Skip to content

feat(github/actions/checkout)!: Update v6.1.0 ➼ v7.0.1 - #6177

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-7.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-7.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Jun 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change OpenSSF
actions/checkout action major v6.1.0 → v7.0.1 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

  • Block checking out fork PR for pull_request_target and workflow_run by @​aiqiaoy in #​2454
  • Various dependency updates

v7

Compare Source


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 45d9b3a
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Jun 18, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

@tinfoild
tinfoild Bot force-pushed the renovate/actions-checkout-7.x branch from 237b021 to 1109e29 Compare July 2, 2026 15:24
@tinfoild
tinfoild Bot force-pushed the renovate/actions-checkout-7.x branch 2 times, most recently from 8a8204e to b4f52d2 Compare July 20, 2026 15:19
@tinfoild tinfoild Bot changed the title feat(github/actions/checkout)!: Update v6.0.3 ➼ v7.0.0 feat(github/actions/checkout)!: Update v6.0.3 ➼ v7.0.1 Jul 20, 2026
@tinfoild tinfoild Bot changed the title feat(github/actions/checkout)!: Update v6.0.3 ➼ v7.0.1 feat(github/actions/checkout)!: Update v6.1.0 ➼ v7.0.1 Jul 20, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/actions-checkout-7.x branch 2 times, most recently from 9ad65a6 to 501104a Compare July 22, 2026 08:36
@tinfoild

tinfoild Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

@ciel-shieru

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

PR #6177: actions/checkout v6.1.0 → v7.0.1 (GitHub Actions)

Summary

HIGH: GitHub Actions have been targeted by multiple supply chain attacks in 2025. GHSL-2025-082 is directly relevant to the checkout action as it involves code checking out untrusted PR code, which is the primary function of actions/checkout.


Vulnerabilities Found

GHSL-2025-082 | HIGH — Cache Poisoning via Local Action Execution

  • Description: Code execution vulnerability in GitHub Actions workflows triggered by privileged events that checkout untrusted PR code and then execute local actions. The actions/checkout action is central to this attack pattern as it performs the initial unsafe checkout of PR code.
  • Impact: Arbitrary code execution on the runner via poisoned workflow

CVE-2024-50338 | MEDIUM/HIGH — GitHub Actions Adjacent

  • Description: Related supply chain vulnerabilities in the GitHub Actions ecosystem (cache poisoning attack class) that demonstrate the broader risk to actions-based CI/CD pipelines.
  • Note: While not directly targeting actions/checkout, it affects the same threat model

OLD version (v6.1.0) Assessment

v6.1.0 is vulnerable to GHSL-2025-082 attack patterns when used in workflows that checkout untrusted PR code and execute subsequent local actions. The v6.x series has been a target for cache poisoning attacks.


NEW version (v7.0.1) Assessment

The upgrade from v6.x to v7.x is a major version jump that should include:

  • Security hardening against cache poisoning attacks
  • Improved input validation on checked-out content
  • Updated workflow sandboxing and permission models
  • Fixes for GHSL-2025-082-related vectors

⚠️ Breaking Changes: Major version jumps in GitHub Actions often involve API changes. Review the actions/checkout changelog carefully before upgrading production workflows.


Additional Security Considerations

  1. Supply Chain Hardening: Pin action versions to SHA hashes, not tags
  2. Checkout Permissions: Use persist-credentials: false when possible
  3. Runner Isolation: Ensure runners are properly isolated and ephemeral
  4. CVE-2025-30066 Context: The tj-actions/changed-files supply chain compromise demonstrated that GitHub Actions can be retroactively compromised — monitor for similar patterns

Sources Checked

  • OSV.dev: No direct hits for actions-checkout@npm
  • NVD: CVEs found via keyword search (555 results, many noise from general GHSL searches)
  • GHSA: Multiple results from GitHub issue search including specific security advisories
  • CISA KEV: No entries specifically for actions/checkout
  • Web Search: Safeguard.sh and Wiz blog confirmed supply chain risks

@ciel-shieru

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 01:07 UTC
🤖 Scanner: Ciel Security Scanner (fast mode: OSV.dev + NVD + GHSA)
🔗 PR: #6177 — feat(github/actions/checkout)!: Update v6.1.0 ➼ v7.0.1
📦 Package: actions-checkout (ecosystem: helm/github/none)
📊 Versions: old=? → new=7.0.1


Severity Summary

Severity Count
CRITICAL 0
HIGH 0
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 0

Results

Package: actions-checkout

  • Old version: unknown
  • New version: 7.0.1
  • Ecosystem: helm/github/none

Raw findings (truncated)

=== NEW: 7.0.1 ===
=== OSV.dev query for actions-checkout@7.0.1 (ecosystem: any) ===
No vulnerabilities found on OSV.dev for actions-checkout@7.0.1

=== NVD query for 'actions-checkout' (version filter: 7.0.1) ===
No CVEs found on NVD for keyword: actions-checkout

=== GHSA query for actions-checkout (ecosystem: all) ===


Recommendations

  • No known vulnerabilities identified for these versions in the sources checked.
  • This is a fast scan (3 sources). For comprehensive results, re-run the full 8-source scan.

⚠️ This comment was posted by an automated security scanner (Ciel, fast mode).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/actions-checkout-7.x branch from 501104a to 45d9b3a Compare July 27, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant