Skip to content

chore(deps): update mise tools - #122

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/mise-tools
Open

renovate[bot] wants to merge 2 commits into
mainfrom
renovate/mise-tools

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
gh tools minor 2.96.0 → 2.101.0 2.102.0
trivy tools minor 0.72.0 → 0.74.0 0.75.0
uv tools minor 0.11.27 → 0.12.15 0.12.21 (+5)

Release Notes

cli/cli (gh)

v2.101.0: GitHub CLI 2.101.0

Compare Source

Linux package repository signing key rotation

GitHub CLI's APT and RPM repositories, along with individual RPM packages, are now signed only with the new PGP key (fingerprint: 7F38BBB59D064DBCB3D84D725612B36462313325)

[!IMPORTANT]
Linux users who installed gh from the official APT or RPM repositories before April 8, 2026, and have not refreshed their keyring, may now see package installation or update failures. Follow the PGP signing key rotation guidance to check and update your keyring. Users on Windows or macOS, and users who installed gh through Homebrew, GitHub Releases, another package manager, or from source, are not affected.

Copy authentication codes to the clipboard by default

gh auth login and gh auth refresh now copy OAuth device codes to the clipboard by default, saving a manual copy step during authentication.

To persistently opt out, run:

gh config set clipboard disabled

Explicit clipboard options still take precedence for an individual invocation.

What's Changed

✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies

New Contributors

Full Changelog: cli/cli@v2.100.0...v2.101.0

v2.100.0: GitHub CLI 2.100.0

Compare Source

Experimental: Route GitHub API traffic through a custom host

Organizations can now route a GitHub host's API traffic through a gateway using the new per-host api_host configuration:

# Route API traffic for github.com through a gateway
gh config set api_host gh-gateway.example.com --host github.com

# Read the configured API host
gh config get api_host --host github.com

The original host remains in use for authentication, Git remotes, and browser URLs.

[!NOTE]
api_host is experimental and is not a security boundary. Requests may still reach the original host.

What's Changed

✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies

Full Changelog: cli/cli@v2.99.0...v2.100.0

v2.99.0: GitHub CLI 2.99.0

Compare Source

Attach images and videos to issues and pull requests

The repeatable --attach flag uploads local images and videos and adds them to issue, pull request, or comment bodies. If a body already references the local path, gh replaces it with the uploaded URL; otherwise it appends the attachment:

# Attach files when creating or editing an issue
gh issue create --attach './repro.png#The error state'
gh issue edit 123 --attach ./walkthrough.mp4

# Attach files when creating or editing a pull request
gh pr create --attach ./before.png
gh pr edit 456 --attach ./after.png

# Attach files to comments
gh issue comment 123 --attach ./repro.png
gh pr comment 456 --attach ./result.mp4

Repeat the flag to attach multiple files in a single invocation. Attachments are available on GitHub.com and GitHub Enterprise Cloud.

For more information see https://gh.io/gh-attach and https://github.blog/changelog/2026-09-01-github-cli-media-in-issues-pull-requests-and-comments/

Worktree support extended to gh issue develop

gh issue develop can now create a linked branch and check it out in a new Git worktree, leaving your current working copy unchanged:

# Create a linked branch for an issue and check it out in a worktree
gh issue develop 123 --checkout --worktree /path/to/wt-feature

What's Changed

✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies

New Contributors

Full Changelog: cli/cli@v2.98.0...v2.99.0

v2.98.0: GitHub CLI 2.98.0

Compare Source

Security

A security vulnerability has been identified, and fixed, that binds the local forwarded port to all available network interfaces by default.

Users of gh codespace ports forward are advised to update gh to version v2.98.0 as soon as possible.

For more information see: GHSA-vfhh-p7hm-pxfh

Support worktrees in pr checkout

Users can now checkout a pull request into a git worktree by using the new --worktree PATH flag in gh pr checkout:

gh pr checkout 12 --worktree ../wt-feature

Add semantic search to search issues

The gh search issues command now supports semantic search for issues. Users can select the search type by passing the --search-type flag:

gh search issues --search-type semantic ...

gh search issues --search-type hybrid ...

For more information about semantic search see: "Improved Search for github issues is now generally available".

What's Changed

✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies

New Contributors

Full Changelog: cli/cli@v2.97.0...v2.98.0

v2.97.0: GitHub CLI 2.97.0

Compare Source

Security

Four security vulnerabilities have been identified, and fixed, in this release. Users are advised to update gh to version v2.97.0 as soon as possible.

Several commands (including gh gist view, gh api, gh pr diff, gh release download --output -, gh codespace logs, gh skills preview, and gh agent-task view/create) printed externally controlled content without neutralizing terminal escape sequences, allowing escape sequence injection into a user's terminal.

See GHSA-3m3g-3wcr-px46 for more information.

Some request URLs were built without escaping their variable path components, so a value containing URL path metacharacters could alter the request path and cause gh to address a different resource than intended.

See GHSA-4fjg-2h4q-fwg3 for more information.

gh auth status (without --show-token) could print a portion of the authentication token in plaintext for token types whose format contains an underscore after the prefix, such as github_pat_*, ghs_*, and ghu_*.

See GHSA-cg6r-mpgc-h9mm for more information.

gh attestation verify built the certificate matcher from --signer-repo and --signer-workflow without escaping regex metacharacters, so a lookalike repository or workflow name could satisfy a matcher intended for a trusted signer and bypass attestation verification.

See GHSA-mm27-mwq9-fr5g for more information.

Address project fields and items by name in gh project

gh project item-edit and gh project item-list can now reference project fields and single-select options by name:

# Set an item's field by name
gh project item-edit 1 --owner monalisa --url <url> --field "Status" --value "In Progress"

# Show named fields as extra columns
gh project item-list 1 --owner "@me" --field "Status" --field "Priority"

What's Changed

✨ Features
🐛 Fixes
📚 Docs & Chores
:dependabot: Dependencies

New Contributors

Full Changelog: cli/cli@v2.96.0...v2.97.0

aquasecurity/trivy (trivy)

v0.74.0

Compare Source

⚡ Highlights ⚡

👉 https://redirect.github.com/aquasecurity/trivy/discussions/11096

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0740-2026-08-14

v0.73.0

Compare Source

Features
Bug Fixes
astral-sh/uv (uv)

v0.12.15

Compare Source

Released on 2026-09-15.

This release fixes a regression in 0.12.14 that lead to rejecting valid installation commands such as using
uv pip install --system in python:* docker images or when using uv pip install --target .. (#​21699)

Performance
  • Speed up cold-cache resolution and HTTP cache revalidation by batching cache writes (#​21675)
Bug fixes
  • Revert "Reject symlinked wheel installation destinations" (#​21699)

v0.12.14

Compare Source

Released on 2026-09-15.

Package-operation errors now use uv's standard diagnostics, with consistent hints and compact, labeled cause chains. (#​17110, #​21599, #​21603)

Package-operation exit codes now reflect the underlying cause: expected failures return 1, while recognized operational and internal failures return 2. ([#​17110](https://redirect.github.com

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner October 1, 2026 18:28
@renovate renovate Bot added bot Automated pull requests or issues dependencies Pull requests that update a dependency file renovate Pull requests from Renovate skip:codecov Skip Codecov reporting and check labels Oct 1, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 1, 2026 18:28
@renovate

renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: mise.lock
�[33mmise�[0m �[33mWARN�[0m  /tmp/renovate/repos/github/aignostics/foundry-python-core/mise.lock uses lockfile format version 0; run `mise lock --upgrade` to enable the latest lockfile features
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_linux_arm64.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_macOS_arm64.zip
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_macOS_amd64.zip
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_windows_amd64.zip
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_linux_amd64.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_linux_amd64.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: gh_2.101.0_linux_arm64.tar.gz
�[33mmise�[0m �[33mWARN�[0m  HTTP GET https://github.com/cli/cli/releases/download/v2.101.0/gh_2.101.0_linux_amd64.tar.gz attempt 1 failed after 194.8ms (transient): HTTP status server error (500 Internal Server Error) for url (https://github.com/cli/cli/releases/download/v2.101.0/gh_2.101.0_linux_amd64.tar.gz); retrying in 178.941972ms
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_Linux-ARM64.tar.gz
�[33mmise�[0m �[33mWARN�[0m  HTTP GET https://github.com/cli/cli/releases/download/v2.101.0/gh_2.101.0_linux_amd64.tar.gz attempt 2 failed after 7.4ms (transient): HTTP status server error (500 Internal Server Error) for url (https://github.com/cli/cli/releases/download/v2.101.0/gh_2.101.0_linux_amd64.tar.gz); retrying in 588.625633ms
�[33mmise�[0m �[33mWARN�[0m  HTTP GET https://github.com/cli/cli/releases/download/v2.101.0/gh_2.101.0_linux_amd64.tar.gz attempt 3 failed after 3.9ms (transient): HTTP status server error (500 Internal Server Error) for url (https://github.com/cli/cli/releases/download/v2.101.0/gh_2.101.0_linux_amd64.tar.gz); retrying in 2.595368665s
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_Linux-ARM64.tar.gz
�[2mmise�[0m lock            gh@2.101.0 linux-arm64
�[2mmise�[0m lock            gh@2.101.0 linux-arm64-musl
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_Linux-64bit.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_Linux-64bit.tar.gz
�[2mmise�[0m lock            gh@2.101.0 macos-arm64
�[2mmise�[0m lock            gh@2.101.0 linux-x64-musl
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_macOS-ARM64.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_macOS-64bit.tar.gz
�[2mmise�[0m lock            gh@2.101.0 windows-x64
�[2mmise�[0m lock            gh@2.101.0 macos-x64
�[2mmise�[0m downloading artifact for lock-time provenance verification: trivy_0.74.0_windows-64bit.zip
�[2mmise�[0m lock            trivy@0.74.0 linux-arm64
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-aarch64-unknown-linux-gnu.tar.gz
�[2mmise�[0m lock            trivy@0.74.0 linux-arm64-musl
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-aarch64-unknown-linux-musl.tar.gz
�[2mmise�[0m lock            gh@2.101.0 linux-x64
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-x86_64-unknown-linux-gnu.tar.gz
�[2mmise�[0m lock            trivy@0.74.0 macos-arm64
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-x86_64-unknown-linux-musl.tar.gz
�[2mmise�[0m lock            trivy@0.74.0 macos-x64
�[2mmise�[0m lock            trivy@0.74.0 linux-x64
�[2mmise�[0m lock            trivy@0.74.0 windows-x64
�[2mmise�[0m lock            trivy@0.74.0 linux-x64-musl
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-aarch64-apple-darwin.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-x86_64-apple-darwin.tar.gz
�[2mmise�[0m downloading artifact for lock-time provenance verification: uv-x86_64-pc-windows-msvc.zip
�[2mmise�[0m lock            uv@0.12.15 linux-arm64
�[2mmise�[0m lock            uv@0.12.15 linux-arm64-musl
�[2mmise�[0m lock            uv@0.12.15 linux-x64
�[2mmise�[0m lock            uv@0.12.15 macos-arm64
�[2mmise�[0m lock            uv@0.12.15 windows-x64
�[2mmise�[0m lock            uv@0.12.15 macos-x64
�[2mmise�[0m lock            uv@0.12.15 linux-x64-musl
�[33mmise�[0m �[33mWARN�[0m  failed to resolve gh for linux-x64: lock-time provenance verification failed (version 2.101.0)
�[2mmise�[0m lock          �[38;5;10m✓�[0m 20 platform entries
�[31mmise�[0m �[31mERROR�[0m failed to resolve gh@2.101.0 for linux-x64; refusing to replace locked version(s) 2.96.0 that support this platform
�[31mmise�[0m �[31mERROR�[0m Version: 2026.9.18 linux-x64 (2026-09-30)
�[31mmise�[0m �[31mERROR�[0m �[2mRun with --verbose or MISE_VERBOSE=1 for more information�[0m

@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@renovate

renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot Automated pull requests or issues dependencies Pull requests that update a dependency file renovate Pull requests from Renovate skip:codecov Skip Codecov reporting and check

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants