chore(deps): update support-deps - #1543
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/support-deps
branch
from
September 8, 2026 14:06
53799e2 to
5f724a6
Compare
renovate
Bot
force-pushed
the
renovate/support-deps
branch
from
September 8, 2026 14:55
5f724a6 to
b073a4f
Compare
renovate
Bot
force-pushed
the
renovate/support-deps
branch
from
September 8, 2026 15:24
b073a4f to
297e7db
Compare
| datasource | package | from | to | | -------------------------- | ----------------------- | --------- | --------- | | github-tags | defenseunicorns/uds-cli | 0.36.0 | 0.37.0 | | github-releases | goreleaser/goreleaser | v2.17.1 | v2.18.0 | | github-releases | jdx/hk | 1.57.0 | 1.58.1 | | github-release-attachments | jdx/mise | v2026.9.1 | v2026.9.3 |
renovate
Bot
force-pushed
the
renovate/support-deps
branch
from
September 8, 2026 20:38
297e7db to
9ff89f6
Compare
bradclawsie
approved these changes
Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.36.0→0.37.0v2.17.1→v2.18.0v2.18.11.57.0→1.58.12026.9.1→2026.9.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
defenseunicorns/uds-cli (aqua:defenseunicorns/uds-cli)
v0.37.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
Miscellaneous
goreleaser/goreleaser (goreleaser/goreleaser)
v2.18.0Compare Source
Announcement
Read the official announcement: Announcing GoReleaser v2.18.
Changelog
New Features
601cd87: feat(ko): support templating for local_domain, base_image, and repositories (#6741) (@mrueg)de88f38: feat(winget): support publishing additional locale manifests (#6733) (@MohammedAnasuddinZaid)cefbc6f: feat: add iru custom apps publisher (#6709) (@wimwenigerkind)1d6e7c0: feat: allow PR creation to use a different auth token (#6717) (@emily-curry)4c41ac0: feat: preflight checks (#6704) (@caarlos0)060260a: feat: release summary (#6810) (@caarlos0)82a5aba: feat: update to Go 1.27 (#6802) (@caarlos0)Security updates
b1cafd4: sec(deps): bump go-openapi/spec and go-openapi/validade (#6766) (@caarlos0)Bug fixes
1970443: fix(aur): expand description templates before escaping quotes (#6791) (@VXNCXNX and @caarlos0)a27402d: fix(blob): honor s3_force_path_style without a custom endpoint (#6789) (@VXNCXNX and @caarlos0)db65b99: fix(brew): a formula without a repository stops the ones after it (#6783) (@caarlos0)2b5fb31: fix(build): node windows targets get no .exe extension (#6777) (@VXNCXNX and @vxncxnx)951fc57: fix(cask): a cask without a repository stops the ones after it (#6785) (@caarlos0)54a6c8e: fix(cask): emit Casks that pass brew style (#6752) (@r0h1tb)2d6b235: fix(changelog): a commit matching two include filters is listed twice (#6773) (@VXNCXNX and @caarlos0)c4cc86f: fix(chocolatey): error on multiple archives for the same platform (#6792) (@VXNCXNX)1a246da: fix(config): type retry durations as strings in schema (#6801) (@skatkov)8be344b: fix(docker): add gpg-agent to the image (#6763) (@caarlos0)5282589: fix(dockers/v2): annotation scopes (#6800) (@CraigAstillRVU and @caarlos0)5560bb9: fix(flatpak): a disabled flatpak stops the ones after it (#6781) (@VXNCXNX)b68113a: fix(git): tag templates strip apostrophes from the message (#6779) (@VXNCXNX and @vxncxnx)1bc6ec7: fix(healthcheck): register upx and makeself dependency checkers (#6793) (@VXNCXNX)9d7d49f: fix(krew): a manifest without a name stops the ones after it (#6787) (@caarlos0)4276c51: fix(krew): apply the documented goarm default (#6775) (@VXNCXNX and @vxncxnx)9700230: fix(mcp): mcp.disable is documented but never read (#6795) (@VXNCXNX)1d79a09: fix(milestone): a milestone with close disabled stops the ones after it (#6778) (@VXNCXNX and @vxncxnx)2a0393d: fix(nfpm): don't set deb arch variant for goamd64 v1 (#6765) (@caarlos0)912704c: fix(nfpm): overrides ignore package_name, epoch, release and prerelease (#6782) (@VXNCXNX)3cf25c0: fix(nfpm): record the conventional extension, not the format name (#6776) (@VXNCXNX and @vxncxnx)ad028a3: fix(nix): a skipped nix entry stops the ones after it (#6788) (@VXNCXNX)b787cd2: fix(notarize): cap macOS notarization timeout at 20m (#6758) (@caarlos0)81a5509: fix(sign): artifacts: none masks real signing failures (#6790) (@VXNCXNX)4eb6037: fix(snapcraft): a disabled snap stops the ones after it (#6784) (@caarlos0)d93d0f1: fix(snapcraft): assumes, hooks and plugs are dropped when apps is omitted (#6780) (@VXNCXNX and @vxncxnx)b3bbd53: fix(srpm): make documented rpm fields actually configurable (#6762) (@caarlos0)7304fdb: fix(tmpl): register the documented join template function (#6772) (@VXNCXNX)6f88b00: fix(upload): a misconfigured upload stops the others (#6786) (@caarlos0)67e4c45: fix(winget): a skipped winget entry stops the ones after it (#6797) (@VXNCXNX)92453c1: fix(winget): count arm64 in the duplicate-archive check (#6774) (@VXNCXNX and @caarlos0)9a43dd0: fix(winget): fall back to the default description in additional locales (#6771) (@VXNCXNX)6127e0f: fix: do not panic decoding a commit whose message contains a log marker (#6738) (@arpitjain099)02cfda7: fix: lint (@caarlos0)b990083: fix: surface archive Close errors when writing release archives (#6690) (@SebTardif and @caarlos0)Documentation updates
33a3f22: docs(dockers_v2): clarify that build and push are a single step (#6742) (@caarlos0)1eb0ee9: docs: download SBOMs (#6803) (@caarlos0)16debcb: docs: many fixes (@caarlos0)ff2822a: docs: update dockers_v2 (@caarlos0)686946e: docs: use correct script for debconf (#6759) (@Daniel15)9921479: docs: use formats plural syntax (#6756) (@FelicianoTech)Other work
2b80858: chore: auto-update generated files (#6731) (@goreleaserbot)7df2cd5: chore: auto-update generated files (#6732) (@goreleaserbot)dd08c1f: chore: auto-update generated files (#6740) (@goreleaserbot)ee0e3c1: chore: auto-update generated files (#6744) (@goreleaserbot)cab7c6e: chore: auto-update generated files (#6769) (@goreleaserbot)39552ca: chore: auto-update generated files (#6794) (@goreleaserbot)4a82792: chore: auto-update generated files (#6798) (@goreleaserbot)ae88a14: chore: auto-update generated files (#6806) (@goreleaserbot)52494d9: chore: auto-update generated files (#6809) (@goreleaserbot)Full Changelog: goreleaser/goreleaser@v2.17.1...v2.18.0
Helping out
This release is only possible thanks to all the support of some awesome people!
Want to be one of them?
You can sponsor, get a Pro License or contribute with code.
Where to go next?
jdx/hk (hk)
v1.58.1Compare Source
📚 Documentation
jdx/mise (jdx/mise)
v2026.9.3Compare Source
v2026.9.2: : Packslip Backend, SSH Relay, and Reimagined Install ProgressCompare Source
This is a large release headlined by the new stable
packslip:backend for installing tools from a vendor's own signed release manifest, a read-only GitHub SSH relay for remote onboarding, redesigned install progress for both terminals and CI logs, and a rebuilt dotfiles-tracking model for bootstrap. It also carries dozens of fixes across shims, tasks, brew, Go, npm, and the schema, plus two security fixes.Highlights
packslip:backend is now generally available: install tools directly from a project's cryptographically signed release manifest, with signer pinning, trusted stampers, host-requirement checks, shell completions, and agent skills all driven from the same signed source.--from-gitonboarding, an AUR package manager, and a rebuilt dotfiles-history model that tracks files through ordinary Git commits synchronized with an origin.Added
packslip: New
packslip:backend installs tools from a vendor-published, signed release manifest (a sigstore bundle) that names every artifact with its digest, platform, format, and executables. The tool name is a pin, like aknown_hostsentry:packslip:github.com/owner/repoaccepts only a packslip signed by that repository's release workflow, and signature, log entry, statement, digest, and size are all verified before anything is unpacked. Custom hosts and monorepo tools are supported. The backend is no longer experimental. (#12778, #12811 by @jdx)packslip: Signer pinning remembers, per project, the signer that signed the first accepted release in a
pins.tomlfile (like SSH's known_hosts) and records the signer inmise.lock, so a later release signed by anyone else, or one that weakens provenance, is refused.mise packslip pinslists what is pinned andmise packslip forget <project>accepts an announced key rotation. (#12783 by @jdx)packslip: New
packslip.stamperssetting lets you require that a trusted host has stamped a version before mise offers or installs it (a scanning service, a mirror, or eventually the registry), with a per-tooltrust = "vendor"override. (#12782 by @jdx)packslip: Declared host requirements (OS/glibc minimums, shared libraries, required commands) are checked before download; confirmed failures refuse the install, gaps mise cannot verify warn only, and
ignore_requirements = trueoverrides hard failures.latestalso resolves from verified vendor recommendations. (#12804, #12805 by @jdx)packslip: A tool's packslip can ship shell completions and agent skills.
mise completion <shell> --tool <name>prints (or--installwrites a version-aware stub for) completions for whichever version is active in the current directory, andmise skills ls/mise skills synclink a tool's Agent Skills into.claude/skillsat the pinned version. Completions are also loaded automatically in activated shells. (#12779, #12780, #12848 by @jdx)install: Redesigned install progress. Interactive terminals now show a live region with an install-wide fractional bar, per-tool phase/elapsed/artifact rows, dependency-wait rows ("waiting for node@24.20.0"), and permanent completion lines written into scrollback.
prune,uninstall, and upgrade removals reuse the same session, so pruning hundreds of versions no longer floods the screen. (#12906 by @jdx)install: CI logs, pipes, and AI-agent terminals (
CLAUDECODE/AI_AGENT) get a compact append-only reporter: one permanent line per finished tool plus a periodic snapshot of the bar, active phases, transfer rates, and queue count, instead of hundreds of scrolling status rows. Resolver hosts and retry progress are surfaced too. (#12902, #12907 by @jdx)ssh: New
mise sshruns ordinary OpenSSH sessions with optional session-scoped, read-only GitHub access, andmise bootstrap remote --from-gitonboards a remote host from a Git repo. The initiating machine keeps the credential and brokers authorized clone/fetch and REST reads over an SSH Unix-socket forward; no token is installed on the target. (#12830 by @jdx)bootstrap:
mise bootstrap --from-git <GIT_URL>clones a repository-backed global config into$MISE_CONFIG_DIRso itsconfig.toml,conf.d/, and tasks apply on the first bootstrap and stay active afterward. (#12715 by @jdx)bootstrap: New
aur:package manager installs from the Arch User Repository viayay(preferred) orparu, with foreign-package status detection so repo packages with colliding names cannot satisfy an AUR request. Bootstrap can also declare packages as absent to remove them, and now reports which root declarations were selected. (#12718, #12716, #12770 by @jdx)bootstrap: Rebuilt dotfiles tracking. Files enrolled with
mode = "track"stay in place while mise commits changes to a separate bare Git store with checkpoints, rollback/undo, and optional origin synchronization, including encryption of shared files before storage. (#12918 by @jdx)activate: New
activate_shims = false(MISE_ACTIVATE_SHIMS=false) keeps tool shim directories off PATH during activation and hooks without changing your auto-install or lazy-tool settings. Command wrappers such as mr-boxington'scargokeep working. (#12926 by @jdx)core: Rust tools accept
mr_boxington = trueandmise usegains a repeatable--tool-option KEY=VALUEflag, so setting up the Cargo wrapper is a single command. (#12908 by @jdx)ruby: mise now reads Bundler's
ruby file: ".ruby-version"form from aGemfile(resolving the path next to the Gemfile), so projects that pin Ruby through a sibling file resolve correctly. (#12914 by @jdx)self-update: New global-only
self_update.repositoryandself_update.api_urlsettings let organizations point manual updates, out-of-date hints, and automatic updates at a curated GitHub or GitHub Enterprise release mirror. Project config cannot redirect updates, and artifacts still pass the embedded-signature check. (#12735 by @jdx)backend:
install_envis now applied when resolving and downloading tools, not just at build time. (#12777 by @rabadin)brew: mise can now evaluate ordinary third-party taps. (#12774 by @jdx)
Fixed
mise-shim.exeresolves correctly through a symlinkedmise.exe. (#12699 by @jdx, #12915 by @acooler15)sourcesaccepts a single string, task status is preserved when the cache audit tracer fails, and POSIX shells no longer have PATH pre-converted (the shell already does it). (#12711, #12769 by @jdx, #12530 by @risu729, #12696 by @JamBalaya56562)auto_updatesenabled are upgraded correctly. (#12645 by @Marukome0743, #12837 by @soodoh, #12857 by @himkt).tool-versionsline is now terminated with a newline. (#12740 by @dylanpulver)SYS_fork/SYS_vforkare omitted on aarch64. (#12807 by @jamescassell)Security
New Contributors
Full Changelog: jdx/mise@v2026.9.1...v2026.9.2
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.