chore(deps): update actions/checkout action to v5.1.0 - #31
Conversation
|
PR author is in the excluded authors list. |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 | ||
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 |
There was a problem hiding this comment.
🔍 Pinned SHA update should be verified against the upstream v5.1.0 tag
This Renovate bump changes the pinned commit for actions/checkout from the v5.0.1 SHA to fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 labeled v5.1.0. Since this workflow is a security gate that deliberately pins by SHA, the only meaningful review action is confirming the new SHA actually corresponds to the upstream v5.1.0 tag in actions/checkout — that cannot be verified from repo contents alone. The same change was applied consistently to the copy at workflow-templates/public-repo-guard.yml:45, so the vendored template and the live workflow stay in sync.
Was this helpful? React with 👍 or 👎 to provide feedback.
ApprovabilityVerdict: Needs human review Minor CI dependency update (actions/checkout v5.0.1 → v5.1.0), but both changed files are owned by yakimoto per CODEOWNERS. The designated owner should review this change. You can customize Macroscope's approvability policy. Learn more. |


This PR contains the following updates:
v5.0.1→v5.1.0Release Notes
actions/checkout (actions/checkout)
v5.1.0Compare Source
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.