime support
    GHA->>GHA: Execute workflow steps
Loading

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jan 5, 2026
@coderabbitai
Copy link

coderabbitai bot commented Jan 5, 2026

Important

Review skipped

Auto reviews are disabled on this repository.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant