[llvm] Update [Github] Update GHA Dependencies to v7 (PR #226858)
via llvm-commits
llvm-commits at lists.llvm.org
Sun Sep 27 17:24:18 PDT 2026
llvmorg-github-actions[bot] wrote:
<!--LLVM PR SUMMARY COMMENT-->
@llvm/pr-subscribers-libcxx
Author: Mend Renovate (renovate-bot)
<details>
<summary>Changes</summary>
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6.0.3` → `v7.0.1` |
| [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6.0.2` → `v7.0.1` |
| [actions/labeler](https://redirect.github.com/actions/labeler) | action | major | `v6.2.0` → `v7.0.0` |
| [actions/setup-node](https://redirect.github.com/actions/setup-node) | action | major | `v6.5.0` → `v7.0.0` |
| [actions/setup-python](https://redirect.github.com/actions/setup-python) | action | major | `v6.3.0` → `v7.0.0` |
---
### Release Notes
<details>
<summary>actions/checkout (actions/checkout)</summary>
### [`v7.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701)
[Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.1)
- Bump github/codeql-action from 3 to 4 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2475](https://redirect.github.com/actions/checkout/pull/2475)
- Bump actions/setup-node from 4 to 6 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2477](https://redirect.github.com/actions/checkout/pull/2477)
- Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2478](https://redirect.github.com/actions/checkout/pull/2478)
- Bump docker/login-action from 3.3.0 to 4.2.0 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2479](https://redirect.github.com/actions/checkout/pull/2479)
- Bump actions/checkout from 6 to 7 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2488](https://redirect.github.com/actions/checkout/pull/2488)
- Bump actions/upload-artifact from 4 to 7 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2476](https://redirect.github.com/actions/checkout/pull/2476)
- eslint 9 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2474](https://redirect.github.com/actions/checkout/pull/2474)
- Bump the minor-actions-dependencies group with 2 updates by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2499](https://redirect.github.com/actions/checkout/pull/2499)
- skip running unsafe pr check if input is default by [@&#<!-- -->8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in [#&#<!-- -->8203;2518](https://redirect.github.com/actions/checkout/pull/2518)
- trim only ascii whitespace for branch by [@&#<!-- -->8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in [#&#<!-- -->8203;2521](https://redirect.github.com/actions/checkout/pull/2521)
- escape values passed to --unset by [@&#<!-- -->8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in [#&#<!-- -->8203;2530](https://redirect.github.com/actions/checkout/pull/2530)
### [`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)
[Compare Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0)
- Block checking out fork PR for pull\_request\_target and workflow\_run by [@&#<!-- -->8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in [#&#<!-- -->8203;2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@&#<!-- -->8203;actions/core](https://redirect.github.com/actions/core) and [@&#<!-- -->8203;actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by [@&#<!-- -->8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in [#&#<!-- -->8203;2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@&#<!-- -->8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#<!-- -->8203;2462](https://redirect.github.com/actions/checkout/pull/2462)
### [`v6.1.0`](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0)
[Compare Source](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0)
</details>
<details>
<summary>actions/labeler (actions/labeler)</summary>
### [`v7.0.0`](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0)
[Compare Source](https://redirect.github.com/actions/labeler/compare/v6.2.0...v7.0.0)
</details>
<details>
<summary>actions/setup-node (actions/setup-node)</summary>
### [`v7.0.0`](https://redirect.github.com/actions/setup-node/releases/tag/v7.0.0)
[Compare Source](https://redirect.github.com/actions/setup-node/compare/v6.5.0...v7.0.0)
##### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@&#<!-- -->8203;gowridurgad](https://redirect.github.com/gowridurgad) in [#&#<!-- -->8203;1577](https://redirect.github.com/actions/setup-node/pull/1577)
- Migrate to ESM and upgrade dependencies by [@&#<!-- -->8203;gowridurgad](https://redirect.github.com/gowridurgad) in [#&#<!-- -->8203;1574](https://redirect.github.com/actions/setup-node/pull/1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@&#<!-- -->8203;gowridurgad](https://redirect.github.com/gowridurgad) in [#&#<!-- -->8203;1558](https://redirect.github.com/actions/setup-node/pull/1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@&#<!-- -->8203;deiga](https://redirect.github.com/deiga) in [#&#<!-- -->8203;1548](https://redirect.github.com/actions/setup-node/pull/1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@&#<!-- -->8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain) in [#&#<!-- -->8203;1536](https://redirect.github.com/actions/setup-node/pull/1536)
- docs: Update restore-only cache documentation by [@&#<!-- -->8203;priya-kinthali](https://redirect.github.com/priya-kinthali) in [#&#<!-- -->8203;1550](https://redirect.github.com/actions/setup-node/pull/1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@&#<!-- -->8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain) in [#&#<!-- -->8203;1567](https://redirect.github.com/actions/setup-node/pull/1567)
##### Dependency update:
- Upgrade [@&#<!-- -->8203;actions/cache](https://redirect.github.com/actions/cache) to 5.1.0, log cache write denied by [@&#<!-- -->8203;jasongin](https://redirect.github.com/jasongin) in [#&#<!-- -->8203;1569](https://redirect.github.com/actions/setup-node/pull/1569)
##### New Contributors
- [@&#<!-- -->8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain) made their first contribution in [#&#<!-- -->8203;1536](https://redirect.github.com/actions/setup-node/pull/1536)
- [@&#<!-- -->8203;deiga](https://redirect.github.com/deiga) made their first contribution in [#&#<!-- -->8203;1548](https://redirect.github.com/actions/setup-node/pull/1548)
- [@&#<!-- -->8203;jasongin](https://redirect.github.com/jasongin) made their first contribution in [#&#<!-- -->8203;1569](https://redirect.github.com/actions/setup-node/pull/1569)
**Full Changelog**: <https://github.com/actions/setup-node/compare/v6...v7.0.0>
</details>
<details>
<summary>actions/setup-python (actions/setup-python)</summary>
### [`v7.0.0`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)
[Compare Source](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 12:59 AM, only on Monday (`* 0 * * 1`)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/llvm/llvm-project).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
---
Patch is 44.53 KiB, truncated to 20.00 KiB below, full version: https://github.com/llvm/llvm-project/pull/226858.diff
53 Files Affected:
- (modified) .github/workflows/bazel-checks.yml (+2-2)
- (modified) .github/workflows/build-ci-container-tooling.yml (+2-2)
- (modified) .github/workflows/build-ci-container-windows.yml (+1-1)
- (modified) .github/workflows/build-ci-container.yml (+2-2)
- (modified) .github/workflows/build-libc-container.yml (+2-2)
- (modified) .github/workflows/build-metrics-container.yml (+2-2)
- (modified) .github/workflows/check-ci.yml (+2-2)
- (modified) .github/workflows/ci-post-commit-analyzer.yml (+1-1)
- (modified) .github/workflows/commit-access-review.yml (+1-1)
- (modified) .github/workflows/compiler-rt-libc-builtins-tests.yml (+1-1)
- (modified) .github/workflows/docs.yml (+2-2)
- (modified) .github/workflows/email-check.yaml (+1-1)
- (modified) .github/workflows/get-llvm-version/action.yml (+1-1)
- (modified) .github/workflows/gha-codeql.yml (+1-1)
- (modified) .github/workflows/hlsl-test-all.yaml (+4-4)
- (modified) .github/workflows/ids-check.yml (+1-1)
- (modified) .github/workflows/issue-release-workflow.yml (+1-1)
- (modified) .github/workflows/issue-write.yml (+1-1)
- (modified) .github/workflows/libc-freebsd-vm-tests.yml (+1-1)
- (modified) .github/workflows/libc-fullbuild-tests.yml (+1-1)
- (modified) .github/workflows/libc-overlay-tests.yml (+2-2)
- (modified) .github/workflows/libc-shared-tests.yml (+3-3)
- (modified) .github/workflows/libclang-abi-tests.yml (+1-1)
- (modified) .github/workflows/libcxx-benchmark-commit.yml (+3-3)
- (modified) .github/workflows/libcxx-benchmark-cron.yml (+4-4)
- (modified) .github/workflows/libcxx-build-containers.yml (+1-1)
- (modified) .github/workflows/libcxx-pr-benchmark.yml (+5-5)
- (modified) .github/workflows/libcxx-pr-check-generated-files.yml (+1-1)
- (modified) .github/workflows/libcxx-pr-conformance-tests.yaml (+5-5)
- (modified) .github/workflows/libcxx-pr-test-tools.yml (+1-1)
- (modified) .github/workflows/lldb-pylint-action.yml (+2-2)
- (modified) .github/workflows/llvm-abi-tests.yml (+1-1)
- (modified) .github/workflows/llvm-bugs.yml (+1-1)
- (modified) .github/workflows/mlir-spirv-tests.yml (+1-1)
- (modified) .github/workflows/new-prs.yml (+1-1)
- (modified) .github/workflows/pr-code-format.yml (+1-1)
- (modified) .github/workflows/pr-code-lint.yml (+1-1)
- (modified) .github/workflows/premerge.yaml (+5-5)
- (modified) .github/workflows/prune-branches.yml (+1-1)
- (modified) .github/workflows/release-asset-audit.yml (+1-1)
- (modified) .github/workflows/release-binaries.yml (+2-2)
- (modified) .github/workflows/release-documentation.yml (+3-3)
- (modified) .github/workflows/release-llvm-testing-tools.yml (+1-1)
- (modified) .github/workflows/release-sources.yml (+2-2)
- (modified) .github/workflows/release-tasks.yml (+3-3)
- (modified) .github/workflows/scorecard.yml (+1-1)
- (modified) .github/workflows/spirv-tests.yml (+1-1)
- (modified) .github/workflows/sycl-tests.yml (+1-1)
- (modified) .github/workflows/test-suite.yml (+3-3)
- (modified) .github/workflows/test-unprivileged-download-artifact.yml (+1-1)
- (modified) .github/workflows/upload-release-artifact/action.yml (+1-1)
- (modified) .github/workflows/version-check.yml (+1-1)
- (modified) .github/workflows/zizmor.yml (+1-1)
``````````diff
diff --git a/.github/workflows/bazel-checks.yml b/.github/workflows/bazel-checks.yml
index f2dd3ab35da9d..712db3cf7fffc 100644
--- a/.github/workflows/bazel-checks.yml
+++ b/.github/workflows/bazel-checks.yml
@@ -22,7 +22,7 @@ jobs:
if: github.repository == 'llvm/llvm-project'
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup Buildifier
@@ -53,7 +53,7 @@ jobs:
if: github.repository == 'llvm/llvm-project'
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# TODO(boomanaiden154): We should use a purpose built container for this. Move
diff --git a/.github/workflows/build-ci-container-tooling.yml b/.github/workflows/build-ci-container-tooling.yml
index f04711c53c69d..fa63056345c27 100644
--- a/.github/workflows/build-ci-container-tooling.yml
+++ b/.github/workflows/build-ci-container-tooling.yml
@@ -51,7 +51,7 @@ jobs:
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
@@ -80,7 +80,7 @@ jobs:
runs-on: ubuntu-26.04
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
diff --git a/.github/workflows/build-ci-container-windows.yml b/.github/workflows/build-ci-container-windows.yml
index d8d464ce98b30..5f9475c466169 100644
--- a/.github/workflows/build-ci-container-windows.yml
+++ b/.github/workflows/build-ci-container-windows.yml
@@ -25,7 +25,7 @@ jobs:
container-filename: ${{ steps.vars.outputs.container-filename }}
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: .github/workflows/containers/github-action-ci-windows
diff --git a/.github/workflows/build-ci-container.yml b/.github/workflows/build-ci-container.yml
index bb8b1503e5eda..9ff5b05279174 100644
--- a/.github/workflows/build-ci-container.yml
+++ b/.github/workflows/build-ci-container.yml
@@ -36,7 +36,7 @@ jobs:
- cd $HOME && printf '#include <iostream>\nint main(int argc, char **argv) { std::cout << "Hello\\n"; }' | clang++ -x c++ - && ./a.out | grep Hello
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
@@ -74,7 +74,7 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
diff --git a/.github/workflows/build-libc-container.yml b/.github/workflows/build-libc-container.yml
index 015d77b1b70eb..00c7fb30dd68a 100644
--- a/.github/workflows/build-libc-container.yml
+++ b/.github/workflows/build-libc-container.yml
@@ -27,7 +27,7 @@ jobs:
- ubuntu-26.04-arm
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
@@ -49,7 +49,7 @@ jobs:
runs-on: ubuntu-26.04
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
diff --git a/.github/workflows/build-metrics-container.yml b/.github/workflows/build-metrics-container.yml
index c2c70d616b28a..a2f5148aec3a6 100644
--- a/.github/workflows/build-metrics-container.yml
+++ b/.github/workflows/build-metrics-container.yml
@@ -23,7 +23,7 @@ jobs:
runs-on: ubuntu-26.04
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
@@ -47,7 +47,7 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
diff --git a/.github/workflows/check-ci.yml b/.github/workflows/check-ci.yml
index a4f0ab2e157e9..0fc81195762fb 100644
--- a/.github/workflows/check-ci.yml
+++ b/.github/workflows/check-ci.yml
@@ -22,12 +22,12 @@ jobs:
if: github.repository == 'llvm/llvm-project'
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: .ci
- name: Setup Python
- uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+ uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: 3.14
cache: 'pip'
diff --git a/.github/workflows/ci-post-commit-analyzer.yml b/.github/workflows/ci-post-commit-analyzer.yml
index fdbff0d6616b4..639ac4c65d1b1 100644
--- a/.github/workflows/ci-post-commit-analyzer.yml
+++ b/.github/workflows/ci-post-commit-analyzer.yml
@@ -41,7 +41,7 @@ jobs:
LLVM_VERSION: 18
steps:
- name: Checkout Source
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/commit-access-review.yml b/.github/workflows/commit-access-review.yml
index 16217536fdccd..0f3241acebe0c 100644
--- a/.github/workflows/commit-access-review.yml
+++ b/.github/workflows/commit-access-review.yml
@@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-26.04
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/compiler-rt-libc-builtins-tests.yml b/.github/workflows/compiler-rt-libc-builtins-tests.yml
index f5e1fdfb91c11..208a132330c14 100644
--- a/.github/workflows/compiler-rt-libc-builtins-tests.yml
+++ b/.github/workflows/compiler-rt-libc-builtins-tests.yml
@@ -28,7 +28,7 @@ jobs:
os: [ubuntu-26.04, ubuntu-26.04-arm]
steps:
- - uses: actions/checkout at de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml
index dc9f69f8b3c13..dd664988169b4 100644
--- a/.github/workflows/docs.yml
+++ b/.github/workflows/docs.yml
@@ -57,7 +57,7 @@ jobs:
if: github.repository == 'llvm/llvm-project'
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 2
@@ -100,7 +100,7 @@ jobs:
workflow:
- '.github/workflows/docs.yml'
- name: Setup Python env
- uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+ uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.14'
cache: 'pip'
diff --git a/.github/workflows/email-check.yaml b/.github/workflows/email-check.yaml
index f15daa39e41d2..80712c3fd4e7d 100644
--- a/.github/workflows/email-check.yaml
+++ b/.github/workflows/email-check.yaml
@@ -14,7 +14,7 @@ jobs:
if: github.repository == 'llvm/llvm-project'
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha }}
diff --git a/.github/workflows/get-llvm-version/action.yml b/.github/workflows/get-llvm-version/action.yml
index a1bda75bd3fd7..4ac4449ad392e 100644
--- a/.github/workflows/get-llvm-version/action.yml
+++ b/.github/workflows/get-llvm-version/action.yml
@@ -21,7 +21,7 @@ outputs:
runs:
using: "composite"
steps:
- - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
path: get-llvm-version
diff --git a/.github/workflows/gha-codeql.yml b/.github/workflows/gha-codeql.yml
index 9d0c0890fb85b..bde5ca511e8e4 100644
--- a/.github/workflows/gha-codeql.yml
+++ b/.github/workflows/gha-codeql.yml
@@ -24,7 +24,7 @@ jobs:
security-events: write
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
diff --git a/.github/workflows/hlsl-test-all.yaml b/.github/workflows/hlsl-test-all.yaml
index 03605497ab660..c1e278b085218 100644
--- a/.github/workflows/hlsl-test-all.yaml
+++ b/.github/workflows/hlsl-test-all.yaml
@@ -29,7 +29,7 @@ jobs:
runs-on: ${{ inputs.SKU }}
steps:
- name: Checkout DXC
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
repository: Microsoft/DirectXShaderCompiler
@@ -37,20 +37,20 @@ jobs:
path: DXC
submodules: true
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ inputs.LLVM-branch }}
path: llvm-project
- name: Checkout OffloadTest
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
repository: llvm/offload-test-suite
ref: main
path: OffloadTest
- name: Checkout Golden Images
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
repository: llvm/offload-golden-images
diff --git a/.github/workflows/ids-check.yml b/.github/workflows/ids-check.yml
index d713a1d89e48f..e39885251a576 100644
--- a/.github/workflows/ids-check.yml
+++ b/.github/workflows/ids-check.yml
@@ -24,7 +24,7 @@ jobs:
timeout-minutes: 20
steps:
- - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
path: ${{ github.workspace }}/llvm-project
diff --git a/.github/workflows/issue-release-workflow.yml b/.github/workflows/issue-release-workflow.yml
index b985b1b93e72c..510cff2baeac2 100644
--- a/.github/workflows/issue-release-workflow.yml
+++ b/.github/workflows/issue-release-workflow.yml
@@ -64,7 +64,7 @@ jobs:
pull-requests: write
steps:
- name: Fetch LLVM sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: llvm/llvm-project
# GitHub stores the token used for checkout and uses it for pushes
diff --git a/.github/workflows/issue-write.yml b/.github/workflows/issue-write.yml
index a9f62685fa08d..c17dce456508e 100644
--- a/.github/workflows/issue-write.yml
+++ b/.github/workflows/issue-write.yml
@@ -33,7 +33,7 @@ jobs:
github.repository == 'llvm/llvm-project'
steps:
- name: Fetch Sources
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
sparse-checkout: |
diff --git a/.github/workflows/libc-freebsd-vm-tests.yml b/.github/workflows/libc-freebsd-vm-tests.yml
index 187029e82aafc..06c03735c765e 100644
--- a/.github/workflows/libc-freebsd-vm-tests.yml
+++ b/.github/workflows/libc-freebsd-vm-tests.yml
@@ -15,7 +15,7 @@ jobs:
runs-on: ubuntu-26.04
steps:
- - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/libc-fullbuild-tests.yml b/.github/workflows/libc-fullbuild-tests.yml
index 7955a760c8dbb..6bec66da492d5 100644
--- a/.github/workflows/libc-fullbuild-tests.yml
+++ b/.github/workflows/libc-fullbuild-tests.yml
@@ -127,7 +127,7 @@ jobs:
# - c_compiler: gcc
# cpp_compiler: g++
steps:
- - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/libc-overlay-tests.yml b/.github/workflows/libc-overlay-tests.yml
index 51b1e7d9dc121..6f2804c5615e7 100644
--- a/.github/workflows/libc-overlay-tests.yml
+++ b/.github/workflows/libc-overlay-tests.yml
@@ -52,7 +52,7 @@ jobs:
cpp_compiler: clang++
steps:
- - uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ - uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
@@ -150,7 +150,7 @@ jobs:
mpc_path: riscv64-linux-gnu
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/libc-shared-tests.yml b/.github/workflows/libc-shared-tests.yml
index a7b3b0d5f1570..8345f537c3450 100644
--- a/.github/workflows/libc-shared-tests.yml
+++ b/.github/workflows/libc-shared-tests.yml
@@ -27,7 +27,7 @@ jobs:
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
@@ -74,7 +74,7 @@ jobs:
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
@@ -149,7 +149,7 @@ jobs:
steps:
- name: Checkout LLVM
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
diff --git a/.github/workflows/libclang-abi-tests.yml b/.github/workflows/libclang-abi-tests.yml
index 755db8a771dba..f054d8f5897b0 100644
--- a/.github/workflows/libclang-abi-tests.yml
+++ b/.github/workflows/libclang-abi-tests.yml
@@ -109,7 +109,7 @@ jobs:
*${{ matrix.ref }}.abi
- name: Download source code
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.cache.outputs.cache-hit != 'true'
with:
persist-credentials: false
diff --git a/.github/workflows/libcxx-benchmark-commit.yml b/.github/workflows/libcxx-benchmark-commit.yml
index 4c62087f2eede..4707431d38ce1 100644
--- a/.github/workflows/libcxx-benchmark-commit.yml
+++ b/.github/workflows/libcxx-benchmark-commit.yml
@@ -52,7 +52,7 @@ jobs:
matrix: ${{ steps.select.outputs.matrix }}
steps:
- name: Checkout the machine definitions
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# Disabling cone mode allows checking out exactly the single file we need.
@@ -112,7 +112,7 @@ jobs:
INSTALL_DIR: ${{ github.workspace }}/install
steps:
- name: Checkout the LLVM monorepo
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# We benchmark arbitrary historical commits, which requires the full history to be available.
@@ -121,7 +121,7 @@ jobs:
- name: Install Python
if: runner.os == 'Linux' # installed via Homebrew on macOS
- uses: actions/setup-python at ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
+ uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.14'
diff --git a/.github/workflows/libcxx-benchmark-cron.yml b/.github/workflows/libcxx-benchmark-cron.yml
index 5bad2531e3077..e9198db104f53 100644
--- a/.github/workflows/libcxx-benchmark-cron.yml
+++ b/.github/workflows/libcxx-benchmark-cron.yml
@@ -45,7 +45,7 @@ jobs:
matrix: ${{ steps.select.outputs.matrix }}
steps:
- name: Checkout the machine definitions
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# Disabling cone mode allows checking out exactly the single file we need.
@@ -110,7 +110,7 @@ jobs:
- name: Checkout the full LLVM monorepo
if: ${{ steps.restore-anchors.outputs.cache-hit != 'true' }}
- uses: actions/checkout at df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
+ uses: actions/checkout at 3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# Selecting anchor commits requires full Git history, but not the blob content.
@@ -119,13 +119,13 @@ jobs:
- name: Checkout sparse LLVM monorepo
if: ${{ steps.restore-anchors.outpu...
[truncated]
``````````
</details>
https://github.com/llvm/llvm-project/pull/226858
More information about the llvm-commits
mailing list