chore(deps): bump actions/checkout from 4 to 6 - #32
dependabot[bot] wants to merge 1 commit into
Conversation
cdf718b to
ff67658
Compare
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v6) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
ff67658 to
f5af1c6
Compare
ghost
left a comment
There was a problem hiding this comment.
✅ Arkana Code Review — APPROVE
Scope: CI-only. 6 workflow files, each with a single-line change: actions/checkout@v4 → actions/checkout@v6. No source code, no protocol code, no API changes.
Findings: None.
- All changed lines are identical
v4→v6substitutions. No other modifications. - All workflows run on
ubuntu-latest(GitHub-hosted), which exceeds the v2.329.0 runner minimum required by checkout v6. - v6 improves credential handling by persisting to
$RUNNER_TEMPinstead of local git config — net security improvement for CI. - No cross-repo impact. No downstream consumers affected.
Ship it.
arkana-ai-bot
left a comment
There was a problem hiding this comment.
CI-only dependency bump: actions/checkout v4 → v6 across release.yml, cli.yml, integration-test.yml, lint.yml, test.yml. No protocol surface touched (no VTXO/signing/forfeit/round/exit code).
Notes:
- v5 moved to Node.js 24; v6 changed credential persistence to store creds under
$RUNNER_TEMPinstead of the local git config, and requires runner ≥ v2.329.0. All jobs useubuntu-latest(GitHub-hosted), so runner version is a non-issue. release.ymlusesfetch-depth: 0in the sdk-hashes and build matrix jobs; the credential-persistence change does not affect this. Neither of the checkouts appears to run any additional git commands that read persisted creds from the old on-disk location, so the storage-location change should be transparent.- No submodules or downstream steps rely on the old
extraheadergit config location that I can see.
Non-blocking observations (pre-existing, not introduced here):
- Actions are pinned by major tag (
@v6) rather than by commit SHA. Not a regression from this PR, but for a protocol-critical repo, SHA-pinning + Dependabot'sversioning-strategyfor actions would be worth considering.
LGTM as a CI bump. Note this PR has been open >30 days and auto-rebase is disabled — rebase manually before merging if base has moved.
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/checkout from 4 to 6.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)08c6903Prepare v5.0.0 release (#2238)