Skip to content

chore(deps): Bump the dependencies group with 2 updates - #1287

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dependencies-935faae5d3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dependencies-935faae5d3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 2 updates: jdx/mise-action and codelytv/pr-size-labeler.

Updates jdx/mise-action from 4.3.0 to 5.0.1

Release notes

Sourced from jdx/mise-action's releases.

v5.0.1: Verify cached mise binaries before running them

mise-action now checks the integrity of an already-installed mise binary before running it. This fixes a security issue that was reported privately.

Fixed

  • An existing mise binary is verified before it is run. When a mise binary is already on the runner (for example, restored from cache or in mise_dir), the action now checks it before calling it. If you set a sha256 input, the binary must match that checksum and report the requested version. Otherwise, it must match the signed release checksums for the version being installed. If the check fails, the action prints a warning, deletes the binary and installs the requested release again. Before this fix, the action could run a cached binary before checking it. (#637 by @​jdx)

Changed

Changes to how the action handles an existing binary, also from #637:

  • Switching versions uses a full install. If the cached binary doesn't match the requested version, the action downloads and installs that version. It no longer runs mise self-update.
  • Unpinned runs always pick a release. Without a version input, the action now selects a release every time, using minimum_release_age, even when mise is already installed. It then checks the existing binary against that release, and reinstalls if the binary doesn't match.
  • Older releases need a sha256 input to reuse a cached binary. Some older mise releases have no signed checksums. With the sha256 input set, a cached binary of one of these releases can still be reused without a download. Without it, the action can't verify the binary and installs it again.

Full Changelog: jdx/mise-action@v5.0.0...v5.0.1

v5.0.0: Default minimum release age of 24 hours for mise

If you don't pin a version, mise-action now installs the newest stable mise release that is at least 24 hours old. Upgrading mise on a runner that already has it is also less likely to hit GitHub API rate limits.

Breaking Changes

minimum_release_age now defaults to 24h (#632 by @​jdx)

Before this release, minimum_release_age was an opt-in setting. It now defaults to 24h. If you don't set version, the action picks the highest-numbered stable mise release published at least 24 hours ago. A mise release that just shipped won't be installed until it's a day old.

To get the latest stable release right away, as in v4, set the delay to 0s. You can also choose a longer delay:

- uses: jdx/mise-action@v5
  with:
    minimum_release_age: 0s   # or e.g. 7d
  • An explicit version input still takes precedence and skips the delay.
  • The setting applies only to the mise binary, not to tools installed by mise.
  • The action now gets the release list from a public CDN index (releases.tsv on mise.jdx.dev) instead of paging through the GitHub Releases API. Picking a release doesn't use GitHub API quota, even when an installed binary is reused. If the index is missing or malformed, the action fails instead of skipping the release-age check.
  • Replacing an older installed binary still runs mise self-update, which may call the GitHub API to fetch that exact release.

Fixed

  • mise self-update now runs with MISE_GITHUB_TOKEN. When a runner already had a different mise version installed, the action runs mise self-update to switch versions. That GitHub API call used to go out without authentication, so busy shared or self-hosted runners could hit the rate limit and fail with HTTP 403 RateLimitedError. If you already set a token in your environment, the action leaves it unchanged. (#619 by @​hegde5)

New Contributors

Full Changelog: jdx/mise-action@v4.3.0...v5.0.0

Changelog

Sourced from jdx/mise-action's changelog.

Changelog


5.1.1 - 2026-10-04

🐛 Bug Fixes


5.1.0 - 2026-10-04

🚀 Features

🐛 Bug Fixes

  • (cache) keep a cached mise instead of re-downloading when version is unset (#642) by @​jdx in #642
  • save cache after inexact cache restore (#646) by @​jdx in #646
  • extract mise zip with PowerShell instead of unzip on Windows (#650) by @​jdx in #650
  • cache mise binary for caches saved without a version record (#648) by @​jdx in #648

📚 Documentation

  • explain the Rust cache caveat and workarounds (#651) by @​jdx in #651
  • add matrix and external cache guides; warn on shadowed mise_toml (#654) by @​jdx in #654

⚙️ Miscellaneous Tasks


5.0.1 - 2026-09-30

🐛 Bug Fixes


5.0.0 - 2026-09-28

🚀 Features

... (truncated)

Commits
  • 7a4e45a chore: release v5.0.1 (#638)
  • c4102d4 fix: verify cached mise before execution (#637)
  • baf7eb4 chore(deps): update dependency aube to latest (#636)
  • c75796c chore(deps): update dependency communique to latest (#635)
  • ec2665b chore(deps): update github actions (#633)
  • 342b4c0 chore(deps): update dependency aube to latest (#634)
  • 9149ea8 chore: release v5.0.0 (#620)
  • 279d505 feat!: default minimum release age to 24 hours (#632)
  • aa79241 chore(entire): restore lower-cost trail findings
  • 6ac0f83 chore(entire): commit claude session hooks
  • Additional commits viewable in compare view

Updates codelytv/pr-size-labeler from 1.10.4 to 1.12.0

Release notes

Sourced from codelytv/pr-size-labeler's releases.

v1.12.0

What's Changed

Full Changelog: CodelyTV/pr-size-labeler@v1.11.1...v1.12.0

v1.11.1

What's Changed

Full Changelog: CodelyTV/pr-size-labeler@v1.11.0...v1.11.1

v1.11.0

What's Changed

Full Changelog: CodelyTV/pr-size-labeler@v1.10.5...v1.11.0

v1.10.5

What's Changed

New Contributors

Full Changelog: CodelyTV/pr-size-labeler@v1.10.4...v1.10.5

Commits
  • 19c335e perf: stop fetching PR files at XL threshold (#111)
  • c351236 fix: distinguish exact modification counts from early-stop counts in logs
  • 8cea90c perf: stop fetching PR files at XL threshold
  • 5c7ad1e refactor: count PR file changes during pagination
  • a7900cb fix: label pull requests from forks with a writable token (#112)
  • 4e3aa0f fix: preserve labels added by other automations (#110)
  • e1869bf feat: improve DX when required permissions are missing and reduce the number ...
  • 352cc2a fix: report GitHub API permission failures
  • 6c2d916 docs: document minimal pull request permissions
  • 9366474 docs: clarify files_to_ignore path matching (#108)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 2 updates: [jdx/mise-action](https://github.com/jdx/mise-action) and [codelytv/pr-size-labeler](https://github.com/codelytv/pr-size-labeler).


Updates `jdx/mise-action` from 4.3.0 to 5.0.1
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](jdx/mise-action@c2a8761...7a4e45a)

Updates `codelytv/pr-size-labeler` from 1.10.4 to 1.12.0
- [Release notes](https://github.com/codelytv/pr-size-labeler/releases)
- [Commits](CodelyTV/pr-size-labeler@095a41f...19c335e)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: codelytv/pr-size-labeler
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area/build-and-release Indicates issue or PR related to build or release kind/cleanup Removing things previously overlooked labels Oct 5, 2026
@netlify

netlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for flintlock-docs canceled.

Name Link
🔨 Latest commit 9764cac
🔍 Latest deploy log https://app.netlify.com/projects/flintlock-docs/deploys/6ac42fd76585000008310d14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/build-and-release Indicates issue or PR related to build or release kind/cleanup Removing things previously overlooked

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants