Skip to content

Update shared checkout action to v7 - #61

Merged
pxLi merged 1 commit into
NVIDIA:mainfrom
pxLi:fix-actions-deprecations
Sep 22, 2026
Merged

pxLi merged 1 commit into
NVIDIA:mainfrom
pxLi:fix-actions-deprecations

Conversation

@pxLi

@pxLi pxLi commented Sep 22, 2026

Copy link
Copy Markdown
Member

Description

Update the shared checkout wrapper from actions/checkout@v6 to actions/checkout@v7, following the existing major-version reference convention. The v7 tag currently resolves to the latest stable release, v7.0.1.

Preserve all existing wrapper inputs, defaults, and forwarding. No workflow triggers, permissions, repository policies, or other shared actions are changed.

Checkout v7 adds protection against checking out fork pull request code in pull_request_target and workflow_run workflows. Keep that protection enabled; this change does not expose or enable the unsafe-checkout override. The existing privileged callers checked use trusted base/default-branch refs, and the shared signoff action explicitly checks out NVIDIA/spark-rapids-common at main.

References

Validation

  • YAML parsing and structural comparison passed: the checkout action version is the only semantic change.
  • Verified all 20 forwarded inputs remain supported by checkout v7 and the unsafe-checkout override remains disabled by default.
  • Verified the v7 tag matches the latest stable v7.0.1 release.
  • Inspected current default-branch workflow callers across the seven active Spark repositories and the shared signoff action for compatibility with the privileged-checkout guard.
  • git diff --check passed.
  • Live checkout execution remains to be validated in GitHub Actions; existing repository workflows reference the published common action at main, not this PR branch.

Signed-off-by: Peixin Li <pxLi@nyu.edu>
@pxLi
pxLi requested a review from a team as a code owner September 22, 2026 04:05
@pxLi pxLi added the Action label Sep 22, 2026
@greptile-apps

greptile-apps Bot commented Sep 22, 2026

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

The PR appears safe to merge because the dependency-only update preserves the wrapper contract and no incompatible repository caller was identified.

Summary

Updates the shared checkout composite action from actions/checkout@v6 to actions/checkout@v7.

  • Preserves the wrapper's existing inputs, defaults, and forwarding.
  • Leaves workflow triggers, permissions, and other action dependencies unchanged.
  • Adds a final newline to the action metadata file.

Reviews (1) · Last reviewed commit: "Update shared checkout action to v7"

@pxLi pxLi self-assigned this Sep 22, 2026
@pxLi
pxLi merged commit 834dbba into NVIDIA:main Sep 22, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants