This release includes 1 breaking change for platform teams planning a safe upgrade.
Published 6d
Version Control
✓ No known CVEs patched
✓ No known CVEs patched in this version
Summary
AI summaryBreaking change: allow-unsafe-pr-checkout flag is backported to v2.
Full changelog
What's Changed
- [BREAKING] backport
allow-unsafe-pr-checkoutto v2 by @aiqiaoy in https://github.com/actions/checkout/pull/2504 - backport fixes to releases-v2 by @aiqiaoy in https://github.com/actions/checkout/pull/2526
https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: https://github.com/actions/checkout/compare/v2.7.0...v2.8.0
Breaking Changes
- Removed implicit unsafe behavior for `pull_request_target` in GitHub Actions; `allow-unsafe-pr-checkout` flag must be explicitly enabled to restore previous functionality.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]