Skip to content

chore(deps): bump actions/checkout from 5 to 7 - #431

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/actions/checkout-7
Open

chore(deps): bump actions/checkout from 5 to 7#431
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 5 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 1, 2026
@dependabot
dependabot Bot requested a review from tomymaritano as a code owner July 1, 2026 19:56
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 1, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) July 1, 2026 19:56
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-7 branch from 6e980ab to 5327e5c Compare July 2, 2026 04:46
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-7 branch from 5327e5c to 1a9888a Compare July 3, 2026 17:23
tomymaritano added a commit that referenced this pull request Aug 22, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

Dependabot PRs fail the required `e2e` check in ~20s during `pnpm
install`, not during Playwright. Automerge is already enabled; it cannot
land while e2e is red.

**Exact failure** (PR #482 job
[96541625973](https://github.com/dripnex/app/actions/runs/32404870524/job/96541625973),
also #464 / #456 / #462 and `commitlint` on #464):

```
ERROR  Command failed with exit code 128: git clone git@github.com:electron/node-gyp.git ...
git@github.com: Permission denied (publickey).
```

This is not missing repo secrets. Dependabot-regenerated lockfiles
resolve `@electron/node-gyp` as a git dep whose `resolution.repo` is
SSH:

```
# PR #456 (shell-quote) lockfile
'@electron/node-gyp@git+https://git@github.com:electron/node-gyp.git#06b29aa...'
resolution: {commit: 06b29aa..., repo: git@github.com:electron/node-gyp.git, type: git}

# develop lockfile (e2e green after #541)
'@electron/node-gyp@https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...'
resolution: {tarball: https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...}
```

pnpm clones `resolution.repo` over SSH. GitHub-hosted runners have no
deploy key.

The `setup` job already rewrites SSH to HTTPS and therefore succeeds on
the same PRs. `e2e` and `commitlint` did a fresh `pnpm install` without
that rewrite.

`develop` itself is green after #541 — its lockfile uses the HTTPS
tarball, so e2e never hits the SSH clone.

## Type of Change

- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update

## Fix

Add the same `git config --global 'url.https://github.com/.insteadOf'
'git@github.com:'` step that `setup` / `release` / `build` / `docs`
already use:

- `.github/workflows/ci.yml` `e2e` job — unblocks the required e2e check
- `.github/workflows/pr-title.yml` — same SSH death on Dependabot
lockfiles

Existing Dependabot PRs (#482, #464, #462, #460, #459, #456, #451, #431,
#430, #248) should go green after rebase onto this `develop` change (the
merge commit picks up the workflow).

## Related Issues

Closes #544

## Checklist

- [x] I've read [CONTRIBUTING.md](../CONTRIBUTING.md)
- [ ] Tests pass locally (`pnpm test`) — workflow-only change; no
product code
- [ ] Build succeeds (`pnpm build`) — not applicable
- [x] PR targets `develop` branch (not `main`)

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-65d9f024-2af5-4bbe-8318-35ae4db127d2?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-65d9f024-2af5-4bbe-8318-35ae4db127d2&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code size/S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants