diff --git a/.github/workflows/agent.yml b/.github/workflows/agent.yml index c9685dee0..f432ada78 100644 --- a/.github/workflows/agent.yml +++ b/.github/workflows/agent.yml @@ -30,7 +30,7 @@ jobs: --remove-label agent:ready \ --add-label agent:running - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 # Sibling path-dep workspaces — mirrors ci.yml so the agent can build. - name: Clone sibling repos diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 54240971e..38b6101f9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -25,7 +25,7 @@ jobs: matrix: toolchain: [stable, nightly] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Clone sibling repos run: | git clone --depth 1 https://github.com/ecto/tang.git ../tang @@ -71,7 +71,7 @@ jobs: name: WASM build runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Clone sibling repos run: | git clone --depth 1 https://github.com/ecto/tang.git ../tang @@ -173,7 +173,7 @@ jobs: runs-on: ubuntu-latest needs: wasm steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: actions/setup-node@v6 with: node-version: 22 @@ -233,7 +233,7 @@ jobs: name: cargo audit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Clone sibling repos run: | git clone --depth 1 https://github.com/ecto/tang.git ../tang @@ -253,7 +253,7 @@ jobs: name: npm audit runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: actions/setup-node@v6 with: node-version: 22 diff --git a/.github/workflows/desktop-release.yml b/.github/workflows/desktop-release.yml index 9f7c9e122..2571d7dba 100644 --- a/.github/workflows/desktop-release.yml +++ b/.github/workflows/desktop-release.yml @@ -39,7 +39,7 @@ jobs: outputs: body: ${{ steps.gen.outputs.body }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: # Enough history for release-notes.mjs to pull recent commit # subjects as flavor for the humanized summary. @@ -82,7 +82,7 @@ jobs: runs-on: ubuntu-22.04 if: startsWith(github.ref, 'refs/tags/') steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 # Same sibling-repo clones as `build`; `cargo publish` runs the in-tree # verify pass which compiles the crate, and that resolves path deps on @@ -145,7 +145,7 @@ jobs: tauri-args: '' runs-on: ${{ matrix.platform }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 # Path-dep sibling workspaces (mirrors ci.yml / agent.yml). - name: Clone sibling repos diff --git a/.github/workflows/fix-ci.yml b/.github/workflows/fix-ci.yml index b262473b2..229fc5e0c 100644 --- a/.github/workflows/fix-ci.yml +++ b/.github/workflows/fix-ci.yml @@ -87,7 +87,7 @@ jobs: - name: Checkout PR branch if: steps.pr.outputs.skip != 'true' - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: ref: ${{ steps.pr.outputs.pr_branch }} fetch-depth: 0 diff --git a/.github/workflows/mention.yml b/.github/workflows/mention.yml index 2bb9fadeb..be7ae5bf0 100644 --- a/.github/workflows/mention.yml +++ b/.github/workflows/mention.yml @@ -38,7 +38,7 @@ jobs: github.event.comment.user.type != 'Bot' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Snapshot comment + thread context # Route untrusted user text (comment body, issue title/body) diff --git a/.github/workflows/supabase.yml b/.github/workflows/supabase.yml index 3868c6694..daa9821fd 100644 --- a/.github/workflows/supabase.yml +++ b/.github/workflows/supabase.yml @@ -31,7 +31,7 @@ jobs: if: github.event_name == 'pull_request' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: supabase/setup-cli@v2 with: version: latest @@ -62,7 +62,7 @@ jobs: SUPABASE_DB_PASSWORD: ${{ secrets.SUPABASE_DB_PASSWORD }} SUPABASE_PROJECT_ID: ${{ secrets.SUPABASE_PROJECT_ID }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: supabase/setup-cli@v2 with: version: latest