Tool Open source

actions/checkout

actions/checkout is a GitHub Actions action that checks a repository out into the workflow’s `$GITHUB_WORKSPACE` directory for use by subsequent steps. It can select a repository and ref, perform shallow or complete-history fetches, sparse or partial checkouts, and fetch submodules, Git LFS files, tags, and authenticated content. By default, it fetches only the commit for the event’s triggering ref or SHA; `fetch-depth: 0` retrieves all branches and tags. Authentication can use a token or SSH key configured in the local Git configuration and removed during post-job cleanup; recent releases store persisted credentials in a separate file under `$RUNNER_TEMP`. If Git 2.18 or newer is unavailable, the action falls back to the GitHub REST API to download files.

View repository Mentioned in 1 video ↓

Overview

Checkout v7 migrates the action to ESM, updates direct and transitive dependencies, and refuses fork pull-request code by default for workflows triggered by `pull_request_target` or `workflow_run`, which have access to the base repository’s token, secrets, and runner. Reviewed exceptions can opt in with `allow-unsafe-pr-checkout: true`.

What actions/checkout is used for

1 use taken from transcripts — each links to the moment in the video.

  • A GitHub Actions step that checks a repository out into a workflow workspace for later steps to use. It supports options including full, sparse, and partial history, submodules, Git LFS, multiple repositories, and credential cleanup.

Videos mentioning actions/checkout

1 in the library.