chore(deps): update support-deps - #1452
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/support-deps
branch
from
August 7, 2026 19:20
8888497 to
9ce7c86
Compare
renovate
Bot
force-pushed
the
renovate/support-deps
branch
6 times, most recently
from
August 15, 2026 00:58
fc85f9d to
220faac
Compare
renovate
Bot
force-pushed
the
renovate/support-deps
branch
10 times, most recently
from
August 22, 2026 23:30
998bd95 to
3d95ff1
Compare
renovate
Bot
force-pushed
the
renovate/support-deps
branch
2 times, most recently
from
August 24, 2026 00:03
d024a28 to
df5d53d
Compare
bradclawsie
previously approved these changes
Aug 24, 2026
renovate
Bot
force-pushed
the
renovate/support-deps
branch
3 times, most recently
from
August 26, 2026 03:55
f506c15 to
31f0554
Compare
| datasource | package | from | to | | -------------------------- | ----------------------------------------- | --------- | ---------- | | github-tags | actions/cache | v4.2.3 | v6.1.0 | | github-tags | defenseunicorns/uds-cli | 0.35.0 | 0.36.0 | | github-tags | defenseunicorns/uds-common | v1.27.1 | v1.28.0 | | docker | docker.io/library/nginx | 1.31.3 | 1.31.4 | | github-tags | docker/login-action | v4.5.1 | v4.6.0 | | github-tags | docker/setup-buildx-action | v4.2.0 | v4.3.0 | | docker | ghcr.io/defenseunicorns/packages/uds/core | 1.9.0 | 1.11.1 | | github-tags | github/codeql-action | v4.37.5 | v4.37.8 | | github-releases | jdx/hk | 1.54.0 | 1.56.1 | | github-release-attachments | jdx/mise | v2026.8.2 | v2026.8.14 | | github-tags | jdx/mise-action | v4.2.4 | v4.2.5 | | docker | nginx | 1.31.3 | 1.31.4 |
renovate
Bot
force-pushed
the
renovate/support-deps
branch
from
August 26, 2026 07:05
31f0554 to
5028d17
Compare
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
chance-coleman
approved these changes
Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.3→v6.1.00.35.0→0.36.0v1.27.1→v1.28.01.31.3→1.31.4v4.5.1→v4.6.0v4.2.0→v4.3.01.9.0-upstream→1.11.1-upstreamv4.37.5→v4.37.81.54.0→1.56.12026.8.2→2026.8.14v4.2.4→v4.2.5v4.3.01.31.3→1.31.4Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
actions/cache (actions/cache)
v6.1.0Compare Source
What's Changed
Full Changelog: actions/cache@v6...v6.1.0
v6.0.0Compare Source
What's Changed
Full Changelog: actions/cache@v5...v6.0.0
v5.1.0Compare Source
What's Changed
Full Changelog: actions/cache@v5...v5.1.0
v5.0.5Compare Source
What's Changed
Full Changelog: actions/cache@v5...v5.0.5
v5.0.4Compare Source
What's Changed
New Contributors
Full Changelog: actions/cache@v5...v5.0.4
v5.0.3Compare Source
What's Changed
@actions/cacheto v5.0.5 (Resolves: https://github.com/actions/cache/security/dependabot/33)@actions/coreto v2.0.3Full Changelog: actions/cache@v5...v5.0.3
v5.0.2: v.5.0.2Compare Source
v5.0.2
What's Changed
When creating cache entries, 429s returned from the cache service will not be retried.
v5.0.1Compare Source
v5.0.1
What's Changed
v5.0.0
What's Changed
Full Changelog: actions/cache@v5...v5.0.1
v5.0.0Compare Source
What's Changed
Full Changelog: actions/cache@v4.3.0...v5.0.0
v4.3.0Compare Source
What's Changed
v4.3.0release by @Link- in #1655New Contributors
Full Changelog: actions/cache@v4...v4.3.0
v4.2.4Compare Source
What's Changed
@actions/cacheto4.0.5and move@protobuf-ts/pluginto dev depdencies by @Link- in #16344.2.4by @Link- in #1636New Contributors
Full Changelog: actions/cache@v4...v4.2.4
defenseunicorns/uds-cli (aqua:defenseunicorns/uds-cli)
v0.36.0Compare Source
What's Changed
New Contributors
Full Changelog: v0.35.1...v0.36.0
v0.35.1Compare Source
What's Changed
New Contributors
Full Changelog: v0.35.0...v0.35.1
defenseunicorns/uds-common (defenseunicorns/uds-common)
v1.28.0Compare Source
Features
Bug Fixes
Miscellaneous
v1.27.2Compare Source
⚠ BREAKING CHANGES
Bug Fixes
Miscellaneous
docker/login-action (docker/login-action)
v4.6.0Compare Source
v4.5.2Compare Source
docker/setup-buildx-action (docker/setup-buildx-action)
v4.3.0Compare Source
Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0
github/codeql-action (github/codeql-action)
v4.37.8Compare Source
No user facing changes.
v4.37.7Compare Source
v4.37.6Compare Source
.github/codeql-config.ymlto align it with the suggested path that is used elsewhere. #4070jdx/hk (hk)
v1.56.1Compare Source
🚜 Refactor
📚 Documentation
📦️ Dependency Updates
v1.56.0Compare Source
🚀 Features
🐛 Bug Fixes
🔍 Other Changes
HK_OUTPUT_FILEenv var to control the output file location by @signadou in #1204📦️ Dependency Updates
75abd12by @renovate[bot] in #1208New Contributors
v1.55.0Compare Source
🚀 Features
🐛 Bug Fixes
🧪 Testing
📦️ Dependency Updates
New Contributors
v1.54.1Compare Source
🐛 Bug Fixes
🔍 Other Changes
📦️ Dependency Updates
jdx/mise (jdx/mise)
v2026.8.14Compare Source
v2026.8.13Compare Source
v2026.8.12: : Cleaner diagnostics and a raft of task, config, and tool fixesCompare Source
This release adds package uninstall support to the plugin bootstrap flow and fixes a broad set of task, config, tool, and diagnostic edge cases. Many changes turn silent failures and cryptic errors into actionable messages, so it is largely a robustness and quality-of-life release.
Added
PackageUninstallhook, somise bootstrap packages prune --manager <plugin>is no longer Homebrew-only. mise records ownership only for packages that go from missing to installed during an install, and prune removes only owned packages that are absent from the current config and trusted tracked configs. Pre-existing and manually installed packages are never claimed, dry-run never invokes the hook, and the keep-set is reloaded after confirmation so newly declared packages cannot be removed without another prompt. (#12332 by @jdx)Fixed
Out-File -Encoding utf8) could make.tool-versions,.node-version,package.jsonpackageManager, registry-scraped files likeEarthfile, and.sdkmanrcentries silently vanish or resolve to a corrupt version. Cached idiomatic parses written by an older mise are re-parsed so the fix takes effect on upgrade. (#12325 by @JamBalaya56562)mise edit(and the interactive TUI) now preserves comments — leading, trailing, and section comments are captured on parse and written back on save, instead of being stripped. (#12319 by @Marukome0743)package.jsonthat was tracked while enabled and later disabled no longer triggers a spurious "cannot update idiomatic version file" warning on read-only operations likemise ls --all-sources. The tracking entry is retained so re-enabling the tool reactivates it. (#12194 by @xqm32)cdtarget that cannot be entered (for example viaMISE_CDpointing at a missing directory, or a directory the process cannot chdir into) is now reported with the path and OS reason instead of panicking. (#12314 by @JamBalaya56562)killed by SIGINT/killed by SIGTERMrather than "no exit status". (#12323 by @Marukome0743)--file <file>) now stay string-typed during template rendering, so path filters likedirnamework on them. Switch flags still default to booleans and count flags to integers. (#12355 by @jdx)chmod +xadvice is gone from Windows messages. (#12324 by @JamBalaya56562)env_with_pathrather than rebuilding PATH from a pristine environment, restoring project_.pathdirectories and fixing discovery of sibling stubs. The stub-selected tool version is no longer shadowed by an outer task's install directories. (#12322 by @tmkx)mise watch --clear=reset --restartno longer leaves the terminal without echo after Ctrl-C. The controlling terminal (preferring/dev/tty) is now saved and restored from a drop guard, so it recovers on normal return, errors, and cancellation, including when stdin is redirected or a second terminal is in use. (#12328 by @Marukome0743)go installno longer inherits aGOROOTthat mise exported for a different Go, which causedcompile: version ... does not match go tool version ...failures when anothergowas first on PATH. An explicitly configuredinstall_envGOROOT is still honored. (#12342 by @Marukome0743)mise doctornow flags a tool whose install directory exists but is empty (for example after an interrupted download), marking it(empty)and suggestingmise install --force, instead of silently treating it as installed. (#12321 by @Marukome0743)$VARnow names the key or directive that referenced the missing variable and the config file it lives in, making it possible to find the offending line in a large[env]block. (#12316 by @Marukome0743)oc(OpenShift client) now installs from channel aliases such asoc = "stable"by resolving the unversioned artifact name within the channel directory, fixing a 404. (#12326 by @Marukome0743)Documentation
MISE_TASK_DIRfor locating sibling files, which works consistently across Linux, macOS, and Windows without renaming the task. (#12313 by @JamBalaya56562)New Contributors
Full Changelog: jdx/mise@v2026.8.11...v2026.8.12
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.11: : Automatic updates, remote mise installs, and versioned lockfilesCompare Source
This release adds opt-in automatic self-updates, lets remote bootstrap leave a working mise behind on each target, and introduces versioned lockfiles that bind each request to the version it resolved. It also replaces the CLI parser with usage-rs, hardens remote Git task handling, and fixes a wide range of tool-installation, task, and config edge cases.
Highlights
mise lock --upgradefor safe migration and no surprise drift for existing files.Added
self-update: New opt-in automatic updates. Enable
auto_update(withauto_update_check_duration, default7d) and mise will update itself before eligible interactive commands, then re-exec your original invocation with the new binary. Updates are throttled and lock-serialized, skipped in CI, offline, non-interactive, and shell-integration contexts, and failures never block the requested command. Package-managed builds are steered toward the official optimized binaries. (#12288 by @jdx)bootstrap: Remote bootstrap can now install a persistent mise on each target instead of tearing it down with the staging directory. Set
install_misein[bootstrap.remote](or per host) or pass--install-mise[=/path]; the same checksum-verified executable that ran the bootstrap is installed, so the host converges on the orchestrating mise version. (#12284 by @jdx)lock: Lockfiles now carry
lockfile_version = 1and bind each original request to the entry it resolved, so overlapping requests like"1"and"1.0.0"can lock different versions. Existing unversioned lockfiles stay on format 0 during ordinarymise lock/install/upgradeto avoid drift; runmise lock --upgradeto migrate (transactional, rolls back on failure). (#12299 by @jdx)node: mise can now act as a Corepack replacement, honoring the
+sha...checksum suffixes inpackageManager/devEngines.packageManagerand verifying the exact npm, pnpm, Yarn, or bun artifact before installing. Adds SHA-224/SHA-384 hashing and a Windows script launcher for Yarn's JS CLI. (#12214 by @jdx)prune:
mise prune --dry-runnow explains why each version is prunable, naming either the kept versions and the configs requiring them or the fact that nothing tracked references the tool. (#12304 by @Marukome0743)java: Oracle GraalVM "innovation" feature releases are now recognized. (#12189 by @roele)
Fixed
python/latest) onto the image's Python, so tools no longer dangle at runtime. (#12211 by @jdx)--no-hook-env. (#12218 by @JamBalaya56562)PATHnow folds onto a single key on Windows. (#12312 by @JamBalaya56562)go installwarning paths render correctly, and mise suggests compatible package backends. (#12252, #12251, #12225 by @risu729)conf.dfragments load unconditionally again, and mise no longer prompts for trust when stdin is not a tty. (#12242 by @jdx, #12268 by @Marukome0743)mise lock" hint now points at--globalwhen only global config has tools. (#12260 by @jdx)mise set --filenow refuses a file it cannot read back. (#12207 by @JamBalaya56562)-cshell (#12277 by @JamBalaya56562).Changed
usageCLI, andmise completion --installwrites self-contained scripts. This raises the minimum supported Rust version to 1.95. (#12221 by @jdx)mise generate bootstrapis renamed tomise generate install-scriptto avoid confusion withmise bootstrap. The old spelling still works as a hidden, deprecated alias (removal scheduled for 2027.9.0). (#12247 by @jdx)Security
..traversal, Windows absolute/backslash and drive-qualified forms, and intermediate symlink escapes, and refusing non-regular-file targets. This closes escapes that couldchmod +xand execute attacker-chosen files outside the checkout. (#12254 by @risu729)Deprecated
all_compile = truedefault on Alpine now warns and is scheduled for removal in 2027.8.0; precompiled musl binaries become the default path. Setall_compile = trueexplicitly to keep building from source. (#12287 by @risu729)go.mod(go X.Y) andCMakeLists.txt(cmake_minimum_required) now warn when they resolve a version and stop being read in 2026.11.0.toolchain goX.Y.Zis unaffected. Only affects users who opted these tools intoidiomatic_version_file_enable_tools. (#12259 by @jdx)Documentation
_.sourcebeing bash-only (#12286 by @risu729) and its cacheable source example (#12278 by @Marukome0743), cross-file hook execution order (#12295 by @jdx), that--systemis shared storage rather than a mise-free install (#12253 by @jdx), which backends lockfile strict mode skips (#12306 by @Marukome0743), that task deps ignores run-array refs (#12285 by @risu729), and thatrawserializes execution (#12307 by @Marukome0743).Registry
Performance
Breaking Changes
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.