From b503606b9d942dd2ec69bde6795b6fc8a9101cee Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 19:41:58 +0000 Subject: [PATCH 1/2] build(deps): bump actions/checkout in /actions/setup-environment Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- actions/setup-environment/action.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/actions/setup-environment/action.yml b/actions/setup-environment/action.yml index 339d728..2c80952 100644 --- a/actions/setup-environment/action.yml +++ b/actions/setup-environment/action.yml @@ -43,7 +43,7 @@ runs: egress-policy: audit - name: Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false ref: ${{ inputs.ref }} From 321030dcbf9eb453da9feaebddaf0a3c448dc4f4 Mon Sep 17 00:00:00 2001 From: MattIPv4 Date: Wed, 1 Jul 2026 22:27:07 +0100 Subject: [PATCH 2/2] Remove pull_request_target unsafe checkout ref --- actions/setup-environment/action.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/actions/setup-environment/action.yml b/actions/setup-environment/action.yml index 2c80952..765851e 100644 --- a/actions/setup-environment/action.yml +++ b/actions/setup-environment/action.yml @@ -12,7 +12,7 @@ inputs: ref: description: "The ref to checkout" required: false - default: ${{ github.event_name == 'pull_request_target' && github.event.pull_request.head.sha || github.ref }} + default: ${{ github.ref }} fetch-depth: description: "The fetch depth" required: false