Skip to content

chore(deps): update actions/checkout action to v5.1.0 - #31

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-5.x
Open

chore(deps): update actions/checkout action to v5.1.0#31
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-5.x

Conversation

@renovate

@renovate renovate Bot commented Aug 8, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
actions/checkout action minor v5.0.1v5.1.0

Release Notes

actions/checkout (actions/checkout)

v5.1.0

Compare Source


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "after 1am and before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@renovate
renovate Bot requested a review from yakimoto as a code owner August 8, 2026 07:57
@greptile-apps

greptile-apps Bot commented Aug 8, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Open in Devin Review

runs-on: ubuntu-latest
steps:
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Pinned SHA update should be verified against the upstream v5.1.0 tag

This Renovate bump changes the pinned commit for actions/checkout from the v5.0.1 SHA to fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 labeled v5.1.0. Since this workflow is a security gate that deliberately pins by SHA, the only meaningful review action is confirming the new SHA actually corresponds to the upstream v5.1.0 tag in actions/checkout — that cannot be verified from repo contents alone. The same change was applied consistently to the copy at workflow-templates/public-repo-guard.yml:45, so the vendored template and the live workflow stay in sync.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: low. Left a non-blocking comment — Cursor Security Agent was present but skipped, so this was not auto-approved. Cursor Bugbot was not running; human review is needed (CODEOWNER already requested).

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@macroscopeapp

macroscopeapp Bot commented Aug 8, 2026

Copy link
Copy Markdown

Approvability

Verdict: Needs human review

Minor CI dependency update (actions/checkout v5.0.1 → v5.1.0), but both changed files are owned by yakimoto per CODEOWNERS. The designated owner should review this change.

You can customize Macroscope's approvability policy. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants