Skip to content

fix(deps): bump brace-expansion, dompurify and fast-uri overrides - #2258

Merged
ya7010 merged 2 commits into
mainfrom
ya7010/fix-failing-action-36844731639
Oct 1, 2026
Merged

ya7010 merged 2 commits into
mainfrom
ya7010/fix-failing-action-36844731639

Conversation

@ya7010

@ya7010 ya7010 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

The scheduled OSV-Scanner run failed (run) due to vulnerable npm packages pinned via overrides in pnpm-workspace.yaml.

Package Before After Advisories
brace-expansion 5.0.9 5.0.12 GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr
dompurify 3.4.13 3.4.16 GHSA-p98j-92pf-mc4p
fast-uri 3.1.7 3.1.8 GHSA-hrr3-gc8f-f4qj

All new versions satisfy minimumReleaseAge, and pnpm-lock.yaml was regenerated with pnpm install --lockfile-only.

🤖 Generated with Claude Code

Fixes OSV-Scanner findings:
- brace-expansion 5.0.9 -> 5.0.12 (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr)
- dompurify 3.4.13 -> 3.4.16 (GHSA-p98j-92pf-mc4p)
- fast-uri 3.1.7 -> 3.1.8 (GHSA-hrr3-gc8f-f4qj)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 09:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

override、lockfile、Node.js要件に不整合は見つかりませんでした。

Review effort: Balanced
Findings: None

What changed in this PR

脆弱な npm 依存関係の override を安全なバージョンへ更新する変更です。

Changes:

  • 3 パッケージの override を更新
  • lockfile の解決情報と参照を同期
File Description
pnpm-workspace.yaml 安全な依存バージョンを指定
pnpm-lock.yaml 更新後の解決結果と整合性情報を反映
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ya7010
ya7010 enabled auto-merge (squash) October 1, 2026 10:06
@ya7010
ya7010 merged commit c79548e into main Oct 1, 2026
29 checks passed
@ya7010
ya7010 deleted the ya7010/fix-failing-action-36844731639 branch October 1, 2026 10:24
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube
editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl
shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with
some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files
([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer`
([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter`
([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer`
([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace`
([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion`
([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration
([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks
([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS
([#2726](j178/prek#2726))
- Combine and cache Git repository path queries
([#2724](j178/prek#2724))
- Optimize common builtin hook execution
([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace`
([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks
([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and
`check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows
([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts
([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a
space
([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions
([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in
semantic-line-breaks mode
([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one
space
([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool
changes
([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure
([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and
honor on-error in check
([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at
deploy time
([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings
([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification
([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity
([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse
([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6…
(truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically
equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel
scripts with CRLF shebangs
([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the
`lockfile-normalization` preview feature
([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from
`pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the
output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks`
requirements resolve to the same package
([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with
distinct base and extra requirement specifiers
([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv
tree --format json` output
([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries
([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating
severe cache-revalidation stalls on ext4 filesystems
([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under
`--require-hashes` and `--verify-hashes`
([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under
`--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including
`--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9
([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only
manifest subtables
([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those
involving pre-releases, with the `resolution-inputs` preview feature
([#22004](astral-sh/uv#22004),
[#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions`
file without `--global`
([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as
incompatible with exclusive lower bounds on pre-releases
([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256)
|
|
[uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz)
| Intel macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256)
|
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8
([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags
([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles
([#22010](astral-sh/uv#22010),
[#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in
lockfiles ([#22044](astral-sh/uv#22044),
[#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles
([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace
roots in lockfiles
([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages
([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help
([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit`
([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline
and hide the unsupported option from help
([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture
independently of its Python version
([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download
metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when
relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace
roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3
([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync
--frozen` with `frozen-lockfile`
([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export
--frozen` with `frozen-lockfile`
([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest
using `uv tree --frozen` with `frozen-lockfile`
([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from
`uv.lock` without a workspace manifest using `uv workspace metadata
--frozen` with `frozen-lockfile`
([#22017](astral-sh/uv#22017),
[#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting
dependency selections, avoiding lockfiles that cannot be installed
([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows
ARM64 to install compatible `win_amd64` wheels instead of building from
source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.6` → `1.7.1` | `1.5.6` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files ([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer` ([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter` ([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer` ([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace` ([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion` ([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration ([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks ([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS ([#2726](j178/prek#2726))
- Combine and cache Git repository path queries ([#2724](j178/prek#2724))
- Optimize common builtin hook execution ([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace` ([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks ([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and `check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows ([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts ([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a space ([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions ([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in semantic-line-breaks mode ([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one space ([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool changes ([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure ([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and honor on-error in check ([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at deploy time ([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings ([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification ([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity ([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse ([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6… (truncated)

</details>
<details>
<summary>tombi: `1.5.6` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in tombi-toml/tombi#2225

**Full Changelog**: tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by @​ya7010 in tombi-toml/tombi#2226

**Full Changelog**: tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm workspace injection by @​ya7010 in tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by @​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by @​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by @​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by @​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010 in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by @​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by @​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by @​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now available on [pypi](https://tombi-toml.github.io/tombi/docs/library/python) / [npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing `format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by @​ya7010 in tombi-toml/tombi#2247

**Full Changelog**: tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by combinator branches by @​ya7010 in tombi-toml/tombi#2249

**Full Changelog**: tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the CLI, along with output formats such as `github` and `gitlab`.

Please refer to the [documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output) for details.

### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010 in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with LineIndex at the output boundary by @​ya7010 in tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by @​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on nested arrays by @​ya7010 in tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by @​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at the output boundary by @​ya7010 in tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text inline by @​ya7010 in tombi-toml/tombi#2264

**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by @​ya7010 in tombi-toml/tombi#2266

**Full Changelog**: tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs ([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the `lockfile-normalization` preview feature ([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from `pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks` requirements resolve to the same package ([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with distinct base and extra requirement specifiers ([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv tree --format json` output ([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries ([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems ([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under `--require-hashes` and `--verify-hashes` ([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under `--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including `--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9 ([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only manifest subtables ([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those involving pre-releases, with the `resolution-inputs` preview feature ([#22004](astral-sh/uv#22004), [#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions` file without `--global` ([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases ([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 ([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags ([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles ([#22010](astral-sh/uv#22010), [#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in lockfiles ([#22044](astral-sh/uv#22044), [#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles ([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace roots in lockfiles ([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages ([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help ([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit` ([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline and hide the unsupported option from help ([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture independently of its Python version ([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3 ([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync --frozen` with `frozen-lockfile` ([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export --frozen` with `frozen-lockfile` ([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest using `uv tree --frozen` with `frozen-lockfile` ([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from `uv.lock` without a workspace manifest using `uv workspace metadata --frozen` with `frozen-lockfile` ([#22017](astral-sh/uv#22017), [#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed ([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible `win_amd64` wheels instead of building from source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint
editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek
rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.6` → `1.7.1` | `1.5.6` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with
some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files
([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer`
([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter`
([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer`
([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace`
([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion`
([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration
([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks
([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS
([#2726](j178/prek#2726))
- Combine and cache Git repository path queries
([#2724](j178/prek#2724))
- Optimize common builtin hook execution
([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace`
([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks
([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and
`check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows
([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts
([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a
space
([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions
([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in
semantic-line-breaks mode
([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one
space
([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool
changes
([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure
([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and
honor on-error in check
([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at
deploy time
([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings
([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification
([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity
([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse
([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6…
(truncated)

</details>
<details>
<summary>tombi: `1.5.6` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically
equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel
scripts with CRLF shebangs
([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the
`lockfile-normalization` preview feature
([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from
`pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the
output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks`
requirements resolve to the same package
([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with
distinct base and extra requirement specifiers
([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv
tree --format json` output
([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries
([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating
severe cache-revalidation stalls on ext4 filesystems
([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under
`--require-hashes` and `--verify-hashes`
([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under
`--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including
`--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9
([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only
manifest subtables
([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those
involving pre-releases, with the `resolution-inputs` preview feature
([#22004](astral-sh/uv#22004),
[#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions`
file without `--global`
([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as
incompatible with exclusive lower bounds on pre-releases
([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256)
|
|
[uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz)
| Intel macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256)
|
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8
([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags
([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles
([#22010](astral-sh/uv#22010),
[#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in
lockfiles ([#22044](astral-sh/uv#22044),
[#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles
([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace
roots in lockfiles
([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages
([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help
([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit`
([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline
and hide the unsupported option from help
([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture
independently of its Python version
([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download
metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when
relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace
roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3
([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync
--frozen` with `frozen-lockfile`
([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export
--frozen` with `frozen-lockfile`
([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest
using `uv tree --frozen` with `frozen-lockfile`
([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from
`uv.lock` without a workspace manifest using `uv workspace metadata
--frozen` with `frozen-lockfile`
([#22017](astral-sh/uv#22017),
[#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting
dependency selections, avoiding lockfiles that cannot be installed
([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows
ARM64 to install compatible `win_amd64` wheels instead of building from
source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files ([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer` ([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter` ([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer` ([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace` ([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion` ([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration ([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks ([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS ([#2726](j178/prek#2726))
- Combine and cache Git repository path queries ([#2724](j178/prek#2724))
- Optimize common builtin hook execution ([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace` ([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks ([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and `check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows ([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts ([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a space ([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions ([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in semantic-line-breaks mode ([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one space ([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool changes ([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure ([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and honor on-error in check ([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at deploy time ([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings ([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification ([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity ([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse ([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6… (truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010 in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the primary SchemaView by @​ya7010 in tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in package.json and pnpm-lock.yaml; add new tumbi-lib module with initial implementation by @​ya7010 in tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010 in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in tombi-toml/tombi#2225

**Full Changelog**: tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by @​ya7010 in tombi-toml/tombi#2226

**Full Changelog**: tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm workspace injection by @​ya7010 in tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by @​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by @​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by @​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by @​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010 in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by @​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by @​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by @​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now available on [pypi](https://tombi-toml.github.io/tombi/docs/library/python) / [npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing `format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by @​ya7010 in tombi-toml/tombi#2247

**Full Changelog**: tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by combinator branches by @​ya7010 in tombi-toml/tombi#2249

**Full Changelog**: tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the CLI, along with output formats such as `github` and `gitlab`.

Please refer to the [documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output) for details.

### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010 in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with LineIndex at the output boundary by @​ya7010 in tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by @​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on nested arrays by @​ya7010 in tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by @​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at the output boundary by @​ya7010 in tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text inline by @​ya7010 in tombi-toml/tombi#2264

**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by @​ya7010 in tombi-toml/tombi#2266

**Full Changelog**: tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs ([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the `lockfile-normalization` preview feature ([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from `pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks` requirements resolve to the same package ([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with distinct base and extra requirement specifiers ([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv tree --format json` output ([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries ([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems ([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under `--require-hashes` and `--verify-hashes` ([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under `--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including `--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9 ([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only manifest subtables ([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those involving pre-releases, with the `resolution-inputs` preview feature ([#22004](astral-sh/uv#22004), [#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions` file without `--global` ([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases ([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 ([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags ([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles ([#22010](astral-sh/uv#22010), [#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in lockfiles ([#22044](astral-sh/uv#22044), [#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles ([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace roots in lockfiles ([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages ([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help ([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit` ([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline and hide the unsupported option from help ([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture independently of its Python version ([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3 ([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync --frozen` with `frozen-lockfile` ([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export --frozen` with `frozen-lockfile` ([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest using `uv tree --frozen` with `frozen-lockfile` ([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from `uv.lock` without a workspace manifest using `uv workspace metadata --frozen` with `frozen-lockfile` ([#22017](astral-sh/uv#22017), [#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed ([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible `win_amd64` wheels instead of building from source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint
editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek
rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with
some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files
([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer`
([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter`
([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer`
([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace`
([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion`
([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration
([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks
([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS
([#2726](j178/prek#2726))
- Combine and cache Git repository path queries
([#2724](j178/prek#2724))
- Optimize common builtin hook execution
([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace`
([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks
([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and
`check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows
([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts
([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a
space
([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions
([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in
semantic-line-breaks mode
([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one
space
([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool
changes
([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure
([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and
honor on-error in check
([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at
deploy time
([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings
([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification
([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity
([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse
([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6…
(truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically
equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel
scripts with CRLF shebangs
([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the
`lockfile-normalization` preview feature
([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from
`pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the
output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks`
requirements resolve to the same package
([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with
distinct base and extra requirement specifiers
([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv
tree --format json` output
([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries
([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating
severe cache-revalidation stalls on ext4 filesystems
([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under
`--require-hashes` and `--verify-hashes`
([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under
`--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including
`--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9
([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only
manifest subtables
([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those
involving pre-releases, with the `resolution-inputs` preview feature
([#22004](astral-sh/uv#22004),
[#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions`
file without `--global`
([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as
incompatible with exclusive lower bounds on pre-releases
([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256)
|
|
[uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz)
| Intel macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256)
|
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8
([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags
([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles
([#22010](astral-sh/uv#22010),
[#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in
lockfiles ([#22044](astral-sh/uv#22044),
[#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles
([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace
roots in lockfiles
([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages
([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help
([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit`
([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline
and hide the unsupported option from help
([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture
independently of its Python version
([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download
metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when
relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace
roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3
([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync
--frozen` with `frozen-lockfile`
([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export
--frozen` with `frozen-lockfile`
([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest
using `uv tree --frozen` with `frozen-lockfile`
([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from
`uv.lock` without a workspace manifest using `uv workspace metadata
--frozen` with `frozen-lockfile`
([#22017](astral-sh/uv#22017),
[#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting
dependency selections, avoiding lockfiles that cannot be installed
([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows
ARM64 to install compatible `win_amd64` wheels instead of building from
source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants