Skip to content

chore(deps): bump actions/checkout from 4 to 6#2

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/checkout-6
Open

chore(deps): bump actions/checkout from 4 to 6#2
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/checkout-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 15, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.1

What's Changed

Full Changelog: actions/checkout@v4...v4.3.1

v4.3.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 15, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-6 branch from fbfeef7 to cab916c Compare May 27, 2026 02:45
cortexuvula added a commit that referenced this pull request Jun 16, 2026
…a256, SSE logging, fsync, identifier validation)

Addresses CODE_REVIEW_REPORT.md findings #1, #2, #3, #4/#11, #6, #9.
Verified each against the actual code; skipped #5/#7/#8/#10/#12-15 with
documented rationale (low threat model, intentional design, YAGNI).
cortexuvula added a commit that referenced this pull request Jun 20, 2026
…y, lock scoping)

Addresses 9 findings from the codebase bug audit:

Critical:
- #1 Onboarding bypass: gate on a separate onboarding_started sentinel
  (written by the wizard on first save) instead of inferring from
  app_config row existence. An interrupted wizard now reappears on next
  launch instead of being silently auto-marked complete. Adds
  set_onboarding_started command + API wrapper.
- #2 Ollama/LM Studio deadlock: current_base_url cloned the endpoint out
  of the read guard and dropped it before locking the url_cache, fixing
  the AB-BA lock-ordering inversion with set_endpoint.

PHI leaks (AGENTS.md line 6):
- #3 vocabulary.rs: drop find_text from the 'entry added' log.
- #4 whisper_supervisor: allowlist stderr to known-safe diagnostic
  prefixes; drop arbitrary lines (whisper.cpp can emit recognized text).
- #6 peer_discussion.rs: drop physician_name/specialty from the log.

Security:
- #5 Endpoint-policy: validate_local_endpoint at the top of every
  test/probe command (probe_endpoint_reachable, test_lmstudio_connection,
  test_stt_remote_connection, test_ollama_connection) so a crafted
  payload can't reach a public host.

Robustness:
- #7 start_with_gate: separate 'starting' guard so status()/watcher
  don't freeze during the multi-second gate; clean up the whisper child
  on any error path after it started; stop() clears starting too.
- #8 start_sharing_inner: bind ports + start whisper BEFORE taking the
  sharing write lock; only hold the lock for the assignment; stop the
  service on any error after start.
- #9 SSE malformed-event: propagate as a stream error instead of silent
  drop, so a truncated SOAP note surfaces visibly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants