Skip to content

chore(mise): upgrade local tools - #28

Closed
ghappforreleaseplease[bot] wants to merge 1 commit into
mainfrom
chore/mise-tool-updates-20260810064201
Closed

chore(mise): upgrade local tools#28
ghappforreleaseplease[bot] wants to merge 1 commit into
mainfrom
chore/mise-tool-updates-20260810064201

Conversation

@ghappforreleaseplease

Copy link
Copy Markdown
Contributor

Automated mise tool upgrades from local config.

Updated tools:

  • action-validator
  • actionlint
  • aube
  • editorconfig-checker
  • ghalint
  • node
  • pinact
  • pipx:gh-action-pulse
  • prek
  • rumdl
  • shellcheck
  • shfmt
  • tombi
  • uv
  • yamlfmt
  • yamllint
  • zizmor

Command: mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor

Version changelog (6 tools)
Tool Requested Installed
editorconfig-checker 3.8.03.11.1 3.8.03.11.1
node 2426 24.19.026.7.0
prek 0.4.110.4.12 0.4.110.4.12
rumdl 0.2.490.2.52 0.2.490.2.52
tombi 1.2.61.2.7 1.2.61.2.7
uv 0.12.10.12.3 0.12.10.12.3
Release notes (6 tools)
editorconfig-checker: `3.8.0` → `3.11.1` (editorconfig-checker/editorconfig-checker)

v3.9.0

3.9.0 (2026-07-31)

Features

  • enable immutable releases (6865c06)

v3.10.0

editorconfig-checker v3.10.0 (2026-08-07T23:27:59Z)

Welcome to this new release of editorconfig-checker!

Changelog

Others

  • 77a3415d6127cc892376837b85fd2a4b5c98d40d: Revert "feat(immutable-releases): set release-please to create draft releases" (@​klaernie)
  • a85cd6ab82397f19bdd9bfa30730a487ead1ec74: chore(deps): bump docker/login-action from 4.5.2 to 4.6.0 (#590) (@​dependabot[bot])
  • 74cd03a2e91c1c42deff2bec2d120c06ff1be3e8: chore(main): release 3.10.0 (#588) (@​editorconfig-checker-bot)
  • 8d4f96e7a838bfb0d8b98a40e66ce8cbd8c1e075: chore: allow triggering release-please manually (@​klaernie)
  • a685b542509d0349ce6215adf6088a242fa93d84: feat(immutable-release): tell release-please to create draft releases (@​klaernie)
  • 912f4a986b7da0b22cfa3a055cc24a355dee7cbc: feat(immutable-releases): ensure that despite the release being a draft the tag is created (@​klaernie)
  • 2d48c2ecae1743614cefa660c2796e14cefd7520: feat(immutable-releases): set release-please to create draft releases (@​klaernie)

Thanks!

Those were the changes on v3.10.0!

v3.11.0

editorconfig-checker v3.11.0 (2026-08-08T10:40:38Z)

Welcome to this new release of editorconfig-checker!

Changelog

Others

  • 174c5809baf06f2d8e82c1d2de1f6433cc569a1d: chore(main): release 3.11.0 (#592) (@​editorconfig-checker-bot)
  • e9f143bc9d6cc5bb29030843ec42eae2a94b4dda: chore: replace deprecated goreleaser option with its current form (@​klaernie)
  • 4c08f2ccd339734ff92f2f04d146cd91af02d225: feat(immutable-release): goreleaser should publish its release (@​klaernie)

Thanks!

Those were the changes on v3.11.0!

v3.11.1

3.11.1 (2026-08-08)

Features

  • immutable-release: tell goreleaser to use the existing draft release (a8e6136)
node: `24.19.0` → `26.7.0` (nodejs/node)

v26.0.0

We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals
as we continue to modernize the platform.

As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months.
We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications.

Notable Changes

Temporal API

The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript
that provides a more robust and feature-rich alternative to the legacy Date object.

Contributed by Richard Lau in #61806.

V8 14.6

The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134.

This version also includes:

Contributed by Michaël Zasso in #61898.

Undici 8

Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation.

Deprecations and Removals

  • [dff46c07c3] - (SEMVER-MAJOR) crypto: move DEP0182 to End-of-Life (Tobias Nießen) #61084
  • [93c25815ee] - (SEMVER-MAJOR) http: move writeHeader to end-of-life (Sebastian Beltran) #60635

http.Server.prototype.writeHeader() is now fully removed. Use `http.Server.prototype.write… (truncated)

v26.1.0

Notable Changes

Experimental node:ffi module

Node.js now includes an experimental node:ffi module for loading dynamic
libraries and calling native symbols from JavaScript.

The API is gated behind the --experimental-ffi flag and, when the Permission
Model is enabled, requires --allow-ffi.

This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory
after it has been freed can crash the process or corrupt memory.

Contributed by Paolo Insogna in #62072.

Other Notable Changes

v26.2.0

Notable Changes

  • [189d43a193] - doc: mark stream.compose stable (Matteo Collina) #62562
  • [f858c6140e] - (SEMVER-MINOR) fs: add Temporal.Instant support to Stats and BigIntStats (Livia Medeiros) #60789
  • [0cbb3895df] - (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155

Commits

  • [9a394bab84] - benchmark: respect stream/iter broadcast backpressure (Trivikram Kamat) #63314
  • [ad98b4620b] - crypto: align verifyOneShot accepted types (Anshika Jain) #63280
  • [ba0736a847] - crypto: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) #63255
  • [5573a6a4a8] - crypto: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) #63255
  • [7dc563b8d6] - crypto: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) #63255
  • [b55e2b1f4d] - crypto: improve system certificate enumeration logic on macOS (Robo) #62576
  • [fd509a755a] - crypto: harden CryptoKey algorithm slots… (truncated)

v26.3.0

Notable Changes

Potential changes to macOS Universal Binary availability

With Apple and its ecosystem progressively dropping support for Intel-based
architectures, it has become apparent that the Node.js project may not be able
to maintain the universal binaries we currently distribute for the full lifetime
of Node.js 26. This change serves to communicate that risk. At present, our
intention remains to continue shipping universal binaries supporting both Apple
Silicon and Intel-based Macs for as long as practical.

Contributed by Antoine du Hamel in #63055.

Other notable changes

  • [a2a4b33dd8] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597
  • [051a2152f7] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
  • [49462eca37] - (SEMVER-MINOR) http: add httpValidation option to configure header value validation (RajeshKumar11) #61597
  • [97b7ab19bd] - (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #63079
  • [cfb80a2103] - (SEMVER-MINOR) lib,permission: add permission.drop (Rafael Gonzaga) #62672

Commits

v26.3.1

This is a security release.

Notable Changes

  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
  • (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low

Commits

v26.4.0

Notable Changes

  • [cde0daabcc] - (SEMVER-MINOR) doc: update blockList stability status to release candidate (alphaleadership) #63050
  • [b78f5a7537] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #63634
  • [417aacbc36] - (SEMVER-MINOR) http: close pre-request sockets in closeIdleConnections (semimikoh) #63470
  • [fbb108be7d] - (SEMVER-MINOR) loader: implement package maps (Maël Nison) #62239
  • [45494d5a8a] - (SEMVER-MINOR) net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) #63825
  • [ee29465e77] - (SEMVER-MINOR) tls: add certificateCompression option (Tim Perry) #62217
  • [b17817eb2b] - (SEMVER-MINOR) vfs: dispatch node:fs/promises to mounted VFS instances (Matteo Collina) #63537
  • [7bc93a6ac5] - (SEMVER-MINOR) vfs: add minimal node:vfs subsystem (Matteo Collina) #63115

Commits

v26.5.0

Notable Changes

New release key

Welcome to our newest releaser, Stewart X Addison. Future Node.js releases may be signed with his release key, 655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD.

Other notable changes

  • [55f48446c7] - (SEMVER-MINOR) buffer: implement blob.textStream() (Matthew Aitken) #64036
  • [b373202efc] - (SEMVER-MINOR) esm: add --experimental-import-text flag (Efe) #62300
  • [39e0c14455] - (SEMVER-MINOR) perf_hooks: sample delay per event loop iteration (Pablo Erhard) #62935
  • [999a83c937] - (SEMVER-MINOR) stream: expose ReadableStreamTee (Matteo Collina) #64195
  • [4e0236dc3d] - (SEMVER-MINOR) tls: report negotiated TLS groups (Filip Skokan) #64119

Commits

v26.5.1

This is a security release.

Notable Changes

  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 8.9.0 (Node.js GitHub Bot)

Commits

v26.6.0

Notable Changes

  • [5a36018abc] - doc: add MikeMcC399 as collaborator (Mike McCready) #64656
  • [9b04f82d7b] - (SEMVER-MINOR) ffi: add getCurrentEventLoop (Paolo Insogna) #64323
  • [bb51f2c960] - (SEMVER-MINOR) test_runner: add context.log() and test:log event (Moshe Atlow) #64389
  • [56ce83b3ee] - (SEMVER-MINOR) test_runner: report entryFile in TestStream events (Moshe Atlow) #64309

Commits

  • [248ff9fa5c] - assert,util: fix TypeError on Maps with null keys (Paul Bouchon) #64441
  • [3b5baceafe] - benchmark: add bytes variant to webstreams async-iterator (Matteo Collina) #64291
  • [0a46d1ef66] - buffer: normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115
  • [d9ada18b70] - buffer: fix Blob.stream() leaking source buffer (semimikoh) #63577
  • [d05993bcf6] - build: merge multiple on download artifact (Chengzhong Wu) #64633
  • [6c25ac909a] - build: extract temporal_capi crate directory name into gyp variable (René) [#64482](https://githu… (truncated)

v26.7.0

Notable Changes

  • [58717685a1] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #63949
  • [44b940ee8c] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
  • [c1e4f7365e] - (SEMVER-MINOR) lib: add perfetto support (Chengzhong Wu) #64565
  • [11c2f9c642] - (SEMVER-MINOR) module: implement Symbol.dispose in ModuleHooks (Remco Haszing) #63928
  • [a646319f61] - (SEMVER-MINOR) test_runner: add support for --test-coverage-include-all (avivkeller) #64830

Commits

  • [a2d3f891d3] - async_hooks: use validateBoolean for trackPromises (Soul Lee) #64731
  • [d7266cdd99] - benchmark: fix calibrate-n option handling (Luan Muniz) #64146
  • [2e64293e3f] - buffer: use Clamp conversion in Blob slice (Donghoon Kang) #64739
  • [5fda0958bd] - buffer: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #63904
  • [5298db40f9] - build: run perfetto build and test on GHA (Chengzhong Wu) [#6472… (truncated)

Omitted 14 older releases.

prek: `0.4.11` → `0.4.12` (j178/prek)

v0.4.12

Release Notes

Released on 2026-08-03.

Enhancements

  • Add --require-group for hook group intersections (#2472)
  • Align fast-path and builtin pre-commit hooks (#2433)
  • Do not shuffle file list for verbose output (#2431)
  • Improve top-level command descriptions (#2429)
  • Install uv from Astral CDN and drop source racing (#2455)
  • Make prek install --force bypass external hooks paths (#2437)
  • Show builtin hook flags in verbose list output (#2427)
  • Verify uv release archive checksums (#2456)

Performance

  • Precompute file tags in parallel (#2440)
  • Skip diffs after known hook modifications (#2447)
  • Skip worktree diffs for read-only languages (#2432)
  • Track builtin hook file changes directly (#2404)

Bug fixes

  • Use full object IDs in diff snapshots (#2448)

Documentation

  • Add a multi-repository configuration example (#2434)
  • Rewrite benchmark documentation (#2469)

Contributors

  • @​j178
  • @​BitWeaverDev
  • @​allanlewis

Install prek 0.4.12

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.ps1 | iex"
```… (truncated)

</details>
<details>
<summary>rumdl: `0.2.49``0.2.52` (rvben/rumdl)</summary>

### v0.2.50

### Added

- **md077**: support fixed continuation indent config (#786) ([fea6322](https://github.com/rvben/rumdl/commit/fea63227ae14db43956303a2bbae97ac41d7f68c))

### Fixed

- **md065**: leave markers alone inside a block that hides its content ([2654364](https://github.com/rvben/rumdl/commit/26543648458feb2111e46ec6e6cbb301917636d5))
- **md065**: report thematic breaks written with spaces between markers ([1d29236](https://github.com/rvben/rumdl/commit/1d292366b43bf2dbcc20d1f22ceb0e6fb73652ab))
- **md076**: ask the parser whether a list item's block is really fenced ([fd616c2](https://github.com/rvben/rumdl/commit/fd616c2c31009eb8b39d29836b2ef7b51242e8a6))
- **md022**: require a blank line below a heading above a spaced thematic break ([27120f2](https://github.com/rvben/rumdl/commit/27120f25a9b620fcc0f827ed77b97f2f6b57f4f4))
- **MD076**: preserve fenced list item spacing (#788) ([2d60067](https://github.com/rvben/rumdl/commit/2d60067a2ff5e38875919c7c57190b77f8d7eb9f))
- **md022**: use the same list test below a heading in check and fix (#790) ([ef926b7](https://github.com/rvben/rumdl/commit/ef926b78500015769c23423ebbcf9e332de87385))
- **md040**: locate the fence a list marker holds instead of assuming the indent ([6099a6c](https://github.com/rvben/rumdl/commit/6099a6c11d687480bdaf82f01d8f9695d5998570))
- **md077**: keep the strict-flavor minimum as a floor under a configured indent ([cfaad2e](https://github.com/rvben/rumdl/commit/cfaad2e072c5a69a9e28b9678b126c7f3642b9d4))
- **md077**: reject a configured indent of 0 ([1ac97a3](https://github.com/rvben/rumdl/commit/1ac97a338a109ddc91eee3db557c5798402f8a72))
- **md077**: accept the indent option instead of reporting it as unknown ([cba175c](https://github.com/rvben/rumdl/commit/cba175c0bb148b9a9f5b5dc4082aa00f46da815c))
- **md013**: stop exempting a complete link followed by a parenthesized aside ([722fad6](https://github.com/rvben/rumdl/commit/722fad6984692318160f7ddce71b55701c20d280))
- **md013**: ke… (truncated)

### v0.2.51

### Added

- **md088**: normalize quotes and dashes to ASCII (#763) ([52e9844](https://github.com/rvben/rumdl/commit/52e9844aa1bd7bb96e4a59e12719cc6332218616))

### Fixed

- **config**: keep a file's per-file-ignores out of the workspace index it feeds ([2bb0ce7](https://github.com/rvben/rumdl/commit/2bb0ce7cf02be7780f0b055fa8f8d1c75160ef5c))
- **md051**: validate cross-file link fragments for a document read from stdin ([e215c65](https://github.com/rvben/rumdl/commit/e215c65716059dde61abe64bf5485e3e74f7065b))
- **md051**: report a broken fragment on a query-string destination once ([7c8390f](https://github.com/rvben/rumdl/commit/7c8390f9bdb3ce8bd5ef4954f7836cbd4ab74528))
- **md088**: leave modifier letters and math notation alone ([56dbf0f](https://github.com/rvben/rumdl/commit/56dbf0fefe7d5847c2d64d66e7a168f7f812cd2d))
- **config**: report the effective rule lists from `config get global.*` ([5db8f0c](https://github.com/rvben/rumdl/commit/5db8f0cb4be1fb849640e9d8740bb33a7e9ddcc7))
- **config**: answer `config get` for every key rumdl accepts ([ecce820](https://github.com/rvben/rumdl/commit/ecce8202121ea2964a4cff5423e1f0564e33b516))
- **md035**: publish the horizontal rule style the rule enforces ([77c8c65](https://github.com/rvben/rumdl/commit/77c8c659b93cf28467308ef130a759e59e9a6a6e))
- **config**: accept every config key a rule actually reads ([8ec7bba](https://github.com/rvben/rumdl/commit/8ec7bbabd9bc4f317753be92eb70eba5fad286bf))
- **lsp**: identify documents by the same resolved path as the index ([78f4aa0](https://github.com/rvben/rumdl/commit/78f4aa0cce24508d10dd0048b17ddb72c549249d))
- **lsp**: keep frontmatter values out of find-references results ([499b005](https://github.com/rvben/rumdl/commit/499b00523f646173f01dd2883cce3f9ff48f1324))
- **md051**: index cross-file links independently of frontmatter config ([ca7b93e](https://github.com/rvben/rumdl/commit/ca7b93ecd679398440d6c879a5ca692ee880616e))
- **lsp**: build the workspace index from t… (truncated)

### v0.2.52

### Fixed

- **md012**: report blank lines before a code block that ends the document (#791) ([e897556](https://github.com/rvben/rumdl/commit/e897556460ba0209ad9e768ae64ec5579e1715bc))
- **rules**: treat a template shortcode tag as opaque markup ([6962184](https://github.com/rvben/rumdl/commit/696218496edc7c1aa9403a970311fb19085930f9))
- **cli**: report a piped document's findings on stdout like every other run ([47f8a50](https://github.com/rvben/rumdl/commit/47f8a50d7cf8cf98754a13cfe2adb12868d05a89))


## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.52-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/r… (truncated)

</details>
<details>
<summary>tombi: `1.2.6` → `1.2.7` (tombi-toml/tombi)</summary>

### v1.2.7

<!-- Release notes generated using configuration in .github/release.yml at v1.2.7 -->

## What's Changed
### 🦅 New Features
* feat(config): support per-schema strict mode by @​ya7010 in https://github.com/tombi-toml/tombi/pull/2061
### 🛠️ Other Changes
* fix: improve config file load error reporting by @​ya7010 in https://github.com/tombi-toml/tombi/pull/2062


**Full Changelog**: https://github.com/tombi-toml/tombi/compare/v1.2.6...v1.2.7

</details>
<details>
<summary>uv: `0.12.1``0.12.3` (astral-sh/uv)</summary>

### 0.12.2

## Release Notes

Released on 2026-08-05.

### Python

- Add CPython 3.15.0rc1 ([#20948](https://github.com/astral-sh/uv/pull/20948))
- Add CPython 3.14.7 ([#20971](https://github.com/astral-sh/uv/pull/20971))

### Enhancements

- Ensure diagnostic hints end with a newline to prevent malformed terminal output ([#20959](https://github.com/astral-sh/uv/pull/20959))

### Preview features

- Audit one or all installed tools with `uv tool audit` ([#20921](https://github.com/astral-sh/uv/pull/20921))
- Report physically reclaimed disk space during cache cleanup with the `cache-physical-space` preview feature ([#20925](https://github.com/astral-sh/uv/pull/20925))

### Configuration

- Add `UV_RUN_RLIMIT_NOFILE` to set the open-file limit for commands launched by `uv run` ([#20926](https://github.com/astral-sh/uv/pull/20926))

### Performance

- Speed up `uv.lock` parsing for wheel entries ([#20881](https://github.com/astral-sh/uv/pull/20881))
- Speed up `uv.lock` parsing for source distribution entries ([#20882](https://github.com/astral-sh/uv/pull/20882))
- Speed up filename extraction from distribution URLs ([#20879](https://github.com/astral-sh/uv/pull/20879))
- Reduce filesystem metadata lookups during bytecode compilation ([#20928](https://github.com/astral-sh/uv/pull/20928))
- Reuse file metadata when building source distributions ([#20927](https://github.com/astral-sh/uv/pull/20927))

### Bug fixes

- Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions ([#20963](https://github.com/astral-sh/uv/pull/20963))
- Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested ([#20930](https://github.com/astral-sh/uv/pull/20930))

### Documentation

- Separate build and publish jobs in the GitHub Actions publishing guide ([#20946](https://github.com/astral-sh/uv/pull/20946))
- Ensure the GitHub Actions publishing exampl… (truncated)

### 0.12.3

## Release Notes

Released on 2026-08-07.

### Python

- Add CPython 3.13.15 ([#20997](https://github.com/astral-sh/uv/pull/20997))

### Preview features

- Add `--output-format` to select automatic, human-readable, or raw-byte output for `uv cache size` ([#20992](https://github.com/astral-sh/uv/pull/20992))
- Preserve JSON output from `uv workspace metadata --quiet` while suppressing diagnostics ([#20991](https://github.com/astral-sh/uv/pull/20991))
- Reduce memory usage for large workspaces by streaming `uv workspace metadata` JSON output ([#20990](https://github.com/astral-sh/uv/pull/20990))

### Performance

- Reduce Linux startup latency by initializing the workspace cache before spawning another thread ([#20989](https://github.com/astral-sh/uv/pull/20989))
- Reuse compiled workspace exclusion patterns during workspace discovery ([#20988](https://github.com/astral-sh/uv/pull/20988))
- Speed up conflict-heavy resolutions by avoiding materialized range complements ([#20982](https://github.com/astral-sh/uv/pull/20982))
- Avoid slow procfs reads during Python interpreter discovery on Linux ([#20987](https://github.com/astral-sh/uv/pull/20987))

### Documentation

- Add PEP 740 attestations to the GitHub Actions publishing example ([#20986](https://github.com/astral-sh/uv/pull/20986))
- Restrict the GitHub Actions publishing example to Python version tags ([#20973](https://github.com/astral-sh/uv/pull/20973))
- Correct `--python-pin` to `--pin-python` in the `uv init --bare` example ([#20876](https://github.com/astral-sh/uv/pull/20876))

## Install uv 0.12.3

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.ps1 | iex"

Download uv 0.12.3

| Fi… (truncated)

Modified files:

  • .mise.toml

@github-actions

Copy link
Copy Markdown
Contributor

Commit-Check ✔️

Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `node`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (6 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `editorconfig-checker` | `3.8.0` → `3.11.1` | `3.8.0` → `3.11.1` |
| `node` | `24` → `26` | `24.19.0` → `26.7.0` |
| `prek` | `0.4.11` → `0.4.12` | `0.4.11` → `0.4.12` |
| `rumdl` | `0.2.49` → `0.2.52` | `0.2.49` → `0.2.52` |
| `tombi` | `1.2.6` → `1.2.7` | `1.2.6` → `1.2.7` |
| `uv` | `0.12.1` → `0.12.3` | `0.12.1` → `0.12.3` |

</details>

<details>
<summary>Release notes (6 tools)</summary>

<details>
<summary>editorconfig-checker: `3.8.0` → `3.11.1` (editorconfig-checker/editorconfig-checker)</summary>

### v3.9.0

## [3.9.0](editorconfig-checker/editorconfig-checker@v3.8.0...v3.9.0) (2026-07-31)

### Features

* enable immutable releases ([6865c06](editorconfig-checker/editorconfig-checker@6865c06))

### v3.10.0

## editorconfig-checker v3.10.0 (2026-08-07T23:27:59Z)

Welcome to this new release of editorconfig-checker!

## Changelog
### Others
* 77a3415d6127cc892376837b85fd2a4b5c98d40d: Revert "feat(immutable-releases): set release-please to create draft releases" (@​klaernie)
* a85cd6ab82397f19bdd9bfa30730a487ead1ec74: chore(deps): bump docker/login-action from 4.5.2 to 4.6.0 (#590) (@​dependabot[bot])
* 74cd03a2e91c1c42deff2bec2d120c06ff1be3e8: chore(main): release 3.10.0 (#588) (@​editorconfig-checker-bot)
* 8d4f96e7a838bfb0d8b98a40e66ce8cbd8c1e075: chore: allow triggering release-please manually (@​klaernie)
* a685b542509d0349ce6215adf6088a242fa93d84: feat(immutable-release): tell release-please to create draft releases (@​klaernie)
* 912f4a986b7da0b22cfa3a055cc24a355dee7cbc: feat(immutable-releases): ensure that despite the release being a draft the tag is created (@​klaernie)
* 2d48c2ecae1743614cefa660c2796e14cefd7520: feat(immutable-releases): set release-please to create draft releases (@​klaernie)

## Thanks!

Those were the changes on v3.10.0!

### v3.11.0

## editorconfig-checker v3.11.0 (2026-08-08T10:40:38Z)

Welcome to this new release of editorconfig-checker!

## Changelog
### Others
* 174c5809baf06f2d8e82c1d2de1f6433cc569a1d: chore(main): release 3.11.0 (#592) (@​editorconfig-checker-bot)
* e9f143bc9d6cc5bb29030843ec42eae2a94b4dda: chore: replace deprecated goreleaser option with its current form (@​klaernie)
* 4c08f2ccd339734ff92f2f04d146cd91af02d225: feat(immutable-release): goreleaser should publish its release (@​klaernie)

## Thanks!

Those were the changes on v3.11.0!

### v3.11.1

## [3.11.1](editorconfig-checker/editorconfig-checker@v3.11.0...v3.11.1) (2026-08-08)

### Features

* **immutable-release:** tell goreleaser to use the existing draft release ([a8e6136](editorconfig-checker/editorconfig-checker@a8e6136))

</details>
<details>
<summary>node: `24.19.0` → `26.7.0` (nodejs/node)</summary>

### v26.0.0

We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals
as we continue to modernize the platform.

As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months.
We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications.

### Notable Changes

#### Temporal API

The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript
that provides a more robust and feature-rich alternative to the legacy `Date` object.

Contributed by Richard Lau in [#61806](nodejs/node#61806).

#### V8 14.6

The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134.

This version also includes:

* Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()`
* Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()`

Contributed by Michaël Zasso in [#61898](nodejs/node#61898).

#### Undici 8

Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation.

#### Deprecations and Removals

* \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084)
* \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635)

`http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated)

### v26.1.0

### Notable Changes

#### Experimental `node:ffi` module

Node.js now includes an experimental `node:ffi` module for loading dynamic
libraries and calling native symbols from JavaScript.

The API is gated behind the `--experimental-ffi` flag and, when the Permission
Model is enabled, requires `--allow-ffi`.

This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory
after it has been freed can crash the process or corrupt memory.

Contributed by Paolo Insogna in [#62072](nodejs/node#62072).

#### Other Notable Changes

* \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390)
* \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527)
* \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553)
* \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713)
* \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775)
* \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277)
* \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated)

### v26.2.0

### Notable Changes

* \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562)
* \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789)
* \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155)

### Commits

* \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314)
* \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280)
* \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576)
* \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated)

### v26.3.0

### Notable Changes

#### Potential changes to macOS Universal Binary availability

With Apple and its ecosystem progressively dropping support for Intel-based
architectures, it has become apparent that the Node.js project may not be able
to maintain the universal binaries we currently distribute for the full lifetime
of Node.js 26. This change serves to communicate that risk. At present, our
intention remains to continue shipping universal binaries supporting both Apple
Silicon and Intel-based Macs for as long as practical.

Contributed by Antoine du Hamel in [#63055](nodejs/node#63055).

#### Other notable changes

* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527)
* \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597)
* \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079)
* \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672)

### Commits

* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated)

### v26.3.1

This is a security release.

### Notable Changes

* (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
* (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
* (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
* (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
* (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
* (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
* (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
* (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
* (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
* (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
* (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low

### Commits

* \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878)
* \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890)
* \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903)
* \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779)
* \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated)

### v26.4.0

### Notable Changes

* \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050)
* \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634)
* \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470)
* \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239)
* \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825)
* \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217)
* \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537)
* \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115)

### Commits

* \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929)
* \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated)

### v26.5.0

### Notable Changes

#### New release key

Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`.

#### Other notable changes

* \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036)
* \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300)
* \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935)
* \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195)
* \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119)

### Commits

* \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218)
* \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161)
* \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169)
* \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated)

### v26.5.1

This is a security release.

### Notable Changes

* (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
* (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
* (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
* (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
* (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
* (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
* (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
* (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
* (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
* (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
* deps: update llhttp to 9.4.3 (Paolo Insogna)
* deps: update undici to 8.9.0 (Node.js GitHub Bot)

### Commits

* \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935)
* \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712)
* \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929)
* \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922)
* \[[`23b94c843a`](https://github.… (truncated)

### v26.6.0

### Notable Changes

* \[[`5a36018abc`](nodejs/node@5a36018abc)] - **doc**: add MikeMcC399 as collaborator (Mike McCready) [#64656](nodejs/node#64656)
* \[[`9b04f82d7b`](nodejs/node@9b04f82d7b)] - **(SEMVER-MINOR)** **ffi**: add `getCurrentEventLoop` (Paolo Insogna) [#64323](nodejs/node#64323)
* \[[`bb51f2c960`](nodejs/node@bb51f2c960)] - **(SEMVER-MINOR)** **test\_runner**: add `context.log()` and `test:log` event (Moshe Atlow) [#64389](nodejs/node#64389)
* \[[`56ce83b3ee`](nodejs/node@56ce83b3ee)] - **(SEMVER-MINOR)** **test\_runner**: report `entryFile` in `TestStream` events (Moshe Atlow) [#64309](nodejs/node#64309)

### Commits

* \[[`248ff9fa5c`](nodejs/node@248ff9fa5c)] - **assert,util**: fix TypeError on Maps with null keys (Paul Bouchon) [#64441](nodejs/node#64441)
* \[[`3b5baceafe`](nodejs/node@3b5baceafe)] - **benchmark**: add bytes variant to webstreams async-iterator (Matteo Collina) [#64291](nodejs/node#64291)
* \[[`0a46d1ef66`](nodejs/node@0a46d1ef66)] - **buffer**: normalize lone "\r" in Blob native line endings (Daijiro Wachi) [#64115](nodejs/node#64115)
* \[[`d9ada18b70`](nodejs/node@d9ada18b70)] - **buffer**: fix Blob.stream() leaking source buffer (semimikoh) [#63577](nodejs/node#63577)
* \[[`d05993bcf6`](nodejs/node@d05993bcf6)] - **build**: merge multiple on download artifact (Chengzhong Wu) [#64633](nodejs/node#64633)
* \[[`6c25ac909a`](nodejs/node@6c25ac909a)] - **build**: extract temporal\_capi crate directory name into gyp variable (René) [#64482](https://githu… (truncated)

### v26.7.0

### Notable Changes

* \[[`58717685a1`](nodejs/node@58717685a1)] - **(SEMVER-MINOR)** **crypto**: support loading private keys through STORE loaders (Filip Skokan) [#63949](nodejs/node#63949)
* \[[`44b940ee8c`](nodejs/node@44b940ee8c)] - **crypto**: update root certificates to NSS 3.125 (Node.js GitHub Bot) [#64746](nodejs/node#64746)
* \[[`c1e4f7365e`](nodejs/node@c1e4f7365e)] - **(SEMVER-MINOR)** **lib**: add perfetto support (Chengzhong Wu) [#64565](nodejs/node#64565)
* \[[`11c2f9c642`](nodejs/node@11c2f9c642)] - **(SEMVER-MINOR)** **module**: implement `Symbol.dispose` in `ModuleHooks` (Remco Haszing) [#63928](nodejs/node#63928)
* \[[`a646319f61`](nodejs/node@a646319f61)] - **(SEMVER-MINOR)** **test\_runner**: add support for `--test-coverage-include-all` (avivkeller) [#64830](nodejs/node#64830)

### Commits

* \[[`a2d3f891d3`](nodejs/node@a2d3f891d3)] - **async\_hooks**: use validateBoolean for trackPromises (Soul Lee) [#64731](nodejs/node#64731)
* \[[`d7266cdd99`](nodejs/node@d7266cdd99)] - **benchmark**: fix calibrate-n option handling (Luan Muniz) [#64146](nodejs/node#64146)
* \[[`2e64293e3f`](nodejs/node@2e64293e3f)] - **buffer**: use Clamp conversion in Blob slice (Donghoon Kang) [#64739](nodejs/node#64739)
* \[[`5fda0958bd`](nodejs/node@5fda0958bd)] - **buffer**: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) [#63904](nodejs/node#63904)
* \[[`5298db40f9`](nodejs/node@5298db40f9)] - **build**: run perfetto build and test on GHA (Chengzhong Wu) [#6472… (truncated)

_Omitted 14 older releases._

</details>
<details>
<summary>prek: `0.4.11` → `0.4.12` (j178/prek)</summary>

### v0.4.12

## Release Notes

Released on 2026-08-03.

### Enhancements

- Add `--require-group` for hook group intersections ([#2472](j178/prek#2472))
- Align fast-path and builtin pre-commit hooks ([#2433](j178/prek#2433))
- Do not shuffle file list for verbose output ([#2431](j178/prek#2431))
- Improve top-level command descriptions ([#2429](j178/prek#2429))
- Install `uv` from Astral CDN and drop source racing ([#2455](j178/prek#2455))
- Make `prek install --force` bypass external hooks paths ([#2437](j178/prek#2437))
- Show builtin hook flags in verbose list output ([#2427](j178/prek#2427))
- Verify uv release archive checksums ([#2456](j178/prek#2456))

### Performance

- Precompute file tags in parallel ([#2440](j178/prek#2440))
- Skip diffs after known hook modifications ([#2447](j178/prek#2447))
- Skip worktree diffs for read-only languages ([#2432](j178/prek#2432))
- Track builtin hook file changes directly ([#2404](j178/prek#2404))

### Bug fixes

- Use full object IDs in diff snapshots ([#2448](j178/prek#2448))

### Documentation

- Add a multi-repository configuration example ([#2434](j178/prek#2434))
- Rewrite benchmark documentation ([#2469](j178/prek#2469))

### Contributors

- @​j178
- @​BitWeaverDev
- @​allanlewis

## Install prek 0.4.12

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.ps1 | iex"
```… (truncated)

</details>
<details>
<summary>rumdl: `0.2.49` → `0.2.52` (rvben/rumdl)</summary>

### v0.2.50

### Added

- **md077**: support fixed continuation indent config (#786) ([fea6322](rvben/rumdl@fea6322))

### Fixed

- **md065**: leave markers alone inside a block that hides its content ([2654364](rvben/rumdl@2654364))
- **md065**: report thematic breaks written with spaces between markers ([1d29236](rvben/rumdl@1d29236))
- **md076**: ask the parser whether a list item's block is really fenced ([fd616c2](rvben/rumdl@fd616c2))
- **md022**: require a blank line below a heading above a spaced thematic break ([27120f2](rvben/rumdl@27120f2))
- **MD076**: preserve fenced list item spacing (#788) ([2d60067](rvben/rumdl@2d60067))
- **md022**: use the same list test below a heading in check and fix (#790) ([ef926b7](rvben/rumdl@ef926b7))
- **md040**: locate the fence a list marker holds instead of assuming the indent ([6099a6c](rvben/rumdl@6099a6c))
- **md077**: keep the strict-flavor minimum as a floor under a configured indent ([cfaad2e](rvben/rumdl@cfaad2e))
- **md077**: reject a configured indent of 0 ([1ac97a3](rvben/rumdl@1ac97a3))
- **md077**: accept the indent option instead of reporting it as unknown ([cba175c](rvben/rumdl@cba175c))
- **md013**: stop exempting a complete link followed by a parenthesized aside ([722fad6](rvben/rumdl@722fad6))
- **md013**: ke… (truncated)

### v0.2.51

### Added

- **md088**: normalize quotes and dashes to ASCII (#763) ([52e9844](rvben/rumdl@52e9844))

### Fixed

- **config**: keep a file's per-file-ignores out of the workspace index it feeds ([2bb0ce7](rvben/rumdl@2bb0ce7))
- **md051**: validate cross-file link fragments for a document read from stdin ([e215c65](rvben/rumdl@e215c65))
- **md051**: report a broken fragment on a query-string destination once ([7c8390f](rvben/rumdl@7c8390f))
- **md088**: leave modifier letters and math notation alone ([56dbf0f](rvben/rumdl@56dbf0f))
- **config**: report the effective rule lists from `config get global.*` ([5db8f0c](rvben/rumdl@5db8f0c))
- **config**: answer `config get` for every key rumdl accepts ([ecce820](rvben/rumdl@ecce820))
- **md035**: publish the horizontal rule style the rule enforces ([77c8c65](rvben/rumdl@77c8c65))
- **config**: accept every config key a rule actually reads ([8ec7bba](rvben/rumdl@8ec7bba))
- **lsp**: identify documents by the same resolved path as the index ([78f4aa0](rvben/rumdl@78f4aa0))
- **lsp**: keep frontmatter values out of find-references results ([499b005](rvben/rumdl@499b005))
- **md051**: index cross-file links independently of frontmatter config ([ca7b93e](rvben/rumdl@ca7b93e))
- **lsp**: build the workspace index from t… (truncated)

### v0.2.52

### Fixed

- **md012**: report blank lines before a code block that ends the document (#791) ([e897556](rvben/rumdl@e897556))
- **rules**: treat a template shortcode tag as opaque markup ([6962184](rvben/rumdl@6962184))
- **cli**: report a piped document's findings on stdout like every other run ([47f8a50](rvben/rumdl@47f8a50))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.52-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.52/rumdl-v0.2.52-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/r… (truncated)

</details>
<details>
<summary>tombi: `1.2.6` → `1.2.7` (tombi-toml/tombi)</summary>

### v1.2.7

<!-- Release notes generated using configuration in .github/release.yml at v1.2.7 -->

## What's Changed
### 🦅 New Features
* feat(config): support per-schema strict mode by @​ya7010 in tombi-toml/tombi#2061
### 🛠️ Other Changes
* fix: improve config file load error reporting by @​ya7010 in tombi-toml/tombi#2062

**Full Changelog**: tombi-toml/tombi@v1.2.6...v1.2.7

</details>
<details>
<summary>uv: `0.12.1` → `0.12.3` (astral-sh/uv)</summary>

### 0.12.2

## Release Notes

Released on 2026-08-05.

### Python

- Add CPython 3.15.0rc1 ([#20948](astral-sh/uv#20948))
- Add CPython 3.14.7 ([#20971](astral-sh/uv#20971))

### Enhancements

- Ensure diagnostic hints end with a newline to prevent malformed terminal output ([#20959](astral-sh/uv#20959))

### Preview features

- Audit one or all installed tools with `uv tool audit` ([#20921](astral-sh/uv#20921))
- Report physically reclaimed disk space during cache cleanup with the `cache-physical-space` preview feature ([#20925](astral-sh/uv#20925))

### Configuration

- Add `UV_RUN_RLIMIT_NOFILE` to set the open-file limit for commands launched by `uv run` ([#20926](astral-sh/uv#20926))

### Performance

- Speed up `uv.lock` parsing for wheel entries ([#20881](astral-sh/uv#20881))
- Speed up `uv.lock` parsing for source distribution entries ([#20882](astral-sh/uv#20882))
- Speed up filename extraction from distribution URLs ([#20879](astral-sh/uv#20879))
- Reduce filesystem metadata lookups during bytecode compilation ([#20928](astral-sh/uv#20928))
- Reuse file metadata when building source distributions ([#20927](astral-sh/uv#20927))

### Bug fixes

- Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions ([#20963](astral-sh/uv#20963))
- Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested ([#20930](astral-sh/uv#20930))

### Documentation

- Separate build and publish jobs in the GitHub Actions publishing guide ([#20946](astral-sh/uv#20946))
- Ensure the GitHub Actions publishing exampl… (truncated)

### 0.12.3

## Release Notes

Released on 2026-08-07.

### Python

- Add CPython 3.13.15 ([#20997](astral-sh/uv#20997))

### Preview features

- Add `--output-format` to select automatic, human-readable, or raw-byte output for `uv cache size` ([#20992](astral-sh/uv#20992))
- Preserve JSON output from `uv workspace metadata --quiet` while suppressing diagnostics ([#20991](astral-sh/uv#20991))
- Reduce memory usage for large workspaces by streaming `uv workspace metadata` JSON output ([#20990](astral-sh/uv#20990))

### Performance

- Reduce Linux startup latency by initializing the workspace cache before spawning another thread ([#20989](astral-sh/uv#20989))
- Reuse compiled workspace exclusion patterns during workspace discovery ([#20988](astral-sh/uv#20988))
- Speed up conflict-heavy resolutions by avoiding materialized range complements ([#20982](astral-sh/uv#20982))
- Avoid slow procfs reads during Python interpreter discovery on Linux ([#20987](astral-sh/uv#20987))

### Documentation

- Add PEP 740 attestations to the GitHub Actions publishing example ([#20986](astral-sh/uv#20986))
- Restrict the GitHub Actions publishing example to Python version tags ([#20973](astral-sh/uv#20973))
- Correct `--python-pin` to `--pin-python` in the `uv init --bare` example ([#20876](astral-sh/uv#20876))

## Install uv 0.12.3

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.3/uv-installer.ps1 | iex"
```

## Download uv 0.12.3

|  Fi… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
@jylenhof
jylenhof force-pushed the chore/mise-tool-updates-20260810064201 branch from 8f22a75 to e7f0cdb Compare August 10, 2026 08:01
@jylenhof jylenhof closed this Aug 10, 2026
@jylenhof
jylenhof deleted the chore/mise-tool-updates-20260810064201 branch August 10, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant