Skip to content

ci: bump checkout to v7 - #53

Merged
rnovatorov merged 1 commit into
mainfrom
ci/bump-checkout-v7
Sep 23, 2026
Merged

rnovatorov merged 1 commit into
mainfrom
ci/bump-checkout-v7

Conversation

@rnovatorov

Copy link
Copy Markdown
Member

Summary

Bump all actions/checkout references from @v4 to @v7 (current major; latest v7.0.1).

Jobs updated

All four checkouts in .github/workflows/ci.yml:

  • run_checks
  • upload_to_pypi
  • push_to_docker_hub
  • push_to_enapter_docker_hub

Breaking-change analysis

  • checkout v7 runs on Node 24 and was ported to ESM — no workflow-side changes needed.
  • v7's breaking change is safer defaults for pull_request_target / workflow_run events (new allow-unsafe-pr-checkout input). This workflow triggers on push only and does not use pull_request_target or workflow_run, so it is unaffected.
  • v7 requires Actions Runner v2.327.1+; ubuntu-latest satisfies this.

Notes

Only run_checks is PR-visible in CI; the Docker jobs are tag-gated (refs/tags/v), so they'll be exercised on the next release.

Align to the current major of actions/checkout (Node 24 runtime, ESM).
The v7 breaking change concerns safer pull_request_target/workflow_run
checkout defaults, which this push-only workflow doesn't use. The runner
requirement (v2.327.1+) is satisfied by ubuntu-latest.
@rnovatorov
rnovatorov merged commit 2cf6fd9 into main Sep 23, 2026
7 checks passed
@rnovatorov
rnovatorov deleted the ci/bump-checkout-v7 branch September 23, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant