feat(actions): Update all non-major dependencies #247
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/all-non-major"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
2026.10.1→2026.10.212.0.0→12.1.0v2.7.7→v2.7.84.146.0→4.147.0📦 Grouped update: confirm the group is operationally coherent before merging.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means the datasource reports no release timestamp. Docker Hub is the only Docker registry that reports one, so this preset treats every other Docker registry (ghcr.io, quay.io, Harbor and its proxies, dhi.io) astimestamp-optional:minimumReleaseAgecannot hold those updates back and they are eligible as soon as checks pass. For any other datasource, a missing timestamp holds the update for as long as a soak applies. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.Release Notes
jdx/mise (jdx/mise)
v2026.10.2: : Experimental spinel backend, typed tool options in the schema, and daemon presets on WindowsCompare Source
This release adds an experimental
spinel:backend for compiling Ruby CLIs to native binaries. Themise.tomlschema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting.Added
Experimental
spinel:backend. It builds a Ruby command-line tool from a GitHub repository into a native executable using Spinel, Matz's Ruby AOT compiler. Versions come from git tags throughgit ls-remote, so listing them doesn't call the GitHub API. Available options:entrypoint,bin,tag_prefix,source_refandspinel. You need thespinelcompiler onPATH(mise doesn't install it yet) andmise settings experimental=true. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on nateberkopec/mise-backend-spinel. #13922Typed tool options in the JSON schema. Editors that use
schema/mise.jsonnow validate and autocomplete options for each backend, based on the tool's prefix. This covers github, gitlab, forgejo, ubi, http, s3, aqua, cargo, npm, pypi/pipx, gem, go, conda, spm, packslip and spinel. It also covers core-tool options forpython,java,rustanddotnet, per-platform overrides (platforms.<os>-<arch>) and[tasks.*.tools]tables. For example, a numericasset_patternorjavarelease_type = "stable"is now flagged. Boolean options accepttrue/false,"true"/"false"and1/0, the same values mise accepts.lazy_binsaccepts a single string. The deprecatedexperimental_monorepo_rootkey is allowed again. Runtime behavior is unchanged, but your editor may now flag mistakes in existing configs. #13924Daemon presets on Windows.
mise daemons startno longer refuses preset daemons on Windows. Every preset exceptredis, which has no Windows build, now runs under pitchfork's defaultcmd /Cshell. For PostgreSQL to stop cleanly, you need pitchfork 2.29.0 or later. PostgreSQL also won't start from an elevated prompt. Windows reserves some port ranges for Hyper-V and WSL, so a preset's default port can be blocked. If it is, set a different one withports. #13929 by @JamBalaya56562Install mise with packslip. The installation guide now covers installing mise's signed release without running an install script. packslip verifies the Sigstore signature and the archive digest.
mise self-updateworks with this install method. #13710Fixed
Config and activation
mise hook-envfailed completely, so tools and env from your trusted global config were not applied either. Now it skips the untrusted file, prints the usual one-time warning and loads everything else. Explicit commands such asmise runandmise xstill error on untrusted configs. #13919mise install,mise use,mise upgradeandmise ls-remote --prereleasereload settings partway through. Before, a failed reload aborted mise with SIGABRT and a core dump. Now mise printsfailed to reload settingswith the cause and keeps using the previous settings. #13925--no-configandMISE_NO_CONFIG=1now skip.miserc.tomldiscovery. Before, a malformed project, global or system miserc broke commands likemise --no-config version. #13926 by @donbeaveTasks
timeoutwas reported as successful. Nowmise runreportstimed outand exits non-zero. #13930 by @Marukome0743timeout, mise now sends it Ctrl+C and gives it 5 seconds before ending its process tree, the way Unix uses SIGTERM followed by SIGKILL. For example, PowerShellfinallyblocks now run. Only the timed-out task gets the Ctrl+C. The whole-runmise run --timeoutstill stops tasks immediately on Windows. #13889 by @JamBalaya56562Windows
mise exec -- cmd /ckeeps double quotes. Before,mise exec -- cmd /c 'echo "a b"'printed\"a b\". Pitchfork daemons withmise = truewhoseruncontained a quote, such as a quoted program path with a space, also failed to start. mise now passes a single quoted command after/cor/kto cmd unchanged. #13887 by @JamBalaya56562initsteps start undercmd.exe. Before, they failed with'exec' is not recognized. On Windows, mise now builds the command with cmd quoting and escaping. Writeinitsteps as cmd commands. #13928 by @JamBalaya56562Other
mise packslip forget, the tool'smise.lockentries, or both. Existing pins and lockfile entries still load. #13710mise dot saveand history sync work after a tracked directory is replaced by a symlink. Before, they failed while reading older checkpoints. #13931Registry
helmfile(1.8.1 and later) anddagu(2.18.0 and later) now install from signed packslip manifests. Older versions still install throughaqua:. To list them, runmise ls-remote aqua:helmfile/helmfileormise ls-remote aqua:dagucloud/dagu. #13933goccy/tobari,ymmt2005/pbschema-lens.Full Changelog: https://github.com/jdx/mise/compare/v2026.10.1...v2026.10.2
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
mermaid-js/mermaid (mermaid)
v12.1.0Compare Source
Minor Changes
#8303
9140716Thanks @filipsajdak! - feat: add theelk.orientFeedbackEdgesoption, enabled by default. With the ELK layout, an edge from a node that a subgraph feeds back into that subgraph is now routed downstream instead of around the subgraph. This changes the layout of existing ELK diagrams that contain such edges; setelk.orientFeedbackEdges: falseto keep the previous routing.#8250
fd4f5f2Thanks @kartben! - feat: add abitOrderoption to packet diagrams. It defaults toascending, which is the currentbehaviour, and
descendingmirrors every row so it reads from that row's highest bit down to itslowest. Fields are still declared lowest bit first and keep their width, so switching a diagram
between the two conventions only means changing
bitOrder.Patch Changes
#8330
50c9e55Thanks @ashishjain0512! - fix: upgrade chevrotain to 13 so mermaid no longer pulls in vulnerablelodash-es@4.17.23#8259
4c90f5cThanks @afonsojanu! - fix(sequence): allow whitespace between an actor name and its@{ ... }config objectparticipant Bob@{ "type" : "database" }parsed fine, but adding a single space before theconfig object (
participant Bob @{ "type" : "database" }) failed with a confusing parse error,even though the plain form without a config object tolerates trailing whitespace just fine.
#8339
c7fa1a5Thanks @ashishjain0512! - fix: keep ELK class-diagram cardinalities off namespace frames#8334
d67331dThanks @ashishjain0512! - fix(class): place cardinality labels beside their relation ends on dagre's sides with ELK, centre dagre's end labels, and stop clipping their text#8344
99a050bThanks @pbrolin47! - fix: with the ELK layout, an edge label could sit up to 16px beside its edge instead of centred on it, when the edge's terminal jog was straightened after the label's position was computed. The label is now re-projected onto the straightened route#8276
3101c7dThanks @mir-ashiq! - fix(error): show the actual error message in the error diagramWhen a diagram fails to parse, the error diagram now draws the real error message below the
"Syntax error in text" headline, wrapped to at most four lines. Hosts that only show the SVG
(GitHub, GitLab, Obsidian, exported images) no longer hide what actually went wrong, e.g. that the
flowchart edge limit was exceeded and
maxEdgesneeds raising viamermaid.initialize.#8296
aa29345Thanks @pentaoa! - fix: preserve explicit source relations on event modeling reset frames#8297
967bbdeThanks @pentaoa! - fix: reject duplicate event modeling frame IDs before rendering#8337
147f343Thanks @knsv-bot! - fix: a flowchart that declares the same subgraph id more than once now renders as one merged subgraph with the ELK layout instead of producing NaN geometry. Classes andview: collapsedset on a repeated subgraph now apply to it, whichever declaration they follow.#8203
40ef7b4Thanks @MFA-G! - perf(frontmatter): replace the quadratic front matter regex on hot pathsfrontMatterRegexbacktracks polynomially on whitespace-heavy input, so adiagram well inside the default
maxTextSizecould stall parsing for over asecond.
detectTypeandextractFrontMatternow use a linear scanner thatmatches the regex result exactly, leaving no document stripped differently.
#8254
351d7d2Thanks @galshir! - fix: warn when a gantt task references an unknownafter/untiltask id, or when its end value is neither a valid date nor a valid duration#8249
b657a2cThanks @mir-ashiq! - fix(sequence): allow hyphenated actor and participant names when a config object is attached#8300
c38a565Thanks @filipsajdak! - fix: A partial override of an object-valued theme variable such asxyChart,radarorcynefinkeeps the values the theme generates for the keys it leaves out#8333
8afd83cThanks @ashishjain0512! - fix: upgrade the parser to langium 4.4 / chevrotain 13 so bundles no longer includelodash-es@4.17.23#8285
859f1f8Thanks @mir-ashiq! - fix(sequence): allow actor-menu keywords as participant ids in messagesA participant declared as
Link(orLinks,Properties,Details) could not be used as amessage endpoint: the lexer matched the name as the
linkstatement keyword and the parse failed.The
link,links,propertiesanddetailskeywords are now only recognized when an actorfollows them on the same line, so participant ids that happen to spell these words work in
messages, while the statements themselves keep parsing as before.
#8282
b6d952dThanks @belomaxorka! - fix(sequence): allowLinkas a participant ID in messages and actor menusPreserve the ID's case and alias while keeping the
linkandlinksmenu commands supported.#8345
7917c1aThanks @knsv-bot! - fix: xychart measures text in SVG units so legends no longer clip on wide charts scaled to fit their container, and the chart title is dropped instead of overflowing when the chart is too short for it#8338
4a722fbThanks @ashishjain0512! - fix: Centre the xychart title over the plot area instead of the whole chartUpdated dependencies [
8afd83c]:webgrip/workflows (webgrip/workflows)
v2.7.8Compare Source
Fixed
cloudflare/workers-sdk (wrangler)
v4.147.0Compare Source
Minor Changes
#15928
7f57b1cThanks @ichernetsky-cf! - Allow"us"as a jurisdiction for Container applicationsContainer placement constraints now accept
constraints.jurisdiction: "us"in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside"eu"and"fedramp".Patch Changes
#15974
7f700efThanks @martinezjandrew! - Fixwrangler containers listto report live instancesThe
LIVE INSTANCEScolumn now reports each application's active runtime instances instead of its configured instance count, matching the Cloudflare dashboard. JSON output continues to expose the configured count through the existinginstancesfield.#15980
90e6a1bThanks @martinezjandrew! - Accept Durable Object application IDs in Containers commandswrangler containers instancesandwrangler containers deletenow accept the 32-character hexadecimal application IDs returned for Durable Object-backed applications, in addition to legacy dashed UUIDs.#15871
6a4b0feThanks @tw4! - Retry transient API failures inwrangler workflows instances listandwrangler workflows instances describePreviously, a single temporary 5xx response or dropped connection made these read-only commands exit with an error, even though the next request would have succeeded. They now use Wrangler's existing bounded API retry handling. The read that resolves
--id latestis retried too, which also benefits the otherwrangler workflows instancescommands that acceptlatest; the mutating requests they make afterwards are not retried. Persistent failures are still reported after the retries are exhausted, and under--jsonany retry notices are written to stderr so stdout stays valid JSON.Updated dependencies []:
Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.
d5380b6f9988c6e0e49efeat(deps): update all non-major dependenciesto feat(actions): Update all non-major dependencies88c6e0e49eed009336fe