Skip to content

fix: update vulnerable npm dependencies - #2157

Merged
ya7010 merged 1 commit into
tombi-toml:mainfrom
ya7010:fix-osv-npm-vulns
Sep 4, 2026
Merged

ya7010 merged 1 commit into
tombi-toml:mainfrom
ya7010:fix-osv-npm-vulns

Conversation

@ya7010

@ya7010 ya7010 commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • update vulnerable transitive npm dependencies reported by the scheduled OSV scan
  • pin browserslist, fast-uri, and qs to their fixed versions through workspace overrides
  • allow only qs@6.16.0 through the release-age gate because it is the sole fixed release

Verification

  • pnpm install --lockfile-only --frozen-lockfile --link-workspace-packages=true
  • OSV Scanner v2.3.8: No issues found
  • cargo fmt --all -- --check
  • git diff --check
  • independent local review: no actionable findings

Fixes the failure in https://github.com/tombi-toml/tombi/actions/runs/33741642793/job/100604696725

Copilot AI lite review requested due to automatic review settings September 3, 2026 23:37
@ya7010 ya7010 added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

workspace overrides と lockfile 更新のみで、リポジトリの Node 実行環境(.node-version / CI の Node 設定)とも整合しており、脆弱性対応として妥当です。

Pull request overview

スケジュール実行の OSV scan で検出された脆弱な npm の推移依存を解消するために、workspace の overrides と lockfile を更新し、修正版へ強制的に寄せる PR です。tombi リポジトリ内の Node/TypeScript 系サブプロジェクト(docs / VSCode 拡張 / wasm パッケージ群)の依存解決を安定させる目的に合致しています。

Changes:

  • pnpm-workspace.yaml の overrides で browserslist / fast-uri / qs を修正版へ固定
  • minimumReleaseAgeExclude に qs@6.16.0 を追加し、release-age gate の例外を最小範囲で許可
  • pnpm-lock.yaml を再生成して上記 overrides の反映(関連する推移依存の解決結果更新を含む)
File summaries
File Description
pnpm-workspace.yaml 脆弱性修正版への強制ピンと、release-age gate の例外(qs@6.16.0)を追加
pnpm-lock.yaml overrides 反映後の依存解決結果(固定バージョン・integrity・関連推移依存)へ更新
Review details

Files not reviewed (1)

  • pnpm-lock.yaml: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ya7010
ya7010 merged commit f99f7a9 into tombi-toml:main Sep 4, 2026
25 checks passed
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.0` → `0.5.2` | `0.5.0` → `0.5.2` |
| `rumdl` | `0.2.62` → `0.2.70` | `0.2.62` → `0.2.70` |
| `shfmt` | `3.14.0` → `3.14.1` | `3.14.0` → `3.14.1` |
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |
| `uv` | `0.12.7` → `0.12.12` | `0.12.7` → `0.12.12` |
| `zizmor` | `1.30.0` → `1.30.1` | `1.30.0` → `1.30.1` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>prek: `0.5.0` → `0.5.2` (j178/prek)</summary>

### v0.5.1

## Release Notes

Released on 2026-09-01.

### Enhancements

- Add `--hide-status <passed|failed|skipped>` for hook reports ([#2644](j178/prek#2644))
- Add `prek init` for repository setup ([#2636](j178/prek#2636))
- Apply hook `env` during environment creation ([#2650](j178/prek#2650))
- Disable error snippets in `check-yaml` diagnostics ([#2664](j178/prek#2664))
- Show hooks excluded by skip selectors ([#2645](j178/prek#2645))
- Support Pixi for Conda environments ([#2667](j178/prek#2667))
- Support `cargo-binstall` for Rust CLI dependencies ([#2658](j178/prek#2658))
- Warn about unused keys in user settings ([#2665](j178/prek#2665))

### Bug fixes

- Reject unsupported YAML tags in check-yaml ([#2656](j178/prek#2656))

### Documentation

- Clarify local hook documentation ([#2640](j178/prek#2640))
- Clarify pre-commit command compatibility ([#2635](j178/prek#2635))
- Document automatic PR fixes with autofix.ci ([#2643](j178/prek#2643))
- Document check-yaml unsafe support ([#2632](j178/prek#2632))
- Improve setup and workflow documentation ([#2637](j178/prek#2637))

### Other changes

- Drop low-usage release targets ([#2651](j178/prek#2651))
- Generate a prek manifest JSON schema ([#2648](j178/prek#2648))

### Contributors

- @​j178

## Install prek 0.5.1

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.1/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download… (truncated)

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>
<details>
<summary>rumdl: `0.2.62` → `0.2.70` (rvben/rumdl)</summary>

### v0.2.63

### Added

- **brand**: refine wordmark typography ([e871dcb](rvben/rumdl@e871dcb))
- **playground**: rebuild browser editor ([35e27df](rvben/rumdl@35e27df))
- **analytics**: classify aggregate referral sources ([3cc0ef2](rvben/rumdl@3cc0ef2))
- **brand**: add social previews and npm identity ([d6971f6](rvben/rumdl@d6971f6))
- **docs**: restore terminal capture colors ([eccf710](rvben/rumdl@eccf710))
- **docs**: frame terminal capture ([084fc30](rvben/rumdl@084fc30))
- **docs**: use real terminal capture ([e417bae](rvben/rumdl@e417bae))
- **docs**: replace hero proof with real terminal ([6c66a07](rvben/rumdl@6c66a07))
- **docs**: sharpen homepage activation path ([a60b622](rvben/rumdl@a60b622))
- **docs**: expose private adoption snapshot ([da299bb](rvben/rumdl@da299bb))
- **brand**: adopt Heading Pulse identity ([1a05c28](rvben/rumdl@1a05c28))
- **docs**: activate adoption analytics and reporting ([3a0b64f](rvben/rumdl@3a0b64f))
- **docs**: improve website and product documentation ([ad4ebf9](rvben/rumdl@ad4ebf9))

### Fixed

- **deps**: update vulnerable development dependencies ([8489019](rvben/rumdl@8489019))
- **MD051**: register HTML anc… (truncated)

### v0.2.64

### Added

- **flavor**: add preview support for GitHub Agentic Workflows (`gh-aw`), including imports and current conditional branch syntax ([39f7263](rvben/rumdl@39f7263))
- **Rust API**: add `MarkdownFlavor::GhAw`; downstream exhaustive matches must handle the new variant
- **MD089**: add opt-in cjk-spacing rule ([50f40a2](rvben/rumdl@50f40a2))
- **MD089**: add configuration for cjk-spacing symbol sets ([868e933](rvben/rumdl@868e933))
- **unicode**: add is_cjk_letter predicate ([087e518](rvben/rumdl@087e518))

### Fixed

- **MD013**: handle sentences ending before code spans in sentence-per-line reflow (#811, #812) ([576e2c1](rvben/rumdl@576e2c1))
- **MD022**: accept per-level arrays during validation ([976087c](rvben/rumdl@976087c))
- **MD051**: slug headings with the whitespace an anchor element leaves ([04cbfc2](rvben/rumdl@04cbfc2))
- **MD057**: exclude Markdown-looking frontmatter strings from body link validation and workspace indexing ([39f7263](rvben/rumdl@39f7263))
- **MD041**: never move or promote headings across GitHub Agentic Workflow control boundaries ([39f7263](rvben/rumdl@39f7263))
- **MD063**: capitalize opening link labels in sentence case ([88ea8b7](rvben/rumdl@88ea8b7))
- **MD073**: skip TOC entries for headings that slug to nothing ([41e2312](rvben/rumdl@41e2312))
- **docs**: improve responsi… (truncated)

### v0.2.65

### Added

- **MD091**: add opt-in rule for markdown inside HTML blocks ([4333acf](rvben/rumdl@4333acf))
- **cli**: add `--no-code-block-tools` and `--only-code-block-tools` mode flags (#829) ([fc410f7](rvben/rumdl@fc410f7))
- **config**: show every configuration section in `rumdl config` (#851) ([4dc0d30](rvben/rumdl@4dc0d30))

### Fixed

- **config**: parse `[tool.rumdl.code-block-tools]` in pyproject.toml (#851) ([87b159d](rvben/rumdl@87b159d))
- **config**: report a malformed code-block-tools section ([ed1b7c5](rvben/rumdl@ed1b7c5))
- **config**: report the line length MD013 enforces ([a4bf2a7](rvben/rumdl@a4bf2a7))
- **config**: state that an empty section in `rumdl config` is empty ([cac7b76](rvben/rumdl@cac7b76))
- **config**: print each code-block-tools setting on one line ([02ba15d](rvben/rumdl@02ba15d))
- **MD046**: preserve code blocks during style conversion ([9f13f3b](rvben/rumdl@9f13f3b))
- **MD063**: preserve the English first-person pronoun in sentence-case headings ([#845](rvben/rumdl#845)) ([35b2df9](rvben/rumdl@35b2df9))
- **MD063**: honor pronoun boundaries and explicit ignores ([0604c03](rvben/rumdl@0604c03))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.65-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releas… (truncated)

### v0.2.66

### Fixed

- **MD051**: GitHub-style anchors match GitHub.com for a `§` in the heading and for an emoji not surrounded by spaces (#854) ([d530737](rvben/rumdl@d530737)). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.
- **MD063**: recognize an ordinal wrapped in punctuation ([473bf51](rvben/rumdl@473bf51))
- **MD013**: keep a link-only line inside the sentence it continues ([3e767ee](rvben/rumdl@3e767ee))
- **MD013**: read require-sentence-capital when counting sentences ([8706780](rvben/rumdl@8706780))

### Added

- **config**: apply inline --config overrides to the non-rule sections ([7737dca](rvben/rumdl@7737dca))
- **cli**: accept format as a hidden alias for fmt ([0cd9168](rvben/rumdl@0cd9168))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.66-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-a… (truncated)

### v0.2.67

### Fixed

- **code-block-tools**: survive a tool that exits without reading its input ([a3f2b15](rvben/rumdl@a3f2b15))
- **MD042**: do not report an image with an unparseable destination as an empty link ([600236e](rvben/rumdl@600236e))
- **code-block-tools**: report missing tool binaries instead of passing silently ([fd83c4b](rvben/rumdl@fd83c4b))
- **code-block-tools**: report tool failures from the format path ([4f92370](rvben/rumdl@4f92370))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-x… (truncated)

### v0.2.68

### Fixed

- **MDX**: recognize Markdown links and images inside JSX elements, including generated reference tables, without requiring blank lines. This removes false MD091 warnings and lets normal link rules check the content. JavaScript expressions, JSX attributes, comments, and code are excluded, and link fixes preserve source labels and positions ([#801](rvben/rumdl#801)).

### Performance

- Reduce regex locking and redundant rule work.
- Precompute proper-name lookups and streamline regex caching.

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum… (truncated)

### v0.2.69

### Fixed

- **MD032**: recognize spaced nested blockquotes ([974540f](rvben/rumdl@974540f))
- **MD032**: separate lists from standalone code fences ([e335c58](rvben/rumdl@e335c58))
- **mdx**: avoid parser panic on malformed Setext headings ([5e4a387](rvben/rumdl@5e4a387))
- preserve markdown containing merge conflicts ([8aabd3d](rvben/rumdl@8aabd3d))
- **deps**: remove unmaintained paste and atomic-polyfill ([e2ab5cb](rvben/rumdl@e2ab5cb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-u… (truncated)

### v0.2.70

### Fixed

- **mdx**: recover instead of crashing on unclosed JSX in a link label ([35de79c](rvben/rumdl@35de79c))
- **lsp**: index links whose paths contain parentheses ([bc5adc0](rvben/rumdl@bc5adc0))
- **MD057**: handle balanced parentheses in link paths ([b2a9ce9](rvben/rumdl@b2a9ce9))
- **MD032**: respect suppression at each list boundary ([9aeb5f3](rvben/rumdl@9aeb5f3))
- **MD087,inline-config**: ignore directives inside inline code spans ([749a7ea](rvben/rumdl@749a7ea))
- **stdin**: preserve original bytes when formatting is unchanged ([2c84470](rvben/rumdl@2c84470))
- **MD046**: align fence repairs with diagnostic edits ([443892e](rvben/rumdl@443892e))
- **MD032**: preserve line endings in document fixes ([60bae56](rvben/rumdl@60bae56))

### Performance

- **MD024**: avoid cloned keys and redundant diagnostic work ([ffebf4e](rvben/rumdl@ffebf4e))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/… (truncated)

</details>
<details>
<summary>shfmt: `3.14.0` → `3.14.1` (mvdan/sh)</summary>

### v3.14.1

- **syntax**
  - Fix the indentation of heredocs nested inside command substitutions - #1403
  - Keep literal tabs in `<<-` heredoc bodies rather than replacing them with spaces
  - Don't indent heredocs without dashes nested in `<<-` ones, whose output no longer parsed
  - Zsh: don't drop the prefix in short forms like `$#"$foo"` and `$+"$foo"` - #1405
- **interp**
  - Fix the build on 32-bit FreeBSD and NetBSD
- **expand**
  - Don't let escaped characters such as `\*` act as glob metacharacters
- **pattern**
  - Treat unclosed extended operator groups like `@(a` as literals, avoiding a panic

Consider [becoming a sponsor](https://github.com/sponsors/mvdan) if you benefit from the work that went into this release!

Binaries built on `go version go1.27.1 linux/amd64` with:

	CGO_ENABLED=0 go build -trimpath -ldflags="-w -s"

</details>
<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>
<details>
<summary>uv: `0.12.7` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.8

## Release Notes

Released on 2026-08-31.

### Enhancements

- Warn about invalid tool directories and continue upgrading valid tools with `uv tool upgrade --all` ([#21368](astral-sh/uv#21368))

### Preview features

- Deduplicate identical files within and across cached wheels with the `content-addressed-cache` preview feature ([#21327](astral-sh/uv#21327))
- Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files ([#21340](astral-sh/uv#21340))
- Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk ([#21344](astral-sh/uv#21344))

### Performance

- Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once ([#21379](astral-sh/uv#21379))
- Speed up dependency graph construction from large lockfiles by indexing packages during traversal ([#21373](astral-sh/uv#21373))
- Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks ([#21377](astral-sh/uv#21377))
- Speed up warm resolutions by reducing repeated marker interner work ([#21300](astral-sh/uv#21300))

### Bug fixes

- Do not trust hashes from direct URLs discovered only in wheel metadata when installing with `--require-hashes` ([#21348](astral-sh/uv#21348))
- Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled ([#21366](astral-sh/uv#21366))
- Redact Azure shared access signature (`sig`) query parameters from displayed URLs ([#21360](astral-sh/uv#21360))
- Treat projects below one-level workspace member globs as standalone instead of aborting workspace discovery ([#21341](https://github.com/astra… (truncated)

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>
<details>
<summary>zizmor: `1.30.0` → `1.30.1` (zizmorcore/zizmor)</summary>

### v1.30.1

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix ([#2363](zizmorcore/zizmor#2363))

- Fixed a bug where [self-repository](https://docs.zizmor.sh/audits/#self-repository) auto-fixes were incorrectly marked as "safe" instead of "unsafe" ([#2373](zizmorcore/zizmor#2373))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.4.1` → `1.5.4` | `1.4.1` → `1.5.4` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.4.1` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.0

<!-- Release notes generated using configuration in .github/release.yml at v1.5.0 -->

## What's Changed
Tombi v1.5.0 is a major performance and architecture release.

We redesigned the parser and AST around a compact, source-backed syntax tape, replacing the previous red-green syntax tree.
The new architecture is optimized for Tombi’s lossless, long-lived editor and LSP workloads: it improves memory locality and reduces allocation and pointer-chasing overhead while preserving comments, punctuation, incomplete syntax, and diagnostics.
The AST and document-tree interfaces are now also separated from their syntax-backed implementations.

We also optimized hot paths throughout the parser, JSON Schema processing, linter, formatter, and stdin-based CLI workflows.
In our Apple M2 Max benchmarks, long ASCII comment lexing was approximately 2.3× faster, selected JSON parsing workloads improved by up to 84%, and repository-wide lint time decreased from approximately 355 ms to 81 ms.

### 🚨 Breaking Changes
* perf(parser): replace syntax tree with compact tape by @​ya7010 in tombi-toml/tombi#2140

### 🐝 Bug Fixes
* fix(lsp): preserve composite schema metadata by @​ya7010 in tombi-toml/tombi#2139

### 🛠️ Other Changes
* Improve minimal-change guidance for agents by @​ya7010 in tombi-toml/tombi#2137
* perf(parser): accelerate long comment scanning by @​ya7010 in tombi-toml/tombi#2141
* perf: speed up lint and format by @​ya7010 in tombi-toml/tombi#2142
* perf: reduce stdin runtime overhead by @​ya7010 in tombi-toml/tombi#2143
* perf(json): accelerate long string parsing by @​ya7010 in tombi-toml/tombi#2145
* perf(json): optimize lexer and parser hot paths by @​ya7010 in tombi-toml/tombi#2146

**Full Changelog**: https://github.com/tombi-toml/tomb… (truncated)

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.1` → `0.5.2` | `0.5.1` → `0.5.2` |
| `rumdl` | `0.2.62` → `0.2.70` | `0.2.62` → `0.2.70` |
| `shfmt` | `3.14.0` → `3.14.1` | `3.14.0` → `3.14.1` |
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |
| `uv` | `0.12.8` → `0.12.12` | `0.12.8` → `0.12.12` |
| `zizmor` | `1.30.0` → `1.30.1` | `1.30.0` → `1.30.1` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>prek: `0.5.1` → `0.5.2` (j178/prek)</summary>

### v0.5.2

## Release Notes

Released on 2026-09-03.

### Enhancements

- Allow unknown tags by default in `check-yaml` ([#2678](j178/prek#2678))

### Contributors

- @​j178

## Install prek 0.5.2

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.2/prek-installer.ps1 | iex"
```

### Install prebuilt binaries via Homebrew

```sh
brew install prek
```

## Download prek 0.5.2

|  File  | Platform | Checksum |
|--------|----------|----------|
| [prek-aarch64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-apple-darwin.tar.gz.sha256) |
| [prek-x86_64-apple-darwin.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-apple-darwin.tar.gz.sha256) |
| [prek-aarch64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-pc-windows-msvc.zip.sha256) |
| [prek-x86_64-pc-windows-msvc.zip](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-x86_64-pc-windows-msvc.zip.sha256) |
| [prek-aarch64-unknown-linux-gnu.tar.gz](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.gz) | ARM64 Linux | [checksum](https://github.com/j178/prek/releases/download/v0.5.2/prek-aarch64-unknown-linux-gnu.tar.g… (truncated)

</details>
<details>
<summary>rumdl: `0.2.62` → `0.2.70` (rvben/rumdl)</summary>

### v0.2.63

### Added

- **brand**: refine wordmark typography ([e871dcb](rvben/rumdl@e871dcb))
- **playground**: rebuild browser editor ([35e27df](rvben/rumdl@35e27df))
- **analytics**: classify aggregate referral sources ([3cc0ef2](rvben/rumdl@3cc0ef2))
- **brand**: add social previews and npm identity ([d6971f6](rvben/rumdl@d6971f6))
- **docs**: restore terminal capture colors ([eccf710](rvben/rumdl@eccf710))
- **docs**: frame terminal capture ([084fc30](rvben/rumdl@084fc30))
- **docs**: use real terminal capture ([e417bae](rvben/rumdl@e417bae))
- **docs**: replace hero proof with real terminal ([6c66a07](rvben/rumdl@6c66a07))
- **docs**: sharpen homepage activation path ([a60b622](rvben/rumdl@a60b622))
- **docs**: expose private adoption snapshot ([da299bb](rvben/rumdl@da299bb))
- **brand**: adopt Heading Pulse identity ([1a05c28](rvben/rumdl@1a05c28))
- **docs**: activate adoption analytics and reporting ([3a0b64f](rvben/rumdl@3a0b64f))
- **docs**: improve website and product documentation ([ad4ebf9](rvben/rumdl@ad4ebf9))

### Fixed

- **deps**: update vulnerable development dependencies ([8489019](rvben/rumdl@8489019))
- **MD051**: register HTML anc… (truncated)

### v0.2.64

### Added

- **flavor**: add preview support for GitHub Agentic Workflows (`gh-aw`), including imports and current conditional branch syntax ([39f7263](rvben/rumdl@39f7263))
- **Rust API**: add `MarkdownFlavor::GhAw`; downstream exhaustive matches must handle the new variant
- **MD089**: add opt-in cjk-spacing rule ([50f40a2](rvben/rumdl@50f40a2))
- **MD089**: add configuration for cjk-spacing symbol sets ([868e933](rvben/rumdl@868e933))
- **unicode**: add is_cjk_letter predicate ([087e518](rvben/rumdl@087e518))

### Fixed

- **MD013**: handle sentences ending before code spans in sentence-per-line reflow (#811, #812) ([576e2c1](rvben/rumdl@576e2c1))
- **MD022**: accept per-level arrays during validation ([976087c](rvben/rumdl@976087c))
- **MD051**: slug headings with the whitespace an anchor element leaves ([04cbfc2](rvben/rumdl@04cbfc2))
- **MD057**: exclude Markdown-looking frontmatter strings from body link validation and workspace indexing ([39f7263](rvben/rumdl@39f7263))
- **MD041**: never move or promote headings across GitHub Agentic Workflow control boundaries ([39f7263](rvben/rumdl@39f7263))
- **MD063**: capitalize opening link labels in sentence case ([88ea8b7](rvben/rumdl@88ea8b7))
- **MD073**: skip TOC entries for headings that slug to nothing ([41e2312](rvben/rumdl@41e2312))
- **docs**: improve responsi… (truncated)

### v0.2.65

### Added

- **MD091**: add opt-in rule for markdown inside HTML blocks ([4333acf](rvben/rumdl@4333acf))
- **cli**: add `--no-code-block-tools` and `--only-code-block-tools` mode flags (#829) ([fc410f7](rvben/rumdl@fc410f7))
- **config**: show every configuration section in `rumdl config` (#851) ([4dc0d30](rvben/rumdl@4dc0d30))

### Fixed

- **config**: parse `[tool.rumdl.code-block-tools]` in pyproject.toml (#851) ([87b159d](rvben/rumdl@87b159d))
- **config**: report a malformed code-block-tools section ([ed1b7c5](rvben/rumdl@ed1b7c5))
- **config**: report the line length MD013 enforces ([a4bf2a7](rvben/rumdl@a4bf2a7))
- **config**: state that an empty section in `rumdl config` is empty ([cac7b76](rvben/rumdl@cac7b76))
- **config**: print each code-block-tools setting on one line ([02ba15d](rvben/rumdl@02ba15d))
- **MD046**: preserve code blocks during style conversion ([9f13f3b](rvben/rumdl@9f13f3b))
- **MD063**: preserve the English first-person pronoun in sentence-case headings ([#845](rvben/rumdl#845)) ([35b2df9](rvben/rumdl@35b2df9))
- **MD063**: honor pronoun boundaries and explicit ignores ([0604c03](rvben/rumdl@0604c03))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.65-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releas… (truncated)

### v0.2.66

### Fixed

- **MD051**: GitHub-style anchors match GitHub.com for a `§` in the heading and for an emoji not surrounded by spaces (#854) ([d530737](rvben/rumdl@d530737)). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.
- **MD063**: recognize an ordinal wrapped in punctuation ([473bf51](rvben/rumdl@473bf51))
- **MD013**: keep a link-only line inside the sentence it continues ([3e767ee](rvben/rumdl@3e767ee))
- **MD013**: read require-sentence-capital when counting sentences ([8706780](rvben/rumdl@8706780))

### Added

- **config**: apply inline --config overrides to the non-rule sections ([7737dca](rvben/rumdl@7737dca))
- **cli**: accept format as a hidden alias for fmt ([0cd9168](rvben/rumdl@0cd9168))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.66-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.66/rumdl-v0.2.66-a… (truncated)

### v0.2.67

### Fixed

- **code-block-tools**: survive a tool that exits without reading its input ([a3f2b15](rvben/rumdl@a3f2b15))
- **MD042**: do not report an image with an unparseable destination as an empty link ([600236e](rvben/rumdl@600236e))
- **code-block-tools**: report missing tool binaries instead of passing silently ([fd83c4b](rvben/rumdl@fd83c4b))
- **code-block-tools**: report tool failures from the format path ([4f92370](rvben/rumdl@4f92370))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.67/rumdl-v0.2.67-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.67-x… (truncated)

### v0.2.68

### Fixed

- **MDX**: recognize Markdown links and images inside JSX elements, including generated reference tables, without requiring blank lines. This removes false MD091 warnings and lets normal link rules check the content. JavaScript expressions, JSX attributes, comments, and code are excluded, and link fixes preserve source labels and positions ([#801](rvben/rumdl#801)).

### Performance

- Reduce regex locking and redundant rule work.
- Precompute proper-name lookups and streamline regex caching.

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.68-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.68/rumdl-v0.2.68-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum… (truncated)

### v0.2.69

### Fixed

- **MD032**: recognize spaced nested blockquotes ([974540f](rvben/rumdl@974540f))
- **MD032**: separate lists from standalone code fences ([e335c58](rvben/rumdl@e335c58))
- **mdx**: avoid parser panic on malformed Setext headings ([5e4a387](rvben/rumdl@5e4a387))
- preserve markdown containing merge conflicts ([8aabd3d](rvben/rumdl@8aabd3d))
- **deps**: remove unmaintained paste and atomic-polyfill ([e2ab5cb](rvben/rumdl@e2ab5cb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.69/rumdl-v0.2.69-aarch64-u… (truncated)

### v0.2.70

### Fixed

- **mdx**: recover instead of crashing on unclosed JSX in a link label ([35de79c](rvben/rumdl@35de79c))
- **lsp**: index links whose paths contain parentheses ([bc5adc0](rvben/rumdl@bc5adc0))
- **MD057**: handle balanced parentheses in link paths ([b2a9ce9](rvben/rumdl@b2a9ce9))
- **MD032**: respect suppression at each list boundary ([9aeb5f3](rvben/rumdl@9aeb5f3))
- **MD087,inline-config**: ignore directives inside inline code spans ([749a7ea](rvben/rumdl@749a7ea))
- **stdin**: preserve original bytes when formatting is unchanged ([2c84470](rvben/rumdl@2c84470))
- **MD046**: align fence repairs with diagnostic edits ([443892e](rvben/rumdl@443892e))
- **MD032**: preserve line endings in document fixes ([60bae56](rvben/rumdl@60bae56))

### Performance

- **MD024**: avoid cloned keys and redundant diagnostic work ([ffebf4e](rvben/rumdl@ffebf4e))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.70/rumdl-v0.2.70-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/… (truncated)

</details>
<details>
<summary>shfmt: `3.14.0` → `3.14.1` (mvdan/sh)</summary>

### v3.14.1

- **syntax**
  - Fix the indentation of heredocs nested inside command substitutions - #1403
  - Keep literal tabs in `<<-` heredoc bodies rather than replacing them with spaces
  - Don't indent heredocs without dashes nested in `<<-` ones, whose output no longer parsed
  - Zsh: don't drop the prefix in short forms like `$#"$foo"` and `$+"$foo"` - #1405
- **interp**
  - Fix the build on 32-bit FreeBSD and NetBSD
- **expand**
  - Don't let escaped characters such as `\*` act as glob metacharacters
- **pattern**
  - Treat unclosed extended operator groups like `@(a` as literals, avoiding a panic

Consider [becoming a sponsor](https://github.com/sponsors/mvdan) if you benefit from the work that went into this release!

Binaries built on `go version go1.27.1 linux/amd64` with:

	CGO_ENABLED=0 go build -trimpath -ldflags="-w -s"

</details>
<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>
<details>
<summary>uv: `0.12.8` → `0.12.12` (astral-sh/uv)</summary>

### 0.12.9

## Release Notes

Released on 2026-09-01.

### Python

- Add CPython 3.15.0rc2 ([#21413](astral-sh/uv#21413), [#21415](astral-sh/uv#21415))

### Enhancements

- Add `--no-locked` and `--no-frozen` to disable lock modes enabled by `UV_LOCKED` and `UV_FROZEN` for a single invocation ([#21408](astral-sh/uv#21408))
- Report the exact command-line lock-mode flag in warnings and errors ([#21402](astral-sh/uv#21402))

### Performance

- Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files ([#21372](astral-sh/uv#21372))

### Bug fixes

- Update `async_http_range_reader` to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels ([#21401](astral-sh/uv#21401))
- Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes ([#21382](astral-sh/uv#21382))
- Redact secrets in signed URLs from retry diagnostics, including nested request errors ([#21381](astral-sh/uv#21381))
- Give `--locked`, `--frozen`, `--check`, and `--check-exists` precedence over conflicting `UV_LOCKED` and `UV_FROZEN` values ([#21396](astral-sh/uv#21396))
- Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel ([#21400](astral-sh/uv#21400))

## Install uv 0.12.9

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"
```

## Downlo… (truncated)

### 0.12.10

## Release Notes

Released on 2026-09-04.

### Enhancements

- Attempt to revoke short-lived PyPI trusted-publishing tokens after `uv publish` completes, including when publishing fails ([#21423](astral-sh/uv#21423))

### Preview features

- Omit `exclude-newer-package` settings for packages outside the resolution from `uv.lock` with the `missing-exclude-newer-package-lock` preview feature ([#21455](astral-sh/uv#21455))
- Show terminal dependency cycles in `uv tree --invert` output ([#21404](astral-sh/uv#21404))

### Performance

- Speed up locking large workspaces with conflicts by excluding unrelated extras and dependency groups from conflict simplification ([#21399](astral-sh/uv#21399))
- Speed up `uv publish` by hashing each artifact in a single blocking task and reusing the buffer across reads ([#21389](astral-sh/uv#21389))

### Bug fixes

- Prevent `--locked` from failing when `exclude-newer-package` settings differ only for packages outside the resolution ([#21454](astral-sh/uv#21454))
- Allow `uv lock --check` to reuse a lockfile when an absolute `exclude-newer` cutoff is moved later ([#19571](astral-sh/uv#19571))
- Allow `uv lock --check` to reuse a lockfile when a package-specific `exclude-newer` cutoff is disabled ([#21450](astral-sh/uv#21450))
- Require an explicit `--name` when `uv init` would infer a project name reserved for a Python interpreter ([#21395](astral-sh/uv#21395))
- Write package-specific `exclude-newer` cutoffs to `uv.lock` in a deterministic order ([#21453](astral-sh/uv#21453))

## Install uv 0.12.10

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.10/uv-installer.sh | sh
```

### Instal… (truncated)

### 0.12.11

## Release Notes

Released on 2026-09-08.

### Preview features

- Generate missing artifact hashes when exporting `pylock.toml` files to ensure they conform to PEP 751 ([#20146](astral-sh/uv#20146))
- Warn when `pylock.toml` artifact hash tables are empty, which will be rejected in a future uv release ([#21462](astral-sh/uv#21462))

### Performance

- Speed up installs that overwrite existing files by eliminating per-file temporary directories for atomic hard-link, symlink, and reflink replacements ([#21478](astral-sh/uv#21478))
- Speed up installs that merge copied wheels into existing environments by replacing per-file temporary directories with adjacent temporary files ([#21468](astral-sh/uv#21468))
- Speed up local wheel installs by replacing the shared ZIP cursor lock with positioned reads ([#21500](astral-sh/uv#21500))
- Speed up local wheel installs by reusing ZIP readers and buffers across extracted files ([#21499](astral-sh/uv#21499))
- Avoid transitive dependency checks and unnecessary resolution when `uv pip install --no-deps` finds the requested packages already installed ([#21523](astral-sh/uv#21523))

### Bug fixes

- Verify source archives against hashes recorded in `uv.lock` before reading their metadata or running their build backends ([#21223](astral-sh/uv#21223))
- Verify supplied hashes for registry requirements pinned with `===` under both `--verify-hashes` and `--require-hashes` ([#21543](astral-sh/uv#21543))
- Apply hashes from public-version pins to matching local versions when no exact local-version hash is provided ([#21544](astral-sh/uv#21544))
- Support PowerShell virtual environment activation from UNC paths, including WSL paths ([#19159](astral-sh/uv#19159))
- Tri… (truncated)

### 0.12.12

## Release Notes

Released on 2026-09-09.

The executables in our macOS and Windows release archives and `uv` and `uv_build` wheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.

### Bug fixes

- Exclude distributions uploaded after the `exclude-newer` cutoff from lockfiles and generated requirement hashes ([#21539](astral-sh/uv#21539))

## Install uv 0.12.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-installer.ps1 | iex"
```

## Download uv 0.12.12

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.12/uv-aarch64-pc-windows-msvc.zip.sha256) |
| [uv-i68… (truncated)

</details>
<details>
<summary>zizmor: `1.30.0` → `1.30.1` (zizmorcore/zizmor)</summary>

### v1.30.1

[Sponsorship is appreciated!](https://github.com/sponsors/woodruffw/)

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix ([#2363](zizmorcore/zizmor#2363))

- Fixed a bug where [self-repository](https://docs.zizmor.sh/audits/#self-repository) auto-fixes were incorrectly marked as "safe" instead of "unsafe" ([#2373](zizmorcore/zizmor#2373))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 11, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.5.0` → `1.5.4` | `1.5.0` → `1.5.4` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.5.0` → `1.5.4` (tombi-toml/tombi)</summary>

### v1.5.1

<!-- Release notes generated using configuration in .github/release.yml at v1.5.1 -->

## What's Changed
### 🐝 Bug Fixes
* fix(linter): suppress false strict warnings for ref siblings by  @​kjanat in tombi-toml/tombi#2152
* test(lexer): cover CRLF after basic string escape and simplify test macro by  @​kjanat in tombi-toml/tombi#2150
* fix(lexer): reject newline following escaped quote or backslash in basic string by @​lxl66566 in tombi-toml/tombi#2149

### 🛠️ Other Changes
* fix: tombi lint by @​ya7010 in tombi-toml/tombi#2147
* perf: enable gzip compression for reqwest by @​lxl66566 in tombi-toml/tombi#2148

## New Contributors
* @​lxl66566 made their first contribution in tombi-toml/tombi#2148

**Full Changelog**: tombi-toml/tombi@v1.5.0...v1.5.1

### v1.5.2

<!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @​lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @​xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @​xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @​xtqqczze in tombi-toml/tombi#2156

**Full Changelog**: tombi-toml/tombi@v1.5.1...v1.5.2

### v1.5.3

<!-- Release notes generated using configuration in .github/release.yml at v1.5.3 -->

## What's Changed
### 🐝 Bug Fixes
* test(parser): preserve key after escaped multiline string by @​ya7010 in tombi-toml/tombi#2168
* fix(lsp): respect ignore files in watcher updates by @​ya7010 in tombi-toml/tombi#2169
### 🛠️ Other Changes
* ci: submit WinGet updates from organization fork by @​ya7010 in tombi-toml/tombi#2163
* fix(lexer): close multi-line string after escaped backslash by @​MaxFreedomPollard in tombi-toml/tombi#2167

## New Contributors
* @​MaxFreedomPollard made their first contribution in tombi-toml/tombi#2167

**Full Changelog**: tombi-toml/tombi@v1.5.2...v1.5.3

### v1.5.4

<!-- Release notes generated using configuration in .github/release.yml at v1.5.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): stop triggering completions on newline by @​ya7010 in tombi-toml/tombi#2172

**Full Changelog**: tombi-toml/tombi@v1.5.3...v1.5.4

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
tombi 1.5.2

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre><!-- Release notes generated using configuration in .github/release.yml at v1.5.2 -->

## What's Changed
### 🐝 Bug Fixes
* fix(json-lexer): accept standalone CR as whitespace by @lxl66566 in tombi-toml/tombi#2162
### 📦 Dependencies
* fix: update vulnerable npm dependencies by @xtqqczze in tombi-toml/tombi#2157
* chore(deps): update Cargo.lock by @xtqqczze in tombi-toml/tombi#2161
### 🛠️ Other Changes
* fix(deps): disable default features for zip package by @xtqqczze in tombi-toml/tombi#2156


**Full Changelog**: https://github.com/tombi-toml/tombi/compare/v1.5.1...v1.5.2</pre>
  <p>View the full release notes at <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.5.2">https://github.com/tombi-toml/tombi/releases/tag/v1.5.2</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!18533
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants