Skip to content

build(deps): bump jdx/mise-action from 4.3.0 to 5.0.1 - #9

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/jdx/mise-action-5.0.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/jdx/mise-action-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown

Bumps jdx/mise-action from 4.3.0 to 5.0.1.

Release notes

Sourced from jdx/mise-action's releases.

v5.0.1: Verify cached mise binaries before running them

mise-action now checks the integrity of an already-installed mise binary before running it. This fixes a security issue that was reported privately.

Fixed

  • An existing mise binary is verified before it is run. When a mise binary is already on the runner (for example, restored from cache or in mise_dir), the action now checks it before calling it. If you set a sha256 input, the binary must match that checksum and report the requested version. Otherwise, it must match the signed release checksums for the version being installed. If the check fails, the action prints a warning, deletes the binary and installs the requested release again. Before this fix, the action could run a cached binary before checking it. (#637 by @​jdx)

Changed

Changes to how the action handles an existing binary, also from #637:

  • Switching versions uses a full install. If the cached binary doesn't match the requested version, the action downloads and installs that version. It no longer runs mise self-update.
  • Unpinned runs always pick a release. Without a version input, the action now selects a release every time, using minimum_release_age, even when mise is already installed. It then checks the existing binary against that release, and reinstalls if the binary doesn't match.
  • Older releases need a sha256 input to reuse a cached binary. Some older mise releases have no signed checksums. With the sha256 input set, a cached binary of one of these releases can still be reused without a download. Without it, the action can't verify the binary and installs it again.

Full Changelog: jdx/mise-action@v5.0.0...v5.0.1

v5.0.0: Default minimum release age of 24 hours for mise

If you don't pin a version, mise-action now installs the newest stable mise release that is at least 24 hours old. Upgrading mise on a runner that already has it is also less likely to hit GitHub API rate limits.

Breaking Changes

minimum_release_age now defaults to 24h (#632 by @​jdx)

Before this release, minimum_release_age was an opt-in setting. It now defaults to 24h. If you don't set version, the action picks the highest-numbered stable mise release published at least 24 hours ago. A mise release that just shipped won't be installed until it's a day old.

To get the latest stable release right away, as in v4, set the delay to 0s. You can also choose a longer delay:

- uses: jdx/mise-action@v5
  with:
    minimum_release_age: 0s   # or e.g. 7d
  • An explicit version input still takes precedence and skips the delay.
  • The setting applies only to the mise binary, not to tools installed by mise.
  • The action now gets the release list from a public CDN index (releases.tsv on mise.jdx.dev) instead of paging through the GitHub Releases API. Picking a release doesn't use GitHub API quota, even when an installed binary is reused. If the index is missing or malformed, the action fails instead of skipping the release-age check.
  • Replacing an older installed binary still runs mise self-update, which may call the GitHub API to fetch that exact release.

Fixed

  • mise self-update now runs with MISE_GITHUB_TOKEN. When a runner already had a different mise version installed, the action runs mise self-update to switch versions. That GitHub API call used to go out without authentication, so busy shared or self-hosted runners could hit the rate limit and fail with HTTP 403 RateLimitedError. If you already set a token in your environment, the action leaves it unchanged. (#619 by @​hegde5)

New Contributors

Full Changelog: jdx/mise-action@v4.3.0...v5.0.0

Changelog

Sourced from jdx/mise-action's changelog.

Changelog


5.0.1 - 2026-09-30

🐛 Bug Fixes


5.0.0 - 2026-09-28

🚀 Features

🐛 Bug Fixes

  • fix: authenticate mise self-update to avoid GitHub API rate limits (#619) by @​hegde5 in #619

⚙️ Miscellaneous Tasks

New Contributors


4.3.0 - 2026-08-25

🚀 Features


4.2.5 - 2026-08-13

🐛 Bug Fixes


... (truncated)

Commits
  • 7a4e45a chore: release v5.0.1 (#638)
  • c4102d4 fix: verify cached mise before execution (#637)
  • baf7eb4 chore(deps): update dependency aube to latest (#636)
  • c75796c chore(deps): update dependency communique to latest (#635)
  • ec2665b chore(deps): update github actions (#633)
  • 342b4c0 chore(deps): update dependency aube to latest (#634)
  • 9149ea8 chore: release v5.0.0 (#620)
  • 279d505 feat!: default minimum release age to 24 hours (#632)
  • aa79241 chore(entire): restore lower-cost trail findings
  • 6ac0f83 chore(entire): commit claude session hooks
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 3, 2026
Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 4.3.0 to 5.0.1.
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](jdx/mise-action@c2a8761...7a4e45a)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/jdx/mise-action-5.0.1 branch from 7554c09 to 6811fea Compare October 3, 2026 22:33
napalm255 added a commit that referenced this pull request Oct 3, 2026
Adopt [quick-template
v0.1.2](https://github.com/Ghost-Assembly/quick-template/releases/tag/v0.1.2),
pinned to `174a20f771bc1b25d19b5547820fa3647c752a1a`, so dependency and
Action updates preserve all 33 canonical files across the fleet.

Updates Vitest/coverage to 5.0.3, ESLint 10.12.0, eslint-plugin-security
4.2.0, globals 17.13.0, Python 3.14.8, uv 0.12.22, Ruff 0.16.10, Trivy
0.75.0, and gh 2.102.0. Node remains on the current 24 LTS patch. Shared
workflows use current SHA-pinned Actions and mise 2026.10.1; CodeQL
init/analyze share the 4.38.2 commit, and mise-action 5.0.1 fixes
cached-binary verification. Dependabot's separate SONAR_TOKEN secret is
configured.

Full local `just ci` passes: 192 JavaScript tests, 29 Python tests, 52
browser tests, security/source/history scans, and byte-for-byte equality
with GNOME's official packer. Template checks confirm the exact merged
canonical payload. Hosted CI, CodeQL, and authenticated Sonar remain
required before merging; the zero-finding and zero-duplication policy is
unchanged.

Supersedes the dependency versions proposed in #9, #8, #7, #6. Those
proposals will be retired only after this complete update passes and
merges. No extension version release or store submission is included.
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Author

Looks like jdx/mise-action is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 3, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/jdx/mise-action-5.0.1 branch October 3, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants