Skip to content

build(deps): bump actions/checkout from 6.0.2 to 6.0.3#330

Merged
seonghobae merged 2 commits into
developfrom
dependabot/github_actions/develop/actions/checkout-6.0.3
Jun 18, 2026
Merged

build(deps): bump actions/checkout from 6.0.2 to 6.0.3#330
seonghobae merged 2 commits into
developfrom
dependabot/github_actions/develop/actions/checkout-6.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 6.0.2 to 6.0.3.

Release notes

Sourced from actions/checkout's releases.

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 16, 2026
Copilot AI review requested due to automatic review settings June 16, 2026 17:24
@dependabot dependabot Bot requested a review from seonghobae as a code owner June 16, 2026 17:24
@dependabot @github

dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 16, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OpenCode Agent could not approve because GitHub Checks were still pending before approval.

  • Result: REQUEST_CHANGES
  • Reason: current-head GitHub Checks did not all complete before the bounded approval wait ended for 1d43f4b3400737100b58732770ab5b665652a8a0.
  • Head SHA: 1d43f4b3400737100b58732770ab5b665652a8a0
  • Workflow run: 27635732716
  • Workflow attempt: 1

Pending checks:

The OpenCode approval gate must be rerun after these checks complete so failed Strix or other check logs can be mapped to exact source lines before approval.

@opencode-agent

opencode-agent Bot commented Jun 16, 2026

Copy link
Copy Markdown

OpenCode Review Overview

  • Head SHA: be692dee003bb9b758a0fb6f0323297a7ddb343a
  • Workflow run: 27751354853
  • Workflow attempt: 1
  • Gate result: APPROVE (approval step)

Pull request overview

PR updates actions/checkout from v6.0.2 to v6.0.3. This is a patch version update containing only bug fixes and security improvements. The change maintains the same Node.js runtime version (Node 20) and has no breaking changes. The workflow functionality remains unchanged.

Findings

No blocking findings from OpenCode's independent review.

Verification

  • Review source: independent OpenCode review of the current checkout, focused changed hunks, and current-head GitHub Check evidence.
  • Structural exploration: completed before approval; if structural exploration, changed-file inspection, or evidence completeness is missing, OpenCode must not approve.
  • Result: APPROVE
  • Reason: Safe dependency update with no breaking changes

Gate evidence

  • Head SHA: be692dee003bb9b758a0fb6f0323297a7ddb343a
  • Workflow run: 27751354853
  • Workflow attempt: 1

@github-actions

Copy link
Copy Markdown
Contributor

@coderabbitai review

Scheduled PR review/merge pass found zero unresolved review threads, but this head is not approved yet (CHANGES_REQUESTED). Please review this current head so the normal merge gate can decide it.

@dependabot dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-6.0.3 branch 2 times, most recently from 5a3455b to 8351212 Compare June 18, 2026 00:18
Copilot AI review requested due to automatic review settings June 18, 2026 00:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@dependabot dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-6.0.3 branch from 8351212 to 5a64e73 Compare June 18, 2026 04:04

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode found current-head GitHub Check failures and could not approve until they are mapped to source-backed fixes.

Findings

Line-specific fallback findings:

No deterministic missing-string markers or Strix report locations were recognized. Use the failed-check evidence below to map each failed check to exact local source lines before approving.

Verification

  • Review source: independent OpenCode failed-check diagnosis using current-head check evidence.
  • Result: REQUEST_CHANGES
  • Reason: one or more GitHub Checks failed on current head 5a64e73a8e4cb10712cdd6c4b6bf0ec0d9628fdb.

Gate evidence

  • Head SHA: 5a64e73a8e4cb10712cdd6c4b6bf0ec0d9628fdb
  • Workflow run: 27735920182
  • Workflow attempt: 1

Failed checks:

Failed check evidence for line-specific fixes:

Failed GitHub Check Evidence

  • PR: #330
  • Head SHA: 5a64e73a8e4cb10712cdd6c4b6bf0ec0d9628fdb
  • Repository: Seongho-Bae/bandscope

Line-specific repair contract

  • Treat the check logs and annotations below as diagnostic evidence, not as a complete review.

  • For each actionable failed check, inspect the local source or diff and identify the exact file line that must change.

  • OpenCode REQUEST_CHANGES findings must include path, line, root_cause, fix_direction, regression_test_direction, and suggested_diff.

  • Do not request changes with only a GitHub Actions URL or a generic check name.

  • When Strix logs contain multiple Vulnerability Report or Model ... Vulnerabilities ... sections, include every model-reported vulnerability in the review evidence and findings, including model name, title, severity, endpoint, and Code Locations/path:line evidence when present.

  • Create one OpenCode finding per Strix model vulnerability report; do not satisfy two model reports with one combined finding, even when titles or locations match.

Failed check: security-audit/security-audit

Failed job steps

  • step 11: Install cargo-audit (failure)

Check annotations

  • .github:38-38 [failure] Process completed with exit code 101.

Failed log signal summary

security-audit	Install cargo-audit	2026-06-18T04:04:51.1234793Z ##[error]Process completed with exit code 101.

Failed log excerpt

security-audit	Install cargo-audit	2026-06-18T04:04:50.6961949Z ##[group]Run cargo +stable install cargo-audit --locked
security-audit	Install cargo-audit	2026-06-18T04:04:50.6962389Z ^[[36;1mcargo +stable install cargo-audit --locked^[[0m
security-audit	Install cargo-audit	2026-06-18T04:04:50.6994381Z shell: /usr/bin/bash -e {0}
security-audit	Install cargo-audit	2026-06-18T04:04:50.6994642Z env:
security-audit	Install cargo-audit	2026-06-18T04:04:50.6994834Z   GIT_CONFIG_COUNT: 1
security-audit	Install cargo-audit	2026-06-18T04:04:50.6995086Z   GIT_CONFIG_KEY_0: init.defaultBranch
security-audit	Install cargo-audit	2026-06-18T04:04:50.6995406Z   GIT_CONFIG_VALUE_0: develop
security-audit	Install cargo-audit	2026-06-18T04:04:50.6995731Z   pythonLocation: /opt/hostedtoolcache/Python/3.12.13/x64
security-audit	Install cargo-audit	2026-06-18T04:04:50.6996177Z   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.12.13/x64/lib/pkgconfig
security-audit	Install cargo-audit	2026-06-18T04:04:50.6996610Z   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.12.13/x64
security-audit	Install cargo-audit	2026-06-18T04:04:50.6996999Z   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.12.13/x64
security-audit	Install cargo-audit	2026-06-18T04:04:50.6997382Z   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.12.13/x64
security-audit	Install cargo-audit	2026-06-18T04:04:50.6997780Z   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.12.13/x64/lib
security-audit	Install cargo-audit	2026-06-18T04:04:50.6998180Z   UV_PYTHON_INSTALL_DIR: /home/runner/work/_temp/uv-python-dir
security-audit	Install cargo-audit	2026-06-18T04:04:50.6998535Z ##[endgroup]
security-audit	Install cargo-audit	2026-06-18T04:04:50.8143403Z     Updating crates.io index
security-audit	Install cargo-audit	2026-06-18T04:04:50.8817941Z  Downloading crates ...
security-audit	Install cargo-audit	2026-06-18T04:04:50.9200671Z   Downloaded cargo-audit v0.22.2
security-audit	Install cargo-audit	2026-06-18T04:04:50.9643132Z   Installing cargo-audit v0.22.2
security-audit	Install cargo-audit	2026-06-18T04:04:50.9727969Z     Updating crates.io index
security-audit	Install cargo-audit	2026-06-18T04:04:51.1180746Z error: failed to get `arc-swap` as a dependency of package `abscissa_core v0.9.0`
security-audit	Install cargo-audit	2026-06-18T04:04:51.1182036Z     ... which satisfies dependency `abscissa_core = "^0.9"` (locked to 0.9.0) of package `cargo-audit v0.22.2`
security-audit	Install cargo-audit	2026-06-18T04:04:51.1183005Z 
security-audit	Install cargo-audit	2026-06-18T04:04:51.1183265Z Caused by:
security-audit	Install cargo-audit	2026-06-18T04:04:51.1183836Z   failed to load source for dependency `arc-swap`
security-audit	Install cargo-audit	2026-06-18T04:04:51.1184221Z 
security-audit	Install cargo-audit	2026-06-18T04:04:51.1184352Z Caused by:
security-audit	Install cargo-audit	2026-06-18T04:04:51.1184742Z   unable to update registry `crates-io`
security-audit	Install cargo-audit	2026-06-18T04:04:51.1185088Z 
security-audit	Install cargo-audit	2026-06-18T04:04:51.1185225Z Caused by:
security-audit	Install cargo-audit	2026-06-18T04:04:51.1185591Z   download of ar/c-/arc-swap failed
security-audit	Install cargo-audit	2026-06-18T04:04:51.1185901Z 
security-audit	Install cargo-audit	2026-06-18T04:04:51.1186035Z Caused by:
security-audit	Install cargo-audit	2026-06-18T04:04:51.1186336Z   curl failed
security-audit	Install cargo-audit	2026-06-18T04:04:51.1186524Z 
security-audit	Install cargo-audit	2026-06-18T04:04:51.1186650Z Caused by:
security-audit	Install cargo-audit	2026-06-18T04:04:51.1187017Z   [18] Transferred a partial file
security-audit	Install cargo-audit	2026-06-18T04:04:51.1234793Z ##[error]Process completed with exit code 101.

@dependabot dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-6.0.3 branch from 5a64e73 to 235f4a2 Compare June 18, 2026 04:20
Copilot AI review requested due to automatic review settings June 18, 2026 04:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@dependabot dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-6.0.3 branch 2 times, most recently from 5355889 to abcfab1 Compare June 18, 2026 06:25
Copilot AI review requested due to automatic review settings June 18, 2026 06:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@dependabot dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-6.0.3 branch from abcfab1 to ee3a817 Compare June 18, 2026 07:41
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6.0.2...df4cb1c)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings June 18, 2026 08:58
@dependabot dependabot Bot force-pushed the dependabot/github_actions/develop/actions/checkout-6.0.3 branch from ee3a817 to 5124bd2 Compare June 18, 2026 08:58

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

PR updates actions/checkout from v6.0.2 to v6.0.3. This is a patch version update containing only bug fixes and security improvements. The change maintains the same Node.js runtime version (Node 20) and has no breaking changes. The workflow functionality remains unchanged.

Findings

No blocking findings from OpenCode's independent review.

Verification

  • Review source: independent OpenCode review of the current checkout, focused changed hunks, and current-head GitHub Check evidence.
  • Structural exploration: completed before approval; if structural exploration, changed-file inspection, or evidence completeness is missing, OpenCode must not approve.
  • Result: APPROVE
  • Reason: Safe dependency update with no breaking changes

Gate evidence

  • Head SHA: be692dee003bb9b758a0fb6f0323297a7ddb343a
  • Workflow run: 27751354853
  • Workflow attempt: 1

@seonghobae

Copy link
Copy Markdown
Collaborator

Merge gate evidence for current head be692dee003bb9b758a0fb6f0323297a7ddb343a:

  • OpenCode Review approved current head and explicitly recorded mandatory structural exploration as completed.
  • Required checks passed: CodeQL, ci / build-and-test, dependency-review, gate / build / macos, gate / build / windows, release-preflight, sbom, security-audit, trivy-fs-scan.
  • Cross-platform build-baseline passed for macOS amd64/arm64 and Windows amd64/arm64.
  • Review threads: 0 unresolved.
  • Manual diff review: limited to .github/workflows/opencode-review.yml, updating actions/checkout from SHA-pinned v6.0.2 to SHA-pinned v6.0.3. No permissions were expanded and no runtime app code, IPC, WebView, file handling, subprocess, model, export, or user-facing behavior path changed.

Supply-chain / Security Notes:

  • Third-party action remains commit-SHA pinned, matching docs/security/dependency-policy.md.
  • Dependency-review, SBOM, security-audit, CodeQL, Trivy, and Scorecard workflow checks all ran on the current head; ossf-scorecard and scorecard-sarif-upload passed.
  • Windows and macOS build gates remained required and passed, matching docs/security/cross-platform-build-policy.md.
  • The neutral Scorecard code-scanning check is the known GitHub code-scanning integration mismatch while the Scorecard workflow and SARIF upload passed; Scorecard code-scanning will be restored immediately after merge.

@seonghobae seonghobae merged commit f9a7b0b into develop Jun 18, 2026
25 checks passed
@seonghobae seonghobae deleted the dependabot/github_actions/develop/actions/checkout-6.0.3 branch June 18, 2026 10:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants