Repository navigation
Comparing changes
Open a pull request
base repository: jdx/mise-action
base: v5.0.0
head repository: jdx/mise-action
compare: v5.0.1
- 6 commits
- 11 files changed
- 4 contributors
Commits on Sep 29, 2026
-
chore(deps): update dependency aube to latest (#634)
<!-- entire-trail-link-start --> https://entire.io/gh/jdx/mise-action/trails/11 <!-- entire-trail-link-end --> This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [aube](https://redirect.github.com/jdx/aube) | tools | minor | `2.3.0` → `v2.6.0` | --- ### Release Notes <details> <summary>jdx/aube (aube)</summary> ### [`v2.6.0`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.6.0): : Maintenance release [Compare Source](https://redirect.github.com/jdx/aube/compare/v2.5.1...v2.6.0) There are no user-facing changes in the commit range for this release. **Full Changelog**: <aubepkg/aube@f43833c...v2.6.0> #### 💚 Sponsor aube aube is built and maintained by [@​jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If aube saves your team install time or CI minutes, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep aube fast, free, and independent. ### [`v2.5.1`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.5.1): : Faster repeated fresh installs and faster startup on Linux [Compare Source](https://redirect.github.com/jdx/aube/compare/v2.5.0...v2.5.1) Repeated fresh installs skip redundant OSV lookups, and the Linux release binaries start a little faster. #### Changed - **Faster repeated fresh installs** ([#​1631](https://redirect.github.com/aubepkg/aube/pull/1631) by [@​jdx](https://redirect.github.com/jdx)): When the OSV Bloom filter flags a package that turns out to have no malicious advisory, aube used to confirm it with a live OSV query on every install. That added about 220–250 ms each time. aube now caches a clean result for 30 seconds. A cached result is reused only when both the exact package/version pairs and the validated Bloom filter match. On a warmed Svelte fixture, installing with `node_modules` and `aube-lock.yaml` removed went from a 346 ms median to 107 ms. - Failed OSV queries, failed Bloom filter refreshes and confirmed malicious hits are never cached. - Explicit `add`/`update`/`dlx` checks, `advisoryCheck = required` and `advisoryCheckEveryInstall = true` still query OSV live every time. - **Tradeoff:** if a malicious-package advisory is published for a version that was just cleared, a repeated ordinary install may take up to 30 seconds to catch it. - **About 0.6 ms faster startup on Linux** ([#​1625](https://redirect.github.com/aubepkg/aube/pull/1625) by [@​jdx](https://redirect.github.com/jdx)): The Linux GNU release binaries (x86\_64 and aarch64) for `aube`, `aubr` and `aubx` are now linked as non-PIE. The loader no longer has to patch about 56k pointers at each launch, so `aube --version` drops from about 2.2 ms to 1.6 ms. - **Tradeoff:** ASLR no longer randomizes aube's own code and data. The heap, stack and shared libraries are still randomized. - musl, macOS and Windows builds are unchanged, as are `cargo install`, source builds and the PPA/COPR packages. **Full Changelog**: <aubepkg/aube@98be8d1...v2.5.1> #### 💚 Sponsor aube aube is built and maintained by [@​jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If aube saves your team install time or CI minutes, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep aube fast, free, and independent. ### [`v2.5.0`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.5.0): : Choose range or latest per package in `aube update --interactive` [Compare Source](https://redirect.github.com/jdx/aube/compare/v2.4.0...v2.5.0) `aube update --interactive` now lets you pick, for each package, whether to keep the current version, move to the newest version its range allows, or jump to `latest`. Repeated frozen installs and fresh installs without a lockfile are also faster, and a reinstall that failed after you deleted the cache and lockfile now works. #### Added - **Per-package version choice in `aube update --interactive`** ([#​1612](https://redirect.github.com/aubepkg/aube/pull/1612) by [@​jdx](https://redirect.github.com/jdx)): The picker used to be one checkbox per dependency, with the target set by flags. It is now a table, like Yarn Berry's `upgrade-interactive`. Each row shows the current version, the newest version the range allows, and the registry's `latest`. Use ↑/↓ to move between rows and ←/→ to choose a version. Rows left on Current are skipped, and `/` filters by name. Closes [#​1611](https://redirect.github.com/aubepkg/aube/issues/1611). ``` $ aube update -i Choose which dependencies to update Current Range Latest > chalk [•] ^4.1.2 [ ] ^6.0.0 is-number [•] ^6.0.0 [ ] ^7.0.0 ms [ ] 2.0.0 [•] 2.1.3 semver [ ] 7.5.0 [•] 7.8.5 ↑/↓/k/j up/down • ←/→/h/l choose • / filter • enter confirm ``` - Rows start on Range, or on Latest with `--latest`. Pressing Enter right away does the same thing as the non-interactive command. - Updates keep the manifest's range operator. Exact pins are now listed: each one is offered the newest release its caret range would allow, and it stays an exact pin after the update. `-E` still forces exact pins. - `--no-save` hides Latest and pin bumps, because both would rewrite `package.json`. - Latest is offered only when it is newer than the installed version, so the picker never offers a downgrade. - With `update -r -i`, the version you choose for a shared catalog entry is used for later workspace packages without asking again. - Rows no longer show the dependency section (`dependencies` / `devDependencies`). #### Changed - **Faster repeated frozen installs** ([#​1615](https://redirect.github.com/aubepkg/aube/pull/1615) by [@​jdx](https://redirect.github.com/jdx)): Standalone projects can now reuse the installed state when nothing has changed. This applies to projects with registry dependencies and no declared patches, installed with an explicit `--frozen-lockfile` and lifecycle scripts disabled (for example `aube install --frozen-lockfile --offline --ignore-scripts`). On the benchmark fixture, a no-op install went from about 82 ms to about 7 ms. The freshness check hashes the lockfile and manifest contents, so a change is caught even when file size and modification time stay the same. A missing dependency link also counts as a change. Workspaces, patches, local sources, enabled scripts, custom lockfile locations and active per-install advisory policies still go through full validation. - **Faster advisory checks on fresh installs** ([#​1616](https://redirect.github.com/aubepkg/aube/pull/1616) by [@​jdx](https://redirect.github.com/jdx)): A fresh install without a lockfile used to query OSV for every resolved public-npm package. Under the default `advisoryCheck: on`, graphs with more than 10 distinct package/version pairs are now screened with the advisory Bloom filter first, and only probable hits are checked against the live API. On the benchmark fixtures this cut fresh install time by 36–67%. - Full live checks are still used for smaller graphs, for explicit `aube add` / `aube update`, for transient `aube dlx` installs, and with `advisoryCheck: required` or `advisoryCheckEveryInstall: true`. - If the filter can't be refreshed or validated, every package is checked live. - The filter cache refreshes every 15 minutes, so a newly published advisory may take up to that long to be caught. #### Fixed - **"missing package index" after deleting the cache and lockfile** ([#​1613](https://redirect.github.com/aubepkg/aube/pull/1613) by [@​jdx](https://redirect.github.com/jdx)): A reinstall could fail with this error if you had deleted aube's cache/store and the root lockfile but kept `node_modules`. Now an existing package directory is reused only when its dependency subtree matches the previous install and the directory still exists. Anything else is looked up in the store again, or downloaded again, before linking. **Full Changelog**: <aubepkg/aube@d79acaa...v2.5.0> #### 💚 Sponsor aube aube is built and maintained by [@​jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If aube saves your team install time or CI minutes, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep aube fast, free, and independent. ### [`v2.4.0`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.4.0): : Reuse node_modules/.aube-lock.yaml when the lockfile is missing [Compare Source](https://redirect.github.com/jdx/aube/compare/v2.3.0...v2.4.0) `aube install` can now rebuild a deleted lockfile from a hidden copy kept in `node_modules`, so it doesn't re-resolve from the registry. This release also makes cold installs on Linux faster and lighter on memory, and fixes lifecycle scripts on Windows and a workspace `aube update` that could drop members from the lockfile. #### Added - **Hidden lockfile in `node_modules`** ([#​1594](https://redirect.github.com/aubepkg/aube/pull/1594) by [@​jdx](https://redirect.github.com/jdx)): Every install now writes a copy of the resolved graph to `node_modules/.aube-lock.yaml`. If the project has no lockfile of any supported kind, `aube install` starts from that copy, as pnpm does with its current lockfile. If the manifests haven't changed, the graph is reused with no resolve. If they have changed, only the specs that changed are resolved again, and the other packages keep their locked versions. `aube-lock.yaml` is then written again. ```console $ aube install # writes aube-lock.yaml + node_modules/.aube-lock.yaml $ rm aube-lock.yaml $ aube install # seeds from node_modules/.aube-lock.yaml, no registry resolve ``` - `--frozen-lockfile` and `aube ci` still fail when there is no lockfile. - `--no-frozen-lockfile` ignores the hidden copy. - In auto-CI mode (`CI=true` with no explicit flags), an install that seeds from the hidden copy is treated as prefer-frozen. - If the hidden copy is broken, aube shows `WARN_AUBE_HIDDEN_LOCKFILE_BROKEN` and resolves normally. - The hidden copy is not used with `lockfile=false`, which also deletes any existing copy, or with `sharedWorkspaceLockfile=false`. It is also skipped for reuse installs from npm, yarn or bun lockfiles. #### Changed - **Faster, lighter cold installs on Linux** ([#​1598](https://redirect.github.com/aubepkg/aube/pull/1598), [#​1603](https://redirect.github.com/aubepkg/aube/pull/1603), [#​1604](https://redirect.github.com/aubepkg/aube/pull/1604), [#​1605](https://redirect.github.com/aubepkg/aube/pull/1605) by [@​jdx](https://redirect.github.com/jdx)): - On Linux, the blocking thread pool now defaults to 8 threads instead of 128. On the benchmark fixture this cut peak memory from about 1.5 GB to about 400 MB and reduced kernel CPU time. `AUBE_TOKIO_BLOCKING` still overrides the default, and macOS and Windows keep 128. - Small tarballs (up to 1 MiB) are downloaded in full before their store import begins, so an import no longer ties up a thread while it waits on the network. Memory for these buffered downloads is capped at 64 MiB in total. - Installs with the global virtual store no longer read back dependency links they just wrote. #### Fixed - **Windows lifecycle scripts failing with `EISDIR: illegal operation on a directory, lstat 'C:'`** ([#​1591](https://redirect.github.com/aubepkg/aube/pull/1591) by [@​jdx](https://redirect.github.com/jdx)): This affected scripts that start node through a `.bin` shim (for example `node-gyp-build`) during `aube add`, `remove`, `update`, `dedupe` and `ci`, and during installs from embedding hosts such as mise's `npm:` backend. The install root and the Node-API embedding's project directory no longer carry the `\\?\` verbatim prefix. Fixes [#​1590](https://redirect.github.com/aubepkg/aube/issues/1590). - **`aube update` at a workspace root dropping workspace members from `aube-lock.yaml`** ([#​1579](https://redirect.github.com/aubepkg/aube/pull/1579) by [@​jdx](https://redirect.github.com/jdx)): With a shared lockfile, running `aube update` or `aube update -w` at the root could delete every workspace member's entry in `aube-lock.yaml`. Member entries, their packages, patch hashes and catalog snapshots are now kept, and only the root's direct dependencies are updated. `aube install` also treats a workspace member that declares dependencies but has no entry in the lockfile as stale, so installing again repairs lockfiles already damaged by this bug. **Full Changelog**: <aubepkg/aube@v2.3.0...v2.4.0> #### 💚 Sponsor aube aube is built and maintained by [@​jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If aube saves your team install time or CI minutes, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep aube fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Chicago) - Branch creation - Only on Tuesday (`* * * * 2`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/jdx/mise-action). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 342b4c0 - Browse repository at this point
Copy the full SHA 342b4c0View commit details -
chore(deps): update github actions (#633)
<!-- entire-trail-link-start --> https://entire.io/gh/jdx/mise-action/trails/10 <!-- entire-trail-link-end --> This PR contains the following updates: | Package | Type | Update | Change | Pending | |---|---|---|---|---| | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | patch | `v4.38.0` → `v4.38.1` | `v4.38.2` | | [jdx/renovate-config](https://redirect.github.com/jdx/renovate-config) | workflow | patch | `v1.0.0` → `v1.0.1` | | --- ### Release Notes <details> <summary>github/codeql-action (github/codeql-action)</summary> ### [`v4.38.1`](https://redirect.github.com/github/codeql-action/releases/tag/v4.38.1) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.38.0...v4.38.1) - The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. [#​4146](https://redirect.github.com/github/codeql-action/pull/4146) </details> <details> <summary>jdx/renovate-config (jdx/renovate-config)</summary> ### [`v1.0.1`](https://redirect.github.com/jdx/renovate-config/releases/tag/v1.0.1): : Stop Renovate's npm and pep621 managers from relocking mise sidecars [Compare Source](https://redirect.github.com/jdx/renovate-config/compare/v1.0.0...v1.0.1) The shared preset now keeps Renovate's npm and pep621 managers out of `mise lock` dependency sidecars. Before this, Renovate and the `mise-lock` workflow kept overwriting each other's changes. ##### Fixed - **mise lock sidecars are no longer relocked by other managers.** `mise lock` pins npm and Python tool dependencies in sidecars under `.mise/locks/` or `.config/mise/locks/` and stores a digest of each one in `mise.lock`. Renovate's npm and pep621 managers were treating these sidecars' `package.json` and `pyproject.toml` as regular package files. Lock file maintenance then rewrote the sidecar lockfiles (for example with `uv lock --upgrade`) without updating the digests in `mise.lock`. The `mise-lock` workflow fixed the digests, and Renovate overwrote the fix on its next run. The preset now adds `**/.mise/locks/**` and `**/.config/mise/locks/**` to `ignorePaths`, so only the mise manager updates sidecars. Repos that extend the preset get this fix right away because the preset is read from `main`. ([#​30](https://redirect.github.com/jdx/renovate-config/issues/30), [@​jdx](https://redirect.github.com/jdx)) `ignorePaths` doesn't merge, so the preset now lists the defaults from `config:recommended`'s `:ignoreModulesAndTests` (`node_modules`, `bower_components`, `vendor`, `examples`, `__tests__`, `test`, `tests`, `__fixtures__`) alongside the two mise paths. If your repo sets its own `ignorePaths`, that list replaces the preset's. To keep the fix, add the two mise sidecar globs to your list. **Full Changelog**: <jdx/renovate-config@v1.0.0...v1.0.1> </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Chicago) - Branch creation - Only on Tuesday (`* * * * 2`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/jdx/mise-action). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for ec2665b - Browse repository at this point
Copy the full SHA ec2665bView commit details -
chore(deps): update dependency communique to latest (#635)
<!-- entire-trail-link-start --> https://entire.io/gh/jdx/mise-action/trails/12 <!-- entire-trail-link-end --> This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [communique](https://redirect.github.com/jdx/communique) | tools | minor | `1.4.2` → `v1.5.0` | --- ### Release Notes <details> <summary>jdx/communique (communique)</summary> ### [`v1.5.0`](https://redirect.github.com/jdx/communique/releases/tag/v1.5.0): : Maintenance release [Compare Source](https://redirect.github.com/jdx/communique/compare/v1.4.2...v1.5.0) There are no commits between the previous release point and v1.5.0, so this release has no user-facing changes to report. **Full Changelog**: <jdx/communique@9c54a36...v1.5.0> #### 💚 Sponsor communique communique is built and maintained by [@​jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If communique drafts your release notes or changelogs, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep communique fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Chicago) - Branch creation - Only on Tuesday (`* * * * 2`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/jdx/mise-action). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c75796c - Browse repository at this point
Copy the full SHA c75796cView commit details
Commits on Sep 30, 2026
-
chore(deps): update dependency aube to latest (#636)
<!-- entire-trail-link-start --> https://entire.io/gh/jdx/mise-action/trails/13 <!-- entire-trail-link-end --> This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [aube](https://redirect.github.com/jdx/aube) | tools | patch | `2.6.0` → `v2.6.1` | --- ### Release Notes <details> <summary>jdx/aube (aube)</summary> ### [`v2.6.1`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.6.1): : Maintenance release [Compare Source](https://redirect.github.com/jdx/aube/compare/v2.6.0...v2.6.1) The commit range for this release has no user-facing changes. **Full Changelog**: <aubepkg/aube@bd94e42...v2.6.1> #### 💚 Sponsor aube aube is built and maintained by [@​jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If aube saves your team install time or CI minutes, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep aube fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Chicago) - Branch creation - Only on Tuesday (`* * * * 2`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled because a matching PR was automerged previously. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/jdx/mise-action). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for baf7eb4 - Browse repository at this point
Copy the full SHA baf7eb4View commit details -
fix: verify cached mise before execution (#637)
<!-- entire-trail-link-start --> https://entire.io/gh/jdx/mise-action/trails/14 <!-- entire-trail-link-end --> ## Summary Verify a pre-existing `mise` executable against the requested checksum or the signed release checksums before the action can invoke it. If the executable does not match, remove it and reinstall the requested release. This fixes a known, privately tracked security report. The implementation intentionally omits reproduction details; the reporter attribution and full report remain in the private advisory. ## Validation - `aube run format:check` - `aube run lint` - `aube test` - `aube run package` - isolated regression reproduction: a prewritten marker was invoked before the prior integrity check; with this change existing binaries are verified before any invocation <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **High Risk** > Changes how the GitHub Action trusts and executes cached `mise` binaries—a security-sensitive supply-chain path—with intentional behavior changes around version upgrades and latest-release selection. > > **Overview** > **Verifies any existing `mise` binary before the action runs it**, using the configured `sha256`, signed release checksums, and the requested version. On mismatch it deletes the binary and performs a full install instead of invoking or `self-update`ing untrusted cache. > > **Setup behavior changes:** version mismatches no longer go through `mise self-update`; reinstall handles the requested release. When no version is pinned, the action still resolves the latest release and re-validates an on-disk binary rather than skipping install solely because `mise` exists. > > **CI** adds regression coverage: reusing a verified install (`install: false`), swapping cached versions, and reusing a pre-minisign release without downloads when checksum verification passes. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit a981fde. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Existing `mise` installations are checked against the requested version and available checksum information. A verification mismatch triggers a fresh installation. * **Behavior Changes** * The latest release is selected when no version is specified, even if `mise` is already installed. * When the installed version differs from the requested version, that version is installed instead of using `mise self-update`. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Configuration menu - View commit details
-
Copy full SHA for c4102d4 - Browse repository at this point
Copy the full SHA c4102d4View commit details -
<!-- entire-trail-link-start --> https://entire.io/gh/jdx/mise-action/trails/15 <!-- entire-trail-link-end --> --- ## [5.0.1](https://github.com/jdx/mise-action/compare/v5.0.0..v5.0.1) - 2026-09-30 ### 🐛 Bug Fixes - verify cached mise before execution (#637) by [@jdx](https://github.com/jdx) in [#637](#637) <!-- generated by git-cliff --> <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Only version and changelog updates; no runtime code changes in this diff. > > **Overview** > **Release v5.0.1** — bumps `package.json` from **5.0.0** to **5.0.1** and adds the corresponding **CHANGELOG** section dated 2026-09-30. > > The release notes document one bug fix already merged via [#637](#637): **verify cached mise before execution** (integrity check on a restored/cached binary before the action runs it). This PR does not change application source; it only cuts the release metadata. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit bbee2b3. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: mise-en-dev <123107610+mise-en-dev@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7a4e45a - Browse repository at this point
Copy the full SHA 7a4e45aView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v5.0.0...v5.0.1