ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3) - #301

Merged
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x
Jun 2, 2026
Merged

ci(github-action): update action actions/checkout (v6.0.2 → v6.0.3)#301
its-miso[bot] merged 1 commit into
mainfrom
renovate/actions-checkout-6.x

Conversation

@its-miso

@its-misoits-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageTypeUpdateChange
actions/checkoutactionpatchv6.0.2v6.0.3

Release Notes

actions/checkout (actions/checkout)

v6.0.3

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@its-miso

its-misoBot commented Jun 2, 2026

Copy link
Copy Markdown
ContributorAuthor

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

@its-miso
its-misoBot merged commit e211580 into mainJun 2, 2026
1 check passed
@its-miso
its-misoBot deleted the renovate/actions-checkout-6.x branch June 2, 2026 15:20

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Analysis engine: MiniMax@https://litellm.jory.dev/v1 (anthropic)

Recommendation: Approve

This is a routine, low-risk patch update of the actions/checkout GitHub Action from v6.0.2 to v6.0.3 in .github/workflows/ai-pr-review.yaml. The change is well-formed, SHA-pinned (security best practice), and the upstream release contains only bug fixes — no breaking changes per semver.


Change-by-Change Findings

.github/workflows/ai-pr-review.yaml

  • Old: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
  • New: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
  • The commit SHA df4cb1c069e1874edd31b4311f1884172cec0e10 matches the head commit on the v6.0.2...v6.0.3 compare (4 commits ahead, 0 behind). The release v6.0.3 was published on 2026-06-02.
  • The version comment (# v6.0.3) is updated consistently with the SHA — good.
  • No input changes (fetch-depth: 0, ref: expression) — the upgrade is purely a version bump.

Upstream Release Notes (v6.0.3)

Two fixes only, both SHA-256 related:

  1. #2439 — Fix checkout init for SHA-256 repositories
  2. #2414 — Expand merge commit SHA regex and add SHA-256 test cases

No breaking changes, no API/inputs/outputs changes. Patch-level bump is appropriate per semver.

Repository-Wide Consistency Note (non-blocking)

The same action is also pinned to v6.0.2 in two other workflows:

  • .github/workflows/ci.yaml:28actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  • .github/workflows/image.yaml:32actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

This creates a temporary version drift across workflows. Not a blocker for this PR (Renovate commonly opens per-file PRs, and v6.0.3 is backward-compatible with v6.0.2), but worth noting that follow-up PRs for the other two workflows are likely pending or expected.


Sources


Standards Compliance

AGENTS.md does not codify specific rules for GitHub Actions version pinning, but the change aligns with good security hygiene:

  • ✅ Actions are pinned by full commit SHA, not mutable tag (the v6.0.3 is a comment for human readability; the resolved reference is the immutable SHA).
  • ✅ Version comment # v6.0.3 is kept in sync with the SHA — matches the repository's existing pattern across all three workflow files.
  • ✅ Patch-only bump stays within the v6 major version line.
  • ✅ No secret material, no node_modules/build artifacts, no source code modifications — AGENTS.md §Code Standards rules are unaffected.

Linked Issue Fit

No linked issue references found in the PR body. As a routine Renovate dependency bump, this is not expected to reference an issue. No acceptance criteria to evaluate.

Evidence Provider Findings

No evidence providers were configured for this run. No supply-chain or security findings to report beyond the SHA-pinning verification performed against the GitHub Releases enrichment data.

Tool Harness Findings

Harness reported 0 planned requests with a non-fatal planning warning ("Could not parse planning response as JSON"). No actionable tool findings — the warning is a harness-side issue, not a code defect.

Unknowns or Needs Verification

  • None material. The SHA-to-release mapping is corroborated by both the compare metadata (last commit SHA matches) and the GitHub Releases enrichment (v6.0.3 published 2026-06-02). The version drift in ci.yaml and image.yaml is a minor observation, not a gap that affects this PR's correctness.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants