mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
ci(.github/workflows): update checkout to v7 (#26909)
Update GitHub Actions workflows to use `actions/checkout` v7.0.0 pinned to `9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0`, following the GitHub Actions checkout hardening changes announced in: - https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ - https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/ Audited the existing `pull_request_target` workflows and did not add any `allow-unsafe-pr-checkout` opt-outs, since these workflows do not intentionally check out fork PR head code. Generated by Coder Agents. <details> <summary>Plan notes</summary> - Update all `.github/workflows` `actions/checkout` references to v7.0.0 using the pinned SHA. - Preserve SHA pinning, including the newly added MCP registry workflow. - Validate that old checkout pins are removed and no unsafe checkout opt-outs are introduced. </details>
This commit is contained in:
@@ -30,7 +30,7 @@ jobs:
|
||||
egress-policy: audit
|
||||
|
||||
- name: Checkout
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
@@ -59,7 +59,7 @@ jobs:
|
||||
egress-policy: audit
|
||||
|
||||
- name: Checkout
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
|
||||
Reference in New Issue
Block a user