Skip to content

chore(deps): update ci workflows - #680

Merged
wschurman merged 1 commit into
mainfrom
renovate/ci-workflows
Aug 17, 2026
Merged

chore(deps): update ci workflows#680
wschurman merged 1 commit into
mainfrom
renovate/ci-workflows

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
jdx/mise patch v2026.8.3v2026.8.6
jdx/mise-action action patch v4.2.4v4.2.5

Release Notes

jdx/mise (jdx/mise)

v2026.8.6: : Resumable downloads, richer Homebrew casks, and monorepo task fixes

Compare Source

This release adds resumable HTTP downloads, expands Homebrew cask support, and lands a large batch of fixes across tasks, config, install, and platform-specific behavior — with a particular focus on monorepos and Windows.

Highlights

  • Interrupted artifact downloads now resume instead of restarting from zero, and more transient network failures (including HTTP/2 REFUSED_STREAM) are retried automatically.
  • The Homebrew cask backend gained structured symlinks, generic artifacts, and copy/installer flight steps, closing several gaps in cask installation.
  • A wide round of monorepo task, config precedence, and Windows path handling fixes.

Added

  • http: interrupted downloads now resume via HTTP Range requests when a strong ETag or Last-Modified validator is available, keeping validated partial files across retries and mise invocations instead of re-downloading from byte zero. mise falls back to a clean restart when validators do not match, and abandoned partials expire after 30 days. (#​11866 by @​Marukome0743)

  • brew: the Homebrew cask backend now supports structured symlink steps (with path bases, templates, guards, source globs, and sudo control), generic cask artifacts, and copy/installer flight steps, with transactional rollback if an install fails. (#​11962, #​11963, #​11964 by @​jdx)

  • task: mise run --all opens the interactive task picker with tasks from the entire monorepo, matching the load path already used by mise tasks ls --all. The default picker stays scoped to the current directory hierarchy. (#​11920 by @​jdx)

    mise run --all
  • task: add task.cache.audit_report (MISE_TASK_CACHE_AUDIT_REPORT) to write the complete cache-audit report to a JSON Lines file. The console still caps at 20 paths per task, but the file now captures every undeclared read and write so large audits (e.g. Jest over node_modules) are actually usable. (#​11997 by @​stevenpollack)

    MISE_TASK_CACHE_AUDIT_REPORT=audit.jsonl mise run --force build
  • dotfiles: whole-file [dotfiles] entries can now declare their body inline with content = "..." instead of requiring a separate source file, useful for small configs and user-writable paths outside $HOME. content cannot be combined with source, mode, or exclude. (#​11983 by @​jdx)

  • deps: deps provider config fields (paths, commands, env, descriptions, timeouts) now render Tera templates using the defining config file's context, with shell-style environment expansion and rendered env values folded into freshness identity. Template errors surface as clear configuration errors before commands run. (#​11886 by @​Marukome0743)

  • config: add a config-root-scoped [tool_config] locked = true policy that requires tools declared by configs sharing that root to resolve and install from their lockfiles, without forcing global or parent-root tools into strict mode. [settings] locked, --locked, and MISE_LOCKED remain invocation-wide. (#​11940 by @​jdx)

Fixed

  • task: in monorepo mode, running a task by its bare or :-prefixed name now works from any directory below a config root, resolving to the nearest enclosing project instead of failing. (#​11941 by @​pikeas)
  • task: normalize task cwd for source freshness (#​11987 by @​jdx), bound buffered command output (#​11922), avoid zsh process-substitution hangs (#​11904), and normalize variadic usage env values (#​11881) by @​Marukome0743; mask archive modes in remote cache nodes (#​11877 by @​stevenpollack).
  • http: retry send failures that never produced a response, including HTTP/2 REFUSED_STREAM, which CDNs emit as backpressure and which previously failed on the first attempt even with retries enabled. (#​11961 by @​mariadeluna-tomtom)
  • http: honor system install destinations for downloads. (#​11851 by @​Marukome0743)
  • aqua: when a downloaded checksum file lists per-file hashes but none match the target filename, mise now errors instead of silently returning a wrong checksum. (#​11973 by @​jakedgy)
  • pipx: discover wheel-only package versions from PEP 503 Simple API indexes, so packages published only as wheels now appear in mise ls-remote and latest resolution. (#​11959 by @​jdx)
  • rust: the rolling nightly channel now resolves to a concrete nightly-YYYY-MM-DD toolchain via the official channel manifest, making nightly lock, outdated, upgrade, and offline reuse reproducible while keeping mise.toml on nightly. (#​11980 by @​Marukome0743)
  • ruby: support ruby-build CLI options. (#​11918 by @​Marukome0743)
  • conda: preserve cross-platform lock data (#​11946 by @​jdx) and honor URL replacements (#​11930 by @​Marukome0743).
  • npm: render lifecycle logs through the progress display. (#​11939 by @​jdx)
  • oci: strip the tag from name:tag@digest references so pulling a base image by combined tag-and-digest no longer produces a malformed token scope, while preserving registry ports. (#​11979 by @​fire-ant)
  • install: write tool manifests atomically. (#​11957 by @​jdx)
  • lock: include task-specific tools in the lockfile. (#​11976 by @​Marukome0743)
  • deps: invalidate deps state when a provider's command, environment, working directory, or shell changes, so an edited run command is no longer skipped as fresh (#​11849); honor source and output overrides (#​11896) by @​Marukome0743.
  • hooks: skip tool installation in preinstall tasks. (#​11927 by @​Marukome0743)
  • exec: allow a symlinked resolv.conf inside the sandbox. (#​11958 by @​jdx)
  • generate: honor absolute localized directories. (#​11975 by @​NgoQuocViet2001)
  • config: allow typing j/k to filter in the mise edit tool picker (#​11969 by @​jakedgy); create the config directory before writing into it (#​11934) and stop a conf.d drop-in from becoming the write target (#​11917) by @​JamBalaya56562.
  • bootstrap: avoid sudo for user-writable files (#​11984) and allow Windows bootstrap without system files (#​12003) by @​jdx.
  • semver: stop labeling a mangled value as a semver range. (#​11949 by @​JamBalaya56562)
Windows fixes

Changed

  • upgrade/outdated: -b is now the shorthand for --bump. The old -l bump shorthand is hidden and deprecated (removal planned for 2027.8.5) so -l can later mean --local. When tools are current within configured ranges but a bump is available outside them, both commands now say so instead of reporting everything up to date. (#​11945 by @​jdx)
  • cli: mise use --global alongside a path is now rejected instead of silently ignored. (#​11935 by @​JamBalaya56562)

Deprecated

  • config: the automatic all_compile = true default on NixOS is deprecated and scheduled for removal in 2027.8.0. It currently forces source builds for Node, Python, Erlang, and Ruby even when precompiled binaries work through nix-ld; mise now warns and points to enabling nix-ld or setting all_compile = true explicitly. Alpine's source-build default is unchanged. (#​11956 by @​jdx)

Registry

New Contributors

Full Changelog: jdx/mise@v2026.8.5...v2026.8.6

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.5: : PyPy on the precompiled path, Node source patches, and a broad batch of fixes

Compare Source

This release lets mise install PyPy on the precompiled path (including on Windows), adds Node source-build patching, and lands a wide set of fixes across config precedence, install hooks, version pinning, and the Rust, conda, and vfox backends.

Added

  • python: PyPy can now be installed on the precompiled path — when python.compile=false, and unconditionally on Windows, where PyPy versions previously never appeared in mise ls-remote python and could not be installed at all. mise reads the upstream downloads.python.org/pypy index, downloads and extracts the correct archive, runs ensurepip, and records a blake3 checksum in the lockfile on first install (PyPy publishes no machine-readable checksums). (#​11846 by @​JamBalaya56562)

    mise install python@pypy3.10-7.3.17
  • node: add node.apply_patches (MISE_NODE_APPLY_PATCHES) to apply local or remote patches to the Node source build before ./configure runs, mirroring ruby.apply_patches. It accepts a newline-separated list of patch files or URLs. Strip level is auto-detected from git- or diff-style markers, and patches are recorded in the lockfile since they change the built artifact. If patches are set but a precompiled Node was installed, mise now warns instead of silently dropping them. (#​11850 by @​JamBalaya56562)

    [settings.node]
    compile = true
    apply_patches = "./patches/local.patch"

Fixed

  • config: global config precedence inside ~/.config/mise now matches the documentation — config.local.toml overrides config.toml, which overrides conf.d/*.toml. Previously the order was reversed for [settings], [tools], and [env] when ~/.config/mise was outside the cwd walk. (#​11906 by @​halms)
  • config: mise use now updates a single tool version in place within a standard [tools.<name>] table, preserving comments, key ordering, whitespace, and nested option tables instead of collapsing the table to inline form. (#​11848 by @​Marukome0743)
  • install: inline preinstall and postinstall hooks now run from the owning project root, so relative paths resolve consistently even when mise install is started from a subdirectory. The invocation directory remains available through MISE_ORIGINAL_CWD. (#​11857 by @​jdx)
  • use: mise use --pin now prefers an exact available release when pinning, instead of reusing a more-specific installed fuzzy match. For example mise use --pin erlang@27.3 will pin 27.3 if that exact release exists remotely, rather than depending on which versions happen to be installed. (#​11838 by @​Marukome0743)
  • task: editing a root [task_templates.*] definition or a monorepo task default now correctly invalidates affected tasks, so stale outputs are no longer marked up to date after a template change. (#​11858 by @​jdx)
  • rust: mise now reuses a complete external rustup installation (for example one installed by Homebrew) when the default Rust homes are not initialized, instead of downloading and initializing its own. Explicitly configured Cargo/Rustup homes continue using the mise-managed path. (#​11840 by @​Marukome0743)
  • conda: conda package commands now run through prefix-aware launchers that activate each command's own conda prefix, fixing tools like jdtls that expand ${CONDA_PREFIX} and rely on activation scripts. Dependency executables stay isolated from the user's shell PATH. (#​11855 by @​Marukome0743)
  • python: disable_tools = ["python"] (and allowlist forms like enable_tools = ["node"]) now also suppress the _.python.venv directive, so a disabled Python no longer leaves its virtualenv activated on PATH. (#​11885 by @​JamBalaya56562)
  • vfox: configured vfox tool options are now exposed to plugin hooks through MISE_TOOL_OPTS__* (with legacy RTX_TOOL_OPTS__* aliases), so hooks reading os.getenv("MISE_TOOL_OPTS__...") see the resolved options during install, uninstall, exec-env, and lock paths. (#​11884 by @​Marukome0743)
  • aqua: explicit github_release package-type overrides from version and platform overrides are now applied, fixing installs such as recent Claude Code releases that failed with "relative URL without a base". (#​11901 by @​Marukome0743)

Changed

  • cache: remote build-cache prefetch now downloads output blobs concurrently (up to 48 in parallel) while reserving foreground slots for compiler lookups, dramatically speeding up large Rust cache restores that previously downloaded thousands of small artifacts serially. (#​11905 by @​jdx)

Documentation

Registry

Breaking Changes

  • If you relied on disable_tools = ["python"] while still keeping a _.python.venv activated, that virtualenv will no longer be activated. The existing venv remains on disk and is restored automatically when Python is re-enabled. (#​11885)

Full Changelog: jdx/mise@v2026.8.4...v2026.8.5

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.4: : Cross-backend ls, semver ordering, and bootstrap cask pruning

Compare Source

This release adds explicit semantic version ordering for major backends, teaches mise ls and mise install --force to work across backends, extends bootstrap package management with platform filters and cask pruning, and lands a broad batch of task, config, and platform-specific fixes.

Added

  • backend: tools can now declare an explicit version_order (source or semver) so that latest and version-prefix resolution follow semantic precedence instead of source/chronological order. This is enabled for Aqua, GitHub, GitLab, Forgejo, and HTTP backends, and fixes cases where a backport or older release line was picked ahead of a newer version (for example neo4j, victoria-metrics, go-getter, talosctl, rpk, and tealdeer). mise ls-remote continues to show upstream source order. (#​11774 by @​jdx)

  • ls: mise ls <name> now matches a tool installed from multiple backends. Previously, installing a tool from both its registry backend and, say, a cargo: or ubi: build would show only one of them under mise ls <name> even though both were on PATH. Spelling out a backend (e.g. mise ls ubi:jqlang/jq) still narrows to that single backend. (#​11822 by @​JamBalaya56562)

  • install: mise install --force now works without tool arguments, reinstalling every configured, OS-supported tool (or the monorepo union with --monorepo). (#​11802 by @​Marukome0743)

  • upgrade: add an upgrade.auto_prune setting (default true) that controls whether mise upgrade removes the version it replaced, plus a --prune flag to force removal on for a single run when the setting is off. Useful when a mise-managed interpreter backs a virtualenv you do not want deleted on unattended upgrades. (#​11788 by @​JamBalaya56562)

    [settings]
    upgrade.auto_prune = false
  • bootstrap: mise bootstrap packages prune --manager brew-cask can now conservatively remove mise-owned Homebrew casks that are no longer declared in [bootstrap.packages]. Removal is gated by install-time receipt metadata, fingerprint checks, and ownership validation, and Homebrew-owned, pkg, lifecycle, drifted, or shared casks are skipped with an explicit reason. (#​11810 by @​jdx)

  • bootstrap: [bootstrap.packages] entries can now use table form with a version and [tools]-style os selectors, so a single config can target macOS-only casks and Linux fonts. Platform-incompatible packages surface as unavailable in status output instead of aborting the run, while explicit requests for unsupported packages still error. (#​11809 by @​jdx)

  • brew: the brew-cask manager now supports installing font casks directly from git URLs, including selecting a branch and staging files from a subdirectory. (#​11781 by @​roele)

  • aqua: relative aqua.registries entries in a config file are now resolved against that config's root, so a registry.yaml committed inside a project repository can be referenced without a machine-specific absolute path. (#​11804 by @​JamBalaya56562)

    [settings]
    aqua.registries = ["registry.yaml"]
  • spm: spm: installs can now be pinned to a commit via rev:<commit> (and compatible ref:<commit>), building from source. (#​11815 by @​Marukome0743)

  • generate: generated git hooks can now carry extra mise flags. Anything after -- is inserted between mise and run, so a hook can target config in a subdirectory or set other global flags. (#​11820 by @​JamBalaya56562)

    mise generate git-pre-commit --task lint -- -C subdir -E ci

Fixed

Documentation

Registry

New Contributors

Full Changelog: jdx/mise@v2026.8.3...v2026.8.4

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

jdx/mise-action (jdx/mise-action)

v4.2.5: : Resilient mise downloads with automatic retries

Compare Source

A small patch release that makes setup more resilient to transient network failures when downloading mise.

Fixed
Retry mise downloads after transient failures (#​597 by @​jdx)

The download helpers previously made a single curl or wget attempt, so a transient GitHub release-asset HTTP or TLS failure would abort setup before mise or any user command could run (see #​596).

Downloads now run through a retry wrapper that makes up to five attempts with a 2s pause between failures, logging a warning on each retry. This applies consistently to binary, checksum, signature, and version fetches. Checksum and minisign verification still run only after a successful download — never inside the retry loop — so integrity guarantees are unchanged.

Full Changelog: jdx/mise-action@v4.2.4...v4.2.5


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from wschurman as a code owner August 17, 2026 00:55
@codecov

codecov Bot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (b5f6cb6) to head (4f25d54).

Additional details and impacted files
@@            Coverage Diff             @@
##              main      #680    +/-   ##
==========================================
  Coverage   100.00%   100.00%            
==========================================
  Files          109       109            
  Lines        17825     17825            
  Branches       935      1542   +607     
==========================================
  Hits         17825     17825            
Flag Coverage Δ
integration 28.61% <ø> (ø)
unittest 94.58% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@wschurman
wschurman merged commit f1b13a9 into main Aug 17, 2026
5 checks passed
@wschurman
wschurman deleted the renovate/ci-workflows branch August 17, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant