chore: bump actions/checkout from 6 to 7 - #6021
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
prql-bot
left a comment
There was a problem hiding this comment.
The bump is mechanical and correct across the workflow files, but actions/checkout@v7.0.0 ships one behavioral change worth a maintainer's call before merging: it now refuses to check out fork-PR code under pull_request_target / workflow_run unless allow-unsafe-pr-checkout: true is set (actions/checkout#2454).
The block fires only when all three hold: the trigger is pull_request_target/workflow_run, the PR head is a fork (different repo id), and the resolved ref matches refs/pull/N/(head|merge). I checked every checkout step in the diff — the only one that hits all three is tend-review.yaml, which checks out refs/pull/$PR/merge. Every other tend workflow uses ref: main (safe), and same-repo PRs like this Dependabot one are unaffected because the head-repo id equals the base-repo id.
Net effect: after this merges, tend-review will keep working on internal/branch PRs but will fail on external contributor (fork) PRs with Refusing to check out fork pull request code from a 'pull_request_target' workflow.
I didn't push a fix because both plausible remedies are maintainer/upstream calls, not a mechanical default:
tend-review.yamlis auto-generated by tend (Do not edit this file directly — it will be overwritten on regeneration), so addingallow-unsafe-pr-checkout: truehere would be lost on the nexttend init. The durable fix belongs upstream in max-sixty/tend.- Opting back in re-enables exactly the "pwn request" exposure v7 added the guard for (gh.io/securely-using-pull_request_target) — a security tradeoff worth a deliberate decision.
Everything else in the bump is fine to take as-is.
| echo "::notice::refs/pull/$PR/merge unavailable (likely merge conflict); falling back to /head" | ||
| fi | ||
| - uses: actions/checkout@v6 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
Heads up: under v7, this checkout will throw Refusing to check out fork pull request code from a 'pull_request_target' workflow for fork PRs, because the step resolves ref to refs/pull/N/(head|merge) (see the pr_ref step above) and this job runs on pull_request_target. Internal/branch PRs (same repo id) are unaffected.
To restore fork-PR reviews, the checkout step needs allow-unsafe-pr-checkout: true — but since this file is regenerated by tend, that's best fixed upstream in max-sixty/tend rather than edited here.
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)