Skip to content

fix(deps): update dependency jdx/mise to v2026.3.16#30

Merged
koki-develop merged 1 commit intomainfrom
renovate/jdx-mise-2026.x
Mar 30, 2026
Merged

fix(deps): update dependency jdx/mise to v2026.3.16#30
koki-develop merged 1 commit intomainfrom
renovate/jdx-mise-2026.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Mar 30, 2026

This PR contains the following updates:

Package Update Change Pending
jdx/mise minor 2026.2.232026.3.16 2026.3.17

Release Notes

jdx/mise (jdx/mise)

v2026.3.16

Compare Source

🐛 Bug Fixes
  • (backend) skip GitHub API call for cosign when disabled or unconfigured by @​jdx in #​8753
📦 Aqua Registry Updates
New Packages (1)
Updated Packages (10)

v2026.3.15

Compare Source

🚀 Features
  • (github) add credential_command setting for custom token retrieval by @​jdx in #​8746
🐛 Bug Fixes
  • (github) raise credential_command priority above github_tokens.toml and gh CLI by @​jdx in #​8748

v2026.3.14

Compare Source

🚀 Features
🐛 Bug Fixes
  • (python) respect precompiled flavor when excluding freethreaded builds by @​risu729 in #​8745
  • (shim) revert shims directory check that caused hangs on macOS by @​jdx in e1b8ca4
📚 Documentation
  • (python) swap docs for python.precompiled_arch and python.precompiled_os by @​risu729 in #​8744
🧪 Testing
New Contributors

v2026.3.13

Compare Source

🐛 Bug Fixes
📦️ Dependency Updates
  • ignore RUSTSEC-2026-0066 astral-tokio-tar advisory by @​jdx in #​8723
📦 Registry
New Contributors
📦 Aqua Registry Updates
Updated Packages (1)

v2026.3.12

Compare Source

🐛 Bug Fixes
  • (completions) update zsh completions for usage v3.1.0 by @​jdx in #​8715
Security
  • (lock) block github tool upgrade when provenance is lost by @​jdx in #​8706

v2026.3.11

Compare Source

🚀 Features
  • (github) read tokens from gh CLI hosts.yml config by @​jdx in #​8692
  • (task) support optional args and env fields in run entries by @​jdx in #​8687
  • (task) add --skip-tools flag to mise run by @​jdx in #​8699
  • (vfox) add try_get, try_head, try_download_file to Lua HTTP module by @​jdx in #​8697
🐛 Bug Fixes
  • (config) recognize SSH and other non-HTTPS URLs in get_repo_url by @​modestman in #​8666
  • (docs) add dark mode support to favicon by @​jdx in #​8678
  • (env) support multiple --env/-E flags by @​jdx in #​8686
  • (github) rename_exe renames correct binary when archive contains multiple executables by @​jdx in #​8700
  • (implode) include system data dir in implode cleanup by @​jdx in #​8696
  • (install) skip GitHub API calls for aqua tools in --locked mode by @​jdx in #​8679
  • (install) skip redundant provenance verification when lockfile has integrity data by @​jdx in #​8688
  • (lock) respect existing platforms in lockfile when running mise lock by @​jdx in #​8708
  • (lock) skip global config lockfile by default by @​jdx in #​8707
  • (node) expand tilde in default_packages_file path by @​jdx in #​8709
  • (shell) error when no version specified instead of silent no-op by @​jdx in #​8693
  • (shim) detect shims by checking shims directory instead of binary name by @​jdx in #​8694
  • (task) inherit task_config.dir for included TOML and file tasks by @​jdx in #​8689
  • (task) strip inline args when validating run.tasks references by @​jdx in #​8701
  • (task) include idiomatic version files in monorepo task toolset by @​jdx in #​8702
  • (task) improve error message when task files are not executable by @​jdx in #​8705
  • (test) update vfox provenance test for checksum-backed skip by @​jdx in #​8703
  • improve usage spec element support in tasks by @​nkakouros in #​8623
  • make env plugin (Module) vars available in Tera template context by @​victor-founder in #​8682
  • respect MISE_COLOR=0 for color_eyre error output by @​jdx in #​8690
  • add windows support for usage tool registry by @​jdx in #​8713
📚 Documentation
📦 Registry
New Contributors

v2026.3.10

Compare Source

🐛 Bug Fixes
📚 Documentation
🧪 Testing
📦️ Dependency Updates
📦 Registry
New Contributors
📦 Aqua Registry Updates
New Packages (8)
Updated Packages (8)

v2026.3.9

Compare Source

🚀 Features
🐛 Bug Fixes
  • (aqua) expose main binary when files field is empty and symlink_bins is enabled by @​AlexanderTheGrey in #​8550
  • (env) redact secrets in mise set listing and task-specific env by @​jdx in #​8583
  • (prepare) install config tools before running prepare steps by @​jdx in #​8582
  • (task) allow ctrl-c to interrupt tool downloads during mise run by @​jdx in #​8571
  • (tasks) add file task header parser support for spaces around = by @​roele in #​8574
📚 Documentation
📦️ Dependency Updates
📦 Registry
Chore
New Contributors
📦 Aqua Registry Updates
New Packages (6)
Updated Packages (2)

v2026.3.8

Compare Source

🐛 Bug Fixes
  • (backend) skip cosign provenance in lockfile for opts-only aqua tools by @​jdx in #​8559
  • (exec) resolve wrapper recursion when shims are in PATH by @​jdx in #​8560
📦 Registry
Chore
New Contributors
📦 Aqua Registry Updates
New Packages (1)
Updated Packages (8)

v2026.3.7

Compare Source

🐛 Bug Fixes
New Contributors
📦 Aqua Registry Updates
New Packages (1)
Updated Packages (7)

v2026.3.6

Compare Source

🐛 Bug Fixes
  • (activate) reorder shims to front of PATH on re-source in fish by @​jdx in #​8534
  • (backend) strip mise shims from dependency_env PATH to prevent fork bomb by @​pose in #​8475
  • (github) resolve "latest" version correctly via GitHub API by @​jdx in #​8532
  • (lock) set env tags and clarify lockfile docs by @​jdx in #​8519
  • (lock) use separate mise..lock files instead of env tags by @​jdx in #​8523
  • (task) include args in task output prefix and truncate long prefixes by @​jdx in #​8533
  • (task) only include args in task prefix when disambiguating duplicates by @​jdx in #​8536
  • (test) pin goreleaser version in attestation e2e test by @​jdx in #​8518
  • (windows) env._.source needs to run bash.exe on Windows (fix #​6513) by @​pjeby in #​8520
  • handle locked .exe shims on Windows during reshim by @​davireis in #​8517
🚜 Refactor
  • (prepare) remove touch_outputs and update docs to reflect blake3 hashing by @​jdx in #​8535
📚 Documentation
  • (docker) replace jdxcode/mise image with curl install, update to debian:13-slim by @​jdx in #​8526
  • fix "gzip: stdin is encrypted" error in shell tricks cookbook by @​pjeby in #​8512
📦 Registry
New Contributors
📦 Aqua Registry Updates
New Packages (6)
Updated Packages (1)

v2026.3.5

Compare Source

🚀 Features
🐛 Bug Fixes
  • (env) skip remote version fetching for "latest" in prefer-offline mode by @​jdx in #​8500
  • (tasks) deduplicate shared deps across task delegation by @​vadimpiven in #​8497
  • (windows) correctly identify mise binary without extension by @​jdx in #​8503
🚜 Refactor
  • (core) migrate cmd! callers to async with kill_on_drop by @​jdx in a63f7d2
📦 Registry
Chore
📦 Aqua Registry Updates
New Packages (1)

v2026.3.4

Compare Source

🚀 Features
🐛 Bug Fixes
  • (github) use registry platform options during install by @​jdx in #​8492
  • (http) store tool opts as native TOML to fix platform switching by @​jdx in #​8448
  • (installer) error if MISE_INSTALL_PATH is a directory by @​jdx in #​8468
  • (prepare) resolve sources/outputs relative to dir when set by @​jdx in #​8472
  • (ruby) fetch precompiled binary by release tag instead of listing all releases by @​jdx in #​8488
  • (schema) support structured objects in task depends by @​risu729 in #​8463
  • (task) replace println!/eprintln! with calm_io in task output macros by @​vmaleze in #​8485
  • handle scoped npm package names without backend prefix by @​jdx in #​8477
📦️ Dependency Updates
📦 Registry
New Contributors
📦 Aqua Registry Updates
New Packages (5)
Updated Packages (6)

v2026.3.3

Compare Source

🐛 Bug Fixes
  • (installer) guard zstd archive selection on zstd binary availability by @​octo in #​8460
New Contributors

v2026.3.2

Compare Source

🚀 Features
🐛 Bug Fixes
🚜 Refactor
🧪 Testing
📦 Registry
📦 Aqua Registry Updates
New Packages (1)

v2026.3.1

Compare Source

🐛 Bug Fixes

v2026.3.0

Compare Source

🚀 Features
🐛 Bug Fixes
  • (aqua) restore bin_paths disk cache with fresh_file invalidation by @​jdx in #​8398
  • (idiomatic) use generic parser for idiomatic files by @​risu729 in #​8171
  • (install) apply precompiled options to all platforms in lockfile by @​jdx in #​8396
  • (install) normalize "v" prefix when matching lockfile versions by @​jdx in #​8413
  • (prepare) improve git submodule parser and fix check_staleness error handling by @​jdx in #​8412
  • (python) respect precompiled settings in lock file generation by @​jdx in #​8399
  • (python) clarify uv_venv_auto docs + prevent uv shim recursion in venv creation by @​halms in #​8402
  • (task) remove deprecated # mise task header syntax by @​jdx in #​8403
  • (vfox) avoid eager metadata loading during config file detection by @​jdx in #​8397
  • clarify GitHub attestations to be artifact ones by @​scop in #​8394
  • ignore comments in idiomatic version files by @​iloveitaly in #​7682
🚜 Refactor
📚 Documentation

v2026.2.24

Compare Source

🐛 Bug Fixes
  • (aqua) remove unnecessary bin_paths disk cache by @​jdx in #​8383
  • (hooks) render tera templates and fix output masking by @​jdx in #​8385
  • (install) improve error when registry tool has no supported backends by @​jdx in #​8388
  • (python) remove deprecated venv_auto_create setting by @​jdx in #​8384

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link
Copy Markdown

Renovate PR Review Results

⚖️ Safety Assessment: ✅ Safe

🔍 Release Content Analysis

Version Jump: v2026.2.23 → v2026.3.16 (spans 21 releases from March 2-27, 2026)

Major Changes:

  • Security Enhancements: Lockfile provenance tracking and verification (v2026.3.12, v2026.3.5)
  • Task System Improvements: Interactive task support, args/env in run entries, monorepo task variables
  • Prepare Step Features: Git submodule support, blake3 content-hash checking, dependency ordering
  • Python Backend: Improved precompiled binary handling with checksum verification, freethreaded build exclusion
  • GitHub Backend: Enhanced token management (credential_command, github_tokens.toml, gh CLI integration)
  • Environment Variables: Better redaction support, multiple -E flag support

Breaking Changes:

  • ❌ Removed python.venv_auto_create setting (v2026.3.8) - deprecated feature
  • ❌ Removed old # mise task header syntax (v2026.3.0) - deprecated feature
  • ⚠️ Lockfile format changes to support env-specific files and provenance metadata (backward compatible for reading)

Security Fixes:

  • GitHub attestation verification improvements
  • Cosign provenance checking enhancements
  • Lockfile integrity tracking to prevent provenance loss during upgrades
  • RUSTSEC-2026-0066 (tar advisory) addressed

Bug Fixes: 100+ bug fixes across aqua, github, vfox, python, ruby, node, rust, and other backends

🎯 Impact Scope Investigation

Usage Analysis:

  1. Dockerfile Usage (Primary concern):

    • Downloads mise binary directly from GitHub releases
    • Uses mise use -g <runtime>@<version> for Node.js, Ruby, Go, Python, Rust installation
    • Uses mise settings ruby.compile=false configuration
    • Sets MISE_DATA_DIR="/mise"
    • ✅ All commands remain stable and unchanged
  2. mise.toml Configuration:

    • Defines tools: go@1.26.1, golangci-lint@2.10.1 (aqua), lefthook@2.1.4 (aqua), hadolint@2.14.0 (aqua)
    • ✅ Aqua backend compatibility confirmed in release notes
  3. CI/CD Integration:

    • Uses jdx/mise-action@v3.6.3 in GitHub Actions workflows
    • ✅ No changes to GitHub Action integration

Deprecated Feature Check:

  • venv_auto_create: NOT USED in this project
  • ✅ Old task header syntax: NO task files present
  • ✅ No lockfiles currently in use (backward compatible anyway)

Dependency Impact:

  • ✅ No impact on other Go dependencies
  • ✅ Runtime version management unchanged (Node 24.14.0, Ruby 3.4.8, Go 1.26.0, Python 3.13.12, Rust 1.94.0)

💡 Recommended Actions

Immediate Actions:

  1. Merge this PR - The update is safe and backward compatible
  2. No code changes required - Project doesn't use any deprecated features
  3. CI will validate - Existing CI pipeline will verify compatibility through lint, build, unit tests, and E2E tests

Post-Merge Verification:

  1. Monitor CI/CD pipeline execution after merge
  2. Verify Docker build completes successfully with new mise version
  3. Confirm E2E tests pass on both ubuntu-latest and ubuntu-24.04-arm runners

Optional Enhancements (Not required for this PR):

  • Consider adopting lockfile support for reproducible builds (new provenance features)
  • Explore new task system features for potential workflow improvements
  • Review security enhancements for production use cases

🔗 Reference Links

Generated by koki-develop/claude-renovate-review

@koki-develop koki-develop merged commit e91347b into main Mar 30, 2026
6 of 8 checks passed
@koki-develop koki-develop deleted the renovate/jdx-mise-2026.x branch March 30, 2026 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant