ci(deps): bump actions/checkout from 6 to 7 - #10
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
🤖 AI Surface Check37 production AI surfaces · 42 risk indicators · 2 high, 1 medium Detectors: mcp_audit, llm_sdks, agent_frameworks, env_keys, model_gateways, ai_infra, api_endpoints, vector_rag Diff against the base branch was unavailable; showing full inventory.
Production AI surfaces: 37 · Risk indicators: 42 Severity: 🟠 HIGH 2 · 🟡 MEDIUM 1 LLM SDK Call SitesAzure OpenAIFiles: Models: Risk indicators:
Anthropic SDKFiles: Models: Risk indicators:
OpenAI SDKFiles: Models: Risk indicators:
AWS BedrockFiles: Models: Risk indicators:
Agent FrameworksAWS Strands Agent: triage_agent (in examples/demo-app/src/support_workflow.py)Files: Tools/permissions: Validate at runtime: Coming soon: agent validation in APIsec → 🟠 HIGH LangChain Agent: support_agent (in examples/demo-app/src/chat_agent.py)Files: Tools/permissions: Risk indicators:
Audit risk flags:
Validate at runtime: Coming soon: agent validation in APIsec → Claude Tools: detect (in src/ai_surface/detectors/agent_frameworks.py)Files: Tools/permissions: Validate at runtime: Coming soon: agent validation in APIsec → LangChain (used in 1 file)Files: Validate at runtime: Coming soon: agent validation in APIsec → MCP Servers🟡 MEDIUM MCP Server (in-house): fixtures/generate_demo.pyFiles: Risk indicators:
Audit risk flags:
Trust: unknown Validate at runtime: Coming soon: MCP runtime validation in APIsec → 🟠 HIGH MCP Server (in-house): examples/demo-app/src/orders_mcp_server.pyFiles: Tools/permissions: Risk indicators:
Audit risk flags:
Trust: unknown Validate at runtime: Coming soon: MCP runtime validation in APIsec → Model GatewaysModel Gateway: LiteLLMFiles: Tools/permissions: Risk indicators:
Model Gateway: HeliconeFiles: Risk indicators:
Model Gateway: PortkeyFiles: Risk indicators:
Model Gateway: OpenRouterFiles: Risk indicators:
Model Gateway: Cloudflare AI GatewayFiles: Risk indicators:
AI InfrastructureAI Workload (Helm): vllm (in tests/fixtures/ai_infra/helm_vllm/values.yaml)Files: Risk indicators:
K8s AI Workload: ollama (in tests/fixtures/ai_infra/k8s_ollama/deployment.yaml)Files: Risk indicators:
AI Workload (compose): ollama (in tests/fixtures/ai_infra/compose_ollama/docker-compose.yml)Files: Risk indicators:
K8s AI Workload: vllm (in examples/demo-app/deploy/vllm-embeddings.yaml)Files: Risk indicators:
Bedrock provisioned throughput: anthropic.claude-3-5-sonnet-20240620-v1:0Files: Risk indicators:
Bedrock provisioned throughput: anthropic.claude-sonnet-4-20250514-v1:0Files: Risk indicators:
AI Workload (Dockerfile): vllm (in tests/fixtures/ai_infra/dockerfile_serve/Dockerfile)Files: Risk indicators:
AI Workload (Dockerfile): vllm (in tests/fixtures/ai_infra/dockerfile_vllm/Dockerfile)Files: Risk indicators:
AI Provider API Keys (env)AI Provider API KeysFiles: Risk indicators:
API EndpointsREST API: GET ...Endpoint: Framework: Files: Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: POST ...Endpoint: Framework: Files: Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: GET /pathEndpoint: Framework: Files: Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: POST /pathEndpoint: Framework: Files: Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: * /route/Endpoint: Framework: Files: Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: GET /healthEndpoint: Framework: Files: Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: GET /orders/{order_id}Endpoint: Framework: Files: Risk indicators:
Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: GET /customers/{customer_id}Endpoint: Framework: Files: Risk indicators:
Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → REST API: PATCH /customers/{customer_id}Endpoint: Framework: Files: Risk indicators:
Validate at runtime: Onboard this API for outside-in runtime testing in APIsec → Vector StoreVector store: pgvectorFiles: Risk indicators:
Vector store: Elasticsearch (vector)Files: Risk indicators:
Vector store: MarqoFiles: Risk indicators:
RAG pipeline: LangChainFiles: Risk indicators:
Risk Indicator Summary
Validate which of these surfaces are exploitable in a running application: apisec.ai/products Validate at runtime in APIsecRuntime validation routes available from this scan: Powered by ai-surface. To validate which of these surfaces are exploitable in a running application: apisec.ai/products. |
Bumps actions/checkout from 6 to 7.
Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
9c091bbupdate error wording (#2467)1044a6dgetting ready for checkout v7 release (#2464)f028218Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26upgrade module to esm and update dependencies (#2463)537c7efBump@actions/coreand@actions/tool-cacheand Remove uuid (#2459)130a169Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aaBump actions/publish-immutable-action (#2458)f9e715ablock checking out fork pr for pull_request_target and workflow_run (#2454)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)