Skip to content

chore(actions):(deps): bump actions/checkout from 4 to 7 - #161

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Open

chore(actions):(deps): bump actions/checkout from 4 to 7#161
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: automated, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

⚠️ Major version update detected! Please review this PR manually before merging.

@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

⚠️ Security Alert: Vulnerabilities detected in dependencies

Security Audit Report

npm audit results

# npm audit report

@babel/core  <=7.29.0
@babel/core: Arbitrary File Read via sourceMappingURL Comment - https://github.com/advisories/GHSA-4x5r-pxfx-6jf8
fix available via `npm audit fix`
node_modules/@babel/core

dompurify  <=3.4.10
Severity: moderate
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects - https://github.com/advisories/GHSA-x4vx-rjvf-j5p4
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` - https://github.com/advisories/GHSA-76mc-f452-cxcm
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks - https://github.com/advisories/GHSA-hpcv-96wg-7vj8
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM - https://github.com/advisories/GHSA-r47g-fvhr-h676
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output - https://github.com/advisories/GHSA-vxr8-fq34-vvx9
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes - https://github.com/advisories/GHSA-gvmj-g25r-r7wr
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content - https://github.com/advisories/GHSA-rp9w-3fw7-7cwq
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) - https://github.com/advisories/GHSA-cmwh-pvxp-8882
fix available via `npm audit fix`
node_modules/dompurify
  monaco-editor  0.54.0-dev-20250909 - 0.56.0-dev-20260211
  Depends on vulnerable versions of dompurify
  node_modules/monaco-editor

js-yaml  4.0.0 - 4.1.1
Severity: moderate
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases - https://github.com/advisories/GHSA-h67p-54hq-rp68
fix available via `npm audit fix`
node_modules/js-yaml

protobufjs  <=7.6.2
Severity: moderate
protobufjs : Schema-derived names can shadow runtime-significant properties - https://github.com/advisories/GHSA-f38q-mgvj-vph7
fix available via `npm audit fix`
node_modules/protobufjs
  @google/genai  
  Depends on vulnerable versions of protobufjs
  node_modules/@google/genai

vite  8.0.0 - 8.0.15
Severity: high
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows - https://github.com/advisories/GHSA-v6wh-96g9-6wx3
vite: `server.fs.deny` bypass on Windows alternate paths - https://github.com/advisories/GHSA-fx2h-pf6j-xcff
fix available via `npm audit fix`
node_modules/vite

7 vulnerabilities (2 low, 4 moderate, 1 high)

To address all issues, run:
  npm audit fix

⚠️ Vulnerabilities detected - please review

Outdated Dependencies

Package                           Current   Wanted   Latest  Location                                       Depended by
@eslint/js                         9.39.4   9.39.4   10.0.1  node_modules/@eslint/js                        Omni-Grid-2.0
@google/genai                      1.46.0   1.52.0   2.10.0  node_modules/@google/genai                     Omni-Grid-2.0
@testing-library/react             16.3.1   16.3.2   16.3.2  node_modules/@testing-library/react            Omni-Grid-2.0
@types/node                        25.5.0   25.9.4   26.1.0  node_modules/@types/node                       Omni-Grid-2.0
@types/react                      19.2.14  19.2.17  19.2.17  node_modules/@types/react                      Omni-Grid-2.0
@types/react-grid-layout            2.1.0    2.1.0    1.3.6  node_modules/@types/react-grid-layout          Omni-Grid-2.0
@typescript-eslint/eslint-plugin   8.57.1   8.62.1   8.62.1  node_modules/@typescript-eslint/eslint-plugin  Omni-Grid-2.0
@typescript-eslint/parser          8.57.1   8.62.1   8.62.1  node_modules/@typescript-eslint/parser         Omni-Grid-2.0
@vitejs/plugin-react                6.0.1    6.0.3    6.0.3  node_modules/@vitejs/plugin-react              Omni-Grid-2.0
@vitest/coverage-v8                 4.1.0   4.1.10   4.1.10  node_modules/@vitest/coverage-v8               Omni-Grid-2.0
@vitest/ui                          4.1.0   4.1.10   4.1.10  node_modules/@vitest/ui                        Omni-Grid-2.0
eslint                             9.39.2   9.39.4   10.6.0  node_modules/eslint                            Omni-Grid-2.0
eslint-plugin-react-hooks           7.0.1    7.1.1    7.1.1  node_modules/eslint-plugin-react-hooks         Omni-Grid-2.0
jsdom                              27.4.0   27.4.0   29.1.1  node_modules/jsdom                             Omni-Grid-2.0
lucide-react                      0.577.0  0.577.0   1.23.0  node_modules/lucide-react                      Omni-Grid-2.0
prettier                            3.7.4    3.9.4    3.9.4  node_modules/prettier                          Omni-Grid-2.0
react-grid-layout                   1.4.4    1.4.4    2.2.3  node_modules/react-grid-layout                 Omni-Grid-2.0
typescript                          5.9.3    5.9.3    6.0.3  node_modules/typescript                        Omni-Grid-2.0
vite                                8.0.8    8.1.3    8.1.3  node_modules/vite                              Omni-Grid-2.0
vitest                              4.1.0   4.1.10   4.1.10  node_modules/vitest                            Omni-Grid-2.0
zustand                            5.0.12   5.0.12   5.0.14  node_modules/zustand                           Omni-Grid-2.0

Installed Packages

copy-of-omni-grid@0.0.0 /home/runner/work/Omni-Grid-2.0/Omni-Grid-2.0
├── @eslint/js@9.39.4
├── @google/genai@1.46.0
├── @monaco-editor/react@4.7.0
├── @testing-library/dom@10.4.1
├── @testing-library/jest-dom@6.9.1
├── @testing-library/react@16.3.1
├── @types/node@25.5.0
├── @types/react-dom@19.2.3
├── @types/react-grid-layout@2.1.0
├── @types/react@19.2.14
├── @typescript-eslint/eslint-plugin@8.57.1
├── @typescript-eslint/parser@8.57.1
├── @vitejs/plugin-react@6.0.1
├── @vitest/coverage-v8@4.1.0
├── @vitest/ui@4.1.0
├── eslint-config-prettier@10.1.8
├── eslint-plugin-react-hooks@7.0.1
├── eslint-plugin-react@7.37.5
├── eslint@9.39.2
├── jsdom@27.4.0
├── lucide-react@0.577.0
├── prettier@3.7.4
├── react-dom@19.2.7
├── react-grid-layout@1.4.4
├── react@19.2.7
├── typescript@5.9.3
├── vite@8.0.8
├── vitest@4.1.0
└── zustand@5.0.12


Report generated on Mon Jul 6 09:10:43 UTC 2026

@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

Build Performance Report

Frontend Build

  • Duration: 0s
  • Status: ✅ Built successfully
  • Bundle Size: 996K

Largest Assets

968K	dist/assets/index-yXMczT2r.js
8.0K	dist/sw.js
8.0K	dist/index.html
4.0K	dist/manifest.json

⚠️ Warning: 1 file(s) larger than 500KB detected

C++ Server Build

  • Duration: 3s
  • Binary Size: 76K
  • Status: ✅ Built successfully

@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

👋 This pull request has been automatically marked as stale because it has not had recent activity.
It will be closed in 14 days if no further activity occurs.

If this PR is still relevant, please:

  • Rebase against the latest main branch
  • Address any review comments
  • Add a comment to keep it open
  • Add the keep-open label

Thank you for your contributions! 🙏

@github-actions github-actions Bot added the stale label Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants