From ff4f4594c2b903e19547f873d622598c46ce6865 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 25 Mar 2026 14:10:40 +0000 Subject: [PATCH] fix(ci): bump actions/checkout from 4.2.2 to 6.0.2 Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 6.0.2. - [Release notes](https://github.com/actions/checkout/releases) - [Commits](https://github.com/actions/checkout/compare/v4.2.2...v6.0.2) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.2 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 2 +- .github/workflows/official-build.yml | 2 +- .github/workflows/on-push-verification.yml | 2 +- .github/workflows/sample-workflow.yml | 2 +- .github/workflows/self-hosted-validation-v1.yml | 2 +- .github/workflows/self-hosted-validation-v2.yml | 2 +- .github/workflows/toolchain-version-probe.yml | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e129a116..d738944d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -14,7 +14,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v6.0.2 - name: Set up Node.js uses: actions/setup-node@v6 diff --git a/.github/workflows/official-build.yml b/.github/workflows/official-build.yml index 016e6bde..99ce274d 100644 --- a/.github/workflows/official-build.yml +++ b/.github/workflows/official-build.yml @@ -17,7 +17,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@v6.0.2 - name: Extract branch name shell: bash diff --git a/.github/workflows/on-push-verification.yml b/.github/workflows/on-push-verification.yml index 86138cb4..4bd35a88 100644 --- a/.github/workflows/on-push-verification.yml +++ b/.github/workflows/on-push-verification.yml @@ -22,7 +22,7 @@ jobs: steps: # Checkout your code repository to scan - - uses: actions/checkout@v6 + - uses: actions/checkout@v6.0.2 # Run analyzers - uses: ./ diff --git a/.github/workflows/sample-workflow.yml b/.github/workflows/sample-workflow.yml index 7f2411a8..77c6cf47 100644 --- a/.github/workflows/sample-workflow.yml +++ b/.github/workflows/sample-workflow.yml @@ -20,7 +20,7 @@ jobs: steps: # Checkout your code repository to scan - - uses: actions/checkout@v6 + - uses: actions/checkout@v6.0.2 # Run analyzers - name: Run Microsoft Security DevOps Analysis diff --git a/.github/workflows/self-hosted-validation-v1.yml b/.github/workflows/self-hosted-validation-v1.yml index 67d1254c..3471076b 100644 --- a/.github/workflows/self-hosted-validation-v1.yml +++ b/.github/workflows/self-hosted-validation-v1.yml @@ -14,7 +14,7 @@ jobs: steps: # Checkout your code repository to scan - - uses: actions/checkout@v6 + - uses: actions/checkout@v6.0.2 # Run MSDO v1 - name: Run MSDO diff --git a/.github/workflows/self-hosted-validation-v2.yml b/.github/workflows/self-hosted-validation-v2.yml index de57d5e4..12476bd2 100644 --- a/.github/workflows/self-hosted-validation-v2.yml +++ b/.github/workflows/self-hosted-validation-v2.yml @@ -16,7 +16,7 @@ jobs: steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v6.0.2 - name: Run Defender CLI - Image Scan uses: ./v2/ diff --git a/.github/workflows/toolchain-version-probe.yml b/.github/workflows/toolchain-version-probe.yml index a87751b2..ecc8c564 100644 --- a/.github/workflows/toolchain-version-probe.yml +++ b/.github/workflows/toolchain-version-probe.yml @@ -24,7 +24,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 # Run MSDO — scan may find nothing (no real targets), that's fine. # Side effect: Guardian downloads all tool packages into _msdo/packages/nuget/.