chore(deps): update jdx/mise-action action to v5 - #110
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
requested review from
ns-vasilev
and removed request for
a team
September 28, 2026 23:57
Generated by 🚫 Danger |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #110 +/- ##
=======================================
Coverage 98.90% 98.90%
=======================================
Files 4 4
Lines 362 362
=======================================
Hits 358 358
Misses 4 4 |
renovate
Bot
force-pushed
the
renovate/jdx-mise-action-5.x
branch
from
October 1, 2026 04:21
3c7e37b to
19b8976
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4→v5Release Notes
jdx/mise-action (jdx/mise-action)
v5.0.1: : Verify cached mise binaries before running themCompare Source
mise-action now checks the integrity of an already-installed
misebinary before running it. This fixes a security issue that was reported privately.Fixed
misebinary is verified before it is run. When amisebinary is already on the runner (for example, restored from cache or inmise_dir), the action now checks it before calling it. If you set asha256input, the binary must match that checksum and report the requested version. Otherwise, it must match the signed release checksums for the version being installed. If the check fails, the action prints a warning, deletes the binary and installs the requested release again. Before this fix, the action could run a cached binary before checking it. (#637 by @jdx)Changed
Changes to how the action handles an existing binary, also from #637:
mise self-update.versioninput, the action now selects a release every time, usingminimum_release_age, even whenmiseis already installed. It then checks the existing binary against that release, and reinstalls if the binary doesn't match.sha256input to reuse a cached binary. Some older mise releases have no signed checksums. With thesha256input set, a cached binary of one of these releases can still be reused without a download. Without it, the action can't verify the binary and installs it again.Full Changelog: jdx/mise-action@v5.0.0...v5.0.1
v5.0.0: : Default minimum release age of 24 hours for miseCompare Source
If you don't pin a
version, mise-action now installs the newest stable mise release that is at least 24 hours old. Upgrading mise on a runner that already has it is also less likely to hit GitHub API rate limits.Breaking Changes
minimum_release_agenow defaults to24h(#632 by @jdx)Before this release,
minimum_release_agewas an opt-in setting. It now defaults to24h. If you don't setversion, the action picks the highest-numbered stable mise release published at least 24 hours ago. A mise release that just shipped won't be installed until it's a day old.To get the latest stable release right away, as in v4, set the delay to
0s. You can also choose a longer delay:versioninput still takes precedence and skips the delay.releases.tsvon mise.jdx.dev) instead of paging through the GitHub Releases API. Picking a release doesn't use GitHub API quota, even when an installed binary is reused. If the index is missing or malformed, the action fails instead of skipping the release-age check.mise self-update, which may call the GitHub API to fetch that exact release.Fixed
mise self-updatenow runs withMISE_GITHUB_TOKEN. When a runner already had a different mise version installed, the action runsmise self-updateto switch versions. That GitHub API call used to go out without authentication, so busy shared or self-hosted runners could hit the rate limit and fail withHTTP 403 RateLimitedError. If you already set a token in your environment, the action leaves it unchanged. (#619 by @hegde5)New Contributors
Full Changelog: jdx/mise-action@v4.3.0...v5.0.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.