Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
< Back to tools
C

checkout

> 编程语言
Open source

Action for checking out a repo

8.6K stars0 likes0 views
WebsiteGitHub

About

Action for checking out a repo

Checkout v7

What's new

  • Safer fork pull request handling: checkout now refuses to check out fork pull request code by default when the workflow is triggered by pull_request_target or workflow_run. These triggers run with the base repository's GITHUB_TOKEN, secrets, and runner access, where executing a fork's code commonly leads to "pwn request" vulnerabilities.
    • To opt in after reviewing the risks, set the new allow-unsafe-pr-checkout: true input.
  • Migrated actions/checkout to ESM to support new versions of the @actions/* packages.
  • Updated direct and transitive dependencies, including security fixes for known vulnerabilities.

Checkout v6

What's new

  • Improved credential security: persist-credentials now stores credentials in a separate file under $RUNNER_TEMP instead of directly in .git/config
  • No workflow changes required — git fetch, git push, etc. continue to work automatically
  • Running authenticated git commands from a Docker container action requires Actions Runner v2.329.0 or later

Checkout v5

What's new

  • Updated to the node24 runtime
    • This requires a minimum Actions Runner version of v2.327.1 to run.

Checkout v4

This action checks-out your repository under $GITHUB_WORKSPACE, so your workflow can access it.

Only a single commit is fetched by default, for the ref/SHA that triggered the workflow. Set fetch-depth: 0 to fetch all history for all branches and tags. Refer here to learn which commit $GITHUB_SHA points to for different events.

The auth token is persisted in the local git config. This enables your scripts to run authenticated git commands. The token is removed during post-job cleanup. Set persist-credentials: false to opt-out.

When Git 2.18 or higher is not in your PATH, falls back to the REST API to download the files.

Note

Thank you for your interest in this GitHub action, however, right now we are not taking contributions.

We continue to focus our resources on strategic areas that help our customers be successful while making developers' lives easier. While GitHub Actions remains a key part of this vision, we are allocating resources towards other areas of Actions and are not taking contributions to this repository at this time. The GitHub public roadmap is the best place to follow along for any updates on features we’re working on and what stage they’re in.

We are taking the following steps to better direct requests related to GitHub Actions, including:

  1. We will be directing questions and support requests to our Community Discussions area

  2. High Priority bugs can be reported through Community Discussions or you can report these to our support team https://support.github.com/contact/bug-report.

  3. Security Issues should be handled as per our security.md

We will still provide security updates for this project and fix major breaking changes during this time.

You are welcome to still raise bugs in this repo.

What's new

Please refer to the release page for the latest release notes.

Usage

…

Scenarios

  • Checkout V5
    • What's new
  • Checkout V4
    • Note
  • What's new
  • Usage
  • Scenarios
    • Fetch only the root files
    • Fetch only the root files and .github and src folder
    • Fetch only a single file
    • Fetch all history for all tags and branches
    • Checkout a different branch
    • Checkout HEAD^
    • Checkout multiple repos (side by side)
    • Checkout multiple repos (nested)
    • Checkout multiple repos (private)
    • Checkout pull request HEAD commit instead of merge commit
    • Checkout pull request on closed event
    • Push a commit using the built-in token
    • Push a commit to a PR using the built-in token
  • Recommended permissions
  • License

Fetch only the root files

- uses: actions/checkout@v7
  with:
    sparse-checkout: .

Fetch only the root files and .github and src folder

- uses: actions/checkout@v7
  with:
    sparse-checkout: |
      .github
      src

Fetch only a single file

- uses: actions/checkout@v7
  with:
    sparse-checkout: |
      README.md
    sparse-checkout-cone-mode: false

Fetch all history for all tags and branches

- uses: actions/checkout@v7
  with:
    fetch-depth: 0

Checkout a different branch

- uses: actions/checkout@v7
  with:
    ref: my-branch

Checkout HEAD^

- uses: actions/checkout@v7
  with:
    fetch-depth: 2
- run: git checkout HEAD^

Checkout multiple repos (side by side)

- name: Checkout
  uses: actions/checkout@v7
  with:
    path: main

- name: Checkout tools repo
  uses: actions/checkout@v7
  with:
    repository: my-org/my-tools
    path: my-tools
  • If your secondary repository is private or internal you will need to add the option noted in Checkout multiple repos (private)

Checkout multiple repos (nested)

- name: Checkout
  uses: actions/checkout@v7

- name: Checkout tools repo
  uses: actions/checkout@v7
  with:
    repository: my-org/my-tools
    path: my-tools
  • If your secondary repository is private or internal you will need to add the option noted in Checkout multiple repos (private)

Checkout multiple repos (private)

- name: Checkout
  uses: actions/checkout@v7
  with:
    path: main

- name: Checkout private tools
  uses: actions/checkout@v7
  with:
    repository: my-org/my-private-tools
    token: ${{ secrets.GH_PAT }} # `GH_PAT` is a secret that contains your PAT
    path: my-tools
  • ${{ github.token }} is scoped to the current repository, so if you want to checkout a different repository that is private you will need to provide your own PAT.

Checkout pull request HEAD commit instead of merge commit

- uses: actions/checkout@v7
  with:
    ref: ${{ github.event.pull_request.head.sha }}

Checkout pull request on closed event

on:
  pull_request:
    branches: [main]
    types: [opened, synchronize, closed]
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7

Push a commit using the built-in token

on: push
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7
      - run: |
          date > generated.txt
          # Note: the following account information will not work on GHES
          git config user.name "github-actions[bot]"
          git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
          git add .
          git commit -m "generated"
          git push

NOTE: The user email is {user.id}+{user.login}@users.noreply.github.com. See users API: https://api.github.com/users/github-actions%5Bbot%5D

Push a commit to a PR using the built-in token

In a pull request trigger, ref is required as GitHub Actions checks out in detached HEAD mode, meaning it doesn’t check out your branch by default.

on: pull_request
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7
        with:
          ref: ${{ github.head_ref }}
      - run: |
          date > generated.txt
          # Note: the following account information will not work on GHES
          git config user.name "github-actions[bot]"
          git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
          git add .
          git commit -m "generated"
          git push

NOTE: The user email is {user.id}+{user.login}@users.noreply.github.com. See users API: https://api.github.com/users/github-actions%5Bbot%5D

Recommended permissions

When using the checkout action in your GitHub Actions workflow, it is recommended to set the following GITHUB_TOKEN permissions to ensure proper functionality, unless alternative auth is provided via the token or ssh-key inputs:

permissions:
  contents: read

License

The scripts and documentation in this project are released under the MIT License

GitHub Issues· 0 open

View all on GitHub

No open issues yet, or sync has not completed.

Highlights

  • •To opt in after reviewing the risks, set the new allow-unsafe-pr-checkout: true input.
  • •Migrated actions/checkout to ESM to support new versions of the @actions/* packages.
  • •Updated direct and transitive dependencies, including security fixes for known vulnerabilities.
  • •Improved credential security: persist-credentials now stores credentials in a separate file under $RUNNER_TEMP instead of directly in .git/config
  • •No workflow changes required — git fetch, git push, etc. continue to work automatically
  • •Running authenticated git commands from a Docker container action requires Actions Runner v2.329.0 or later
  • •Updated to the node24 runtime
  • •This requires a minimum Actions Runner version of v2.327.1 to run.
  • •Checkout V5
  • •What's new

> Tags

TypeScript

No comments yet. Be the first to share.

> Details

PublishedAug 1, 2026
UpdatedSep 17, 2026
Category编程语言
PricingOpen source

> Related tools

T
TypeScript
JavaScript 的超集,为前端与全栈提供静态类型
P
Python
通用编程语言,广泛用于 Web、数据与 AI
G
Go
Google 推出的简洁高效系统语言