Light Mode

Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Bump actions/checkout from 5 to 6#64

Merged
docktermj merged 1 commit intomainfrom
dependabot/github_actions/actions/checkout-6
Nov 21, 2025
Merged

Bump actions/checkout from 5 to 6#64
docktermj merged 1 commit intomainfrom
dependabot/github_actions/actions/checkout-6

Conversation

Copy link
Contributor

dependabot bot commented on behalf of github Nov 21, 2025 *
edited by github-actions bot
Loading

Bumps actions/checkout from 5 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

V6.0.0

V5.0.1

V5.0.0

V4.3.1

V4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

v4.1.5

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Resolves #2311
Resolves #2298
Resolves #2286
Resolves #2248
Resolves actions/checkout#2248
Resolves actions/checkout#2286
Resolves actions/checkout#2298
Resolves actions/checkout#2311
Resolves actions/checkout#2301
Resolves actions/checkout#2226
Resolves actions/checkout#2305
Resolves actions/checkout#1971
Resolves actions/checkout#1977
Resolves actions/checkout#2043
Resolves actions/checkout#2044
Resolves actions/checkout#2194
Resolves actions/checkout#2224
Resolves actions/checkout#2236
Resolves actions/checkout#1941
Resolves actions/checkout#1946
Resolves actions/checkout#1924
Resolves actions/checkout#1180
Resolves actions/checkout#1777
Resolves actions/checkout#1872
Resolves actions/checkout#1739
Resolves actions/checkout#1697
Resolves actions/checkout#1774
Resolves actions/checkout#1776
Resolves actions/checkout#1732
Resolves actions/checkout#1703
Resolves actions/checkout#1694
Resolves actions/checkout#1696
Resolves actions/checkout#1695

Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot]
dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Nov 21, 2025
dependabot bot requested a review from a team as a code owner November 21, 2025 15:04
dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Nov 21, 2025
Copy link

github-actions bot commented Nov 21, 2025

Claude Code Review

Code Review Analysis

Summary

This PR updates the GitHub Actions checkout action from v5 to v6. This is a dependency update with minimal code changes.


Detailed Checklist Review

Code Quality

Code follows style guide

  • .github/workflows/pylint.yaml:19 - YAML formatting is consistent and follows standard GitHub Actions conventions
  • No style guide violations in this dependency version bump

No commented-out code

  • The diff contains no commented-out code

Meaningful variable names

  • N/A - No new variables introduced

DRY principle followed

  • N/A - This is a version bump, no code duplication issues

Defects identification

  • No bugs, logic errors, or security vulnerabilities introduced
  • The upgrade from actions/checkout@v5 to @v6 is a standard maintenance update
  • The persist-credentials: false configuration is maintained, which is a security best practice

Testing

Unit tests for new functions

  • N/A - No new functions added

Integration tests for new endpoints

  • N/A - No new endpoints added

Edge cases covered

  • N/A - This is an action version bump

Test coverage > 80%

  • N/A - No testable code changes

Note: While marked as , these items are not applicable to this type of change. A dependency update to a GitHub Action doesn't require new tests.

Documentation

Readme updated if needed

  • Not required - workflow file changes don't need README updates

API docs updated

  • N/A - No API changes

Inline comments for complex logic

  • N/A - No complex logic added

CHANGELOG.md updated

  • .github/workflows/pylint.yaml:19 - Minor infrastructure update that typically wouldn't require CHANGELOG entry
  • Recommendation: Consider whether your project tracks GitHub Actions updates in CHANGELOG. Most projects don't, but verify your convention.

Security

No hardcoded credentials

  • No credentials present

Input validation implemented

  • N/A - No new inputs

Proper error handling

  • N/A - No error handling changes needed

No sensitive data in logs

  • No logging changes

No license files (.lic) or AQAAAD strings

  • No license files or suspicious strings detected

Overall Assessment

APPROVED

This is a clean, low-risk dependency update:

  • Updates actions/checkout from v5 to v6
  • Maintains security best practice (persist-credentials: false)
  • No functional code changes
  • Standard maintenance update

Recommendations:

  1. Verify that actions/checkout@v6 is compatible with your workflow needs (breaking changes are minimal between v5-v6)
  2. Consider if your project requires CHANGELOG entries for GitHub Actions updates

Risk Level: Low
Merge Recommendation: Safe to merge

Automated code review analyzing defects and coding standards

docktermj approved these changes Nov 21, 2025
docktermj merged commit d654455 into main Nov 21, 2025
25 checks passed
docktermj deleted the dependabot/github_actions/actions/checkout-6 branch November 21, 2025 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

docktermj docktermj approved these changes

Assignees

No one assigned

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant