Skip to content

Bump actions/checkout from 5 to 6#25

Merged
rennf93 merged 1 commit intomasterfrom
dependabot/github_actions/actions/checkout-6
Nov 30, 2025
Merged

Bump actions/checkout from 5 to 6#25
rennf93 merged 1 commit intomasterfrom
dependabot/github_actions/actions/checkout-6

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 24, 2025

Bumps actions/checkout from 5 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

V6.0.0

V5.0.1

V5.0.0

V4.3.1

V4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

v4.1.5

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Nov 24, 2025
@github-actions
Copy link

🔍 Vulnerabilities of renzof93/github-actions-secrets-mgmt:latest

📦 Image Reference renzof93/github-actions-secrets-mgmt:latest
digestsha256:4558a684db088ca57b9f2207138077fd993cfd1eb62c52f2ac7c26cf92a790c7
vulnerabilitiescritical: 0 high: 0 medium: 1 low: 0
platformlinux/amd64
size104 MB
packages63
📦 Base Image python:3-alpine3.20
also known as
  • 3.13-alpine3.20
  • 3.13.3-alpine3.20
  • alpine3.20
digestsha256:68834522e73344a5337150a62e87a75be9046c0e39b9bab925be078d953e54e1
vulnerabilitiescritical: 0 high: 2 medium: 5 low: 2
critical: 0 high: 0 medium: 1 low: 0 requests 2.32.3 (pypi)

pkg:pypi/requests@2.32.3

medium 5.3: CVE--2024--47081 Insufficiently Protected Credentials

Affected range<2.32.4
Fixed version2.32.4
CVSS Score5.3
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score0.067%
EPSS Percentile21st percentile
Description

Impact

Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.

Workarounds

For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs).

References

psf/requests#6965
https://seclists.org/fulldisclosure/2025/Jun/2

@github-actions
Copy link

Recommended fixes for image renzof93/github-actions-secrets-mgmt:latest

Base image is python:3-alpine3.20

Name3.13.3-alpine3.20
Digestsha256:68834522e73344a5337150a62e87a75be9046c0e39b9bab925be078d953e54e1
Vulnerabilitiescritical: 0 high: 2 medium: 5 low: 2
Pushed6 months ago
Size16 MB
Packages41
Flavoralpine
OS3.20
Runtime3.13.3

Refresh base image

Rebuild the image using a newer base image version. Updating this may result in breaking changes.

✅ This image version is up to date.

Change base image

TagDetailsPushedVulnerabilities
3-alpine
Tag is preferred tag
Also known as:
  • alpine
  • alpine3.22
  • 3.14.0-alpine
  • 3.14.0-alpine3.22
  • 3.14-alpine
  • 3.14-alpine3.22
  • 3-alpine3.22
Benefits:
  • Same OS detected
  • Minor runtime version update
  • Minor OS version update
  • Tag is preferred tag
  • Tag was pushed more recently
  • Image has similar size
  • Image introduces no new vulnerability but removes 6
  • Image contains equal number of packages
  • 3-alpine was pulled 51K times last month
Image details:
  • Size: 18 MB
  • Flavor: alpine
  • OS: 3.22
  • Runtime: 3.14.0
1 month ago



3.13-alpine3.21
Minor runtime version update
Also known as:
  • 3.13.9-alpine3.21
Benefits:
  • Same OS detected
  • Minor runtime version update
  • Image is smaller by 49 KB
  • Minor OS version update
  • Image contains 3 fewer packages
  • Tag was pushed more recently
  • Image introduces no new vulnerability but removes 6
Image details:
  • Size: 16 MB
  • Flavor: alpine
  • OS: 3.21
  • Runtime: 3.13.9
1 month ago



3-alpine3.21
Minor runtime version update
Also known as:
  • alpine3.21
  • 3.14.0-alpine3.21
  • 3.14-alpine3.21
Benefits:
  • Same OS detected
  • Minor runtime version update
  • Minor OS version update
  • Image contains 1 fewer package
  • Tag was pushed more recently
  • Image has similar size
  • Image introduces no new vulnerability but removes 6
Image details:
  • Size: 17 MB
  • Flavor: alpine
  • OS: 3.21
  • Runtime: 3.14.0
1 month ago



3.13-alpine
Minor runtime version update
Also known as:
  • 3.13.9-alpine
  • 3.13.9-alpine3.22
  • 3.13-alpine3.22
Benefits:
  • Same OS detected
  • Minor runtime version update
  • Minor OS version update
  • Image contains 2 fewer packages
  • Tag was pushed more recently
  • Image has similar size
  • Image introduces no new vulnerability but removes 6
Image details:
  • Size: 17 MB
  • Flavor: alpine
  • OS: 3.22
  • Runtime: 3.13.9
1 month ago



@github-actions
Copy link

Overview

Image reference renzof93/github-actions-secrets-mgmt:latest renzof93/github-actions-secrets-mgmt:latest
- digest 69a63135d395 4558a684db08
- tag latest latest
- stream latest
- vulnerabilities critical: 0 high: 1 medium: 6 low: 2 critical: 0 high: 1 medium: 5 low: 2
- platform linux/amd64 linux/amd64
- size 93 MB 104 MB (+11 MB)
- packages 63 63
Base Image python:3-alpine3.20 python:3-alpine3.20
- vulnerabilities critical: 0 high: 2 medium: 5 low: 2 critical: 0 high: 2 medium: 5 low: 2
Packages and Vulnerabilities (3 package changes and 1 vulnerability changes)
  • ♾️ 3 packages changed
  • 60 packages unchanged
  • ✔️ 1 vulnerabilities removed
Changes for packages of type pypi (3 changes)
Package Version
renzof93/github-actions-secrets-mgmt:latest
Version
renzof93/github-actions-secrets-mgmt:latest
♾️ certifi 2025.10.5 2025.11.12
♾️ charset-normalizer 3.4.3 3.4.4
♾️ pip 25.2 25.3
critical: 0 high: 0 medium: 1 low: 0
Removed vulnerabilities (1):
  • medium : CVE--2025--8869

@rennf93 rennf93 merged commit 36ed458 into master Nov 30, 2025
2 checks passed
@dependabot dependabot bot deleted the dependabot/github_actions/actions/checkout-6 branch November 30, 2025 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant