feat(actions): Update all non-major dependencies #247

Merged
ryangr0 merged 1 commit from renovate/all-non-major into development 2026-10-05 19:08:17 +00:00
Member

This PR contains the following updates:

Package Type Update Change Released Age (d) Age Adoption Passing Confidence
jdx/mise uses-with patch 2026.10.1 → 2026.10.2 2026-10-04T12:31:22.000Z 1d age adoption passing confidence
mermaid minor 12.0.0 → 12.1.0 2026-10-02T11:14:26.341Z 3d age adoption passing confidence
webgrip/workflows action patch v2.7.7 → v2.7.8 2026-10-04T10:56:14.000Z 1d age adoption passing confidence
wrangler (source) devDependencies minor 4.146.0 → 4.147.0 2026-10-02T11:30:47.699Z 3d age adoption passing confidence

📦 Grouped update: confirm the group is operationally coherent before merging.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means the datasource reports no release timestamp. Docker Hub is the only Docker registry that reports one, so this preset treats every other Docker registry (ghcr.io, quay.io, Harbor and its proxies, dhi.io) as timestamp-optional: minimumReleaseAge cannot hold those updates back and they are eligible as soon as checks pass. For any other datasource, a missing timestamp holds the update for as long as a soak applies. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


Release Notes

jdx/mise (jdx/mise)

v2026.10.2: : Experimental spinel backend, typed tool options in the schema, and daemon presets on Windows

Compare Source

This release adds an experimental spinel: backend for compiling Ruby CLIs to native binaries. The mise.toml schema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting.

Added
  • Experimental spinel: backend. It builds a Ruby command-line tool from a GitHub repository into a native executable using Spinel, Matz's Ruby AOT compiler. Versions come from git tags through git ls-remote, so listing them doesn't call the GitHub API. Available options: entrypoint, bin, tag_prefix, source_ref and spinel. You need the spinel compiler on PATH (mise doesn't install it yet) and mise settings experimental=true. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on nateberkopec/mise-backend-spinel. #​13922

    [tools."spinel:tobi/try"]
    version = "1.10.1"
    entrypoint = "try.rb"
    bin = "try"
    tag_prefix = "v"
    
  • Typed tool options in the JSON schema. Editors that use schema/mise.json now validate and autocomplete options for each backend, based on the tool's prefix. This covers github, gitlab, forgejo, ubi, http, s3, aqua, cargo, npm, pypi/pipx, gem, go, conda, spm, packslip and spinel. It also covers core-tool options for python, java, rust and dotnet, per-platform overrides (platforms.<os>-<arch>) and [tasks.*.tools] tables. For example, a numeric asset_pattern or java release_type = "stable" is now flagged. Boolean options accept true/false, "true"/"false" and 1/0, the same values mise accepts. lazy_bins accepts a single string. The deprecated experimental_monorepo_root key is allowed again. Runtime behavior is unchanged, but your editor may now flag mistakes in existing configs. #​13924

  • Daemon presets on Windows. mise daemons start no longer refuses preset daemons on Windows. Every preset except redis, which has no Windows build, now runs under pitchfork's default cmd /C shell. For PostgreSQL to stop cleanly, you need pitchfork 2.29.0 or later. PostgreSQL also won't start from an elevated prompt. Windows reserves some port ranges for Hyper-V and WSL, so a preset's default port can be blocked. If it is, set a different one with ports. #​13929 by @​JamBalaya56562

    [daemons.db]
    preset = "postgres"
    version = "18"
    options = { database = "app" }
    
  • Install mise with packslip. The installation guide now covers installing mise's signed release without running an install script. packslip verifies the Sigstore signature and the archive digest. mise self-update works with this install method. #​13710

    packslip install github.com/jdx/mise --pin ps1_nlhmwtfeufglxv5myvwvronk7a
    
Fixed
Config and activation
  • An untrusted project config no longer breaks shell activation. Before, mise hook-env failed completely, so tools and env from your trusted global config were not applied either. Now it skips the untrusted file, prints the usual one-time warning and loads everything else. Explicit commands such as mise run and mise x still error on untrusted configs. #​13919
  • A failed settings reload is reported as an error instead of crashing. Commands such as mise install, mise use, mise upgrade and mise ls-remote --prerelease reload settings partway through. Before, a failed reload aborted mise with SIGABRT and a core dump. Now mise prints failed to reload settings with the cause and keeps using the previous settings. #​13925
  • --no-config and MISE_NO_CONFIG=1 now skip .miserc.toml discovery. Before, a malformed project, global or system miserc broke commands like mise --no-config version. #​13926 by @​donbeave
Tasks
  • A timed-out task fails even if it exits cleanly. On Unix, a task that caught SIGTERM and exited 0 after its timeout was reported as successful. Now mise run reports timed out and exits non-zero. #​13930 by @​Marukome0743
  • Timed-out tasks on Windows can clean up. When a task hits its timeout, mise now sends it Ctrl+C and gives it 5 seconds before ending its process tree, the way Unix uses SIGTERM followed by SIGKILL. For example, PowerShell finally blocks now run. Only the timed-out task gets the Ctrl+C. The whole-run mise run --timeout still stops tasks immediately on Windows. #​13889 by @​JamBalaya56562
Windows
  • mise exec -- cmd /c keeps double quotes. Before, mise exec -- cmd /c 'echo "a b"' printed \"a b\". Pitchfork daemons with mise = true whose run contained a quote, such as a quoted program path with a space, also failed to start. mise now passes a single quoted command after /c or /k to cmd unchanged. #​13887 by @​JamBalaya56562
  • Task daemons with init steps start under cmd.exe. Before, they failed with 'exec' is not recognized. On Windows, mise now builds the command with cmd quoting and escaping. Write init steps as cmd commands. #​13928 by @​JamBalaya56562
Other
  • packslip follows repositories that moved to a new owner. mise now treats a transfer like a rename, matching on repository ID with a one-time warning. It still refuses a different repository that reuses a deleted repository's name. Refusal messages now tell you which records to clear: mise packslip forget, the tool's mise.lock entries, or both. Existing pins and lockfile entries still load. #​13710
  • mise dot save and history sync work after a tracked directory is replaced by a symlink. Before, they failed while reading older checkpoints. #​13931
Registry
  • helmfile (1.8.1 and later) and dagu (2.18.0 and later) now install from signed packslip manifests. Older versions still install through aqua:. To list them, run mise ls-remote aqua:helmfile/helmfile or mise ls-remote aqua:dagucloud/dagu. #​13933
  • New aqua packages: goccy/tobari, ymmt2005/pbschema-lens.

Full Changelog: https://github.com/jdx/mise/compare/v2026.10.1...v2026.10.2

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

mermaid-js/mermaid (mermaid)

v12.1.0

Compare Source

Minor Changes
  • #​8303 9140716 Thanks @​filipsajdak! - feat: add the elk.orientFeedbackEdges option, enabled by default. With the ELK layout, an edge from a node that a subgraph feeds back into that subgraph is now routed downstream instead of around the subgraph. This changes the layout of existing ELK diagrams that contain such edges; set elk.orientFeedbackEdges: false to keep the previous routing.

  • #​8250 fd4f5f2 Thanks @​kartben! - feat: add a bitOrder option to packet diagrams. It defaults to ascending, which is the current
    behaviour, and descending mirrors every row so it reads from that row's highest bit down to its
    lowest. Fields are still declared lowest bit first and keep their width, so switching a diagram
    between the two conventions only means changing bitOrder.

Patch Changes
  • #​8330 50c9e55 Thanks @​ashishjain0512! - fix: upgrade chevrotain to 13 so mermaid no longer pulls in vulnerable lodash-es@4.17.23

  • #​8259 4c90f5c Thanks @​afonsojanu! - fix(sequence): allow whitespace between an actor name and its @{ ... } config object

    participant Bob@{ "type" : "database" } parsed fine, but adding a single space before the
    config object (participant Bob @{ "type" : "database" }) failed with a confusing parse error,
    even though the plain form without a config object tolerates trailing whitespace just fine.

  • #​8339 c7fa1a5 Thanks @​ashishjain0512! - fix: keep ELK class-diagram cardinalities off namespace frames

  • #​8334 d67331d Thanks @​ashishjain0512! - fix(class): place cardinality labels beside their relation ends on dagre's sides with ELK, centre dagre's end labels, and stop clipping their text

  • #​8344 99a050b Thanks @​pbrolin47! - fix: with the ELK layout, an edge label could sit up to 16px beside its edge instead of centred on it, when the edge's terminal jog was straightened after the label's position was computed. The label is now re-projected onto the straightened route

  • #​8276 3101c7d Thanks @​mir-ashiq! - fix(error): show the actual error message in the error diagram

    When a diagram fails to parse, the error diagram now draws the real error message below the
    "Syntax error in text" headline, wrapped to at most four lines. Hosts that only show the SVG
    (GitHub, GitLab, Obsidian, exported images) no longer hide what actually went wrong, e.g. that the
    flowchart edge limit was exceeded and maxEdges needs raising via mermaid.initialize.

  • #​8296 aa29345 Thanks @​pentaoa! - fix: preserve explicit source relations on event modeling reset frames

  • #​8297 967bbde Thanks @​pentaoa! - fix: reject duplicate event modeling frame IDs before rendering

  • #​8337 147f343 Thanks @​knsv-bot! - fix: a flowchart that declares the same subgraph id more than once now renders as one merged subgraph with the ELK layout instead of producing NaN geometry. Classes and view: collapsed set on a repeated subgraph now apply to it, whichever declaration they follow.

  • #​8203 40ef7b4 Thanks @​MFA-G! - perf(frontmatter): replace the quadratic front matter regex on hot paths

    frontMatterRegex backtracks polynomially on whitespace-heavy input, so a
    diagram well inside the default maxTextSize could stall parsing for over a
    second. detectType and extractFrontMatter now use a linear scanner that
    matches the regex result exactly, leaving no document stripped differently.

  • #​8254 351d7d2 Thanks @​galshir! - fix: warn when a gantt task references an unknown after/until task id, or when its end value is neither a valid date nor a valid duration

  • #​8249 b657a2c Thanks @​mir-ashiq! - fix(sequence): allow hyphenated actor and participant names when a config object is attached

  • #​8300 c38a565 Thanks @​filipsajdak! - fix: A partial override of an object-valued theme variable such as xyChart, radar or cynefin keeps the values the theme generates for the keys it leaves out

  • #​8333 8afd83c Thanks @​ashishjain0512! - fix: upgrade the parser to langium 4.4 / chevrotain 13 so bundles no longer include lodash-es@4.17.23

  • #​8285 859f1f8 Thanks @​mir-ashiq! - fix(sequence): allow actor-menu keywords as participant ids in messages

    A participant declared as Link (or Links, Properties, Details) could not be used as a
    message endpoint: the lexer matched the name as the link statement keyword and the parse failed.
    The link, links, properties and details keywords are now only recognized when an actor
    follows them on the same line, so participant ids that happen to spell these words work in
    messages, while the statements themselves keep parsing as before.

  • #​8282 b6d952d Thanks @​belomaxorka! - fix(sequence): allow Link as a participant ID in messages and actor menus

    Preserve the ID's case and alias while keeping the link and links menu commands supported.

  • #​8345 7917c1a Thanks @​knsv-bot! - fix: xychart measures text in SVG units so legends no longer clip on wide charts scaled to fit their container, and the chart title is dropped instead of overflowing when the chart is too short for it

  • #​8338 4a722fb Thanks @​ashishjain0512! - fix: Centre the xychart title over the plot area instead of the whole chart

  • Updated dependencies [8afd83c]:

webgrip/workflows (webgrip/workflows)

v2.7.8

Compare Source

Fixed
  • dnscontrol: een push die een zone zou aanmaken wordt geweigerd (72967d4)
cloudflare/workers-sdk (wrangler)

v4.147.0

Compare Source

Minor Changes
  • #​15928 7f57b1c Thanks @​ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Patch Changes
  • #​15974 7f700ef Thanks @​martinezjandrew! - Fix wrangler containers list to report live instances

    The LIVE INSTANCES column now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existing instances field.

  • #​15980 90e6a1b Thanks @​martinezjandrew! - Accept Durable Object application IDs in Containers commands

    wrangler containers instances and wrangler containers delete now accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs.

  • #​15871 6a4b0fe Thanks @​tw4! - Retry transient API failures in wrangler workflows instances list and wrangler workflows instances describe

    Previously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves --id latest is retried too, which also benefits the other wrangler workflows instances commands that accept latest; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under --json any retry notices are written to stderr so stdout stays valid JSON.

  • Updated dependencies []:


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Type | Update | Change | Released | Age (d) | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---|---|---|---|---| | [jdx/mise](https://github.com/jdx/mise) | uses-with | patch | `2026.10.1` → `2026.10.2` | 2026-10-04T12:31:22.000Z | 1d | ![age](https://developer.mend.io/api/mc/badges/age/github-release-attachments/jdx%2fmise/v2026.10.2?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/github-release-attachments/jdx%2fmise/v2026.10.2?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/github-release-attachments/jdx%2fmise/v2026.10.1/v2026.10.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-release-attachments/jdx%2fmise/v2026.10.1/v2026.10.2?slim=true) | | [mermaid](https://github.com/mermaid-js/mermaid) | | minor | `12.0.0` → `12.1.0` | 2026-10-02T11:14:26.341Z | 3d | ![age](https://developer.mend.io/api/mc/badges/age/npm/mermaid/12.1.0?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/mermaid/12.1.0?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/mermaid/12.0.0/12.1.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/mermaid/12.0.0/12.1.0?slim=true) | | [webgrip/workflows](https://forgejo.webgrip.dev/webgrip/workflows) | action | patch | `v2.7.7` → `v2.7.8` | 2026-10-04T10:56:14.000Z | 1d | ![age](https://developer.mend.io/api/mc/badges/age/gitea-tags/webgrip%2fworkflows/v2.7.8?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/gitea-tags/webgrip%2fworkflows/v2.7.8?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/gitea-tags/webgrip%2fworkflows/v2.7.7/v2.7.8?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/gitea-tags/webgrip%2fworkflows/v2.7.7/v2.7.8?slim=true) | | [wrangler](https://github.com/cloudflare/workers-sdk) ([source](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler)) | devDependencies | minor | [`4.146.0` → `4.147.0`](https://renovatebot.com/diffs/npm/wrangler/4.146.0/4.147.0) | 2026-10-02T11:30:47.699Z | 3d | ![age](https://developer.mend.io/api/mc/badges/age/npm/wrangler/4.147.0?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/wrangler/4.147.0?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/wrangler/4.146.0/4.147.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/wrangler/4.146.0/4.147.0?slim=true) | 📦 **Grouped update**: confirm the group is operationally coherent before merging. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means the datasource reports no release timestamp. Docker Hub is the only Docker registry that reports one, so this preset treats every other Docker registry (ghcr.io, quay.io, Harbor and its proxies, dhi.io) as `timestamp-optional`: `minimumReleaseAge` cannot hold those updates back and they are eligible as soon as checks pass. For any other datasource, a missing timestamp holds the update for as long as a soak applies. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### Release Notes <details> <summary>jdx/mise (jdx/mise)</summary> ### [`v2026.10.2`](https://github.com/jdx/mise/releases/tag/v2026.10.2): : Experimental spinel backend, typed tool options in the schema, and daemon presets on Windows [Compare Source](https://github.com/jdx/mise/compare/mise-sigstore-v2026.10.1...vfox-v2026.10.2) This release adds an experimental `spinel:` backend for compiling Ruby CLIs to native binaries. The `mise.toml` schema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting. ##### Added - **Experimental `spinel:` backend.** It builds a Ruby command-line tool from a GitHub repository into a native executable using [Spinel](https://github.com/matz/spinel), Matz's Ruby AOT compiler. Versions come from git tags through `git ls-remote`, so listing them doesn't call the GitHub API. Available options: `entrypoint`, `bin`, `tag_prefix`, `source_ref` and `spinel`. You need the `spinel` compiler on `PATH` (mise doesn't install it yet) and `mise settings experimental=true`. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on [nateberkopec/mise-backend-spinel](https://github.com/nateberkopec/mise-backend-spinel). [#&#8203;13922](https://github.com/jdx/mise/pull/13922) ```toml [tools."spinel:tobi/try"] version = "1.10.1" entrypoint = "try.rb" bin = "try" tag_prefix = "v" ``` - **Typed tool options in the JSON schema.** Editors that use `schema/mise.json` now validate and autocomplete options for each backend, based on the tool's prefix. This covers github, gitlab, forgejo, ubi, http, s3, aqua, cargo, npm, pypi/pipx, gem, go, conda, spm, packslip and spinel. It also covers core-tool options for `python`, `java`, `rust` and `dotnet`, per-platform overrides (`platforms.<os>-<arch>`) and `[tasks.*.tools]` tables. For example, a numeric `asset_pattern` or `java` `release_type = "stable"` is now flagged. Boolean options accept `true`/`false`, `"true"`/`"false"` and `1`/`0`, the same values mise accepts. `lazy_bins` accepts a single string. The deprecated `experimental_monorepo_root` key is allowed again. Runtime behavior is unchanged, but your editor may now flag mistakes in existing configs. [#&#8203;13924](https://github.com/jdx/mise/pull/13924) - **Daemon presets on Windows.** `mise daemons start` no longer refuses preset daemons on Windows. Every preset except `redis`, which has no Windows build, now runs under pitchfork's default `cmd /C` shell. For PostgreSQL to stop cleanly, you need pitchfork 2.29.0 or later. PostgreSQL also won't start from an elevated prompt. Windows reserves some port ranges for Hyper-V and WSL, so a preset's default port can be blocked. If it is, set a different one with `ports`. [#&#8203;13929](https://github.com/jdx/mise/pull/13929) by [@&#8203;JamBalaya56562](https://github.com/JamBalaya56562) ```toml [daemons.db] preset = "postgres" version = "18" options = { database = "app" } ``` - **Install mise with packslip.** The installation guide now covers installing mise's signed release without running an install script. packslip verifies the Sigstore signature and the archive digest. `mise self-update` works with this install method. [#&#8203;13710](https://github.com/jdx/mise/pull/13710) ```sh packslip install github.com/jdx/mise --pin ps1_nlhmwtfeufglxv5myvwvronk7a ``` ##### Fixed ##### Config and activation - **An untrusted project config no longer breaks shell activation.** Before, `mise hook-env` failed completely, so tools and env from your trusted global config were not applied either. Now it skips the untrusted file, prints the usual one-time warning and loads everything else. Explicit commands such as `mise run` and `mise x` still error on untrusted configs. [#&#8203;13919](https://github.com/jdx/mise/pull/13919) - **A failed settings reload is reported as an error instead of crashing.** Commands such as `mise install`, `mise use`, `mise upgrade` and `mise ls-remote --prerelease` reload settings partway through. Before, a failed reload aborted mise with SIGABRT and a core dump. Now mise prints `failed to reload settings` with the cause and keeps using the previous settings. [#&#8203;13925](https://github.com/jdx/mise/pull/13925) - **`--no-config` and `MISE_NO_CONFIG=1` now skip `.miserc.toml` discovery.** Before, a malformed project, global or system miserc broke commands like `mise --no-config version`. [#&#8203;13926](https://github.com/jdx/mise/pull/13926) by [@&#8203;donbeave](https://github.com/donbeave) ##### Tasks - **A timed-out task fails even if it exits cleanly.** On Unix, a task that caught SIGTERM and exited 0 after its `timeout` was reported as successful. Now `mise run` reports `timed out` and exits non-zero. [#&#8203;13930](https://github.com/jdx/mise/pull/13930) by [@&#8203;Marukome0743](https://github.com/Marukome0743) - **Timed-out tasks on Windows can clean up.** When a task hits its `timeout`, mise now sends it Ctrl+C and gives it 5 seconds before ending its process tree, the way Unix uses SIGTERM followed by SIGKILL. For example, PowerShell `finally` blocks now run. Only the timed-out task gets the Ctrl+C. The whole-run `mise run --timeout` still stops tasks immediately on Windows. [#&#8203;13889](https://github.com/jdx/mise/pull/13889) by [@&#8203;JamBalaya56562](https://github.com/JamBalaya56562) ##### Windows - **`mise exec -- cmd /c` keeps double quotes.** Before, `mise exec -- cmd /c 'echo "a b"'` printed `\"a b\"`. Pitchfork daemons with `mise = true` whose `run` contained a quote, such as a quoted program path with a space, also failed to start. mise now passes a single quoted command after `/c` or `/k` to cmd unchanged. [#&#8203;13887](https://github.com/jdx/mise/pull/13887) by [@&#8203;JamBalaya56562](https://github.com/JamBalaya56562) - **Task daemons with `init` steps start under `cmd.exe`.** Before, they failed with `'exec' is not recognized`. On Windows, mise now builds the command with cmd quoting and escaping. Write `init` steps as cmd commands. [#&#8203;13928](https://github.com/jdx/mise/pull/13928) by [@&#8203;JamBalaya56562](https://github.com/JamBalaya56562) ##### Other - **packslip follows repositories that moved to a new owner.** mise now treats a transfer like a rename, matching on repository ID with a one-time warning. It still refuses a different repository that reuses a deleted repository's name. Refusal messages now tell you which records to clear: `mise packslip forget`, the tool's `mise.lock` entries, or both. Existing pins and lockfile entries still load. [#&#8203;13710](https://github.com/jdx/mise/pull/13710) - **`mise dot save` and history sync work after a tracked directory is replaced by a symlink.** Before, they failed while reading older checkpoints. [#&#8203;13931](https://github.com/jdx/mise/pull/13931) ##### Registry - `helmfile` (1.8.1 and later) and `dagu` (2.18.0 and later) now install from signed packslip manifests. Older versions still install through `aqua:`. To list them, run `mise ls-remote aqua:helmfile/helmfile` or `mise ls-remote aqua:dagucloud/dagu`. [#&#8203;13933](https://github.com/jdx/mise/pull/13933) - New aqua packages: `goccy/tobari`, `ymmt2005/pbschema-lens`. **Full Changelog**: <https://github.com/jdx/mise/compare/v2026.10.1...v2026.10.2> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. </details> <details> <summary>mermaid-js/mermaid (mermaid)</summary> ### [`v12.1.0`](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4012.1.0) [Compare Source](https://github.com/mermaid-js/mermaid/compare/mermaid@12.0.0...mermaid@12.1.0) ##### Minor Changes - [#&#8203;8303](https://github.com/mermaid-js/mermaid/pull/8303) [`9140716`](https://github.com/mermaid-js/mermaid/commit/9140716e72d1c1a3eb82bd5b25786e44f0cb6163) Thanks [@&#8203;filipsajdak](https://github.com/filipsajdak)! - feat: add the `elk.orientFeedbackEdges` option, enabled by default. With the ELK layout, an edge from a node that a subgraph feeds back into that subgraph is now routed downstream instead of around the subgraph. This changes the layout of existing ELK diagrams that contain such edges; set `elk.orientFeedbackEdges: false` to keep the previous routing. - [#&#8203;8250](https://github.com/mermaid-js/mermaid/pull/8250) [`fd4f5f2`](https://github.com/mermaid-js/mermaid/commit/fd4f5f26546110b4da281b44d60f94644f9a146c) Thanks [@&#8203;kartben](https://github.com/kartben)! - feat: add a `bitOrder` option to packet diagrams. It defaults to `ascending`, which is the current behaviour, and `descending` mirrors every row so it reads from that row's highest bit down to its lowest. Fields are still declared lowest bit first and keep their width, so switching a diagram between the two conventions only means changing `bitOrder`. ##### Patch Changes - [#&#8203;8330](https://github.com/mermaid-js/mermaid/pull/8330) [`50c9e55`](https://github.com/mermaid-js/mermaid/commit/50c9e555a17725e50a9cf92f4a0876710e44a53a) Thanks [@&#8203;ashishjain0512](https://github.com/ashishjain0512)! - fix: upgrade chevrotain to 13 so mermaid no longer pulls in vulnerable `lodash-es@4.17.23` - [#&#8203;8259](https://github.com/mermaid-js/mermaid/pull/8259) [`4c90f5c`](https://github.com/mermaid-js/mermaid/commit/4c90f5c4487c5c5628e28073454e88708af26bfb) Thanks [@&#8203;afonsojanu](https://github.com/afonsojanu)! - fix(sequence): allow whitespace between an actor name and its `@{ ... }` config object `participant Bob@{ "type" : "database" }` parsed fine, but adding a single space before the config object (`participant Bob @{ "type" : "database" }`) failed with a confusing parse error, even though the plain form without a config object tolerates trailing whitespace just fine. - [#&#8203;8339](https://github.com/mermaid-js/mermaid/pull/8339) [`c7fa1a5`](https://github.com/mermaid-js/mermaid/commit/c7fa1a550cf024ce1c74faece36ecf18a5935c5e) Thanks [@&#8203;ashishjain0512](https://github.com/ashishjain0512)! - fix: keep ELK class-diagram cardinalities off namespace frames - [#&#8203;8334](https://github.com/mermaid-js/mermaid/pull/8334) [`d67331d`](https://github.com/mermaid-js/mermaid/commit/d67331d927d90e53ed0cd6da7e031f3513866d41) Thanks [@&#8203;ashishjain0512](https://github.com/ashishjain0512)! - fix(class): place cardinality labels beside their relation ends on dagre's sides with ELK, centre dagre's end labels, and stop clipping their text - [#&#8203;8344](https://github.com/mermaid-js/mermaid/pull/8344) [`99a050b`](https://github.com/mermaid-js/mermaid/commit/99a050ba56c834569df4d9891c70fd23ffe92203) Thanks [@&#8203;pbrolin47](https://github.com/pbrolin47)! - fix: with the ELK layout, an edge label could sit up to 16px beside its edge instead of centred on it, when the edge's terminal jog was straightened after the label's position was computed. The label is now re-projected onto the straightened route - [#&#8203;8276](https://github.com/mermaid-js/mermaid/pull/8276) [`3101c7d`](https://github.com/mermaid-js/mermaid/commit/3101c7da2add126d0e1f3e256f408620efdd987e) Thanks [@&#8203;mir-ashiq](https://github.com/mir-ashiq)! - fix(error): show the actual error message in the error diagram When a diagram fails to parse, the error diagram now draws the real error message below the "Syntax error in text" headline, wrapped to at most four lines. Hosts that only show the SVG (GitHub, GitLab, Obsidian, exported images) no longer hide what actually went wrong, e.g. that the flowchart edge limit was exceeded and `maxEdges` needs raising via `mermaid.initialize`. - [#&#8203;8296](https://github.com/mermaid-js/mermaid/pull/8296) [`aa29345`](https://github.com/mermaid-js/mermaid/commit/aa29345b9a5c58346fb457396614cfd349a94e68) Thanks [@&#8203;pentaoa](https://github.com/pentaoa)! - fix: preserve explicit source relations on event modeling reset frames - [#&#8203;8297](https://github.com/mermaid-js/mermaid/pull/8297) [`967bbde`](https://github.com/mermaid-js/mermaid/commit/967bbdeb1b47a46f9f73c65d009d1dd19381cc05) Thanks [@&#8203;pentaoa](https://github.com/pentaoa)! - fix: reject duplicate event modeling frame IDs before rendering - [#&#8203;8337](https://github.com/mermaid-js/mermaid/pull/8337) [`147f343`](https://github.com/mermaid-js/mermaid/commit/147f343c863f537e1acd4d1df527eccfc88574c8) Thanks [@&#8203;knsv-bot](https://github.com/knsv-bot)! - fix: a flowchart that declares the same subgraph id more than once now renders as one merged subgraph with the ELK layout instead of producing NaN geometry. Classes and `view: collapsed` set on a repeated subgraph now apply to it, whichever declaration they follow. - [#&#8203;8203](https://github.com/mermaid-js/mermaid/pull/8203) [`40ef7b4`](https://github.com/mermaid-js/mermaid/commit/40ef7b47259cb9dd335583298917c69d1174e2cb) Thanks [@&#8203;MFA-G](https://github.com/MFA-G)! - perf(frontmatter): replace the quadratic front matter regex on hot paths `frontMatterRegex` backtracks polynomially on whitespace-heavy input, so a diagram well inside the default `maxTextSize` could stall parsing for over a second. `detectType` and `extractFrontMatter` now use a linear scanner that matches the regex result exactly, leaving no document stripped differently. - [#&#8203;8254](https://github.com/mermaid-js/mermaid/pull/8254) [`351d7d2`](https://github.com/mermaid-js/mermaid/commit/351d7d21af7f8e1dba6e021bef7e0c30f3deb92f) Thanks [@&#8203;galshir](https://github.com/galshir)! - fix: warn when a gantt task references an unknown `after`/`until` task id, or when its end value is neither a valid date nor a valid duration - [#&#8203;8249](https://github.com/mermaid-js/mermaid/pull/8249) [`b657a2c`](https://github.com/mermaid-js/mermaid/commit/b657a2c0735e60d9049d5078a550e0625cf42b2e) Thanks [@&#8203;mir-ashiq](https://github.com/mir-ashiq)! - fix(sequence): allow hyphenated actor and participant names when a config object is attached - [#&#8203;8300](https://github.com/mermaid-js/mermaid/pull/8300) [`c38a565`](https://github.com/mermaid-js/mermaid/commit/c38a56597c07ce6af62081aa3f1536c09a101a42) Thanks [@&#8203;filipsajdak](https://github.com/filipsajdak)! - fix: A partial override of an object-valued theme variable such as `xyChart`, `radar` or `cynefin` keeps the values the theme generates for the keys it leaves out - [#&#8203;8333](https://github.com/mermaid-js/mermaid/pull/8333) [`8afd83c`](https://github.com/mermaid-js/mermaid/commit/8afd83c9fd7a4b9dfdc08cd620fbf38978bb7982) Thanks [@&#8203;ashishjain0512](https://github.com/ashishjain0512)! - fix: upgrade the parser to langium 4.4 / chevrotain 13 so bundles no longer include `lodash-es@4.17.23` - [#&#8203;8285](https://github.com/mermaid-js/mermaid/pull/8285) [`859f1f8`](https://github.com/mermaid-js/mermaid/commit/859f1f81a23836552b60cdfece9af5d11fca12c7) Thanks [@&#8203;mir-ashiq](https://github.com/mir-ashiq)! - fix(sequence): allow actor-menu keywords as participant ids in messages A participant declared as `Link` (or `Links`, `Properties`, `Details`) could not be used as a message endpoint: the lexer matched the name as the `link` statement keyword and the parse failed. The `link`, `links`, `properties` and `details` keywords are now only recognized when an actor follows them on the same line, so participant ids that happen to spell these words work in messages, while the statements themselves keep parsing as before. - [#&#8203;8282](https://github.com/mermaid-js/mermaid/pull/8282) [`b6d952d`](https://github.com/mermaid-js/mermaid/commit/b6d952db3bff4e601c1025d544d207eae5d664b4) Thanks [@&#8203;belomaxorka](https://github.com/belomaxorka)! - fix(sequence): allow `Link` as a participant ID in messages and actor menus Preserve the ID's case and alias while keeping the `link` and `links` menu commands supported. - [#&#8203;8345](https://github.com/mermaid-js/mermaid/pull/8345) [`7917c1a`](https://github.com/mermaid-js/mermaid/commit/7917c1a5dfdc5a436c2aece25c359561181b9731) Thanks [@&#8203;knsv-bot](https://github.com/knsv-bot)! - fix: xychart measures text in SVG units so legends no longer clip on wide charts scaled to fit their container, and the chart title is dropped instead of overflowing when the chart is too short for it - [#&#8203;8338](https://github.com/mermaid-js/mermaid/pull/8338) [`4a722fb`](https://github.com/mermaid-js/mermaid/commit/4a722fb62769cd3e9a572410b4ad33b0e46adae8) Thanks [@&#8203;ashishjain0512](https://github.com/ashishjain0512)! - fix: Centre the xychart title over the plot area instead of the whole chart - Updated dependencies \[[`8afd83c`](https://github.com/mermaid-js/mermaid/commit/8afd83c9fd7a4b9dfdc08cd620fbf38978bb7982)]: - [@&#8203;mermaid-js/parser](https://github.com/mermaid-js/parser)@2.0.1 </details> <details> <summary>webgrip/workflows (webgrip/workflows)</summary> ### [`v2.7.8`](https://forgejo.webgrip.dev/webgrip/workflows/releases/tag/v2.7.8) [Compare Source](https://forgejo.webgrip.dev/webgrip/workflows/compare/v2.7.7...v2.7.8) ##### Fixed - **dnscontrol:** een push die een zone zou aanmaken wordt geweigerd ([72967d4](https://forgejo.webgrip.dev/webgrip/workflows/commit/72967d400a0488b4e05000373a28f0f0282b9821)) </details> <details> <summary>cloudflare/workers-sdk (wrangler)</summary> ### [`v4.147.0`](https://github.com/cloudflare/workers-sdk/blob/HEAD/packages/wrangler/CHANGELOG.md#41470) [Compare Source](https://github.com/cloudflare/workers-sdk/compare/wrangler@4.146.0...wrangler@4.147.0) ##### Minor Changes - [#&#8203;15928](https://github.com/cloudflare/workers-sdk/pull/15928) [`7f57b1c`](https://github.com/cloudflare/workers-sdk/commit/7f57b1c60002ae3f077dd9c1e8cc482371065ef4) Thanks [@&#8203;ichernetsky-cf](https://github.com/ichernetsky-cf)! - Allow `"us"` as a jurisdiction for Container applications Container placement constraints now accept `constraints.jurisdiction: "us"` in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside `"eu"` and `"fedramp"`. ##### Patch Changes - [#&#8203;15974](https://github.com/cloudflare/workers-sdk/pull/15974) [`7f700ef`](https://github.com/cloudflare/workers-sdk/commit/7f700ef52c47127c67f20137a03c051d26a0c8e5) Thanks [@&#8203;martinezjandrew](https://github.com/martinezjandrew)! - Fix `wrangler containers list` to report live instances The `LIVE INSTANCES` column now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existing `instances` field. - [#&#8203;15980](https://github.com/cloudflare/workers-sdk/pull/15980) [`90e6a1b`](https://github.com/cloudflare/workers-sdk/commit/90e6a1be8c67c0687a6a0ce51c9d101c9ad363e0) Thanks [@&#8203;martinezjandrew](https://github.com/martinezjandrew)! - Accept Durable Object application IDs in Containers commands `wrangler containers instances` and `wrangler containers delete` now accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs. - [#&#8203;15871](https://github.com/cloudflare/workers-sdk/pull/15871) [`6a4b0fe`](https://github.com/cloudflare/workers-sdk/commit/6a4b0fefa20ef2ffc52acdcf1cb194210d1b4c4b) Thanks [@&#8203;tw4](https://github.com/tw4)! - Retry transient API failures in `wrangler workflows instances list` and `wrangler workflows instances describe` Previously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves `--id latest` is retried too, which also benefits the other `wrangler workflows instances` commands that accept `latest`; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under `--json` any retry notices are written to stderr so stdout stays valid JSON. - Updated dependencies \[]: - <miniflare@5.20261001.0-alpha> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzIuNSIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMi41IiwidGFyZ2V0QnJhbmNoIjoiZGV2ZWxvcG1lbnQiLCJsYWJlbHMiOlsiYXV0b21lcmdlIiwiZGVwZW5kZW5jaWVzIiwiZ2l0aHViLWFjdGlvbnMiLCJyZW5vdmF0ZSIsInR5cGUvbWlub3IiLCJ0eXBlL3BhdGNoIl19-->
feat(deps): update all non-major dependencies
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / ploeg-pin (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
d5380b6f99
renovate force-pushed renovate/all-non-major from d5380b6f99
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / checks (pull_request) Has been cancelled
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
[Workflow] On Pull Request / ploeg-pin (pull_request) Has been cancelled
[Workflow] On Pull Request / release-policy (pull_request) Has been cancelled
to 88c6e0e49e
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 36s
[Workflow] On Pull Request / checks (pull_request) Failing after 3m25s
[Workflow] On Pull Request / warnings (pull_request) Successful in 1s
[Workflow] On Pull Request / release-policy (pull_request) Failing after 16s
2026-10-05 13:03:00 +00:00
Compare
renovate changed title from feat(deps): update all non-major dependencies to feat(actions): Update all non-major dependencies 2026-10-05 13:04:30 +00:00
renovate force-pushed renovate/all-non-major from 88c6e0e49e
Some checks failed
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 36s
[Workflow] On Pull Request / checks (pull_request) Failing after 3m25s
[Workflow] On Pull Request / warnings (pull_request) Successful in 1s
[Workflow] On Pull Request / release-policy (pull_request) Failing after 16s
to ed009336fe
Some checks failed
[Workflow] On Pull Request / ploeg-pin (pull_request) Successful in 37s
renovate/stability-days Updates have met minimum release age requirement
[Workflow] On Pull Request / release-policy (pull_request) Failing after 45s
[Workflow] On Pull Request / checks (pull_request) Failing after 3m51s
[Workflow] On Pull Request / warnings (pull_request) Successful in 0s
2026-10-05 15:03:13 +00:00
Compare
ryangr0 merged commit e7d1588ad8 into development 2026-10-05 19:08:17 +00:00
ryangr0 deleted branch renovate/all-non-major 2026-10-05 19:08:18 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!247
No description provided.