Skip to content

ci(review): pin actions/checkout to v7.0.1 - #7

Merged
PerfectPan merged 1 commit into
mainfrom
ci/pin-checkout-v7
Sep 30, 2026
Merged

PerfectPan merged 1 commit into
mainfrom
ci/pin-checkout-v7

Conversation

@PerfectPan

Copy link
Copy Markdown
Owner

Title format: type(scope): summary

Summary

  • review.yml and ci.yml.example use actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 instead of @v4.

Motivation

  • Dependabot in a downstream repository proposed this bump inside review.yml, a file that should stay a verbatim copy of the template. Bumping here keeps every copy identical.
  • Pinning by SHA makes the workflow reproducible.

Implementation Notes

  • SHA verified against gh api repos/actions/checkout/git/ref/tags/v7.0.1.

Validation

  • Repository checks: ./scripts/check-repository.sh --staged ok.
  • This PR's Review run exercises the new pin.

Skipped gates and reasons:

  • No stack-specific gates in this template.

Evidence

  • Review workflow run on this PR.

Safety Checklist

  • No credentials, tokens, private hostnames, personal filesystem paths, or generated logs are included.
  • Local config, generated output, build artifacts, and temporary workspaces are not staged.
  • User-facing behavior, docs, changelog, migrations, or rollback notes are updated when relevant.
  • Completed Spec/Plan constraints are migrated to tests or current-state docs before retirement; unfinished scope remains active.
  • The branch is current enough for review, and the remote head matches the intended commit.

Follow-up Risks

  • Downstream repositories need to re-sync review.yml.

Pin by commit SHA so the review workflow is reproducible, and bump it
here so downstream copies of review.yml stay identical to the template.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@PerfectPan
PerfectPan merged commit c5349a0 into main Sep 30, 2026
3 checks passed
@PerfectPan
PerfectPan deleted the ci/pin-checkout-v7 branch September 30, 2026 17:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant