Skip to content

chore(deps): bump actions/checkout from 4 to 6#5

Closed
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/github_actions/actions/checkout-6
Closed

chore(deps): bump actions/checkout from 4 to 6#5
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/github_actions/actions/checkout-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown

Bumps actions/checkout from 4 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.1

What's Changed

Full Changelog: actions/checkout@v4...v4.3.1

v4.3.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

... (truncated)

Commits

- Core: init, scan, version
- Dependency analysis: deps, drift, watch, tpn
- Security analysis: reach, audit, secrets
- Remediation: fix, update
- Compliance: baseline (OSPS), badge, license, policy
- Supply chain: slsa, supply-chain, pin, maturity (S2C2F)
- Generation: insights, sbom-gen, ci, report
- Container: container (Dockerfile linting)
- Utilities: compare, fuzz
- 147 unit tests
- OpenSSF repo standards: LICENSE, SECURITY.md, CODE_OF_CONDUCT.md,
  CONTRIBUTING.md, CHANGELOG.md, CI workflow, Scorecard, CodeQL,
  Dependabot, SBOM generation, Sigstore signing
@dependabot @github

dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

kkotari and others added 3 commits May 7, 2026 17:44
- Fix all 47 ruff lint errors (unused imports, ambiguous variables)
- Rewrite README.md documenting all 26 commands
- Add CI badges (CI status, license, Python version)
- Add PyPI release workflow with trusted publishing
- Remove stale roadmap (all items implemented)
- Fix GitHub URLs to kirankotari/ossguard
- Run ruff format on all 31 unformatted files
- Fix ossf/scorecard-action@v2 (tag doesn't exist) to @v2.4.0
- Fix scorecard generator template to use v2.4.0
- All ruff check + format + 147 tests pass
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): Bump actions/checkout from 4 to 6 chore(deps): bump actions/checkout from 4 to 6 May 7, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-6 branch from 80d247d to 529e438 Compare May 7, 2026 22:00
@kirankotari kirankotari closed this May 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/github_actions/actions/checkout-6 branch May 7, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants