Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: jdx/mise-action
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v5.0.0
Choose a base ref
...
head repository: jdx/mise-action
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v5.0.1
Choose a head ref
  • 6 commits
  • 11 files changed
  • 4 contributors

Commits on Sep 29, 2026

  1. chore(deps): update dependency aube to latest (#634)

    <!-- entire-trail-link-start -->
    https://entire.io/gh/jdx/mise-action/trails/11
    <!-- entire-trail-link-end -->
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [aube](https://redirect.github.com/jdx/aube) | tools | minor | `2.3.0`
    → `v2.6.0` |
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>jdx/aube (aube)</summary>
    
    ###
    [`v2.6.0`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.6.0):
    : Maintenance release
    
    [Compare
    Source](https://redirect.github.com/jdx/aube/compare/v2.5.1...v2.6.0)
    
    There are no user-facing changes in the commit range for this release.
    
    **Full Changelog**:
    <aubepkg/aube@f43833c...v2.6.0>
    
    #### 💚 Sponsor aube
    
    aube is built and maintained by
    [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer
    at [**entire.io**](https://entire.io/), the title sponsor of his open
    source work.
    
    If aube saves your team install time or CI minutes, please consider
    becoming an [individual or company
    sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing
    development and helps keep aube fast, free, and independent.
    
    ###
    [`v2.5.1`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.5.1):
    : Faster repeated fresh installs and faster startup on Linux
    
    [Compare
    Source](https://redirect.github.com/jdx/aube/compare/v2.5.0...v2.5.1)
    
    Repeated fresh installs skip redundant OSV lookups, and the Linux
    release binaries start a little faster.
    
    #### Changed
    
    - **Faster repeated fresh installs**
    ([#&#8203;1631](https://redirect.github.com/aubepkg/aube/pull/1631) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): When the OSV Bloom
    filter flags a package that turns out to have no malicious advisory,
    aube used to confirm it with a live OSV query on every install. That
    added about 220–250 ms each time. aube now caches a clean result for 30
    seconds. A cached result is reused only when both the exact
    package/version pairs and the validated Bloom filter match. On a warmed
    Svelte fixture, installing with `node_modules` and `aube-lock.yaml`
    removed went from a 346 ms median to 107 ms.
    - Failed OSV queries, failed Bloom filter refreshes and confirmed
    malicious hits are never cached.
    - Explicit `add`/`update`/`dlx` checks, `advisoryCheck = required` and
    `advisoryCheckEveryInstall = true` still query OSV live every time.
    - **Tradeoff:** if a malicious-package advisory is published for a
    version that was just cleared, a repeated ordinary install may take up
    to 30 seconds to catch it.
    - **About 0.6 ms faster startup on Linux**
    ([#&#8203;1625](https://redirect.github.com/aubepkg/aube/pull/1625) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): The Linux GNU release
    binaries (x86\_64 and aarch64) for `aube`, `aubr` and `aubx` are now
    linked as non-PIE. The loader no longer has to patch about 56k pointers
    at each launch, so `aube --version` drops from about 2.2 ms to 1.6 ms.
    - **Tradeoff:** ASLR no longer randomizes aube's own code and data. The
    heap, stack and shared libraries are still randomized.
    - musl, macOS and Windows builds are unchanged, as are `cargo install`,
    source builds and the PPA/COPR packages.
    
    **Full Changelog**:
    <aubepkg/aube@98be8d1...v2.5.1>
    
    #### 💚 Sponsor aube
    
    aube is built and maintained by
    [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer
    at [**entire.io**](https://entire.io/), the title sponsor of his open
    source work.
    
    If aube saves your team install time or CI minutes, please consider
    becoming an [individual or company
    sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing
    development and helps keep aube fast, free, and independent.
    
    ###
    [`v2.5.0`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.5.0):
    : Choose range or latest per package in `aube update --interactive`
    
    [Compare
    Source](https://redirect.github.com/jdx/aube/compare/v2.4.0...v2.5.0)
    
    `aube update --interactive` now lets you pick, for each package, whether
    to keep the current version, move to the newest version its range
    allows, or jump to `latest`. Repeated frozen installs and fresh installs
    without a lockfile are also faster, and a reinstall that failed after
    you deleted the cache and lockfile now works.
    
    #### Added
    
    - **Per-package version choice in `aube update --interactive`**
    ([#&#8203;1612](https://redirect.github.com/aubepkg/aube/pull/1612) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): The picker used to be
    one checkbox per dependency, with the target set by flags. It is now a
    table, like Yarn Berry's `upgrade-interactive`. Each row shows the
    current version, the newest version the range allows, and the registry's
    `latest`. Use ↑/↓ to move between rows and ←/→ to choose a version. Rows
    left on Current are skipped, and `/` filters by name. Closes
    [#&#8203;1611](https://redirect.github.com/aubepkg/aube/issues/1611).
    
      ```
      $ aube update -i
      Choose which dependencies to update
                    Current     Range      Latest
       > chalk      [•] ^4.1.2             [ ] ^6.0.0
         is-number  [•] ^6.0.0             [ ] ^7.0.0
         ms         [ ] 2.0.0   [•] 2.1.3
         semver     [ ] 7.5.0   [•] 7.8.5
      ↑/↓/k/j up/down • ←/→/h/l choose • / filter • enter confirm
      ```
    
    - Rows start on Range, or on Latest with `--latest`. Pressing Enter
    right away does the same thing as the non-interactive command.
    - Updates keep the manifest's range operator. Exact pins are now listed:
    each one is offered the newest release its caret range would allow, and
    it stays an exact pin after the update. `-E` still forces exact pins.
    - `--no-save` hides Latest and pin bumps, because both would rewrite
    `package.json`.
    - Latest is offered only when it is newer than the installed version, so
    the picker never offers a downgrade.
    - With `update -r -i`, the version you choose for a shared catalog entry
    is used for later workspace packages without asking again.
    - Rows no longer show the dependency section (`dependencies` /
    `devDependencies`).
    
    #### Changed
    
    - **Faster repeated frozen installs**
    ([#&#8203;1615](https://redirect.github.com/aubepkg/aube/pull/1615) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): Standalone projects can
    now reuse the installed state when nothing has changed. This applies to
    projects with registry dependencies and no declared patches, installed
    with an explicit `--frozen-lockfile` and lifecycle scripts disabled (for
    example `aube install --frozen-lockfile --offline --ignore-scripts`). On
    the benchmark fixture, a no-op install went from about 82 ms to about 7
    ms. The freshness check hashes the lockfile and manifest contents, so a
    change is caught even when file size and modification time stay the
    same. A missing dependency link also counts as a change. Workspaces,
    patches, local sources, enabled scripts, custom lockfile locations and
    active per-install advisory policies still go through full validation.
    - **Faster advisory checks on fresh installs**
    ([#&#8203;1616](https://redirect.github.com/aubepkg/aube/pull/1616) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): A fresh install without
    a lockfile used to query OSV for every resolved public-npm package.
    Under the default `advisoryCheck: on`, graphs with more than 10 distinct
    package/version pairs are now screened with the advisory Bloom filter
    first, and only probable hits are checked against the live API. On the
    benchmark fixtures this cut fresh install time by 36–67%.
    - Full live checks are still used for smaller graphs, for explicit `aube
    add` / `aube update`, for transient `aube dlx` installs, and with
    `advisoryCheck: required` or `advisoryCheckEveryInstall: true`.
    - If the filter can't be refreshed or validated, every package is
    checked live.
    - The filter cache refreshes every 15 minutes, so a newly published
    advisory may take up to that long to be caught.
    
    #### Fixed
    
    - **"missing package index" after deleting the cache and lockfile**
    ([#&#8203;1613](https://redirect.github.com/aubepkg/aube/pull/1613) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): A reinstall could fail
    with this error if you had deleted aube's cache/store and the root
    lockfile but kept `node_modules`. Now an existing package directory is
    reused only when its dependency subtree matches the previous install and
    the directory still exists. Anything else is looked up in the store
    again, or downloaded again, before linking.
    
    **Full Changelog**:
    <aubepkg/aube@d79acaa...v2.5.0>
    
    #### 💚 Sponsor aube
    
    aube is built and maintained by
    [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer
    at [**entire.io**](https://entire.io/), the title sponsor of his open
    source work.
    
    If aube saves your team install time or CI minutes, please consider
    becoming an [individual or company
    sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing
    development and helps keep aube fast, free, and independent.
    
    ###
    [`v2.4.0`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.4.0):
    : Reuse node_modules/.aube-lock.yaml when the lockfile is missing
    
    [Compare
    Source](https://redirect.github.com/jdx/aube/compare/v2.3.0...v2.4.0)
    
    `aube install` can now rebuild a deleted lockfile from a hidden copy
    kept in `node_modules`, so it doesn't re-resolve from the registry. This
    release also makes cold installs on Linux faster and lighter on memory,
    and fixes lifecycle scripts on Windows and a workspace `aube update`
    that could drop members from the lockfile.
    
    #### Added
    
    - **Hidden lockfile in `node_modules`**
    ([#&#8203;1594](https://redirect.github.com/aubepkg/aube/pull/1594) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): Every install now
    writes a copy of the resolved graph to `node_modules/.aube-lock.yaml`.
    If the project has no lockfile of any supported kind, `aube install`
    starts from that copy, as pnpm does with its current lockfile. If the
    manifests haven't changed, the graph is reused with no resolve. If they
    have changed, only the specs that changed are resolved again, and the
    other packages keep their locked versions. `aube-lock.yaml` is then
    written again.
    
      ```console
    $ aube install # writes aube-lock.yaml + node_modules/.aube-lock.yaml
      $ rm aube-lock.yaml
    $ aube install # seeds from node_modules/.aube-lock.yaml, no registry
    resolve
      ```
    
    - `--frozen-lockfile` and `aube ci` still fail when there is no
    lockfile.
      - `--no-frozen-lockfile` ignores the hidden copy.
    - In auto-CI mode (`CI=true` with no explicit flags), an install that
    seeds from the hidden copy is treated as prefer-frozen.
    - If the hidden copy is broken, aube shows
    `WARN_AUBE_HIDDEN_LOCKFILE_BROKEN` and resolves normally.
    - The hidden copy is not used with `lockfile=false`, which also deletes
    any existing copy, or with `sharedWorkspaceLockfile=false`. It is also
    skipped for reuse installs from npm, yarn or bun lockfiles.
    
    #### Changed
    
    - **Faster, lighter cold installs on Linux**
    ([#&#8203;1598](https://redirect.github.com/aubepkg/aube/pull/1598),
    [#&#8203;1603](https://redirect.github.com/aubepkg/aube/pull/1603),
    [#&#8203;1604](https://redirect.github.com/aubepkg/aube/pull/1604),
    [#&#8203;1605](https://redirect.github.com/aubepkg/aube/pull/1605) by
    [@&#8203;jdx](https://redirect.github.com/jdx)):
    - On Linux, the blocking thread pool now defaults to 8 threads instead
    of 128. On the benchmark fixture this cut peak memory from about 1.5 GB
    to about 400 MB and reduced kernel CPU time. `AUBE_TOKIO_BLOCKING` still
    overrides the default, and macOS and Windows keep 128.
    - Small tarballs (up to 1 MiB) are downloaded in full before their store
    import begins, so an import no longer ties up a thread while it waits on
    the network. Memory for these buffered downloads is capped at 64 MiB in
    total.
    - Installs with the global virtual store no longer read back dependency
    links they just wrote.
    
    #### Fixed
    
    - **Windows lifecycle scripts failing with `EISDIR: illegal operation on
    a directory, lstat 'C:'`**
    ([#&#8203;1591](https://redirect.github.com/aubepkg/aube/pull/1591) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): This affected scripts
    that start node through a `.bin` shim (for example `node-gyp-build`)
    during `aube add`, `remove`, `update`, `dedupe` and `ci`, and during
    installs from embedding hosts such as mise's `npm:` backend. The install
    root and the Node-API embedding's project directory no longer carry the
    `\\?\` verbatim prefix. Fixes
    [#&#8203;1590](https://redirect.github.com/aubepkg/aube/issues/1590).
    - **`aube update` at a workspace root dropping workspace members from
    `aube-lock.yaml`**
    ([#&#8203;1579](https://redirect.github.com/aubepkg/aube/pull/1579) by
    [@&#8203;jdx](https://redirect.github.com/jdx)): With a shared lockfile,
    running `aube update` or `aube update -w` at the root could delete every
    workspace member's entry in `aube-lock.yaml`. Member entries, their
    packages, patch hashes and catalog snapshots are now kept, and only the
    root's direct dependencies are updated. `aube install` also treats a
    workspace member that declares dependencies but has no entry in the
    lockfile as stale, so installing again repairs lockfiles already damaged
    by this bug.
    
    **Full Changelog**:
    <aubepkg/aube@v2.3.0...v2.4.0>
    
    #### 💚 Sponsor aube
    
    aube is built and maintained by
    [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer
    at [**entire.io**](https://entire.io/), the title sponsor of his open
    source work.
    
    If aube saves your team install time or CI minutes, please consider
    becoming an [individual or company
    sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing
    development and helps keep aube fast, free, and independent.
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (in timezone America/Chicago)
    
    - Branch creation
      - Only on Tuesday (`* * * * 2`)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/jdx/mise-action).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
    
    ---------
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
    renovate[bot] and github-actions[bot] authored Sep 29, 2026
    Configuration menu
    Copy the full SHA
    342b4c0 View commit details
    Browse the repository at this point in the history
  2. chore(deps): update github actions (#633)

    <!-- entire-trail-link-start -->
    https://entire.io/gh/jdx/mise-action/trails/10
    <!-- entire-trail-link-end -->
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change | Pending |
    |---|---|---|---|---|
    |
    [github/codeql-action](https://redirect.github.com/github/codeql-action)
    | action | patch | `v4.38.0` → `v4.38.1` | `v4.38.2` |
    | [jdx/renovate-config](https://redirect.github.com/jdx/renovate-config)
    | workflow | patch | `v1.0.0` → `v1.0.1` | |
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>github/codeql-action (github/codeql-action)</summary>
    
    ###
    [`v4.38.1`](https://redirect.github.com/github/codeql-action/releases/tag/v4.38.1)
    
    [Compare
    Source](https://redirect.github.com/github/codeql-action/compare/v4.38.0...v4.38.1)
    
    - The CodeQL Action now has experimental support for CodeQL releases for
    which per-language bundles are available. Per-language bundles support
    analysis for a single language and are therefore smaller than the
    combined bundles that allow analysis for all supported languages. As a
    result, per-language bundles take up less space on disk and are faster
    to download. We expect to roll this change out to everyone in the coming
    weeks.
    [#&#8203;4146](https://redirect.github.com/github/codeql-action/pull/4146)
    
    </details>
    
    <details>
    <summary>jdx/renovate-config (jdx/renovate-config)</summary>
    
    ###
    [`v1.0.1`](https://redirect.github.com/jdx/renovate-config/releases/tag/v1.0.1):
    : Stop Renovate's npm and pep621 managers from relocking mise sidecars
    
    [Compare
    Source](https://redirect.github.com/jdx/renovate-config/compare/v1.0.0...v1.0.1)
    
    The shared preset now keeps Renovate's npm and pep621 managers out of
    `mise lock` dependency sidecars. Before this, Renovate and the
    `mise-lock` workflow kept overwriting each other's changes.
    
    ##### Fixed
    
    - **mise lock sidecars are no longer relocked by other managers.** `mise
    lock` pins npm and Python tool dependencies in sidecars under
    `.mise/locks/` or `.config/mise/locks/` and stores a digest of each one
    in `mise.lock`. Renovate's npm and pep621 managers were treating these
    sidecars' `package.json` and `pyproject.toml` as regular package files.
    Lock file maintenance then rewrote the sidecar lockfiles (for example
    with `uv lock --upgrade`) without updating the digests in `mise.lock`.
    The `mise-lock` workflow fixed the digests, and Renovate overwrote the
    fix on its next run. The preset now adds `**/.mise/locks/**` and
    `**/.config/mise/locks/**` to `ignorePaths`, so only the mise manager
    updates sidecars. Repos that extend the preset get this fix right away
    because the preset is read from `main`.
    ([#&#8203;30](https://redirect.github.com/jdx/renovate-config/issues/30),
    [@&#8203;jdx](https://redirect.github.com/jdx))
    
    `ignorePaths` doesn't merge, so the preset now lists the defaults from
    `config:recommended`'s `:ignoreModulesAndTests` (`node_modules`,
    `bower_components`, `vendor`, `examples`, `__tests__`, `test`, `tests`,
    `__fixtures__`) alongside the two mise paths. If your repo sets its own
    `ignorePaths`, that list replaces the preset's. To keep the fix, add the
    two mise sidecar globs to your list.
    
    **Full Changelog**:
    <jdx/renovate-config@v1.0.0...v1.0.1>
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (in timezone America/Chicago)
    
    - Branch creation
      - Only on Tuesday (`* * * * 2`)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    👻 **Immortal**: This PR will be recreated if closed unmerged. Get
    [config
    help](https://redirect.github.com/renovatebot/renovate/discussions) if
    that's undesired.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/jdx/mise-action).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
    
    ---------
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
    renovate[bot] and github-actions[bot] authored Sep 29, 2026
    Configuration menu
    Copy the full SHA
    ec2665b View commit details
    Browse the repository at this point in the history
  3. chore(deps): update dependency communique to latest (#635)

    <!-- entire-trail-link-start -->
    https://entire.io/gh/jdx/mise-action/trails/12
    <!-- entire-trail-link-end -->
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [communique](https://redirect.github.com/jdx/communique) | tools |
    minor | `1.4.2` → `v1.5.0` |
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>jdx/communique (communique)</summary>
    
    ###
    [`v1.5.0`](https://redirect.github.com/jdx/communique/releases/tag/v1.5.0):
    : Maintenance release
    
    [Compare
    Source](https://redirect.github.com/jdx/communique/compare/v1.4.2...v1.5.0)
    
    There are no commits between the previous release point and v1.5.0, so
    this release has no user-facing changes to report.
    
    **Full Changelog**:
    <jdx/communique@9c54a36...v1.5.0>
    
    #### 💚 Sponsor communique
    
    communique is built and maintained by
    [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer
    at [**entire.io**](https://entire.io/), the title sponsor of his open
    source work.
    
    If communique drafts your release notes or changelogs, please consider
    becoming an [individual or company
    sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing
    development and helps keep communique fast, free, and independent.
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (in timezone America/Chicago)
    
    - Branch creation
      - Only on Tuesday (`* * * * 2`)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/jdx/mise-action).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Sep 29, 2026
    Configuration menu
    Copy the full SHA
    c75796c View commit details
    Browse the repository at this point in the history

Commits on Sep 30, 2026

  1. chore(deps): update dependency aube to latest (#636)

    <!-- entire-trail-link-start -->
    https://entire.io/gh/jdx/mise-action/trails/13
    <!-- entire-trail-link-end -->
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [aube](https://redirect.github.com/jdx/aube) | tools | patch | `2.6.0`
    → `v2.6.1` |
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>jdx/aube (aube)</summary>
    
    ###
    [`v2.6.1`](https://redirect.github.com/aubepkg/aube/releases/tag/v2.6.1):
    : Maintenance release
    
    [Compare
    Source](https://redirect.github.com/jdx/aube/compare/v2.6.0...v2.6.1)
    
    The commit range for this release has no user-facing changes.
    
    **Full Changelog**:
    <aubepkg/aube@bd94e42...v2.6.1>
    
    #### 💚 Sponsor aube
    
    aube is built and maintained by
    [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer
    at [**entire.io**](https://entire.io/), the title sponsor of his open
    source work.
    
    If aube saves your team install time or CI minutes, please consider
    becoming an [individual or company
    sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing
    development and helps keep aube fast, free, and independent.
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (in timezone America/Chicago)
    
    - Branch creation
      - Only on Tuesday (`* * * * 2`)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Disabled because a matching PR was automerged
    previously.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/jdx/mise-action).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
    
    ---------
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
    renovate[bot] and github-actions[bot] authored Sep 30, 2026
    Configuration menu
    Copy the full SHA
    baf7eb4 View commit details
    Browse the repository at this point in the history
  2. fix: verify cached mise before execution (#637)

    <!-- entire-trail-link-start -->
    https://entire.io/gh/jdx/mise-action/trails/14
    <!-- entire-trail-link-end -->
    
    ## Summary
    
    Verify a pre-existing `mise` executable against the requested checksum
    or the signed release checksums before the action can invoke it. If the
    executable does not match, remove it and reinstall the requested
    release.
    
    This fixes a known, privately tracked security report. The
    implementation intentionally omits reproduction details; the reporter
    attribution and full report remain in the private advisory.
    
    ## Validation
    
    - `aube run format:check`
    - `aube run lint`
    - `aube test`
    - `aube run package`
    - isolated regression reproduction: a prewritten marker was invoked
    before the prior integrity check; with this change existing binaries are
    verified before any invocation
    
    <!-- CURSOR_SUMMARY -->
    ---
    
    > [!NOTE]
    > **High Risk**
    > Changes how the GitHub Action trusts and executes cached `mise`
    binaries—a security-sensitive supply-chain path—with intentional
    behavior changes around version upgrades and latest-release selection.
    > 
    > **Overview**
    > **Verifies any existing `mise` binary before the action runs it**,
    using the configured `sha256`, signed release checksums, and the
    requested version. On mismatch it deletes the binary and performs a full
    install instead of invoking or `self-update`ing untrusted cache.
    > 
    > **Setup behavior changes:** version mismatches no longer go through
    `mise self-update`; reinstall handles the requested release. When no
    version is pinned, the action still resolves the latest release and
    re-validates an on-disk binary rather than skipping install solely
    because `mise` exists.
    > 
    > **CI** adds regression coverage: reusing a verified install (`install:
    false`), swapping cached versions, and reusing a pre-minisign release
    without downloads when checksum verification passes.
    > 
    > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
    a981fde. Bugbot is set up for automated
    code reviews on this repo. Configure
    [here](https://www.cursor.com/dashboard/bugbot).</sup>
    <!-- /CURSOR_SUMMARY -->
    
    <!-- This is an auto-generated comment: release notes by coderabbit.ai
    -->
    ## Summary by CodeRabbit
    
    * **Bug Fixes**
    * Existing `mise` installations are checked against the requested
    version and available checksum information. A verification mismatch
    triggers a fresh installation.
    * **Behavior Changes**
    * The latest release is selected when no version is specified, even if
    `mise` is already installed.
    * When the installed version differs from the requested version, that
    version is installed instead of using `mise self-update`.
    <!-- end of auto-generated comment: release notes by coderabbit.ai -->
    jdx authored Sep 30, 2026
    Configuration menu
    Copy the full SHA
    c4102d4 View commit details
    Browse the repository at this point in the history
  3. chore: release v5.0.1 (#638)

    <!-- entire-trail-link-start -->
    https://entire.io/gh/jdx/mise-action/trails/15
    <!-- entire-trail-link-end -->
    
    
    ---
    ## [5.0.1](https://github.com/jdx/mise-action/compare/v5.0.0..v5.0.1) -
    2026-09-30
    
    ### 🐛 Bug Fixes
    
    - verify cached mise before execution (#637) by
    [@jdx](https://github.com/jdx) in
    [#637](#637)
    
    <!-- generated by git-cliff -->
    
    <!-- CURSOR_SUMMARY -->
    ---
    
    > [!NOTE]
    > **Low Risk**
    > Only version and changelog updates; no runtime code changes in this
    diff.
    > 
    > **Overview**
    > **Release v5.0.1** — bumps `package.json` from **5.0.0** to **5.0.1**
    and adds the corresponding **CHANGELOG** section dated 2026-09-30.
    > 
    > The release notes document one bug fix already merged via
    [#637](#637): **verify cached
    mise before execution** (integrity check on a restored/cached binary
    before the action runs it). This PR does not change application source;
    it only cuts the release metadata.
    > 
    > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
    bbee2b3. Bugbot is set up for automated
    code reviews on this repo. Configure
    [here](https://www.cursor.com/dashboard/bugbot).</sup>
    <!-- /CURSOR_SUMMARY -->
    
    Co-authored-by: mise-en-dev <123107610+mise-en-dev@users.noreply.github.com>
    jdx and mise-en-dev authored Sep 30, 2026
    Configuration menu
    Copy the full SHA
    7a4e45a View commit details
    Browse the repository at this point in the history
Loading