Skip to content

chore(deps): update jdx/mise-action action to v5.0.1 - #318

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jdx-mise-action-5.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/jdx-mise-action-5.x

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
jdx/mise-action action patch v5.0.0 → v5.0.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

jdx/mise-action (jdx/mise-action)

v5.0.1: : Verify cached mise binaries before running them

Compare Source

mise-action now checks the integrity of an already-installed mise binary before running it. This fixes a security issue that was reported privately.

Fixed
  • An existing mise binary is verified before it is run. When a mise binary is already on the runner (for example, restored from cache or in mise_dir), the action now checks it before calling it. If you set a sha256 input, the binary must match that checksum and report the requested version. Otherwise, it must match the signed release checksums for the version being installed. If the check fails, the action prints a warning, deletes the binary and installs the requested release again. Before this fix, the action could run a cached binary before checking it. (#​637 by @​jdx)
Changed

Changes to how the action handles an existing binary, also from #​637:

  • Switching versions uses a full install. If the cached binary doesn't match the requested version, the action downloads and installs that version. It no longer runs mise self-update.
  • Unpinned runs always pick a release. Without a version input, the action now selects a release every time, using minimum_release_age, even when mise is already installed. It then checks the existing binary against that release, and reinstalls if the binary doesn't match.
  • Older releases need a sha256 input to reuse a cached binary. Some older mise releases have no signed checksums. With the sha256 input set, a cached binary of one of these releases can still be reused without a download. Without it, the action can't verify the binary and installs it again.

Full Changelog: jdx/mise-action@v5.0.0...v5.0.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants