Skip to content

XS✔ ◾ Bump actions/checkout from 6.0.2 to 6.0.3#814

Merged
muiriswoulfe merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-6.0.3
Jun 12, 2026
Merged

XS✔ ◾ Bump actions/checkout from 6.0.2 to 6.0.3#814
muiriswoulfe merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-6.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 11, 2026

Copy link
Copy Markdown
Contributor

Additional Changes: Beyond the actions/checkout bump (from 6.0.2 to 6.0.3) that Dependabot opened this PR for, it now also:

  • Bumps github/codeql-action from 4.36.0 to 4.36.2 (merged in from XS✔ ◾ Bump github/codeql-action from 4.36.0 to 4.36.2 #813).
  • Switches the Dependabot CI job in .github/workflows/build.yml to auto-approve Dependabot pull requests (gh pr review --approve) instead of auto-merging them, and narrows the minted App token to {"pull_requests":"write"} (dropping contents:write and workflows:write).

Rationale for the CI change: The App installation is not granted the workflows permission and the repository is squash-only, so the App token cannot squash-merge github-actions updates, which always modify workflow files. A maintainer completes the squash merge manually.


Bumps actions/checkout from 6.0.2 to 6.0.3.

Release notes

Sourced from actions/checkout's releases.

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Updates to dependencies github-actions Updates to GitHub Action dependencies labels Jun 11, 2026
@dependabot dependabot Bot requested review from a team and Copilot June 11, 2026 12:20
@dependabot dependabot Bot added dependencies Updates to dependencies github-actions Updates to GitHub Action dependencies labels Jun 11, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@muiriswoulfe

Copy link
Copy Markdown
Member

/AzurePipelines run

@muiriswoulfe

Copy link
Copy Markdown
Member

Azure Pipelines run for Commit ab8abfd

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@microsoft-pr-metrics

microsoft-pr-metrics Bot commented Jun 11, 2026

Copy link
Copy Markdown

PR Metrics

Thanks for keeping your pull request small.
Thanks for adding tests.

Lines
Product Code -
Test Code -
Subtotal -
Ignored Code 15
Total 15

Metrics computed by PR Metrics. Add it to your Azure DevOps and GitHub PRs!

@microsoft-pr-metrics microsoft-pr-metrics Bot changed the title Bump actions/checkout from 6.0.2 to 6.0.3 XS✔ ◾ Bump actions/checkout from 6.0.2 to 6.0.3 Jun 11, 2026
@muiriswoulfe muiriswoulfe enabled auto-merge (squash) June 11, 2026 13:41
Copilot AI review requested due to automatic review settings June 11, 2026 14:33
@muiriswoulfe muiriswoulfe force-pushed the dependabot/github_actions/actions/checkout-6.0.3 branch from 84d2d89 to f1259c8 Compare June 11, 2026 14:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

microsoft-pr-metrics[bot]
microsoft-pr-metrics Bot previously approved these changes Jun 11, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

Comment thread .github/workflows/build.yml
@muiriswoulfe

Copy link
Copy Markdown
Member

/AzurePipelines run

@muiriswoulfe

Copy link
Copy Markdown
Member

Azure Pipelines run for Commit 4caef51

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@muiriswoulfe

Copy link
Copy Markdown
Member

/AzurePipelines run

@muiriswoulfe

Copy link
Copy Markdown
Member

Azure Pipelines run for Commit 8d04cf7

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@muiriswoulfe muiriswoulfe merged commit 3559bd0 into main Jun 12, 2026
35 checks passed
@muiriswoulfe muiriswoulfe deleted the dependabot/github_actions/actions/checkout-6.0.3 branch June 12, 2026 09:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Updates to dependencies github-actions Updates to GitHub Action dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants