Skip to content

build(deps): bump jdx/mise-action from 5.0.1 to 5.1.1 - #237

Merged
gabizou merged 1 commit into
mainfrom
dependabot/github_actions/jdx/mise-action-5.1.1
Oct 7, 2026
Merged

gabizou merged 1 commit into
mainfrom
dependabot/github_actions/jdx/mise-action-5.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps jdx/mise-action from 5.0.1 to 5.1.1.

Release notes

Sourced from jdx/mise-action's releases.

v5.1.1: GitHub token is no longer exported to later steps by default

mise-action no longer exports its GitHub token as MISE_GITHUB_TOKEN to every later step in the job. A new persist_github_token input lets you turn that back on, or pass a different token to later steps. This changes the default behavior. If later steps need the token, see Breaking Changes below.

Fixed

  • The GitHub token now stays inside the action by default. Before this release, the github_token input (which defaults to ${{ github.token }}) was written to GITHUB_ENV as MISE_GITHUB_TOKEN. That let any later step read the token and call the GitHub API with the job's permissions, even if the step never asked for a credential. Now the token is set only for the mise-action step and the processes it starts. The action masks the token in logs. (#658 by @​jdx, reported in #657)

Added

  • persist_github_token input (default false). It takes one of three values:

    • false: the token stays inside the action.
    • true: the token the action used is exported to later steps. If env.MISE_GITHUB_TOKEN is already set, it takes precedence over github_token.
    • A token value: that token is exported to later steps instead, for example a read-only token. The action still installs tools with github_token, or with MISE_GITHUB_TOKEN if it's already set.

    Setting false doesn't clear a MISE_GITHUB_TOKEN that was already set at the job level or exported by an earlier step. (#658 by @​jdx)

Breaking Changes

Check your workflow if a later step needs MISE_GITHUB_TOKEN, such as mise shims, mise exec, mise run or lazy tool installs that call the GitHub API. Those steps no longer get the token automatically and may hit GitHub API rate limits. To get the old behavior back, opt in:

- uses: jdx/mise-action@v5
  with:
    persist_github_token: true

Or give later steps a separate token:

- uses: jdx/mise-action@v5
  with:
    persist_github_token: ${{ secrets.READ_ONLY_TOKEN }}

Full Changelog: jdx/mise-action@v5.1.0...v5.1.1

v5.1.0: Tool version outputs, plugins input, and cached mise reuse

mise-action now reports the tool versions it installed as step outputs, can install mise plugins before tools, and can save the cache at the end of the job. Several caching fixes stop the action from downloading mise again on every run.

Added

  • Tool versions as step outputs. After install, the action runs mise ls --json --current and sets a versions output. This is a JSON object of the active, installed tools. Each tool maps to a list of {version, requested_version, install_path, source} entries. Each tool also gets its own output with its resolved version, such as steps.mise.outputs.node. A tool only gets its own output if its name is a valid output name and isn't cache-hit or versions. Names like npm:@scope/pkg appear only in versions. If the action can't read the versions, it prints a warning and the step still succeeds. (#655 by @​jdx)
    - uses: jdx/mise-action@v5
      id: mise
    - run: echo "node ${{ steps.mise.outputs.node }}"
  • plugins input. List plugins one per line as name or name url. Blank lines and # comments are ignored. The action runs mise plugins install -y for each one before mise install. Plugins that are already installed, for example restored from the cache, are left as they are. An unknown plugin fails the step. When plugins is set, its hash is added to the default cache key. Custom cache_key templates can use it as {{plugins_hash}}. If plugins is unset, existing cache keys don't change. (#656 by @​jdx)
    - uses: jdx/mise-action@v5

... (truncated)

Changelog

Sourced from jdx/mise-action's changelog.

Changelog


5.1.1 - 2026-10-04

🐛 Bug Fixes


5.1.0 - 2026-10-04

🚀 Features

🐛 Bug Fixes

  • (cache) keep a cached mise instead of re-downloading when version is unset (#642) by @​jdx in #642
  • save cache after inexact cache restore (#646) by @​jdx in #646
  • extract mise zip with PowerShell instead of unzip on Windows (#650) by @​jdx in #650
  • cache mise binary for caches saved without a version record (#648) by @​jdx in #648

📚 Documentation

  • explain the Rust cache caveat and workarounds (#651) by @​jdx in #651
  • add matrix and external cache guides; warn on shadowed mise_toml (#654) by @​jdx in #654

⚙️ Miscellaneous Tasks


5.0.1 - 2026-09-30

🐛 Bug Fixes


5.0.0 - 2026-09-28

🚀 Features

... (truncated)

Commits
  • 2d8d4ca chore: release v5.1.1 (#659)
  • 3eb43e3 fix: make GitHub token persistence opt-in (#658)
  • 94c60b3 chore: release v5.1.0 (#640)
  • 4fff0c6 feat: add plugins input (#656)
  • 893fc72 docs: add matrix and external cache guides; warn on shadowed mise_toml (#654)
  • 41f5868 feat: add opt-in cache_save_post input (#649)
  • 2fe229b fix: cache mise binary for caches saved without a version record (#648)
  • abd75d9 fix: extract mise zip with PowerShell instead of unzip on Windows (#650)
  • 4b9c295 docs: explain the Rust cache caveat and workarounds (#651)
  • 7927c6f feat: output active tool versions (#655)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jdx/mise-action](https://github.com/jdx/mise-action) from 5.0.1 to 5.1.1.
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](jdx/mise-action@7a4e45a...2d8d4ca)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 5.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 7, 2026
@gabizou
gabizou merged commit 4b9d2b0 into main Oct 7, 2026
7 checks passed
@gabizou
gabizou deleted the dependabot/github_actions/jdx/mise-action-5.1.1 branch October 7, 2026 16:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant