Skip to content

chore(ci): bump actions/checkout from 4 to 6#4

Merged
wcatz merged 1 commit intomainfrom
dependabot/github_actions/actions/checkout-6
Mar 15, 2026
Merged

chore(ci): bump actions/checkout from 4 to 6#4
wcatz merged 1 commit intomainfrom
dependabot/github_actions/actions/checkout-6

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 14, 2026

Bumps actions/checkout from 4 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.1

What's Changed

Full Changelog: actions/checkout@v4...v4.3.1

v4.3.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 14, 2026
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-6 branch from 740a27b to 392a834 Compare March 15, 2026 02:26
@wcatz wcatz merged commit 5d5fa7d into main Mar 15, 2026
2 checks passed
@wcatz wcatz deleted the dependabot/github_actions/actions/checkout-6 branch March 15, 2026 02:26
wcatz added a commit that referenced this pull request Mar 15, 2026
CodeQL cannot trace through safeJoin as a sanitizer. Since all
filenames are hardcoded constants and the base path is validated
(EvalSymlinks + Stat + IsDir), use filepath.Join directly with
nosec annotations. Clears alerts #4-#6.
wcatz added a commit that referenced this pull request Mar 15, 2026
* feat(approval): deny with instructions + fix CodeQL path injection

- Auto-scroll only when user is near bottom of chat (no more yanking
  back while reading earlier messages during streaming)
- Auto-approve toggle: muted when OFF, red glow when ON (YOLO mode)
- Fix 3 HIGH CodeQL go/path-injection findings in project/context.go:
  validate resolved path is existing directory before file operations

* fix(security): inline path joins for CodeQL go/path-injection

CodeQL cannot trace through safeJoin as a sanitizer. Since all
filenames are hardcoded constants and the base path is validated
(EvalSymlinks + Stat + IsDir), use filepath.Join directly with
nosec annotations. Clears alerts #4-#6.
wcatz added a commit that referenced this pull request Mar 16, 2026
…ad, reminder text

Bug #2: Briefing used CalDAV instead of Google Calendar. Added Google
provider to briefing.Sources, prefer Google over CalDAV, add Gmail
unread count + recent emails to morning briefing.

Bug #3: Telegram /chat discarded Claude's response. Now parses SSE
stream, collects text events, and sends the full response back to the
user with mdv2.Split for long messages.

Bug #4: Cron jobs lost on restart. Added reloadJobs() in Start() that
reads scheduled_jobs from SQLite on startup.

Bug #5: Reminder message included time expression. Now strips the
parsed time portion using olebedev/when Result.Index and Result.Text,
keeping only the actual reminder content.
wcatz added a commit that referenced this pull request Mar 16, 2026
…ad, reminder text (#60)

Bug #2: Briefing used CalDAV instead of Google Calendar. Added Google
provider to briefing.Sources, prefer Google over CalDAV, add Gmail
unread count + recent emails to morning briefing.

Bug #3: Telegram /chat discarded Claude's response. Now parses SSE
stream, collects text events, and sends the full response back to the
user with mdv2.Split for long messages.

Bug #4: Cron jobs lost on restart. Added reloadJobs() in Start() that
reads scheduled_jobs from SQLite on startup.

Bug #5: Reminder message included time expression. Now strips the
parsed time portion using olebedev/when Result.Index and Result.Text,
keeping only the actual reminder content.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant