From e89b36d02f58c7155bca00c3849bede60581321b Mon Sep 17 00:00:00 2001 From: Craig McChesney Date: Wed, 30 Sep 2026 16:34:06 -0600 Subject: [PATCH] ci: upgrade actions/checkout from v3.7.0 to v7.0.1 in release.yml (#94) The step has no with: block, and the v4-v7 majors change only the runtime and internals (Node 20/24, credential file location, ESM, fork-PR restriction on pull_request_target/workflow_run), none of which this tag-push/dispatch workflow touches. v3.7.0 runs on Node 16, which is past deprecation. SHA resolved from the tag ref and verified to carry both v7.0.1 and v7; it matches the pin already used in dp-grpc, dp-service, dp-desktop-app and dp-python-lib. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_012nsCzraPATf4LCKVyUStfd --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 40e198a..4c05bd4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -42,7 +42,7 @@ jobs: # downloads the release JARs of three sibling repos and publishes the tarball users # install from, so a compromised upstream tag here could alter what ships. See the # convention in CLAUDE.md. Dependabot (.github/dependabot.yml) keeps the pins current. - uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # On a tag push the version comes from the tag. On a manual dispatch GITHUB_REF_NAME is # the branch, not a tag, so the version has to be supplied as an input -- it selects