Skip to content

Allow unknown tags by default in check-yaml - #2678

Merged
j178 merged 1 commit into
masterfrom
check-yaml-tags
Sep 2, 2026
Merged

j178 merged 1 commit into
masterfrom
check-yaml-tags

Conversation

@j178

@j178 j178 commented Sep 2, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to #2674.

Rejecting unknown tags by default causes false positives in ecosystems such as MkDocs and Ansible. A generic YAML checker cannot know the tag vocabulary of the application that consumes a file, so an unrecognized application-specific tag does not make the YAML invalid.

This intentionally differs from upstream check-yaml. prek allows unknown tags by default and provides --disallow-unknown-tags for users who want to enforce a closed tag vocabulary. Only tag rejection changes; all other loading checks remain enabled.

Copilot AI lite review requested due to automatic review settings September 2, 2026 17:06
@j178 j178 added the enhancement New feature or request label Sep 2, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-02T17:25:42.015744Z 834c86d New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

It introduces a CLI breaking change by removing --allow-unknown-tags, and the docs currently understate that --disallow-unknown-tags can provide pinned behavior without disabling the fast path.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Updates the built-in check-yaml hook to allow unknown YAML tags by default (addressing CI failures with tools like MkDocs that use custom tags), while providing an opt-in flag to reject them.

Changes:

  • Flip default behavior to allow unrecognized YAML tags when loading YAML.
  • Replace the CLI flag with --disallow-unknown-tags (and update hook docs/output accordingly).
  • Update docs and tests to reflect the new default and flag behavior.
File summaries
File Description
docs/builtin.md Documents the new default behavior and how it relates to the pinned pre-commit-hooks implementation.
crates/prek/tests/list_builtins.rs Updates the expected list-builtins output to show the new flag name/description.
crates/prek/tests/builtin_hooks.rs Updates integration-style snapshot coverage for allow-by-default vs reject-with-flag behavior.
crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs Implements the behavior change and updates unit tests around unknown tag handling.
Review details

Suppressed comments (1)

crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs:49

  • If you keep a deprecated --allow-unknown-tags flag for compatibility, it should be incorporated into the runtime behavior (and/or used to avoid "field never read" warnings) so that passing it continues to force-allow tags and it cleanly conflicts with --disallow-unknown-tags.
        CheckMode::Load {
            multiple: args.allow_multiple_documents,
            disallow_unknown_tags: args.disallow_unknown_tags,
        }
  • Files reviewed: 4/4 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs
Comment thread docs/builtin.md Outdated
@codecov

codecov Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.11%. Comparing base (78bb3fe) to head (834c86d).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #2678   +/-   ##
=======================================
  Coverage   94.11%   94.11%           
=======================================
  Files         141      141           
  Lines       30051    30057    +6     
=======================================
+ Hits        28281    28287    +6     
  Misses       1770     1770           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copilot AI review requested due to automatic review settings September 2, 2026 17:15
@prek-ci-bot

prek-ci-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown

📦 Cargo Bloat Comparison

.text size change: +0.00% (12.8 MiB → 12.8 MiB)

Expand for cargo-bloat output

Head Branch Results

File  .text     Size             Crate Name
0.1%   2.5% 332.0KiB        aws_lc_sys aws_lc_0_44_0_aes_gcm_encrypt_avx512
0.1%   2.5% 332.0KiB        aws_lc_sys aws_lc_0_44_0_aes_gcm_decrypt_avx512
0.0%   0.7%  96.5KiB              prek <prek::cli::Command as clap_builder::derive::Subcommand>::augment_subcommands
0.0%   0.4%  50.1KiB              prek <<prek::config::hook::HookWire as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.4%  49.7KiB              prek prek::run::{closure#0}
0.0%   0.4%  48.7KiB annotate_snippets annotate_snippets::renderer::render::render
0.0%   0.3%  43.9KiB              prek <<prek::config::Config as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.3%  40.3KiB              prek <prek::cli::RunOptions as clap_builder::derive::Args>::augment_args
0.0%   0.3%  37.0KiB              prek prek::cli::run::run::run::{closure#0}
0.0%   0.2%  28.7KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.6KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  28.2KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.0KiB        aws_lc_sys aws_lc_0_44_0_edwards25519_scalarmuldouble_alt
0.0%   0.2%  27.5KiB        aws_lc_sys aws_lc_0_44_0_edwards25519_scalarmuldouble
0.0%   0.2%  27.3KiB              toml <toml::de::deserializer::value::ValueDeserializer as serde_core::de::Deserializer>::deserialize_any::<<prek::config::hook::HookWire as serde_core::de::Deserialize>::deserialize::__Visitor>
0.0%   0.2%  27.1KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  26.9KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  26.9KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
4.2%  87.0%  11.1MiB                   And 20385 smaller methods. Use -n N to show more.
4.8% 100.0%  12.8MiB                   .text section size, the file size is 263.5MiB

Base Branch Results

File  .text     Size             Crate Name
0.1%   2.5% 332.0KiB        aws_lc_sys aws_lc_0_44_0_aes_gcm_encrypt_avx512
0.1%   2.5% 332.0KiB        aws_lc_sys aws_lc_0_44_0_aes_gcm_decrypt_avx512
0.0%   0.7%  96.5KiB              prek <prek::cli::Command as clap_builder::derive::Subcommand>::augment_subcommands
0.0%   0.4%  50.1KiB              prek <<prek::config::hook::HookWire as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.4%  49.7KiB              prek prek::run::{closure#0}
0.0%   0.4%  48.7KiB annotate_snippets annotate_snippets::renderer::render::render
0.0%   0.3%  43.9KiB              prek <<prek::config::Config as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.3%  40.3KiB              prek <prek::cli::RunOptions as clap_builder::derive::Args>::augment_args
0.0%   0.3%  37.0KiB              prek prek::cli::run::run::run::{closure#0}
0.0%   0.2%  28.7KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.6KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  28.2KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.0KiB        aws_lc_sys aws_lc_0_44_0_edwards25519_scalarmuldouble_alt
0.0%   0.2%  27.5KiB        aws_lc_sys aws_lc_0_44_0_edwards25519_scalarmuldouble
0.0%   0.2%  27.3KiB              toml <toml::de::deserializer::value::ValueDeserializer as serde_core::de::Deserializer>::deserialize_any::<<prek::config::hook::HookWire as serde_core::de::Deserialize>::deserialize::__Visitor>
0.0%   0.2%  27.1KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  26.9KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  26.9KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
4.2%  87.0%  11.1MiB                   And 20385 smaller methods. Use -n N to show more.
4.8% 100.0%  12.8MiB                   .text section size, the file size is 263.5MiB

@prek-ci-bot

prek-ci-bot Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

⚡️ Hyperfine Benchmarks

Summary: 0 regressions, 0 improvements above the 10% threshold.

Environment
  • OS: Linux 6.17.0-1022-azure
  • CPU: 4 cores
  • prek version: prek 0.5.1+8 (0c54469 2026-09-02)
  • Rust version: rustc 1.98.0 (88d9e12ae 2026-08-18)
  • Hyperfine version: hyperfine 1.20.0
CLI Commands

Benchmarking basic commands in the main repo:

prek --version

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base --version 2.5 ± 0.1 2.4 3.0 1.08 ± 0.04
prek-head --version 2.3 ± 0.0 2.2 2.5 1.00

prek list

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base list 9.6 ± 0.1 9.4 9.9 1.02 ± 0.02
prek-head list 9.4 ± 0.1 9.2 9.7 1.00

prek validate-config .pre-commit-config.yaml

⏭️ Skipped: .pre-commit-config.yaml not found

prek sample-config

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base sample-config 2.8 ± 0.1 2.7 3.0 1.03 ± 0.04
prek-head sample-config 2.7 ± 0.1 2.6 2.9 1.00
Cold vs Warm Runs

Comparing first run (cold) vs subsequent runs (warm cache):

prek run --all-files (cold - no cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 38.4 ± 1.5 36.9 41.4 1.01 ± 0.05
prek-head run --all-files 38.0 ± 1.0 36.6 40.1 1.00

prek run --all-files (warm - with cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 38.1 ± 1.1 36.4 40.7 1.02 ± 0.04
prek-head run --all-files 37.4 ± 0.9 35.9 39.9 1.00
Full Hook Suite

Running the builtin hook suite on the benchmark workspace:

prek run --all-files (full builtin hook suite)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 37.9 ± 1.1 35.3 42.4 1.00
prek-head run --all-files 38.7 ± 3.5 36.3 54.6 1.02 ± 0.10
Individual Hook Performance

Benchmarking each hook individually on the test repo:

prek run trailing-whitespace --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run trailing-whitespace --all-files 13.1 ± 0.3 12.6 13.5 1.02 ± 0.03
prek-head run trailing-whitespace --all-files 12.8 ± 0.3 12.2 13.5 1.00

prek run end-of-file-fixer --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run end-of-file-fixer --all-files 11.5 ± 0.4 10.8 12.2 1.02 ± 0.05
prek-head run end-of-file-fixer --all-files 11.3 ± 0.4 10.8 12.2 1.00

prek run check-json --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-json --all-files 8.4 ± 0.3 7.9 9.3 1.04 ± 0.05
prek-head run check-json --all-files 8.1 ± 0.2 7.6 8.5 1.00

prek run check-yaml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-yaml --all-files 8.2 ± 0.3 7.8 9.1 1.03 ± 0.04
prek-head run check-yaml --all-files 7.9 ± 0.2 7.6 8.7 1.00

prek run check-toml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-toml --all-files 8.9 ± 2.2 7.9 20.2 1.07 ± 0.26
prek-head run check-toml --all-files 8.3 ± 0.4 7.7 9.1 1.00

prek run check-xml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-xml --all-files 8.5 ± 0.5 7.9 9.6 1.06 ± 0.08
prek-head run check-xml --all-files 8.1 ± 0.3 7.7 9.2 1.00

prek run detect-private-key --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run detect-private-key --all-files 11.7 ± 0.6 10.7 12.7 1.02 ± 0.08
prek-head run detect-private-key --all-files 11.5 ± 0.7 10.5 13.3 1.00

prek run fix-byte-order-marker --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run fix-byte-order-marker --all-files 13.2 ± 0.8 11.9 14.4 1.01 ± 0.09
prek-head run fix-byte-order-marker --all-files 13.1 ± 0.8 11.9 14.6 1.00
Installation Performance

Benchmarking hook installation (fast path hooks skip Python setup):

prek install-hooks (cold - no cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base install-hooks 5.0 ± 0.1 5.0 5.1 1.03 ± 0.02
prek-head install-hooks 4.9 ± 0.1 4.8 5.0 1.00

prek install-hooks (warm - with cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base install-hooks 5.1 ± 0.1 5.0 5.1 1.00 ± 0.02
prek-head install-hooks 5.1 ± 0.1 5.0 5.1 1.00
File Filtering/Scoping Performance

Testing different file selection modes:

prek run (staged files only)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run 25.9 ± 0.4 25.4 26.7 1.03 ± 0.02
prek-head run 25.2 ± 0.3 24.5 25.9 1.00

prek run --files '*.json' (specific file type)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --files '*.json' 5.7 ± 0.1 5.6 6.0 1.05 ± 0.02
prek-head run --files '*.json' 5.4 ± 0.0 5.3 5.5 1.00
Workspace Discovery & Initialization

Benchmarking hook discovery and initialization overhead:

prek run --dry-run --all-files (measures init overhead)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --dry-run --all-files 7.4 ± 0.1 7.3 7.6 1.02 ± 0.02
prek-head run --dry-run --all-files 7.2 ± 0.1 7.1 7.3 1.00
Meta Hooks Performance

Benchmarking meta hooks separately:

prek run check-hooks-apply --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-hooks-apply --all-files 8.8 ± 0.1 8.7 9.2 1.03 ± 0.02
prek-head run check-hooks-apply --all-files 8.6 ± 0.1 8.5 8.8 1.00

prek run check-useless-excludes --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-useless-excludes --all-files 8.8 ± 0.1 8.7 8.9 1.03 ± 0.01
prek-head run check-useless-excludes --all-files 8.5 ± 0.1 8.4 8.7 1.00

prek run identity --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run identity --all-files 7.7 ± 0.1 7.6 8.0 1.02 ± 0.02
prek-head run identity --all-files 7.6 ± 0.1 7.5 7.7 1.00

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f464973bf7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs
@j178 j178 mentioned this pull request Sep 2, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Dropping the previously supported --allow-unknown-tags flag is a breaking CLI/config change that will cause existing configurations to fail to parse.

Review details

Suppressed comments (1)

crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs:23

  • Removing --allow-unknown-tags is a breaking change for existing prek configs (especially for users who added it in 0.5.1 to work around default tag rejection). Consider keeping --allow-unknown-tags as a hidden/deprecated no-op flag so older configs continue to parse, while --disallow-unknown-tags controls the new behavior.
    /// Reject unrecognized YAML tags.
    #[arg(long)]
    disallow_unknown_tags: bool,
  • Files reviewed: 4/4 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 2, 2026 17:23
@j178
j178 enabled auto-merge (squash) September 2, 2026 17:24
@j178
j178 disabled auto-merge September 2, 2026 17:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The --allow-unknown-tags → --disallow-unknown-tags rename breaks existing configs that still pass the old flag, and it should be retained as a hidden/deprecated compatibility no-op.

Review details

Suppressed comments (1)

crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs:23

  • Renaming the CLI from --allow-unknown-tags to --disallow-unknown-tags is a breaking change for existing prek / pre-commit configs that already pass --allow-unknown-tags (even though it is now the default). Consider keeping --allow-unknown-tags as a hidden/deprecated no-op flag for compatibility, and error if both --allow-unknown-tags and --disallow-unknown-tags are provided.
    /// Reject unrecognized YAML tags.
    #[arg(long, conflicts_with = "unsafe")]
    disallow_unknown_tags: bool,
  • Files reviewed: 4/4 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@j178
j178 merged commit f0ce4c2 into master Sep 2, 2026
37 checks passed
@j178
j178 deleted the check-yaml-tags branch September 2, 2026 17:30
DanielH2018 added a commit to DanielH2018/server that referenced this pull request Sep 10, 2026
Renovate raised #1513 for this, but its branch was cut against a base
older than master: the diff read 0.4.14 -> 0.5.0 while master already
carried 0.5.0, so merging it would have landed nothing behind a green CI
while the title claimed 0.5.2. Bumping the pin directly instead.

0.5.1 and 0.5.2 are enhancement-only — no breaking changes in either
release note. One behaviour change worth knowing: 0.5.2 allows unknown
tags by default in `check-yaml` (j178/prek#2678), which relaxes that
hook rather than tightening it, so nothing that passed before starts
failing.

🤖 Generated with [Claude Code](https://claude.com/claude-code)


Claude-Session: https://claude.ai/code/session_01P64Y978Gqkb6pGzh5GtLo6

Co-authored-by: Claude <noreply@anthropic.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.0` → `0.5.2` | `0.5.0` → `0.5.2` |
| `rumdl` | `0.2.62` → `0.2.70` | `0.2.62` → `0.2.70` |
| `shfmt` | `3.14.0` → `3.14.1` | `3.14.0` → `3.14.1` |
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |
| `uv` | `0.12.7` → `0.12.12` | `0.12.7` → `0.12.12` |
| `zizmor` | `1.30.0` → `1.30.1` | `1.30.0` → `1.30.1` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>prek: `0.5.0` → `0.5.2` (j178/prek)</summary>

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>
<details>
<summary>rumdl: `0.2.62` → `0.2.70` (rvben/rumdl)</summary>

### v0.2.63

### Added

- **brand**: refine wordmark typography ([e871dcb](rvben/rumdl@e871dcb))
- **playground**: rebuild browser editor ([35e27df](rvben/rumdl@35e27df))
- **analytics**: classify aggregate referral sources ([3cc0ef2](rvben/rumdl@3cc0ef2))
- **brand**: add social previews and npm identity ([d6971f6](rvben/rumdl@d6971f6))
- **docs**: restore terminal capture colors ([eccf710](rvben/rumdl@eccf710))
- **docs**: frame terminal capture ([084fc30](rvben/rumdl@084fc30))
- **docs**: use real terminal capture ([e417bae](rvben/rumdl@e417bae))
- **docs**: replace hero proof with real terminal ([6c66a07](rvben/rumdl@6c66a07))
- **docs**: sharpen homepage activation path ([a60b622](rvben/rumdl@a60b622))
- **docs**: expose private adoption snapshot ([da299bb](rvben/rumdl@da299bb))
- **brand**: adopt Heading Pulse identity ([1a05c28](rvben/rumdl@1a05c28))
- **docs**: activate adoption analytics and reporting ([3a0b64f](rvben/rumdl@3a0b64f))
- **docs**: improve website and product documentation ([ad4ebf9](rvben/rumdl@ad4ebf9))

### Fixed

- **deps**: update vulnerable development dependencies ([8489019](rvben/rumdl@8489019))
- **MD051**: register HTML anc… (truncated)

### v0.2.64

### Added

- **flavor**: add preview support for GitHub Agentic Workflows (`gh-aw`), including imports and current conditional branch syntax ([39f7263](rvben/rumdl@39f7263))
- **Rust API**: add `MarkdownFlavor::GhAw`; downstream exhaustive matches must handle the new variant
- **MD089**: add opt-in cjk-spacing rule ([50f40a2](rvben/rumdl@50f40a2))
- **MD089**: add configuration for cjk-spacing symbol sets ([868e933](rvben/rumdl@868e933))
- **unicode**: add is_cjk_letter predicate ([087e518](rvben/rumdl@087e518))

### Fixed

- **MD013**: handle sentences ending before code spans in sentence-per-line reflow (#811, #812) ([576e2c1](rvben/rumdl@576e2c1))
- **MD022**: accept per-level arrays during validation ([976087c](rvben/rumdl@976087c))
- **MD051**: slug headings with the whitespace an anchor element leaves ([04cbfc2](rvben/rumdl@04cbfc2))
- **MD057**: exclude Markdown-looking frontmatter strings from body link validation and workspace indexing ([39f7263](rvben/rumdl@39f7263))
- **MD041**: never move or promote headings across GitHub Agentic Workflow control boundaries ([39f7263](rvben/rumdl@39f7263))
- **MD063**: capitalize opening link labels in sentence case ([88ea8b7](rvben/rumdl@88ea8b7))
- **MD073**: skip TOC entries for headings that slug to nothing ([41e2312](rvben/rumdl@41e2312))
- **docs**: improve responsi… (truncated)

### v0.2.65

### Added

- **MD091**: add opt-in rule for markdown inside HTML blocks ([4333acf](rvben/rumdl@4333acf))
- **cli**: add `--no-code-block-tools` and `--only-code-block-tools` mode flags (#829) ([fc410f7](rvben/rumdl@fc410f7))
- **config**: show every configuration section in `rumdl config` (#851) ([4dc0d30](rvben/rumdl@4dc0d30))

### Fixed

- **config**: parse `[tool.rumdl.code-block-tools]` in pyproject.toml (#851) ([87b159d](rvben/rumdl@87b159d))
- **config**: report a malformed code-block-tools section ([ed1b7c5](rvben/rumdl@ed1b7c5))
- **config**: report the line length MD013 enforces ([a4bf2a7](rvben/rumdl@a4bf2a7))
- **config**: state that an empty section in `rumdl config` is empty ([cac7b76](rvben/rumdl@cac7b76))
- **config**: print each code-block-tools setting on one line ([02ba15d](rvben/rumdl@02ba15d))
- **MD046**: preserve code blocks during style conversion ([9f13f3b](rvben/rumdl@9f13f3b))
- **MD063**: preserve the English first-person pronoun in sentence-case headings ([#845](rvben/rumdl#845)) ([35b2df9](rvben/rumdl@35b2df9))
- **MD063**: honor pronoun boundaries and explicit ignores ([0604c03](rvben/rumdl@0604c03))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.65-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releas… (truncated)

### v0.2.66

### Fixed

- **MD051**: GitHub-style anchors match GitHub.com for a `§` in the heading and for an emoji not surrounded by spaces (#854) ([d530737](rvben/rumdl@d530737)). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.
- **MD063**: recognize an ordinal wrapped in punctuation ([473bf51](rvben/rumdl@473bf51))
- **MD013**: keep a link-only line inside the sentence it continues ([3e767ee](rvben/rumdl@3e767ee))
- **MD013**: read require-sentence-capital when counting sentences ([8706780](rvben/rumdl@8706780))

### Added

- **config**: apply inline --config overrides to the non-rule sections ([7737dca](rvben/rumdl@7737dca))
- **cli**: accept format as a hidden alias for fmt ([0cd9168](rvben/rumdl@0cd9168))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.66-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-a… (truncated)

### v0.2.67

### Fixed

- **code-block-tools**: survive a tool that exits without reading its input ([a3f2b15](rvben/rumdl@a3f2b15))
- **MD042**: do not report an image with an unparseable destination as an empty link ([600236e](rvben/rumdl@600236e))
- **code-block-tools**: report missing tool binaries instead of passing silently ([fd83c4b](rvben/rumdl@fd83c4b))
- **code-block-tools**: report tool failures from the format path ([4f92370](rvben/rumdl@4f92370))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-x… (truncated)

### v0.2.68

### Fixed

- **MDX**: recognize Markdown links and images inside JSX elements, including generated reference tables, without requiring blank lines. This removes false MD091 warnings and lets normal link rules check the content. JavaScript expressions, JSX attributes, comments, and code are excluded, and link fixes preserve source labels and positions ([#801](rvben/rumdl#801)).

### Performance

- Reduce regex locking and redundant rule work.
- Precompute proper-name lookups and streamline regex caching.

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum… (truncated)

### v0.2.69

### Fixed

- **MD032**: recognize spaced nested blockquotes ([974540f](rvben/rumdl@974540f))
- **MD032**: separate lists from standalone code fences ([e335c58](rvben/rumdl@e335c58))
- **mdx**: avoid parser panic on malformed Setext headings ([5e4a387](rvben/rumdl@5e4a387))
- preserve markdown containing merge conflicts ([8aabd3d](rvben/rumdl@8aabd3d))
- **deps**: remove unmaintained paste and atomic-polyfill ([e2ab5cb](rvben/rumdl@e2ab5cb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-u… (truncated)

### v0.2.70

### Fixed

- **mdx**: recover instead of crashing on unclosed JSX in a link label ([35de79c](rvben/rumdl@35de79c))
- **lsp**: index links whose paths contain parentheses ([bc5adc0](rvben/rumdl@bc5adc0))
- **MD057**: handle balanced parentheses in link paths ([b2a9ce9](rvben/rumdl@b2a9ce9))
- **MD032**: respect suppression at each list boundary ([9aeb5f3](rvben/rumdl@9aeb5f3))
- **MD087,inline-config**: ignore directives inside inline code spans ([749a7ea](rvben/rumdl@749a7ea))
- **stdin**: preserve original bytes when formatting is unchanged ([2c84470](rvben/rumdl@2c84470))
- **MD046**: align fence repairs with diagnostic edits ([443892e](rvben/rumdl@443892e))
- **MD032**: preserve line endings in document fixes ([60bae56](rvben/rumdl@60bae56))

### Performance

- **MD024**: avoid cloned keys and redundant diagnostic work ([ffebf4e](rvben/rumdl@ffebf4e))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/… (truncated)

</details>
<details>
<summary>shfmt: `3.14.0` → `3.14.1` (mvdan/sh)</summary>

### v3.14.1

- **syntax**
  - Fix the indentation of heredocs nested inside command substitutions - #1403
  - Keep literal tabs in `<<-` heredoc bodies rather than replacing them with spaces
  - Don't indent heredocs without dashes nested in `<<-` ones, whose output no longer parsed
  - Zsh: don't drop the prefix in short forms like `$#"$foo"` and `$+"$foo"` - #1405
- **interp**
  - Fix the build on 32-bit FreeBSD and NetBSD
- **expand**
  - Don't let escaped characters such as `\*` act as glob metacharacters
- **pattern**
  - Treat unclosed extended operator groups like `@(a` as literals, avoiding a panic

Consider [becoming a sponsor](https://github.com/sponsors/mvdan) if you benefit from the work that went into this release!

Binaries built on `go version go1.27.1 linux/amd64` with:

	CGO_ENABLED=0 go build -trimpath -ldflags="-w -s"

</details>
<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>
<details>
<summary>uv: `0.12.7` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>
<details>
<summary>zizmor: `1.30.0` → `1.30.1` (zizmorcore/zizmor)</summary>

### v1.30.1

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix ([#2363](zizmorcore/zizmor#2363))

- Fixed a bug where [self-repository](https://docs.zizmor.sh/audits/#self-repository) auto-fixes were incorrectly marked as "safe" instead of "unsafe" ([#2373](zizmorcore/zizmor#2373))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.14` → `0.5.2` | `0.4.14` → `0.5.2` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.14` → `0.5.2` (j178/prek)</summary>

### v0.5.0

## Release Notes

Released on 2026-08-27.

### Highlights

#### Choose where hook toolchains come from

`language_version` now accepts a source `preference` alongside the version
`request`, letting you control where prek looks for a compatible toolchain when
it creates a hook environment. Use `managed` (the default) or `system` to choose
which source prek tries first while still allowing fallback and downloads. Use
`only-managed` or `only-system` to require one source.

For example, this local Ruff hook requires a Python 3.12 toolchain managed by
prek:

```yaml
repos:
  - repo: local
    hooks:
      - id: ruff
        name: ruff
        language: python
        entry: ruff check
        additional_dependencies: [ruff]
        language_version:
          request: "3.12"
          preference: only-managed
```

With `only-managed`, prek reuses a compatible toolchain from its managed store
or downloads one when needed. It never falls back to Python from `PATH`, an OS
package manager, or a version manager, so toolchain selection does not depend on
the developer or CI machine's external environment.

Existing scalar values such as `language_version: "3.12"` continue to work. See
[toolchain management and `language_version`](https://prek.j178.dev/0.5.0/languages/#toolchain-management-and-language_version)
for the full source-selection behavior. ([#2613](j178/prek#2613))

### Breaking changes

The breaking changes in this release are mostly small cleanups, and most users should not be affected.

- Group names can no longer start with `@`. This prefix is now reserved for special group selectors such as the new `@​ungrouped` selector. ([#2617](j178/prek#2617))
- `PREK_MAX_CONCURRENCY` has been removed. Use `PREK_CONCURRENT_HOOKS` and `PREK_CONCURRENT_BATCHES` to control hook and per-hook batch concurrency separately. ([#2620](j178/prek#2620))
- The top-level `prek init-template-dir` command… (truncated)

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.14` → `0.5.2` | `0.4.14` → `0.5.2` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.14` → `0.5.2` (j178/prek)</summary>

### v0.5.0

## Release Notes

Released on 2026-08-27.

### Highlights

#### Choose where hook toolchains come from

`language_version` now accepts a source `preference` alongside the version
`request`, letting you control where prek looks for a compatible toolchain when
it creates a hook environment. Use `managed` (the default) or `system` to choose
which source prek tries first while still allowing fallback and downloads. Use
`only-managed` or `only-system` to require one source.

For example, this local Ruff hook requires a Python 3.12 toolchain managed by
prek:

```yaml
repos:
  - repo: local
    hooks:
      - id: ruff
        name: ruff
        language: python
        entry: ruff check
        additional_dependencies: [ruff]
        language_version:
          request: "3.12"
          preference: only-managed
```

With `only-managed`, prek reuses a compatible toolchain from its managed store
or downloads one when needed. It never falls back to Python from `PATH`, an OS
package manager, or a version manager, so toolchain selection does not depend on
the developer or CI machine's external environment.

Existing scalar values such as `language_version: "3.12"` continue to work. See
[toolchain management and `language_version`](https://prek.j178.dev/0.5.0/languages/#toolchain-management-and-language_version)
for the full source-selection behavior. ([#2613](j178/prek#2613))

### Breaking changes

The breaking changes in this release are mostly small cleanups, and most users should not be affected.

- Group names can no longer start with `@`. This prefix is now reserved for special group selectors such as the new `@​ungrouped` selector. ([#2617](j178/prek#2617))
- `PREK_MAX_CONCURRENCY` has been removed. Use `PREK_CONCURRENT_HOOKS` and `PREK_CONCURRENT_BATCHES` to control hook and per-hook batch concurrency separately. ([#2620](j178/prek#2620))
- The top-level `prek init-template-dir` command… (truncated)

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.0` → `0.5.2` | `0.5.0` → `0.5.2` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.5.0` → `0.5.2` (j178/prek)</summary>

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.1` → `0.5.2` | `0.5.1` → `0.5.2` |
| `rumdl` | `0.2.62` → `0.2.70` | `0.2.62` → `0.2.70` |
| `shfmt` | `3.14.0` → `3.14.1` | `3.14.0` → `3.14.1` |
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |
| `uv` | `0.12.8` → `0.12.12` | `0.12.8` → `0.12.12` |
| `zizmor` | `1.30.0` → `1.30.1` | `1.30.0` → `1.30.1` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>prek: `0.5.1` → `0.5.2` (j178/prek)</summary>

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>
<details>
<summary>rumdl: `0.2.62` → `0.2.70` (rvben/rumdl)</summary>

### v0.2.63

### Added

- **brand**: refine wordmark typography ([e871dcb](rvben/rumdl@e871dcb))
- **playground**: rebuild browser editor ([35e27df](rvben/rumdl@35e27df))
- **analytics**: classify aggregate referral sources ([3cc0ef2](rvben/rumdl@3cc0ef2))
- **brand**: add social previews and npm identity ([d6971f6](rvben/rumdl@d6971f6))
- **docs**: restore terminal capture colors ([eccf710](rvben/rumdl@eccf710))
- **docs**: frame terminal capture ([084fc30](rvben/rumdl@084fc30))
- **docs**: use real terminal capture ([e417bae](rvben/rumdl@e417bae))
- **docs**: replace hero proof with real terminal ([6c66a07](rvben/rumdl@6c66a07))
- **docs**: sharpen homepage activation path ([a60b622](rvben/rumdl@a60b622))
- **docs**: expose private adoption snapshot ([da299bb](rvben/rumdl@da299bb))
- **brand**: adopt Heading Pulse identity ([1a05c28](rvben/rumdl@1a05c28))
- **docs**: activate adoption analytics and reporting ([3a0b64f](rvben/rumdl@3a0b64f))
- **docs**: improve website and product documentation ([ad4ebf9](rvben/rumdl@ad4ebf9))

### Fixed

- **deps**: update vulnerable development dependencies ([8489019](rvben/rumdl@8489019))
- **MD051**: register HTML anc… (truncated)

### v0.2.64

### Added

- **flavor**: add preview support for GitHub Agentic Workflows (`gh-aw`), including imports and current conditional branch syntax ([39f7263](rvben/rumdl@39f7263))
- **Rust API**: add `MarkdownFlavor::GhAw`; downstream exhaustive matches must handle the new variant
- **MD089**: add opt-in cjk-spacing rule ([50f40a2](rvben/rumdl@50f40a2))
- **MD089**: add configuration for cjk-spacing symbol sets ([868e933](rvben/rumdl@868e933))
- **unicode**: add is_cjk_letter predicate ([087e518](rvben/rumdl@087e518))

### Fixed

- **MD013**: handle sentences ending before code spans in sentence-per-line reflow (#811, #812) ([576e2c1](rvben/rumdl@576e2c1))
- **MD022**: accept per-level arrays during validation ([976087c](rvben/rumdl@976087c))
- **MD051**: slug headings with the whitespace an anchor element leaves ([04cbfc2](rvben/rumdl@04cbfc2))
- **MD057**: exclude Markdown-looking frontmatter strings from body link validation and workspace indexing ([39f7263](rvben/rumdl@39f7263))
- **MD041**: never move or promote headings across GitHub Agentic Workflow control boundaries ([39f7263](rvben/rumdl@39f7263))
- **MD063**: capitalize opening link labels in sentence case ([88ea8b7](rvben/rumdl@88ea8b7))
- **MD073**: skip TOC entries for headings that slug to nothing ([41e2312](rvben/rumdl@41e2312))
- **docs**: improve responsi… (truncated)

### v0.2.65

### Added

- **MD091**: add opt-in rule for markdown inside HTML blocks ([4333acf](rvben/rumdl@4333acf))
- **cli**: add `--no-code-block-tools` and `--only-code-block-tools` mode flags (#829) ([fc410f7](rvben/rumdl@fc410f7))
- **config**: show every configuration section in `rumdl config` (#851) ([4dc0d30](rvben/rumdl@4dc0d30))

### Fixed

- **config**: parse `[tool.rumdl.code-block-tools]` in pyproject.toml (#851) ([87b159d](rvben/rumdl@87b159d))
- **config**: report a malformed code-block-tools section ([ed1b7c5](rvben/rumdl@ed1b7c5))
- **config**: report the line length MD013 enforces ([a4bf2a7](rvben/rumdl@a4bf2a7))
- **config**: state that an empty section in `rumdl config` is empty ([cac7b76](rvben/rumdl@cac7b76))
- **config**: print each code-block-tools setting on one line ([02ba15d](rvben/rumdl@02ba15d))
- **MD046**: preserve code blocks during style conversion ([9f13f3b](rvben/rumdl@9f13f3b))
- **MD063**: preserve the English first-person pronoun in sentence-case headings ([#845](rvben/rumdl#845)) ([35b2df9](rvben/rumdl@35b2df9))
- **MD063**: honor pronoun boundaries and explicit ignores ([0604c03](rvben/rumdl@0604c03))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.65-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releas… (truncated)

### v0.2.66

### Fixed

- **MD051**: GitHub-style anchors match GitHub.com for a `§` in the heading and for an emoji not surrounded by spaces (#854) ([d530737](rvben/rumdl@d530737)). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.
- **MD063**: recognize an ordinal wrapped in punctuation ([473bf51](rvben/rumdl@473bf51))
- **MD013**: keep a link-only line inside the sentence it continues ([3e767ee](rvben/rumdl@3e767ee))
- **MD013**: read require-sentence-capital when counting sentences ([8706780](rvben/rumdl@8706780))

### Added

- **config**: apply inline --config overrides to the non-rule sections ([7737dca](rvben/rumdl@7737dca))
- **cli**: accept format as a hidden alias for fmt ([0cd9168](rvben/rumdl@0cd9168))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.66-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-a… (truncated)

### v0.2.67

### Fixed

- **code-block-tools**: survive a tool that exits without reading its input ([a3f2b15](rvben/rumdl@a3f2b15))
- **MD042**: do not report an image with an unparseable destination as an empty link ([600236e](rvben/rumdl@600236e))
- **code-block-tools**: report missing tool binaries instead of passing silently ([fd83c4b](rvben/rumdl@fd83c4b))
- **code-block-tools**: report tool failures from the format path ([4f92370](rvben/rumdl@4f92370))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-x… (truncated)

### v0.2.68

### Fixed

- **MDX**: recognize Markdown links and images inside JSX elements, including generated reference tables, without requiring blank lines. This removes false MD091 warnings and lets normal link rules check the content. JavaScript expressions, JSX attributes, comments, and code are excluded, and link fixes preserve source labels and positions ([#801](rvben/rumdl#801)).

### Performance

- Reduce regex locking and redundant rule work.
- Precompute proper-name lookups and streamline regex caching.

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum… (truncated)

### v0.2.69

### Fixed

- **MD032**: recognize spaced nested blockquotes ([974540f](rvben/rumdl@974540f))
- **MD032**: separate lists from standalone code fences ([e335c58](rvben/rumdl@e335c58))
- **mdx**: avoid parser panic on malformed Setext headings ([5e4a387](rvben/rumdl@5e4a387))
- preserve markdown containing merge conflicts ([8aabd3d](rvben/rumdl@8aabd3d))
- **deps**: remove unmaintained paste and atomic-polyfill ([e2ab5cb](rvben/rumdl@e2ab5cb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-u… (truncated)

### v0.2.70

### Fixed

- **mdx**: recover instead of crashing on unclosed JSX in a link label ([35de79c](rvben/rumdl@35de79c))
- **lsp**: index links whose paths contain parentheses ([bc5adc0](rvben/rumdl@bc5adc0))
- **MD057**: handle balanced parentheses in link paths ([b2a9ce9](rvben/rumdl@b2a9ce9))
- **MD032**: respect suppression at each list boundary ([9aeb5f3](rvben/rumdl@9aeb5f3))
- **MD087,inline-config**: ignore directives inside inline code spans ([749a7ea](rvben/rumdl@749a7ea))
- **stdin**: preserve original bytes when formatting is unchanged ([2c84470](rvben/rumdl@2c84470))
- **MD046**: align fence repairs with diagnostic edits ([443892e](rvben/rumdl@443892e))
- **MD032**: preserve line endings in document fixes ([60bae56](rvben/rumdl@60bae56))

### Performance

- **MD024**: avoid cloned keys and redundant diagnostic work ([ffebf4e](rvben/rumdl@ffebf4e))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/… (truncated)

</details>
<details>
<summary>shfmt: `3.14.0` → `3.14.1` (mvdan/sh)</summary>

### v3.14.1

- **syntax**
  - Fix the indentation of heredocs nested inside command substitutions - #1403
  - Keep literal tabs in `<<-` heredoc bodies rather than replacing them with spaces
  - Don't indent heredocs without dashes nested in `<<-` ones, whose output no longer parsed
  - Zsh: don't drop the prefix in short forms like `$#"$foo"` and `$+"$foo"` - #1405
- **interp**
  - Fix the build on 32-bit FreeBSD and NetBSD
- **expand**
  - Don't let escaped characters such as `\*` act as glob metacharacters
- **pattern**
  - Treat unclosed extended operator groups like `@(a` as literals, avoiding a panic

Consider [becoming a sponsor](https://github.com/sponsors/mvdan) if you benefit from the work that went into this release!

Binaries built on `go version go1.27.1 linux/amd64` with:

	CGO_ENABLED=0 go build -trimpath -ldflags="-w -s"

</details>
<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>
<details>
<summary>uv: `0.12.8` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>
<details>
<summary>zizmor: `1.30.0` → `1.30.1` (zizmorcore/zizmor)</summary>

### v1.30.1

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix ([#2363](zizmorcore/zizmor#2363))

- Fixed a bug where [self-repository](https://docs.zizmor.sh/audits/#self-repository) auto-fixes were incorrectly marked as "safe" instead of "unsafe" ([#2373](zizmorcore/zizmor#2373))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.0` → `0.5.2` | `0.5.0` → `0.5.2` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.5.0` → `0.5.2` (j178/prek)</summary>

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants