From f1c7de1697b86262951f936565afa580108bdee7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 18:41:06 +0000 Subject: [PATCH] chore(deps): bump actions/checkout from 4 to 7 Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/audit.yml | 6 +++--- .github/workflows/ci.yml | 2 +- .github/workflows/docker-publish.yml | 4 ++-- .github/workflows/ns8-module.yml | 4 ++-- .github/workflows/pullfrog.yml | 2 +- 5 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/audit.yml b/.github/workflows/audit.yml index bc2ac811..4de6d7ae 100644 --- a/.github/workflows/audit.yml +++ b/.github/workflows/audit.yml @@ -22,7 +22,7 @@ jobs: security-events: write id-token: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: persist-credentials: false @@ -46,7 +46,7 @@ jobs: name: SBOM (syft) runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: anchore/sbom-action@v0 with: @@ -59,7 +59,7 @@ jobs: name: Deterministic claims guard runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 # gitleaks needs full history diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 390f265e..a71427ba 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,7 +17,7 @@ jobs: check: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: pnpm/action-setup@v6 with: diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 727cb844..d0db0c5a 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -36,7 +36,7 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: docker/setup-qemu-action@v3 @@ -89,7 +89,7 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 # Pull the matching version's section out of CHANGELOG.md for the release body, # so the GitHub Release and the CHANGELOG stay identical. Index-based (not a `\[` diff --git a/.github/workflows/ns8-module.yml b/.github/workflows/ns8-module.yml index afe38069..56ccfde8 100644 --- a/.github/workflows/ns8-module.yml +++ b/.github/workflows/ns8-module.yml @@ -24,7 +24,7 @@ jobs: validate: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Validate action scripts and schemas working-directory: packaging/ns8 @@ -42,7 +42,7 @@ jobs: contents: read packages: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 # Mirror the app tagging in docker-publish.yml: release tags pin both # images to the same version, branches track the moving app tags. diff --git a/.github/workflows/pullfrog.yml b/.github/workflows/pullfrog.yml index 90c75951..e175a251 100644 --- a/.github/workflows/pullfrog.yml +++ b/.github/workflows/pullfrog.yml @@ -22,7 +22,7 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: fetch-depth: 1 - name: Run agent