chore(deps): bump actions/checkout from 4 to 6#2
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
There was a problem hiding this comment.
Claude Code Review
This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.
Tip: disable this comment in your organization's Code Review settings.
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v6) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
fbfeef7 to
cab916c
Compare
cortexuvula
added a commit
that referenced
this pull request
Jun 20, 2026
…y, lock scoping) Addresses 9 findings from the codebase bug audit: Critical: - #1 Onboarding bypass: gate on a separate onboarding_started sentinel (written by the wizard on first save) instead of inferring from app_config row existence. An interrupted wizard now reappears on next launch instead of being silently auto-marked complete. Adds set_onboarding_started command + API wrapper. - #2 Ollama/LM Studio deadlock: current_base_url cloned the endpoint out of the read guard and dropped it before locking the url_cache, fixing the AB-BA lock-ordering inversion with set_endpoint. PHI leaks (AGENTS.md line 6): - #3 vocabulary.rs: drop find_text from the 'entry added' log. - #4 whisper_supervisor: allowlist stderr to known-safe diagnostic prefixes; drop arbitrary lines (whisper.cpp can emit recognized text). - #6 peer_discussion.rs: drop physician_name/specialty from the log. Security: - #5 Endpoint-policy: validate_local_endpoint at the top of every test/probe command (probe_endpoint_reachable, test_lmstudio_connection, test_stt_remote_connection, test_ollama_connection) so a crafted payload can't reach a public host. Robustness: - #7 start_with_gate: separate 'starting' guard so status()/watcher don't freeze during the multi-second gate; clean up the whisper child on any error path after it started; stop() clears starting too. - #8 start_sharing_inner: bind ports + start whisper BEFORE taking the sharing write lock; only hold the lock for the assignment; stop the service on any error after start. - #9 SSE malformed-event: propagate as a stream error instead of silent drop, so a truncated SOAP note surfaces visibly.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/checkout from 4 to 6.
Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)08c6903Prepare v5.0.0 release (#2238)