Skip to content

Pin dependencies - #290

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github-actions
Closed

Pin dependencies#290
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Nov 18, 2025

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
SonarSource/ci-github-actions action pin v11.8.9
SonarSource/gh-action_pre-commit action minor 1.1.01.2.1
SonarSource/gh-action_releasability action pin v33.3.0
actions/checkout action pin v7v7.0.1
jdx/mise uses-with minor 2026.6.12026.8.14 v2026.8.15
jdx/mise uses-with minor 2025.7.122025.12.13
jdx/mise-action action minor v4.1.0v4.3.0
jdx/mise-action action minor v4.2.0v4.3.0

Add the preset :preserveSemverRanges to your config if you don't want to pin your dependencies.


Release Notes

SonarSource/gh-action_pre-commit (SonarSource/gh-action_pre-commit)

v1.2.1

Compare Source

What's Changed

Dependency Updates
Package Update Change
actions/setup-python minor v6.1.0v6.3.0 (#​45)
nick-fields/assert-action pin v4v4.0.1 (#​45)
actions/cache major v5.0.1v6.1.0 (#​46)
actions/checkout major v6.0.1v7.0.0 (#​46)
nick-fields/assert-action major v2.0.0v4.0.1 (#​46)
nick-fields/assert-action major v2v4 (#​46)
Internal & Chores
  • Added GitHub workflows (PullRequestClosed, PullRequestCreated, RequestReview, SubmitReview) to automate Jira status updates on PR review events, using SonarSource/vault-action-wrapper for credential retrieval (#​49, BUILD-11517)

Full Changelog: SonarSource/gh-action_pre-commit@1.2.0...1.2.1

v1.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: SonarSource/gh-action_pre-commit@1.1.0...1.2.0

jdx/mise (jdx/mise)

v2026.8.14: : npm/aube install fixes and cleaner temp/prune handling

Compare Source

This is a small release focused on bug fixes for npm (aube-backed) installs, HTTP cache cleanup, and Windows config pruning.

Fixed
  • npm: Aube-backed npm installs no longer drop a synthetic .npmrc into the per-tool install directory. Install-scoped settings such as minimumReleaseAge, trustPolicyExclude, allowedUnpopularPackages, and (for CLI installs) globalDir/globalBinDir now go into .config/aube/config.toml as typed TOML, while allowBuilds stays in package.json. Inline-table trust_policy_excludes / allow_low_downloads in mise.toml still round-trip correctly. (#​12425 by @​jdx)
  • npm: mise now intercepts the private __node-gyp-bootstrap trampoline that embedded aube's lazy node-gyp shim re-execs. Previously naked-run rewriting turned it into mise run __node-gyp-bootstrap … and failed with "no tasks defined", breaking allow_builds installs whose lifecycle scripts call node-gyp (for example gemini-cli via node-pty). (#​12429 by @​jdx)
  • http: A failed extraction (truncated download, unreadable archive, full disk, or Ctrl-C mid-extraction) no longer leaves a permanent hash-named temp directory behind in http-tarballs. All failure paths now clean up the temp directory. (#​12420 by @​Marukome0743)
  • prune: mise prune --configs on Windows now removes trusted config links whose target no longer exists. Because Windows stores these links as plain files holding the target path, the previous existence check never fired; the link's target is now resolved before deciding whether to prune. (#​12418 by @​JamBalaya56562)

Full Changelog: jdx/mise@v2026.8.13...v2026.8.14

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.13: : Task exclusions, visible conf.d fragments, and a broad round of fixes

Compare Source

This release adds a few configuration and task features and delivers a large batch of fixes across completions, tools, lockfiles, tasks, config parsing, and shell integration. It also restores dynamic shell completions that regressed after the recent CLI parser change.

Added
  • task: New task_config.excludes lets file-task discovery skip config-root-relative paths, directories, and glob patterns, so accidental TOML files (like a pyproject.toml inside a task directory) or entire subtrees are no longer treated as tasks. The closest config that sets excludes replaces inherited values, and an empty list clears the cascade. Relative task.disable_paths now resolve from the declaring config file. (#​12366 by @​jdx)

    [task_config]
    excludes = ["scripts/vendor", "**/*.generated.toml"]
  • config: Project configuration can now be split into visible mise/conf.d/*.toml fragments, mirroring the existing .mise/conf.d and .config/mise/conf.d support but without a hidden dot-directory. Fragments merge alphabetically, mise/config.toml still wins over fragments, and environment-specific and .local variants (for example mise/conf.d/tools.development.toml) follow the usual env config rules. (#​12395 by @​jdx)

  • bootstrap: Added --skip-dirty to mise bootstrap, mise bootstrap repos apply, and mise bootstrap repos update to warn and skip repos with local changes so the remaining repos still update. Origin mismatches and non-git targets still fail closed as before. (#​12364 by @​jdx)

Fixed
  • completion: Restored dynamic shell completions that broke after the switch to usage-rs. Task names, task-specific flags, task value choices, and run= completers work again in fish and zsh, while native file/path completion still falls back correctly. (#​12376, #​12379 by @​jdx)
  • env: Command-prefix and runtime environment overrides (for example VAR=override mise run ...) are no longer wiped when reconstructing the pre-mise environment in an activated shell; mise-managed values are only rolled back when the live value still matches what mise recorded. (#​12390 by @​jdx)
  • env: A leading UTF-8 byte-order mark in an env file is now stripped before parsing. (#​12320 by @​JamBalaya56562)
  • backend: Fixed a regression where an offline latest request failed for a tool installed only with mise install --system; the effective install directory is now recovered so system/shared-only installs satisfy latest. (#​12406 by @​jdx)
  • github: When a lockfile records a checksum but no provenance, mise no longer probes the GitHub releases API at install time. This avoids hard install failures under rate limiting in high-concurrency CI, since the lockfile checksum already guarantees artifact integrity. The lockfile checksum now also takes priority over release-metadata digests. (#​12377 by @​effati)
  • brew: Cask installs now recursively extract single nested archives (matching Homebrew's extract_nestedly, for example a zip containing only a DMG), and bare cask .pkg downloads are staged correctly. (#​12373, #​12371 by @​jdx)
  • pipx: Non-GitHub Git latest requests now resolve to the remote default branch HEAD and are treated as a rolling channel, so outdated and upgrade detect branch movement. An unavailable configured executable is now rejected instead of failing later. (#​12407, #​12416 by @​jdx)
  • lockfile: Each new version is now attributed to its own request source, so in monorepo or parent/child layouts that request the same tool at different versions, every lockfile receives its own entry instead of the first request's lockfile getting them all. Monorepo root requests are also included in lockfile maintenance. (#​12381, #​12382 by @​pikeas)
  • task: Several ordering and output fixes: keep-order buffers are flushed instead of discarded, injected tasks are anchored at their parent's keep-order slot, #MISE header keys that need quoting are no longer dropped, and negative template argument bounds are rejected. Sandbox errors now name which paths do not exist yet. (#​12370, #​12397, #​12415, #​12421, #​12309)
  • config: Clearer parse errors, each reported once: TOML and settings parse failures name the offending file a single time (through the logger), and a message now explains what a backslash does when a config fails to parse. Picker descriptions are truncated safely. (#​12329, #​12327, #​12330 by @​JamBalaya56562; #​12422 by @​jdx)
  • generate: Generated files are now each named in output, and a task stub is named after the task rather than its file. (#​12333, #​12341 by @​JamBalaya56562)
  • trust: A path that does not exist is now refused rather than trusting its parent. (#​12372 by @​JamBalaya56562)
  • prune: Tracked configs that cannot be a config file are now removed. (#​12380 by @​Marukome0743)
  • self-update: A failure updating plugins no longer fails the whole command. (#​12363 by @​JamBalaya56562)
  • cli: On Windows, mise now defaults to an editor that exists and names the editor that failed to launch. (#​12375 by @​JamBalaya56562)
  • nushell: __MISE_SESSION is now unset on deactivate. (#​12361 by @​NgoQuocViet2001)
  • elvish: The prepended PATH entry is now separated correctly from the existing PATH. (#​12362 by @​NgoQuocViet2001)
  • ui: Tables no longer pad the last column past its content. (#​12334 by @​JamBalaya56562)
Documentation
  • security: Updated the description of paranoid mode behavior. (#​12394 by @​jdx)
Registry

Full Changelog: jdx/mise@v2026.8.12...v2026.8.13

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.12: : Cleaner diagnostics and a raft of task, config, and tool fixes

Compare Source

This release adds package uninstall support to the plugin bootstrap flow and fixes a broad set of task, config, tool, and diagnostic edge cases. Many changes turn silent failures and cryptic errors into actionable messages, so it is largely a robustness and quality-of-life release.

Added

  • bootstrap: Package-plugin managers now support pruning via an optional PackageUninstall hook, so mise bootstrap packages prune --manager <plugin> is no longer Homebrew-only. mise records ownership only for packages that go from missing to installed during an install, and prune removes only owned packages that are absent from the current config and trusted tracked configs. Pre-existing and manually installed packages are never claimed, dry-run never invokes the hook, and the keep-set is reloaded after confirmation so newly declared packages cannot be removed without another prompt. (#​12332 by @​jdx)

Fixed

  • config: Version-declaring files that begin with a UTF-8 byte-order mark now parse correctly. Previously a leading BOM (as written by Notepad or PowerShell's Out-File -Encoding utf8) could make .tool-versions, .node-version, package.json packageManager, registry-scraped files like Earthfile, and .sdkmanrc entries silently vanish or resolve to a corrupt version. Cached idiomatic parses written by an older mise are re-parsed so the fix takes effect on upgrade. (#​12325 by @​JamBalaya56562)
  • config: Saving from mise edit (and the interactive TUI) now preserves comments — leading, trailing, and section comments are captured on parse and written back on save, instead of being stripped. (#​12319 by @​Marukome0743)
  • config: An idiomatic file such as package.json that was tracked while enabled and later disabled no longer triggers a spurious "cannot update idiomatic version file" warning on read-only operations like mise ls --all-sources. The tracking entry is retained so re-enabling the tool reactivates it. (#​12194 by @​xqm32)
  • cli: A cd target that cannot be entered (for example via MISE_CD pointing at a missing directory, or a directory the process cannot chdir into) is now reported with the path and OS reason instead of panicking. (#​12314 by @​JamBalaya56562)
  • task: A task whose child process is killed by SIGINT (Ctrl-C reaching only the child) is now treated as an interruption, exiting 130 without failing sibling tasks, instead of reporting a spurious failure. Signalled processes now render as killed by SIGINT/killed by SIGTERM rather than "no exit status". (#​12323 by @​Marukome0743)
  • task: Value-taking usage flags without a default (for example --file <file>) now stay string-typed during template rendering, so path filters like dirname work on them. Switch flags still default to booleans and count flags to integers. (#​12355 by @​jdx)
  • tasks: On Windows, task files skipped because they have no known extension or shebang now explain why and give platform-appropriate guidance, instead of producing no output or a misleading "Are you in a project directory?" message. Outdated chmod +x advice is gone from Windows messages. (#​12324 by @​JamBalaya56562)
  • tool-stub: Non-cached tool-stub execution now keeps the toolset's env_with_path rather than rebuilding PATH from a pristine environment, restoring project _.path directories and fixing discovery of sibling stubs. The stub-selected tool version is no longer shadowed by an outer task's install directories. (#​12322 by @​tmkx)
  • watch: mise watch --clear=reset --restart no longer leaves the terminal without echo after Ctrl-C. The controlling terminal (preferring /dev/tty) is now saved and restored from a drop guard, so it recovers on normal return, errors, and cancellation, including when stdin is redirected or a second terminal is in use. (#​12328 by @​Marukome0743)
  • go: go install no longer inherits a GOROOT that mise exported for a different Go, which caused compile: version ... does not match go tool version ... failures when another go was first on PATH. An explicitly configured install_env GOROOT is still honored. (#​12342 by @​Marukome0743)
  • doctor: mise doctor now flags a tool whose install directory exists but is empty (for example after an interrupted download), marking it (empty) and suggesting mise install --force, instead of silently treating it as installed. (#​12321 by @​Marukome0743)
  • env: When an age SSH identity cannot be used (passphrase-protected, encrypted, hardware-backed, or an unsupported key type), decryption failures now explain which identity could not be read and why, instead of the misleading "No matching keys found". (#​12339 by @​Marukome0743)
  • env: The warning for an unexpanded $VAR now names the key or directive that referenced the missing variable and the config file it lives in, making it possible to find the offending line in a large [env] block. (#​12316 by @​Marukome0743)
  • brew-cask: Casks already owned by Homebrew are now recognized as installed (read-only) rather than reported missing and then blocked by the ownership guard, making declarative bootstrap idempotent for Homebrew-managed casks. mise leaves such installations untouched across status, apply, use, upgrade, and prune. (#​12346 by @​donbeave)
  • registry: oc (OpenShift client) now installs from channel aliases such as oc = "stable" by resolving the unversioned artifact name within the channel directory, fixing a 404. (#​12326 by @​Marukome0743)

Documentation

  • tasks: PowerShell task guidance now points extensionless tasks at MISE_TASK_DIR for locating sibling files, which works consistently across Linux, macOS, and Windows without renaming the task. (#​12313 by @​JamBalaya56562)

New Contributors

Full Changelog: jdx/mise@v2026.8.11...v2026.8.12

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.11: : Automatic updates, remote mise installs, and versioned lockfiles

Compare Source

This release adds opt-in automatic self-updates, lets remote bootstrap leave a working mise behind on each target, and introduces versioned lockfiles that bind each request to the version it resolved. It also replaces the CLI parser with usage-rs, hardens remote Git task handling, and fixes a wide range of tool-installation, task, and config edge cases.

Highlights

  • mise can now keep itself up to date and provision itself onto remote hosts, closing two long-standing gaps in unattended and remote workflows.
  • Lockfiles gained an explicit format version so overlapping loose and exact requests can pin distinct versions, with mise lock --upgrade for safe migration and no surprise drift for existing files.
  • The CLI parser moved from clap to usage-rs, and remote Git task paths are now contained against traversal, symlink, and Windows path escapes.

Added

  • self-update: New opt-in automatic updates. Enable auto_update (with auto_update_check_duration, default 7d) and mise will update itself before eligible interactive commands, then re-exec your original invocation with the new binary. Updates are throttled and lock-serialized, skipped in CI, offline, non-interactive, and shell-integration contexts, and failures never block the requested command. Package-managed builds are steered toward the official optimized binaries. (#​12288 by @​jdx)

    [settings]
    auto_update = true
    auto_update_check_duration = "7d"
  • bootstrap: Remote bootstrap can now install a persistent mise on each target instead of tearing it down with the staging directory. Set install_mise in [bootstrap.remote] (or per host) or pass --install-mise[=/path]; the same checksum-verified executable that ran the bootstrap is installed, so the host converges on the orchestrating mise version. (#​12284 by @​jdx)

    [bootstrap.remote]
    install_mise = true  # installs to ~/.local/bin/mise
  • lock: Lockfiles now carry lockfile_version = 1 and bind each original request to the entry it resolved, so overlapping requests like "1" and "1.0.0" can lock different versions. Existing unversioned lockfiles stay on format 0 during ordinary mise lock/install/upgrade to avoid drift; run mise lock --upgrade to migrate (transactional, rolls back on failure). (#​12299 by @​jdx)

  • node: mise can now act as a Corepack replacement, honoring the +sha... checksum suffixes in packageManager / devEngines.packageManager and verifying the exact npm, pnpm, Yarn, or bun artifact before installing. Adds SHA-224/SHA-384 hashing and a Windows script launcher for Yarn's JS CLI. (#​12214 by @​jdx)

  • prune: mise prune --dry-run now explains why each version is prunable, naming either the kept versions and the configs requiring them or the fact that nothing tracked references the tool. (#​12304 by @​Marukome0743)

  • java: Oracle GraalVM "innovation" feature releases are now recognized. (#​12189 by @​roele)

Fixed

Changed

  • cli: The command-line parser, help output, and shell completions moved from clap to usage-rs. Completions and help are now generated from compiled usage metadata rather than an external usage CLI, and mise completion --install writes self-contained scripts. This raises the minimum supported Rust version to 1.95. (#​12221 by @​jdx)
  • generate: mise generate bootstrap is renamed to mise generate install-script to avoid confusion with mise bootstrap. The old spelling still works as a hidden, deprecated alias (removal scheduled for 2027.9.0). (#​12247 by @​jdx)
  • prompts: confirmation prompts now distinguish "could not ask" from an explicit "no". (#​12273 by @​Marukome0743)

Security

  • task: Remote Git task paths are now contained to the checkout root, rejecting .. traversal, Windows absolute/backslash and drive-qualified forms, and intermediate symlink escapes, and refusing non-regular-file targets. This closes escapes that could chmod +x and execute attacker-chosen files outside the checkout. (#​12254 by @​risu729)

Deprecated

  • config (Alpine): The distro-wide all_compile = true default on Alpine now warns and is scheduled for removal in 2027.8.0; precompiled musl binaries become the default path. Set all_compile = true explicitly to keep building from source. (#​12287 by @​risu729)
  • config (idiomatic files): Minimum-version floors in go.mod (go X.Y) and CMakeLists.txt (cmake_minimum_required) now warn when they resolve a version and stop being read in 2026.11.0. toolchain goX.Y.Z is unaffected. Only affects users who opted these tools into idiomatic_version_file_enable_tools. (#​12259 by @​jdx)

Documentation

Registry

Performance

Breaking Changes

  • The CLI parser migration (#​12221) raises the minimum supported Rust version to 1.95 for building from source, and mise completion's --include-bash-completion-lib / --usage flags are now no-ops. Command behavior, flags, and aliases are otherwise preserved.

New Contributors

Full Changelog: jdx/mise@v2026.8.10...v2026.8.11

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.10: : Remote bootstrap environments and asset-matching fixes

Compare Source

This release lets remote bootstrap pick which config environments run on each target, fixes several tool-installation edge cases (archive naming, Windows ZIP preference, renamed aqua packages, Homebrew cask metadata), and hardens pacman package detection and Windows self-update cleanup.

Added

  • bootstrap: Remote bootstrap can now select which mise.<env>.toml layers load on each SSH target without inheriting the orchestrator's full environment. Set a default with [bootstrap.remote].mise_env, override per host in your inventory, or pass --remote-env (repeatable or comma-separated) on the command line. (#​12182 by @​jdx)

    [bootstrap.remote]
    mise_env = ["production"]
  • bootstrap: Independent config roots can now contribute symlink-each trees that share the same target directory, as long as their leaf paths are disjoint. Overlapping leaves and file/directory collisions still fail before any changes, reporting both declaring config origins. (#​12190 by @​jdx)

  • doctor: mise doctor now detects leftover Windows self-update helper files (__relocated__ / __selfdelete__ copies in TEMP) and reports their count and total size, noting that a subsequent mise self-update removes them. (#​12205 by @​JamBalaya56562)

Fixed

  • system (pacman): Arch packages satisfied by an installed provider through Provides are no longer reported as missing. mise now uses pacman -T to distinguish genuinely missing packages, recovers the provider's version for status, and skips provider-satisfied aliases during targeted upgrades so pacman does not try to replace the provider. (#​12183 by @​jdx)
  • registry (aqua): Twelve aqua: backends (including d2, typstyle, gitui, gradle, ktlint, kubeseal, and velero) now point at their renamed, canonical package ids, so they install even in networks where api.github.com is unreachable. A regression test prevents this drift from returning. (#​12186 by @​kkom)
  • registry (azure-cli): On Windows x64, azure-cli now installs from the official bundled-Python ZIP release instead of PyPI, fixing az failing with 'python' is not recognized or No module named 'azure'. Linux and macOS continue to use the existing pipx install. (#​12161 by @​JamBalaya56562)
  • brew: Homebrew cask metadata now deserializes when the API sends "auto_updates": null, treating it as the default false. This was breaking metadata fetches for the majority of current casks. (#​12192 by @​jdx)
  • backend: Restored the strict preference for Windows ZIP archives over all tarball formats (tar.zst > tar.xz > other), which a prior change had accidentally reduced to a tiebreak. (#​12200 by @​risu729)
  • backend: Shorthand archive extensions like .tbz and .tbz2 are now normalized correctly when matching preferred asset names and stem-only checksums, including mixed-case suffixes. This prevents assets from losing the preferred-name bonus and selecting the wrong archive. (#​12199 by @​risu729)
  • sync: External-provider link reconciliation no longer removes links owned by another source or races with concurrent installs. Managed installs, runtime aliases, and links from unselected providers are preserved, and stale dangling links are correctly replaced with the winning provider's install. (#​11682 by @​risu729)
  • self-update: On Windows, stale helper copies in TEMP are now swept before the TEMP-length check, so cleanup still runs on the long-TEMP machines that need it most. (#​12205 by @​JamBalaya56562)

Performance

  • cache: Foreground blob lookups during rustc cache restores are now batched into a single blob-pack request when the remote supports it, instead of one request per digest, with response metadata validated and a safe fallback to individual blob GETs. (#​12191, #​12193 by @​jdx)

Documentation

New Contributors

Full Changelog: jdx/mise@v2026.8.9...v2026.8.10

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.9: : Composable Bootstrap, Environment-Aware conf.d, and Faster Startup

Compare Source

This release expands declarative bootstrap into a composable, multi-root system; adds environment-specific conf.d fragments and glob-based ignored config paths; smooths out shell activation so runtime overrides stick; and delivers major startup performance gains for vfox-backed setups. It also includes several security hardening fixes worth noting.

Highlights

  • Bootstrap can now compose declarative resources (dotfiles, files, directories, services, and Compose projects) from multiple independent config roots, with provenance tracking and clear conflict diagnostics.
  • Startup is dramatically faster on machines with vfox plugins: idiomatic file detection is now gated on opt-in, and vfox plugin metadata is cached on disk, cutting common invocations from hundreds of milliseconds to single digits.
  • Security hardening: forge tokens no longer leak to third-party hosts, and safe mode now blocks tool-level install hooks.

Added

  • bootstrap: Compose declarative resources from multiple independent config roots via [bootstrap].config_roots. Selected roots contribute [dotfiles], [bootstrap.files], [bootstrap.directories], [bootstrap.services], and [bootstrap.compose] without gaining precedence from list or glob order; identical declarations are deduplicated and conflicting declarations fail with both origins reported. (#​12105, #​12132 by @​jdx)

    [bootstrap]
    config_roots = ["bundles/*"]
  • bootstrap: Declaration provenance is now retained and exposed for dotfiles and managed files/directories. mise bootstrap plan, bootstrap status, and mise dotfiles status include origin details (declaring config, config root, environment, resolved source) in JSON, and human-readable tables gain a Config column. (#​12100 by @​jdx)

  • bootstrap: Homebrew-compatible support for self-updating and adopted casks in [bootstrap.packages]. Casks declaring auto_updates: true are left to update themselves, and existing app bundles can be adopted globally with [bootstrap.brew].adopt = true or per cask with adopt = true. (#​12074 by @​ascarter)

  • bootstrap: Remote bootstrap gains symlink materialization controls. Use --copy-link <PATH> (repeatable) to dereference selected source-relative symlinks or --copy-links to recursively dereference all archived symlinks; both are also configurable in [bootstrap.remote] and per-host. Default behavior is unchanged (links stay links). (#​12121 by @​jdx)

  • config: Environment-specific conf.d fragments. Files like .mise/conf.d/*.{env}.toml (and .local variants) load only when that config environment is active, applying to project, global, and system conf.d directories. (#​12151 by @​jdx)

  • config: ignored_config_paths now supports relative entries and glob patterns (including recursive **). Entries in .miserc.toml resolve against the declaring file, while MISE_IGNORED_CONFIG_PATHS resolves against the invocation directory — making it easy to exclude vendored repos portably. (#​12169 by @​jdx)

  • config: mise run, naked mise <task>, mise install, mise exec, and mise watch now implicitly trust and persist the active config in normal mode, avoiding a redundant prompt. Automatic hook-env/inspection commands still require explicit trust, and paranoid and safe modes are unchanged. (#​12107 by @​jdx)

  • system: Plugins can declare an ordered list of candidate package names per package manager in systemDependencies, so the same capability can be expressed across distro renames (for example apt = { "libaio1t64", "libaio1" }). mise resolves the first available candidate. (#​12149 by @​jdx)

  • vfox: Traditional vfox plugins can now read configured [tools] options from ctx.options in PreInstall and PostInstall hooks, with scalars as strings and arrays/tables as structured Lua values. Existing hook environment variables continue to work. (#​12174 by @​jdx)

Fixed

  • hook-env: Runtime environment overrides now persist between refreshes. Changes made with export, shell aliases, sourced scripts, or direct PATH edits are no longer reverted on every prompt, reversing the continuous enforcement introduced in 2026.8.0. (#​12094 by @​jdx)
  • aqua: Prefer glibc release assets on unqualified glibc Linux targets, falling back to a musl asset only when no glibc sibling exists. Explicit libc selections stay strict. (#​12093 by @​jdx)
  • python: Automatic venv creation now resolves the configured uv even when invoked through a tool override (for example mise x tiny@3), so python.uv_venv_auto no longer reports uv as missing right after mise installs it. (#​12177 by @​jdx)
  • which: mise which <bin> --tool=<tool>@<version> now reports that the requested version is not installed (with an install hint) instead of the misleading "not currently active" message. (#​12106 by @​TrevorBurnham)
  • shell: The pwsh command-not-found hook now branches on the command exit code and skips mise's own commands, and the environment is refreshed on auto-install when --no-hook-env omits the hook. (#​12089, #​12131, #​12117 by @​JamBalaya56562)
  • bootstrap: Create missing parent directories when bootstrapping. (#​12096 by @​jdx)
  • github: Match arm assets on arm64 hosts. (#​12098 by @​jdx)
  • use: Scope global install hooks correctly. (#​12101 by @​jdx)
  • task: Support Azure DevOps cloud SSH URLs as remote git task sources, and normalize Windows task environment paths. (#​12102 by @​cheesemans, #​12173 by @​jdx)
  • system: Resolve dependency executables on Windows. (#​12178 by @​jdx)
  • backend: Keep flavour queries from crossing a +, and key the remote version cache by listing tool options. (#​12118 by @​Marukome0743, #​12164 by @​JamBalaya56562)
  • http: Order remote versions consistently. (#​12170 by @​jdx)
  • **v

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Paris)

  • Branch creation
    • "after 7am every weekday,before 8pm every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team November 18, 2025 04:40
@sonarqube-next

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 93273ff to 72c65a5 Compare May 7, 2026 10:27
@renovate
renovate Bot requested a review from a team as a code owner May 7, 2026 10:27
@renovate renovate Bot changed the title chore(deps): update actions/checkout action to v4.3.1 Pin dependencies May 7, 2026
@renovate

renovate Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: undefined
Post-upgrade command 'pre-commit autoupdate --freeze || true' has not been added to the allowed list in allowedCommands

@sonar-review-alpha

sonar-review-alpha Bot commented May 7, 2026

Copy link
Copy Markdown

Summary

This Renovate-generated PR pins GitHub Actions workflow dependencies to specific commit SHAs, replacing floating version references like v1, v7, and v3 with immutable commit hashes. Each pinned reference includes a version comment for readability.

Note: The actual versions pinned in the workflows differ from those listed in the PR description:

  • SonarSource/ci-github-actions is pinned to 1.4.0 (not 1.3.35 as stated)
  • SonarSource/gh-action_release is pinned to 7.0.1 (not 7.0.0 as stated)

Reviewers should verify these versions are intentional, not accidental updates.

What reviewers should know

Files modified: All .github/workflows/ files

  • build.yml: pins checkout and both ci-github-actions actions
  • pr-cleanup.yml: pins ci-github-actions
  • pre-commit.yml: pins gh-action_pre-commit (includes feature update to 1.2.0)
  • releasability.yaml: pins gh-action_releasability
  • release.yml: pins gh-action_release

Security context: Pinning to commit SHAs prevents unexpected action behavior from future version releases while still maintaining version comments for reference.

Verification needed: Cross-check the actual pinned versions (in the # comments) against the PR description to ensure they match intended updates.


  • Generate Walkthrough
  • Generate Diagram

🗣️ Give feedback

sonar-review-alpha[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 72c65a5 to 18c861e Compare May 7, 2026 16:07
@sonarqube-next

sonarqube-next Bot commented May 7, 2026

Copy link
Copy Markdown

@sonar-review-alpha sonar-review-alpha Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ✅

Clean dependency-pinning PR with no bugs or logic issues. The versions actually pinned in the workflows differ from the PR description: ci-github-actions is pinned to 1.4.0 (description says 1.3.35) and gh-action_release to 7.0.1 (description says 7.0.0). This is a known Renovate behaviour — the description can fall out of sync if the upstream tag moves between when Renovate opens the PR and when it commits. The SHAs in the workflows are what matters; confirm they resolve to the intended tags before merging.

🗣️ Give feedback

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 18c861e to 5ea85e2 Compare May 22, 2026 16:53
@renovate
renovate Bot temporarily deployed to sca-checking May 22, 2026 16:54 Inactive
@sonarqube-next

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5ea85e2 to 08740c6 Compare June 2, 2026 12:52
@renovate
renovate Bot temporarily deployed to sca-checking June 2, 2026 12:52 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 08740c6 to 9af7da3 Compare June 3, 2026 17:37
@renovate
renovate Bot temporarily deployed to sca-checking June 3, 2026 17:37 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 9af7da3 to 4b7c790 Compare June 8, 2026 20:31
@renovate
renovate Bot temporarily deployed to sca-checking June 8, 2026 20:31 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4b7c790 to 012d4be Compare June 9, 2026 18:37
@renovate
renovate Bot temporarily deployed to sca-checking June 9, 2026 18:37 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 012d4be to 2f46314 Compare June 10, 2026 01:00
@renovate
renovate Bot temporarily deployed to sca-checking June 10, 2026 01:00 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 2f46314 to 8fd3dc6 Compare June 10, 2026 13:23
@renovate
renovate Bot temporarily deployed to sca-checking June 10, 2026 13:23 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8fd3dc6 to f23e8f1 Compare June 15, 2026 09:15
@renovate
renovate Bot temporarily deployed to sca-checking June 15, 2026 09:15 Inactive
@renovate
renovate Bot force-pushed the renovate/github-actions branch 8 times, most recently from d7d3110 to 6637a66 Compare August 5, 2026 00:00
@renovate
renovate Bot force-pushed the renovate/github-actions branch 5 times, most recently from afbb77b to 150d756 Compare August 10, 2026 03:41
@renovate
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from e85144d to 5ba3989 Compare August 17, 2026 14:01
@renovate
renovate Bot force-pushed the renovate/github-actions branch 6 times, most recently from 7c409c6 to 5aed8d1 Compare August 29, 2026 11:25
@renovate
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 746b546 to eae0289 Compare August 30, 2026 23:55
@renovate
renovate Bot force-pushed the renovate/github-actions branch from eae0289 to 242700c Compare August 31, 2026 03:39
@sonarqubecloud

Copy link
Copy Markdown

@sonarqube-next

Copy link
Copy Markdown

@sonar-platform-bot

Copy link
Copy Markdown

This pull request is being closed because it has been identified as stale.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants