Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 12, 2025

User description

Bumps actions/checkout from 4.2.2 to 5.0.0.

Release notes

Sourced from actions/checkout's releases.

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v4...v4.3.0

Changelog

Sourced from actions/checkout's changelog.

V5.0.0

V4.3.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

PR Type

Enhancement, Dependencies


Description

Bump actions/checkout to v5.0.0.
Update in test and deploy jobs.
Aligns workflow with Node 24 runner.
No logic changes to pipeline steps.


Diagram Walkthrough

flowchart LR
  WF["GitHub Actions workflow"]
  CO4["actions/[email protected]"]
  CO5["actions/[email protected]"]
  Test["Test job"]
  Deploy["Deploy job"]

  WF -- "used by" --> Test
  WF -- "used by" --> Deploy
  Test -- "replace" --> CO5
  Deploy -- "replace" --> CO5
  CO4 -- "upgrade to" --> CO5
Loading

File Walkthrough

Relevant files
Dependencies
deploy.yml
Upgrade checkout action to v5 in workflow                               

.github/workflows/deploy.yml

  • Upgrade actions/checkout v4.2.2 -> v5.0.0
  • Apply upgrade in Test job
  • Apply upgrade in Deploy job
+2/-2     

Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 5.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4.2.2...v5.0.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 12, 2025
@sophie-syntax sophie-syntax bot changed the title build(deps): bump actions/checkout from 4.2.2 to 5.0.0 build(deps): bump actions/checkout to v5.0.0 in workflows Aug 12, 2025
Copy link

sophie-syntax bot commented Aug 12, 2025

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 Security concerns

Supply-chain hardening:
Using a floating major tag (actions/[email protected] tag reference) can be less secure than pinning to a specific commit SHA. Consider pinning to the exact commit of v5.0.0 to reduce risk of tag hijacking.

⚡ Recommended focus areas for review

Compatibility Check

Verify that workflow permissions and inputs remain compatible with actions/checkout v5.0.0 on windows-latest, especially around default token permissions and any breaking changes between v4 and v5.

- name: Check out code
  uses: actions/[email protected]
  with:
    fetch-depth: 0
Pinning Strategy

Consider pinning to a specific commit SHA for actions/checkout v5 for supply-chain security and reproducibility, rather than a moving major tag.

- name: Check out code
  uses: actions/[email protected]
  with:
    fetch-depth: 0

steps:
- name: Check out code
uses: actions/checkout@v4.2.2
uses: actions/checkout@v5.0.0
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: Pin the action to a specific commit SHA instead of a floating tag to prevent supply-chain and breaking-change risks. Update the reference to the official v5.0.0 commit digest. [security, importance: 8]

Suggested change
uses: actions/checkout@v5.0.0
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code Review effort 1/5
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants