[llvm] Update [Github] Update GHA Dependencies to v7 (PR #226858)

Mend Renovate via llvm-commits llvm-commits at lists.llvm.org
Sun Sep 27 17:23:29 PDT 2026


https://github.com/renovate-bot created https://github.com/llvm/llvm-project/pull/226858

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6.0.3` → `v7.0.1` |
| [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6.0.2` → `v7.0.1` |
| [actions/labeler](https://redirect.github.com/actions/labeler) | action | major | `v6.2.0` → `v7.0.0` |
| [actions/setup-node](https://redirect.github.com/actions/setup-node) | action | major | `v6.5.0` → `v7.0.0` |
| [actions/setup-python](https://redirect.github.com/actions/setup-python) | action | major | `v6.3.0` → `v7.0.0` |

---

### Release Notes

<details>
<summary>actions/checkout (actions/checkout)</summary>

### [`v7.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701)

[Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.1)

- Bump github/codeql-action from 3 to 4 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2475](https://redirect.github.com/actions/checkout/pull/2475)
- Bump actions/setup-node from 4 to 6 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2477](https://redirect.github.com/actions/checkout/pull/2477)
- Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2478](https://redirect.github.com/actions/checkout/pull/2478)
- Bump docker/login-action from 3.3.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2479](https://redirect.github.com/actions/checkout/pull/2479)
- Bump actions/checkout from 6 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2488](https://redirect.github.com/actions/checkout/pull/2488)
- Bump actions/upload-artifact from 4 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2476](https://redirect.github.com/actions/checkout/pull/2476)
- eslint 9 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2474](https://redirect.github.com/actions/checkout/pull/2474)
- Bump the minor-actions-dependencies group with 2 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2499](https://redirect.github.com/actions/checkout/pull/2499)
- skip running unsafe pr check if input is default by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2518](https://redirect.github.com/actions/checkout/pull/2518)
- trim only ascii whitespace for branch by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2521](https://redirect.github.com/actions/checkout/pull/2521)
- escape values passed to --unset by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2530](https://redirect.github.com/actions/checkout/pull/2530)

### [`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@​actions/core](https://redirect.github.com/actions/core) and [@​actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2462](https://redirect.github.com/actions/checkout/pull/2462)

### [`v6.1.0`](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0)

[Compare Source](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0)

</details>

<details>
<summary>actions/labeler (actions/labeler)</summary>

### [`v7.0.0`](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0)

[Compare Source](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0)

</details>

<details>
<summary>actions/setup-node (actions/setup-node)</summary>

### [`v7.0.0`](https://redirect.github.com/actions/setup-node/releases/tag/v7.0.0)

[Compare Source](https://redirect.github.com/actions/setup-node/compare/v6.5.0...v7.0.0)

##### What's Changed

##### Enhancements:

- Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://redirect.github.com/gowridurgad) in [#​1577](https://redirect.github.com/actions/setup-node/pull/1577)
- Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://redirect.github.com/gowridurgad) in [#​1574](https://redirect.github.com/actions/setup-node/pull/1574)

##### Bug fixes:

- Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://redirect.github.com/gowridurgad) in [#​1558](https://redirect.github.com/actions/setup-node/pull/1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://redirect.github.com/deiga) in [#​1548](https://redirect.github.com/actions/setup-node/pull/1548)

##### Documentation updates:

- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://redirect.github.com/chiranjib-swain) in [#​1536](https://redirect.github.com/actions/setup-node/pull/1536)
- docs: Update restore-only cache documentation by [@​priya-kinthali](https://redirect.github.com/priya-kinthali) in [#​1550](https://redirect.github.com/actions/setup-node/pull/1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://redirect.github.com/chiranjib-swain) in [#​1567](https://redirect.github.com/actions/setup-node/pull/1567)

##### Dependency update:

- Upgrade [@​actions/cache](https://redirect.github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://redirect.github.com/jasongin) in [#​1569](https://redirect.github.com/actions/setup-node/pull/1569)

##### New Contributors

- [@​chiranjib-swain](https://redirect.github.com/chiranjib-swain) made their first contribution in [#​1536](https://redirect.github.com/actions/setup-node/pull/1536)
- [@​deiga](https://redirect.github.com/deiga) made their first contribution in [#​1548](https://redirect.github.com/actions/setup-node/pull/1548)
- [@​jasongin](https://redirect.github.com/jasongin) made their first contribution in [#​1569](https://redirect.github.com/actions/setup-node/pull/1569)

**Full Changelog**: <https://github.com/actions/setup-node/compare/v6...v7.0.0>

</details>

<details>
<summary>actions/setup-python (actions/setup-python)</summary>

### [`v7.0.0`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)

[Compare Source](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Between 12:00 AM and 12:59 AM, only on Monday (`* 0 * * 1`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/llvm/llvm-project).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->


>From 0b6fa87b8fe9cb21206bbd069960045a6a5de058 Mon Sep 17 00:00:00 2001
From: Mend Renovate <bot at renovateapp.com>
Date: Mon, 28 Sep 2026 00:23:11 +0000
Subject: [PATCH] Update [Github] Update GHA Dependencies to v7

---
 .github/workflows/bazel-checks.yml                     |  4 ++--
 .github/workflows/build-ci-container-tooling.yml       |  4 ++--
 .github/workflows/build-ci-container-windows.yml       |  2 +-
 .github/workflows/build-ci-container.yml               |  4 ++--
 .github/workflows/build-libc-container.yml             |  4 ++--
 .github/workflows/build-metrics-container.yml          |  4 ++--
 .github/workflows/check-ci.yml                         |  4 ++--
 .github/workflows/ci-post-commit-analyzer.yml          |  2 +-
 .github/workflows/commit-access-review.yml             |  2 +-
 .github/workflows/compiler-rt-libc-builtins-tests.yml  |  2 +-
 .github/workflows/docs.yml                             |  4 ++--
 .github/workflows/email-check.yaml                     |  2 +-
 .github/workflows/get-llvm-version/action.yml          |  2 +-
 .github/workflows/gha-codeql.yml                       |  2 +-
 .github/workflows/hlsl-test-all.yaml                   |  8 ++++----
 .github/workflows/ids-check.yml                        |  2 +-
 .github/workflows/issue-release-workflow.yml           |  2 +-
 .github/workflows/issue-write.yml                      |  2 +-
 .github/workflows/libc-freebsd-vm-tests.yml            |  2 +-
 .github/workflows/libc-fullbuild-tests.yml             |  2 +-
 .github/workflows/libc-overlay-tests.yml               |  4 ++--
 .github/workflows/libc-shared-tests.yml                |  6 +++---
 .github/workflows/libclang-abi-tests.yml               |  2 +-
 .github/workflows/libcxx-benchmark-commit.yml          |  6 +++---
 .github/workflows/libcxx-benchmark-cron.yml            |  8 ++++----
 .github/workflows/libcxx-build-containers.yml          |  2 +-
 .github/workflows/libcxx-pr-benchmark.yml              | 10 +++++-----
 .github/workflows/libcxx-pr-check-generated-files.yml  |  2 +-
 .github/workflows/libcxx-pr-conformance-tests.yaml     | 10 +++++-----
 .github/workflows/libcxx-pr-test-tools.yml             |  2 +-
 .github/workflows/lldb-pylint-action.yml               |  4 ++--
 .github/workflows/llvm-abi-tests.yml                   |  2 +-
 .github/workflows/llvm-bugs.yml                        |  2 +-
 .github/workflows/mlir-spirv-tests.yml                 |  2 +-
 .github/workflows/new-prs.yml                          |  2 +-
 .github/workflows/pr-code-format.yml                   |  2 +-
 .github/workflows/pr-code-lint.yml                     |  2 +-
 .github/workflows/premerge.yaml                        | 10 +++++-----
 .github/workflows/prune-branches.yml                   |  2 +-
 .github/workflows/release-asset-audit.yml              |  2 +-
 .github/workflows/release-binaries.yml                 |  4 ++--
 .github/workflows/release-documentation.yml            |  6 +++---
 .github/workflows/release-llvm-testing-tools.yml       |  2 +-
 .github/workflows/release-sources.yml                  |  4 ++--
 .github/workflows/release-tasks.yml                    |  6 +++---
 .github/workflows/scorecard.yml                        |  2 +-
 .github/workflows/spirv-tests.yml                      |  2 +-
 .github/workflows/sycl-tests.yml                       |  2 +-
 .github/workflows/test-suite.yml                       |  6 +++---
 .../workflows/test-unprivileged-download-artifact.yml  |  2 +-
 .github/workflows/upload-release-artifact/action.yml   |  2 +-
 .github/workflows/version-check.yml                    |  2 +-
 .github/workflows/zizmor.yml                           |  2 +-
 53 files changed, 92 insertions(+), 92 deletions(-)

diff --git a/.github/workflows/bazel-checks.yml b/.github/workflows/bazel-checks.yml
index f2dd3ab35da9d..712db3cf7fffc 100644
--- a/.github/workflows/bazel-checks.yml
+++ b/.github/workflows/bazel-checks.yml
@@ -22,7 +22,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Setup Buildifier
@@ -53,7 +53,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
         # TODO(boomanaiden154): We should use a purpose built container for this. Move
diff --git a/.github/workflows/build-ci-container-tooling.yml b/.github/workflows/build-ci-container-tooling.yml
index f04711c53c69d..fa63056345c27 100644
--- a/.github/workflows/build-ci-container-tooling.yml
+++ b/.github/workflows/build-ci-container-tooling.yml
@@ -51,7 +51,7 @@ jobs:
 
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -80,7 +80,7 @@ jobs:
     runs-on: ubuntu-26.04
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/build-ci-container-windows.yml b/.github/workflows/build-ci-container-windows.yml
index d8d464ce98b30..5f9475c466169 100644
--- a/.github/workflows/build-ci-container-windows.yml
+++ b/.github/workflows/build-ci-container-windows.yml
@@ -25,7 +25,7 @@ jobs:
       container-filename: ${{ steps.vars.outputs.container-filename }}
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: .github/workflows/containers/github-action-ci-windows
diff --git a/.github/workflows/build-ci-container.yml b/.github/workflows/build-ci-container.yml
index bb8b1503e5eda..9ff5b05279174 100644
--- a/.github/workflows/build-ci-container.yml
+++ b/.github/workflows/build-ci-container.yml
@@ -36,7 +36,7 @@ jobs:
           - cd $HOME && printf '#include <iostream>\nint main(int argc, char **argv) { std::cout << "Hello\\n"; }' | clang++ -x c++ - && ./a.out | grep Hello
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -74,7 +74,7 @@ jobs:
       GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/build-libc-container.yml b/.github/workflows/build-libc-container.yml
index 015d77b1b70eb..00c7fb30dd68a 100644
--- a/.github/workflows/build-libc-container.yml
+++ b/.github/workflows/build-libc-container.yml
@@ -27,7 +27,7 @@ jobs:
           - ubuntu-26.04-arm
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -49,7 +49,7 @@ jobs:
     runs-on: ubuntu-26.04
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/build-metrics-container.yml b/.github/workflows/build-metrics-container.yml
index c2c70d616b28a..a2f5148aec3a6 100644
--- a/.github/workflows/build-metrics-container.yml
+++ b/.github/workflows/build-metrics-container.yml
@@ -23,7 +23,7 @@ jobs:
     runs-on: ubuntu-26.04
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -47,7 +47,7 @@ jobs:
       GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/check-ci.yml b/.github/workflows/check-ci.yml
index a4f0ab2e157e9..0fc81195762fb 100644
--- a/.github/workflows/check-ci.yml
+++ b/.github/workflows/check-ci.yml
@@ -22,12 +22,12 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: .ci
       - name: Setup Python
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           python-version: 3.14
           cache: 'pip'
diff --git a/.github/workflows/ci-post-commit-analyzer.yml b/.github/workflows/ci-post-commit-analyzer.yml
index fdbff0d6616b4..639ac4c65d1b1 100644
--- a/.github/workflows/ci-post-commit-analyzer.yml
+++ b/.github/workflows/ci-post-commit-analyzer.yml
@@ -41,7 +41,7 @@ jobs:
       LLVM_VERSION: 18
     steps:
       - name: Checkout Source
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
diff --git a/.github/workflows/commit-access-review.yml b/.github/workflows/commit-access-review.yml
index 16217536fdccd..0f3241acebe0c 100644
--- a/.github/workflows/commit-access-review.yml
+++ b/.github/workflows/commit-access-review.yml
@@ -17,7 +17,7 @@ jobs:
     runs-on: ubuntu-26.04
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       
diff --git a/.github/workflows/compiler-rt-libc-builtins-tests.yml b/.github/workflows/compiler-rt-libc-builtins-tests.yml
index f5e1fdfb91c11..208a132330c14 100644
--- a/.github/workflows/compiler-rt-libc-builtins-tests.yml
+++ b/.github/workflows/compiler-rt-libc-builtins-tests.yml
@@ -28,7 +28,7 @@ jobs:
         os: [ubuntu-26.04, ubuntu-26.04-arm]
 
     steps:
-      - uses: actions/checkout at de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml
index dc9f69f8b3c13..dd664988169b4 100644
--- a/.github/workflows/docs.yml
+++ b/.github/workflows/docs.yml
@@ -57,7 +57,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
@@ -100,7 +100,7 @@ jobs:
             workflow:
               - '.github/workflows/docs.yml'
       - name: Setup Python env
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           python-version: '3.14'
           cache: 'pip'
diff --git a/.github/workflows/email-check.yaml b/.github/workflows/email-check.yaml
index f15daa39e41d2..80712c3fd4e7d 100644
--- a/.github/workflows/email-check.yaml
+++ b/.github/workflows/email-check.yaml
@@ -14,7 +14,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           ref: ${{ github.event.pull_request.head.sha }}
diff --git a/.github/workflows/get-llvm-version/action.yml b/.github/workflows/get-llvm-version/action.yml
index a1bda75bd3fd7..4ac4449ad392e 100644
--- a/.github/workflows/get-llvm-version/action.yml
+++ b/.github/workflows/get-llvm-version/action.yml
@@ -21,7 +21,7 @@ outputs:
 runs:
   using: "composite"
   steps:
-    - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+    - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       with:
         persist-credentials: false
         path: get-llvm-version
diff --git a/.github/workflows/gha-codeql.yml b/.github/workflows/gha-codeql.yml
index 9d0c0890fb85b..bde5ca511e8e4 100644
--- a/.github/workflows/gha-codeql.yml
+++ b/.github/workflows/gha-codeql.yml
@@ -24,7 +24,7 @@ jobs:
       security-events: write
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/hlsl-test-all.yaml b/.github/workflows/hlsl-test-all.yaml
index 03605497ab660..c1e278b085218 100644
--- a/.github/workflows/hlsl-test-all.yaml
+++ b/.github/workflows/hlsl-test-all.yaml
@@ -29,7 +29,7 @@ jobs:
     runs-on: ${{ inputs.SKU }}
     steps:
       - name: Checkout DXC
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           repository: Microsoft/DirectXShaderCompiler
@@ -37,20 +37,20 @@ jobs:
           path: DXC
           submodules: true
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           ref: ${{ inputs.LLVM-branch }}
           path: llvm-project
       - name: Checkout OffloadTest
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           repository: llvm/offload-test-suite
           ref: main
           path: OffloadTest
       - name: Checkout Golden Images
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           repository: llvm/offload-golden-images
diff --git a/.github/workflows/ids-check.yml b/.github/workflows/ids-check.yml
index d713a1d89e48f..e39885251a576 100644
--- a/.github/workflows/ids-check.yml
+++ b/.github/workflows/ids-check.yml
@@ -24,7 +24,7 @@ jobs:
     timeout-minutes: 20
 
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           path: ${{ github.workspace }}/llvm-project
diff --git a/.github/workflows/issue-release-workflow.yml b/.github/workflows/issue-release-workflow.yml
index b985b1b93e72c..510cff2baeac2 100644
--- a/.github/workflows/issue-release-workflow.yml
+++ b/.github/workflows/issue-release-workflow.yml
@@ -64,7 +64,7 @@ jobs:
       pull-requests: write
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           repository: llvm/llvm-project
           # GitHub stores the token used for checkout and uses it for pushes
diff --git a/.github/workflows/issue-write.yml b/.github/workflows/issue-write.yml
index a9f62685fa08d..c17dce456508e 100644
--- a/.github/workflows/issue-write.yml
+++ b/.github/workflows/issue-write.yml
@@ -33,7 +33,7 @@ jobs:
       github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch Sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/libc-freebsd-vm-tests.yml b/.github/workflows/libc-freebsd-vm-tests.yml
index 187029e82aafc..06c03735c765e 100644
--- a/.github/workflows/libc-freebsd-vm-tests.yml
+++ b/.github/workflows/libc-freebsd-vm-tests.yml
@@ -15,7 +15,7 @@ jobs:
     runs-on: ubuntu-26.04
     
     steps:
-    - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+    - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       with:
         persist-credentials: false
     
diff --git a/.github/workflows/libc-fullbuild-tests.yml b/.github/workflows/libc-fullbuild-tests.yml
index 7955a760c8dbb..6bec66da492d5 100644
--- a/.github/workflows/libc-fullbuild-tests.yml
+++ b/.github/workflows/libc-fullbuild-tests.yml
@@ -127,7 +127,7 @@ jobs:
           # - c_compiler: gcc
           #   cpp_compiler: g++
     steps:
-    - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+    - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       with:
         persist-credentials: false
 
diff --git a/.github/workflows/libc-overlay-tests.yml b/.github/workflows/libc-overlay-tests.yml
index 51b1e7d9dc121..6f2804c5615e7 100644
--- a/.github/workflows/libc-overlay-tests.yml
+++ b/.github/workflows/libc-overlay-tests.yml
@@ -52,7 +52,7 @@ jobs:
               cpp_compiler: clang++
     
     steps:
-    - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+    - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       with:
         persist-credentials: false
     
@@ -150,7 +150,7 @@ jobs:
             mpc_path: riscv64-linux-gnu
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
diff --git a/.github/workflows/libc-shared-tests.yml b/.github/workflows/libc-shared-tests.yml
index a7b3b0d5f1570..8345f537c3450 100644
--- a/.github/workflows/libc-shared-tests.yml
+++ b/.github/workflows/libc-shared-tests.yml
@@ -27,7 +27,7 @@ jobs:
 
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
@@ -74,7 +74,7 @@ jobs:
 
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
@@ -149,7 +149,7 @@ jobs:
 
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
diff --git a/.github/workflows/libclang-abi-tests.yml b/.github/workflows/libclang-abi-tests.yml
index 755db8a771dba..f054d8f5897b0 100644
--- a/.github/workflows/libclang-abi-tests.yml
+++ b/.github/workflows/libclang-abi-tests.yml
@@ -109,7 +109,7 @@ jobs:
             *${{ matrix.ref }}.abi
 
       - name: Download source code
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         if: steps.cache.outputs.cache-hit != 'true'
         with:
           persist-credentials: false
diff --git a/.github/workflows/libcxx-benchmark-commit.yml b/.github/workflows/libcxx-benchmark-commit.yml
index 4c62087f2eede..4707431d38ce1 100644
--- a/.github/workflows/libcxx-benchmark-commit.yml
+++ b/.github/workflows/libcxx-benchmark-commit.yml
@@ -52,7 +52,7 @@ jobs:
       matrix: ${{ steps.select.outputs.matrix }}
     steps:
       - name: Checkout the machine definitions
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           # Disabling cone mode allows checking out exactly the single file we need.
@@ -112,7 +112,7 @@ jobs:
       INSTALL_DIR: ${{ github.workspace }}/install
     steps:
       - name: Checkout the LLVM monorepo
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           # We benchmark arbitrary historical commits, which requires the full history to be available.
@@ -121,7 +121,7 @@ jobs:
 
       - name: Install Python
         if: runner.os == 'Linux' # installed via Homebrew on macOS
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           python-version: '3.14'
 
diff --git a/.github/workflows/libcxx-benchmark-cron.yml b/.github/workflows/libcxx-benchmark-cron.yml
index 5bad2531e3077..e9198db104f53 100644
--- a/.github/workflows/libcxx-benchmark-cron.yml
+++ b/.github/workflows/libcxx-benchmark-cron.yml
@@ -45,7 +45,7 @@ jobs:
       matrix: ${{ steps.select.outputs.matrix }}
     steps:
       - name: Checkout the machine definitions
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           # Disabling cone mode allows checking out exactly the single file we need.
@@ -110,7 +110,7 @@ jobs:
 
       - name: Checkout the full LLVM monorepo
         if: ${{ steps.restore-anchors.outputs.cache-hit != 'true' }}
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           # Selecting anchor commits requires full Git history, but not the blob content.
@@ -119,13 +119,13 @@ jobs:
 
       - name: Checkout sparse LLVM monorepo
         if: ${{ steps.restore-anchors.outputs.cache-hit == 'true' }}
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: libcxx/utils # Only checkout what the tools need
 
       - name: Install Python
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           python-version: '3.14'
           cache: pip
diff --git a/.github/workflows/libcxx-build-containers.yml b/.github/workflows/libcxx-build-containers.yml
index 5f24cc54021ad..aaeb02b47c28d 100644
--- a/.github/workflows/libcxx-build-containers.yml
+++ b/.github/workflows/libcxx-build-containers.yml
@@ -33,7 +33,7 @@ jobs:
       packages: write
 
     steps:
-    - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+    - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       with:
         persist-credentials: false
 
diff --git a/.github/workflows/libcxx-pr-benchmark.yml b/.github/workflows/libcxx-pr-benchmark.yml
index e5de26cc1f0f2..e481217e7d6e4 100644
--- a/.github/workflows/libcxx-pr-benchmark.yml
+++ b/.github/workflows/libcxx-pr-benchmark.yml
@@ -28,7 +28,7 @@ jobs:
       name: main-branch-only
       deployment: false
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -49,7 +49,7 @@ jobs:
       pull-requests: write
     steps:
       - name: Checkout the LNT configurations
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           # Disabling cone mode allows checking out exactly the single file we need.
@@ -121,7 +121,7 @@ jobs:
       TOOLING: ${{ github.workspace }}/tooling
     steps:
       - name: Checkout the PR
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           ref: ${{ needs.extract-info.outputs.pr_head }}
@@ -132,7 +132,7 @@ jobs:
       # commit so that we're always running tooling that's in sync with the workflow's definition. Only the
       # code and the test suite (including its testing configuration) are taken from the PR head.
       - name: Checkout the tooling from ${{ github.sha }}
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           ref: ${{ github.sha }}
@@ -143,7 +143,7 @@ jobs:
 
       - name: Install Python
         if: runner.os == 'Linux' # installed via Homebrew on macOS
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           python-version: '3.14'
 
diff --git a/.github/workflows/libcxx-pr-check-generated-files.yml b/.github/workflows/libcxx-pr-check-generated-files.yml
index b7f0da7eb67f5..1fb1a44f7eb3f 100644
--- a/.github/workflows/libcxx-pr-check-generated-files.yml
+++ b/.github/workflows/libcxx-pr-check-generated-files.yml
@@ -18,7 +18,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
diff --git a/.github/workflows/libcxx-pr-conformance-tests.yaml b/.github/workflows/libcxx-pr-conformance-tests.yaml
index 61e455e1a799d..191a4920244a1 100644
--- a/.github/workflows/libcxx-pr-conformance-tests.yaml
+++ b/.github/workflows/libcxx-pr-conformance-tests.yaml
@@ -57,7 +57,7 @@ jobs:
             cc: 'gcc-16'
             cxx: 'g++-16'
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: ${{ matrix.config }}.${{ matrix.cxx }}
@@ -112,7 +112,7 @@ jobs:
             cc: 'clang-21'
             cxx: 'clang++-21'
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: ${{ matrix.config }}
@@ -177,7 +177,7 @@ jobs:
           'bootstrapping-build'
         ]
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: ${{ matrix.config }}
@@ -232,7 +232,7 @@ jobs:
           xcode-version: '26.6'
     runs-on: ["self-hosted", "macOS", "apple-runners", "26.6.2"] # macOS 26.6.2, which has Xcode 26.6
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Select Xcode
@@ -280,7 +280,7 @@ jobs:
         - { config: mingw-static,             mingw: true,  cc: cc,       cxx: c++, runner: windows-11-arm }
     runs-on: ${{ matrix.runner != '' && matrix.runner || 'windows-2022' }}
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Install dependencies
diff --git a/.github/workflows/libcxx-pr-test-tools.yml b/.github/workflows/libcxx-pr-test-tools.yml
index 64bbc705e5e09..f07bd977dfe23 100644
--- a/.github/workflows/libcxx-pr-test-tools.yml
+++ b/.github/workflows/libcxx-pr-test-tools.yml
@@ -36,7 +36,7 @@ jobs:
       CC: clang-23
       CXX: clang++-23
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 0 # some tools need full git history
diff --git a/.github/workflows/lldb-pylint-action.yml b/.github/workflows/lldb-pylint-action.yml
index b4347107ca54c..d3907b6f010ba 100644
--- a/.github/workflows/lldb-pylint-action.yml
+++ b/.github/workflows/lldb-pylint-action.yml
@@ -19,13 +19,13 @@ jobs:
       cancel-in-progress: true
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
 
       - name: Setup python
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           python-version: '3.14'
 
diff --git a/.github/workflows/llvm-abi-tests.yml b/.github/workflows/llvm-abi-tests.yml
index 74b6b18dee306..cd8e879897c3b 100644
--- a/.github/workflows/llvm-abi-tests.yml
+++ b/.github/workflows/llvm-abi-tests.yml
@@ -98,7 +98,7 @@ jobs:
             llvm.symbols
 
       - name: Download source code
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         if: steps.cache.outputs.cache-hit != 'true'
         with:
           persist-credentials: false
diff --git a/.github/workflows/llvm-bugs.yml b/.github/workflows/llvm-bugs.yml
index 13ec49e49856c..5fb8c9ebc21a9 100644
--- a/.github/workflows/llvm-bugs.yml
+++ b/.github/workflows/llvm-bugs.yml
@@ -14,7 +14,7 @@ jobs:
     runs-on: ubuntu-26.04
     if: github.repository == 'llvm/llvm-project'
     steps:
-      - uses: actions/setup-node at 249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
+      - uses: actions/setup-node at 820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
         with:
           node-version: 24
           check-latest: true
diff --git a/.github/workflows/mlir-spirv-tests.yml b/.github/workflows/mlir-spirv-tests.yml
index 14dfbe892b06f..b3d275d7bf305 100644
--- a/.github/workflows/mlir-spirv-tests.yml
+++ b/.github/workflows/mlir-spirv-tests.yml
@@ -28,7 +28,7 @@ jobs:
     container:
       image: ghcr.io/llvm/ci-ubuntu-26.04:latest at sha256:7ac659feb90ac48dd8676e4eb305b9aa5b31fc8b329b7e39379c38af06efc6e1
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Setup ccache
diff --git a/.github/workflows/new-prs.yml b/.github/workflows/new-prs.yml
index 20348f26b1038..ba02343bfc2d0 100644
--- a/.github/workflows/new-prs.yml
+++ b/.github/workflows/new-prs.yml
@@ -74,7 +74,7 @@ jobs:
           repositories: ${{ github.repository }}
           permission-contents: read
           permission-pull-requests: write
-      - uses: actions/labeler at b8dd2d9be0f68b860e7dae5dae7d772984eacd6d # v6.2.0
+      - uses: actions/labeler at bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13 # v7.0.0
         with:
           configuration-path: .github/new-prs-labeler.yml
           repo-token: ${{ steps.app-token.outputs.token }}
diff --git a/.github/workflows/pr-code-format.yml b/.github/workflows/pr-code-format.yml
index 88720720c3d57..e53358c21606d 100644
--- a/.github/workflows/pr-code-format.yml
+++ b/.github/workflows/pr-code-format.yml
@@ -21,7 +21,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
diff --git a/.github/workflows/pr-code-lint.yml b/.github/workflows/pr-code-lint.yml
index 16b6d40489467..6fd3cfd3d10df 100644
--- a/.github/workflows/pr-code-lint.yml
+++ b/.github/workflows/pr-code-lint.yml
@@ -28,7 +28,7 @@ jobs:
       cancel-in-progress: true
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
diff --git a/.github/workflows/premerge.yaml b/.github/workflows/premerge.yaml
index c6d604533f1f6..d6f7ae545071c 100644
--- a/.github/workflows/premerge.yaml
+++ b/.github/workflows/premerge.yaml
@@ -37,7 +37,7 @@ jobs:
         shell: bash
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
@@ -113,7 +113,7 @@ jobs:
         shell: bash
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
@@ -201,14 +201,14 @@ jobs:
       # back to a git diff, which needs real history.
       - name: Checkout LLVM (sparse)
         if: github.event_name == 'pull_request'
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: .ci
           sparse-checkout-cone-mode: false
       - name: Checkout LLVM
         if: github.event_name != 'pull_request'
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
@@ -252,7 +252,7 @@ jobs:
         needs.premerge-compute-macos.outputs.macos-projects != ''
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 2
diff --git a/.github/workflows/prune-branches.yml b/.github/workflows/prune-branches.yml
index 5c46f1350bd1d..2df833e0c3cd3 100644
--- a/.github/workflows/prune-branches.yml
+++ b/.github/workflows/prune-branches.yml
@@ -20,7 +20,7 @@ jobs:
       contents: write
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: true # Relies on persisted credentials to delete unused remote branches
           fetch-depth: 0
diff --git a/.github/workflows/release-asset-audit.yml b/.github/workflows/release-asset-audit.yml
index b60974e3dd97f..37769a8a5fe6a 100644
--- a/.github/workflows/release-asset-audit.yml
+++ b/.github/workflows/release-asset-audit.yml
@@ -23,7 +23,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index 759dea944a0fb..1844da1ba90e6 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -224,7 +224,7 @@ jobs:
     # to do that we need to specify a specific python version.  It's also
     # good practice to do this on other OSes so the version of python doesn't
     # get changed unexpectedly.
-    - uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+    - uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
       with:
         python-version: '3.14.6'
 
@@ -240,7 +240,7 @@ jobs:
         git config --global core.autocrlf false
 
     - name: Checkout LLVM
-      uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       with:
         persist-credentials: false
         ref: ${{ needs.prepare.outputs.ref }}
diff --git a/.github/workflows/release-documentation.yml b/.github/workflows/release-documentation.yml
index 0e86ec0ca5355..c278907055d41 100644
--- a/.github/workflows/release-documentation.yml
+++ b/.github/workflows/release-documentation.yml
@@ -75,7 +75,7 @@ jobs:
       doxygen-artifact-id: ${{ steps.doxygen-artifact-upload.outputs.artifact-id }}
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
@@ -86,7 +86,7 @@ jobs:
           release-version: ${{ inputs.release-version }}
 
       - name: Setup Python env
-        uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+        uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
         with:
           cache: 'pip'
           cache-dependency-path: './llvm/docs/requirements.txt'
@@ -163,7 +163,7 @@ jobs:
       contents: read
     steps:
       - name: Clone www-releases
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           repository: ${{ github.repository_owner }}/www-releases
           ref: main
diff --git a/.github/workflows/release-llvm-testing-tools.yml b/.github/workflows/release-llvm-testing-tools.yml
index 1fb413566e139..af5e1f2bca6ea 100644
--- a/.github/workflows/release-llvm-testing-tools.yml
+++ b/.github/workflows/release-llvm-testing-tools.yml
@@ -19,7 +19,7 @@ jobs:
     if: github.repository == 'llvm/llvm-project'
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Build Binaries
diff --git a/.github/workflows/release-sources.yml b/.github/workflows/release-sources.yml
index aa8aa433964d3..28aa36cb392cb 100644
--- a/.github/workflows/release-sources.yml
+++ b/.github/workflows/release-sources.yml
@@ -53,7 +53,7 @@ jobs:
       export-args: ${{ steps.inputs.outputs.export-args }}
     runs-on: ubuntu-26.04
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -88,7 +88,7 @@ jobs:
       - inputs
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           ref: ${{ needs.inputs.outputs.ref }}
diff --git a/.github/workflows/release-tasks.yml b/.github/workflows/release-tasks.yml
index 76b94add1cbdf..bebce9618711b 100644
--- a/.github/workflows/release-tasks.yml
+++ b/.github/workflows/release-tasks.yml
@@ -41,7 +41,7 @@ jobs:
           sudo apt-get install python3-github
 
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
@@ -91,7 +91,7 @@ jobs:
     environment: pypi
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           ref: "llvmorg-${{ needs.validate-tag.outputs.release-version }}"
@@ -184,7 +184,7 @@ jobs:
           sudo apt-get install python3-github
 
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: llvm/utils/release/github-upload-release.py
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index c5e53e7f8b9e5..6a4ae0b02c27d 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -31,7 +31,7 @@ jobs:
 
     steps:
       - name: "Checkout code"
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 
diff --git a/.github/workflows/spirv-tests.yml b/.github/workflows/spirv-tests.yml
index 7a32576b725c4..34a4267eaf039 100644
--- a/.github/workflows/spirv-tests.yml
+++ b/.github/workflows/spirv-tests.yml
@@ -24,7 +24,7 @@ jobs:
     container:
       image: ghcr.io/llvm/ci-ubuntu-26.04:latest at sha256:7ac659feb90ac48dd8676e4eb305b9aa5b31fc8b329b7e39379c38af06efc6e1
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Setup ccache
diff --git a/.github/workflows/sycl-tests.yml b/.github/workflows/sycl-tests.yml
index 60b8ae4c538a1..1c29be7186b64 100644
--- a/.github/workflows/sycl-tests.yml
+++ b/.github/workflows/sycl-tests.yml
@@ -23,7 +23,7 @@ jobs:
     container:
       image: ghcr.io/llvm/ci-ubuntu-26.04:latest at sha256:7ac659feb90ac48dd8676e4eb305b9aa5b31fc8b329b7e39379c38af06efc6e1
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
       - name: Setup ccache
diff --git a/.github/workflows/test-suite.yml b/.github/workflows/test-suite.yml
index 7cafb4f5f9916..b018a36a3d43a 100644
--- a/.github/workflows/test-suite.yml
+++ b/.github/workflows/test-suite.yml
@@ -21,7 +21,7 @@ jobs:
       name: main-branch-only
       deployment: false
     steps:
-      - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+      - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
@@ -82,7 +82,7 @@ jobs:
           EOF
           exit 1
       - name: Checkout pull request
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           ref: ${{ fromJSON(steps.get-pr.outputs.result).merge_commit_sha }}
           # test merge commits are stored in the base repository, not the head
@@ -91,7 +91,7 @@ jobs:
           path: llvm-project
           persist-credentials: false
       - name: Checkout llvm/llvm-test-suite
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           repository: llvm/llvm-test-suite
           path: llvm-test-suite
diff --git a/.github/workflows/test-unprivileged-download-artifact.yml b/.github/workflows/test-unprivileged-download-artifact.yml
index 7da0b8363a093..a45a7e450a5d7 100644
--- a/.github/workflows/test-unprivileged-download-artifact.yml
+++ b/.github/workflows/test-unprivileged-download-artifact.yml
@@ -46,7 +46,7 @@ jobs:
     needs: [ upload-test-artifact ]
     steps:
       - name: Checkout LLVM
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           sparse-checkout: |
diff --git a/.github/workflows/upload-release-artifact/action.yml b/.github/workflows/upload-release-artifact/action.yml
index dc15de78cc114..30385a393203b 100644
--- a/.github/workflows/upload-release-artifact/action.yml
+++ b/.github/workflows/upload-release-artifact/action.yml
@@ -103,7 +103,7 @@ runs:
           *.jsonl
     
     # Checkout the files used by this action.
-    - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+    - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
       if: inputs.upload == 'true'
       with:
         persist-credentials: false
diff --git a/.github/workflows/version-check.yml b/.github/workflows/version-check.yml
index 6508b30ac10d8..12233b4efe60c 100644
--- a/.github/workflows/version-check.yml
+++ b/.github/workflows/version-check.yml
@@ -17,7 +17,7 @@ jobs:
     runs-on: ubuntu-26.04
     steps:
       - name: Fetch LLVM sources
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
           fetch-depth: 0
diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml
index 22ab25c2110b9..b5a9a6a60b235 100644
--- a/.github/workflows/zizmor.yml
+++ b/.github/workflows/zizmor.yml
@@ -21,7 +21,7 @@ jobs:
       actions: read
     steps:
       - name: Checkout repository
-        uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+        uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
         with:
           persist-credentials: false
 



More information about the llvm-commits mailing list