Skip to content

chore(deps): bump actions/checkout from 6 to 7#213

Merged
JAVGan merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7
Jun 22, 2026
Merged

chore(deps): bump actions/checkout from 6 to 7#213
JAVGan merged 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6 to 7.

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 22, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 22, 2026
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@JAVGan JAVGan force-pushed the dependabot/github_actions/actions/checkout-7 branch from 8b27e32 to d419dd3 Compare June 22, 2026 17:09
@qodo-for-releng

Copy link
Copy Markdown

CI Feedback 🧐

A test triggered by this PR failed. Here is an AI-generated analysis of the failure:

Action: security

Failed stage: OWASP check [❌]

Failed test name: ""

Failure summary:

The action failed during an OWASP Dependency-Check run because it could not update the NVD (National
Vulnerability Database) data feed.
- Dependency-Check repeatedly retried NVD API requests (at least
15–31 retries) and ultimately failed with NVD Returned Status Code: 503 (service unavailable).
-
This caused a fatal org.owasp.dependencycheck.data.update.exception.UpdateException: Error updating
the NVD Data (see stack trace around NvdApiDataSource.processApi(NvdApiDataSource.java:387)).
-
Dependency-Check then aborted the scan (Unable to continue dependency-check analysis) and exited
with code 13.

Relevant error logs:
1:  ##[group]Runner Image Provisioner
2:  Hosted Compute Agent
...

556:  pythonLocation: /opt/hostedtoolcache/Python/3.10.20/x64
557:  PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.10.20/x64/lib/pkgconfig
558:  Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.20/x64
559:  Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.20/x64
560:  Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.20/x64
561:  LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.10.20/x64/lib
562:  GHA_PIP_AUDIT_SUMMARY: true
563:  GHA_PIP_AUDIT_NO_DEPS: false
564:  GHA_PIP_AUDIT_REQUIRE_HASHES: false
565:  GHA_PIP_AUDIT_VULNERABILITY_SERVICE: PyPI
566:  GHA_PIP_AUDIT_VIRTUAL_ENVIRONMENT: 
567:  GHA_PIP_AUDIT_LOCAL: false
568:  GHA_PIP_AUDIT_INDEX_URL: 
569:  GHA_PIP_AUDIT_EXTRA_INDEX_URLS: 
570:  GHA_PIP_AUDIT_IGNORE_VULNS: 
571:  GHA_PIP_AUDIT_INTERNAL_BE_CAREFUL_ALLOW_FAILURE: false
572:  GHA_PIP_AUDIT_INTERNAL_BE_CAREFUL_EXTRA_FLAGS: 
...

726:  inflating: dependency-check/lib/semver4j-5.8.0.jar  
727:  inflating: dependency-check/lib/slf4j-api-2.0.17.jar  
728:  inflating: dependency-check/lib/snakeyaml-2.5.jar  
729:  inflating: dependency-check/lib/spotbugs-annotations-4.9.8.jar  
730:  inflating: dependency-check/lib/toml4j-0.7.2.jar  
731:  inflating: dependency-check/lib/velocity-engine-core-2.4.1.jar  
732:  inflating: dependency-check/lib/xz-1.9.jar  
733:  inflating: dependency-check/LICENSE.txt  
734:  inflating: dependency-check/NOTICE.txt  
735:  inflating: dependency-check/licenses/commons-cli/LICENSE.txt  
736:  inflating: dependency-check/README.md  
737:  [WARN] '--disableRetireJS' is deprecated and may be removed in the next major release, please migrate to '--disableRetireJs'
738:  [WARN] ossIndexPassword used on the command line, consider moving the password to a properties file using the key `analyzer.ossindex.password` and using the --propertyfile argument instead
739:  [INFO] Checking for updates
740:  [INFO] NVD API has 342,130 records in this update
741:  [WARN] NVD API request failures are occurring; retrying request for the 15th time
742:  [WARN] NVD API request failures are occurring; retrying request for the 16th time
743:  [WARN] NVD API request failures are occurring; retrying request for the 17th time
744:  [WARN] NVD API request failures are occurring; retrying request for the 18th time
745:  [WARN] NVD API request failures are occurring; retrying request for the 19th time
746:  [WARN] NVD API request failures are occurring; retrying request for the 20th time
747:  [WARN] NVD API request failures are occurring; retrying request for the 21st time
748:  [WARN] NVD API request failures are occurring; retrying request for the 22nd time
749:  [WARN] NVD API request failures are occurring; retrying request for the 23rd time
750:  [WARN] NVD API request failures are occurring; retrying request for the 24th time
751:  [WARN] NVD API request failures are occurring; retrying request for the 25th time
752:  [WARN] NVD API request failures are occurring; retrying request for the 26th time
753:  [WARN] NVD API request failures are occurring; retrying request for the 27th time
754:  [WARN] NVD API request failures are occurring; retrying request for the 28th time
755:  [WARN] NVD API request failures are occurring; retrying request for the 29th time
756:  [WARN] NVD API request failures are occurring; retrying request for the 30th time
757:  [WARN] NVD API request failures are occurring; retrying request for the 31st time
758:  [ERROR] Error updating the NVD Data
759:  org.owasp.dependencycheck.data.update.exception.UpdateException: Error updating the NVD Data
760:  at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:387)
...

762:  at org.owasp.dependencycheck.Engine.doUpdates(Engine.java:887)
763:  at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase(Engine.java:692)
764:  at org.owasp.dependencycheck.Engine.analyzeDependencies(Engine.java:619)
765:  at org.owasp.dependencycheck.App.runScan(App.java:265)
766:  at org.owasp.dependencycheck.App.run(App.java:197)
767:  at org.owasp.dependencycheck.App.main(App.java:88)
768:  Caused by: io.github.jeremylong.openvulnerability.client.nvd.NvdApiException: NVD Returned Status Code: 503
769:  at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient._next(NvdCveClient.java:445)
770:  at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient.next(NvdCveClient.java:356)
771:  at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:343)
772:  ... 7 common frames omitted
773:  [INFO] Updating CISA Known Exploited Vulnerability list: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
774:  [INFO] Begin database defrag
775:  [INFO] End database defrag (5671 ms)
776:  [WARN] Unable to update 1 or more Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities.
777:  [ERROR] Unable to continue dependency-check analysis.
778:  [ERROR] One or more fatal errors occurred
779:  [ERROR] Error updating the NVD Data
780:  [ERROR] No documents exist
781:  ##[error]Process completed with exit code 13.
782:  ##[group]Run actions/upload-artifact@v7

@JAVGan JAVGan merged commit bc730d4 into main Jun 22, 2026
19 of 21 checks passed
@JAVGan JAVGan deleted the dependabot/github_actions/actions/checkout-7 branch June 22, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant