chore(deps): update jdx/mise-action action to v4.2.3 - #218
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/jdx-mise-action-4.x
branch
2 times, most recently
from
July 27, 2026 10:46
b8b3cb8 to
80b06f4
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-action-4.x
branch
from
July 27, 2026 14:07
80b06f4 to
22e9b65
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-action-4.x
branch
from
July 27, 2026 21:46
22e9b65 to
9271341
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.0→v4.2.3Release Notes
jdx/mise-action (jdx/mise-action)
v4.2.3: : Restore mise PATH propagationCompare Source
A patch release that restores mise's PATH propagation to subsequent workflow steps — without reintroducing the full-PATH snapshot behavior that v4.2.1 fixed.
Fixed
Export mise PATH entries to subsequent steps (#575) by @jdx
v4.2.1 stopped exporting the complete
PATHreturned bymise env --jsonintoGITHUB_ENV, which correctly prevented snapshotting the runner's environment into subsequent steps. However, that also dropped mise-produced PATH entries — tool shims,[env] _.pathdirectories, and similar — that workflows relied on after the setup step. See #565.The action now computes only the prefix that mise prepended to the existing
PATHand forwards those directories individually throughGITHUB_PATH. This preserves mise's configured ordering, composes cleanly with PATH changes from other actions, and never persists the runner's fullPATHthroughGITHUB_ENV. The dotenv fallback path (used with older mise versions) also stripsPATH=lines and re-derives additions frommise env --json.A new
export_pathinput (defaulttrue) lets workflows keep regularenvexports while opting out of PATH changes:Full Changelog: jdx/mise-action@v4.2.2...v4.2.3
v4.2.2: : Zstd tar fallback for older runnersCompare Source
A small patch release that fixes archive selection on runners with an older
tarand corrects a stale default in the README.Fixed
Verify
tarsupports Zstd before picking.tar.zst(#569 by @JackMyers001The action previously chose the
.tar.zstmise archive wheneverzstd --versionsucceeded, then extracted it withtar --zstd. On RHEL 8-compatible runners that shipzstd1.4.4 alongside GNUtar1.30, the--zstdoption isn't recognized and installation failed.Detection now runs both checks:
If either fails, the action falls back to the
.tar.gzarchive. No configuration change is required — existing workflows on affected runners just start working again. Fixes #568.Documentation
cache_key_prefixexample in the README to reflect the current default ofmise-v1(previously documented asmise-v0) (#570 by @muzimuzhi).New Contributors
Full Changelog: jdx/mise-action@v4.2.1...v4.2.2
v4.2.1: : Signed checksums and PATH export fixCompare Source
A small patch release with two user-facing fixes: mise downloads are now verified against minisign-signed release checksums by default, and the
envinput no longer leaks the runner'sPATHinto subsequent steps.Fixed
Verify mise downloads with signed checksums (#548) by @jdx
The action now embeds mise's minisign public key and verifies
SHASUMS256.txt.minisigbefore trusting any release checksums, then checks the downloaded mise binary's SHA256 against the verified list. This applies to both GitHub release archives (verified before extraction) and the defaultmise.jdx.devCDN path (verified against the signed checksum for the matching release asset). If a CDN download fails verification, the action warns and falls back to the signed GitHub release asset instead of installing an unverified binary.sha256input still works as an explicit override.2024.12.24(which predate minisign checksums) get a warning and skip signed verification rather than failing.download | tarfast path is replaced with a download-then-verify-then-extract flow.Thanks to @potiuk for the detailed threat-model writeup in #547.
Exclude
PATHfrom environment export (#556) by @jdxThe
envinput has always documented that "PATH modifications are not part of this", but since the switch tomise env --jsonin #252 (needed for redaction support), the action was exporting every string value returned by mise — including the computedPATH— intoGITHUB_ENV. That effectively snapshotted the runner's entirePATHinto subsequent steps and let[env] _.pathentries inmise.tomlleak past the action's own PATH management.exportMiseEnvnow skipsPATH(case-insensitive) when exporting JSON env vars, restoring the documented behavior. Normal mise env vars are still exported, and PATH continues to be managed by the action's own setup (e.g.add_shims_to_path). Fixes #555.Full Changelog: jdx/mise-action@v4.2.0...v4.2.1
Configuration
📅 Schedule: (in timezone Asia/Tokyo)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.