ci: bump actions/checkout to v6.0.3#83
Merged
Merged
Conversation
Carved out of the Dependabot github-actions group (#77), taking only the safe actions/checkout v6.0.2 -> v6.0.3 patch. Holds back the group's actions/download-artifact v7 -> v8 bump: v8 makes artifact hash mismatches fail by default (a warning in v7), and the only consumer is the release workflow's "Download all installer artifacts" step over large binary installers (.dmg/.msi/.flatpak) where transient digest mismatches happen. That path is never exercised by PR CI, so the bump's risk can't be validated here. download-artifact stays on v7, which both the desktop and Android releases just shipped on. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Carved out of the Dependabot
github-actionsgroup (#77), taking only the safe actions/checkout v6.0.2 → v6.0.3 patch acrossci.ymlandrelease.yml.Why not the whole group
The group also bumped actions/download-artifact v7 → v8, which is held back:
.dmg/.msi/.flatpak) — exactly where GitHub's backend occasionally returns a transient digest mismatch.download-artifactstays on v7, which both the desktop and Android releases just shipped on cleanly. It can be revisited deliberately later (e.g. with adigest-mismatchoverride, or validated on a throwaway-rc).Supersedes #77, which will be closed.
🤖 Generated with Claude Code