Skip to content

chore(deps): update support-deps - #1452

Merged
eoghanriley merged 2 commits into
mainfrom
renovate/support-deps
Aug 26, 2026
Merged

eoghanriley merged 2 commits into
mainfrom
renovate/support-deps

Conversation

@renovate

@renovate renovate Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
actions/cache action major v4.2.3v6.1.0
aqua:defenseunicorns/uds-cli tools minor 0.35.00.36.0
defenseunicorns/uds-common minor v1.27.1v1.28.0
docker.io/library/nginx (source) patch 1.31.31.31.4
docker/login-action action minor v4.5.1v4.6.0
docker/setup-buildx-action action minor v4.2.0v4.3.0
ghcr.io/defenseunicorns/packages/uds/core minor 1.9.0-upstream1.11.1-upstream
github/codeql-action action patch v4.37.5v4.37.8
hk tools minor 1.54.01.56.1
jdx/mise uses-with patch 2026.8.22026.8.14
jdx/mise-action action patch v4.2.4v4.2.5 v4.3.0
nginx (source) patch 1.31.31.31.4

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

actions/cache (actions/cache)

v6.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v5.0.2: v.5.0.2

Compare Source

v5.0.2
What's Changed

When creating cache entries, 429s returned from the cache service will not be retried.

v5.0.1

Compare Source

[!IMPORTANT]
actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


v5.0.1
What's Changed
v5.0.0
What's Changed

Full Changelog: actions/cache@v5...v5.0.1

v5.0.0

Compare Source

[!IMPORTANT]
actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


What's Changed

Full Changelog: actions/cache@v4.3.0...v5.0.0

v4.3.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v4...v4.3.0

v4.2.4

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v4...v4.2.4

defenseunicorns/uds-cli (aqua:defenseunicorns/uds-cli)

v0.36.0

Compare Source

What's Changed

New Contributors

Full Changelog: v0.35.1...v0.36.0

v0.35.1

Compare Source

What's Changed

New Contributors

Full Changelog: v0.35.0...v0.35.1

defenseunicorns/uds-common (defenseunicorns/uds-common)

v1.28.0

Compare Source

Features
Bug Fixes
Miscellaneous

v1.27.2

Compare Source

⚠ BREAKING CHANGES
  • update the license to AGPLv3 or Commercial (#​286)
Bug Fixes
Miscellaneous
docker/login-action (docker/login-action)

v4.6.0

Compare Source

v4.5.2

Compare Source

docker/setup-buildx-action (docker/setup-buildx-action)

v4.3.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

github/codeql-action (github/codeql-action)

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070
jdx/hk (hk)

v1.56.1

Compare Source

🚜 Refactor
📚 Documentation
📦️ Dependency Updates

v1.56.0

Compare Source

🚀 Features
🐛 Bug Fixes
🔍 Other Changes
📦️ Dependency Updates
New Contributors

v1.55.0

Compare Source

🚀 Features
🐛 Bug Fixes
🧪 Testing
  • (init) decouple agent docs assertion from releases by @​jdx in #​1187
📦️ Dependency Updates
New Contributors

v1.54.1

Compare Source

🐛 Bug Fixes
🔍 Other Changes
📦️ Dependency Updates
jdx/mise (jdx/mise)

v2026.8.14

Compare Source

v2026.8.13

Compare Source

v2026.8.12: : Cleaner diagnostics and a raft of task, config, and tool fixes

Compare Source

This release adds package uninstall support to the plugin bootstrap flow and fixes a broad set of task, config, tool, and diagnostic edge cases. Many changes turn silent failures and cryptic errors into actionable messages, so it is largely a robustness and quality-of-life release.

Added

  • bootstrap: Package-plugin managers now support pruning via an optional PackageUninstall hook, so mise bootstrap packages prune --manager <plugin> is no longer Homebrew-only. mise records ownership only for packages that go from missing to installed during an install, and prune removes only owned packages that are absent from the current config and trusted tracked configs. Pre-existing and manually installed packages are never claimed, dry-run never invokes the hook, and the keep-set is reloaded after confirmation so newly declared packages cannot be removed without another prompt. (#​12332 by @​jdx)

Fixed

  • config: Version-declaring files that begin with a UTF-8 byte-order mark now parse correctly. Previously a leading BOM (as written by Notepad or PowerShell's Out-File -Encoding utf8) could make .tool-versions, .node-version, package.json packageManager, registry-scraped files like Earthfile, and .sdkmanrc entries silently vanish or resolve to a corrupt version. Cached idiomatic parses written by an older mise are re-parsed so the fix takes effect on upgrade. (#​12325 by @​JamBalaya56562)
  • config: Saving from mise edit (and the interactive TUI) now preserves comments — leading, trailing, and section comments are captured on parse and written back on save, instead of being stripped. (#​12319 by @​Marukome0743)
  • config: An idiomatic file such as package.json that was tracked while enabled and later disabled no longer triggers a spurious "cannot update idiomatic version file" warning on read-only operations like mise ls --all-sources. The tracking entry is retained so re-enabling the tool reactivates it. (#​12194 by @​xqm32)
  • cli: A cd target that cannot be entered (for example via MISE_CD pointing at a missing directory, or a directory the process cannot chdir into) is now reported with the path and OS reason instead of panicking. (#​12314 by @​JamBalaya56562)
  • task: A task whose child process is killed by SIGINT (Ctrl-C reaching only the child) is now treated as an interruption, exiting 130 without failing sibling tasks, instead of reporting a spurious failure. Signalled processes now render as killed by SIGINT/killed by SIGTERM rather than "no exit status". (#​12323 by @​Marukome0743)
  • task: Value-taking usage flags without a default (for example --file <file>) now stay string-typed during template rendering, so path filters like dirname work on them. Switch flags still default to booleans and count flags to integers. (#​12355 by @​jdx)
  • tasks: On Windows, task files skipped because they have no known extension or shebang now explain why and give platform-appropriate guidance, instead of producing no output or a misleading "Are you in a project directory?" message. Outdated chmod +x advice is gone from Windows messages. (#​12324 by @​JamBalaya56562)
  • tool-stub: Non-cached tool-stub execution now keeps the toolset's env_with_path rather than rebuilding PATH from a pristine environment, restoring project _.path directories and fixing discovery of sibling stubs. The stub-selected tool version is no longer shadowed by an outer task's install directories. (#​12322 by @​tmkx)
  • watch: mise watch --clear=reset --restart no longer leaves the terminal without echo after Ctrl-C. The controlling terminal (preferring /dev/tty) is now saved and restored from a drop guard, so it recovers on normal return, errors, and cancellation, including when stdin is redirected or a second terminal is in use. (#​12328 by @​Marukome0743)
  • go: go install no longer inherits a GOROOT that mise exported for a different Go, which caused compile: version ... does not match go tool version ... failures when another go was first on PATH. An explicitly configured install_env GOROOT is still honored. (#​12342 by @​Marukome0743)
  • doctor: mise doctor now flags a tool whose install directory exists but is empty (for example after an interrupted download), marking it (empty) and suggesting mise install --force, instead of silently treating it as installed. (#​12321 by @​Marukome0743)
  • env: When an age SSH identity cannot be used (passphrase-protected, encrypted, hardware-backed, or an unsupported key type), decryption failures now explain which identity could not be read and why, instead of the misleading "No matching keys found". (#​12339 by @​Marukome0743)
  • env: The warning for an unexpanded $VAR now names the key or directive that referenced the missing variable and the config file it lives in, making it possible to find the offending line in a large [env] block. (#​12316 by @​Marukome0743)
  • brew-cask: Casks already owned by Homebrew are now recognized as installed (read-only) rather than reported missing and then blocked by the ownership guard, making declarative bootstrap idempotent for Homebrew-managed casks. mise leaves such installations untouched across status, apply, use, upgrade, and prune. (#​12346 by @​donbeave)
  • registry: oc (OpenShift client) now installs from channel aliases such as oc = "stable" by resolving the unversioned artifact name within the channel directory, fixing a 404. (#​12326 by @​Marukome0743)

Documentation

  • tasks: PowerShell task guidance now points extensionless tasks at MISE_TASK_DIR for locating sibling files, which works consistently across Linux, macOS, and Windows without renaming the task. (#​12313 by @​JamBalaya56562)

New Contributors

Full Changelog: jdx/mise@v2026.8.11...v2026.8.12

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.11: : Automatic updates, remote mise installs, and versioned lockfiles

Compare Source

This release adds opt-in automatic self-updates, lets remote bootstrap leave a working mise behind on each target, and introduces versioned lockfiles that bind each request to the version it resolved. It also replaces the CLI parser with usage-rs, hardens remote Git task handling, and fixes a wide range of tool-installation, task, and config edge cases.

Highlights

  • mise can now keep itself up to date and provision itself onto remote hosts, closing two long-standing gaps in unattended and remote workflows.
  • Lockfiles gained an explicit format version so overlapping loose and exact requests can pin distinct versions, with mise lock --upgrade for safe migration and no surprise drift for existing files.
  • The CLI parser moved from clap to usage-rs, and remote Git task paths are now contained against traversal, symlink, and Windows path escapes.

Added

  • self-update: New opt-in automatic updates. Enable auto_update (with auto_update_check_duration, default 7d) and mise will update itself before eligible interactive commands, then re-exec your original invocation with the new binary. Updates are throttled and lock-serialized, skipped in CI, offline, non-interactive, and shell-integration contexts, and failures never block the requested command. Package-managed builds are steered toward the official optimized binaries. (#​12288 by @​jdx)

    [settings]
    auto_update = true
    auto_update_check_duration = "7d"
  • bootstrap: Remote bootstrap can now install a persistent mise on each target instead of tearing it down with the staging directory. Set install_mise in [bootstrap.remote] (or per host) or pass --install-mise[=/path]; the same checksum-verified executable that ran the bootstrap is installed, so the host converges on the orchestrating mise version. (#​12284 by @​jdx)

    [bootstrap.remote]
    install_mise = true  # installs to ~/.local/bin/mise
  • lock: Lockfiles now carry lockfile_version = 1 and bind each original request to the entry it resolved, so overlapping requests like "1" and "1.0.0" can lock different versions. Existing unversioned lockfiles stay on format 0 during ordinary mise lock/install/upgrade to avoid drift; run mise lock --upgrade to migrate (transactional, rolls back on failure). (#​12299 by @​jdx)

  • node: mise can now act as a Corepack replacement, honoring the +sha... checksum suffixes in packageManager / devEngines.packageManager and verifying the exact npm, pnpm, Yarn, or bun artifact before installing. Adds SHA-224/SHA-384 hashing and a Windows script launcher for Yarn's JS CLI. (#​12214 by @​jdx)

  • prune: mise prune --dry-run now explains why each version is prunable, naming either the kept versions and the configs requiring them or the fact that nothing tracked references the tool. (#​12304 by @​Marukome0743)

  • java: Oracle GraalVM "innovation" feature releases are now recognized. (#​12189 by @​roele)

Fixed

Changed

  • cli: The command-line parser, help output, and shell completions moved from clap to usage-rs. Completions and help are now generated from compiled usage metadata rather than an external usage CLI, and mise completion --install writes self-contained scripts. This raises the minimum supported Rust version to 1.95. (#​12221 by @​jdx)
  • generate: mise generate bootstrap is renamed to mise generate install-script to avoid confusion with mise bootstrap. The old spelling still works as a hidden, deprecated alias (removal scheduled for 2027.9.0). (#​12247 by @​jdx)
  • prompts: confirmation prompts now distinguish "could not ask" from an explicit "no". (#​12273 by @​Marukome0743)

Security

  • task: Remote Git task paths are now contained to the checkout root, rejecting .. traversal, Windows absolute/backslash and drive-qualified forms, and intermediate symlink escapes, and refusing non-regular-file targets. This closes escapes that could chmod +x and execute attacker-chosen files outside the checkout. (#​12254 by @​risu729)

Deprecated

  • config (Alpine): The distro-wide all_compile = true default on Alpine now warns and is scheduled for removal in 2027.8.0; precompiled musl binaries become the default path. Set all_compile = true explicitly to keep building from source. (#​12287 by @​risu729)
  • config (idiomatic files): Minimum-version floors in go.mod (go X.Y) and CMakeLists.txt (cmake_minimum_required) now warn when they resolve a version and stop being read in 2026.11.0. toolchain goX.Y.Z is unaffected. Only affects users who opted these tools into idiomatic_version_file_enable_tools. (#​12259 by @​jdx)

Documentation

Registry

Performance

Breaking Changes

  • The CLI parser migration (#​12221) raises t

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner August 7, 2026 13:35
@renovate
renovate Bot force-pushed the renovate/support-deps branch from 8888497 to 9ce7c86 Compare August 7, 2026 19:20
@renovate renovate Bot changed the title chore(deps): update support dependencies to v4.37.6 chore(deps): update support-deps Aug 7, 2026
@renovate
renovate Bot force-pushed the renovate/support-deps branch 6 times, most recently from fc85f9d to 220faac Compare August 15, 2026 00:58
@renovate
renovate Bot force-pushed the renovate/support-deps branch 10 times, most recently from 998bd95 to 3d95ff1 Compare August 22, 2026 23:30
@renovate
renovate Bot force-pushed the renovate/support-deps branch 2 times, most recently from d024a28 to df5d53d Compare August 24, 2026 00:03
bradclawsie
bradclawsie previously approved these changes Aug 24, 2026
@renovate
renovate Bot force-pushed the renovate/support-deps branch 3 times, most recently from f506c15 to 31f0554 Compare August 26, 2026 03:55
| datasource                 | package                                   | from      | to         |
| -------------------------- | ----------------------------------------- | --------- | ---------- |
| github-tags                | actions/cache                             | v4.2.3    | v6.1.0     |
| github-tags                | defenseunicorns/uds-cli                   | 0.35.0    | 0.36.0     |
| github-tags                | defenseunicorns/uds-common                | v1.27.1   | v1.28.0    |
| docker                     | docker.io/library/nginx                   | 1.31.3    | 1.31.4     |
| github-tags                | docker/login-action                       | v4.5.1    | v4.6.0     |
| github-tags                | docker/setup-buildx-action                | v4.2.0    | v4.3.0     |
| docker                     | ghcr.io/defenseunicorns/packages/uds/core | 1.9.0     | 1.11.1     |
| github-tags                | github/codeql-action                      | v4.37.5   | v4.37.8    |
| github-releases            | jdx/hk                                    | 1.54.0    | 1.56.1     |
| github-release-attachments | jdx/mise                                  | v2026.8.2 | v2026.8.14 |
| github-tags                | jdx/mise-action                           | v4.2.4    | v4.2.5     |
| docker                     | nginx                                     | 1.31.3    | 1.31.4     |
@renovate
renovate Bot force-pushed the renovate/support-deps branch from 31f0554 to 5028d17 Compare August 26, 2026 07:05
@renovate

renovate Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@eoghanriley
eoghanriley merged commit bdb5643 into main Aug 26, 2026
41 checks passed
@eoghanriley
eoghanriley deleted the renovate/support-deps branch August 26, 2026 18:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants