docs: document scrape query limits in request API - #2
Closed
zeitlinger wants to merge 397 commits into
Closed
Conversation
🤖 I have created a release *beep* *boop* --- ### Updating meta-information for bleeding-edge SNAPSHOT release. --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…rometheus#2076) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [go:github.com/gohugoio/hugo](https://redirect.github.com/gohugoio/hugo) | `v0.161.0` → `v0.161.1` |  |  | --- ### Release Notes <details> <summary>gohugoio/hugo (go:github.com/gohugoio/hugo)</summary> ### [`v0.161.1`](https://redirect.github.com/gohugoio/hugo/releases/tag/v0.161.1) [Compare Source](https://redirect.github.com/gohugoio/hugo/compare/v0.161.0...v0.161.1) ##### What's Changed - resources: Honor Retry-After header in resources.GetRemote retries [`c4eba92`](https://redirect.github.com/gohugoio/hugo/commit/c4eba928) [@​bep](https://redirect.github.com/bep) [#​14828](https://redirect.github.com/gohugoio/hugo/issues/14828) - warpc: Move to parson.c in <https://github.com/kgabis/parson> [`8b40a96`](https://redirect.github.com/gohugoio/hugo/commit/8b40a96b) [@​bep](https://redirect.github.com/bep) [#​14823](https://redirect.github.com/gohugoio/hugo/issues/14823) - config/security: Add AllowChildProcess to security.node.permissions [`d65af84`](https://redirect.github.com/gohugoio/hugo/commit/d65af84d) [@​bep](https://redirect.github.com/bep) [#​14824](https://redirect.github.com/gohugoio/hugo/issues/14824) - config/security: Restrict default http.urls "@​" deny to userinfo [`454450a`](https://redirect.github.com/gohugoio/hugo/commit/454450a6) [@​bep](https://redirect.github.com/bep) [#​14825](https://redirect.github.com/gohugoio/hugo/issues/14825) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> --------- Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
…o v3.2.4 (prometheus#2088) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [com.github.ben-manes.caffeine:caffeine](https://redirect.github.com/ben-manes/caffeine) | `3.2.3` → `3.2.4` |  |  | --- ### Release Notes <details> <summary>ben-manes/caffeine (com.github.ben-manes.caffeine:caffeine)</summary> ### [`v3.2.4`](https://redirect.github.com/ben-manes/caffeine/releases/tag/v3.2.4): 3.2.4 [Compare Source](https://redirect.github.com/ben-manes/caffeine/compare/v3.2.3...v3.2.4) - Improved access expiration's read performance by avoiding false sharing effects caused by the timestamp update - Fixed head-of-line blocking of expiration queues caused by in-flight async entries ([#​1954](https://redirect.github.com/ben-manes/caffeine/issues/1954)) - Fixed various minor issues found using AI audits - Added [ObjectInputFilter](https://docs.oracle.com/en/java/javase/25/docs/api//java.base/java/io/ObjectInputFilter.html) support to JCache </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…etheus#2085) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | eclipse-temurin | final | patch | `25.0.2_10-jre` → `25.0.3_9-jre` | | eclipse-temurin | | patch | `25.0.2_10-jre` → `25.0.3_9-jre` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [mise](https://redirect.github.com/jdx/mise) | minor | `v2026.4.23` → `v2026.5.0` | --- ### Release Notes <details> <summary>jdx/mise (mise)</summary> ### [`v2026.5.0`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.0): : Conda graduates, smarter prereleases, and Windows POSIX tasks [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.4.28...vfox-v2026.5.0) #### Added - **(conda)** Graduated the conda backend out of experimental ([#​9544](https://redirect.github.com/jdx/mise/pull/9544)) by [@​jdx](https://redirect.github.com/jdx). - **(deps)** Added `dart` and `flutter` deps providers backed by `pubspec.yaml` / `pubspec.lock` ([#​9505](https://redirect.github.com/jdx/mise/pull/9505)) by [@​tjarvstrand](https://redirect.github.com/tjarvstrand). - **(task)** `sources` entries can now be prefixed with `!` to exclude paths, and a new `sources_exclude` field is supported; exclusions apply to freshness checks, `task_source_files`, and `mise watch` ([#​9496](https://redirect.github.com/jdx/mise/pull/9496)) by [@​jlarmstrongiv](https://redirect.github.com/jlarmstrongiv). - **(vfox)** Added `stat` to the Lua `file` module so plugins can read file metadata ([#​9497](https://redirect.github.com/jdx/mise/pull/9497)) by [@​esteve](https://redirect.github.com/esteve). - **(registry)** Added `neo4j` ([#​9525](https://redirect.github.com/jdx/mise/pull/9525)), `rustfs` ([#​9530](https://redirect.github.com/jdx/mise/pull/9530)), `expert` ([#​9498](https://redirect.github.com/jdx/mise/pull/9498)), `systemctl-tui` ([#​9521](https://redirect.github.com/jdx/mise/pull/9521)), `codon` ([#​9538](https://redirect.github.com/jdx/mise/pull/9538)), `yr` ([#​9542](https://redirect.github.com/jdx/mise/pull/9542)), `betterleaks` ([#​9541](https://redirect.github.com/jdx/mise/pull/9541)), `git-filter-repo` ([#​9550](https://redirect.github.com/jdx/mise/pull/9550)), `umoci` ([#​9555](https://redirect.github.com/jdx/mise/pull/9555)), `google-java-format` ([#​9488](https://redirect.github.com/jdx/mise/pull/9488)), an aqua backend for `elixir-ls` ([#​9557](https://redirect.github.com/jdx/mise/pull/9557)), and enabled `shellcheck` on Windows ([#​9487](https://redirect.github.com/jdx/mise/pull/9487)). #### Fixed - **(backend)** Stamp prerelease metadata via regex for backends that don't expose it upstream ([#​9500](https://redirect.github.com/jdx/mise/pull/9500)) by [@​jdx](https://redirect.github.com/jdx). - **(backend)** Treat `-nightly`, `-canary`, `-experimental`, `-insider`, `-edge` as prereleases ([#​9523](https://redirect.github.com/jdx/mise/pull/9523)) by [@​jdx](https://redirect.github.com/jdx). - **(backend)** Scope PEP 440 prerelease detection to Python backends ([#​9558](https://redirect.github.com/jdx/mise/pull/9558)) by [@​jdx](https://redirect.github.com/jdx). - **(backend)** Honor `dotnet.package_flags = "prerelease"` and `--prerelease` for dotnet ([#​9551](https://redirect.github.com/jdx/mise/pull/9551)) by [@​jdx](https://redirect.github.com/jdx). - **(backend)** Suppress repeated `No versions found` warnings for backends that support unresolved `latest` ([#​9548](https://redirect.github.com/jdx/mise/pull/9548)) by [@​jdx](https://redirect.github.com/jdx). - **(install)** Don't warn for configured tools when version is passed via CLI ([#​9522](https://redirect.github.com/jdx/mise/pull/9522)) by [@​jdx](https://redirect.github.com/jdx). - **(install)** Refresh `latest` before installing missing tools ([#​9545](https://redirect.github.com/jdx/mise/pull/9545)) by [@​jdx](https://redirect.github.com/jdx). - **(install)** Don't cache nonexistent install paths ([#​9553](https://redirect.github.com/jdx/mise/pull/9553)) by [@​jdx](https://redirect.github.com/jdx). - **(lockfile)** Don't propagate ad-hoc CLI overrides into the project lockfile ([#​9562](https://redirect.github.com/jdx/mise/pull/9562)) by [@​jdx](https://redirect.github.com/jdx). - **(plugin)** Detect plugin types after cloning ([#​9540](https://redirect.github.com/jdx/mise/pull/9540)) by [@​risu729](https://redirect.github.com/risu729). - **(task)** Convert PATH to MSYS Unix form when spawning POSIX shells on Windows ([#​9547](https://redirect.github.com/jdx/mise/pull/9547)) by [@​JamBalaya56562](https://redirect.github.com/JamBalaya56562). - **(cargo)** Apply `install_env` during `cargo install` ([#​9502](https://redirect.github.com/jdx/mise/pull/9502)) by [@​c22](https://redirect.github.com/c22). - **(github)** Skip attestations on non-default `api_url` ([#​9486](https://redirect.github.com/jdx/mise/pull/9486)) by [@​jdx](https://redirect.github.com/jdx). - **(github)** Retry IP allow list errors without auth ([#​9506](https://redirect.github.com/jdx/mise/pull/9506)) by [@​risu729](https://redirect.github.com/risu729). - **(http)** Update versions host tracking endpoint ([#​9527](https://redirect.github.com/jdx/mise/pull/9527)) by [@​jdx](https://redirect.github.com/jdx). - **(release)** Pass `--no-git-checks` to `aube publish` ([#​9483](https://redirect.github.com/jdx/mise/pull/9483)) by [@​jdx](https://redirect.github.com/jdx). - **(copr)** Drop `epel-9` chroots since rust >= 1.91 is unavailable ([#​9484](https://redirect.github.com/jdx/mise/pull/9484)) by [@​jdx](https://redirect.github.com/jdx). #### Changed - **(registry)** Deny inline backend options in registry tool entries ([#​9565](https://redirect.github.com/jdx/mise/pull/9565)) by [@​risu729](https://redirect.github.com/risu729). - **(registry)** Update entry for `checkmake` ([#​9504](https://redirect.github.com/jdx/mise/pull/9504)) by [@​eread](https://redirect.github.com/eread). #### Deprecated - `shorthands_file` setting / `MISE_SHORTHANDS_FILE` is deprecated; warning starts in 2026.6.0, removal planned for 2026.12.0. Use `[plugins]` instead ([#​9534](https://redirect.github.com/jdx/mise/pull/9534)) by [@​risu729](https://redirect.github.com/risu729). #### Documentation - Document `ghtkn` as a GitHub `credential_command` ([#​9546](https://redirect.github.com/jdx/mise/pull/9546)) by [@​jdx](https://redirect.github.com/jdx). - Clarify registry backend acceptance policy ([#​9543](https://redirect.github.com/jdx/mise/pull/9543), [7bbeebe](https://redirect.github.com/jdx/mise/commit/7bbeebe6dceabdb98dd3c59a55f6d58d7af34bd1)) by [@​jdx](https://redirect.github.com/jdx). - Update `mise watch` docs to `pitchfork.en.dev` ([#​9536](https://redirect.github.com/jdx/mise/pull/9536)) by [@​risu729](https://redirect.github.com/risu729). - Use bash in `exec` example for variable echoing ([#​9567](https://redirect.github.com/jdx/mise/pull/9567)) by [@​kuboon](https://redirect.github.com/kuboon). #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.4.28`](https://redirect.github.com/jdx/mise/releases/tag/v2026.4.28): : Remote tasks pinned by commit SHA [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.4.27...v2026.4.28) A small patch release: remote tasks pinned to a commit SHA no longer panic, and the Fedora COPR packaging pipeline picks up Dockerfile fixes again. #### Fixed - **(task)** Remote tasks referenced by commit SHA (a `git::` source with `?ref=<40-char hex>`) no longer crash mise with `we map by name only and have no object-id in refspec` from `gix` ([#​9473](https://redirect.github.com/jdx/mise/pull/9473)) by [@​jdx](https://redirect.github.com/jdx). `gix-refspec` parses any 40- or 64-char hex string as an `ObjectId` refspec, but `gix::clone::fetch::util::find_custom_refname` only handles name-based matches and `expect()`s on the result, so passing a bare SHA to `prepare_clone.with_ref_name()` triggered a hard process panic on every cache miss. `Git::clone` now detects SHA-shaped refs via a `looks_like_sha` heuristic, skips both the `with_ref_name()` and `git clone -b` paths (neither accepts bare SHAs), drops `--depth 1` since shallow clones may not contain the requested object, and checks out the SHA after the clone via the existing CLI-backed update. Named branches and tags continue to use the existing fast paths. Closes [#​9472](https://redirect.github.com/jdx/mise/discussions/9472). - **(copr)** The `copr-publish` workflow no longer pins a stale `ghcr.io/jdx/mise:copr` image digest, and `docker.yml` now rebuilds the `:copr` image whenever `packaging/copr/Dockerfile` changes on `main` ([#​9451](https://redirect.github.com/jdx/mise/pull/9451)) by [@​bestagi](https://redirect.github.com/bestagi). Previously the workflow kept hitting `ModuleNotFoundError: No module named 'rich'` even after [#​9421](https://redirect.github.com/jdx/mise/pull/9421) switched `copr-cli` to `dnf install`, because the hardcoded digest still pointed at the old pip-installed image. #### New Contributors - [@​bestagi](https://redirect.github.com/bestagi) made their first contribution in [#​9451](https://redirect.github.com/jdx/mise/pull/9451) **Full Changelog**: <jdx/mise@v2026.4.27...v2026.4.28> ### [`v2026.4.27`](https://redirect.github.com/jdx/mise/releases/tag/v2026.4.27): : npm install args, smarter watch, and a macOS shim recursion fix [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.4.25...v2026.4.27) A focused release: more control over how npm-backed tools get installed, smarter `mise watch` that follows task dependencies, and a fix for a nasty macOS shim recursion that could lock up a shell during `mise up --bump`. #### Added - **(backend)** New `npm_args`, `pnpm_args`, `bun_args`, and `aube_args` tool options on the npm backend ([#​9109](https://redirect.github.com/jdx/mise/pull/9109)) by [@​risu729](https://redirect.github.com/risu729). Each one is forwarded to the matching package manager when it's the active `settings.npm.package_manager`, mirroring the `pipx` backend's style. The args are also recorded in the lockfile and at install time: ```toml [tools] "npm:npm" = { version = "latest", aube_args = "--reporter append-only" } "npm:tiny" = { version = "latest", pnpm_args = "--loglevel=warn" } ``` - **(env)** External vfox environment plugins now get `ctx.config_root` in their `MiseEnv` / `MisePath` hooks ([#​9465](https://redirect.github.com/jdx/mise/pull/9465)) by [@​hisaac](https://redirect.github.com/hisaac). This matches what built-in directives like `_.file` already see, so plugins (e.g. [`mise-xcode`](https://redirect.github.com/hisaac/mise-xcode)) can resolve user-supplied relative paths against the project root regardless of the shell's cwd. `watch_files` returned from a plugin are now also absolutized against `config_root` instead of `current_dir()`. - **(task)** `mise watch` now follows the task graph and watches the sources of each chosen task's dependencies as well as its own ([#​9437](https://redirect.github.com/jdx/mise/pull/9437)) by [@​43081j](https://redirect.github.com/43081j). Pass `--skip-deps` (or set `skip_deps`) to restore the previous "task sources only" behavior. Explicit `--glob` overrides still win. - **(release)** `scripts/gen-aqua-changelog.sh` now diffs the previous tag's `registry.yaml` against the current one and emits `New Packages` / `Updated Packages` sections in the release PR, instead of dumping the aqua-registry release tags rolled into the release ([#​9471](https://redirect.github.com/jdx/mise/pull/9471)) by [@​jdx](https://redirect.github.com/jdx). This restores the pre-[#​9043](https://redirect.github.com/jdx/mise/pull/9043) behavior for the merged-registry world. #### Fixed - **(backend)** When `_list_remote_versions` returned an empty list (invalid module path, throttling, etc.) the empty result was cached as if it were authoritative, poisoning both the on-disk cache file and the in-memory `OnceCell` for up to an hour ([#​9444](https://redirect.github.com/jdx/mise/pull/9444)) by [@​c22](https://redirect.github.com/c22). The cache is now cleared in both places when the list comes back empty, so the next call re-fetches. - **(shims)** Fixed an infinite shim recursion on macOS reported in [#​9462](https://redirect.github.com/jdx/mise/discussions/9462) where `mise up --bump` against npm packages would loop `mise -> npm shim -> mise -> npm shim -> ...` and sometimes crash the session ([#​9468](https://redirect.github.com/jdx/mise/pull/9468)) by [@​jdx](https://redirect.github.com/jdx). The trigger was a case-mismatched `$HOME` in `PATH` (`/Users/Olfway/...` vs. `/Users/olfway/...`) — the shims-stripping in `Backend::dependency_env` compared byte-equal, so on case-insensitive APFS/HFS+ volumes it was a no-op and `npm` re-resolved to the mise shim. A new `file::paths_eq` does case-insensitive compares on macOS/Windows and byte-equal on Linux, and is now used everywhere mise asks "is this PATH entry the shims directory?" — including `path_env_without_shims`, `which_no_shims`, `PathEnv` partitioning, `cli::exec` program resolution, and the doctor's `shims_on_path` check (which had been silently reporting `no` for affected users). - **(task)** Under `deny_env = true` on Linux, every env var was being stripped from the child process — including the `PATH` / `HOME` / `USER` / `SHELL` / `TERM` / `LANG` that `filter_env` and the docs say should pass through ([#​9467](https://redirect.github.com/jdx/mise/pull/9467)) by [@​jdx](https://redirect.github.com/jdx), fixing [#​9466](https://redirect.github.com/jdx/mise/discussions/9466). `apply_sandbox()` was calling `Command::env_clear()` *after* the task executor populated explicit envs via `.envs(filtered_env)`, wiping both. The Linux branch now snapshots the explicit envs before clearing and re-applies them; macOS already did this. A new `path_test` task in `e2e/sandbox/test_sandbox_task` guards against regressions. #### New Contributors - [@​43081j](https://redirect.github.com/43081j) made their first contribution in [#​9437](https://redirect.github.com/jdx/mise/pull/9437) - [@​hisaac](https://redirect.github.com/hisaac) made their first contribution in [#​9465](https://redirect.github.com/jdx/mise/pull/9465) **Full Changelog**: <jdx/mise@v2026.4.26...v2026.4.27> ### [`v2026.4.25`](https://redirect.github.com/jdx/mise/releases/tag/v2026.4.25): : Sharper task tooling and lockfile fixes [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.4.24...v2026.4.25) A patch release focused on smoothing rough edges in tasks (sandbox path resolution, dependency templates, a new `--name-only` listing) and fixing a handful of upgrade/`ls-remote` pitfalls. #### Added - **(task)** New `--name-only` flag on `mise tasks ls` (and `mise tasks`) prints one task name per line — no headers, no padding, no description column ([#​9435](https://redirect.github.com/jdx/mise/pull/9435)) by [@​jdx](https://redirect.github.com/jdx). It composes with `--all`, `--global`/`--local`, `--hidden`, `--sort`/`--sort-order`, and uses a broken-pipe-tolerant writer so dropping it into `fzf` Just Works: ```sh mise run "$(mise tasks ls --name-only --all | fzf)" ``` Conflicts with `--json`, `--extended`, and `--usage`. #### Fixed - **(task)** Dependency templates can now branch on `usage` values inside Tera statement tags, not just output expressions, and boolean/array flags are passed through with their real types instead of stringified ([#​9424](https://redirect.github.com/jdx/mise/pull/9424)) by [@​jdx](https://redirect.github.com/jdx). So this finally does what it looks like: ```toml [tasks.lint] usage = 'flag "--run-post" default=#false' depends_post = [''' {%- if usage.run_post -%} postlint:** {%- else -%} noop {%- endif -%} '''] run = 'echo "lint ran"' ``` - **(task)** Tasks that define `usage` with subcommands but no top-level args/flags now correctly populate `usage.cmd` for dependency templates, fixing a regression from [#​9424](https://redirect.github.com/jdx/mise/pull/9424) where the early-return path skipped subcommand handling ([#​9431](https://redirect.github.com/jdx/mise/pull/9431)) by [@​jdx](https://redirect.github.com/jdx). The fix also de-duplicates `make_usage_ctx` between the script parser and the dep renderer so they can't drift again. - **(task)** Sandbox `allow_read` / `allow_write` paths declared on a task are now resolved against the task's effective working directory rather than the shell's `pwd` ([#​9428](https://redirect.github.com/jdx/mise/pull/9428)) by [@​jdx](https://redirect.github.com/jdx). Previously, `dir = "../bar"` plus `allow_read = ["."]` opened up the *caller's* directory while the task itself ran in `bar/` and got blocked. CLI overrides like `mise run --allow-read=…` still resolve against shell cwd. Closes [#​9423](https://redirect.github.com/jdx/mise/discussions/9423). - **(lockfile)** `mise upgrade` now updates the global lockfile (`~/.config/mise/mise.lock`) when bumping a fuzzy version such as `latest` ([#​9442](https://redirect.github.com/jdx/mise/pull/9442)) by [@​jdx](https://redirect.github.com/jdx). The grouping pass was excluding global config files entirely, and fuzzy requests could re-resolve through the stale lockfile entry mid-update. Newly installed versions are now overlaid before lockfiles are rewritten, so a global `dummy = "latest"` upgrading from `1.0.0` to `2.0.0` actually pins `2.0.0`. - **(aqua)** When `list_releases_including_prereleases` returned an empty list (paginated/cached edge case, throttling, or a repo that genuinely has no releases), aqua fell back to `list_tags` and pulled in every git tag in the repo ([#​9443](https://redirect.github.com/jdx/mise/pull/9443)) by [@​jdx](https://redirect.github.com/jdx). For monorepos that tag sub-crates, that meant ripgrep's `grep-regex-0.1.1` and friends ended up in the shared `mise-versions` snapshot, so `ripgrep = "latest"` resolved to a tag with no matching release asset and 404'd on install. Empty release lists now propagate as empty version lists; packages that legitimately use tags as their version source still opt in via `version_source = "github_tag"`. The `remote_versions` cache filename is also reverted to `remote_versions.msgpack.z` to avoid needlessly invalidating existing caches — `VersionInfo` already deserializes forward-compatibly. (Server-side `mise-versions` snapshots will need to be regenerated with this fix.) - **(ls-remote)** `mise ls-remote --json` no longer emits `"rolling":false,"prerelease":false` on every entry ([#​9439](https://redirect.github.com/jdx/mise/pull/9439)) by [@​jdx](https://redirect.github.com/jdx). Dummy output is now `[{"version":"1.0.0"},{"version":"1.1.0"},{"version":"2.0.0"}]`. Backends that legitimately set either flag (rust nightly/beta/stable, github/aqua pre-releases) still emit the field; cached entries written by older builds continue to deserialize. - **(docs)** The docs site no longer flickers between light/dark themes on initial load ([#​9427](https://redirect.github.com/jdx/mise/pull/9427)) by [@​vhespanha](https://redirect.github.com/vhespanha). VitePress's anti-flicker inline script is now marked `data-cfasync="false"` so Cloudflare's Rocket Loader stops deferring it. Fixes [#​9393](https://redirect.github.com/jdx/mise/discussions/9393). - **(Dockerfile)** `copr-cli` is now installed via `dnf` instead of pip, fixing `ModuleNotFoundError: No module named 'rich'` in the publish-copr workflow ([#​9421](https://redirect.github.com/jdx/mise/pull/9421)) by [@​bestagi](https://redirect.github.com/bestagi). #### New Contributors - [@​vhespanha](https://redirect.github.com/vhespanha) made their first contribution in [#​9427](https://redirect.github.com/jdx/mise/pull/9427) - [@​bestagi](https://redirect.github.com/bestagi) made their first contribution in [#​9421](https://redirect.github.com/jdx/mise/pull/9421) **Full Changelog**: <jdx/mise@v2026.4.24...v2026.4.25> ### [`v2026.4.24`](https://redirect.github.com/jdx/mise/releases/tag/v2026.4.24): : Resilient downloads and global pre-release opt-in [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.4.23...v2026.4.24) A small release that hardens HTTP downloads against flaky networks and adds a global way to surface pre-release versions, plus refreshed intro messaging. #### Added - **(ls-remote)** New global `prereleases` setting (`MISE_PRERELEASES=1`) and a `--prerelease` flag for `mise ls-remote` ([#​9415](https://redirect.github.com/jdx/mise/pull/9415)) by [@​jdx](https://redirect.github.com/jdx). Acts as `prerelease = true` applied to every tool, so GitHub releases flagged `prerelease: true` show up in `ls-remote`, `latest` resolves against the full list, and fuzzy queries like `1.2` can match pre-release tags. Currently honored by the `github:` and `aqua:` backends; draft releases are still excluded. ```sh mise ls-remote github:cli/cli --prerelease # or, persistently: export MISE_PRERELEASES=1 ``` #### Fixed - **(http)** HTTP requests now retry transient failures with a jittered backoff schedule (\~200ms / 1s / 4s / 15s, then capped at 15s) and the default `http_retries` is bumped from `0` to `3` ([#​9414](https://redirect.github.com/jdx/mise/pull/9414)) by [@​jdx](https://redirect.github.com/jdx). Retries fire on 5xx, 408, 429, and network-layer errors (connect refused, timeout, mid-stream body drops); deterministic 4xx responses like 404 fail fast without retry. Downloads wrap the full request + body so a chunk failure mid-stream restarts from byte 0 instead of failing the install. Each retry logs a `warn!` immediately so flaky infrastructure surfaces in real time, and the same logic now powers vfox plugin downloads (which honor `MISE_HTTP_RETRIES` too). Set `MISE_HTTP_RETRIES=0` to opt out. The `http`→`https` fallback now only triggers on connection-level errors, not on HTTP status errors. - **(release)** `scripts/publish-s3.sh` now purges the `mise.en.dev` Cloudflare zone (alongside `jdx.dev` and `mise.run`) after each S3 publish ([#​9416](https://redirect.github.com/jdx/mise/pull/9416)) by [@​jdx](https://redirect.github.com/jdx). Because `install.sh` is uploaded with `immutable` cache-control, missing the purge could leave one zone serving the previous release's `install.sh` next to a new release's `install.sh.minisig`. #### Documentation - Refreshed the project tagline and intro across the README, docs site, landing page, man page, snapcraft/RPM/DEB/npm packaging metadata, and CLI help text to "Dev tools, env vars, and tasks in one CLI" with a clearer "what is it?" pitch focused on what mise does rather than what it replaces ([#​9418](https://redirect.github.com/jdx/mise/pull/9418)) by [@​jdx](https://redirect.github.com/jdx). - The docs site's GitHub star count is now prefixed with a ★ glyph for clarity ([#​9417](https://redirect.github.com/jdx/mise/pull/9417)) by [@​jdx](https://redirect.github.com/jdx). **Full Changelog**: <jdx/mise@v2026.4.23...v2026.4.24> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…2101) ## Summary - document that downstream `MultiCollector` adapters must expose registration metadata that matches the metric families they emit at scrape time - make the newer suffix/collision validation model more explicit for adapter maintainers ## Why - the existing release notes already describe the suffix-handling and collision-model change - what was missing was explicit guidance that downstream adapters also need their registration-time metadata to stay aligned with emitted `MetricSnapshot` families ## Testing - `mise run lint`
…e to v11.0.22 (prometheus#2099) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.apache.tomcat.embed:tomcat-embed-core](https://tomcat.apache.org/) | `11.0.21` → `11.0.22` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
) This PR contains the following updates: | Package | Update | Change | |---|---|---| | grafana/k6 | digest | `9481efe` → `50e5517` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.eclipse.jetty.ee10:jetty-ee10-servlet](https://jetty.org) ([source](https://redirect.github.com/jetty/jetty.project)) | `12.1.8` → `12.1.9` |  |  | | [org.eclipse.jetty:jetty-server](https://jetty.org) ([source](https://redirect.github.com/jetty/jetty.project)) | `12.1.8` → `12.1.9` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Related to prometheus#2075 This reduces allocation and GC pressure in histogram text formatting by eliminating unnecessary intermediate allocations. --------- Signed-off-by: Jay DeLuca <jaydeluca4@gmail.com> Signed-off-by: Ubuntu <jaydeluca4@gmail.com>
## What changed - bump lychee in mise.toml to 0.24.2 - migrate .github/config/lychee.toml from include_fragments = true to include_fragments = "anchor-only" ## Why lychee 0.24.x changed include_fragments from a boolean to a mode enum. anchor-only preserves the old anchor-checking behavior without broadening validation to scroll-to-text fragments. ## Validation - mise run lint completed link checks successfully, but the full repo lint still exits locally because super-linter needs Docker/Podman and lint:renovate-deps exits nonzero in this environment.
…e7c4 (prometheus#2104) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | eclipse-temurin | final | digest | `671061a` → `9c9e7c4` | | eclipse-temurin | | digest | `671061a` → `9c9e7c4` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [mise](https://redirect.github.com/jdx/mise) | patch | `v2026.5.0` → `v2026.5.5` | --- ### Release Notes <details> <summary>jdx/mise (mise)</summary> ### [`v2026.5.5`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.5): : Inactive upgrades, Windows bash and bunx fixes [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.4...v2026.5.5) A grab-bag release: a new `--inactive` flag for catching installed-but-unconfigured tools, several Windows fixes around `bunx` and the `bash` task shell, and correctness fixes for the npm shim, aqua bin-path resolution, and dotnet prereleases. #### Added - **(outdated/upgrade)** New `--inactive` flag on `mise outdated` and `mise upgrade` that includes installed-but-inactive tools — versions you have installed but that aren't referenced by the current config ([#​9640](https://redirect.github.com/jdx/mise/pull/9640)) by [@​roele](https://redirect.github.com/roele). Useful for cleaning up or upgrading old tool installs: ```sh # show every installed tool that has a newer version, even if it's not in mise.toml mise outdated --inactive # upgrade an installed-but-inactive tool to its current latest mise upgrade tiny --inactive ``` When a tool has no config source, `--inactive` resolves against the backend's latest version rather than the pinned installed version. #### Fixed - **(node)** The generated npm shim now invokes `<this-install>/bin/node` directly instead of `node` from `PATH`. Previously, running one Node install's `npm` while a different Node version was active could let npm derive its global prefix from the other install, sending default packages to the wrong place ([#​9749](https://redirect.github.com/jdx/mise/pull/9749)) by [@​jdx](https://redirect.github.com/jdx). - **(bun, Windows)** `mise install bun` on Windows now creates a `bunx` entry alongside `bun.exe`, matching what the upstream PowerShell installer does. mise tries a `bunx.exe -> bun.exe` hardlink first (bun switches to bunx mode based on argv\[0]) and falls back to a `bunx.cmd` shim. `reshim` picks it up automatically, so `bunx <pkg>` finally works under mise-managed bun on Windows ([#​9732](https://redirect.github.com/jdx/mise/pull/9732)) by [@​JamBalaya56562](https://redirect.github.com/JamBalaya56562). - **(task, Windows)** When a task uses `shell = "bash -c"` and mise is invoked from PowerShell, `C:\Windows\System32\bash.exe` (the WSL launcher) used to win the `PATH` search, silently running the task body inside a WSL Linux user-space where mise-managed Windows tools aren't visible. mise now resolves bash in this order: `MISE_BASH_PATH`, common Git Bash install locations (`C:\Program Files\Git\bin\bash.exe`, the x86 variant, `%LOCALAPPDATA%\Programs\Git\bin\bash.exe`), the existing PATH search, and finally an explicit reject of the WSL launcher with a warning ([#​9750](https://redirect.github.com/jdx/mise/pull/9750)) by [@​JamBalaya56562](https://redirect.github.com/JamBalaya56562). `sh`/`zsh`/`fish`/`ksh`/`dash` and non-Windows builds are unaffected. - **(aqua)** Aqua `list_bin_paths()` correctly handles packages whose actual git tags add an extra `v` after a version prefix (e.g. `tool-v1.2.3` for canonical `1.2.3`), without putting remote resolution back on the bin-path hot path that was reverted in [#​5574](https://redirect.github.com/jdx/mise/issues/5574). Install passes the already-resolved tag/version directly into file-link creation instead of recomputing it ([#​9759](https://redirect.github.com/jdx/mise/pull/9759)) by [@​risu729](https://redirect.github.com/risu729). - **(dotnet)** The dotnet backend now uses the shared `prerelease = true` tool option used by aqua/github, fetches the NuGet prerelease superset, and skips the latest fast paths when prereleases are enabled. The global `prereleases` setting and the deprecated `dotnet.package_flags = ["prerelease"]` continue to work ([#​9720](https://redirect.github.com/jdx/mise/pull/9720)) by [@​risu729](https://redirect.github.com/risu729): ```sh MISE_EXPERIMENTAL=1 mise ls-remote 'dotnet:GitVersion.Tool[prerelease=true]' ``` #### Registry - Added `scalafmt` ([github:scalameta/scalafmt](https://redirect.github.com/scalameta/scalafmt)) — the official Scala formatter ([#​9757](https://redirect.github.com/jdx/mise/pull/9757)) by [@​pokir](https://redirect.github.com/pokir). - Removed `flarectl`: upstream `cloudflare/cloudflare-go` no longer ships release binaries (the existing registry test was already commented out) ([#​9756](https://redirect.github.com/jdx/mise/pull/9756)) by [@​risu729](https://redirect.github.com/risu729). - Removed 49 registry shorthands with zero recorded users (bbr, brig, btrace, carp, clarinet, cli53, concourse, conduit, copper, credhub, datree, djinni, dome, draft, dtm, envcli, esy, glen, grain, inlets, kcctl, ki, kp, krab, kube-credential-cache, kubefedctl, kubefirst, kubemqctl, kwt, lab, lane, levant, melt, opsgenie-lamp, pachctl, psc-package, purerl, redo, rke, sinker, soracom, starboard, sver, terradozer, titan, uaa-cli, wasm4, wren-cli, zbctl) ([#​9725](https://redirect.github.com/jdx/mise/pull/9725)) by [@​jdx](https://redirect.github.com/jdx). Tools added in 2026 were skipped, and any of these can still be installed with explicit backend syntax (e.g. `mise use aqua:cloudfoundry/uaa-cli`). #### Documentation - **(secrets)** Document that direct age encryption requires experimental mode, that age decryption is strict by default, and that `age.strict=false` skips undecryptable values and keeps resolving the environment ([#​9737](https://redirect.github.com/jdx/mise/pull/9737)) by [@​risu729](https://redirect.github.com/risu729). - **(tasks)** Add a bash shebang to the conditional-dependencies example ([#​9747](https://redirect.github.com/jdx/mise/pull/9747)) by [@​JamBalaya56562](https://redirect.github.com/JamBalaya56562). - Backend tool option docs: document S3 support for `size`, `strip_components`, `bin`, and `rename_exe`; add `no_app` to GitLab and Forgejo; clarify that GitHub-family `api_url` covers release lookup and private/self-hosted API downloads, not just version listing ([#​9738](https://redirect.github.com/jdx/mise/pull/9738)) by [@​risu729](https://redirect.github.com/risu729). #### New Contributors - [@​pokir](https://redirect.github.com/pokir) made their first contribution in [#​9757](https://redirect.github.com/jdx/mise/pull/9757) **Full Changelog**: <jdx/mise@v2026.5.4...v2026.5.5> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.4`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.4): : Java on Alpine, faster pwsh exits [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.3...v2026.5.4) A small release that smooths out Java installs on Alpine, makes pwsh shell activation noticeably snappier, and cleans up `ibmcloud`'s `$PATH` footprint. #### Added - **(java)** Automatic musl detection on Alpine Linux ([#​9688](https://redirect.github.com/jdx/mise/pull/9688)) by [@​roele](https://redirect.github.com/roele). Java versions on Alpine no longer require an explicit `-musl` feature suffix — `mise-java` now exposes an `alpine-linux` OS containing the musl builds, and mise selects it automatically when running on a musl libc. So this: ```sh mise use java@corretto-25 ``` picks the Alpine/musl Corretto build on Alpine, and `-musl`-suffixed versions (e.g. `corretto-musl-25`) continue to resolve for backwards compatibility. #### Fixed - **(registry)** `ibmcloud` now uses `symlink_bins`, so only the `ibmcloud` binary is placed on `$PATH` instead of the entire install directory. This prevents the bundled `install` binary from shadowing `/usr/bin/install` ([#​9685](https://redirect.github.com/jdx/mise/pull/9685)) by [@​dnwe](https://redirect.github.com/dnwe). #### Performance - **(pwsh)** Activation no longer spawns a fresh `pwsh -NoProfile -Command exit $status` (or `powershell` on PS 5) after every hook just to propagate mise's exit code — it now assigns `$global:LASTEXITCODE = $status` directly. On a typical machine that's \~270ms (`pwsh`) or \~185ms (`powershell`) shaved off every prompt ([#​9723](https://redirect.github.com/jdx/mise/pull/9723)) by [@​vemoo](https://redirect.github.com/vemoo). #### Changed - **(schema)** `xtasks/render/schema.ts` no longer overwrites `$defs.task_template` and the trailing `$defs.task.oneOf` branch on every `mise run render:schema`; those shapes already live in `schema/mise.json`, with lightweight guard checks remaining ([#​9680](https://redirect.github.com/jdx/mise/pull/9680)) by [@​risu729](https://redirect.github.com/risu729). #### Aqua Registry Updates New packages: - [`DataDog/managed-kubernetes-auditing-toolkit`](https://redirect.github.com/DataDog/managed-kubernetes-auditing-toolkit) - `oracle.com/sqlcl` Updated packages: - [`alltuner/mise-completions-sync`](https://redirect.github.com/alltuner/mise-completions-sync) - [`iann0036/iamlive`](https://redirect.github.com/iann0036/iamlive) - [`pnpm/pnpm`](https://redirect.github.com/pnpm/pnpm) **Full Changelog**: <jdx/mise@v2026.5.3...v2026.5.4> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.3`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.3): : Aqua latest from GitHub releases [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.5.2...v2026.5.3) A small patch release that fixes how the aqua backend resolves `latest` for tools backed by GitHub releases. #### Fixed - **(aqua)** Resolve `latest` via GitHub's latest-release endpoint instead of walking the chronological tag list, so `mise use <tool>@​latest` and similar requests pick the upstream "latest" release rather than the newest tag. Packages using `version_source = github_tag` continue to use the existing tag-based fallback, and `before_date` / `minimum_release_age` settings still bypass the fast path. Tag-to-version normalization (version prefixes, leading `v`, asset checks) is now shared across remote listing, install lookup, and latest resolution ([#​9277](https://redirect.github.com/jdx/mise/pull/9277)) by [@​risu729](https://redirect.github.com/risu729). **Full Changelog**: <jdx/mise@v2026.5.2...v2026.5.3> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.2`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.2): : Stable monorepo task roots, fail-fast parallel tasks, and curated lockfiles [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.5.1...vfox-v2026.5.2) #### Added - **(aqua)** Support registry libc variants (`gnu` vs `musl`) when resolving package overrides on Linux, including cross-platform lock targets like `linux-x64-musl` ([#​9652](https://redirect.github.com/jdx/mise/pull/9652)) by [@​jdx](https://redirect.github.com/jdx). - **(aqua)** Honor aqua registry `files[].link` and `files[].hard` entries, creating relative symlink (or hard link) aliases next to extracted binaries so tools that inspect `$0`/`argv[0]` (e.g. `granted`/`assumego`, newer `pnpm`) launch correctly ([#​9610](https://redirect.github.com/jdx/mise/pull/9610)) by [@​risu729](https://redirect.github.com/risu729). - **(bin-paths)** New `mise bin-paths --bin-names` flag prints executable names from active bin directories, and `--json` now emits structured entries with `name`, `path`, and `symlink` ([#​9617](https://redirect.github.com/jdx/mise/pull/9617)) by [@​risu729](https://redirect.github.com/risu729). - **(task)** Added `MISE_MONOREPO_ROOT` env var pointing at the directory of the config with `experimental_monorepo_root = true` ([#​9657](https://redirect.github.com/jdx/mise/pull/9657)) by [@​jdx](https://redirect.github.com/jdx). - **(registry)** Added `code-review-graph` via `pipx:code-review-graph` ([#​9673](https://redirect.github.com/jdx/mise/pull/9673)) by [@​chautruonglong](https://redirect.github.com/chautruonglong). #### Fixed - **(task)** Parallel `mise run --jobs N` siblings now terminate promptly when one task fails, via per-task process groups and `killpg`, with a 10s pipe-drain timeout ([#​9655](https://redirect.github.com/jdx/mise/pull/9655)) by [@​jdx](https://redirect.github.com/jdx). - **(task)** `MISE_PROJECT_ROOT` for monorepo subproject tasks is now stable regardless of invocation cwd ([#​9657](https://redirect.github.com/jdx/mise/pull/9657)) by [@​jdx](https://redirect.github.com/jdx). - **(install)** Don't force a remote-versions cache refresh in `prefer_offline` mode; fixes a v2026.5.0 regression with shim auto-install of `prefix:` requests ([#​9627](https://redirect.github.com/jdx/mise/pull/9627)) by [@​jdx](https://redirect.github.com/jdx). - **(lockfile)** Auto-lock during `mise install` now respects user-curated lockfiles — removed platforms stay removed ([#​9621](https://redirect.github.com/jdx/mise/pull/9621)) by [@​jdx](https://redirect.github.com/jdx). - **(lock)** `mise lock` from a nested project scopes targets to the active project root and stops churning parent lockfiles; `--global` is now exclusive ([#​9319](https://redirect.github.com/jdx/mise/pull/9319)) by [@​risu729](https://redirect.github.com/risu729). - **(deps)** Fall through to source-hash freshness when a provider returns no outputs, so `bundle install`, `pip install`, `go mod download`, `poetry install`, and `uv sync` stop rerunning on every invocation ([#​9622](https://redirect.github.com/jdx/mise/pull/9622)) by [@​jdx](https://redirect.github.com/jdx). - **(backend)** Inline tool option overrides (e.g. `tool[asset_pattern=...]`) are now applied consistently across all backends, with backend alias `[...]` options as a distinct overlay layer ([#​9306](https://redirect.github.com/jdx/mise/pull/9306)) by [@​risu729](https://redirect.github.com/risu729). - **(backend)** Skip the `mise-versions` host when locally overridden tool options affect remote version listing ([#​9568](https://redirect.github.com/jdx/mise/pull/9568)) by [@​risu729](https://redirect.github.com/risu729). - **(backend)** Reject bare package-backend names like `cargo` and `gem` as implicit `cargo:cargo`/`gem:gem` tools ([#​9608](https://redirect.github.com/jdx/mise/pull/9608)) by [@​risu729](https://redirect.github.com/risu729). - **(aqua)** Preserve configured file extensions (e.g. `.bat` scripts) on Windows; avoid doubling `version_prefix` ([#​9611](https://redirect.github.com/jdx/mise/pull/9611)) by [@​risu729](https://redirect.github.com/risu729). - **(github)** Chmod only the explicitly configured `bin` target instead of every archive file ([#​9609](https://redirect.github.com/jdx/mise/pull/9609)) by [@​risu729](https://redirect.github.com/risu729). - **(pipx)** Filter yanked PyPI releases from fuzzy/`latest` resolution while keeping exact pinned installs available ([#​9607](https://redirect.github.com/jdx/mise/pull/9607)) by [@​risu729](https://redirect.github.com/risu729). - **(pipx)** Declare `python` as a backend dependency so `pipx.pyz` resolves to mise-managed Python ([#​9678](https://redirect.github.com/jdx/mise/pull/9678)) by [@​jdx](https://redirect.github.com/jdx). - **(trust)** Run `enter` hooks after `mise trust` newly trusts a config for the current directory ([#​9634](https://redirect.github.com/jdx/mise/pull/9634)) by [@​risu729](https://redirect.github.com/risu729). - **(ui)** Stop clearing the screen for confirmation prompts like `mise prune` ([#​9619](https://redirect.github.com/jdx/mise/pull/9619)) by [@​jdx](https://redirect.github.com/jdx). - Use `/bin/cp` on macOS for `mise sync` so it doesn't break when GNU `cp` from Homebrew shadows it on `PATH` ([#​9656](https://redirect.github.com/jdx/mise/pull/9656)) by [@​pdehlke](https://redirect.github.com/pdehlke). - **(schema)** Update refs to `$defs` in `mise-registry-tool.json` ([#​9671](https://redirect.github.com/jdx/mise/pull/9671)) by [@​risu729](https://redirect.github.com/risu729). #### Changed - **(registry)** Removed registry-level `depends` from generated registry tools and added `test.tools` for tools whose dependencies are only needed by `mise test-tool` ([#​9571](https://redirect.github.com/jdx/mise/pull/9571)) by [@​risu729](https://redirect.github.com/risu729). - **(config)** Registry backend options now accept full TOML values (booleans, integers, arrays, tables) instead of strings only ([#​9584](https://redirect.github.com/jdx/mise/pull/9584)) by [@​risu729](https://redirect.github.com/risu729). #### Documentation - **(node)** Added tips for enabling node idiomatic version files ([#​9675](https://redirect.github.com/jdx/mise/pull/9675)) by [@​fu050409](https://redirect.github.com/fu050409). #### New Contributors - [@​chautruonglong](https://redirect.github.com/chautruonglong) made their first contribution in [#​9673](https://redirect.github.com/jdx/mise/pull/9673) - [@​pdehlke](https://redirect.github.com/pdehlke) made their first contribution in [#​9656](https://redirect.github.com/jdx/mise/pull/9656) #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.1`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.1): : Aqua cosign and a reshim rescue [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.5.0...vfox-v2026.5.1) A small follow-up to v2026.5.0 that lands top-level cosign verification for the aqua backend, fixes a `mise reshim` failure caused by stale `latest` install directories, and tightens schema validation. #### Added - **(backend)** The aqua backend now honors top-level `cosign` metadata when verifying packages, covering both checksum and artifact flows and reusing the existing native sigstore path. Lockfiles record top-level cosign provenance, with new e2e and lockfile regression coverage ([#​9111](https://redirect.github.com/jdx/mise/pull/9111)) by [@​risu729](https://redirect.github.com/risu729). - **(registry)** Added `wasm-tools` via `aqua:bytecodealliance/wasm-tools` for working with the WebAssembly Component Model ([#​9596](https://redirect.github.com/jdx/mise/pull/9596)) by [@​2xdevv](https://redirect.github.com/2xdevv). #### Fixed - **(shim)** `mise reshim` no longer aborts with `failed to rebuild shims: no versions found for <tool>` when an install directory literally named `latest` (or any other non-resolvable name) is left on disk. `Toolset::list_installed_versions` already reads concrete version directory names, so it now constructs `ToolVersion` directly instead of calling `.resolve()` (no network), and per-tool `ToolRequest::new` failures are warned-and-skipped instead of aborting the entire rebuild ([#​9599](https://redirect.github.com/jdx/mise/pull/9599)) by [@​jdx](https://redirect.github.com/jdx). Repro: ```sh mkdir -p ~/.mise/installs/buck2/latest/bin touch ~/.mise/installs/buck2/latest/bin/buck2 mise reshim # previously failed; now succeeds ``` - **(schema)** All files under `schema/` are now validated against `draft/2020-12` in strict mode. Hand-written schemas and the `BoolOrString` renderer in `schema.ts` use `oneOf` instead of union type arrays so AJV's `strictTypes` no longer rejects them; the bogus `--strict-schema` flag is replaced with `--strict-types=true --strict-tuples=true` ([#​9594](https://redirect.github.com/jdx/mise/pull/9594)) by [@​risu729](https://redirect.github.com/risu729). - **(registry)** `elixir-ls` re-enables `symlink_bins` so the move to the aqua backend stops exposing internal binaries that aren't meant to be called directly ([#​9592](https://redirect.github.com/jdx/mise/pull/9592)) by [@​AlternateRT](https://redirect.github.com/AlternateRT). #### Changed - **(registry)** `rebar` now installs from the GitHub backend (`erlang/rebar3`) since rebar3 is just an `escript`; the asdf plugin fallback is removed. Versions before rebar 3 are no longer supported, and the installed executable remains `rebar3` to match upstream docs ([#​9576](https://redirect.github.com/jdx/mise/pull/9576)) by [@​risu729](https://redirect.github.com/risu729). - **(registry)** `bashly` drops the `asdf:mise-plugins/mise-bashly` fallback and the redundant explicit `ruby` dependency, since the `gem` backend already pulls in Ruby ([#​9578](https://redirect.github.com/jdx/mise/pull/9578)) by [@​risu729](https://redirect.github.com/risu729). - **(release)** Restored the "Sponsor mise" block on every successful GitHub release. It had been accidentally scoped to the communique-failure fallback in [#​9395](https://redirect.github.com/jdx/mise/pull/9395), so normal releases since v2026.4.22 lost it ([#​9580](https://redirect.github.com/jdx/mise/pull/9580)) by [@​jdx](https://redirect.github.com/jdx). #### Documentation - **(dev-tools)** Clarified that vfox metadata `depends` runs install hooks for the listed dependency tools ([#​9573](https://redirect.github.com/jdx/mise/pull/9573)) by [@​risu729](https://redirect.github.com/risu729). - **(plugins)** Removed outdated registry submission guidance from the plugins docs ([#​9577](https://redirect.github.com/jdx/mise/pull/9577)) by [@​risu729](https://redirect.github.com/risu729). #### Aqua Registry Updates New packages: - [`salesforce/reactive-grpc/protoc-gen-reactor-grpc`](https://redirect.github.com/salesforce/reactive-grpc) - [`spinframework/spin`](https://redirect.github.com/spinframework/spin) Updated: - [`pnpm/pnpm`](https://redirect.github.com/pnpm/pnpm) **Full Changelog**: <jdx/mise@v2026.5.0...v2026.5.1> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Documents prometheus#1411. Adds documentation for the PushGateway runtime issue seen with shaded jars when removes protobuf classes loaded via reflection. Changes: - add a troubleshooting note to the PushGateway docs - clarify the shading and dependency requirements for protobuf exposition --------- Signed-off-by: ADITYA-CODE-SOURCE <adityavishe67@gmail.com> Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com> Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
) This PR contains the following updates: | Package | Update | Change | |---|---|---| | grafana/k6 | digest | `50e5517` → `632ddbc` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTkuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE1OS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
## What changed - upgraded the Flint runtime in `mise.toml` to `aqua:grafana/flint@0.22.2` - migrated obsolete tool declarations that Flint now rewrites automatically - replaced `codespell` with `typos` - refreshed `.github/renovate-tracked-deps.json` - added targeted regex-based `_typos.toml` ignores for intentional tokens and fixture content ## Why This validates the Flint `v0.22.2` rollout on another consumer repo using the same migration policy: - no source-content rewrites to satisfy `typos` - use targeted regex ignores instead of broad word allowlists where practical - leave Renovate preset bumps to Renovate ## Validation - `mise run lint` ## Notes - `mise run test` failed in this checkout, but the failure appears unrelated to this Flint-only config change. The failing tests error on Java `Map.of(...)` compilation in existing test sources under `prometheus-metrics-config`.
Fixes prometheus#2095 ## Summary Restores OM1/protobuf compatibility for dotted gauge names after `feat: move suffix handling to scrape time (prometheus#1955)`. The bug was that non-OpenMetrics exposition changed visible output for gauge names that merely ended in suffix-like dotted strings such as `.created` and `.total`. Examples: - `Gauge("test3.created")` regressed from `test3` to `test3_created` - `Gauge("test6.total")` regressed from `test6` to `test6_total` This PR restores the legacy OM1/protobuf behavior while keeping OpenMetrics on literal-name handling. This is the extracted prom-side fix from prometheus#2093. The Micrometer workflow and related downstream testing were split into a stacked follow-up PR so this can merge independently. ## What changed - Fix OM1 text exposition for dotted gauge names ending in `.created` and `.total` - Fix protobuf exposition for the same compatibility cases - Add regression tests that cover the restored OM1/protobuf behavior and the preserved OpenMetrics behavior - Clean up protobuf family-name resolution so legacy gauge handling lives in one path instead of pre-rewriting metadata objects ## Follow-up stacked PR - Micrometer workflow/task split: #1 ## Related - Replaces: prometheus#2093 - Issue: prometheus#2095 ## Testing - `mise run build` - `mise run lint` - `./mvnw test -pl prometheus-metrics-exposition-textformats,prometheus-metrics-exposition-formats -Dtest=ExpositionFormatsTest,ProtobufExpositionFormatsTest,DuplicateNamesProtobufTest -Dcoverage.skip=true -Dcheckstyle.skip=true`
…o v0.152.0 (prometheus#2111) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [otel/opentelemetry-collector-contrib](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases) | minor | `0.151.0` → `0.152.0` | --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-collector-releases (otel/opentelemetry-collector-contrib)</summary> ### [`v0.152.0`](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/blob/HEAD/CHANGELOG.md#v01520) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/compare/v0.151.0...v0.152.0) ##### 🚀 New components 🚀 - `drainprocessor`: Add drain processor to contrib distribution. ([#​47235](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/47235)) - `drainprocessor`: Add drain processor to k8s distribution. ([#​47235](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/47235)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…62e8 (prometheus#2113) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | eclipse-temurin | final | digest | `9c9e7c4` → `04262e8` | | eclipse-temurin | | digest | `9c9e7c4` → `04262e8` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…metheus#2112) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.slf4j:slf4j-simple](http://www.slf4j.org) ([source](https://redirect.github.com/qos-ch/slf4j), [changelog](https://www.slf4j.org/news.html)) | `2.0.17` → `2.0.18` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzMuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE3My42IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grafana/flint](https://redirect.github.com/grafana/flint) | minor | `v0.21.0` → `v0.22.2` | --- ### Release Notes <details> <summary>grafana/flint (grafana/flint)</summary> ### [`v0.22.2`](https://redirect.github.com/grafana/flint/releases/tag/v0.22.2) [Compare Source](https://redirect.github.com/grafana/flint/compare/v0.22.1...v0.22.2) ##### Fixed - *(release)* dispatch renamed release workflow ([#​291](https://redirect.github.com/grafana/flint/pull/291)) ### [`v0.22.1`](https://redirect.github.com/grafana/flint/compare/v0.22.0...v0.22.1) [Compare Source](https://redirect.github.com/grafana/flint/compare/v0.22.0...v0.22.1) ### [`v0.22.0`](https://redirect.github.com/grafana/flint/releases/tag/v0.22.0) [Compare Source](https://redirect.github.com/grafana/flint/compare/v0.21.0...v0.22.0) ##### Added - replace codespell with typos ([#​269](https://redirect.github.com/grafana/flint/pull/269)) - *(lychee)* add local cache for local runs ([#​268](https://redirect.github.com/grafana/flint/pull/268)) ##### Fixed - *(renovate-deps)* surface real renovate failure in error output ([#​278](https://redirect.github.com/grafana/flint/pull/278)) - *(ci)* drop double release-plz update from release:pr ([#​276](https://redirect.github.com/grafana/flint/pull/276)) - *(init)* normalize node runtime before linters ([#​267](https://redirect.github.com/grafana/flint/pull/267)) - *(renovate)* support block-scalar mise sha256 values ([#​266](https://redirect.github.com/grafana/flint/pull/266)) - *(mise)* migrate flint-managed tools to supported backends ([#​258](https://redirect.github.com/grafana/flint/pull/258)) - validate renovate dependency rule coverage ([#​263](https://redirect.github.com/grafana/flint/pull/263)) - make flint-setup state-based ([#​252](https://redirect.github.com/grafana/flint/pull/252)) - *(init)* let rustfmt own Rust line length ([#​250](https://redirect.github.com/grafana/flint/pull/250)) - run renovate-deps for deleted tracked files ([#​247](https://redirect.github.com/grafana/flint/pull/247)) - validate CI env and isolate check types ([#​253](https://redirect.github.com/grafana/flint/pull/253)) - *(init)* remove stale head sha from CI snippets ([#​248](https://redirect.github.com/grafana/flint/pull/248)) - *(init)* enable yamllint indentation rule ([#​251](https://redirect.github.com/grafana/flint/pull/251)) ##### Other - streamline README getting started ([#​280](https://redirect.github.com/grafana/flint/pull/280)) - *(deps)* update taiki-e/install-action digest to [`fa0dd4c`](https://redirect.github.com/grafana/flint/commit/fa0dd4c) ([#​282](https://redirect.github.com/grafana/flint/pull/282)) - *(deps)* lock file maintenance ([#​285](https://redirect.github.com/grafana/flint/pull/285)) - *(deps)* update dependency mise to v2026.5.2 ([#​284](https://redirect.github.com/grafana/flint/pull/284)) - *(deps)* update dependency go to v1.26.3 ([#​283](https://redirect.github.com/grafana/flint/pull/283)) - *(deps)* update taiki-e/install-action digest to [`e3134ec`](https://redirect.github.com/grafana/flint/commit/e3134ec) ([#​281](https://redirect.github.com/grafana/flint/pull/281)) - pass git-token and forge to release-plz ([#​274](https://redirect.github.com/grafana/flint/pull/274)) - *(deps)* update taiki-e/install-action digest to [`3fa6878`](https://redirect.github.com/grafana/flint/commit/3fa6878) ([#​275](https://redirect.github.com/grafana/flint/pull/275)) - *(deps)* bump renovate to 43.150.0 ([#​273](https://redirect.github.com/grafana/flint/pull/273)) - \[**breaking**] drop --fast-only flag and tighten renovate-deps timing ([#​270](https://redirect.github.com/grafana/flint/pull/270)) - *(deps)* update rust crate tokio to v1.52.2 ([#​272](https://redirect.github.com/grafana/flint/pull/272)) - upgrade lychee to v0.24.2 ([#​265](https://redirect.github.com/grafana/flint/pull/265)) - *(deps)* update taiki-e/install-action digest to [`cca35ed`](https://redirect.github.com/grafana/flint/commit/cca35ed) ([#​254](https://redirect.github.com/grafana/flint/pull/254)) - *(deps)* update dependency aqua:owenlamont/ryl to v0.8.0 ([#​261](https://redirect.github.com/grafana/flint/pull/261)) - *(deps)* update dependency mise to v2026.4.28 ([#​262](https://redirect.github.com/grafana/flint/pull/262)) - *(deps)* update dependency golangci-lint to v2.12.1 ([#​264](https://redirect.github.com/grafana/flint/pull/264)) - *(deps)* update dependency aqua:owenlamont/ryl to v0.7.0 ([#​259](https://redirect.github.com/grafana/flint/pull/259)) - *(renovate)* simplify quickstart and batch weekly linter updates ([#​257](https://redirect.github.com/grafana/flint/pull/257)) - *(deps)* update dependency npm:renovate to v43.141.6 ([#​255](https://redirect.github.com/grafana/flint/pull/255)) - expand positioning and comparisons ([#​239](https://redirect.github.com/grafana/flint/pull/239)) - *(deps)* update taiki-e/install-action digest to [`1f2425c`](https://redirect.github.com/grafana/flint/commit/1f2425c) ([#​246](https://redirect.github.com/grafana/flint/pull/246)) - move release-plz flow into mise tasks ([#​234](https://redirect.github.com/grafana/flint/pull/234)) - *(deps)* update taiki-e/install-action digest to [`481c34c`](https://redirect.github.com/grafana/flint/commit/481c34c) ([#​231](https://redirect.github.com/grafana/flint/pull/231)) - *(deps)* update dependency ruff to v0.15.12 ([#​245](https://redirect.github.com/grafana/flint/pull/245)) - *(deps)* update dependency npm:renovate to v43.141.5 ([#​244](https://redirect.github.com/grafana/flint/pull/244)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [mise](https://redirect.github.com/jdx/mise) | patch | `v2026.5.5` → `v2026.5.11` | --- ### Release Notes <details> <summary>jdx/mise (mise)</summary> ### [`v2026.5.11`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.11): : Provenance verification at lock time [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.10...v2026.5.11) #### Added - **(security)** Verify and record provenance during `mise lock`, with a new `provenance_api_failures_fatal` setting to control whether GitHub attestation API failures are fatal ([#​9945](https://redirect.github.com/jdx/mise/pull/9945) by [@​jdx](https://redirect.github.com/jdx)). - **(security)** Fall back to verifying archive contents when SLSA provenance attests every file inside an archive but not the archive itself, fixing releases like `github:prefix-dev/pixi@0.68.1` ([#​9898](https://redirect.github.com/jdx/mise/pull/9898) by [@​sargunv](https://redirect.github.com/sargunv)). - **(plugins)** Support remote git subdirectory sources for plugins, e.g. `git::https://host/repo.git//path/to/plugin?ref=branch` ([#​9893](https://redirect.github.com/jdx/mise/pull/9893) by [@​jdx](https://redirect.github.com/jdx)). #### Fixed - **(github)** Asset picker now picks the shortest matching name as a tiebreaker for `asset_pattern` and accepts platform-agnostic runtime archives like `.phar`, `.jar`, and `.pyz` (fixes installing `composer`) ([#​9946](https://redirect.github.com/jdx/mise/pull/9946) by [@​jdx](https://redirect.github.com/jdx)). - **(config)** Invalid `miserc.toml` now produces a clear parse error at startup instead of being silently ignored ([#​9937](https://redirect.github.com/jdx/mise/pull/9937) by [@​jdx](https://redirect.github.com/jdx)). - **(install)** Per-tool `.mise.backend.toml` metadata is now written alongside install directories, making merged/copied installs self-describing and refreshing install state mid-run so same-run dependency resolution sees freshly installed tools ([#​9941](https://redirect.github.com/jdx/mise/pull/9941) by [@​jdx](https://redirect.github.com/jdx)). - **(install)** `postinstall` hooks now run through the configured default inline shell instead of `$SHELL -c` ([#​9812](https://redirect.github.com/jdx/mise/pull/9812) by [@​risu729](https://redirect.github.com/risu729)). - **(cache)** `mise cache prune [PLUGIN]...` now honors the plugin filter instead of pruning every cache directory ([#​9914](https://redirect.github.com/jdx/mise/pull/9914) by [@​risu729](https://redirect.github.com/risu729)). - **(task)** Preserve task-declared env, `MISE_TASK_*` metadata, and `MISE_ENV` across nested `hook-env` invocations, while keeping the nested-PATH fix from [#​9765](https://redirect.github.com/jdx/mise/pull/9765) intact ([#​9850](https://redirect.github.com/jdx/mise/pull/9850) by [@​risu729](https://redirect.github.com/risu729)). - **(backend)** Resolve helper dependency toolsets in offline mode so `minimum_release_age` cannot mis-route helper tools like `node`/`npm` when querying upstream versions ([#​9808](https://redirect.github.com/jdx/mise/pull/9808) by [@​risu729](https://redirect.github.com/risu729)). - **(vfox)** Key vfox `EnvKeys` hooks by the resolved install path so shared/system installs don't reuse user-path cache entries ([#​9907](https://redirect.github.com/jdx/mise/pull/9907) by [@​risu729](https://redirect.github.com/risu729)). - **(use)** Skip the `mise use -g` shadow warning when the active version comes from system config ([#​9900](https://redirect.github.com/jdx/mise/pull/9900) by [@​risu729](https://redirect.github.com/risu729)). - **(doctor)** List installed plugins from install state, including those owned by disabled backends, and add a `plugins` object to `mise doctor -J` ([#​9863](https://redirect.github.com/jdx/mise/pull/9863) by [@​risu729](https://redirect.github.com/risu729)). - **(erlang)** `erlang.compile = false` is now strict precompiled mode and no longer falls back to `kerl build-install` on unsupported distros ([#​9866](https://redirect.github.com/jdx/mise/pull/9866) by [@​risu729](https://redirect.github.com/risu729)). #### Changed - **(registry)** Prefer the `aqua` backend for `cilium-hubble`, `localstack`, `mark`, `openbao`, `porter`, `process-compose`, `rtk`, `sqlc`, `turso`, and `xcodegen`, with existing GitHub/asdf backends preserved as fallbacks ([#​9789](https://redirect.github.com/jdx/mise/pull/9789) by [@​risu729](https://redirect.github.com/risu729)). - **(registry)** Add `aqua:jbangdev/jbang` as the primary backend for `jbang`, enabling Windows support ([#​9811](https://redirect.github.com/jdx/mise/pull/9811) by [@​risu729](https://redirect.github.com/risu729)). - **(registry)** Alias `dotnet-core` to `dotnet` ([#​9807](https://redirect.github.com/jdx/mise/pull/9807) by [@​risu729](https://redirect.github.com/risu729)). - **(registry)** Add [`lisette`](https://lisette.run/) ([#​9944](https://redirect.github.com/jdx/mise/pull/9944) by [@​ivov](https://redirect.github.com/ivov)). - **(registry)** Fix `sourcery` archive format so macOS installs use the `.zip` asset instead of trying to extract it as `tar.gz` ([#​9902](https://redirect.github.com/jdx/mise/pull/9902) by [@​risu729](https://redirect.github.com/risu729)). - **(docs)** Trim the global settings example in the configuration docs ([#​9912](https://redirect.github.com/jdx/mise/pull/9912) by [@​risu729](https://redirect.github.com/risu729)). #### New Contributors - [@​ivov](https://redirect.github.com/ivov) made their first contribution in [#​9944](https://redirect.github.com/jdx/mise/pull/9944) #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.10`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.10): : AWS SSO for s3 backends [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.9...v2026.5.10) A small release that unblocks s3 backends for users on AWS SSO profiles, plus two minor option-handling fixes that fell out of an internal refactor of the GitHub/GitLab/Forgejo backend. #### Fixed - **(s3)** s3 backends now work with SSO-based AWS profiles. The `sso` feature of `aws-config` is enabled, so configurations that authenticate via [AWS IAM Identity Center](https://aws.amazon.com/iam/identity-center/) no longer fail with: ``` S3 error: DispatchFailure { ... ProfileFile provider could not be built: This behavior requires following cargo feature(s) enabled: sso. ``` ([#​9875](https://redirect.github.com/jdx/mise/pull/9875) by [@​Amir-Ahmad](https://redirect.github.com/Amir-Ahmad)). - **(backend)** Two small behavior fixes landed while centralizing Git backend option reads ([#​9838](https://redirect.github.com/jdx/mise/pull/9838) by [@​risu729](https://redirect.github.com/risu729)): - Forgejo now applies the same install-time option filtering as GitHub/GitLab. - `no_app` is now read through target-aware platform option lookup, so `platforms.<target>.no_app = true` is honored when resolving assets for cross-platform lockfiles. #### Changed - **(backend)** Internal refactor introducing a shared `BackendOptions` reader and a typed option wrapper for the unified GitHub/GitLab/Forgejo backend. No user-visible behavior change beyond the fixes above ([#​9838](https://redirect.github.com/jdx/mise/pull/9838) by [@​risu729](https://redirect.github.com/risu729)). #### New Contributors - [@​Amir-Ahmad](https://redirect.github.com/Amir-Ahmad) made their first contribution in [#​9875](https://redirect.github.com/jdx/mise/pull/9875) **Full Changelog**: <jdx/mise@v2026.5.9...v2026.5.10> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.9`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.9): : SwiftPM artifact bundles and per-hook watch shells [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.8...v2026.5.9) A modest release: SwiftPM gains artifact bundle support, `[[watch_files]]` hooks can pick their own inline shell, and a handful of fixes land for aqua latest-tag resolution, vfox `cmd.exec`, and GitHub OAuth device-flow URLs. Plain-string Tera rendering also gets a fast path. #### Added - **(spm)** SwiftPM installs now prefer prebuilt artifact bundles (`*.artifactbundle.zip`) when a release publishes one for the current Swift target triple, falling back to a source build otherwise ([#​9825](https://redirect.github.com/jdx/mise/pull/9825)) by [@​ikesyo](https://redirect.github.com/ikesyo). New controls: ```toml [tools] # require an artifact bundle; fail instead of source-building "spm:giginet/swift-testing-revolutionary" = { version = "0.4.0", artifactbundle = true } # always source-build, ignore any bundles "spm:tuist/tuist" = { version = "latest", artifactbundle = false } # disambiguate when multiple bundle assets are published "spm:org/tool" = { version = "1.0.0", artifactbundle_asset = "tool.artifactbundle.zip" } [settings] # apply "bundles only" globally (mirrors cargo.binstall_only) spm.artifactbundle_only = true ``` - **(config)** `[[watch_files]]` entries with `run` accept an optional `shell` field, rendered through templates and falling back to the configured default inline shell when unset ([#​9810](https://redirect.github.com/jdx/mise/pull/9810)) by [@​risu729](https://redirect.github.com/risu729): ```toml [[watch_files]] patterns = ["*.js"] run = "eslint --fix ." shell = "bash -c" ``` `shell` only applies to `run` hooks; combining it with `task` produces a warning and the value is ignored. #### Fixed - **(aqua)** When GitHub's `latest` release pointed at a tag that aqua's registry rejected via `version_filter` or `version_constraint`, mise would return it anyway. The latest fast path now applies both checks before accepting a tag ([#​9834](https://redirect.github.com/jdx/mise/pull/9834)) by [@​risu729](https://redirect.github.com/risu729). - **(vfox)** Lua `cmd.exec` calls inside vfox plugins now build commands from mise's configured `unix_default_inline_shell_args` / `windows_default_inline_shell_args` instead of hardcoding `sh -c` or `cmd /C`, aligning plugin behavior with tasks, Tera command rendering, and other inline shell users ([#​9837](https://redirect.github.com/jdx/mise/pull/9837)) by [@​risu729](https://redirect.github.com/risu729). - GitHub OAuth device-flow paths were slightly off compared to the documented endpoints. The default `oauth_auth_url` is now the GitHub login base, with mise appending `/device/code` and `/oauth/access_token` per [GitHub's device-flow docs](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/authorizing-oauth-apps#device-flow) ([#​9791](https://redirect.github.com/jdx/mise/pull/9791)) by [@​jasisk](https://redirect.github.com/jasisk). - **(patrons)** `mise patrons` now points the "become a patron" link to the en.dev homepage instead of `/sponsor` ([#​9868](https://redirect.github.com/jdx/mise/pull/9868)) by [@​jdx](https://redirect.github.com/jdx). #### Changed - **(registry)** `npm` is now resolved through `aqua:npm/cli` (with `npm:npm` retained as a fallback), and `buck2` switches to `aqua:facebook/buck2` with `prerelease = true` so its always-prerelease releases are visible ([#​9762](https://redirect.github.com/jdx/mise/pull/9762), [#​9805](https://redirect.github.com/jdx/mise/pull/9805)) by [@​risu729](https://redirect.github.com/risu729). - **(registry)** Added SonarQube CLI as `aqua:SonarSource/sonarqube-cli` ([#​9824](https://redirect.github.com/jdx/mise/pull/9824)) by [@​3PeatVR](https://redirect.github.com/3PeatVR). #### Performance - **(config)** Strings with no Tera block markers (`{{`, `{%`, `{#`, including whitespace-trimmed forms) now bypass the Tera renderer at config evaluation sites, skipping context construction, async context fetches, and `get_tera` setup. Tera 1.20.1's grammar guarantees these are the only block openers, so output is unchanged for both well-formed and malformed templates ([#​9833](https://redirect.github.com/jdx/mise/pull/9833)) by [@​risu729](https://redirect.github.com/risu729). #### Documentation - Updated the Walkthrough guide ([#​9853](https://redirect.github.com/jdx/mise/pull/9853)) by [@​thernstig](https://redirect.github.com/thernstig). #### New Contributors - [@​3PeatVR](https://redirect.github.com/3PeatVR) made their first contribution in [#​9824](https://redirect.github.com/jdx/mise/pull/9824) - [@​ikesyo](https://redirect.github.com/ikesyo) made their first contribution in [#​9825](https://redirect.github.com/jdx/mise/pull/9825) - [@​thernstig](https://redirect.github.com/thernstig) made their first contribution in [#​9853](https://redirect.github.com/jdx/mise/pull/9853) **Full Changelog**: <jdx/mise@v2026.5.8...v2026.5.9> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.8`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.8): : Patrons, cleaner task output, and sigstore-rust [Compare Source](https://redirect.github.com/jdx/mise/compare/aqua-registry-v2026.5.7...v2026.5.8) A small release: a new `mise patrons` command, cleaner task command output when scripts start with a shebang, and a fix for `mise upgrade` summaries getting wiped by progress cleanup. Under the hood, signature verification moves to the modern sigstore-rust stack. #### Added - **(patrons)** New `mise patrons` subcommand lists individuals on the Patron tier supporting mise development ([#​9841](https://redirect.github.com/jdx/mise/pull/9841)) by [@​jdx](https://redirect.github.com/jdx). Data is fetched from the en.dev patrons feed, cached for 24h, and falls back to stale cache on network failure. Each patron's name renders as a clickable OSC 8 hyperlink in supporting terminals. ``` $ mise patrons mise is supported by these patrons — thank you • Ronald Gierlach • youfoundron Become a patron: https://en.dev/sponsor ``` Flags: `-J/--json`, `--refresh`. - **(registry)** Add a `racket` shorthand backed by the aqua `racket/racket/minimal` package, exposing both `racket` and `raco` from the official racket-lang.org release artifacts ([#​9784](https://redirect.github.com/jdx/mise/pull/9784)) by [@​albertnetymk](https://redirect.github.com/albertnetymk). #### Fixed - **(task)** When a task's `run` body starts with `#!/usr/bin/env bash` or `set -Eeuo pipefail`, the echoed command line would show only that boilerplate and hide the rest of the script. Leading shebang, blank, and `set ...` lines are now skipped when building the displayed command, so the first real command shows up. Execution is unchanged ([#​9844](https://redirect.github.com/jdx/mise/pull/9844)) by [@​jdx](https://redirect.github.com/jdx). Fixes [#​9842](https://redirect.github.com/jdx/mise/issues/9842). ``` # before [generate-completions] $ #!/usr/bin/env bash # after [generate-completions] $ fzf --fish > ~/.config/fish/completions/fzf.fish ``` - **(upgrade)** `mise upgrade` could erase its own `Upgraded N tools:` summary detail lines when an upgrade also performed an uninstall — fresh progress jobs registered for the cleanup phase were still active at shutdown, so `stop_clear()` wiped them along with the summary. Progress jobs are now finished and reset before the summary prints ([#​9860](https://redirect.github.com/jdx/mise/pull/9860)) by [@​risu729](https://redirect.github.com/risu729). Regression from [#​9779](https://redirect.github.com/jdx/mise/pull/9779); addresses [#​9856](https://redirect.github.com/jdx/mise/discussions/9856). #### Changed - **(security)** Sigstore verification (`verify_github_attestation`, `verify_cosign_signature`, `verify_slsa_provenance`, `detect_attestations`) now runs on a local `mise-sigstore` adapter built on `sigstore-verify` 0.7 from sigstore-rust, replacing the previous `sigstore-verification` 0.2 dependency ([#​9260](https://redirect.github.com/jdx/mise/pull/9260)) by [@​jdx](https://redirect.github.com/jdx). The mise call sites and helper API are unchanged. The new adapter still covers legacy cosign v1 bundles (e.g. goreleaser-signed releases) and raw DSSE `*.intoto.jsonl` envelopes (slsa-github-generator) that the upstream `Bundle::from_json` rejects. #### Deprecated - **(config)** The top-level `env_file` setting (and `MISE_ENV_FILE`) is now marked deprecated. Use `env._.file` in `mise.toml` instead ([#​9862](https://redirect.github.com/jdx/mise/pull/9862)) by [@​risu729](https://redirect.github.com/risu729). The JSON Schema gains the `deprecated` keyword, a warning is scheduled for 2026.11.0, and removal is planned for 2027.11.0. ```toml # before env_file = ".env" # after [env] _.file = ".env" ``` #### New Contributors - [@​albertnetymk](https://redirect.github.com/albertnetymk) made their first contribution in [#​9784](https://redirect.github.com/jdx/mise/pull/9784) **Full Changelog**: <jdx/mise@v2026.5.7...v2026.5.8> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.7`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.7): : Lazy GitHub tokens, hardened version parsing, and faster task freshness [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.6...aqua-registry-v2026.5.7) A round of correctness and performance fixes: vfox-managed tools no longer prompt your password manager on every shell hook, `mise upgrade` stops double-printing its summary, `mise settings get` finally distinguishes typos from unset values, and conda installs that pulled in `adwaita-icon-theme` are unstuck. Plus a security pass that hardens version-string parsing against shell injection. #### Fixed - **(vfox)** GitHub tokens are now resolved lazily inside Lua plugins. Previously, `mise hook-env`, `mise activate`, `mise completion`, and even `mise --help` would call `github.credential_command` for every installed vfox tool — potentially unlocking a password manager on every prompt. The resolver is now only invoked when a Lua plugin actually issues an HTTP request to a GitHub API URL, e.g. during an install ([#​9816](https://redirect.github.com/jdx/mise/pull/9816)) by [@​jdx](https://redirect.github.com/jdx). Fixes [#​9797](https://redirect.github.com/jdx/mise/issues/9797). - **(upgrade)** `mise upgrade` (and `mise up`) no longer prints the installed-tools block twice when an upgrade also needs to uninstall an older version. The shared progress-job registry is now cleared after each phase so the subsequent uninstall renders cleanly ([#​9779](https://redirect.github.com/jdx/mise/pull/9779)) by [@​jdx](https://redirect.github.com/jdx). Fixes [#​9774](https://redirect.github.com/jdx/mise/issues/9774). - **(settings)** `mise settings get` distinguishes between a known setting that hasn't been set and a typo: ```sh $ mise settings get python.compile mise ERROR Setting [python.compile] is not set $ mise settings get not.a.real.setting mise ERROR Unknown setting: not.a.real.setting ``` Previously both returned `Unknown setting`, since `Option<T>` fields skipped by TOML serialization were indistinguishable from missing keys ([#​9818](https://redirect.github.com/jdx/mise/pull/9818)) by [@​jdx](https://redirect.github.com/jdx). - **(backend)** Several backends (`aqua`, `github`/`gitlab`/`forgejo`, `http`, `s3`, `ubi`, `vfox`, `conda`, Windows `npm`) reported `bin-paths` pointing at the concrete resolved install dir (e.g. `installs/tiny/1.0.0/...`) instead of the stable runtime symlink for the requested label (e.g. `installs/tiny/latest/...`). A new `runtime_path_for_install_path` helper remaps backend-discovered absolute paths onto the runtime path while leaving explicit relative `bin_path` values alone ([#​9606](https://redirect.github.com/jdx/mise/pull/9606)) by [@​risu729](https://redirect.github.com/risu729). - **(conda)** `mise use -g imagemagick` (and other tools pulling in `adwaita-icon-theme`) failed with `conda solve failed: encountered duplicate records for adwaita-icon-theme-40.1.1-...`. rattler-solve detects duplicates by `DistArchiveIdentifier` rather than URL, so when conda-forge served the same archive under multiple CDN URLs, the existing URL-based dedup wasn't enough. Dedup now uses `r.identifier`, the exact key the solver uses ([#​9831](https://redirect.github.com/jdx/mise/pull/9831)) by [@​jdx](https://redirect.github.com/jdx). Fixes [#​9829](https://redirect.github.com/jdx/mise/discussions/9829). #### Added - **(github)** `github.credential_command` now runs through the configured default inline shell (instead of hardcoded `sh -c`) and is invoked with `MISE_CREDENTIAL_HOST` and `MISE_CREDENTIAL_PROVIDER` in the environment. The deprecated `$1` / `${1}` hostname positional argument continues to work for sh-compatible shells (`ash`, `bash`, `dash`, `ksh`, `sh`, `zsh`); a deprecation warning lands in `2026.11.0` and removal is planned for `2027.11.0` ([#​9664](https://redirect.github.com/jdx/mise/pull/9664)) by [@​risu729](https://redirect.github.com/risu729). #### Performance - **(aqua)** The baked aqua standard-registry package and alias lookup tables are now generated as static `phf::Map`s at build time via `phf_codegen`, instead of lazy runtime `HashMap`s. Warmed lookup is comparable, but first-use no longer allocates \~115 KiB of heap or builds a 2,179-entry bucket table ([#​9763](https://redirect.github.com/jdx/mise/pull/9763)) by [@​risu729](https://redirect.github.com/risu729). - **(task)** When `task.source_freshness_hash_contents = true`, mise now caches each source file's blake3 hash keyed by `(size, mtime_secs, mtime_nanos)` — git's stat-info trick — in a per-task file under `STATE/task-sources/`. Unchanged files are skipped on subsequent runs; entries for files removed from `sources` are pruned automatically ([#​9819](https://redirect.github.com/jdx/mise/pull/9819)) by [@​jdx](https://redirect.github.com/jdx). See [discussion #​9802](https://redirect.github.com/jdx/mise/discussions/9802). #### Security - **Reject shell metacharacters in version strings at the `ToolRequest` boundary** ([#​9814](https://redirect.github.com/jdx/mise/pull/9814)) by [@​jdx](https://redirect.github.com/jdx). `ToolRequest::new` now validates `version`, `prefix`, `ref/*`, `sub-*`, and `path:` requests, rejecting `$`, backticks, quotes, `\`, control chars, and `..` traversal. This single change neutralizes the CRITICAL RCE class flagged against `vfox-ag`, `vfox-bfs`, `vfox-bpkg`, `vfox-chezscheme`, `vfox-redis`, `vfox-yarn`, and shell-injection findings on `clickhouse`, `leiningen`, `pipenv`, `poetry`, `azure-functions-core-tools`, `carthage`, and `android-sdk`, since no Lua hook can observe a hostile `ctx.version` / `ctx.rootPath`. Real-world strings like `1.2.3-beta`, `lts/hydrogen`, `3.12.0a1`, and `nightly` continue to validate. The PR also tightens `workflow_dispatch` input validation in the COPR, PPA, npm-publish, and Docker workflows. #### Registry - Replace unsupported `exe = ...` options across \~30 GitHub/GitLab registry entries (`astro`, `babashka`, `coursier`, `glab`, `odin`, `openbao`, `purescript`, and many more) ([#​9587](https://redirect.github.com/jdx/mise/pull/9587)) by [@​risu729](https://redirect.github.com/risu729). Two entries gained real config to fix Linux installs: - `solidity` now uses `bin = "solc"` so the installed binary matches the upstream `solc-static-linux` asset. - `sourcery` now uses `format = "tar.gz"` because the upstream Linux asset is gzip-compressed despite its `.tar.xz` filename. - Update `pi` to `earendil-works/pi` ([#​9792](https://redirect.github.com/jdx/mise/pull/9792)) by [@​garysassano](https://redirect.github.com/garysassano). #### Documentation - **(aliases)** Fix the Aliased Versions example and drop the stale asdf callout ([#​9830](https://redirect.github.com/jdx/mise/pull/9830)) by [@​jdx](https://redirect.github.com/jdx). **Full Changelog**: <jdx/mise@v2026.5.6...v2026.5.7> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. ### [`v2026.5.6`](https://redirect.github.com/jdx/mise/releases/tag/v2026.5.6): : Native GitHub OAuth, project-scoped OCI builds, faster registries [Compare Source](https://redirect.github.com/jdx/mise/compare/v2026.5.5...v2026.5.6) A mix of features and correctness work: a native GitHub OAuth token source (experimental) that drops the dependency on `gh`/`ghtkn`, `mise oci` commands scoped to the current project by default, and two registry-lookup performance wins — plus fixes across activate, exec, java, lock, pipx, and vfox. #### Added - **(cli)** Add `--before <date>` to `mise ls-remote` and `mise lock` for release-date-aware version discovery ([#​9269](https://redirect.github.com/jdx/mise/pull/9269)) by [@​risu729](https://redirect.github.com/risu729) - **(config)** Hooks can now be defined as a table — `{ run = "...", shell = "bash -c" }` — to pick a shell inline, alongside the existing string form ([#​9718](https://redirect.github.com/jdx/mise/pull/9718)) by [@​risu729](https://redirect.github.com/risu729) - **(github)** Add native GitHub OAuth device-flow token source (experimental) — no dependency on `gh`/`ghtkn` ([#​9654](https://redirect.github.com/jdx/mise/pull/9654)) by [@​jdx](https://redirect.github.com/jdx). Create a GitHub App with device flow enabled, then authorize once: ```sh mise settings set experimental true mise settings set github.oauth_client_id Iv1.yourgithubappclientid mise token github --oauth ``` mise caches and refreshes the token for its own GitHub API calls, and auto-exports it as `GITHUB_TOKEN` to shells started under `mise activate`/`exec` so `gh`, `git`, and other GitHub-aware tools pick it up too. See [GitHub Tokens → Native GitHub OAuth](https://mise.en.dev/dev-tools/github-tokens.html#native-github-oauth) for the full setup. - **(oci)** `mise oci build/run/push` are now scoped to the current project's config by default; pass `--include-global` to opt back into the previous behavior of including global config ([#​9766](https://redirect.github.com/jdx/mise/pull/9766)) by [@​jdx](https://redirect.github.com/jdx) - **(outdated)** Prefixed-version requests now resolve to the latest within the prefix — e.g. `temurin-17.0.19+10` for a `temurin-17.x` request, instead of jumping ahead to `temurin-26.x` ([#​9767](https://redirect.github.com/jdx/mise/pull/9767)) by [@​roele](https://redirect.github.com/roele) #### Fixed - **(activate)** Guard bash `chpwd_functions` expansion under `set -u` so activated shells no longer fail with `chpwd_functions[@​]: unbound variable` ([#​9716](https://redirect.github.com/jdx/mise/pull/9716)) by [@​risu729](https://redirect.github.com/risu729) - **(backend)** Date-check the `latest_stable_version` fast path when `--before` or `minimum_release_age` is active, instead of returning a too-new version ([#​9650](https://redirect.github.com/jdx/mise/pull/9650)) by [@​risu729](https://redirect.github.com/risu729) - **(config)** Parse core tool options consistently between table and bracket syntax, so `[depends=...]` and `os=` set the named core fields ([#​9742](https://redirect.github.com/jdx/mise/pull/9742)) by [@​risu729](https://redirect.github.com/risu729) - **(exec)** Nested `mise -C <dir> exec` correctly resolves the inner toolset's tools again — `__MISE_DIFF` is now propagated to children so the child no longer inherits a mutated PATH that hides its own tools ([#​9765](https://redirect.github.com/jdx/mise/pull/9765)) by [@​jdx](https://redirect.github.com/jdx) - **(forgejo)** Include prereleases when `prerelease = true` / `MISE_PRERELEASES=1` is set ([#​9717](https://redirect.github.com/jdx/mise/pull/9717)) by [@​risu729](https://redirect.github.com/risu729) - **(github)** Avoid caching empty release-asset responses, refetching instead ([#​9616](https://redirect.github.com/jdx/mise/pull/9616)) by [@​risu729](https://redirect.github.com/risu729) - **(java)** Resolve `core:java` lockfile URLs/checksums from mise Java metadata, fixing `mise install --locked` for Java ([#​9719](https://redirect.github.com/jdx/mise/pull/9719)) by [@​risu729](https://redirect.github.com/risu729) - **(lock)** Cache `github_attestations = "unavailable"` so locked installs stop hitting the GitHub attestation API for artifacts known to have none ([#​9741](https://redirect.github.com/jdx/mise/pull/9741)) by [@​risu729](https://redirect.github.com/risu729) - **(pipx)** Preserve `uvx_args`/`pipx_args`/`extras`/`uvx = false` when pipx tools are reinstalled after a Python upgrade ([#​9663](https://redirect.github.com/jdx/mise/pull/9663)) by [@​risu729](https://redirect.github.com/risu729) - **(python)** Skip redundant GitHub attestation re-verification when the lockfile already has checksum + `provenance = "github-attestations"` ([#​9739](https://redirect.github.com/jdx/mise/pull/9739)) by [@​risu729](https://redirect.github.com/risu729) - **(vfox)** Run vfox plugin `pre_uninstall` hooks before removing install directories ([#​9662](https://redirect.github.com/jdx/mise/pull/9662)) by [@​risu729](https://redirect.github.com/risu729) - Quote `program` and `args` in `cmd::cmd(..)` debug output so logged commands are unambiguous ([#​9777](https://redirect.github.com/jdx/mise/pull/9777)) by [@​ktetzlaff](https://redirect.github.com/ktetzlaff) #### Performance - **(aqua)** Bake aqua registry packages as rkyv blobs for much faster lookup ([#​9535](https://redirect.github.com/jdx/mise/pull/9535)) by [@​risu729](https://redirect.github.com/risu729) - **(registry)** Use `phf` for the mise registry lookup table, around 3.3x faster than the previous `BTreeMap` path ([#​9769](https://redirect.github.com/jdx/mise/pull/9769)) by [@​risu729](https://redirect.github.com/risu729) #### Registry - Added `vector` ([#​9761](https://redirect.github.com/jdx/mise/pull/9761)) by [@​kquinsland](https://redirect.github.com/kquinsland) - Added `openshift-install` and an `http:` backend for `oc` ([#​9669](https://redirect.github.com/jdx/mise/pull/9669)) by [@​konono](https://redirect.github.com/konono) #### New Contributors - [@​konono](https://redirect.github.com/konono) made their first contribution in [#​9669](https://redirect.github.com/jdx/mise/pull/9669) - [@​kquinsland](https://redirect.github.com/kquinsland) made their first contribution in [#​9761](https://redirect.github.com/jdx/mise/pull/9761) - [@​ktetzlaff](https://redirect.github.com/ktetzlaff) made their first contribution in [#​9777](https://redirect.github.com/jdx/mise/pull/9777) **Full Changelog**: <jdx/mise@v2026.5.5...v2026.5.6> #### 💚 Sponsor mise mise is built by [@​jdx](https://redirect.github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [maven](https://maven.apache.org/) ([source](https://redirect.github.com/apache/maven)) | `3.9.15` → `3.9.16` |  |  | --- ### Release Notes <details> <summary>apache/maven (maven)</summary> ### [`v3.9.16`](https://redirect.github.com/apache/maven/releases/tag/maven-3.9.16): 3.9.16 [Compare Source](https://redirect.github.com/apache/maven/compare/maven-3.9.15...maven-3.9.16) <!-- Optional: add a release summary here --> #### 🐛 Bug Fixes - Trim `threadConfiguration` to accept input surrounded with spaces ([#​12042](https://redirect.github.com/apache/maven/pull/12042)) [@​slawekjaranowski](https://redirect.github.com/slawekjaranowski) - Backport: Maven 3.10.x fixed plugin resolution ([#​12022](https://redirect.github.com/apache/maven/pull/12022)) [@​cstamas](https://redirect.github.com/cstamas) #### 📦 Dependency updates - Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0 ([#​12039](https://redirect.github.com/apache/maven/pull/12039)) @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - \[3.9.x] Bump to parent POM 48 ([#​12024](https://redirect.github.com/apache/maven/pull/12024)) [@​cstamas](https://redirect.github.com/cstamas) - Bump commons-io:commons-io from 2.21.0 to 2.22.0 ([#​11980](https://redirect.github.com/apache/maven/pull/11980)) @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre ([#​11951](https://redirect.github.com/apache/maven/pull/11951)) @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump actions/cache from 5.0.4 to 5.0.5 ([#​11943](https://redirect.github.com/apache/maven/pull/11943)) @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjE3OS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…r-plugin to v3.6.3 (prometheus#2125) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.apache.maven.plugins:maven-enforcer-plugin](https://maven.apache.org/enforcer/) ([source](https://redirect.github.com/apache/maven-enforcer)) | `3.6.2` → `3.6.3` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…emetry-instrumentation-bom-alpha to v2.28.0-alpha (prometheus#2127) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha](https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.27.0-alpha` → `2.28.0-alpha` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…emetry-instrumentation-bom-alpha to v2.28.0-alpha (prometheus#2126) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha](https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.27.0-alpha` → `2.28.0-alpha` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODIuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE4Mi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> --------- Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
…etricName()` (prometheus#2124) Fixes prometheus#2087. Supersedes prometheus#2094 with the same fix on a clean, signed-off commit so the DCO check can pass. `sanitizeMetricName()` was simplified in 1.6.0 to return its input unchanged because any non-empty UTF-8 string is now a valid metric name. That silently broke downstream tools — notably the JMX Exporter and the simpleclient bridge — that call `sanitizeMetricName()` to normalize external names before passing them to snapshot builders. The missing stripping means a JMX attribute that produces `kafka_consumer_request_total` as a raw name is no longer sanitized to `kafka_consumer_request`. With `inferCounterTypeFromName: true` this triggers unintended counter-type inference; with it `false` the metric is stored under the wrong name, breaking exact-name registry lookups. ## Changes - Restore `RESERVED_METRIC_NAME_SUFFIXES` and the iterative suffix-stripping loop in `PrometheusNaming.sanitizeMetricName()`. - Keep the exact-match case, for example `"_total"` -> `"total"`, in a dedicated pre-pass before the stripping loop. - Update `PrometheusNamingTest` and `MetricMetadataTest` expectations. - Add regression coverage for the JMX Exporter scenario and dot-variant corner case, for example `.total`. ```java // Before fix: suffix preserved -> metric stored as "kafka_consumer_request_total" PrometheusNaming.sanitizeMetricName("kafka_consumer_request_total"); // After fix: suffix stripped -> metric stored as "kafka_consumer_request" PrometheusNaming.sanitizeMetricName("kafka_consumer_request_total"); ``` `Counter.builder().name("events_total")` is unaffected because the builder API does not go through `sanitizeMetricName()`. ## Validation - `mise run build` Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
This PR contains the following updates: | Package | Type | Update | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [protoc](https://redirect.github.com/protocolbuffers/protobuf) | | major | `34.1` → `35.0` |  |  | | [com.google.protobuf:protobuf-java](https://developers.google.com/protocol-buffers/) ([source](https://redirect.github.com/protocolbuffers/protobuf)) | compile | minor | `4.34.1` → `4.35.0` |  |  | --- ### Release Notes <details> <summary>protocolbuffers/protobuf (protoc)</summary> ### [`v35.0`](https://redirect.github.com/protocolbuffers/protobuf/releases/tag/v35.0): Protocol Buffers v35.0 [Compare Source](https://redirect.github.com/protocolbuffers/protobuf/compare/v34.1...v35.0-rc2) ### Announcements - This version includes potential breaking changes without a major version bump to: Bazel.\*\* - \[Bazel] Change @​protobuf//bazel/flags:prefer\_prebuilt\_proto flag to True. ([`f9f32d2`](https://redirect.github.com/protocolbuffers/protobuf/commit/f9f32d28007ae692a494e70d6a5e808069938843)) - **This version includes potential breaking changes without a major version bump to: Bazel.** - [Protobuf News](https://protobuf.dev/news/) may include additional announcements or pre-announcements for upcoming changes. ### Bazel - Bazel 9 Support: Upgrade tests to Bazel 9 ([`3ee8d8a`](https://redirect.github.com/protocolbuffers/protobuf/commit/3ee8d8a008a5696f61aa72327e2c4cf2ae068e00)) - Moved `protocopt` flag out of the `cc` dir, since it is not a c++-specific flag. ([`325d8dc`](https://redirect.github.com/protocolbuffers/protobuf/commit/325d8dca2ffdc658824aa6b05d825dcb86cca2cb)) - Add support for bazel 9.x ([#​26201](https://redirect.github.com/protocolbuffers/protobuf/issues/26201)) ([`f08d703`](https://redirect.github.com/protocolbuffers/protobuf/commit/f08d70329211dfd74584c3761da5da5e32ab34f3)) - Breaking change: Change @​protobuf//bazel/flags:prefer\_prebuilt\_proto flag to True. ([`f9f32d2`](https://redirect.github.com/protocolbuffers/protobuf/commit/f9f32d28007ae692a494e70d6a5e808069938843)) - Dropped support for Bazel 7. ([`1816758`](https://redirect.github.com/protocolbuffers/protobuf/commit/181675806987071b1a9af6e22b881cf9c3dca73e)) ### Compiler - Implement the Edition 2026 naming style enforcement feature. This will help prevent field name collisions. ([`ae0d964`](https://redirect.github.com/protocolbuffers/protobuf/commit/ae0d964699968a13977ceabfe7ed0127e125c624)) - Add enum to `enforce_naming_style` feature to avoid field naming collisions which will be implemented in Edition 2026. ([`e4911a1`](https://redirect.github.com/protocolbuffers/protobuf/commit/e4911a17241386611643972b977edaf2ce83468f)) - Fail writing files in protoc CLI if any file output path is relative. ([`3bf2b07`](https://redirect.github.com/protocolbuffers/protobuf/commit/3bf2b07b2a77c8c8840031a3ef5867acf1b97f30)) - Mangle types named `XyzView` if there is any direct sibling named `Xyz` ([`63d6ef0`](https://redirect.github.com/protocolbuffers/protobuf/commit/63d6ef01b0e669333dda6fd91728862725c38968)) - Improve the namespacing selected by rustc used for gencode types in errors. ([`ce2eb73`](https://redirect.github.com/protocolbuffers/protobuf/commit/ce2eb733c7cb025c13a20735e8a8d005ba0fe19e)) - Fully qualify scalar types in Kotlin/Native proto generator. ([`adc8d22`](https://redirect.github.com/protocolbuffers/protobuf/commit/adc8d22a30cc8369d5976c8b2685374e938640a5)) - Change \_opt() accessors to return an std::Option instead of protobuf::Optional ([`6ced612`](https://redirect.github.com/protocolbuffers/protobuf/commit/6ced6127bc5fb4d65ae0cbfad7a5625d7aceab23)) - Make Message's trait bounds much better for generic use ([`be1292f`](https://redirect.github.com/protocolbuffers/protobuf/commit/be1292fbe2fc84ad59b6365a7620625e30114181)) - Support more chars in type URLs in the C++ text-format parser. ([`3a87c6c`](https://redirect.github.com/protocolbuffers/protobuf/commit/3a87c6c1fd7fdb7f88540bf3f378f53d3ca1f00d)) - Validate Feature Support on Custom Options ([`34c1110`](https://redirect.github.com/protocolbuffers/protobuf/commit/34c1110d38f225b0edcb14db965d3a5130e3ab29)) - Trait clarity effort: introduce `Singular` trait, for types which are allowed as simple fields ([`cdbfaf1`](https://redirect.github.com/protocolbuffers/protobuf/commit/cdbfaf118e9906c8ca7c27b641a8abafbd129b0b)) - Trait clarity improvement on Map traits ([`a8daa95`](https://redirect.github.com/protocolbuffers/protobuf/commit/a8daa95057bab1ca7f62830a539dc549359df78f)) ### C++ - Workaround for attribute handling bug in gcc < 13 ([`78dc67e`](https://redirect.github.com/protocolbuffers/protobuf/commit/78dc67e4d598d4e2ec8929105eb2ddbb4bf50935)) - Implement the Edition 2026 naming style enforcement feature. This will help prevent field name collisions. ([`ae0d964`](https://redirect.github.com/protocolbuffers/protobuf/commit/ae0d964699968a13977ceabfe7ed0127e125c624)) - Add enum to `enforce_naming_style` feature to avoid field naming collisions which will be implemented in Edition 2026. ([`e4911a1`](https://redirect.github.com/protocolbuffers/protobuf/commit/e4911a17241386611643972b977edaf2ce83468f)) - Enhance ParseInfoTree to provide location of names and values. ([`1cb4fdb`](https://redirect.github.com/protocolbuffers/protobuf/commit/1cb4fdb8eaaa60917cdbd23cf6f38fc5f1307054)) - Add integer overflow check to RepeatedPtrField::MergeFrom. ([`cb5fe97`](https://redirect.github.com/protocolbuffers/protobuf/commit/cb5fe976f319683934d8153bdedb21355ab2e008)) - Adding sanity check for `ListFields` reflection call ([`555360e`](https://redirect.github.com/protocolbuffers/protobuf/commit/555360e3b52f63e9a29d075c5e6900f7db7fdd2c)) - Introduce `Arena::UniquePtr` and `Arena::Ptr` as smart pointers to better manage ([`bb00218`](https://redirect.github.com/protocolbuffers/protobuf/commit/bb002180b59c957e6b2f0dddecf0e90ef5a26723)) - Bug fix for edition 2024 visibility checking. Visibility checking was not properly applied to service method input and output types. This is now applied properly and will error if method input/output types do not have visibility to those messages. ([`5a56dee`](https://redirect.github.com/protocolbuffers/protobuf/commit/5a56dee4de2b6e6ffcd963054d100fc610171427)) - Fixed data race in Python Free Threading by removing unnecessary `SetHasBitForRepeated()` call. ([`8c1a9a4`](https://redirect.github.com/protocolbuffers/protobuf/commit/8c1a9a4b0163eded7d9ff0c255507ed3163caf1f)) - Add support for bazel 9.x ([#​26201](https://redirect.github.com/protocolbuffers/protobuf/issues/26201)) ([`f08d703`](https://redirect.github.com/protocolbuffers/protobuf/commit/f08d70329211dfd74584c3761da5da5e32ab34f3)) - Add `proto2::sort`/`stable_sort` utilities that behave as the standard ones but are optimized for Protobuf containers. ([`252281f`](https://redirect.github.com/protocolbuffers/protobuf/commit/252281f6be6df834a0f64a7f8d085c0bd679d1da)) - Add `proto2::erase`/`erase_if` utilities that behave as the standard ones but are optimized for Protobuf containers. ([`dc9fb35`](https://redirect.github.com/protocolbuffers/protobuf/commit/dc9fb354dbb75c730cb57856a909015aac5d9595)) - Extend Abseil flag support for enums to include std::vector<Enum>. ([`bd42ac6`](https://redirect.github.com/protocolbuffers/protobuf/commit/bd42ac6b29603d5ba62d05d8f0dac6064d959b0d)) - Dropped support for Bazel 7. ([`1816758`](https://redirect.github.com/protocolbuffers/protobuf/commit/181675806987071b1a9af6e22b881cf9c3dca73e)) - Add native Abseil flag support to protobuf message types. ([`ec42e19`](https://redirect.github.com/protocolbuffers/protobuf/commit/ec42e190317343e78a5be17962a57e45e3ff439d)) - Support more chars in type URLs in the C++ text-format parser. ([`3a87c6c`](https://redirect.github.com/protocolbuffers/protobuf/commit/3a87c6c1fd7fdb7f88540bf3f378f53d3ca1f00d)) - Stripping empty options ([`d5d6d4c`](https://redirect.github.com/protocolbuffers/protobuf/commit/d5d6d4c89ef7f23b847d9e4fa459e57a4393b28d)) - Creating generic MaybeAddError helper function ([`4bcf773`](https://redirect.github.com/protocolbuffers/protobuf/commit/4bcf773b240132846e8dc3361b7e629fc0926ebb)) - Validate Feature Support on Custom Options ([`34c1110`](https://redirect.github.com/protocolbuffers/protobuf/commit/34c1110d38f225b0edcb14db965d3a5130e3ab29)) - Add bounds checks to `UnsafeArenaExtractSubrange`, `ReleaseLast` and `SwapElements`. ([`d124c2d`](https://redirect.github.com/protocolbuffers/protobuf/commit/d124c2dc26841e5ee0b8d1505438fcf0660c9db0)) - Fix UTF-8 Validation of string extensions in C++ ([`0936f33`](https://redirect.github.com/protocolbuffers/protobuf/commit/0936f33595ef736726f191c087eaabbc5d1c5fc6)) - Remove first implementation of protobuf out of bounds enforcement. ([`507f86b`](https://redirect.github.com/protocolbuffers/protobuf/commit/507f86bd3a9acdffaff10a32e8b48456b2559783)) - Add native Abseil flag support to protobuf enums. ([`a203388`](https://redirect.github.com/protocolbuffers/protobuf/commit/a203388028fc5e3374d30ff3a385202a330fbefb)) - Improve EINTR handling for close in `zero_copy_stream_impl.h` ([`a904af9`](https://redirect.github.com/protocolbuffers/protobuf/commit/a904af9cc8597eea47b3d4c657dd4f36eefa1145)) - Add cc\_proto\_library for MessageSet in //src/google/protobuf/bridge ([`6d23e8e`](https://redirect.github.com/protocolbuffers/protobuf/commit/6d23e8ec14908edda3fdb44027eb87b90499f789)) ### Java - Add BytecodeClassName functions, matching helpers in the java GeneratorNames utility. ([`514aceb`](https://redirect.github.com/protocolbuffers/protobuf/commit/514aceb974fbd55031169b79d2bd9f7646157787)) - Add enum to `enforce_naming_style` feature to avoid field naming collisions which will be implemented in Edition 2026. ([`e4911a1`](https://redirect.github.com/protocolbuffers/protobuf/commit/e4911a17241386611643972b977edaf2ce83468f)) - Avoid toBigIntegerExact in JsonFormat to avoid degenerate parse behavior in the face of large exponents. ([`57093a8`](https://redirect.github.com/protocolbuffers/protobuf/commit/57093a8bd5cb44211f323519a0045b883475666f)) - Dropped support for Bazel 7. ([`1816758`](https://redirect.github.com/protocolbuffers/protobuf/commit/181675806987071b1a9af6e22b881cf9c3dca73e)) - Add native Abseil flag support to protobuf enums. ([`a203388`](https://redirect.github.com/protocolbuffers/protobuf/commit/a203388028fc5e3374d30ff3a385202a330fbefb)) ### Csharp - Implement WriteDelimitedTo(BufferWriter<byte>) ([#​21325](https://redirect.github.com/protocolbuffers/protobuf/issues/21325)) ([`407f457`](https://redirect.github.com/protocolbuffers/protobuf/commit/407f4570b201293783f5416cdaae493366bc6b14)) - Add an "include" directory containing WKTs for Google.Protobuf.Tools nuget package. ([`6029d17`](https://redirect.github.com/protocolbuffers/protobuf/commit/6029d174f2eed7a64ad3a42182d08f2f3e66fcf6)) ### Objective-C - ObjC: Block Roots from being created. ([`8274114`](https://redirect.github.com/protocolbuffers/protobuf/commit/827411455abe4a62dd11b2c8afb15a594ff35b42)) - Fix naming convention in c\_function extension syntax ([`e3bee07`](https://redirect.github.com/protocolbuffers/protobuf/commit/e3bee077db853dc0d6e8e04d1e3071018e222faf)) - Modify unit tests to use c\_function extension syntax via ifdefs ([`e1f2f52`](https://redirect.github.com/protocolbuffers/protobuf/commit/e1f2f5272097cfd44dac849d7906b11445e93d38)) ### Rust - Mangle types named `XyzView` if there is any direct sibling named `Xyz` ([`63d6ef0`](https://redirect.github.com/protocolbuffers/protobuf/commit/63d6ef01b0e669333dda6fd91728862725c38968)) - Improve the namespacing selected by rustc used for gencode types in errors. ([`ce2eb73`](https://redirect.github.com/protocolbuffers/protobuf/commit/ce2eb733c7cb025c13a20735e8a8d005ba0fe19e)) - Allow ProtoStr to be used in const contexts. ([`7f7b974`](https://redirect.github.com/protocolbuffers/protobuf/commit/7f7b974fce500ad67ddb9aaa517c0bd6796d479d)) - Make any \&T impl AsView if T impl AsView ([`d787869`](https://redirect.github.com/protocolbuffers/protobuf/commit/d787869082f031e561d0dc7f31e5cfc03848bd15)) - Change \_opt() accessors to return an std::Option instead of protobuf::Optional ([`6ced612`](https://redirect.github.com/protocolbuffers/protobuf/commit/6ced6127bc5fb4d65ae0cbfad7a5625d7aceab23)) - Add some common methods to ProtoStr to make it more ergonomic to use without dropping down to &\[u8] ([`f8daf2f`](https://redirect.github.com/protocolbuffers/protobuf/commit/f8daf2fabc8601e69c547fbf8c0addb6d6837e47)) - Ffi\_11: Define basic arithmetic operations and comparison with underlying type ([`74b6f3f`](https://redirect.github.com/protocolbuffers/protobuf/commit/74b6f3fe0b9a80205309083ab88bd2ab012ed1eb)) - Make Message's trait bounds much better for generic use ([`be1292f`](https://redirect.github.com/protocolbuffers/protobuf/commit/be1292fbe2fc84ad59b6365a7620625e30114181)) - Remove ProxiedInMapValue alias, since it is superceded by MapValue ([`5bde6e8`](https://redirect.github.com/protocolbuffers/protobuf/commit/5bde6e8d3134cdf67a513cbff403d19526df11ad)) - Add fn push\_default(\&mut self) -> SomeMsgMut<> fn for Repeated message type fields. ([`a3bf3ec`](https://redirect.github.com/protocolbuffers/protobuf/commit/a3bf3ec75512e8bc89334b2e245924ad15f6352c)) - Fix that f32 and f64 were incorrectly tagged as legal for MapKeys in RustProto. ([`ab3793e`](https://redirect.github.com/protocolbuffers/protobuf/commit/ab3793e7a8f6270081cc0e74ba2ffd7b7ee35159)) - Trait clarity effort: introduce `Singular` trait, for types which are allowed as simple fields ([`cdbfaf1`](https://redirect.github.com/protocolbuffers/protobuf/commit/cdbfaf118e9906c8ca7c27b641a8abafbd129b0b)) - Trait clarity improvement on Map traits ([`a8daa95`](https://redirect.github.com/protocolbuffers/protobuf/commit/a8daa95057bab1ca7f62830a539dc549359df78f)) - *See also UPB changes below, which may affect Rust.* ### Python - Fix Python text\_format by adding an optional recursion depth limit ([#​26604](https://redirect.github.com/protocolbuffers/protobuf/issues/26604)) ([`8abff6b`](https://redirect.github.com/protocolbuffers/protobuf/commit/8abff6bb4b36575159bf247f3da62f4efa742bdd)) - Fix data race in CMessage lazy initialization for Python freethreading. ([`28e4512`](https://redirect.github.com/protocolbuffers/protobuf/commit/28e451233d38148856587c96bd8864b7e9767587)) - Fixed data race in Python Free Threading by removing unnecessary `SetHasBitForRepeated()` call. ([`8c1a9a4`](https://redirect.github.com/protocolbuffers/protobuf/commit/8c1a9a4b0163eded7d9ff0c255507ed3163caf1f)) - Fix type annotation for FindAllExtensionNumbers() to be a list rather than the more general Iterator. ([`3edd615`](https://redirect.github.com/protocolbuffers/protobuf/commit/3edd61508bed8b58e5190b6c28884d3e21cf5bdc)) - Add type hints to descriptor\_database.py. ([`cbe6403`](https://redirect.github.com/protocolbuffers/protobuf/commit/cbe6403761a4fa349c6612102f048ff584441f09)) - Fixed a bug in `msg.MergeFrom(msg2)` in Python. ([`ab14c0f`](https://redirect.github.com/protocolbuffers/protobuf/commit/ab14c0f8ad88109b99205af9bd2ef961e991ea41)) - Fix NULL byte handling issue in Python Protobuf find symbols in pool ([`059dc7e`](https://redirect.github.com/protocolbuffers/protobuf/commit/059dc7ed3256bd6c247694d92e624590c52a400a)) - Add support for bazel 9.x ([#​26201](https://redirect.github.com/protocolbuffers/protobuf/issues/26201)) ([`f08d703`](https://redirect.github.com/protocolbuffers/protobuf/commit/f08d70329211dfd74584c3761da5da5e32ab34f3)) - Add recursion guards for the following nested messages: ([`b4c3fec`](https://redirect.github.com/protocolbuffers/protobuf/commit/b4c3fecb8599b84967f293806d2db54aff77664b)) - Protobuf Python UPB Free Threading support. ([`f10c1de`](https://redirect.github.com/protocolbuffers/protobuf/commit/f10c1de25fa7285a41978e5d054d03c48d19b9f1)) - Fix Any recursion depth bypass in Python json\_format.ParseDict ([#​25239](https://redirect.github.com/protocolbuffers/protobuf/issues/25239)) ([`d2b0016`](https://redirect.github.com/protocolbuffers/protobuf/commit/d2b001626d137c62dfee6c88c87324102531868b)) - Supports exporting `int` as `int` ([`ea78297`](https://redirect.github.com/protocolbuffers/protobuf/commit/ea78297e0a85dfd319381748d7c93dc69d2c5958)) ### PHP - Fail writing files in protoc CLI if any file output path is relative. ([`3bf2b07`](https://redirect.github.com/protocolbuffers/protobuf/commit/3bf2b07b2a77c8c8840031a3ef5867acf1b97f30)) ##### PHP C-Extension - Fix 1-byte stack overflow in PHP extension int64 formatting ([#​26530](https://redirect.github.com/protocolbuffers/protobuf/issues/26530)) ([`3f04505`](https://redirect.github.com/protocolbuffers/protobuf/commit/3f045053e2a3fe55d0e3bf2b14d4d29e4f863fd5)) - *See also UPB changes below, which may affect PHP C-Extension.* ### Ruby - Gracefully handle payloads >2GB. ([`918ad5b`](https://redirect.github.com/protocolbuffers/protobuf/commit/918ad5bff3f174a417dded6b58ceab4cf6720e65)) ##### Ruby C-Extension - Gracefully handle payloads >2GB. ([`918ad5b`](https://redirect.github.com/protocolbuffers/protobuf/commit/918ad5bff3f174a417dded6b58ceab4cf6720e65)) - *See also UPB changes below, which may affect Ruby C-Extension.* ### UPB (Python/PHP/Ruby C-Extension) - Fixed two GCC-only issues around upb's generated extension registry. - Avoid theoretical overflow of uintptr\_t in AddAllLinkedExtensions ([`e7785e0`](https://redirect.github.com/protocolbuffers/protobuf/commit/e7785e0509aab295692061fb569c00645d3ef3a4)) - Test(proto): Add message to test oneof name conflict resolution ([`29476e1`](https://redirect.github.com/protocolbuffers/protobuf/commit/29476e1a91dc3dfbc10a8d4a5bce998896452258)) - Add recursion guards for the following nested messages: ([`b4c3fec`](https://redirect.github.com/protocolbuffers/protobuf/commit/b4c3fecb8599b84967f293806d2db54aff77664b)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
…emetry-instrumentation-bom-alpha to v2.28.1-alpha (prometheus#2132) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha](https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.28.0-alpha` → `2.28.1-alpha` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…emetry-instrumentation-bom-alpha to v2.28.1-alpha (prometheus#2133) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha](https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.28.0-alpha` → `2.28.1-alpha` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…dbf0 (prometheus#2367) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://redirect.github.com/adoptium/containers)) | final | digest | `681c543` → `f19dbf0` | | [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://redirect.github.com/adoptium/containers)) | | digest | `681c543` → `f19dbf0` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [node](https://nodejs.org)
([source](https://redirect.github.com/nodejs/node)) | tools | minor |
`24.18.1` → `24.19.0` |
---
### Release Notes
<details>
<summary>nodejs/node (node)</summary>
###
[`v24.19.0`](https://redirect.github.com/nodejs/node/releases/tag/v24.19.0):
2026-08-03, Version 24.19.0 'Krypton' (LTS), @​aduh95
[Compare
Source](https://redirect.github.com/nodejs/node/compare/v24.18.1...v24.19.0)
##### Notable Changes
-
\[[`d08872b530`](https://redirect.github.com/nodejs/node/commit/d08872b530)]
- **(SEMVER-MINOR)** **buffer**: implement `blob.textStream()` (Matthew
Aitken)
[#​64036](https://redirect.github.com/nodejs/node/pull/64036)
-
\[[`35222948be`](https://redirect.github.com/nodejs/node/commit/35222948be)]
- **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support
compression (Tim Perry)
[#​62217](https://redirect.github.com/nodejs/node/pull/62217)
-
\[[`d6ab039f24`](https://redirect.github.com/nodejs/node/commit/d6ab039f24)]
- **(SEMVER-MINOR)** **doc**: update `blockList` stability status to
release candidate (alphaleadership)
[#​63050](https://redirect.github.com/nodejs/node/pull/63050)
-
\[[`1da05fb79d`](https://redirect.github.com/nodejs/node/commit/1da05fb79d)]
- **doc**: mark `stream.compose` stable (Matteo Collina)
[#​62562](https://redirect.github.com/nodejs/node/pull/62562)
-
\[[`3c1636dabf`](https://redirect.github.com/nodejs/node/commit/3c1636dabf)]
- **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag
(Efe)
[#​62300](https://redirect.github.com/nodejs/node/pull/62300)
-
\[[`e323e877be`](https://redirect.github.com/nodejs/node/commit/e323e877be)]
- **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()`
buffers (Matteo Collina)
[#​63634](https://redirect.github.com/nodejs/node/pull/63634)
-
\[[`c1248c9544`](https://redirect.github.com/nodejs/node/commit/c1248c9544)]
- **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure
header value validation (RajeshKumar11)
[#​61597](https://redirect.github.com/nodejs/node/pull/61597)
-
\[[`a534b65815`](https://redirect.github.com/nodejs/node/commit/a534b65815)]
- **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT`
in `setKeepAlive` (Guy Bedford)
[#​63825](https://redirect.github.com/nodejs/node/pull/63825)
-
\[[`a23cdec683`](https://redirect.github.com/nodejs/node/commit/a23cdec683)]
- **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop
iteration (Pablo Erhard)
[#​62935](https://redirect.github.com/nodejs/node/pull/62935)
-
\[[`7428b57a37`](https://redirect.github.com/nodejs/node/commit/7428b57a37)]
- **(SEMVER-MINOR)** **src**: allow empty `--experimental-config-file`
(Marco Ippolito)
[#​61610](https://redirect.github.com/nodejs/node/pull/61610)
-
\[[`e57597173c`](https://redirect.github.com/nodejs/node/commit/e57597173c)]
- **(SEMVER-MINOR)** **stream**: expose `ReadableStreamTee` (Matteo
Collina)
[#​64195](https://redirect.github.com/nodejs/node/pull/64195)
-
\[[`5396235993`](https://redirect.github.com/nodejs/node/commit/5396235993)]
- **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip
Skokan)
[#​64119](https://redirect.github.com/nodejs/node/pull/64119)
-
\[[`5e901b5cd9`](https://redirect.github.com/nodejs/node/commit/5e901b5cd9)]
- **(SEMVER-MINOR)** **tls**: add `certificateCompression` option (Tim
Perry)
[#​62217](https://redirect.github.com/nodejs/node/pull/62217)
##### Commits
-
\[[`676467fa9f`](https://redirect.github.com/nodejs/node/commit/676467fa9f)]
- **benchmark**: trim down the argon2 sets (Filip Skokan)
[#​64218](https://redirect.github.com/nodejs/node/pull/64218)
-
\[[`a77a2000b7`](https://redirect.github.com/nodejs/node/commit/a77a2000b7)]
- **benchmark**: add child\_process async path baselines (Yagiz Nizipli)
[#​63929](https://redirect.github.com/nodejs/node/pull/63929)
-
\[[`dd4482e915`](https://redirect.github.com/nodejs/node/commit/dd4482e915)]
- **buffer**: remove unreachable overflow check in atob (haramjeong)
[#​60161](https://redirect.github.com/nodejs/node/pull/60161)
-
\[[`081c41eb86`](https://redirect.github.com/nodejs/node/commit/081c41eb86)]
- **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu)
[#​64169](https://redirect.github.com/nodejs/node/pull/64169)
-
\[[`d08872b530`](https://redirect.github.com/nodejs/node/commit/d08872b530)]
- **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew
Aitken)
[#​64036](https://redirect.github.com/nodejs/node/pull/64036)
-
\[[`6e2f7e6013`](https://redirect.github.com/nodejs/node/commit/6e2f7e6013)]
- **build**: remove redundant intermediate node\_aix\_shared (Chengzhong
Wu) [#​63747](https://redirect.github.com/nodejs/node/pull/63747)
-
\[[`87e0675f51`](https://redirect.github.com/nodejs/node/commit/87e0675f51)]
- **build**: build codecache and snapshot with libnode (Chengzhong Wu)
[#​63626](https://redirect.github.com/nodejs/node/pull/63626)
-
\[[`32174a7bae`](https://redirect.github.com/nodejs/node/commit/32174a7bae)]
- **build**: support setting an emulator from configure script (Ivan
Trubach)
[#​53899](https://redirect.github.com/nodejs/node/pull/53899)
-
\[[`69cfb2f240`](https://redirect.github.com/nodejs/node/commit/69cfb2f240)]
- **build**: remove duplicated node\_use\_sqlite and node\_use\_ffi
conditions (Chengzhong Wu)
[#​63629](https://redirect.github.com/nodejs/node/pull/63629)
-
\[[`37ac6e8cb5`](https://redirect.github.com/nodejs/node/commit/37ac6e8cb5)]
- **build**: add manually-dispatched stress-test workflow (Joyee Cheung)
[#​64118](https://redirect.github.com/nodejs/node/pull/64118)
-
\[[`2424207191`](https://redirect.github.com/nodejs/node/commit/2424207191)]
- **build**: suppress compiler warnings for histogram (Richard Lau)
[#​63980](https://redirect.github.com/nodejs/node/pull/63980)
-
\[[`63502b7404`](https://redirect.github.com/nodejs/node/commit/63502b7404)]
- **build,win**: fix VS2022 arm64 PGO build (Stefan Stojanovic)
[#​63413](https://redirect.github.com/nodejs/node/pull/63413)
-
\[[`fe4e4055d0`](https://redirect.github.com/nodejs/node/commit/fe4e4055d0)]
- **child\_process**: fix permission model propagation via NODE\_OPTIONS
(Matteo Collina)
[#​63972](https://redirect.github.com/nodejs/node/pull/63972)
-
\[[`aa2f3c066e`](https://redirect.github.com/nodejs/node/commit/aa2f3c066e)]
- **child\_process**: pass spawn options to the binding positionally
(Yagiz Nizipli)
[#​63930](https://redirect.github.com/nodejs/node/pull/63930)
-
\[[`fcf32cf77a`](https://redirect.github.com/nodejs/node/commit/fcf32cf77a)]
- **child\_process**: serialize advanced IPC messages natively (Yagiz
Nizipli)
[#​63933](https://redirect.github.com/nodejs/node/pull/63933)
-
\[[`7907134734`](https://redirect.github.com/nodejs/node/commit/7907134734)]
- **crypto**: reject small-order EdDSA points during verify (Filip
Skokan)
[#​64026](https://redirect.github.com/nodejs/node/pull/64026)
-
\[[`b505cd5465`](https://redirect.github.com/nodejs/node/commit/b505cd5465)]
- **crypto**: support non-byte WebCrypto lengths and cSHAKE (Filip
Skokan)
[#​63988](https://redirect.github.com/nodejs/node/pull/63988)
-
\[[`0f54a872e2`](https://redirect.github.com/nodejs/node/commit/0f54a872e2)]
- **crypto**: share WebCrypto method and usage helpers (Filip Skokan)
[#​63975](https://redirect.github.com/nodejs/node/pull/63975)
-
\[[`824ec11c05`](https://redirect.github.com/nodejs/node/commit/824ec11c05)]
- **crypto**: refactor keyObject.toCryptoKey() and
SubtleCrypto.getPublicKey() (Filip Skokan)
[#​63622](https://redirect.github.com/nodejs/node/pull/63622)
-
\[[`73aba92689`](https://redirect.github.com/nodejs/node/commit/73aba92689)]
- **crypto**: coerce -0 to +0 before native calls (Filip Skokan)
[#​63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`c83b79874e`](https://redirect.github.com/nodejs/node/commit/c83b79874e)]
- **crypto**: reject invalid raw key imports (Filip Skokan)
[#​63134](https://redirect.github.com/nodejs/node/pull/63134)
-
\[[`934fda64b9`](https://redirect.github.com/nodejs/node/commit/934fda64b9)]
- **crypto**: improve accuracy of SubtleCrypto.supports (Filip Skokan)
[#​63104](https://redirect.github.com/nodejs/node/pull/63104)
-
\[[`e392e1f791`](https://redirect.github.com/nodejs/node/commit/e392e1f791)]
- **crypto**: fix large DH generator validation (Tobias Nießen)
[#​64092](https://redirect.github.com/nodejs/node/pull/64092)
-
\[[`e75a363e70`](https://redirect.github.com/nodejs/node/commit/e75a363e70)]
- **crypto**: use EVP\_MAC for HMAC on OpenSSL >=3 (Filip Skokan)
[#​63942](https://redirect.github.com/nodejs/node/pull/63942)
-
\[[`adbaf7af9b`](https://redirect.github.com/nodejs/node/commit/adbaf7af9b)]
- **crypto**: make webcrypto aliasKeyFormat directional (Filip Skokan)
[#​63910](https://redirect.github.com/nodejs/node/pull/63910)
-
\[[`bb1aea8897`](https://redirect.github.com/nodejs/node/commit/bb1aea8897)]
- **crypto**: fix unhandled error in Hash.\_transform (Haram Jeong)
[#​63261](https://redirect.github.com/nodejs/node/pull/63261)
-
\[[`12c87732c1`](https://redirect.github.com/nodejs/node/commit/12c87732c1)]
- **crypto**: handle cipher context allocation failures (Tian Teng)
[#​63542](https://redirect.github.com/nodejs/node/pull/63542)
-
\[[`858496b453`](https://redirect.github.com/nodejs/node/commit/858496b453)]
- **crypto**: deduplicate X509 subject matching logic (Tobias Nießen)
[#​63644](https://redirect.github.com/nodejs/node/pull/63644)
-
\[[`9a29cb0964`](https://redirect.github.com/nodejs/node/commit/9a29cb0964)]
- **crypto**: fix warnings in test\_node\_crypto.cc (Maya Lekova)
[#​63490](https://redirect.github.com/nodejs/node/pull/63490)
-
\[[`8bb536066d`](https://redirect.github.com/nodejs/node/commit/8bb536066d)]
- **crypto**: optimize normalizeAlgorithm dispatch hot path (Filip
Skokan)
[#​62756](https://redirect.github.com/nodejs/node/pull/62756)
-
\[[`329e5496ff`](https://redirect.github.com/nodejs/node/commit/329e5496ff)]
- **crypto,tls**: do not ignore BN\_get\_word error (Tobias Nießen)
[#​63895](https://redirect.github.com/nodejs/node/pull/63895)
-
\[[`97b7a3f9c7`](https://redirect.github.com/nodejs/node/commit/97b7a3f9c7)]
- **debugger**: add --max-hit option to probe mode (Joyee Cheung)
[#​63704](https://redirect.github.com/nodejs/node/pull/63704)
-
\[[`9098585c5e`](https://redirect.github.com/nodejs/node/commit/9098585c5e)]
- **debugger**: add more logs to probe mode (Joyee Cheung)
[#​63663](https://redirect.github.com/nodejs/node/pull/63663)
-
\[[`59cca26cd5`](https://redirect.github.com/nodejs/node/commit/59cca26cd5)]
- **debugger**: surface inspector failures in probe mode (Joyee Cheung)
[#​63437](https://redirect.github.com/nodejs/node/pull/63437)
-
\[[`2922290eae`](https://redirect.github.com/nodejs/node/commit/2922290eae)]
- **debugger**: disambiguate probe location binding (Joyee Cheung)
[#​63286](https://redirect.github.com/nodejs/node/pull/63286)
-
\[[`6fb2c2c7e2`](https://redirect.github.com/nodejs/node/commit/6fb2c2c7e2)]
- **debugger**: lazily wait for initial break output (Trivikram Kamat)
[#​63969](https://redirect.github.com/nodejs/node/pull/63969)
-
\[[`688e792551`](https://redirect.github.com/nodejs/node/commit/688e792551)]
- **debugger**: defer probe pause handling until startup (Trivikram
Kamat)
[#​63608](https://redirect.github.com/nodejs/node/pull/63608)
-
\[[`1ac93cc05a`](https://redirect.github.com/nodejs/node/commit/1ac93cc05a)]
- **debugger**: await initialization after run and restart (Trivikram
Kamat)
[#​63607](https://redirect.github.com/nodejs/node/pull/63607)
-
\[[`92a909cf72`](https://redirect.github.com/nodejs/node/commit/92a909cf72)]
- **debugger,test**: deflake resume failure test and add debug logs
(Joyee Cheung)
[#​63524](https://redirect.github.com/nodejs/node/pull/63524)
-
\[[`8b37af8b11`](https://redirect.github.com/nodejs/node/commit/8b37af8b11)]
- **deps**: V8: backport
[`bef0d9c`](https://redirect.github.com/nodejs/node/commit/bef0d9c1bc90)
(Joyee Cheung)
[#​62132](https://redirect.github.com/nodejs/node/pull/62132)
-
\[[`8832126422`](https://redirect.github.com/nodejs/node/commit/8832126422)]
- **deps**: V8: cherry-pick
[`64b36b4`](https://redirect.github.com/nodejs/node/commit/64b36b441179)
(Dan Carney)
[#​61712](https://redirect.github.com/nodejs/node/pull/61712)
-
\[[`75990c2cd6`](https://redirect.github.com/nodejs/node/commit/75990c2cd6)]
- **deps**: update googletest to
[`8b53336`](https://redirect.github.com/nodejs/node/commit/8b53336594cc52213c6c2c7a0b29194fa896d039)
(Node.js GitHub Bot)
[#​64181](https://redirect.github.com/nodejs/node/pull/64181)
-
\[[`8500c7ba86`](https://redirect.github.com/nodejs/node/commit/8500c7ba86)]
- **deps**: update sqlite to 3.53.3 (Node.js GitHub Bot)
[#​64180](https://redirect.github.com/nodejs/node/pull/64180)
-
\[[`dc78091b45`](https://redirect.github.com/nodejs/node/commit/dc78091b45)]
- **deps**: c-ares: cherry-pick
[`8ba37af`](https://redirect.github.com/nodejs/node/commit/8ba37af8e3fb)
(René)
[#​64110](https://redirect.github.com/nodejs/node/pull/64110)
-
\[[`873cc72125`](https://redirect.github.com/nodejs/node/commit/873cc72125)]
- **deps**: update googletest to
[`0b1e895`](https://redirect.github.com/nodejs/node/commit/0b1e895ba4226c2fda5ee0178c9b5b1195a741aa)
(Node.js GitHub Bot)
[#​64039](https://redirect.github.com/nodejs/node/pull/64039)
-
\[[`1d3d166538`](https://redirect.github.com/nodejs/node/commit/1d3d166538)]
- **deps**: update acorn to 8.17.0 (Node.js GitHub Bot)
[#​63901](https://redirect.github.com/nodejs/node/pull/63901)
-
\[[`35222948be`](https://redirect.github.com/nodejs/node/commit/35222948be)]
- **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support
compression (Tim Perry)
[#​62217](https://redirect.github.com/nodejs/node/pull/62217)
-
\[[`e40cee5f79`](https://redirect.github.com/nodejs/node/commit/e40cee5f79)]
- **deps**: upgrade npm to 11.17.0 (npm team)
[#​63857](https://redirect.github.com/nodejs/node/pull/63857)
-
\[[`85c6d46606`](https://redirect.github.com/nodejs/node/commit/85c6d46606)]
- **deps**: add ngtcp2\_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞)
[#​63821](https://redirect.github.com/nodejs/node/pull/63821)
-
\[[`d2ea8b7a8c`](https://redirect.github.com/nodejs/node/commit/d2ea8b7a8c)]
- **deps**: update googletest to
[`7140cd4`](https://redirect.github.com/nodejs/node/commit/7140cd416cecd7462a8aae488024abeee55598e4)
(Node.js GitHub Bot)
[#​63775](https://redirect.github.com/nodejs/node/pull/63775)
-
\[[`25b4d57bb6`](https://redirect.github.com/nodejs/node/commit/25b4d57bb6)]
- **deps**: update sqlite to 3.53.2 (Node.js GitHub Bot)
[#​63774](https://redirect.github.com/nodejs/node/pull/63774)
-
\[[`a96368e4c7`](https://redirect.github.com/nodejs/node/commit/a96368e4c7)]
- **deps**: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot)
[#​63773](https://redirect.github.com/nodejs/node/pull/63773)
-
\[[`b59f1f5f37`](https://redirect.github.com/nodejs/node/commit/b59f1f5f37)]
- **deps**: update amaro to 1.1.10 (Node.js GitHub Bot)
[#​63670](https://redirect.github.com/nodejs/node/pull/63670)
-
\[[`0b3b56ee95`](https://redirect.github.com/nodejs/node/commit/0b3b56ee95)]
- **deps**: update googletest to
[`8736d2c`](https://redirect.github.com/nodejs/node/commit/8736d2cd5c1dcba41170ed2fddca14021d4916c3)
(Node.js GitHub Bot)
[#​63669](https://redirect.github.com/nodejs/node/pull/63669)
-
\[[`aa67b5b9c4`](https://redirect.github.com/nodejs/node/commit/aa67b5b9c4)]
- **dgram**: add synchronous Socket connectSync() (Guy Bedford)
[#​63932](https://redirect.github.com/nodejs/node/pull/63932)
-
\[[`ef38374875`](https://redirect.github.com/nodejs/node/commit/ef38374875)]
- **dgram**: add synchronous Socket.prototype.bindSync() (Guy Bedford)
[#​63838](https://redirect.github.com/nodejs/node/pull/63838)
-
\[[`6edc3a9967`](https://redirect.github.com/nodejs/node/commit/6edc3a9967)]
- **dgram**: skip dns.lookup() for literal IP addresses (Ruben
Bridgewater)
[#​64133](https://redirect.github.com/nodejs/node/pull/64133)
-
\[[`d4cfe2d8ac`](https://redirect.github.com/nodejs/node/commit/d4cfe2d8ac)]
- **dns**: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan)
[#​63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`91c9ce5a45`](https://redirect.github.com/nodejs/node/commit/91c9ce5a45)]
- **doc**: improve `fs.StatFs` properties descriptions (aymanxdev)
[#​62578](https://redirect.github.com/nodejs/node/pull/62578)
-
\[[`54e21675fa`](https://redirect.github.com/nodejs/node/commit/54e21675fa)]
- **doc**: fix inconsistencies in CJS code snippets (Antoine du Hamel)
[#​63199](https://redirect.github.com/nodejs/node/pull/63199)
-
\[[`64c23daa76`](https://redirect.github.com/nodejs/node/commit/64c23daa76)]
- **doc**: remove typo comma from man page (Vas Sudanagunta)
[#​63080](https://redirect.github.com/nodejs/node/pull/63080)
-
\[[`bc943cd34a`](https://redirect.github.com/nodejs/node/commit/bc943cd34a)]
- **doc**: update Http2SecureServer.on("timeout") default value (YuSheng
Chen)
[#​64187](https://redirect.github.com/nodejs/node/pull/64187)
-
\[[`a46bc452a6`](https://redirect.github.com/nodejs/node/commit/a46bc452a6)]
- **doc**: add note on visibility of CI failures to new contributor
guide (Stewart X Addison)
[#​64256](https://redirect.github.com/nodejs/node/pull/64256)
-
\[[`c0fb52506c`](https://redirect.github.com/nodejs/node/commit/c0fb52506c)]
- **doc**: clarify HTTP/1.1 response ordering (Matteo Collina)
[#​64213](https://redirect.github.com/nodejs/node/pull/64213)
-
\[[`d3073a7ba6`](https://redirect.github.com/nodejs/node/commit/d3073a7ba6)]
- **doc**: recommend node-stress-single-test for flaky tests (Trivikram
Kamat)
[#​64223](https://redirect.github.com/nodejs/node/pull/64223)
-
\[[`bb9951ead0`](https://redirect.github.com/nodejs/node/commit/bb9951ead0)]
- **doc**: fix typo in examples (Vas Sudanagunta)
[#​64184](https://redirect.github.com/nodejs/node/pull/64184)
-
\[[`fe674e96fc`](https://redirect.github.com/nodejs/node/commit/fe674e96fc)]
- **doc**: clarify defense-in-depth issues (Matteo Collina)
[#​64215](https://redirect.github.com/nodejs/node/pull/64215)
-
\[[`faad042184`](https://redirect.github.com/nodejs/node/commit/faad042184)]
- **doc**: add guide and answers to FAQs for first-time contributors
(Joyee Cheung)
[#​63685](https://redirect.github.com/nodejs/node/pull/63685)
-
\[[`79d685adf3`](https://redirect.github.com/nodejs/node/commit/79d685adf3)]
- **doc**: update `Http2Server.close` & `Http2SecureServer.close`
(YuSheng Chen)
[#​63298](https://redirect.github.com/nodejs/node/pull/63298)
-
\[[`744e40e05e`](https://redirect.github.com/nodejs/node/commit/744e40e05e)]
- **doc**: update list of people in `SECURITY.md` (Richard Lau)
[#​64152](https://redirect.github.com/nodejs/node/pull/64152)
-
\[[`185f57c4a4`](https://redirect.github.com/nodejs/node/commit/185f57c4a4)]
- **doc**: add missing option to man page (Richard Lau)
[#​64156](https://redirect.github.com/nodejs/node/pull/64156)
-
\[[`8933303568`](https://redirect.github.com/nodejs/node/commit/8933303568)]
- **doc**: fix callback example import in fs docs (Kamal Rawal)
[#​63912](https://redirect.github.com/nodejs/node/pull/63912)
-
\[[`3a0549dacb`](https://redirect.github.com/nodejs/node/commit/3a0549dacb)]
- **doc**: fix keepAliveTimeout default in http.createServer options
(Jahanzaib iqbal)
[#​63974](https://redirect.github.com/nodejs/node/pull/63974)
-
\[[`5a35e48d08`](https://redirect.github.com/nodejs/node/commit/5a35e48d08)]
- **doc**: add sxa GPG key
([`ed25519`](https://redirect.github.com/nodejs/node/commit/ed25519))
(Stewart X Addison)
[#​64193](https://redirect.github.com/nodejs/node/pull/64193)
-
\[[`66e7f815f1`](https://redirect.github.com/nodejs/node/commit/66e7f815f1)]
- **doc**: add aduh95 to last security release steward (Antoine du
Hamel)
[#​63981](https://redirect.github.com/nodejs/node/pull/63981)
-
\[[`a7e35040dd`](https://redirect.github.com/nodejs/node/commit/a7e35040dd)]
- **doc**: fix typo in util.md (Daijiro Wachi)
[#​63961](https://redirect.github.com/nodejs/node/pull/63961)
-
\[[`d74b3a7e90`](https://redirect.github.com/nodejs/node/commit/d74b3a7e90)]
- **doc**: clarify callback exceptions (Matteo Collina)
[#​63939](https://redirect.github.com/nodejs/node/pull/63939)
-
\[[`b7a8f8fabd`](https://redirect.github.com/nodejs/node/commit/b7a8f8fabd)]
- **doc**: fix incorrect test runner mock examples (Kimaswa Emmanuel
Yusufu)
[#​63656](https://redirect.github.com/nodejs/node/pull/63656)
-
\[[`f11aa690cd`](https://redirect.github.com/nodejs/node/commit/f11aa690cd)]
- **doc**: fix typo in cli.md (Daijiro Wachi)
[#​63883](https://redirect.github.com/nodejs/node/pull/63883)
-
\[[`df85f50269`](https://redirect.github.com/nodejs/node/commit/df85f50269)]
- **doc**: fix typo in vm.md (Daijiro Wachi)
[#​63881](https://redirect.github.com/nodejs/node/pull/63881)
-
\[[`a00a567175`](https://redirect.github.com/nodejs/node/commit/a00a567175)]
- **doc**: fix typo in packages.md (Daijiro Wachi)
[#​63882](https://redirect.github.com/nodejs/node/pull/63882)
-
\[[`206c1b8437`](https://redirect.github.com/nodejs/node/commit/206c1b8437)]
- **doc**: fix a/an article typos in module, util, and dns (Daijiro
Wachi)
[#​63766](https://redirect.github.com/nodejs/node/pull/63766)
-
\[[`e3e5ef1cff`](https://redirect.github.com/nodejs/node/commit/e3e5ef1cff)]
- **doc**: update npm supported versions link (hojeong park)
[#​63672](https://redirect.github.com/nodejs/node/pull/63672)
-
\[[`e3c4852413`](https://redirect.github.com/nodejs/node/commit/e3c4852413)]
- **doc**: fix AES-OCB IV length in SubtleCrypto.supports example
(Anshika Jain)
[#​63717](https://redirect.github.com/nodejs/node/pull/63717)
-
\[[`0b3fbc82d7`](https://redirect.github.com/nodejs/node/commit/0b3fbc82d7)]
- **doc**: add webstreams to args for `pipeline` from `stream/promises`
(David Sanders)
[#​63628](https://redirect.github.com/nodejs/node/pull/63628)
-
\[[`62078a8328`](https://redirect.github.com/nodejs/node/commit/62078a8328)]
- **doc**: fix "used to sent" → "used to send" in http2 (Daijiro Wachi)
[#​63700](https://redirect.github.com/nodejs/node/pull/63700)
-
\[[`fd74eefb23`](https://redirect.github.com/nodejs/node/commit/fd74eefb23)]
- **doc**: clarify tty raw mode applies to input processing only
(Muhammad Zeeshan)
[#​63438](https://redirect.github.com/nodejs/node/pull/63438)
-
\[[`42cd7e47de`](https://redirect.github.com/nodejs/node/commit/42cd7e47de)]
- **doc**: add worker\_threads history entries (Bob Put)
[#​63545](https://redirect.github.com/nodejs/node/pull/63545)
-
\[[`d6ab039f24`](https://redirect.github.com/nodejs/node/commit/d6ab039f24)]
- **(SEMVER-MINOR)** **doc**: update `blockList` stability status to
release candidate (alphaleadership)
[#​63050](https://redirect.github.com/nodejs/node/pull/63050)
-
\[[`56bdd87378`](https://redirect.github.com/nodejs/node/commit/56bdd87378)]
- **doc**: move hyperlinks outside of text blocks (Aviv Keller)
[#​63493](https://redirect.github.com/nodejs/node/pull/63493)
-
\[[`1da05fb79d`](https://redirect.github.com/nodejs/node/commit/1da05fb79d)]
- **doc**: mark stream.compose stable (Matteo Collina)
[#​62562](https://redirect.github.com/nodejs/node/pull/62562)
-
\[[`7bb6dab70c`](https://redirect.github.com/nodejs/node/commit/7bb6dab70c)]
- **doc,crypto**: mark argon2 and encap/decap as stable (Filip Skokan)
[#​63924](https://redirect.github.com/nodejs/node/pull/63924)
-
\[[`1a4edb3c22`](https://redirect.github.com/nodejs/node/commit/1a4edb3c22)]
- **doc,lib**: align WebCrypto names with spec (Filip Skokan)
[#​63518](https://redirect.github.com/nodejs/node/pull/63518)
-
\[[`3c1636dabf`](https://redirect.github.com/nodejs/node/commit/3c1636dabf)]
- **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag
(Efe)
[#​62300](https://redirect.github.com/nodejs/node/pull/62300)
-
\[[`e0f211ca79`](https://redirect.github.com/nodejs/node/commit/e0f211ca79)]
- **events**: improve `addAbortListener` perf by caching options object
(Raz Luvaton)
[#​52367](https://redirect.github.com/nodejs/node/pull/52367)
-
\[[`a124429b36`](https://redirect.github.com/nodejs/node/commit/a124429b36)]
- **fs**: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied)
[#​63709](https://redirect.github.com/nodejs/node/pull/63709)
-
\[[`e323e877be`](https://redirect.github.com/nodejs/node/commit/e323e877be)]
- **(SEMVER-MINOR)** **fs**: support caller-supplied readFile() buffers
(Matteo Collina)
[#​63634](https://redirect.github.com/nodejs/node/pull/63634)
-
\[[`a41b4824d7`](https://redirect.github.com/nodejs/node/commit/a41b4824d7)]
- **fs**: prevent spurious recursive watch events on prefix siblings
(Marco)
[#​63095](https://redirect.github.com/nodejs/node/pull/63095)
-
\[[`c63e00e3a5`](https://redirect.github.com/nodejs/node/commit/c63e00e3a5)]
- **fs**: ignore deleted dirs in recursive watch scan (Trivikram Kamat)
[#​63686](https://redirect.github.com/nodejs/node/pull/63686)
-
\[[`d3d7cd05e3`](https://redirect.github.com/nodejs/node/commit/d3d7cd05e3)]
- **fs**: coerce -0 to +0 in mode flags and watch intervals (Filip
Skokan)
[#​63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`6f6387ecb3`](https://redirect.github.com/nodejs/node/commit/6f6387ecb3)]
- **gyp**: update deps gypfiles (Nad Alaba)
[#​63117](https://redirect.github.com/nodejs/node/pull/63117)
-
\[[`592544af44`](https://redirect.github.com/nodejs/node/commit/592544af44)]
- **http**: document and validate options.path when it's in
absolute-form (Joyee Cheung)
[#​64108](https://redirect.github.com/nodejs/node/pull/64108)
-
\[[`c1248c9544`](https://redirect.github.com/nodejs/node/commit/c1248c9544)]
- **(SEMVER-MINOR)** **http**: add httpValidation option to configure
header value validation (RajeshKumar11)
[#​61597](https://redirect.github.com/nodejs/node/pull/61597)
-
\[[`85a223bf15`](https://redirect.github.com/nodejs/node/commit/85a223bf15)]
- **http**: fix drain event with cork/uncork (David Evans)
[#​64038](https://redirect.github.com/nodejs/node/pull/64038)
-
\[[`8b060a9628`](https://redirect.github.com/nodejs/node/commit/8b060a9628)]
- **inspector**: fix crash when writing to closed inspector socket
(ympark2011)
[#​64209](https://redirect.github.com/nodejs/node/pull/64209)
-
\[[`e68a3d33ac`](https://redirect.github.com/nodejs/node/commit/e68a3d33ac)]
- **inspector**: fix inspector.close() documented behavior (Chengzhong
Wu) [#​63837](https://redirect.github.com/nodejs/node/pull/63837)
-
\[[`d3682930b7`](https://redirect.github.com/nodejs/node/commit/d3682930b7)]
- **lib**: fix missing lazyDOMException import (Filip Skokan)
[#​64033](https://redirect.github.com/nodejs/node/pull/64033)
-
\[[`af9ea9cfcf`](https://redirect.github.com/nodejs/node/commit/af9ea9cfcf)]
- **lib**: reject string "0" in validatePort when allowZero is false
(Daijiro Wachi)
[#​64174](https://redirect.github.com/nodejs/node/pull/64174)
-
\[[`cd1ea26110`](https://redirect.github.com/nodejs/node/commit/cd1ea26110)]
- **lib**: use `__proto__: null` when calling `ObjectDefineProperty`
(Antoine du Hamel)
[#​64239](https://redirect.github.com/nodejs/node/pull/64239)
-
\[[`5b264398ce`](https://redirect.github.com/nodejs/node/commit/5b264398ce)]
- **lib**: lazily initialize kEvents and kHandlers maps (Guilherme
Araújo)
[#​63702](https://redirect.github.com/nodejs/node/pull/63702)
-
\[[`823efe8c71`](https://redirect.github.com/nodejs/node/commit/823efe8c71)]
- **lib**: improve control abstraction coverage in frozen intrinsics
(Renegade334)
[#​63698](https://redirect.github.com/nodejs/node/pull/63698)
-
\[[`7f4af5568f`](https://redirect.github.com/nodejs/node/commit/7f4af5568f)]
- **lib**: add Iterator global to primordials (Renegade334)
[#​63698](https://redirect.github.com/nodejs/node/pull/63698)
-
\[[`c8f3f5e5a5`](https://redirect.github.com/nodejs/node/commit/c8f3f5e5a5)]
- **lib**: make `Navigator#language` getter throw on invalid `this`
(Mohamed Sayed)
[#​63601](https://redirect.github.com/nodejs/node/pull/63601)
-
\[[`1ebbbd59cf`](https://redirect.github.com/nodejs/node/commit/1ebbbd59cf)]
- **lib**: optimize webidl conversion options (Filip Skokan)
[#​62756](https://redirect.github.com/nodejs/node/pull/62756)
-
\[[`88590d1bb7`](https://redirect.github.com/nodejs/node/commit/88590d1bb7)]
- **meta**: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot\[bot])
[#​63726](https://redirect.github.com/nodejs/node/pull/63726)
-
\[[`0ea9cb9630`](https://redirect.github.com/nodejs/node/commit/0ea9cb9630)]
- **meta**: bump actions/upload-artifact from 7.0.0 to 7.0.1
(dependabot\[bot])
[#​62850](https://redirect.github.com/nodejs/node/pull/62850)
-
\[[`f7275a0864`](https://redirect.github.com/nodejs/node/commit/f7275a0864)]
- **meta**: fix linter warning in `stale.yml` (Antoine du Hamel)
[#​64281](https://redirect.github.com/nodejs/node/pull/64281)
-
\[[`3a77d21d8c`](https://redirect.github.com/nodejs/node/commit/3a77d21d8c)]
- **meta**: bump actions/cache from 5.0.5 to 6.1.0 (dependabot\[bot])
[#​64248](https://redirect.github.com/nodejs/node/pull/64248)
-
\[[`84e2836c95`](https://redirect.github.com/nodejs/node/commit/84e2836c95)]
- **meta**: bump github/codeql-action/autobuild from 4.36.1 to 4.36.2
(dependabot\[bot])
[#​64247](https://redirect.github.com/nodejs/node/pull/64247)
-
\[[`09f800eec6`](https://redirect.github.com/nodejs/node/commit/09f800eec6)]
- **meta**: bump github/codeql-action/analyze from 4.36.1 to 4.36.2
(dependabot\[bot])
[#​64246](https://redirect.github.com/nodejs/node/pull/64246)
-
\[[`6df1f97e64`](https://redirect.github.com/nodejs/node/commit/6df1f97e64)]
- **meta**: bump codecov/codecov-action from 6.0.1 to 7.0.0
(dependabot\[bot])
[#​64244](https://redirect.github.com/nodejs/node/pull/64244)
-
\[[`737eb89651`](https://redirect.github.com/nodejs/node/commit/737eb89651)]
- **meta**: bump rtCamp/action-slack-notify from 2.3.3 to 2.4.0
(dependabot\[bot])
[#​64243](https://redirect.github.com/nodejs/node/pull/64243)
-
\[[`dac3cd8b8f`](https://redirect.github.com/nodejs/node/commit/dac3cd8b8f)]
- **meta**: bump github/codeql-action/init from 4.36.1 to 4.36.2
(dependabot\[bot])
[#​64242](https://redirect.github.com/nodejs/node/pull/64242)
-
\[[`108a6bc481`](https://redirect.github.com/nodejs/node/commit/108a6bc481)]
- **meta**: bump github/codeql-action/upload-sarif from 4.36.1 to 4.36.2
(dependabot\[bot])
[#​64240](https://redirect.github.com/nodejs/node/pull/64240)
-
\[[`34d09a725d`](https://redirect.github.com/nodejs/node/commit/34d09a725d)]
- **meta**: clarify V8 flags are outside threat model (Matteo Collina)
[#​64224](https://redirect.github.com/nodejs/node/pull/64224)
-
\[[`944d9bc25f`](https://redirect.github.com/nodejs/node/commit/944d9bc25f)]
- **meta**: move one or more collaborators to emeritus (Node.js GitHub
Bot) [#​64057](https://redirect.github.com/nodejs/node/pull/64057)
-
\[[`cc22555402`](https://redirect.github.com/nodejs/node/commit/cc22555402)]
- **meta**: update status of past strategic initiatives (Joyee Cheung)
[#​63480](https://redirect.github.com/nodejs/node/pull/63480)
-
\[[`da7a21931e`](https://redirect.github.com/nodejs/node/commit/da7a21931e)]
- **meta**: speed up stale bot (Aviv Keller)
[#​64075](https://redirect.github.com/nodejs/node/pull/64075)
-
\[[`7bfcf7ca56`](https://redirect.github.com/nodejs/node/commit/7bfcf7ca56)]
- **meta**: bump github/codeql-action from 4.35.3 to 4.36.1
(dependabot\[bot])
[#​63724](https://redirect.github.com/nodejs/node/pull/63724)
-
\[[`db6c983cdd`](https://redirect.github.com/nodejs/node/commit/db6c983cdd)]
- **meta**: bump actions/cache from 5.0.4 to 5.0.5 (dependabot\[bot])
[#​62847](https://redirect.github.com/nodejs/node/pull/62847)
-
\[[`9e4f1339d1`](https://redirect.github.com/nodejs/node/commit/9e4f1339d1)]
- **meta**: bump codecov/codecov-action from 6.0.0 to 6.0.1
(dependabot\[bot])
[#​63725](https://redirect.github.com/nodejs/node/pull/63725)
-
\[[`92c98d3ade`](https://redirect.github.com/nodejs/node/commit/92c98d3ade)]
- **meta**: bump actions/stale from 10.2.0 to 10.3.0 (dependabot\[bot])
[#​63728](https://redirect.github.com/nodejs/node/pull/63728)
-
\[[`bbd3ffde89`](https://redirect.github.com/nodejs/node/commit/bbd3ffde89)]
- **meta**: bump step-security/harden-runner from 2.19.0 to 2.19.4
(dependabot\[bot])
[#​63727](https://redirect.github.com/nodejs/node/pull/63727)
-
\[[`a6dd675c82`](https://redirect.github.com/nodejs/node/commit/a6dd675c82)]
- **module**: enable import support for addons by default (Chengzhong
Wu) [#​64221](https://redirect.github.com/nodejs/node/pull/64221)
-
\[[`fb2ccb15a1`](https://redirect.github.com/nodejs/node/commit/fb2ccb15a1)]
- **module**: use file: URL as sourceURL for type-stripped CommonJS
(Joyee Cheung)
[#​63705](https://redirect.github.com/nodejs/node/pull/63705)
-
\[[`b9e17dc424`](https://redirect.github.com/nodejs/node/commit/b9e17dc424)]
- **net**: early TCP binding via synchronous net.BoundSocket (Guy
Bedford)
[#​63951](https://redirect.github.com/nodejs/node/pull/63951)
-
\[[`a534b65815`](https://redirect.github.com/nodejs/node/commit/a534b65815)]
- **(SEMVER-MINOR)** **net**: support TCP\_KEEPINTVL and TCP\_KEEPCNT in
setKeepAlive (Guy Bedford)
[#​63825](https://redirect.github.com/nodejs/node/pull/63825)
-
\[[`c55dd030e6`](https://redirect.github.com/nodejs/node/commit/c55dd030e6)]
- **net**: coerce -0 to +0 in BlockList prefixes (Filip Skokan)
[#​63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`a23cdec683`](https://redirect.github.com/nodejs/node/commit/a23cdec683)]
- **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop
iteration (Pablo Erhard)
[#​62935](https://redirect.github.com/nodejs/node/pull/62935)
-
\[[`f08b83bc1d`](https://redirect.github.com/nodejs/node/commit/f08b83bc1d)]
- **perf\_hooks**: add NODE\_PERFORMANCE\_GC\_MINOR\_MARK\_SWEEP
constant (Attila Szegedi)
[#​63877](https://redirect.github.com/nodejs/node/pull/63877)
-
\[[`8d58e1b415`](https://redirect.github.com/nodejs/node/commit/8d58e1b415)]
- **process**: fix finalization cleanup ref tracking (Trivikram Kamat)
[#​64087](https://redirect.github.com/nodejs/node/pull/64087)
-
\[[`c757e3ef59`](https://redirect.github.com/nodejs/node/commit/c757e3ef59)]
- **sqlite**: do not leave database open after failed open (Yagiz
Nizipli)
[#​63854](https://redirect.github.com/nodejs/node/pull/63854)
-
\[[`87064a096b`](https://redirect.github.com/nodejs/node/commit/87064a096b)]
- **sqlite**: fix stack-use-after-scope with function callback
(ndossche)
[#​63640](https://redirect.github.com/nodejs/node/pull/63640)
-
\[[`7428b57a37`](https://redirect.github.com/nodejs/node/commit/7428b57a37)]
- **(SEMVER-MINOR)** **src**: allow empty --experimental-config-file
(Marco Ippolito)
[#​61610](https://redirect.github.com/nodejs/node/pull/61610)
-
\[[`d7946c9c07`](https://redirect.github.com/nodejs/node/commit/d7946c9c07)]
- **src**: add test flag to config file (Marco Ippolito)
[#​60798](https://redirect.github.com/nodejs/node/pull/60798)
-
\[[`a642657d71`](https://redirect.github.com/nodejs/node/commit/a642657d71)]
- **src**: rename config file testRunner to test (Marco Ippolito)
[#​60798](https://redirect.github.com/nodejs/node/pull/60798)
-
\[[`818b43d09e`](https://redirect.github.com/nodejs/node/commit/818b43d09e)]
- **src**: do not enable wasm trap handler if there's not enough vmem
(Joyee Cheung)
[#​62132](https://redirect.github.com/nodejs/node/pull/62132)
-
\[[`af5e1a9729`](https://redirect.github.com/nodejs/node/commit/af5e1a9729)]
- **src**: fix escaping of single quotes in task runner (Antoine du
Hamel)
[#​64089](https://redirect.github.com/nodejs/node/pull/64089)
-
\[[`8a5d3bc168`](https://redirect.github.com/nodejs/node/commit/8a5d3bc168)]
- **src**: abstract tracing agent for both legacy and perfetto
(Chengzhong Wu)
[#​64053](https://redirect.github.com/nodejs/node/pull/64053)
-
\[[`ce6f29e45b`](https://redirect.github.com/nodejs/node/commit/ce6f29e45b)]
- **src**: avoid redundant call to `std::get_if<>()` (Tobias Nießen)
[#​64094](https://redirect.github.com/nodejs/node/pull/64094)
-
\[[`96478050f2`](https://redirect.github.com/nodejs/node/commit/96478050f2)]
- **src**: omit unconvertible names in cjs\_lexer::Parse (Yagiz Nizipli)
[#​63943](https://redirect.github.com/nodejs/node/pull/63943)
-
\[[`0147ed746e`](https://redirect.github.com/nodejs/node/commit/0147ed746e)]
- **src**: guard OpenSSL compression header include (Filip Skokan)
[#​64009](https://redirect.github.com/nodejs/node/pull/64009)
-
\[[`8d2858a9c4`](https://redirect.github.com/nodejs/node/commit/8d2858a9c4)]
- **src**: handle empty MaybeLocal in cjs\_lexer::Parse (Yagiz Nizipli)
[#​63885](https://redirect.github.com/nodejs/node/pull/63885)
-
\[[`e5289d180f`](https://redirect.github.com/nodejs/node/commit/e5289d180f)]
- **src**: do not track weak `BaseObject`s as childrens of `Realm`s
(Anna Henningsen)
[#​63842](https://redirect.github.com/nodejs/node/pull/63842)
-
\[[`e8352ff754`](https://redirect.github.com/nodejs/node/commit/e8352ff754)]
- **src**: allow tracking children in `MemoryTracker` with weak edges
(Anna Henningsen)
[#​63842](https://redirect.github.com/nodejs/node/pull/63842)
-
\[[`a408f279c5`](https://redirect.github.com/nodejs/node/commit/a408f279c5)]
- **src**: use C++14 deprecated attribute for `NODE_DEPRECATED` (Anna
Henningsen)
[#​63755](https://redirect.github.com/nodejs/node/pull/63755)
-
\[[`4b5eb7b72d`](https://redirect.github.com/nodejs/node/commit/4b5eb7b72d)]
- **src**: add cleanup hooks to `node::ObjectWrap` (Anna Henningsen)
[#​63642](https://redirect.github.com/nodejs/node/pull/63642)
-
\[[`44976c6071`](https://redirect.github.com/nodejs/node/commit/44976c6071)]
- **src**: fix edge case when deflateInit2() fails with
Z\_VERSION\_ERROR (Nora Dossche)
[#​63476](https://redirect.github.com/nodejs/node/pull/63476)
-
\[[`5b3bb284f3`](https://redirect.github.com/nodejs/node/commit/5b3bb284f3)]
- **src**: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can
Altin)
[#​63385](https://redirect.github.com/nodejs/node/pull/63385)
-
\[[`7cdad636c4`](https://redirect.github.com/nodejs/node/commit/7cdad636c4)]
- **src**: fix crash when reading length on Storage.prototype (Mohamed
Sayed)
[#​63529](https://redirect.github.com/nodejs/node/pull/63529)
-
\[[`c438250c68`](https://redirect.github.com/nodejs/node/commit/c438250c68)]
- **stream**: cut per-chunk overhead in WHATWG streams (Matteo Collina)
[#​64252](https://redirect.github.com/nodejs/node/pull/64252)
-
\[[`291c127947`](https://redirect.github.com/nodejs/node/commit/291c127947)]
- **stream**: reduce allocations on WHATWG streams hot paths (Matteo
Collina)
[#​63876](https://redirect.github.com/nodejs/node/pull/63876)
-
\[[`3d91aeb434`](https://redirect.github.com/nodejs/node/commit/3d91aeb434)]
- **stream**: optimize pipeTo promise handling (Matteo Collina)
[#​63572](https://redirect.github.com/nodejs/node/pull/63572)
-
\[[`fcbff00a44`](https://redirect.github.com/nodejs/node/commit/fcbff00a44)]
- **stream**: preserve half-open duplexes in async iteration (Efe)
[#​64275](https://redirect.github.com/nodejs/node/pull/64275)
-
\[[`e57597173c`](https://redirect.github.com/nodejs/node/commit/e57597173c)]
- **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo
Collina)
[#​64195](https://redirect.github.com/nodejs/node/pull/64195)
-
\[[`a48edf40e8`](https://redirect.github.com/nodejs/node/commit/a48edf40e8)]
- **stream**: proxy first own method in Readable.wrap() (Daijiro Wachi)
[#​64048](https://redirect.github.com/nodejs/node/pull/64048)
-
\[[`f58c5bafcf`](https://redirect.github.com/nodejs/node/commit/f58c5bafcf)]
- **stream**: fix Writable.toWeb() desiredSize for non-object-mode
(Matteo Collina)
[#​62986](https://redirect.github.com/nodejs/node/pull/62986)
-
\[[`7261276f45`](https://redirect.github.com/nodejs/node/commit/7261276f45)]
- **stream**: fix Utf8Stream stall after full write of multi-byte data
(Daijiro Wachi)
[#​63964](https://redirect.github.com/nodejs/node/pull/63964)
-
\[[`1558986b78`](https://redirect.github.com/nodejs/node/commit/1558986b78)]
- **stream**: only pass the expected number of parameters to callbacks
(Antoine du Hamel)
[#​63909](https://redirect.github.com/nodejs/node/pull/63909)
-
\[[`edef89ba6a`](https://redirect.github.com/nodejs/node/commit/edef89ba6a)]
- **stream**: fix dropped first chunk in Utf8Stream buffer mode (Daijiro
Wachi)
[#​63833](https://redirect.github.com/nodejs/node/pull/63833)
-
\[[`915e3e2f42`](https://redirect.github.com/nodejs/node/commit/915e3e2f42)]
- **stream**: check done before backpressure in stream reader (Daijiro
Wachi)
[#​63699](https://redirect.github.com/nodejs/node/pull/63699)
-
\[[`2d29628b5b`](https://redirect.github.com/nodejs/node/commit/2d29628b5b)]
- **test**: update WPT for WebCryptoAPI to
[`03a1476`](https://redirect.github.com/nodejs/node/commit/03a1476844)
(Node.js GitHub Bot)
[#​63900](https://redirect.github.com/nodejs/node/pull/63900)
-
\[[`89e23b70c4`](https://redirect.github.com/nodejs/node/commit/89e23b70c4)]
- **test**: deflake test-debugger-probe-timeout (Joyee Cheung)
[#​63547](https://redirect.github.com/nodejs/node/pull/63547)
-
\[[`54ca514414`](https://redirect.github.com/nodejs/node/commit/54ca514414)]
- **test**: make blob desiredSize assertion robust (Trivikram Kamat)
[#​64106](https://redirect.github.com/nodejs/node/pull/64106)
-
\[[`01cbe530eb`](https://redirect.github.com/nodejs/node/commit/01cbe530eb)]
- **test**: update WPT for urlpattern to
[`11a459a`](https://redirect.github.com/nodejs/node/commit/11a459a2b1)
(Node.js GitHub Bot)
[#​64037](https://redirect.github.com/nodejs/node/pull/64037)
-
\[[`6fcd3cf516`](https://redirect.github.com/nodejs/node/commit/6fcd3cf516)]
- **test**: improve lcov reporter snapshot diagnostics (Trivikram Kamat)
[#​64049](https://redirect.github.com/nodejs/node/pull/64049)
-
\[[`f50a55d7e5`](https://redirect.github.com/nodejs/node/commit/f50a55d7e5)]
- **test**: keep finalization close fixture ref alive (Trivikram Kamat)
[#​64085](https://redirect.github.com/nodejs/node/pull/64085)
-
\[[`3085714530`](https://redirect.github.com/nodejs/node/commit/3085714530)]
- **test**: fix typo from overriden to overridden (parkhojeong)
[#​63403](https://redirect.github.com/nodejs/node/pull/63403)
-
\[[`9f5347e8df`](https://redirect.github.com/nodejs/node/commit/9f5347e8df)]
- **test**: mark hr-time WPT flaky on macos15-x64 (Trivikram Kamat)
[#​64054](https://redirect.github.com/nodejs/node/pull/64054)
-
\[[`44b4fe4246`](https://redirect.github.com/nodejs/node/commit/44b4fe4246)]
- **test**: use one-off agent in http consumed timeout test (Trivikram
Kamat)
[#​64052](https://redirect.github.com/nodejs/node/pull/64052)
-
\[[`2f567edaca`](https://redirect.github.com/nodejs/node/commit/2f567edaca)]
- **test**: fix flaky test-runner coverage threshold test (Trivikram
Kamat)
[#​64051](https://redirect.github.com/nodejs/node/pull/64051)
-
\[[`a56fbb2d36`](https://redirect.github.com/nodejs/node/commit/a56fbb2d36)]
- **test**: tolerate duplicate watch change events (Trivikram Kamat)
[#​63937](https://redirect.github.com/nodejs/node/pull/63937)
-
\[[`b636f4769c`](https://redirect.github.com/nodejs/node/commit/b636f4769c)]
- **test**: mark test-debugger-run-after-quit-restart as flaky on macOS
(Matteo Collina)
[#​64006](https://redirect.github.com/nodejs/node/pull/64006)
-
\[[`ba23eb9717`](https://redirect.github.com/nodejs/node/commit/ba23eb9717)]
- **test**: update WPT for url to
[`d4598eb`](https://redirect.github.com/nodejs/node/commit/d4598eba09)
(Node.js GitHub Bot)
[#​63899](https://redirect.github.com/nodejs/node/pull/63899)
-
\[[`bc420f20d8`](https://redirect.github.com/nodejs/node/commit/bc420f20d8)]
- **test**: update WPT for urlpattern to
[`23aac92`](https://redirect.github.com/nodejs/node/commit/23aac92784)
(Node.js GitHub Bot)
[#​63898](https://redirect.github.com/nodejs/node/pull/63898)
-
\[[`d2c9c07af8`](https://redirect.github.com/nodejs/node/commit/d2c9c07af8)]
- **test**: add tests for 3 methods in utils (Daijiro Wachi)
[#​63765](https://redirect.github.com/nodejs/node/pull/63765)
-
\[[`4e00c8ec2e`](https://redirect.github.com/nodejs/node/commit/4e00c8ec2e)]
- **test**: mark SEA tests flaky on linux arm debug (Trivikram Kamat)
[#​63743](https://redirect.github.com/nodejs/node/pull/63743)
-
\[[`a17cf06d12`](https://redirect.github.com/nodejs/node/commit/a17cf06d12)]
- **test**: validate ERR\_INVALID\_THIS for scheduler methods (Daijiro
Wachi)
[#​63764](https://redirect.github.com/nodejs/node/pull/63764)
-
\[[`d59d7fdd16`](https://redirect.github.com/nodejs/node/commit/d59d7fdd16)]
- **test**: add coverage outside SEA (Daijiro Wachi)
[#​63744](https://redirect.github.com/nodejs/node/pull/63744)
-
\[[`71a32d31bf`](https://redirect.github.com/nodejs/node/commit/71a32d31bf)]
- **test**: update WPT for urlpattern to
[`2f28df5`](https://redirect.github.com/nodejs/node/commit/2f28df545c)
(Node.js GitHub Bot)
[#​63771](https://redirect.github.com/nodejs/node/pull/63771)
-
\[[`28c77ab174`](https://redirect.github.com/nodejs/node/commit/28c77ab174)]
- **test**: make Brotli 16GB test wait for backpressure (Trivikram
Kamat)
[#​63389](https://redirect.github.com/nodejs/node/pull/63389)
-
\[[`9a81921d4a`](https://redirect.github.com/nodejs/node/commit/9a81921d4a)]
- **test**: add regression test for using `ObjectWrap` in worker
(Mohamed Akram)
[#​63642](https://redirect.github.com/nodejs/node/pull/63642)
-
\[[`88ab61f2f8`](https://redirect.github.com/nodejs/node/commit/88ab61f2f8)]
- **test**: accept SIGILL aborts in async-hooks tests (Trivikram Kamat)
[#​63687](https://redirect.github.com/nodejs/node/pull/63687)
-
\[[`b4f5c86463`](https://redirect.github.com/nodejs/node/commit/b4f5c86463)]
- **test**: add more test cases for pathToFileURL (Rafael Gonzaga)
[#​63293](https://redirect.github.com/nodejs/node/pull/63293)
-
\[[`812a66f0ac`](https://redirect.github.com/nodejs/node/commit/812a66f0ac)]
- **test**: update test426-fixtures to
[`2965987`](https://redirect.github.com/nodejs/node/commit/2965987bf4c96afa400c9356c8e620cb340aaee)
(Node.js GitHub Bot)
[#​63668](https://redirect.github.com/nodejs/node/pull/63668)
-
\[[`2bf0de838d`](https://redirect.github.com/nodejs/node/commit/2bf0de838d)]
- **test**: cover webcrypto prototype pollution systematically (Filip
Skokan)
[#​63520](https://redirect.github.com/nodejs/node/pull/63520)
-
\[[`bec6856ae8`](https://redirect.github.com/nodejs/node/commit/bec6856ae8)]
- **test,debugger**: add test for type stripping in debugger probe mode
(Joyee Cheung)
[#​63748](https://redirect.github.com/nodejs/node/pull/63748)
-
\[[`a2b9095e03`](https://redirect.github.com/nodejs/node/commit/a2b9095e03)]
- **test\_runner**: avoid recompiling coverage globs for every file
(sangwook)
[#​63675](https://redirect.github.com/nodejs/node/pull/63675)
-
\[[`02fbff446f`](https://redirect.github.com/nodejs/node/commit/02fbff446f)]
- **test\_runner**: cache `shouldSkipFileCoverage` result per URL
(sangwook)
[#​63675](https://redirect.github.com/nodejs/node/pull/63675)
-
\[[`094869354a`](https://redirect.github.com/nodejs/node/commit/094869354a)]
- **test\_runner**: ignore erased TS lines in coverage (Matteo Collina)
[#​63510](https://redirect.github.com/nodejs/node/pull/63510)
-
\[[`68edc2b009`](https://redirect.github.com/nodejs/node/commit/68edc2b009)]
- **test\_runner**: fix suite diagnostic chanel end (Moshe Atlow)
[#​63533](https://redirect.github.com/nodejs/node/pull/63533)
-
\[[`659d5bf068`](https://redirect.github.com/nodejs/node/commit/659d5bf068)]
- **test\_runner**: add parentId to test events with testId (Moshe
Atlow)
[#​63435](https://redirect.github.com/nodejs/node/pull/63435)
-
\[[`eaebeb8b88`](https://redirect.github.com/nodejs/node/commit/eaebeb8b88)]
- **test\_runner**: fix hooks test context (Moshe Atlow)
[#​63285](https://redirect.github.com/nodejs/node/pull/63285)
-
\[[`d03d96889b`](https://redirect.github.com/nodejs/node/commit/d03d96889b)]
- **test\_runner**: add tags option and tag-name filter (Chemi Atlow)
[#​63221](https://redirect.github.com/nodejs/node/pull/63221)
-
\[[`e8c3db1364`](https://redirect.github.com/nodejs/node/commit/e8c3db1364)]
- **test\_runner**: add `getTestContext()` (Moshe Atlow)
[#​62501](https://redirect.github.com/nodejs/node/pull/62501)
-
\[[`345c591d10`](https://redirect.github.com/nodejs/node/commit/345c591d10)]
- **test\_runner**: filter execArgv fallback for child tests (Trivikram
Kamat)
[#​64056](https://redirect.github.com/nodejs/node/pull/64056)
-
\[[`2f47fb23bf`](https://redirect.github.com/nodejs/node/commit/2f47fb23bf)]
- **test\_runner**: improve coverage failure diagnostics (Trivikram
Kamat)
[#​64050](https://redirect.github.com/nodejs/node/pull/64050)
-
\[[`260cf1ac89`](https://redirect.github.com/nodejs/node/commit/260cf1ac89)]
- **test\_runner**: add timestamp to JUnit reporter testsuites
(sangwook)
[#​64029](https://redirect.github.com/nodejs/node/pull/64029)
-
\[[`24140eafdf`](https://redirect.github.com/nodejs/node/commit/24140eafdf)]
- **test\_runner**: remove unused shuffleArrayWithSeed (Daijiro Wachi)
[#​63847](https://redirect.github.com/nodejs/node/pull/63847)
-
\[[`b7fdb4891a`](https://redirect.github.com/nodejs/node/commit/b7fdb4891a)]
- **test\_runner**: fix watch cwd with isolation none (Trivikram Kamat)
[#​63690](https://redirect.github.com/nodejs/node/pull/63690)
-
\[[`e48b307e09`](https://redirect.github.com/nodejs/node/commit/e48b307e09)]
- **timers**: reuse Timeout objects in setStreamTimeout (Matteo Collina)
[#​64254](https://redirect.github.com/nodejs/node/pull/64254)
-
\[[`5396235993`](https://redirect.github.com/nodejs/node/commit/5396235993)]
- **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip
Skokan)
[#​64119](https://redirect.github.com/nodejs/node/pull/64119)
-
\[[`a653e9bb57`](https://redirect.github.com/nodejs/node/commit/a653e9bb57)]
- **tls**: handle large RSA exponents in X.509 cert (Tobias Nießen)
[#​64093](https://redirect.github.com/nodejs/node/pull/64093)
-
\[[`5e901b5cd9`](https://redirect.github.com/nodejs/node/commit/5e901b5cd9)]
- **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim
Perry)
[#​62217](https://redirect.github.com/nodejs/node/pull/62217)
-
\[[`3abcfa723c`](https://redirect.github.com/nodejs/node/commit/3abcfa723c)]
- **tls**: route event listener exceptions through error handlers
(Antoine du Hamel)
[#​63822](https://redirect.github.com/nodejs/node/pull/63822)
-
\[[`eaba4cd59d`](https://redirect.github.com/nodejs/node/commit/eaba4cd59d)]
- **tools**: bump the eslint group in /tools/eslint with 8 updates
(dependabot\[bot])
[#​64249](https://redirect.github.com/nodejs/node/pull/64249)
-
\[[`7d7ea1dbca`](https://redirect.github.com/nodejs/node/commit/7d7ea1dbca)]
- **tools**: update c-ares updater script (Antoine du Hamel)
[#​64194](https://redirect.github.com/nodejs/node/pull/64194)
-
\[[`976827cd71`](https://redirect.github.com/nodejs/node/commit/976827cd71)]
- **tools**: validate version number in release proposal commit message
lint (Antoine du Hamel)
[#​64070](https://redirect.github.com/nodejs/node/pull/64070)
-
\[[`cc0c586b52`](https://redirect.github.com/nodejs/node/commit/cc0c586b52)]
- **tools**: update sccache to v0.16.0 (Michaël Zasso)
[#​63078](https://redirect.github.com/nodejs/node/pull/63078)
-
\[[`f0a35fa56a`](https://redirect.github.com/nodejs/node/commit/f0a35fa56a)]
- **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md
(dependabot\[bot])
[#​63948](https://redirect.github.com/nodejs/node/pull/63948)
-
\[[`dafbd23240`](https://redirect.github.com/nodejs/node/commit/dafbd23240)]
- **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint
(dependabot\[bot])
[#​63947](https://redirect.github.com/nodejs/node/pull/63947)
-
\[[`0ae1552650`](https://redirect.github.com/nodejs/node/commit/0ae1552650)]
- **tools**: update the llhttp updater script (Antoine du Hamel)
[#​63819](https://redirect.github.com/nodejs/node/pull/63819)
-
\[[`3623586d1f`](https://redirect.github.com/nodejs/node/commit/3623586d1f)]
- **tools**: align Bash snippets in GHA with `lint-sh` conventions
(Antoine du Hamel)
[#​63829](https://redirect.github.com/nodejs/node/pull/63829)
-
\[[`64b130ce1d`](https://redirect.github.com/nodejs/node/commit/64b130ce1d)]
- **tools**: bump the eslint group in /tools/eslint with 7 updates
(dependabot\[bot])
[#​63730](https://redirect.github.com/nodejs/node/pull/63730)
-
\[[`4900cac251`](https://redirect.github.com/nodejs/node/commit/4900cac251)]
- **tools**: fix zlib updater script (Antoine du Hamel)
[#​63707](https://redirect.github.com/nodejs/node/pull/63707)
-
\[[`8edf3abafc`](https://redirect.github.com/nodejs/node/commit/8edf3abafc)]
- **typings**: add typing for crypto (Filip Skokan)
[#​64122](https://redirect.github.com/nodejs/node/pull/64122)
-
\[[`d5be94e820`](https://redirect.github.com/nodejs/node/commit/d5be94e820)]
- **url**: fix URLSearchParams(null) to prudce null= per spec (Marco)
[#​63782](https://redirect.github.com/nodejs/node/pull/63782)
-
\[[`ee66a3851c`](https://redirect.github.com/nodejs/node/commit/ee66a3851c)]
- **util**: fix OOM in inspect color stack formatting (Ijtihed Kilani)
[#​64022](https://redirect.github.com/nodejs/node/pull/64022)
-
\[[`e26f183699`](https://redirect.github.com/nodejs/node/commit/e26f183699)]
- **util**: fix scientific notation formatting (Daijiro Wachi)
[#​63823](https://redirect.github.com/nodejs/node/pull/63823)
-
\[[`7993e3e476`](https://redirect.github.com/nodejs/node/commit/7993e3e476)]
- **util**: fix -0 formatting when numericSeparator is enabled (Daijiro
Wachi)
[#​63815](https://redirect.github.com/nodejs/node/pull/63815)
-
\[[`38758a7789`](https://redirect.github.com/nodejs/node/commit/38758a7789)]
- **util**: remove style caches from styleText slow path (Guilherme
Araújo)
[#​63706](https://redirect.github.com/nodejs/node/pull/63706)
-
\[[`46a0ca256a`](https://redirect.github.com/nodejs/node/commit/46a0ca256a)]
- **watch**: print name of changed file that triggers restart (Marco)
[#​63781](https://redirect.github.com/nodejs/node/pull/63781)
-
\[[`e1582818ad`](https://redirect.github.com/nodejs/node/commit/e1582818ad)]
- **watch**: cancel pending restart on shutdown (Trivikram Kamat)
[#​63383](https://redirect.github.com/nodejs/node/pull/63383)
-
\[[`9a208668b0`](https://redirect.github.com/nodejs/node/commit/9a208668b0)]
- **zlib**: validate flush king for all streams (Ic3b3rg)
[#​63746](https://redirect.github.com/nodejs/node/pull/63746)
-
\[[`928981d803`](https://redirect.github.com/nodejs/node/commit/928981d803)]
- **zlib**: validate flush kind for brotli streams (Ic3b3rg)
[#​63746](https://redirect.github.com/nodejs/node/pull/63746)
-
\[[`fd0fb00164`](https://redirect.github.com/nodejs/node/commit/fd0fb00164)]
- **zlib**: expose rejectGarbageAfterEnd option (Filip Skokan)
[#​64023](https://redirect.github.com/nodejs/node/pull/64023)
-
\[[`e334d30b4c`](https://redirect.github.com/nodejs/node/commit/e334d30b4c)]
- **zlib**: reject trailing gzip members in web streams (Filip Skokan)
[#​64023](https://redirect.github.com/nodejs/node/pull/64023)
-
\[[`7433c3df2e`](https://redirect.github.com/nodejs/node/commit/7433c3df2e)]
- **zlib**: coerce -0 to +0 for crc32 seeds (Filip Skokan)
[#​63556](https://redirect.github.com/nodejs/node/pull/63556)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…o v0.158.0 (prometheus#2370) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [otel/opentelemetry-collector-contrib](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases) | minor | `0.157.0` → `0.158.0` | --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-collector-releases (otel/opentelemetry-collector-contrib)</summary> ### [`v0.158.0`](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/blob/HEAD/CHANGELOG.md#v01580) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/compare/v0.157.0...v0.158.0) ##### 🛑 Breaking changes 🛑 - `all`: Update Cosign usage to work with v3 ([#​1570](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1570)) The Cosign v3 upgrade introduced a change in signing workflow. Previous two files were required to map the outputs (certificate and signature), now only one file is required. The new file is a bundle that contains both outputs in JSON format. This change has been done following the guidance from <https://goreleaser.com/blog/cosign-v3/>. With this change, anyone who wants to verify the signature of the artifacts produced by the release will need to use Cosign V3 and point to the new bundle file or download the bundle and unpack it to get the certificate and signature files. - `all`: Use split checksum for all binaries and distros ([#​1582](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1582)) The previous attempt at splitting the checksum file for AIX releases was not successful. The problem lies on the fac that `.runtime.GOOS` will always be the runtime of the compiled goreleaser binary ("linux" in this case). The only way to split the checksum file per target is what's implement here, but it ends up giving one checksum file per produced artifact. ##### 🚀 New components 🚀 - `icmpcheckreceiver`: Add icmpcheckreceiver to the contrib distribution ([#​1577](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1577)) ##### 💡 Enhancements 💡 - `all`: Add new binaries for aix/ppc64 ([#​1424](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1424)) ##### 🧰 Bug fixes 🧰 - `all`: Skip Docker build and publish in AIX release job. ([#​1580](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1580)) The release for Contrib on AIX runs in its own job, where it doesn't build Docker images. The `continue --merge` phase of goreleaser runs all publishers by default, including the Docker manifests one. This will fail for AIX as the images aren't built. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMS40IiwidXBkYXRlZEluVmVyIjoiNDQuMTEuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.eclipse.jetty.ee10:jetty-ee10-servlet](https://jetty.org) ([source](https://redirect.github.com/jetty/jetty.project)) | `12.1.11` → `12.1.12` |  |  | | [org.eclipse.jetty:jetty-server](https://jetty.org) ([source](https://redirect.github.com/jetty/jetty.project)) | `12.1.11` → `12.1.12` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMS40IiwidXBkYXRlZEluVmVyIjoiNDQuMTEuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…#2369) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grafana/grafana](https://redirect.github.com/grafana/grafana) | patch | `13.1.1` → `13.1.2` | --- ### Release Notes <details> <summary>grafana/grafana (grafana/grafana)</summary> ### [`v13.1.2`](https://redirect.github.com/grafana/grafana/blob/HEAD/CHANGELOG.md#1310-2026-06-23) ##### Features and enhancements - **A11y:** Remove interactivity from UserIcon if onClick is not provided [#​120284](https://redirect.github.com/grafana/grafana/pull/120284), [@​idastambuk](https://redirect.github.com/idastambuk) - **Accessibility:** Add `aria-pressed` state to `FilterPill` [#​123069](https://redirect.github.com/grafana/grafana/pull/123069), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **Accessibility:** Colorblind-safe line style fill patterns [#​121386](https://redirect.github.com/grafana/grafana/pull/121386), [@​vijaygovindaraja](https://redirect.github.com/vijaygovindaraja) - **Alerting:** Add Mimir Alertmanager auto-sync configuration to settings page [#​124855](https://redirect.github.com/grafana/grafana/pull/124855), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Add alerting.rulesAPIV2 feature flag [#​122606](https://redirect.github.com/grafana/grafana/pull/122606), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Add common section to filter dropdown in Alerts Activity [#​124547](https://redirect.github.com/grafana/grafana/pull/124547), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Add feature flag for notifications api migration [#​124625](https://redirect.github.com/grafana/grafana/pull/124625), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Add label section to enrichment view/edit drawers (Enterprise) - **Alerting:** Add reusable hook to add enrichment query param to url on drawer open [#​123584](https://redirect.github.com/grafana/grafana/pull/123584), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Add support for label selectors in AlertRule and RecordingRule legacy storage [#​122293](https://redirect.github.com/grafana/grafana/pull/122293), [@​moustafab](https://redirect.github.com/moustafab) - **Alerting:** Alert activity UI improvements part 3 [#​121790](https://redirect.github.com/grafana/grafana/pull/121790), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Alert activity groupBy not filtering by environment [#​121952](https://redirect.github.com/grafana/grafana/pull/121952), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Alerts Activity Instance drawer drilldown, Silence flow [#​122317](https://redirect.github.com/grafana/grafana/pull/122317), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Allow restricting contact point integration types [#​118858](https://redirect.github.com/grafana/grafana/pull/118858), [@​chriscerie](https://redirect.github.com/chriscerie) - **Alerting:** Block Viewers from Alert Group edit route [#​125669](https://redirect.github.com/grafana/grafana/pull/125669), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Block editing plugin-provided and provisioned rule groups [#​123214](https://redirect.github.com/grafana/grafana/pull/123214), [@​konrad147](https://redirect.github.com/konrad147) - **Alerting:** Deduplicate and validate `groupBy` labels in alerts [#​122983](https://redirect.github.com/grafana/grafana/pull/122983), [@​yuri-tceretian](https://redirect.github.com/yuri-tceretian) - **Alerting:** Export external Alertmanager sender metrics with data source UIDs [#​121996](https://redirect.github.com/grafana/grafana/pull/121996), [@​santihernandezc](https://redirect.github.com/santihernandezc) - **Alerting:** Include error in Loki state history when exec\_err\_state is Alerting [#​125775](https://redirect.github.com/grafana/grafana/pull/125775), [@​imankurpatel000](https://redirect.github.com/imankurpatel000) - **Alerting:** Mark notification provisioning endpoints deprecated [#​121995](https://redirect.github.com/grafana/grafana/pull/121995), [@​titolins](https://redirect.github.com/titolins) - **Alerting:** Move filters to sidebar alerts activity [#​121577](https://redirect.github.com/grafana/grafana/pull/121577), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Open new alert rule drawer from panel menu [#​125712](https://redirect.github.com/grafana/grafana/pull/125712), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Preview notification routing in the alert instances table [#​121699](https://redirect.github.com/grafana/grafana/pull/121699), [@​ppcano](https://redirect.github.com/ppcano) - **Alerting:** Propagate plugin rule origin as X-Rule-Origin header [#​125206](https://redirect.github.com/grafana/grafana/pull/125206), [@​yuri-tceretian](https://redirect.github.com/yuri-tceretian) - **Alerting:** Remove alertRuleUseFiredAtForStartsAt feature toggle [#​124677](https://redirect.github.com/grafana/grafana/pull/124677), [@​fayzal-g](https://redirect.github.com/fayzal-g) - **Alerting:** Restrict email contact point recipients to org members [#​123173](https://redirect.github.com/grafana/grafana/pull/123173), [@​yuri-tceretian](https://redirect.github.com/yuri-tceretian) - **Alerting:** Set enrichment uid in url for enrichment view/edit drawer (Enterprise) - **Alerting:** Small improvements to instance drawer drilldown silence flow [#​123429](https://redirect.github.com/grafana/grafana/pull/123429), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Support creating Grafana-managed rules without a group [#​120228](https://redirect.github.com/grafana/grafana/pull/120228), [@​moustafab](https://redirect.github.com/moustafab) - **Alerting:** Surface contact point save errors in the UI [#​123211](https://redirect.github.com/grafana/grafana/pull/123211), [@​konrad147](https://redirect.github.com/konrad147) - **Alerting:** Surface errors on contact point creation [#​124339](https://redirect.github.com/grafana/grafana/pull/124339), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Surface save and bulk-delete errors to the user [#​123690](https://redirect.github.com/grafana/grafana/pull/123690), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Use Rules API v2 in panel alert rule drawer [#​125787](https://redirect.github.com/grafana/grafana/pull/125787), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Annotations:** Clustering GA [#​124173](https://redirect.github.com/grafana/grafana/pull/124173), [@​gtk-grafana](https://redirect.github.com/gtk-grafana) - **Auth:** Support inline public keys for JWT authentication [#​126184](https://redirect.github.com/grafana/grafana/pull/126184), [@​cinaglia](https://redirect.github.com/cinaglia) - **Auth:** Use GrafanaComProxyAPIToken for managed plugin API requests (Enterprise) - **Auth:** Use dedicated token for requests to Grafana.com [#​122269](https://redirect.github.com/grafana/grafana/pull/122269), [@​s4kh](https://redirect.github.com/s4kh) - **Azure Monitor:** Pool gzip writers in Log Analytics deep-link encoder [#​123555](https://redirect.github.com/grafana/grafana/pull/123555), [@​adamyeats](https://redirect.github.com/adamyeats) - **Azure Monitor:** Refactor `fetchInitialRows` to improve async utilisation [#​123278](https://redirect.github.com/grafana/grafana/pull/123278), [@​adamyeats](https://redirect.github.com/adamyeats) - **Azure Monitor:** Stream-decode responses and typed structs for portal deep link [#​123565](https://redirect.github.com/grafana/grafana/pull/123565), [@​adamyeats](https://redirect.github.com/adamyeats) - **Browse Dashboards:** Change messaging of delete/move modal and add counts to tabs in folder detail [#​124299](https://redirect.github.com/grafana/grafana/pull/124299), [@​aocenas](https://redirect.github.com/aocenas) - **Browse Dashboards:** Refresh old parent folder on save dashboard [#​125323](https://redirect.github.com/grafana/grafana/pull/125323), [@​aocenas](https://redirect.github.com/aocenas) - **CloudWatch Logs:** Remove data links from results [#​120348](https://redirect.github.com/grafana/grafana/pull/120348), [@​iwysiu](https://redirect.github.com/iwysiu) - **Cloudwatch:** Add id to metric expression datalinks [#​120526](https://redirect.github.com/grafana/grafana/pull/120526), [@​iwysiu](https://redirect.github.com/iwysiu) - **Combobox:** Add isOpen and onIsOpenChangeHandler [#​122992](https://redirect.github.com/grafana/grafana/pull/122992), [@​L2D2Grafana](https://redirect.github.com/L2D2Grafana) - **ConvertFieldType:** Preserve null and empty string in string-to-number conversion [#​120893](https://redirect.github.com/grafana/grafana/pull/120893), [@​moktamd](https://redirect.github.com/moktamd) - **CsvExport:** Remove legacy CsvExportPage (Enterprise) - **Dashboard variables:** Improve accessibility [#​120758](https://redirect.github.com/grafana/grafana/pull/120758), [@​idastambuk](https://redirect.github.com/idastambuk) - **Dashboard/DTO:** Remove isStarred property [#​122118](https://redirect.github.com/grafana/grafana/pull/122118), [@​ryantxu](https://redirect.github.com/ryantxu) - **Dashboard:** Add annotation CRUD to mutation API [#​123939](https://redirect.github.com/grafana/grafana/pull/123939), [@​ivanortegaalba](https://redirect.github.com/ivanortegaalba) - **Dashboard:** Display variable label in outline to better match what the users sees in the dashboard [#​123321](https://redirect.github.com/grafana/grafana/pull/123321), [@​oscarkilhed](https://redirect.github.com/oscarkilhed) - **Dashboard:** Edit pane go back action [#​122918](https://redirect.github.com/grafana/grafana/pull/122918), [@​torkelo](https://redirect.github.com/torkelo) - **Dashboard:** Preserve timezone user-preference when converting V1 → V2 [#​122267](https://redirect.github.com/grafana/grafana/pull/122267), [@​ivanortegaalba](https://redirect.github.com/ivanortegaalba) - **Dashboard:** Switch tab selects tab only when pane is open (docked or not) [#​121755](https://redirect.github.com/grafana/grafana/pull/121755), [@​torkelo](https://redirect.github.com/torkelo) - **Dashboards:** Add panel screenshot API [#​124045](https://redirect.github.com/grafana/grafana/pull/124045), [@​dprokop](https://redirect.github.com/dprokop) - **Dashboards:** Preserve query variable sort modes in v1->v2 conversion [#​124247](https://redirect.github.com/grafana/grafana/pull/124247), [@​oscarkilhed](https://redirect.github.com/oscarkilhed) - **Dashboards:** Remove dashboardScene and publicDashboardsScene feature toggles [#​121781](https://redirect.github.com/grafana/grafana/pull/121781), [@​Sergej-Vlasov](https://redirect.github.com/Sergej-Vlasov) - **Dashboards:** Show k8s format in provisioned save [#​123033](https://redirect.github.com/grafana/grafana/pull/123033), [@​stephaniehingtgen](https://redirect.github.com/stephaniehingtgen) - **Dashboards:** Strip BOM characters in admission mutation hook [#​122677](https://redirect.github.com/grafana/grafana/pull/122677), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Data Source:** Add forward\_user\_agent option to preserve client User-Agent [#​124244](https://redirect.github.com/grafana/grafana/pull/124244), [@​marcsanmi](https://redirect.github.com/marcsanmi) - **DataSources:** Introduce async APIs and hooks as replacement for datasourceSrv [#​123037](https://redirect.github.com/grafana/grafana/pull/123037), [@​mckn](https://redirect.github.com/mckn) - **Datasources:** Add dynamodb to supported plugins list in dsauth (Enterprise) - **Datasources:** Allow editing data source title [#​122053](https://redirect.github.com/grafana/grafana/pull/122053), [@​MattIPv4](https://redirect.github.com/MattIPv4) - **Datasources:** Finish decoupling mssql & postgresql - backend [#​119110](https://redirect.github.com/grafana/grafana/pull/119110), [@​njvrzm](https://redirect.github.com/njvrzm) - **Datasources:** Finish decoupling mssql, tempo, and graphite - frontend changes [#​119106](https://redirect.github.com/grafana/grafana/pull/119106), [@​njvrzm](https://redirect.github.com/njvrzm) - **Docker:** Bump Alpine-based images to 3.23.4 [#​122930](https://redirect.github.com/grafana/grafana/pull/122930), [@​Proximyst](https://redirect.github.com/Proximyst) - **Docker:** Bump Alpine-based images to 3.24.1 [#​126529](https://redirect.github.com/grafana/grafana/pull/126529), [@​macabu](https://redirect.github.com/macabu) - **Dynamic dashboards:** preserve tab/row URL slugs and keep legacy tab URLs working [#​123159](https://redirect.github.com/grafana/grafana/pull/123159), [@​idastambuk](https://redirect.github.com/idastambuk) - **Expressions:** Add memory limit for math expression binary operations [#​121945](https://redirect.github.com/grafana/grafana/pull/121945), [@​rwwiv](https://redirect.github.com/rwwiv) - **Go:** Update to 1.25.9 [#​122094](https://redirect.github.com/grafana/grafana/pull/122094), [@​macabu](https://redirect.github.com/macabu) - **Google Cloud Monitoring:** Add Forward OAuth Identity authentication (frontend) [#​124618](https://redirect.github.com/grafana/grafana/pull/124618), [@​ktw4071](https://redirect.github.com/ktw4071) - **GrafanaUI:** Remove feature toggle for new panel padding [#​124870](https://redirect.github.com/grafana/grafana/pull/124870), [@​torkelo](https://redirect.github.com/torkelo) - **Graphite:** Strip tagged path from `tags.name` when `aliasSub` wrapping is detected [#​122277](https://redirect.github.com/grafana/grafana/pull/122277), [@​adamyeats](https://redirect.github.com/adamyeats) - **Histogram:** filter NaN and Infinity from bucket size calculation [#​117698](https://redirect.github.com/grafana/grafana/pull/117698), [@​ethervoid](https://redirect.github.com/ethervoid) - **Homepage:** Support v2 dashboards if defined by a file [#​122994](https://redirect.github.com/grafana/grafana/pull/122994), [@​stephaniehingtgen](https://redirect.github.com/stephaniehingtgen) - **I18n:** Prevents `en-US` localization resources from loading [#​125327](https://redirect.github.com/grafana/grafana/pull/125327), [@​hugohaggmark](https://redirect.github.com/hugohaggmark) - **Import:** Library panel missing DS when imported in v1 and classic [#​119980](https://redirect.github.com/grafana/grafana/pull/119980), [@​ivanortegaalba](https://redirect.github.com/ivanortegaalba) - **InfluxDB:** Decouple backend [#​119167](https://redirect.github.com/grafana/grafana/pull/119167), [@​njvrzm](https://redirect.github.com/njvrzm) - **InfluxDB:** Decouple frontend [#​119169](https://redirect.github.com/grafana/grafana/pull/119169), [@​njvrzm](https://redirect.github.com/njvrzm) - **InteractiveTable:** Support specific column widths [#​121384](https://redirect.github.com/grafana/grafana/pull/121384), [@​vijaygovindaraja](https://redirect.github.com/vijaygovindaraja) - **LibraryPanels:** Return 403 instead of 500 for insufficient permissions [#​123407](https://redirect.github.com/grafana/grafana/pull/123407), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Log Details:** Add support for filtering from add-hoc stats and to include/exclude the log line [#​126782](https://redirect.github.com/grafana/grafana/pull/126782), [@​matyax](https://redirect.github.com/matyax) - **Log Details:** Add support to expand or shrink inline Log Details [#​123156](https://redirect.github.com/grafana/grafana/pull/123156), [@​matyax](https://redirect.github.com/matyax) - **Logs Panel:** Add support to copy a log entry with fields/labels as JSON [#​124816](https://redirect.github.com/grafana/grafana/pull/124816), [@​matyax](https://redirect.github.com/matyax) - **Logs:** Add emergency to supported LogLevel mapping [#​119957](https://redirect.github.com/grafana/grafana/pull/119957), [@​Kuehn-Andreas](https://redirect.github.com/Kuehn-Andreas) - **Logs:** Add keyboard navigation support for Log Details [#​123406](https://redirect.github.com/grafana/grafana/pull/123406), [@​matyax](https://redirect.github.com/matyax) - **Logs:** Add optional download support for dashboards [#​123256](https://redirect.github.com/grafana/grafana/pull/123256), [@​matyax](https://redirect.github.com/matyax) - **Logs:** Highlight multi-unit durations in log syntax highlighting [#​124433](https://redirect.github.com/grafana/grafana/pull/124433), [@​o6ivp](https://redirect.github.com/o6ivp) - **Logs:** Log line menu is now sticky [#​126572](https://redirect.github.com/grafana/grafana/pull/126572), [@​matyax](https://redirect.github.com/matyax) - **Logs:** Removed logsPanelControls feature flag and related components [#​122114](https://redirect.github.com/grafana/grafana/pull/122114), [@​matyax](https://redirect.github.com/matyax) - **Logs:** introduce "unspecified" log level for missing log level and separate from "unknown" [#​125716](https://redirect.github.com/grafana/grafana/pull/125716), [@​matyax](https://redirect.github.com/matyax) - **Migration:** Widen team.updated to DATETIME(3) on MySQL [#​124314](https://redirect.github.com/grafana/grafana/pull/124314), [@​mgyongyosi](https://redirect.github.com/mgyongyosi) - **PieChartPanel:** Add gradient color scheme with WCAG-aware slice labels [#​121303](https://redirect.github.com/grafana/grafana/pull/121303), [@​fedir](https://redirect.github.com/fedir) - **Plugins:** Add plugins.marketplaceLicensing feature toggle [#​124246](https://redirect.github.com/grafana/grafana/pull/124246), [@​xnyo](https://redirect.github.com/xnyo) - **Plugins:** Sanitise header values to printable ASCII for gRPC compatibility [#​122237](https://redirect.github.com/grafana/grafana/pull/122237), [@​adamyeats](https://redirect.github.com/adamyeats) - **Prometheus:** Fetch metric metadata on code editor mount [#​121339](https://redirect.github.com/grafana/grafana/pull/121339) - **Prometheus:** Prevent prometheus package to be released automatically [#​122824](https://redirect.github.com/grafana/grafana/pull/122824), [@​itsmylife](https://redirect.github.com/itsmylife) - **Prometheus:** Use [@​grafana/prometheus](https://redirect.github.com/grafana/prometheus) v13.1.2 [#​123024](https://redirect.github.com/grafana/grafana/pull/123024), [@​itsmylife](https://redirect.github.com/itsmylife) - **Provisioning:** Add commit signing configuration UI (GPG, SSH, S/MIME) [#​126023](https://redirect.github.com/grafana/grafana/pull/126023), [@​amalavet](https://redirect.github.com/amalavet) - **Provisioning:** Don't mark folders pending due to \_folder.json metadata [#​124118](https://redirect.github.com/grafana/grafana/pull/124118), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Enforce folder version in finalizer handler [#​123179](https://redirect.github.com/grafana/grafana/pull/123179), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Honor ruleset bypass for write workflow validation [#​123893](https://redirect.github.com/grafana/grafana/pull/123893), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Include dashboard validation errors in pull request comments [#​122233](https://redirect.github.com/grafana/grafana/pull/122233), [@​gttrigger](https://redirect.github.com/gttrigger) - **Provisioning:** Invalid resources should cause a warning job [#​123047](https://redirect.github.com/grafana/grafana/pull/123047), [@​gttrigger](https://redirect.github.com/gttrigger) - **Provisioning:** List resources should return correct api version [#​122653](https://redirect.github.com/grafana/grafana/pull/122653), [@​gttrigger](https://redirect.github.com/gttrigger) - **Provisioning:** Negotiate receive-pack capabilities for git pushes [#​124122](https://redirect.github.com/grafana/grafana/pull/124122), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Per-verb fallback for the files subresource [#​123867](https://redirect.github.com/grafana/grafana/pull/123867), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Remove GET method from webhook connector [#​125539](https://redirect.github.com/grafana/grafana/pull/125539), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Require new token when provisioning URL changes [#​125525](https://redirect.github.com/grafana/grafana/pull/125525), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Retry SQLITE\_BUSY on repository status patch [#​123873](https://redirect.github.com/grafana/grafana/pull/123873), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Return Bad request for repo mismatch in webhook [#​124453](https://redirect.github.com/grafana/grafana/pull/124453), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Return early for errors on resource creation in Parser [#​125122](https://redirect.github.com/grafana/grafana/pull/125122), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Rotate webhook secret periodically [#​122797](https://redirect.github.com/grafana/grafana/pull/122797), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Scope repository uniqueness by (URL, branch, path) [#​123498](https://redirect.github.com/grafana/grafana/pull/123498), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Surface folder uid-too-long and other validation 4xx as sync warnings [#​123797](https://redirect.github.com/grafana/grafana/pull/123797), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Use full sync instead of incremental if diff size exceeds a certain amount [#​123127](https://redirect.github.com/grafana/grafana/pull/123127), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Write `_folder.json` when creating dashboards in new folders [#​126042](https://redirect.github.com/grafana/grafana/pull/126042), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Write `_folder.json` when moving dashboards into new folders [#​126552](https://redirect.github.com/grafana/grafana/pull/126552), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** add PR comment if resources metadata is removed [#​122664](https://redirect.github.com/grafana/grafana/pull/122664), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** add new check for webhook creation in repository controller [#​122725](https://redirect.github.com/grafana/grafana/pull/122725), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** add public\_root\_url instance setting for external URLs [#​123613](https://redirect.github.com/grafana/grafana/pull/123613), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** replay protection for GitHub webhooks [#​125550](https://redirect.github.com/grafana/grafana/pull/125550), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** validate ref query parameter on files and history endpoints [#​125551](https://redirect.github.com/grafana/grafana/pull/125551), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Pyroscope:** Add support for heatmap query API [#​120995](https://redirect.github.com/grafana/grafana/pull/120995), [@​simonswine](https://redirect.github.com/simonswine) - **Pyroscope:** Include profile ID and absolute times in assistant context [#​122665](https://redirect.github.com/grafana/grafana/pull/122665), [@​marcsanmi](https://redirect.github.com/marcsanmi) - **Removal:** GroupAttributeSync routes [#​126247](https://redirect.github.com/grafana/grafana/pull/126247), [@​Jguer](https://redirect.github.com/Jguer) - **Reporting:** Add backend support for URL-based report rendering (Enterprise) - **Reporting:** Limit report emails to org members only (behind new config property) (Enterprise) - **Revert "Alerting:** Migrate notifications.alerting.grafana.app from v0alpha1 to v1beta1" [#​121955](https://redirect.github.com/grafana/grafana/pull/121955), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Scenes:** Upgrade to v8 [#​123698](https://redirect.github.com/grafana/grafana/pull/123698), [@​torkelo](https://redirect.github.com/torkelo) - **Search API:** Filter out k6 technical folder in unified search [#​122674](https://redirect.github.com/grafana/grafana/pull/122674), [@​aocenas](https://redirect.github.com/aocenas) - **Secrets Keeper:** AWS create form with instruction wizard (Enterprise) - **Secrets Keeper:** Activate and deactivate keeper from the UI (Enterprise) - **Secrets Keeper:** Add delete keeper functionality (Enterprise) - **Secrets Keeper:** Add keeper edit page with form prepopulation (Enterprise) - **Sidebar:** Open pane actions, dock, and go back redesign [#​123683](https://redirect.github.com/grafana/grafana/pull/123683), [@​torkelo](https://redirect.github.com/torkelo) - **SqlExpressions:** Interpolate variables in schema queries [#​123779](https://redirect.github.com/grafana/grafana/pull/123779), [@​NWRichmond](https://redirect.github.com/NWRichmond) - **SqlExpressions:** Migrate AI features to Grafana Assistant [#​122085](https://redirect.github.com/grafana/grafana/pull/122085), [@​NWRichmond](https://redirect.github.com/NWRichmond) - **Stats:** Remove dashboard version metric [#​121900](https://redirect.github.com/grafana/grafana/pull/121900), [@​stephaniehingtgen](https://redirect.github.com/stephaniehingtgen) - **Table:** GroupToNestedTable v2 UI [#​121646](https://redirect.github.com/grafana/grafana/pull/121646), [@​fastfrwrd](https://redirect.github.com/fastfrwrd) - **Team folders:** Refresh browse dashboard cache after changes to team folders [#​123794](https://redirect.github.com/grafana/grafana/pull/123794), [@​aocenas](https://redirect.github.com/aocenas) - **Tempo:** Unify dynamic int/double span attributes as float64 [#​121645](https://redirect.github.com/grafana/grafana/pull/121645), [@​zoltanbedi](https://redirect.github.com/zoltanbedi) - **Tempo:** Unify nested span subframe schema across span sets [#​124885](https://redirect.github.com/grafana/grafana/pull/124885), [@​zoltanbedi](https://redirect.github.com/zoltanbedi) - **TimeRangePicker:** Adjust accent color to be accessible [#​122040](https://redirect.github.com/grafana/grafana/pull/122040), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **Transformations:** Removes unused predicate matchers [#​124790](https://redirect.github.com/grafana/grafana/pull/124790), [@​hugohaggmark](https://redirect.github.com/hugohaggmark) - **Unified Storage:** Pass commit message when routing managed-resource writes [#​125556](https://redirect.github.com/grafana/grafana/pull/125556), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Users:** Use SHA-256 for Gravatar email identifier [#​122319](https://redirect.github.com/grafana/grafana/pull/122319), [@​Jguer](https://redirect.github.com/Jguer) - **Zipkin:** Remove core datasource (Enterprise) - **patch(security):** apply May 2026 patches [#​124824](https://redirect.github.com/grafana/grafana/pull/124824), [@​github-actions\[bot\]](https://redirect.github.com/github-actions\[bot]) ##### Bug fixes - **Alerting:** Fix named policy route showing as Default when routing toggle is off [#​125817](https://redirect.github.com/grafana/grafana/pull/125817), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Add warning when editing grouped alert rule to ungrouped [#​126292](https://redirect.github.com/grafana/grafana/pull/126292), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Fix AlertManagerPicker visibility to check Alertmanager datasources [#​123137](https://redirect.github.com/grafana/grafana/pull/123137), [@​konrad147](https://redirect.github.com/konrad147) - **Alerting:** Fix Test button not shown for provisioned contact points [#​126371](https://redirect.github.com/grafana/grafana/pull/126371), [@​gillesdemey](https://redirect.github.com/gillesdemey) - **Alerting:** Fix crash when MultiCombobox value contains duplicates [#​122180](https://redirect.github.com/grafana/grafana/pull/122180), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Fix crash when ruler returns namespace with empty groups array [#​122704](https://redirect.github.com/grafana/grafana/pull/122704), [@​konrad147](https://redirect.github.com/konrad147) - **Alerting:** Fix error toaster when removing last rule from group [#​126296](https://redirect.github.com/grafana/grafana/pull/126296), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Fix inhibition status flickering during load of alert rule detail [#​126288](https://redirect.github.com/grafana/grafana/pull/126288), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Fix missing permission check for routing preview [#​122344](https://redirect.github.com/grafana/grafana/pull/122344), [@​rodrigopk](https://redirect.github.com/rodrigopk) - **Alerting:** Fix notification policies tab hidden for Viewer/Editor after managed routes migration [#​122123](https://redirect.github.com/grafana/grafana/pull/122123), [@​gillesdemey](https://redirect.github.com/gillesdemey) - **Alerting:** Fix page title for /alerting/groups when V2 nav is enabled without triage [#​123286](https://redirect.github.com/grafana/grafana/pull/123286), [@​firasmosbehi](https://redirect.github.com/firasmosbehi) - **Alerting:** Fix rule matching when expressions contain inline comments [#​126152](https://redirect.github.com/grafana/grafana/pull/126152), [@​gillesdemey](https://redirect.github.com/gillesdemey) - **Alerting:** Fix slug in alerting nested folder URL [#​123670](https://redirect.github.com/grafana/grafana/pull/123670), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Fix threshold value reset when changing condition type [#​122455](https://redirect.github.com/grafana/grafana/pull/122455), [@​gillesdemey](https://redirect.github.com/gillesdemey) - **Alerting:** Fix toast spam when typing silence matcher regex [#​125643](https://redirect.github.com/grafana/grafana/pull/125643), [@​laurenashleigh](https://redirect.github.com/laurenashleigh) - **Alerting:** Make contact point settings redaction logic case insensitive [#​124955](https://redirect.github.com/grafana/grafana/pull/124955), [@​khalilhaji](https://redirect.github.com/khalilhaji) - **Alerting:** Set 'ResolvedAt' when transitioning from Error to Normal [#​122329](https://redirect.github.com/grafana/grafana/pull/122329), [@​santihernandezc](https://redirect.github.com/santihernandezc) - **Auth:** URL-encode redirectTo cookie value in OAuth login flow [#​121953](https://redirect.github.com/grafana/grafana/pull/121953), [@​jsclayton](https://redirect.github.com/jsclayton) - **AzureMonitor:** Fix focus trapping on `ResourceField` modal [#​123072](https://redirect.github.com/grafana/grafana/pull/123072), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **Browse dashboards:** Fix delete modal affected counts [#​122747](https://redirect.github.com/grafana/grafana/pull/122747), [@​aocenas](https://redirect.github.com/aocenas) - **Dashboads:** Fixes flickering issues [#​118567](https://redirect.github.com/grafana/grafana/pull/118567), [@​torkelo](https://redirect.github.com/torkelo) - **Dashboard:** DashboardCodePane width refactoring and fixes [#​122700](https://redirect.github.com/grafana/grafana/pull/122700), [@​torkelo](https://redirect.github.com/torkelo) - **Dashboard:** Fixes issue with interval variable with Auto value [#​123889](https://redirect.github.com/grafana/grafana/pull/123889), [@​torkelo](https://redirect.github.com/torkelo) - **DashboardDS:** Fix Mixed panels not updating on time-range change with stale upstreams [#​124665](https://redirect.github.com/grafana/grafana/pull/124665), [@​ivanortegaalba](https://redirect.github.com/ivanortegaalba) - **DashboardDS:** Fix Mixed panels with a time override stuck in permanent loading [#​125954](https://redirect.github.com/grafana/grafana/pull/125954), [@​oscarkilhed](https://redirect.github.com/oscarkilhed) - **Dashboards:** Fix broken add panel button after removing last panel [#​124551](https://redirect.github.com/grafana/grafana/pull/124551), [@​ifrost](https://redirect.github.com/ifrost) - **Datasources:** return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid [#​125398](https://redirect.github.com/grafana/grafana/pull/125398), [@​papagian](https://redirect.github.com/papagian) - **Fix:** Don't mutate shared SecureJSONData map in dsauth (Enterprise) - **Fix:** Short-cut auth service Apply for non-handled plugin IDs (Enterprise) - **GrafanaUI:** Correctly close `Select`/`Combobox` menus with the keyboard [#​122133](https://redirect.github.com/grafana/grafana/pull/122133), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **HomePage:** Fix redirect when served under a subpath [#​124557](https://redirect.github.com/grafana/grafana/pull/124557), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **Jaeger:** Fix log event timestamp unit conversion in trace view [#​123302](https://redirect.github.com/grafana/grafana/pull/123302), [@​ktw4071](https://redirect.github.com/ktw4071) - **K8s Dashboards:** Fix folder permission check to use dashboards:create [#​124612](https://redirect.github.com/grafana/grafana/pull/124612), [@​mihai-turdean](https://redirect.github.com/mihai-turdean) - **Loki:** Show Step option for all query types and fix volume reload on step change [#​122184](https://redirect.github.com/grafana/grafana/pull/122184), [@​paulojmdias](https://redirect.github.com/paulojmdias) - **Menu:** Correctly show active state in forced colors mode [#​123633](https://redirect.github.com/grafana/grafana/pull/123633), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **Portal:** Fix nested portals to overlay correctly [#​122450](https://redirect.github.com/grafana/grafana/pull/122450), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **PostgreSQL:** Allow sql\_engine to return results for EXPLAIN queries [#​122739](https://redirect.github.com/grafana/grafana/pull/122739), [@​sdague](https://redirect.github.com/sdague) - **Provisioning:** Bump nanogit to v0.17.0 to fix pushes with repositories using git modules [#​124114](https://redirect.github.com/grafana/grafana/pull/124114), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Provisioning:** Fix PR comments on multi-org Grafana instances [#​126700](https://redirect.github.com/grafana/grafana/pull/126700), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Fix PR links when folder is renamed via UI [#​126695](https://redirect.github.com/grafana/grafana/pull/126695), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Fix duplicate folder cleanup during full sync [#​124256](https://redirect.github.com/grafana/grafana/pull/124256), [@​ferruvich](https://redirect.github.com/ferruvich) - **Provisioning:** Fix race in PullStatus condition with controller patches [#​123358](https://redirect.github.com/grafana/grafana/pull/123358), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **Public Dashboards:** Fix issues navigating to public dashboards from a logged-in session [#​121017](https://redirect.github.com/grafana/grafana/pull/121017), [@​mmandrus](https://redirect.github.com/mmandrus) - **QueryEditor:** Fix loss of query edits when switching queries [#​123001](https://redirect.github.com/grafana/grafana/pull/123001), [@​NWRichmond](https://redirect.github.com/NWRichmond) - **Tempo Datasource:** Fix gRPC basic auth over non-TLS connections [#​123026](https://redirect.github.com/grafana/grafana/pull/123026), [@​RobertClarke64](https://redirect.github.com/RobertClarke64) - **Tempo:** Fix Ctrl+/ comment toggle in TraceQL editor [#​121460](https://redirect.github.com/grafana/grafana/pull/121460), [@​Krishnachaitanyakc](https://redirect.github.com/Krishnachaitanyakc) - **Tempo:** Fix trace rendering failure when span attributes contain NaN or Infinity [#​122504](https://redirect.github.com/grafana/grafana/pull/122504), [@​Tarasusrus](https://redirect.github.com/Tarasusrus) - **TimePicker:** Show label for fiscal-quarter relative ranges [#​122384](https://redirect.github.com/grafana/grafana/pull/122384), [@​jeanibarz](https://redirect.github.com/jeanibarz) - **Unified storage:** Skip migrations if dualwrite state shows they were already migrated [#​122866](https://redirect.github.com/grafana/grafana/pull/122866), [@​stephaniehingtgen](https://redirect.github.com/stephaniehingtgen) - **alerting:** fix ORM table mapping bug causing SELECT alert\_rule columns FROM user on PostgreSQL [#​124935](https://redirect.github.com/grafana/grafana/pull/124935), [@​dhananjay6561](https://redirect.github.com/dhananjay6561) - **fix(provisioning):** ignore terminating repositories when validating connection delete [#​126822](https://redirect.github.com/grafana/grafana/pull/126822), [@​MissingRoberto](https://redirect.github.com/MissingRoberto) - **fix:** bad MySQL query in datasource\_type column migration [#​126821](https://redirect.github.com/grafana/grafana/pull/126821), [@​gassiss](https://redirect.github.com/gassiss) ##### Breaking changes - **Prometheus:** Remove azure and sigv4 auth from core prometheus [#​123089](https://redirect.github.com/grafana/grafana/pull/123089), [@​itsmylife](https://redirect.github.com/itsmylife) - **Prometheus:** Remove grafana-prometheus [package#122953](https://redirect.github.com/package/grafana/issues/122953) [#​123035](https://redirect.github.com/grafana/grafana/pull/123035), [@​itsmylife](https://redirect.github.com/itsmylife) - **Zipkin:** Remove from core plugins [#​124148](https://redirect.github.com/grafana/grafana/pull/124148), [@​itsmylife](https://redirect.github.com/itsmylife) ##### Plugin development fixes & changes - **Card:** Improve responsiveness [#​123876](https://redirect.github.com/grafana/grafana/pull/123876), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **Combobox:** Fix caret jumping to the end of the input [#​123950](https://redirect.github.com/grafana/grafana/pull/123950), [@​joshhunt](https://redirect.github.com/joshhunt) - **DataLinkInput:** Expose prop to properly link labels to input [#​123795](https://redirect.github.com/grafana/grafana/pull/123795), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **RadioButton:** Fix selected visibility in forced colors mode [#​123952](https://redirect.github.com/grafana/grafana/pull/123952), [@​ashharrison90](https://redirect.github.com/ashharrison90) - **RadioButtonGroup:** Prevent RadioButtonGroup overflow with ellipsis and hover title [#​119124](https://redirect.github.com/grafana/grafana/pull/119124), [@​Apahadi73](https://redirect.github.com/Apahadi73) - **TimeOfDayPicker:** use Combobox [#​123777](https://redirect.github.com/grafana/grafana/pull/123777), [@​leeoniya](https://redirect.github.com/leeoniya) <!-- 13.1.0 END --> <!-- 12.3.6+security-04 START --> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMS40IiwidXBkYXRlZEluVmVyIjoiNDQuMTEuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…s#2368) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | patch | `v4.37.5` → `v4.37.6` | --- ### Release Notes <details> <summary>github/codeql-action (github/codeql-action)</summary> ### [`v4.37.6`](https://redirect.github.com/github/codeql-action/releases/tag/v4.37.6) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.37.5...v4.37.6) - Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to `.github/codeql-config.yml` to align it with the suggested path that is used elsewhere. [#​4070](https://redirect.github.com/github/codeql-action/pull/4070) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMS40IiwidXBkYXRlZEluVmVyIjoiNDQuMTEuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…#2372) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grafana/grafana](https://redirect.github.com/grafana/grafana) | patch | `13.1.2` → `13.1.3` | --- ### Release Notes <details> <summary>grafana/grafana (grafana/grafana)</summary> ### [`v13.1.3`](https://redirect.github.com/grafana/grafana/releases/tag/v13.1.3): 13.1.3 [Download page](https://grafana.com/grafana/download/13.1.3) [What's new highlights](https://grafana.com/docs/grafana/latest/whatsnew/) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…rometheus#2373) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grafana/docker-otel-lgtm](https://redirect.github.com/grafana/docker-otel-lgtm) | patch | `0.30.0` → `0.30.1` | --- ### Release Notes <details> <summary>grafana/docker-otel-lgtm (grafana/docker-otel-lgtm)</summary> ### [`v0.30.1`](https://redirect.github.com/grafana/docker-otel-lgtm/releases/tag/v0.30.1) [Compare Source](https://redirect.github.com/grafana/docker-otel-lgtm/compare/v0.30.0...v0.30.1) <!-- Release notes generated using configuration in .github/release.yml at main --> #### What's Changed ##### OpenTelemetry & LGTM - chore(deps): update dependency prometheus to v3.13.2 by [@​renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot] in [#​1678](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1678) ##### Other Changes - Update renovate config by [@​martincostello](https://redirect.github.com/martincostello) in [#​1668](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1668) - Add renovate schedule by [@​martincostello](https://redirect.github.com/martincostello) in [#​1683](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1683) **Full Changelog**: <grafana/docker-otel-lgtm@v0.30.0...v0.30.1> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.junit:junit-bom](https://junit.org/) ([source](https://redirect.github.com/junit-team/junit-framework)) | `6.1.2` → `6.1.3` |  |  | | [org.junit.jupiter:junit-jupiter-params](https://junit.org/) ([source](https://redirect.github.com/junit-team/junit-framework)) | `6.1.2` → `6.1.3` |  |  | | [org.junit.jupiter:junit-jupiter](https://junit.org/) ([source](https://redirect.github.com/junit-team/junit-framework)) | `6.1.2` → `6.1.3` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
) This PR contains the following updates: | Package | Update | Change | |---|---|---| | grafana/k6 | digest | `e7eeddf` → `5221b62` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…s#2381) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | patch | `v4.37.6` → `v4.37.7` | --- ### Release Notes <details> <summary>github/codeql-action (github/codeql-action)</summary> ### [`v4.37.7`](https://redirect.github.com/github/codeql-action/releases/tag/v4.37.7) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.37.6...v4.37.7) - Update default CodeQL bundle version to [2.26.3](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3). [#​4085](https://redirect.github.com/github/codeql-action/pull/4085) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…us#2351) This PR contains the following updates: | Package | Update | Change | |---|---|---| | zeitlinger/micrometer | digest | `8f90b70` → `f240f09` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Update | Change | |---|---| | lockFileMaintenance | All locks refreshed | 🔧 This Pull Request updates lock files to use the latest dependency versions. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…rometheus#2383) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grafana/docker-otel-lgtm](https://redirect.github.com/grafana/docker-otel-lgtm) | patch | `0.30.1` → `0.30.2` | --- ### Release Notes <details> <summary>grafana/docker-otel-lgtm (grafana/docker-otel-lgtm)</summary> ### [`v0.30.2`](https://redirect.github.com/grafana/docker-otel-lgtm/releases/tag/v0.30.2) [Compare Source](https://redirect.github.com/grafana/docker-otel-lgtm/compare/v0.30.1...v0.30.2) <!-- Release notes generated using configuration in .github/release.yml at main --> #### What's Changed ##### OpenTelemetry & LGTM - chore(deps): update dependency grafana to v13.1.2 by [@​renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot] in [#​1706](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1706) - chore(deps): update dependency grafana to v13.1.3 by [@​renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot] in [#​1717](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1717) - chore(deps): update dependency pyroscope to v2.2.1 by [@​renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot] in [#​1719](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1719) - chore(deps): update dependency loki to v3.7.6 by [@​renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot] in [#​1718](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1718) **Full Changelog**: <grafana/docker-otel-lgtm@v0.30.1...v0.30.2> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…4efa (prometheus#2379) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://redirect.github.com/adoptium/containers)) | final | digest | `f19dbf0` → `a214efa` | | [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin) ([source](https://redirect.github.com/adoptium/containers)) | | digest | `f19dbf0` → `a214efa` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [jdx/mise-action](https://redirect.github.com/jdx/mise-action) | action | patch | `v4.2.4` → `v4.2.5` | --- ### Release Notes <details> <summary>jdx/mise-action (jdx/mise-action)</summary> ### [`v4.2.5`](https://redirect.github.com/jdx/mise-action/releases/tag/v4.2.5): : Resilient mise downloads with automatic retries [Compare Source](https://redirect.github.com/jdx/mise-action/compare/v4.2.4...v4.2.5) A small patch release that makes setup more resilient to transient network failures when downloading mise. ##### Fixed ##### Retry mise downloads after transient failures ([#​597](https://redirect.github.com/jdx/mise-action/pull/597) by [@​jdx](https://redirect.github.com/jdx)) The download helpers previously made a single `curl` or `wget` attempt, so a transient GitHub release-asset HTTP or TLS failure would abort setup before mise or any user command could run (see [#​596](https://redirect.github.com/jdx/mise-action/issues/596)). Downloads now run through a retry wrapper that makes up to five attempts with a 2s pause between failures, logging a warning on each retry. This applies consistently to binary, checksum, signature, and version fetches. Checksum and minisign verification still run only after a successful download — never inside the retry loop — so integrity guarantees are unchanged. **Full Changelog**: <jdx/mise-action@v4.2.4...v4.2.5> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Update | Change | |---|---|---| | grafana/tempo | patch | `3.0.2` → `3.0.3` | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
> ℹ️ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Type | Update | Change | Pending |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|---|
|
[aqua:jonwiggins/xmloxide](https://redirect.github.com/jonwiggins/xmloxide)
| tools | minor | `0.4.4` → `0.5.0` | |

|

|
| [biome](https://redirect.github.com/biomejs/biome) | tools | patch |
`2.5.5` → `2.5.8` | |

|

|
|
[editorconfig-checker](https://redirect.github.com/editorconfig-checker/editorconfig-checker)
| tools | minor | `3.8.0` → `3.11.1` | |

|

|
|
[google-java-format](https://redirect.github.com/google/google-java-format)
| tools | minor | `1.35.0` → `1.36.1` | |

|

|
| [npm:renovate](https://renovatebot.com)
([source](https://redirect.github.com/renovatebot/renovate)) | tools |
major | [`43.279.1` →
`44.29.4`](https://octochangelog.com/compare?repo=renovatebot%2Frenovate&from=43.279.1&to=44.29.4)
| `44.31.0` (+6) |

|

|
| [ruff](https://redirect.github.com/astral-sh/ruff) | tools | patch |
`0.16.0` → `0.16.3` | |

|

|
| [rumdl](https://redirect.github.com/rvben/rumdl) | tools | patch |
`v0.2.43` → `v0.2.55` | |

|

|
| [typos](https://redirect.github.com/crate-ci/typos) | tools | minor |
`1.48.0` → `1.49.0` | |

|

|
| [zizmor](https://redirect.github.com/zizmorcore/zizmor) | tools |
minor | `1.28.0` → `1.29.0` | |

|

|
---
### Release Notes
<details>
<summary>jonwiggins/xmloxide (aqua:jonwiggins/xmloxide)</summary>
###
[`v0.5.0`](https://redirect.github.com/jonwiggins/xmloxide/blob/HEAD/CHANGELOG.md#050---2026-08-08)
[Compare
Source](https://redirect.github.com/jonwiggins/xmloxide/compare/v0.4.4...v0.5.0)
##### Changed
- **XPath attribute results are first-class attribute nodes**
([#​47](https://redirect.github.com/jonwiggins/xmloxide/issues/47)).
Node-sets (`XPathValue::NodeSet`) now hold `XPathNode` entries — either
a
tree node or an attribute identified by owner element and index —
instead
of bare `NodeId`s. This fixes a family of wrong-answer bugs rooted in
the
old one-value-per-element override map: `//a/@x != //a/@y` comparisons
no
longer clobber each other's values, `@*` yields one node per attribute
(previously only the first per element), `count((//a)[1]/@href)` returns
a
number instead of a type error,
`name()`/`local-name()`/`namespace-uri()`
work on attribute nodes, `@attr/..` navigates to the owner element,
predicates evaluate with the attribute as context node, and namespace
declarations (`xmlns`, `xmlns:*`) are no longer visible as attributes
per
the XPath 1.0 data model. Mixed node-sets (`//a | //a/@x`) sort in
document order with attributes directly after their owner element.
**Breaking:** code matching `XPathValue::NodeSet` must handle
`XPathNode`; use `.anchor()` for the owning tree node or
`.as_tree_node()` to filter attributes out. The single-match collapse
(attribute paths returning `XPathValue::String`) is gone — convert with
`string()` where a string is wanted. `xmllint --xpath` prints attribute
results as `name="value"` lines, matching libxml2. The C API keeps
`xmloxide_xpath_nodeset_item()` (returns the owner element id for
attributes) and adds `xmloxide_xpath_nodeset_item_is_attribute()`,
`..._attr_name()`, and `..._attr_value()`.
- **XPath step predicates apply per context node** per XPath 1.0 §2.4:
`//a/b[1]` now selects the first `b` of *every* `a` (previously the
first
of the merged set), and `position()`/`last()` in step predicates are
relative to each context node's own node-set, matching libxml2. The
parenthesized form `(//a/b)[1]` keeps global-position semantics.
- **Schematron rules with attribute contexts** (`context="//@id"`) now
fire
with the attribute itself as the context node — `.` is the attribute
value and `<value-of select="."/>` reads it, per ISO Schematron.
Previously such rules either never fired (single match) or misfired
against the owner element.
##### Security
- **Fix exponential-time entity recursion check**
([#​42](https://redirect.github.com/jonwiggins/xmloxide/issues/42),
thanks [@​hey-jj](https://redirect.github.com/hey-jj)). The
WFC: No Recursion walks in the DTD validator re-visited entities once
per
path, so a 474-byte document with chained entity declarations took 8+
seconds to parse and a 694-byte one about 22 hours. The walks (including
parameter entities and ATTLIST-default validation) now memoize entities
proven acyclic, making the check linear in the size of the DTD. Cycle
detection is unaffected.
- **Bound element nesting across entity expansions.** Entity replacement
text
is parsed by nested sub-parsers, which now inherit the outer parser's
nesting depth so total element depth stays bounded by
`ParseOptions::max_depth` instead of `max_depth` per expansion level.
##### Fixed
- **General entity replacement text is parsed as content** per XML 1.0
§4.4
([#​43](https://redirect.github.com/jonwiggins/xmloxide/issues/43),
thanks [@​hey-jj](https://redirect.github.com/hey-jj)).
`EntityRef` nodes now carry their parsed expansion
as children: character references in declarations are expanded when
replacement text is built (§4.5), nested entity references are included,
and markup-bearing entities produce real element children instead of
escaped text — while serialization still emits `&name;`, keeping
round-trips lossless. Replacement text must match the content production
(§4.3.2); unbalanced or split tags are rejected. Entity expansion is
subject to the expansion counter, a nesting-depth cap, and the 5x
amplification guard, matching libxml2. DTD content-model validation sees
through entity references (§4.4.3), so entity-supplied elements are
validated too.
- **XPath `!=` uses its own existential semantics for node-sets** per
XPath
1.0 §3.4
([#​44](https://redirect.github.com/jonwiggins/xmloxide/issues/44),
thanks [@​hey-jj](https://redirect.github.com/hey-jj)). `!=` was
evaluated as `not(=)`, inverting
empty-node-set comparisons and breaking multi-node sets (both `=` and
`!=`
can hold at once). Node-set vs boolean keeps boolean-conversion
semantics;
scalar comparisons are unchanged. An absent attribute step now also
yields
an empty node-set (false under both `=` and `!=`) instead of an
empty-string sentinel.
- **XPath filter-path continuations navigate instead of filtering**
([#​20](https://redirect.github.com/jonwiggins/xmloxide/issues/20),
thanks [@​ancientcatz](https://redirect.github.com/ancientcatz)).
`(//a)[1]/@href` parsed to the same AST as
`(//a)[@href]`, so the trailing path acted as a predicate and
`string((//a)[1]/@href)` returned the anchor text. A new
`Expr::FilterPath` AST variant evaluates the continuation steps against
the filter's node-set. **Breaking:** downstream exhaustive matches on
`xpath::ast::Expr` must handle the new variant.
</details>
<details>
<summary>biomejs/biome (biome)</summary>
###
[`v2.5.8`](https://redirect.github.com/biomejs/biome/releases/tag/%40biomejs/biome%402.5.8):
Biome CLI v2.5.8
[Compare
Source](https://redirect.github.com/biomejs/biome/compare/@biomejs/biome@2.5.7...@biomejs/biome@2.5.8)
#### 2.5.8
##### Patch Changes
- [#​10710](https://redirect.github.com/biomejs/biome/pull/10710)
[`0a0fbc1`](https://redirect.github.com/biomejs/biome/commit/0a0fbc15d67c410c80dfae398903f845544fcd65)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Added a new
nursery rule
[`useReactCompiler`](https://biomejs.dev/linter/rules/use-react-compiler/),
which reports diagnostics from React Compiler lint mode.
- [#​11251](https://redirect.github.com/biomejs/biome/pull/11251)
[`ea9dd8a`](https://redirect.github.com/biomejs/biome/commit/ea9dd8a93e65f849840415e8e26cd668aa1af913)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Improved
performance of
[`noImportCycles`](https://biomejs.dev/linter/rules/no-import-cycles/).
- [#​11247](https://redirect.github.com/biomejs/biome/pull/11247)
[`52b44d6`](https://redirect.github.com/biomejs/biome/commit/52b44d6795741d051bf703bd69c6cb447af8fd1d)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Added the
nursery rule
[`noSvelteLegacyConst`](https://biomejs.dev/linter/rules/no-svelte-legacy-const/),
which disallows legacy Svelte `{@const}` tags and recommends declaration
tags with `$derived()`.
Invalid:
```svelte
{#each boxes as box}
{@const area = box.width * box.height}
<p>{area}</p>
{/each}
```
Valid:
```svelte
{#each boxes as box}
{const area = $derived(box.width * box.height)}
<p>{area}</p>
{/each}
```
- [#​11252](https://redirect.github.com/biomejs/biome/pull/11252)
[`d5f5704`](https://redirect.github.com/biomejs/biome/commit/d5f570414fdcdddf62372e35c05f6dababad9287)
Thanks [@​Turtle-Hwan](https://redirect.github.com/Turtle-Hwan)! -
Fixed
[#​11250](https://redirect.github.com/biomejs/biome/issues/11250):
[`useAwait`](https://biomejs.dev/linter/rules/use-await/) no longer
reports async functions that contain an `await using` declaration.
- [#​11143](https://redirect.github.com/biomejs/biome/pull/11143)
[`6be7be1`](https://redirect.github.com/biomejs/biome/commit/6be7be1b147d7b4352ff5625a78bd54a48958950)
Thanks [@​vznh](https://redirect.github.com/vznh)! - Fixed
[#​11017](https://redirect.github.com/biomejs/biome/issues/11017):
[`noUselessUndefined`](https://biomejs.dev/linter/rules/no-useless-undefined/)
no longer reports `return undefined` when the enclosing function has a
return type annotation other than `undefined` or `void`.
- [#​11234](https://redirect.github.com/biomejs/biome/pull/11234)
[`caefe39`](https://redirect.github.com/biomejs/biome/commit/caefe393c66340914c481f7ccfc82979cf76b61b)
Thanks [@​subotac](https://redirect.github.com/subotac)! - Fixed
[#​11228](https://redirect.github.com/biomejs/biome/issues/11228):
CSS block comments between a declaration colon and value now preserve
their source indentation.
```diff
:root {
--font-stack:
-/* comment */
+ /* comment */
system-ui;
}
```
- [#​11285](https://redirect.github.com/biomejs/biome/pull/11285)
[`bca1f73`](https://redirect.github.com/biomejs/biome/commit/bca1f73d939423056337bfd0a42cbdcb66bb1e3f)
Thanks [@​denbezrukov](https://redirect.github.com/denbezrukov)! -
Fixed
[#​11280](https://redirect.github.com/biomejs/biome/issues/11280):
CSS formatting keeps comments inside functional pseudo-classes and
pseudo-elements instead of moving them before the function name.
```diff
-:/* comment */ where(div) {}
+:where(/* comment */ div) {}
```
- [#​11080](https://redirect.github.com/biomejs/biome/pull/11080)
[`af16a0b`](https://redirect.github.com/biomejs/biome/commit/af16a0bf884c48bad2caab70e7930096e81e1c99)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - HTML `style`
attribute values are now parsed as CSS. All Biome CSS lint rules are
applied to the `style` attributes.
- [#​11195](https://redirect.github.com/biomejs/biome/pull/11195)
[`6a85588`](https://redirect.github.com/biomejs/biome/commit/6a85588578725195625281984a47c9a8563bf103)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Fixed Svelte
files failing to parse when an expression begins with an object literal.
Now the following snippet is correctly parsed:
```svelte
<p>{{ a: true }}</p>
<div class={{ active: isActive }}></div>
```
- [#​11173](https://redirect.github.com/biomejs/biome/pull/11173)
[`481d008`](https://redirect.github.com/biomejs/biome/commit/481d008f6e8872a78749496fbbf1f9c761d9a770)
Thanks [@​Austin1serb](https://redirect.github.com/Austin1serb)! -
Fixed
[#​10242](https://redirect.github.com/biomejs/biome/issues/10242):
JavaScript GritQL patterns with multiple metavariables now match
snippets consistently in WebAssembly.
- [#​11187](https://redirect.github.com/biomejs/biome/pull/11187)
[`23c0369`](https://redirect.github.com/biomejs/biome/commit/23c0369c43b59284ca68c65883d6ede4228b6fb8)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Added the nursery rule
[`noInvalidPropertyInitValue`](https://biomejs.dev/linter/rules/no-invalid-property-init-value/),
which reports an `@property` whose `initial-value` does not match its
`syntax` descriptor. For example, the following declaration triggers the
rule because `red` is not a `<length>`:
```css
@property --size {
syntax: "<length>";
inherits: false;
initial-value: red;
}
```
- [#​11272](https://redirect.github.com/biomejs/biome/pull/11272)
[`73896e6`](https://redirect.github.com/biomejs/biome/commit/73896e6712ba4c398ba21141829f8361ace45eb2)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Improved the diagnostic emitted by
[`noRootType`](https://biomejs.dev/linter/rules/no-root-type).
- [#​11240](https://redirect.github.com/biomejs/biome/pull/11240)
[`bd0b68d`](https://redirect.github.com/biomejs/biome/commit/bd0b68d418890059930074b46273aa616fbb735a)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed
[#​11223](https://redirect.github.com/biomejs/biome/issues/11223):
Improved the
performance of
[`noMisusedPromises`](https://biomejs.dev/linter/rules/no-misused-promises/)
when analyzing async class methods that call other methods through
`this`.
- [#​11172](https://redirect.github.com/biomejs/biome/pull/11172)
[`4a0bc5c`](https://redirect.github.com/biomejs/biome/commit/4a0bc5c46e6dbbefd17fa133ea426aa41f0a23f8)
Thanks
[@​saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#​10806](https://redirect.github.com/biomejs/biome/issues/10806):
[`noUselessFragments`](https://biomejs.dev/linter/rules/no-useless-fragments/)
no longer causes Biome to panic when its unsafe fix removes a fragment
used as a JSX attribute value.
- [#​11227](https://redirect.github.com/biomejs/biome/pull/11227)
[`4d603b0`](https://redirect.github.com/biomejs/biome/commit/4d603b072fae45a69bd291ab92f3379232cd34df)
Thanks
[@​saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#​11178](https://redirect.github.com/biomejs/biome/issues/11178):
[`noUndeclaredVariables`](https://biomejs.dev/linter/rules/no-undeclared-variables/)
no longer reports Vue's built-in instance properties, such as `$slots`
and `$attrs`, in template expressions or `$event` in inline
event-handler expressions. The instance properties are still reported
inside `<script setup>`, where they are not defined.
- [#​11187](https://redirect.github.com/biomejs/biome/pull/11187)
[`23c0369`](https://redirect.github.com/biomejs/biome/commit/23c0369c43b59284ca68c65883d6ede4228b6fb8)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed CSS parsing of registered custom properties: Biome now correctly
validates the `syntax` descriptor of `@property` rules.
#### What's Changed
- feat(service): treat html style attributes as CSS by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11080](https://redirect.github.com/biomejs/biome/pull/11080)
- feat: code review skill by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11235](https://redirect.github.com/biomejs/biome/pull/11235)
- refactor(inference): prepare legacy type removal by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11010](https://redirect.github.com/biomejs/biome/pull/11010)
- fix(lint/noUselessFragments): panic when fixing a fragment used as a
JSX attribute value by
[@​saberoueslati](https://redirect.github.com/saberoueslati) in
[#​11172](https://redirect.github.com/biomejs/biome/pull/11172)
- ci: update codspeed crates by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11239](https://redirect.github.com/biomejs/biome/pull/11239)
- feat(lint/js): add `useReactCompiler` by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​10710](https://redirect.github.com/biomejs/biome/pull/10710)
- ci: fix windows builds by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11245](https://redirect.github.com/biomejs/biome/pull/11245)
- ci: enable longpaths in main.yml by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11246](https://redirect.github.com/biomejs/biome/pull/11246)
- fix(inference): query local types before global by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11240](https://redirect.github.com/biomejs/biome/pull/11240)
- feat(lint/html): add `noSvelteLegacyConst` by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11247](https://redirect.github.com/biomejs/biome/pull/11247)
- fix(useAwait): treat await using as an async operation by
[@​Turtle-Hwan](https://redirect.github.com/Turtle-Hwan) in
[#​11252](https://redirect.github.com/biomejs/biome/pull/11252)
- feat(css): support SCSS nesting combinator by
[@​denbezrukov](https://redirect.github.com/denbezrukov) in
[#​11243](https://redirect.github.com/biomejs/biome/pull/11243)
- feat: markdown linter by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11253](https://redirect.github.com/biomejs/biome/pull/11253)
- fix(analyzer): scope Vue template globals correctly by
[@​saberoueslati](https://redirect.github.com/saberoueslati) in
[#​11227](https://redirect.github.com/biomejs/biome/pull/11227)
- fix(grit): use byte offsets for WASM snippets by
[@​Austin1serb](https://redirect.github.com/Austin1serb) in
[#​11173](https://redirect.github.com/biomejs/biome/pull/11173)
- fix(lint): preserve explicitly typed undefined returns by
[@​vznh](https://redirect.github.com/vznh) in
[#​11143](https://redirect.github.com/biomejs/biome/pull/11143)
- refactor(md/parse): two-phase parse by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11256](https://redirect.github.com/biomejs/biome/pull/11256)
- perf(noImportCycles): exclude node\_modules, add more tests by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11251](https://redirect.github.com/biomejs/biome/pull/11251)
- fix(css\_formatter): preserve block comment indentation by
[@​subotac](https://redirect.github.com/subotac) in
[#​11234](https://redirect.github.com/biomejs/biome/pull/11234)
- chore: markdown rule generator by
[@​Netail](https://redirect.github.com/Netail) in
[#​11261](https://redirect.github.com/biomejs/biome/pull/11261)
- perf(md/parse): restore parser state via checkpoint by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11257](https://redirect.github.com/biomejs/biome/pull/11257)
- chore: markdownlint rule source by
[@​Netail](https://redirect.github.com/Netail) in
[#​11265](https://redirect.github.com/biomejs/biome/pull/11265)
- fix(parse/html): stop reading `{{` as an interpolation in Svelte by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11195](https://redirect.github.com/biomejs/biome/pull/11195)
- fix(yaml/parse): catch more errors by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11259](https://redirect.github.com/biomejs/biome/pull/11259)
- fix(tools): rule gen and rename rule by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11269](https://redirect.github.com/biomejs/biome/pull/11269)
- fix(tools): path normalisation by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11271](https://redirect.github.com/biomejs/biome/pull/11271)
- test(format/html): format embedded content in the formatter tests by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11209](https://redirect.github.com/biomejs/biome/pull/11209)
- feat(useSortedClasses): order variants in sort\_v4 by
[@​johncarmack1984](https://redirect.github.com/johncarmack1984)
in [#​11249](https://redirect.github.com/biomejs/biome/pull/11249)
- fix(lint/graphql): text range by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11272](https://redirect.github.com/biomejs/biome/pull/11272)
- test(format/html): indent script and style in the HTML Prettier
samples by [@​dyc3](https://redirect.github.com/dyc3) in
[#​11210](https://redirect.github.com/biomejs/biome/pull/11210)
- feat(lint): nursery noInvalidPropertyInitValue by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11187](https://redirect.github.com/biomejs/biome/pull/11187)
- fix(css\_formatter): preserve pseudo function comments by
[@​denbezrukov](https://redirect.github.com/denbezrukov) in
[#​11285](https://redirect.github.com/biomejs/biome/pull/11285)
- chore(deps): update rust crate rust-lapper to 1.3.0 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11292](https://redirect.github.com/biomejs/biome/pull/11292)
- chore(deps): update pnpm to v11.20.0 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11291](https://redirect.github.com/biomejs/biome/pull/11291)
- feat: useTopLevelHeading by
[@​Netail](https://redirect.github.com/Netail) in
[#​11286](https://redirect.github.com/biomejs/biome/pull/11286)
- ci: release by
[@​github-actions](https://redirect.github.com/github-actions)\[bot]
in [#​11236](https://redirect.github.com/biomejs/biome/pull/11236)
#### New Contributors
- [@​Turtle-Hwan](https://redirect.github.com/Turtle-Hwan) made
their first contribution in
[#​11252](https://redirect.github.com/biomejs/biome/pull/11252)
- [@​Austin1serb](https://redirect.github.com/Austin1serb) made
their first contribution in
[#​11173](https://redirect.github.com/biomejs/biome/pull/11173)
- [@​vznh](https://redirect.github.com/vznh) made their first
contribution in
[#​11143](https://redirect.github.com/biomejs/biome/pull/11143)
**Full Changelog**:
<https://github.com/biomejs/biome/compare/@biomejs/biome@2.5.7...@​biomejs/biome@2.5.8>
###
[`v2.5.7`](https://redirect.github.com/biomejs/biome/releases/tag/%40biomejs/biome%402.5.7):
Biome CLI v2.5.7
[Compare
Source](https://redirect.github.com/biomejs/biome/compare/@biomejs/biome@2.5.6...@biomejs/biome@2.5.7)
#### 2.5.7
##### Patch Changes
- [#​10822](https://redirect.github.com/biomejs/biome/pull/10822)
[`c171b3b`](https://redirect.github.com/biomejs/biome/commit/c171b3bd513d49c35b66cdc74a5de0ca0766b6ef)
Thanks [@​pkallos](https://redirect.github.com/pkallos)! - Added
the option `ignoreIfStatements` to
[useNullishCoalescing](https://biomejs.dev/linter/rules/use-nullish-coalescing/).
Biome now flags `if` statements that only assign to a nullish variable
(such as `if (!a) { a = b }`) and can rewrite them to `??=`. When
enabled, Biome ignores those `if` statements.
- [#​11136](https://redirect.github.com/biomejs/biome/pull/11136)
[`e63354c`](https://redirect.github.com/biomejs/biome/commit/e63354cf280783fa6380951342bdacc3fd55e681)
Thanks [@​AkashNaickar](https://redirect.github.com/AkashNaickar)!
- Added a new nursery rule
[`noExtendNative`](https://biomejs.dev/linter/rules/no-extend-native/),
which reports extending the prototype of a built-in object.
- [#​10094](https://redirect.github.com/biomejs/biome/pull/10094)
[`e007143`](https://redirect.github.com/biomejs/biome/commit/e00714360807115210e549caca0f235431ca9a8a)
Thanks [@​THEjacob1000](https://redirect.github.com/THEjacob1000)!
- Added the nursery rule
[`noTailwindArbitraryValue`](https://biomejs.dev/linter/rules/no-tailwind-arbitrary-value/).
Biome now reports Tailwind CSS arbitrary values such as `w-[400px]`,
including in HTML/JSX class attributes, configured utility functions,
and tagged templates.
- [#​11184](https://redirect.github.com/biomejs/biome/pull/11184)
[`135f476`](https://redirect.github.com/biomejs/biome/commit/135f476de8b853f9dc2ff2679ea3525432e66e8e)
Thanks [@​subotac](https://redirect.github.com/subotac)! - Fixed
[#​11176](https://redirect.github.com/biomejs/biome/issues/11176):
`noUnknownPseudoClass` now recognizes Vue's `:deep()` pseudo-class
inside `.vue` style blocks.
- [#​8239](https://redirect.github.com/biomejs/biome/pull/8239)
[`a519f9d`](https://redirect.github.com/biomejs/biome/commit/a519f9d19e56015ec906efac4629fbb15708f5e2)
Thanks [@​cormacrelf](https://redirect.github.com/cormacrelf)! -
Fixed
[#​8233](https://redirect.github.com/biomejs/biome/issues/8233),
where Biome CLI in
stdin mode didn't work correctly when handling files in projects with
nested
configurations. For example, with the following structure,
`--stdin-file-path=subdirectory/...` would not use the nested
configuration in
`subdirectory/biome.json`:
```
├── biome.json
└── subdirectory
├── biome.json
└── lib.js
```
```shell
biome format --write --stdin-file-path=subdirectory/lib.js <
subdirectory/lib.js
```
Now, the nested configuration is correctly picked up and applied.
In addition, Biome now shows a warning if `--stdin-file-path` is
provided but
that path is ignored and therefore not formatted or fixed.
- [#​11138](https://redirect.github.com/biomejs/biome/pull/11138)
[`8c2c6bd`](https://redirect.github.com/biomejs/biome/commit/8c2c6bd96c035e506bc60b75448afb039e331fb1)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed
[`noUnnecessaryConditions`](https://biomejs.dev/linter/rules/no-unnecessary-conditions/):
Biome now chooses the same function overload as TypeScript when an
argument is a callback, so conditions that were previously missed are
reported.
The following code is now invalid, because a parameter typed `() =>
void` accepts an `async` callback and `schedule` therefore returns
`string`:
```ts
declare function schedule(handler: () => void): string;
declare function schedule(handler: () => Promise<void>): string |
undefined;
schedule(async () => {}) ?? "fallback";
```
The following code is also now invalid, because `map(() => 42)` returns
`42`:
```ts
type Mapper<T> = () => T;
declare function map<T>(mapper: Mapper<T>): T;
map(() => 42) || flag;
```
- [#​11138](https://redirect.github.com/biomejs/biome/pull/11138)
[`8c2c6bd`](https://redirect.github.com/biomejs/biome/commit/8c2c6bd96c035e506bc60b75448afb039e331fb1)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed
[#​11087](https://redirect.github.com/biomejs/biome/issues/11087):
[`noUnnecessaryConditions`](https://biomejs.dev/linter/rules/no-unnecessary-conditions/)
no longer reports optional chains and nullish coalescing whose receiver
can be nullish.
For example, the optional chain and fallback in the following code are
no longer reported:
```ts
declare const usage: { range: { startDate: string } } | null;
const startDate = usage?.range.startDate ?? "N/A";
```
- [#​11118](https://redirect.github.com/biomejs/biome/pull/11118)
[`9c16840`](https://redirect.github.com/biomejs/biome/commit/9c16840801a806ba34fbba7da28b9724d250207a)
Thanks [@​subotac](https://redirect.github.com/subotac)! - Fixed
[#​11098](https://redirect.github.com/biomejs/biome/issues/11098):
The HTML formatter now preserves the configured trailing newline when a
file ends with a comment.
```diff
-<!-- trailing comment -->
\ No newline at end of file
+<!-- trailing comment -->
```
- [#​11201](https://redirect.github.com/biomejs/biome/pull/11201)
[`0e80610`](https://redirect.github.com/biomejs/biome/commit/0e8061069915651a6f7cbba918a0bde0dbc1491f)
Thanks [@​Bishwas-py](https://redirect.github.com/Bishwas-py)! -
Fixed
[#​11182](https://redirect.github.com/biomejs/biome/issues/11182):
suppression comments for
[`noPositiveTabindex`](https://biomejs.dev/linter/rules/no-positive-tabindex/)
now suppress the rule in HTML files when the attributes of the element
span multiple lines.
- [#​11079](https://redirect.github.com/biomejs/biome/pull/11079)
[`607afd2`](https://redirect.github.com/biomejs/biome/commit/607afd2488efb30cff5ea4b27de4d98eca728e0f)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - The HTML
formatter now lays out the `srcset` attribute of `<img>` and `<source>`
as the list of candidates it is. Runs of whitespace between candidates
collapse, and once the list no longer fits on one line each candidate
goes on its own line with the descriptors aligned:
```diff
- <img srcset="/visual@0.5.png 400w, /visual.png 805w, /visual@2x.png
1610w, /visual@3x.png 2415w" />
+ <img
+ srcset="
+ /visual@0.5.png 400w,
+ /visual.png 805w,
+ /visual@2x.png 1610w,
+ /visual@3x.png 2415w
+ "
+ />
```
- [#​11156](https://redirect.github.com/biomejs/biome/pull/11156)
[`fed72c7`](https://redirect.github.com/biomejs/biome/commit/fed72c7e8a2bff2942d5970f182262d18e049914)
Thanks
[@​saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#​11129](https://redirect.github.com/biomejs/biome/issues/11129):
[`noUnusedVariables`](https://biomejs.dev/linter/rules/no-unused-variables/)
no longer reports Vue bindings as unused when they are assigned through
automatically unwrapped template refs.
- [#​11124](https://redirect.github.com/biomejs/biome/pull/11124)
[`d890b39`](https://redirect.github.com/biomejs/biome/commit/d890b39c3ef21040bded453d9af91e1b301a0d67)
Thanks [@​denbezrukov](https://redirect.github.com/denbezrukov)! -
Fixed CSS formatting of line comments between a declaration colon and
value to preserve their source indentation.
```diff
.test {
background:
- /////// foo
- // bar
+ /////// foo
+ // bar
radial-gradient(circle, #​000, transparent);
}
```
- [#​11113](https://redirect.github.com/biomejs/biome/pull/11113)
[`3d8ab73`](https://redirect.github.com/biomejs/biome/commit/3d8ab73619f1c62a2d544d41ffee16eab9307d51)
Thanks [@​denbezrukov](https://redirect.github.com/denbezrukov)! -
Fixed CSS formatting of long block comments between comma-separated
property values:
```diff
.foo {
box-shadow:
- 1000px /* long long long long long long long long long long long long
comment */ 1000px /* long long long long long long long long long
comment */ 2px color(srgb 0.555555555 0.555555555 0.555555555),
+ 1000px
+ /* long long long long long long long long long long long long comment
*/
+ 1000px /* long long long long long long long long long comment */ 2px
+ color(srgb 0.555555555 0.555555555 0.555555555),
1px 1px black;
}
```
- [#​11127](https://redirect.github.com/biomejs/biome/pull/11127)
[`da5c1a5`](https://redirect.github.com/biomejs/biome/commit/da5c1a539bac009eb1bc275b9bd8194f9ca7d5fa)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - The HTML
formatter now picks the quote character for an attribute by counting the
quotes in the value rather than looking only for a double quote.
`'` and `"` count as the characters they stand for, and only
the character that ends up as the delimiter stays escaped:
```diff
- <div title='123 '" 456'></div>
+ <div title="123 '" 456"></div>
```
Entities that are not quotes, such as `&` or
`&[#​39](https://redirect.github.com/biomejs/biome/issues/39);`,
are left exactly as written.
- [#​11193](https://redirect.github.com/biomejs/biome/pull/11193)
[`77035bb`](https://redirect.github.com/biomejs/biome/commit/77035bb3777805c682eefa4cbed5464c94baccba)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Fixed the
HTML formatter collapsing the blank line between an element and the text
that follows it. A blank line before text is now kept, the way one
before another element already was:
```diff
<div>foo</div>
-
text
```
- [#​11106](https://redirect.github.com/biomejs/biome/pull/11106)
[`ad80f57`](https://redirect.github.com/biomejs/biome/commit/ad80f572c922fc2a80c90b8e26a66300dfb82d24)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - The HTML
formatter now writes the HTML5 doctype in lowercase, matching Prettier:
```diff
- <!DOCTYPE html>
+ <!doctype html>
```
This only applies to a plain `.html` file whose doctype stands alone. A
doctype that names a DTD keeps the case it was written with, since the
rest of the declaration is not lowercased either:
```html
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
```
A `.vue`, `.svelte`, or `.astro` file keeps whatever the author wrote.
- [#​11188](https://redirect.github.com/biomejs/biome/pull/11188)
[`60679db`](https://redirect.github.com/biomejs/biome/commit/60679dbe6d53c9b78571042b0b8c906bd345e52d)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Fixed the
HTML formatter printing a comment twice when it ended the line of the
last element in a document:
```diff
- text<!-- a --><!-- a -->
+ text<!-- a -->
```
- [#​11077](https://redirect.github.com/biomejs/biome/pull/11077)
[`4dcd0d9`](https://redirect.github.com/biomejs/biome/commit/4dcd0d99579650191696dc5fb8b16dd69d65c4ee)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Fixed a bug
where the HTML formatter collapsed the whitespace inside `<textarea>`,
`<xmp>` and `<plaintext>`, changing what the page renders.
```diff
- <textarea>
- line one
- line two </textarea>
+ <textarea>line one line two</textarea>
```
Biome now prints the content of these elements exactly as it appears in
the source, matching the existing behavior for `<pre>`.
- [#​11194](https://redirect.github.com/biomejs/biome/pull/11194)
[`abfbb11`](https://redirect.github.com/biomejs/biome/commit/abfbb11da260852f0b4aa15f36207314ccfae436)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Fixed the
HTML formatter refusing to format a Svelte file containing an array
pattern that skips a position:
```svelte
{#each animals as [, value]}
<p>{value}</p>
{/each}
```
- [#​10094](https://redirect.github.com/biomejs/biome/pull/10094)
[`e007143`](https://redirect.github.com/biomejs/biome/commit/e00714360807115210e549caca0f235431ca9a8a)
Thanks [@​THEjacob1000](https://redirect.github.com/THEjacob1000)!
- Fixed
[`useSortedClasses`](https://biomejs.dev/linter/rules/use-sorted-classes/)
to correctly detect unsorted classes in static member expression tagged
templates (e.g. `tw.div\`...\`\`). Previously, these were silently
skipped due to surrounding whitespace trivia not being stripped from the
tag name.
- [#​11078](https://redirect.github.com/biomejs/biome/pull/11078)
[`10da30e`](https://redirect.github.com/biomejs/biome/commit/10da30e0013c35fe2f4d3e335b88a539ae6eb87a)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Fixed Vue
single-file components failing to parse when they contain a custom block
such as `<i18n>` or `<docs>`, or a `<template>` written in another
language. Their content is no longer read as HTML, so a block may hold
whatever its own tooling expects:
```vue
<docs>
This block is prose, and it may mention a `<my-component>` without
closing it.
</docs>
<template lang="pug">
.test
#foo
</template>
```
Previously both blocks produced a parse error and the whole file was
left unformatted. Biome now prints their content unchanged while still
formatting the opening tag.
- [#​11231](https://redirect.github.com/biomejs/biome/pull/11231)
[`4afd901`](https://redirect.github.com/biomejs/biome/commit/4afd901edd5d921d63a259a049c6a774269c7b82)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Improved the performance of the following lint rules:
- [`noArguments`](https://biomejs.dev/linter/rules/no-arguments/).
-
[`noGlobalAssign`](https://biomejs.dev/linter/rules/no-global-assign/).
-
[`noUndeclaredVariables`](https://biomejs.dev/linter/rules/no-undeclared-variables/).
-
[`noRestrictedGlobals`](https://biomejs.dev/linter/rules/no-restricted-globals/).
-
[`noInvalidUseBeforeDeclaration`](https://biomejs.dev/linter/rules/no-invalid-use-before-declaration/).
- [`noShadow`](https://biomejs.dev/linter/rules/no-shadow/).
- [`noRedeclare`](https://biomejs.dev/linter/rules/no-redeclare/).
- [#​11134](https://redirect.github.com/biomejs/biome/pull/11134)
[`2fa0a62`](https://redirect.github.com/biomejs/biome/commit/2fa0a62224af7a13869a28ef80aefa5ea75ebfd2)
Thanks [@​yanthomasdev](https://redirect.github.com/yanthomasdev)!
- Clarified the warning emitted when using the experimental `json` and
`json-pretty` reporters.
- [#​11198](https://redirect.github.com/biomejs/biome/pull/11198)
[`ed88b13`](https://redirect.github.com/biomejs/biome/commit/ed88b13a6d95fe564aaee6c731651e7dec8266db)
Thanks
[@​saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#​11171](https://redirect.github.com/biomejs/biome/issues/11171):
variables referenced only inside a Svelte attachment (`{@attach ...}`)
are no longer reported as unused by
[`noUnusedVariables`](https://biomejs.dev/linter/rules/no-unused-variables/)
and
[`noUnusedImports`](https://biomejs.dev/linter/rules/no-unused-imports/).
- [#​11155](https://redirect.github.com/biomejs/biome/pull/11155)
[`6ee17ea`](https://redirect.github.com/biomejs/biome/commit/6ee17ea2df979a67df5d1263734f28f77c6512a6)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Improved
performance when printing diagnostics to the console.
- [#​11160](https://redirect.github.com/biomejs/biome/pull/11160)
[`217f8ad`](https://redirect.github.com/biomejs/biome/commit/217f8adbc2f700ab4c92cb227434c2afba9f9611)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Improved the
performance of
[`noFloatingPromises`](https://biomejs.dev/linter/rules/no-floating-promises/)
by skipping type inference for assignment statements, which are always
considered handled.
- [#​11159](https://redirect.github.com/biomejs/biome/pull/11159)
[`26c23d9`](https://redirect.github.com/biomejs/biome/commit/26c23d96ced1a6eca496955fbe93279da2747346)
Thanks
[@​saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#​11144](https://redirect.github.com/biomejs/biome/issues/11144):
[`noFloatingPromises`](https://biomejs.dev/linter/rules/no-floating-promises/)
no longer reports already-awaited optional Promise values.
- [#​11138](https://redirect.github.com/biomejs/biome/pull/11138)
[`8c2c6bd`](https://redirect.github.com/biomejs/biome/commit/8c2c6bd96c035e506bc60b75448afb039e331fb1)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed
[#​11121](https://redirect.github.com/biomejs/biome/issues/11121):
[`noUnnecessaryConditions`](https://biomejs.dev/linter/rules/no-unnecessary-conditions/)
no longer reports conditions based on an inapplicable function overload.
For example, the condition in the following code is no longer reported
because `query({})` selects the overload that returns `boolean`:
```ts
declare function query(options: { initial: string }): { isPending: false
};
declare function query(options: { initial?: string }): { isPending:
boolean };
const { isPending } = query({});
isPending || fallback;
```
- [#​11152](https://redirect.github.com/biomejs/biome/pull/11152)
[`c4fc6a9`](https://redirect.github.com/biomejs/biome/commit/c4fc6a90777358905cf99b3261a479de73d7d383)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Improved the
performance of collecting rule timings with `--profile-rules` in heavily
multithreaded environments.
- [#​11128](https://redirect.github.com/biomejs/biome/pull/11128)
[`4d3ff76`](https://redirect.github.com/biomejs/biome/commit/4d3ff7689c36af5149142d9a4a23165154359655)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed
[#​7635](https://redirect.github.com/biomejs/biome/issues/7635):
[`noDeprecatedImports`](https://biomejs.dev/linter/rules/no-deprecated-imports/)
now detects deprecated ambient declarations that are exported
separately.
- [#​11117](https://redirect.github.com/biomejs/biome/pull/11117)
[`01f7ef5`](https://redirect.github.com/biomejs/biome/commit/01f7ef58d4c19a587b01754c96b577a2a5a47418)
Thanks [@​subotac](https://redirect.github.com/subotac)! - Fixed
[#​11014](https://redirect.github.com/biomejs/biome/issues/11014):
[`noDelete`](https://biomejs.dev/linter/rules/no-delete/) no longer
reports `process.env["FOO"]` style property deletions.
- [#​11168](https://redirect.github.com/biomejs/biome/pull/11168)
[`9847e68`](https://redirect.github.com/biomejs/biome/commit/9847e680ff8bb891a6c910e881af98a4fffa33c2)
Thanks
[@​saberoueslati](https://redirect.github.com/saberoueslati)! -
Added the nursery rule
[`noNonScalableViewport`](https://biomejs.dev/linter/rules/no-non-scalable-viewport),
which reports viewport metadata that disables user scaling with
`user-scalable=no`.
For example:
```html
<meta name="viewport" content="width=device-width, user-scalable=no" />
```
- [#​11154](https://redirect.github.com/biomejs/biome/pull/11154)
[`a1d6b1f`](https://redirect.github.com/biomejs/biome/commit/a1d6b1fc544c6c6cc1dd38f87898d34738fbe97b)
Thanks [@​dyc3](https://redirect.github.com/dyc3)! - Improved the
performance of
[`noImportCycles`](https://biomejs.dev/linter/rules/no-import-cycles/)
by skipping graph traversals for imports that cannot be part of a cycle.
- [#​11175](https://redirect.github.com/biomejs/biome/pull/11175)
[`d96d6dd`](https://redirect.github.com/biomejs/biome/commit/d96d6dd07702828f7e7a5ce59f8fc00006f6ee46)
Thanks [@​ematipico](https://redirect.github.com/ematipico)! -
Fixed CSS parsing of registered custom properties: Biome now correctly
validates the `syntax` descriptor of `@property` rules.
#### What's Changed
- fix(html): preserve trailing newline after comments by
[@​subotac](https://redirect.github.com/subotac) in
[#​11118](https://redirect.github.com/biomejs/biome/pull/11118)
- fix(format/html): preserve the content of preformatted elements by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11077](https://redirect.github.com/biomejs/biome/pull/11077)
- feat(format/yaml): explicit block mapping entries by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11053](https://redirect.github.com/biomejs/biome/pull/11053)
- feat(format/yaml): normalize scalar quotes by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11054](https://redirect.github.com/biomejs/biome/pull/11054)
- fix(parser/yaml): plain scalar `#` and alias name lexing by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11061](https://redirect.github.com/biomejs/biome/pull/11061)
- feat(format/yaml): normalize node property placement by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11062](https://redirect.github.com/biomejs/biome/pull/11062)
- feat(format/yaml): middle comments by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11063](https://redirect.github.com/biomejs/biome/pull/11063)
- feat(css\_formatter): scss and css comments inside declarations by
[@​denbezrukov](https://redirect.github.com/denbezrukov) in
[#​11113](https://redirect.github.com/biomejs/biome/pull/11113)
- chore: trim published crate sizes with cargo diet by
[@​dreyfus92](https://redirect.github.com/dreyfus92) in
[#​11123](https://redirect.github.com/biomejs/biome/pull/11123)
- feat(useSortedClasses): resolve bare functional utilities with
defaults in sort\_v4 by
[@​johncarmack1984](https://redirect.github.com/johncarmack1984)
in [#​11120](https://redirect.github.com/biomejs/biome/pull/11120)
- feat(lint): add ignoreIfStatements option to useNullishCoalescing by
[@​pkallos](https://redirect.github.com/pkallos) in
[#​10822](https://redirect.github.com/biomejs/biome/pull/10822)
- feat(md/fmt): dedent code blocks, normalize strings, indentation fixes
by [@​ematipico](https://redirect.github.com/ematipico) in
[#​11111](https://redirect.github.com/biomejs/biome/pull/11111)
- fix: `--stdin-file-path` with nested configuration by
[@​cormacrelf](https://redirect.github.com/cormacrelf) in
[#​8239](https://redirect.github.com/biomejs/biome/pull/8239)
- fix(noDelete): allow computed process.env deletion by
[@​subotac](https://redirect.github.com/subotac) in
[#​11117](https://redirect.github.com/biomejs/biome/pull/11117)
- chore(xtask): migrate Date global type by
[@​minseong0324](https://redirect.github.com/minseong0324) in
[#​11107](https://redirect.github.com/biomejs/biome/pull/11107)
- feat(format/yaml): flow collection blank lines and spacing by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11064](https://redirect.github.com/biomejs/biome/pull/11064)
- feat(format/yaml): explicit-form mapping keys by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11065](https://redirect.github.com/biomejs/biome/pull/11065)
- feat(format/yaml): document separation and trailing newlines by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11066](https://redirect.github.com/biomejs/biome/pull/11066)
- feat(format/yaml): block scalar trailing comment lines by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11058](https://redirect.github.com/biomejs/biome/pull/11058)
- fix(css\_formatter): preserve property value comment indentation by
[@​denbezrukov](https://redirect.github.com/denbezrukov) in
[#​11124](https://redirect.github.com/biomejs/biome/pull/11124)
- feat(fmt/md): prose-wrap formatting for markdown by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11115](https://redirect.github.com/biomejs/biome/pull/11115)
- feat(lint): add nursery rule noTailwindArbitraryValue by
[@​THEjacob1000](https://redirect.github.com/THEjacob1000) in
[#​10094](https://redirect.github.com/biomejs/biome/pull/10094)
- fix(parser/yaml): property attachment across lines in block mappings
by [@​dyc3](https://redirect.github.com/dyc3) in
[#​11057](https://redirect.github.com/biomejs/biome/pull/11057)
- fix(css): resolve empty syntax node pointers by
[@​denbezrukov](https://redirect.github.com/denbezrukov) in
[#​11132](https://redirect.github.com/biomejs/biome/pull/11132)
- fix(inference): regression in optional chain types by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11138](https://redirect.github.com/biomejs/biome/pull/11138)
- docs: rework CLI by
[@​yanthomasdev](https://redirect.github.com/yanthomasdev) in
[#​11134](https://redirect.github.com/biomejs/biome/pull/11134)
- fix(html): track Vue template assignment references by
[@​saberoueslati](https://redirect.github.com/saberoueslati) in
[#​11156](https://redirect.github.com/biomejs/biome/pull/11156)
- feat(css): property syntax value codec by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11148](https://redirect.github.com/biomejs/biome/pull/11148)
- feat(lint): add noExtendNative nursery rule by
[@​AkashNaickar](https://redirect.github.com/AkashNaickar) in
[#​11136](https://redirect.github.com/biomejs/biome/pull/11136)
- feat(css): property semantic model by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11149](https://redirect.github.com/biomejs/biome/pull/11149)
- perf(console): batch writes when printing instead of one char at a
time by [@​dyc3](https://redirect.github.com/dyc3) in
[#​11155](https://redirect.github.com/biomejs/biome/pull/11155)
- fix(lint): detect deprecated ambient imports by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11128](https://redirect.github.com/biomejs/biome/pull/11128)
- chore(xtask): migrate RegExp global types by
[@​minseong0324](https://redirect.github.com/minseong0324) in
[#​11108](https://redirect.github.com/biomejs/biome/pull/11108)
- perf(rule\_profiler): thread local profilers, aggregate at the end by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11152](https://redirect.github.com/biomejs/biome/pull/11152)
- perf(noFloatingPromises): short circuit assignment statements by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11160](https://redirect.github.com/biomejs/biome/pull/11160)
- feat(module-graph): css traversal for properties by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11153](https://redirect.github.com/biomejs/biome/pull/11153)
- fix(inference): collapse instance wrappers around unions by
[@​saberoueslati](https://redirect.github.com/saberoueslati) in
[#​11159](https://redirect.github.com/biomejs/biome/pull/11159)
- fix(parse/html): read Vue SFC custom blocks as opaque text by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11078](https://redirect.github.com/biomejs/biome/pull/11078)
- feat(format/html): lay out the srcset attribute by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11079](https://redirect.github.com/biomejs/biome/pull/11079)
- fix(format/html): write the HTML5 doctype in lowercase by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11106](https://redirect.github.com/biomejs/biome/pull/11106)
- fix(format/html): pick attribute quotes by counting them by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11127](https://redirect.github.com/biomejs/biome/pull/11127)
- chore(xtask): migrate Map and Set global types by
[@​minseong0324](https://redirect.github.com/minseong0324) in
[#​11109](https://redirect.github.com/biomejs/biome/pull/11109)
- feat(lint): add noNonScalableViewport rule by
[@​saberoueslati](https://redirect.github.com/saberoueslati) in
[#​11168](https://redirect.github.com/biomejs/biome/pull/11168)
- chore(xtask): migrate Array global types by
[@​minseong0324](https://redirect.github.com/minseong0324) in
[#​11125](https://redirect.github.com/biomejs/biome/pull/11125)
- fix(css\_parser): tighten interpolated identifier boundaries by
[@​denbezrukov](https://redirect.github.com/denbezrukov) in
[#​11181](https://redirect.github.com/biomejs/biome/pull/11181)
- fix(analyze): recognize references in Svelte attachments by
[@​saberoueslati](https://redirect.github.com/saberoueslati) in
[#​11198](https://redirect.github.com/biomejs/biome/pull/11198)
- fix(lint/css): recognize Vue :deep() pseudo-class by
[@​subotac](https://redirect.github.com/subotac) in
[#​11184](https://redirect.github.com/biomejs/biome/pull/11184)
- chore(deps): update rust crate serde to 1.0.229 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11200](https://redirect.github.com/biomejs/biome/pull/11200)
- chore(deps): update rust crate camino to 1.2.5 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11197](https://redirect.github.com/biomejs/biome/pull/11197)
- chore(deps): update rust crate schemars to 1.2.2 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11199](https://redirect.github.com/biomejs/biome/pull/11199)
- chore(deps): update rust crate serde\_json to 1.0.151 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11203](https://redirect.github.com/biomejs/biome/pull/11203)
- chore(deps): update rust crate bpaf to 0.9.27 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11196](https://redirect.github.com/biomejs/biome/pull/11196)
- chore(deps): update github-actions by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11204](https://redirect.github.com/biomejs/biome/pull/11204)
- chore(deps): update pnpm to v11.18.0 by
[@​renovate](https://redirect.github.com/renovate)\[bot] in
[#​11205](https://redirect.github.com/biomejs/biome/pull/11205)
- test(format/html): enable `html_embeds` feature for tests by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11216](https://redirect.github.com/biomejs/biome/pull/11216)
- perf(noImportCycles): prune DFS traversals by grouping strongly
connected components by [@​dyc3](https://redirect.github.com/dyc3)
in [#​11154](https://redirect.github.com/biomejs/biome/pull/11154)
- feat(graph): traversal of HTML-ish files by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11158](https://redirect.github.com/biomejs/biome/pull/11158)
- feat(css): js traverse, source order paths, cache traverse by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11169](https://redirect.github.com/biomejs/biome/pull/11169)
- fix(css): validate
[@​property](https://redirect.github.com/property) syntax
descriptors by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11175](https://redirect.github.com/biomejs/biome/pull/11175)
- test(format/html): run the prettier-plugin-svelte suite by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11130](https://redirect.github.com/biomejs/biome/pull/11130)
- fix(format/html): stop printing a document's last comment twice by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11188](https://redirect.github.com/biomejs/biome/pull/11188)
- fix(noPositiveTabindex): make suppression comments work on multiline
HTML tags by
[@​Bishwas-py](https://redirect.github.com/Bishwas-py) in
[#​11201](https://redirect.github.com/biomejs/biome/pull/11201)
- perf(lint): reduce trigger of rules by
[@​ematipico](https://redirect.github.com/ematipico) in
[#​11231](https://redirect.github.com/biomejs/biome/pull/11231)
- fix(format/html): keep the blank line before text by
[@​dyc3](https://redirect.github.com/dyc3) in
[#​11193](https://redirect.github.com/biomejs/biome/pull/11193)
- fix(format/html): format a Svelte array pattern that skips a position
by [@​dyc3](https://redirect.github.com/dyc3) in
[#​11194](https://redirect.github.com/biomejs/biome/pull/11194)
- ci: release by
[@​github-actions](https://redirect.github.com/github-actions)\[bot]
in [#​11119](https://redirect.github.com/biomejs/biome/pull/11119)
#### New Contributors
- [@​subotac](https://redirect.github.com/subotac) made their
first contribution in
[#​11118](https://redirect.github.com/biomejs/biome/pull/11118)
- [@​dreyfus92](https://redirect.github.com/dreyfus92) made their
first contribution in
[#​11123](https://redirect.github.com/biomejs/biome/pull/11123)
- [@​THEjacob1000](https://redirect.github.com/THEjacob1000)
> ✂ **Note**
>
> PR body was truncated to here.
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- "before 4am on Monday"
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [hugo](https://redirect.github.com/gohugoio/hugo) | tools | minor | `0.164.0` → `0.165.0` | --- ### Release Notes <details> <summary>gohugoio/hugo (hugo)</summary> ### [`v0.165.0`](https://redirect.github.com/gohugoio/hugo/releases/tag/v0.165.0) [Compare Source](https://redirect.github.com/gohugoio/hugo/compare/v0.164.0...v0.165.0) The two main new things is the new `css.ChromaStyles` template func and the new `importContext` option demonstrated below. ```handlebars {{ $light := css.ChromaStyles (dict "targetPath" "css/components/chroma-light.css" "style" "github" "mode" "light") }} {{ $dark := css.ChromaStyles (dict "targetPath" "css/components/chroma-dark.css" "style" "github" "mode" "dark") }} {{ $opts := dict "minify" true "importContext" (slice $light $dark) }} {{ $css := resources.Get "css/main.css" | css.Build $opts }} ``` The `importContext` is relevant for `css.Build`, `js.Build`, `css.Sass`, and `css.PostCSS`. and it allows you to make resources (e.g. built from `resources.FromString`) resolvable in e.g. CSS `@import` statements. #### Note - Remove tailwindcss from the default security.exec.allow list (note) [`8a55df7`](https://redirect.github.com/gohugoio/hugo/commit/8a55df7a) [@​bep](https://redirect.github.com/bep) [#​15178](https://redirect.github.com/gohugoio/hugo/issues/15178) [#​15171](https://redirect.github.com/gohugoio/hugo/issues/15171) #### Bug fixes - Fix resource transformation chaining after content access [`f772998`](https://redirect.github.com/gohugoio/hugo/commit/f772998f) [@​bep](https://redirect.github.com/bep) [#​15189](https://redirect.github.com/gohugoio/hugo/issues/15189) - Fix server static file detection for deleted files/directories in the static syncer [`2ffaf1f`](https://redirect.github.com/gohugoio/hugo/commit/2ffaf1fc) [@​bep](https://redirect.github.com/bep) - Fix server errors when deleting static files or directories [`a808f6e`](https://redirect.github.com/gohugoio/hugo/commit/a808f6e4) [@​bep](https://redirect.github.com/bep) [#​15174](https://redirect.github.com/gohugoio/hugo/issues/15174) - Fix panic on server atomic save edits on MacOS [`6bf1524`](https://redirect.github.com/gohugoio/hugo/commit/6bf15241) [@​bep](https://redirect.github.com/bep) [#​15130](https://redirect.github.com/gohugoio/hugo/issues/15130) - markup/asciidocext: Fix TOC parsing for asciidoctor-html5s [`f961093`](https://redirect.github.com/gohugoio/hugo/commit/f961093e) [@​jmooring](https://redirect.github.com/jmooring) [#​15121](https://redirect.github.com/gohugoio/hugo/issues/15121) - snap: Fix snap home environment [`984358f`](https://redirect.github.com/gohugoio/hugo/commit/984358f0) [@​jmooring](https://redirect.github.com/jmooring) [#​15114](https://redirect.github.com/gohugoio/hugo/issues/15114) #### Improvements - resources: Resume chained resource transformations [`995a215`](https://redirect.github.com/gohugoio/hugo/commit/995a2159) [@​bep](https://redirect.github.com/bep) [#​15189](https://redirect.github.com/gohugoio/hugo/issues/15189) [#​15189](https://redirect.github.com/gohugoio/hugo/issues/15189) - resources/jsconfig: Drop source root mapping for the current source root [`f88f0a9`](https://redirect.github.com/gohugoio/hugo/commit/f88f0a9f) [@​bep](https://redirect.github.com/bep) [#​15169](https://redirect.github.com/gohugoio/hugo/issues/15169) - circleci: Upgrade to Go 1.26.5 [`52c9bd7`](https://redirect.github.com/gohugoio/hugo/commit/52c9bd79) [@​bep](https://redirect.github.com/bep) - Add Data.Artifacts to css.Build and js.Build [`44da086`](https://redirect.github.com/gohugoio/hugo/commit/44da0860) [@​bep](https://redirect.github.com/bep) [#​15173](https://redirect.github.com/gohugoio/hugo/issues/15173) - css: Add classDark and classLight options to css.ChromaStyles and gen chromastyles [`33d1f2c`](https://redirect.github.com/gohugoio/hugo/commit/33d1f2c8) [@​bep](https://redirect.github.com/bep) [#​15167](https://redirect.github.com/gohugoio/hugo/issues/15167) - markup/highlight: Re-emit token colors dropped by Chroma's minifier [`64da6d7`](https://redirect.github.com/gohugoio/hugo/commit/64da6d7c) [@​bep](https://redirect.github.com/bep) [#​15161](https://redirect.github.com/gohugoio/hugo/issues/15161) - Add importContext option to css.Build, js.Build, css.Sass and css.TailwindCSS [`70db201`](https://redirect.github.com/gohugoio/hugo/commit/70db201e) [@​bep](https://redirect.github.com/bep) [#​15103](https://redirect.github.com/gohugoio/hugo/issues/15103) - Remove some old deprecations [`8a468df`](https://redirect.github.com/gohugoio/hugo/commit/8a468df0) [@​bep](https://redirect.github.com/bep) - Add css.ChromaStyles [`615e45d`](https://redirect.github.com/gohugoio/hugo/commit/615e45d6) [@​bep](https://redirect.github.com/bep) [#​15112](https://redirect.github.com/gohugoio/hugo/issues/15112) - check.sh: Handle staticcheck not installed/in PATH [`a243a61`](https://redirect.github.com/gohugoio/hugo/commit/a243a615) [@​Soundcreates](https://redirect.github.com/Soundcreates) - warpc: Improve AVIF error message on memory allocation failure [`7d90277`](https://redirect.github.com/gohugoio/hugo/commit/7d90277a) [@​bep](https://redirect.github.com/bep) - cache/filecache: Don't prune used cache entries with mixed-case dir names [`861ede6`](https://redirect.github.com/gohugoio/hugo/commit/861ede6d) [@​bep](https://redirect.github.com/bep) [#​15101](https://redirect.github.com/gohugoio/hugo/issues/15101) - Drop symlinks in parent directories [`f228c87`](https://redirect.github.com/gohugoio/hugo/commit/f228c87d) [@​bep](https://redirect.github.com/bep) - Delete .gemini [`7df45f6`](https://redirect.github.com/gohugoio/hugo/commit/7df45f61) [@​bep](https://redirect.github.com/bep) - common/hugo: Include non-go dependencies in go env output [`89b8c32`](https://redirect.github.com/gohugoio/hugo/commit/89b8c322) [@​jmooring](https://redirect.github.com/jmooring) [#​15116](https://redirect.github.com/gohugoio/hugo/issues/15116) #### Dependency Updates - build(deps): bump github.com/bep/imagemeta from 0.17.3 to 1.0.0 [`0bb337b`](https://redirect.github.com/gohugoio/hugo/commit/0bb337b2) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/evanw/esbuild from 0.28.1 to 0.28.2 [`03dc917`](https://redirect.github.com/gohugoio/hugo/commit/03dc9170) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/tdewolff/minify/v2 from 2.24.14 to 2.24.16 [`c829b73`](https://redirect.github.com/gohugoio/hugo/commit/c829b736) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/getkin/kin-openapi from 0.145.0 to 0.146.0 [`94f3908`](https://redirect.github.com/gohugoio/hugo/commit/94f3908e) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/rogpeppe/go-internal from 1.15.0 to 1.16.0 [`75fcc75`](https://redirect.github.com/gohugoio/hugo/commit/75fcc752) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/mattn/go-isatty from 0.0.22 to 0.0.24 [`b5fa03d`](https://redirect.github.com/gohugoio/hugo/commit/b5fa03d3) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/yuin/goldmark from 1.8.4 to 1.8.5 [`9da472d`](https://redirect.github.com/gohugoio/hugo/commit/9da472dd) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump golang.org/x/tools from 0.47.0 to 0.48.0 [`635532a`](https://redirect.github.com/gohugoio/hugo/commit/635532a2) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/kyokomi/emoji/v2 from 2.2.13 to 2.2.14 [`9c71f60`](https://redirect.github.com/gohugoio/hugo/commit/9c71f600) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/getkin/kin-openapi from 0.144.0 to 0.145.0 [`420527f`](https://redirect.github.com/gohugoio/hugo/commit/420527fc) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump golang.org/x/image from 0.43.0 to 0.44.0 [`7fe786e`](https://redirect.github.com/gohugoio/hugo/commit/7fe786e3) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/bep/imagemeta from 0.17.2 to 0.17.3 [`03b244f`](https://redirect.github.com/gohugoio/hugo/commit/03b244fc) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/tdewolff/minify/v2 from 2.24.13 to 2.24.14 [`9611813`](https://redirect.github.com/gohugoio/hugo/commit/96118133) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/yuin/goldmark from 1.8.2 to 1.8.4 [`e35b7f0`](https://redirect.github.com/gohugoio/hugo/commit/e35b7f04) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump golang.org/x/net from 0.56.0 to 0.57.0 [`0796fa7`](https://redirect.github.com/gohugoio/hugo/commit/0796fa7a) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump golang.org/x/text from 0.38.0 to 0.40.0 [`1b701b7`](https://redirect.github.com/gohugoio/hugo/commit/1b701b72) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump github.com/getkin/kin-openapi from 0.140.0 to 0.144.0 [`a32d70b`](https://redirect.github.com/gohugoio/hugo/commit/a32d70b7) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 [`948cfb9`](https://redirect.github.com/gohugoio/hugo/commit/948cfb98) [@​dependabot](https://redirect.github.com/dependabot)\[bot] - build(deps): bump golang.org/x/mod from 0.37.0 to 0.38.0 [`8930802`](https://redirect.github.com/gohugoio/hugo/commit/8930802e) [@​dependabot](https://redirect.github.com/dependabot)\[bot] #### Documentation - Remove Star History from README [`dd3f273`](https://redirect.github.com/gohugoio/hugo/commit/dd3f2731) [@​bep](https://redirect.github.com/bep) [#​15190](https://redirect.github.com/gohugoio/hugo/issues/15190) - Update README.md [`d1f191c`](https://redirect.github.com/gohugoio/hugo/commit/d1f191c5) [@​jmooring](https://redirect.github.com/jmooring) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…#2384) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [aqua:grafana/gcx](https://redirect.github.com/grafana/gcx) | tools | minor | `1.0.0` → `1.1.0` | --- ### Release Notes <details> <summary>grafana/gcx (aqua:grafana/gcx)</summary> ### [`v1.1.0`](https://redirect.github.com/grafana/gcx/blob/HEAD/CHANGELOG.md#v110-2026-08-14) [Compare Source](https://redirect.github.com/grafana/gcx/compare/v1.0.0...v1.1.0) **Breaking changes** - `gcx agento11y collections add-conversations` and `gcx agento11y collections remove-conversation` emit `type: gcx.agento11y.collection_membership` instead of `gcx.aio11y.collection_membership`. `schema_version` stays `1`. No fields changed. Scripts that read `type` must accept the new value. **New features** - Add `gcx profiles data-range` for Pyroscope ingestion health. - Add the same `data-range` command under `gcx datasources pyroscope`. - Add `gcx instrumentation explain` and `list-explanations` for the finding explanations that ship with `otel-checker` (now v0.3.1). - Add an `EXPLAIN_ID` column to `gcx instrumentation check` table output, and an `explain_id` field to its JSON output. Pass the value to `gcx instrumentation explain`. - Add `gcx assistant investigations list-evidence`. - Show the chat ID next to the investigation ID in `investigations get`. - Keep full v2 investigation summaries and totals in list output. - Filter IRM alert groups by escalation chain and by date window. - Add agent support to `gcx metrics list-names`. - Add agent support to metrics label matching. **Improvements** - Check contexts concurrently in `gcx config check`. - Record `target_kind` in usage telemetry events. **Fixes** - Make `gcx dev serve` exit on Ctrl-C. - Set `AllowsEdits` so gcx-managed dashboards stay editable in the UI. - Keep `configType` in Fleet so OTel pipelines round-trip. - Support UTF-8 label names in profiles. - Match experiment report types and trial counts to the API. - Send guard redaction config as `redact` with `{id, regex}`. - Drop `rule_id` from the rules update PATCH body. - Handle an unavailable keychain safely during verification. **Internal** - Rename the `aio11y` Go package to `agento11y`. - Add the `integrate-with-gcx` and `review-pr` contributor skills. - Add a command naming conventions guide. - Restructure the Grafana Cloud documentation. - Pin `GCX_AGENT_MODE=false` for the test tasks. - Add data sources code owners for `internal/datasources`. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
> ℹ️ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [mise](https://redirect.github.com/jdx/mise) | minor | `v2026.7.5` →
`v2026.8.6` |
---
### Release Notes
<details>
<summary>jdx/mise (mise)</summary>
###
[`v2026.8.6`](https://redirect.github.com/jdx/mise/releases/tag/v2026.8.6):
: Resumable downloads, richer Homebrew casks, and monorepo task fixes
[Compare
Source](https://redirect.github.com/jdx/mise/compare/v2026.8.5...v2026.8.6)
This release adds resumable HTTP downloads, expands Homebrew cask
support, and lands a large batch of fixes across tasks, config, install,
and platform-specific behavior — with a particular focus on monorepos
and Windows.
#### Highlights
- Interrupted artifact downloads now resume instead of restarting from
zero, and more transient network failures (including HTTP/2
`REFUSED_STREAM`) are retried automatically.
- The Homebrew cask backend gained structured symlinks, generic
artifacts, and copy/installer flight steps, closing several gaps in cask
installation.
- A wide round of monorepo task, config precedence, and Windows path
handling fixes.
#### Added
- **http:** interrupted downloads now resume via HTTP Range requests
when a strong ETag or Last-Modified validator is available, keeping
validated partial files across retries and mise invocations instead of
re-downloading from byte zero. mise falls back to a clean restart when
validators do not match, and abandoned partials expire after 30 days.
([#​11866](https://redirect.github.com/jdx/mise/pull/11866) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **brew:** the Homebrew cask backend now supports structured `symlink`
steps (with path bases, templates, guards, source globs, and sudo
control), generic cask artifacts, and `copy`/installer flight steps,
with transactional rollback if an install fails.
([#​11962](https://redirect.github.com/jdx/mise/pull/11962),
[#​11963](https://redirect.github.com/jdx/mise/pull/11963),
[#​11964](https://redirect.github.com/jdx/mise/pull/11964) by
[@​jdx](https://redirect.github.com/jdx))
- **task:** `mise run --all` opens the interactive task picker with
tasks from the entire monorepo, matching the load path already used by
`mise tasks ls --all`. The default picker stays scoped to the current
directory hierarchy.
([#​11920](https://redirect.github.com/jdx/mise/pull/11920) by
[@​jdx](https://redirect.github.com/jdx))
```console
mise run --all
```
- **task:** add `task.cache.audit_report`
(`MISE_TASK_CACHE_AUDIT_REPORT`) to write the complete cache-audit
report to a JSON Lines file. The console still caps at 20 paths per
task, but the file now captures every undeclared read and write so large
audits (e.g. Jest over `node_modules`) are actually usable.
([#​11997](https://redirect.github.com/jdx/mise/pull/11997) by
[@​stevenpollack](https://redirect.github.com/stevenpollack))
```console
MISE_TASK_CACHE_AUDIT_REPORT=audit.jsonl mise run --force build
```
- **dotfiles:** whole-file `[dotfiles]` entries can now declare their
body inline with `content = "..."` instead of requiring a separate
source file, useful for small configs and user-writable paths outside
`$HOME`. `content` cannot be combined with `source`, `mode`, or
`exclude`.
([#​11983](https://redirect.github.com/jdx/mise/pull/11983) by
[@​jdx](https://redirect.github.com/jdx))
- **deps:** deps provider config fields (paths, commands, `env`,
descriptions, timeouts) now render Tera templates using the defining
config file's context, with shell-style environment expansion and
rendered env values folded into freshness identity. Template errors
surface as clear configuration errors before commands run.
([#​11886](https://redirect.github.com/jdx/mise/pull/11886) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **config:** add a config-root-scoped `[tool_config] locked = true`
policy that requires tools declared by configs sharing that root to
resolve and install from their lockfiles, without forcing global or
parent-root tools into strict mode. `[settings] locked`, `--locked`, and
`MISE_LOCKED` remain invocation-wide.
([#​11940](https://redirect.github.com/jdx/mise/pull/11940) by
[@​jdx](https://redirect.github.com/jdx))
#### Fixed
- **task:** in monorepo mode, running a task by its bare or `:`-prefixed
name now works from any directory below a config root, resolving to the
nearest enclosing project instead of failing.
([#​11941](https://redirect.github.com/jdx/mise/pull/11941) by
[@​pikeas](https://redirect.github.com/pikeas))
- **task:** normalize task cwd for source freshness
([#​11987](https://redirect.github.com/jdx/mise/pull/11987) by
[@​jdx](https://redirect.github.com/jdx)), bound buffered command
output
([#​11922](https://redirect.github.com/jdx/mise/pull/11922)),
avoid zsh process-substitution hangs
([#​11904](https://redirect.github.com/jdx/mise/pull/11904)), and
normalize variadic usage env values
([#​11881](https://redirect.github.com/jdx/mise/pull/11881)) by
[@​Marukome0743](https://redirect.github.com/Marukome0743); mask
archive modes in remote cache nodes
([#​11877](https://redirect.github.com/jdx/mise/pull/11877) by
[@​stevenpollack](https://redirect.github.com/stevenpollack)).
- **http:** retry send failures that never produced a response,
including HTTP/2 `REFUSED_STREAM`, which CDNs emit as backpressure and
which previously failed on the first attempt even with retries enabled.
([#​11961](https://redirect.github.com/jdx/mise/pull/11961) by
[@​mariadeluna-tomtom](https://redirect.github.com/mariadeluna-tomtom))
- **http:** honor system install destinations for downloads.
([#​11851](https://redirect.github.com/jdx/mise/pull/11851) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **aqua:** when a downloaded checksum file lists per-file hashes but
none match the target filename, mise now errors instead of silently
returning a wrong checksum.
([#​11973](https://redirect.github.com/jdx/mise/pull/11973) by
[@​jakedgy](https://redirect.github.com/jakedgy))
- **pipx:** discover wheel-only package versions from PEP 503 Simple API
indexes, so packages published only as wheels now appear in `mise
ls-remote` and `latest` resolution.
([#​11959](https://redirect.github.com/jdx/mise/pull/11959) by
[@​jdx](https://redirect.github.com/jdx))
- **rust:** the rolling `nightly` channel now resolves to a concrete
`nightly-YYYY-MM-DD` toolchain via the official channel manifest, making
nightly lock, outdated, upgrade, and offline reuse reproducible while
keeping `mise.toml` on `nightly`.
([#​11980](https://redirect.github.com/jdx/mise/pull/11980) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **ruby:** support ruby-build CLI options.
([#​11918](https://redirect.github.com/jdx/mise/pull/11918) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **conda:** preserve cross-platform lock data
([#​11946](https://redirect.github.com/jdx/mise/pull/11946) by
[@​jdx](https://redirect.github.com/jdx)) and honor URL
replacements
([#​11930](https://redirect.github.com/jdx/mise/pull/11930) by
[@​Marukome0743](https://redirect.github.com/Marukome0743)).
- **npm:** render lifecycle logs through the progress display.
([#​11939](https://redirect.github.com/jdx/mise/pull/11939) by
[@​jdx](https://redirect.github.com/jdx))
- **oci:** strip the tag from `name:tag@digest` references so pulling a
base image by combined tag-and-digest no longer produces a malformed
token scope, while preserving registry ports.
([#​11979](https://redirect.github.com/jdx/mise/pull/11979) by
[@​fire-ant](https://redirect.github.com/fire-ant))
- **install:** write tool manifests atomically.
([#​11957](https://redirect.github.com/jdx/mise/pull/11957) by
[@​jdx](https://redirect.github.com/jdx))
- **lock:** include task-specific tools in the lockfile.
([#​11976](https://redirect.github.com/jdx/mise/pull/11976) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **deps:** invalidate deps state when a provider's command,
environment, working directory, or shell changes, so an edited `run`
command is no longer skipped as fresh
([#​11849](https://redirect.github.com/jdx/mise/pull/11849));
honor source and output overrides
([#​11896](https://redirect.github.com/jdx/mise/pull/11896)) by
[@​Marukome0743](https://redirect.github.com/Marukome0743).
- **hooks:** skip tool installation in preinstall tasks.
([#​11927](https://redirect.github.com/jdx/mise/pull/11927) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **exec:** allow a symlinked `resolv.conf` inside the sandbox.
([#​11958](https://redirect.github.com/jdx/mise/pull/11958) by
[@​jdx](https://redirect.github.com/jdx))
- **generate:** honor absolute localized directories.
([#​11975](https://redirect.github.com/jdx/mise/pull/11975) by
[@​NgoQuocViet2001](https://redirect.github.com/NgoQuocViet2001))
- **config:** allow typing `j`/`k` to filter in the `mise edit` tool
picker ([#​11969](https://redirect.github.com/jdx/mise/pull/11969)
by [@​jakedgy](https://redirect.github.com/jakedgy)); create the
config directory before writing into it
([#​11934](https://redirect.github.com/jdx/mise/pull/11934)) and
stop a `conf.d` drop-in from becoming the write target
([#​11917](https://redirect.github.com/jdx/mise/pull/11917)) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562).
- **bootstrap:** avoid sudo for user-writable files
([#​11984](https://redirect.github.com/jdx/mise/pull/11984)) and
allow Windows bootstrap without system files
([#​12003](https://redirect.github.com/jdx/mise/pull/12003)) by
[@​jdx](https://redirect.github.com/jdx).
- **semver:** stop labeling a mangled value as a semver range.
([#​11949](https://redirect.github.com/jdx/mise/pull/11949) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
##### Windows fixes
- **cli:** `mise activate` and `mise completion` now both accept `pwsh`
and `powershell`, and shell detection recognizes `.exe` suffixes.
([#​11928](https://redirect.github.com/jdx/mise/pull/11928) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **shell:** resolve a shell named by a full Windows path.
([#​11950](https://redirect.github.com/jdx/mise/pull/11950) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **shims:** stop treating a full-path `argv[0]` as a shim name.
([#​11982](https://redirect.github.com/jdx/mise/pull/11982) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **toolset:** accept a Windows tool path spelled with backslashes
([#​11937](https://redirect.github.com/jdx/mise/pull/11937)) and
reject `cmd.exe` metacharacters in a Windows tool path
([#​11947](https://redirect.github.com/jdx/mise/pull/11947)) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562).
- **dotfiles:** treat an unmanaged file as a conflict on Windows too.
([#​11981](https://redirect.github.com/jdx/mise/pull/11981) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **tasks:** stop telling Windows users to run `chmod +x`.
([#​11923](https://redirect.github.com/jdx/mise/pull/11923) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
#### Changed
- **upgrade/outdated:** `-b` is now the shorthand for `--bump`. The old
`-l` bump shorthand is hidden and deprecated (removal planned for
2027.8.5) so `-l` can later mean `--local`. When tools are current
within configured ranges but a bump is available outside them, both
commands now say so instead of reporting everything up to date.
([#​11945](https://redirect.github.com/jdx/mise/pull/11945) by
[@​jdx](https://redirect.github.com/jdx))
- **cli:** `mise use --global` alongside a path is now rejected instead
of silently ignored.
([#​11935](https://redirect.github.com/jdx/mise/pull/11935) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
#### Deprecated
- **config:** the automatic `all_compile = true` default on NixOS is
deprecated and scheduled for removal in 2027.8.0. It currently forces
source builds for Node, Python, Erlang, and Ruby even when precompiled
binaries work through `nix-ld`; mise now warns and points to enabling
`nix-ld` or setting `all_compile = true` explicitly. Alpine's
source-build default is unchanged.
([#​11956](https://redirect.github.com/jdx/mise/pull/11956) by
[@​jdx](https://redirect.github.com/jdx))
#### Registry
- Added `native-sdk`
([github:vercel-labs/native](https://redirect.github.com/vercel-labs/native))
by [@​phall1](https://redirect.github.com/phall1) in
[#​11942](https://redirect.github.com/jdx/mise/pull/11942)
- Added `restate` binaries
([github:restatedev/restate](https://redirect.github.com/restatedev/restate))
by [@​Bing-su](https://redirect.github.com/Bing-su) in
[#​11953](https://redirect.github.com/jdx/mise/pull/11953)
- Added `mailpit`
([aqua:axllent/mailpit](https://redirect.github.com/axllent/mailpit)) by
[@​joealden](https://redirect.github.com/joealden) in
[#​11960](https://redirect.github.com/jdx/mise/pull/11960)
#### New Contributors
- [@​stevenpollack](https://redirect.github.com/stevenpollack)
made their first contribution in
[#​11997](https://redirect.github.com/jdx/mise/pull/11997)
-
[@​mariadeluna-tomtom](https://redirect.github.com/mariadeluna-tomtom)
made their first contribution in
[#​11961](https://redirect.github.com/jdx/mise/pull/11961)
- [@​pikeas](https://redirect.github.com/pikeas) made their first
contribution in
[#​11941](https://redirect.github.com/jdx/mise/pull/11941)
- [@​phall1](https://redirect.github.com/phall1) made their first
contribution in
[#​11942](https://redirect.github.com/jdx/mise/pull/11942)
**Full Changelog**:
<https://github.com/jdx/mise/compare/v2026.8.5...v2026.8.6>
#### 💚 Sponsor mise
mise is maintained by [@​jdx](https://redirect.github.com/jdx), an
open source developer for [**entire.io**](https://entire.io), the title
sponsor of the [jdx.dev](https://jdx.dev) open source tools. Development
is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at
[jdx.dev](https://jdx.dev/sponsors.html). Individual and company
sponsorships keep mise fast, free, and independent.
###
[`v2026.8.5`](https://redirect.github.com/jdx/mise/releases/tag/v2026.8.5):
: PyPy on the precompiled path, Node source patches, and a broad batch
of fixes
[Compare
Source](https://redirect.github.com/jdx/mise/compare/mise-interactive-config-v2026.8.4...v2026.8.5)
This release lets mise install PyPy on the precompiled path (including
on Windows), adds Node source-build patching, and lands a wide set of
fixes across config precedence, install hooks, version pinning, and the
Rust, conda, and vfox backends.
#### Added
- **python:** PyPy can now be installed on the precompiled path — when
`python.compile=false`, and unconditionally on Windows, where PyPy
versions previously never appeared in `mise ls-remote python` and could
not be installed at all. mise reads the upstream
`downloads.python.org/pypy` index, downloads and extracts the correct
archive, runs `ensurepip`, and records a blake3 checksum in the lockfile
on first install (PyPy publishes no machine-readable checksums).
([#​11846](https://redirect.github.com/jdx/mise/pull/11846) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
```console
mise install python@pypy3.10-7.3.17
```
- **node:** add `node.apply_patches` (`MISE_NODE_APPLY_PATCHES`) to
apply local or remote patches to the Node source build before
`./configure` runs, mirroring `ruby.apply_patches`. It accepts a
newline-separated list of patch files or URLs. Strip level is
auto-detected from git- or diff-style markers, and patches are recorded
in the lockfile since they change the built artifact. If patches are set
but a precompiled Node was installed, mise now warns instead of silently
dropping them.
([#​11850](https://redirect.github.com/jdx/mise/pull/11850) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
```toml
[settings.node]
compile = true
apply_patches = "./patches/local.patch"
```
#### Fixed
- **config:** global config precedence inside `~/.config/mise` now
matches the documentation — `config.local.toml` overrides `config.toml`,
which overrides `conf.d/*.toml`. Previously the order was reversed for
`[settings]`, `[tools]`, and `[env]` when `~/.config/mise` was outside
the cwd walk.
([#​11906](https://redirect.github.com/jdx/mise/pull/11906) by
[@​halms](https://redirect.github.com/halms))
- **config:** `mise use` now updates a single tool version in place
within a standard `[tools.<name>]` table, preserving comments, key
ordering, whitespace, and nested option tables instead of collapsing the
table to inline form.
([#​11848](https://redirect.github.com/jdx/mise/pull/11848) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **install:** inline `preinstall` and `postinstall` hooks now run from
the owning project root, so relative paths resolve consistently even
when `mise install` is started from a subdirectory. The invocation
directory remains available through `MISE_ORIGINAL_CWD`.
([#​11857](https://redirect.github.com/jdx/mise/pull/11857) by
[@​jdx](https://redirect.github.com/jdx))
- **use:** `mise use --pin` now prefers an exact available release when
pinning, instead of reusing a more-specific installed fuzzy match. For
example `mise use --pin erlang@27.3` will pin `27.3` if that exact
release exists remotely, rather than depending on which versions happen
to be installed.
([#​11838](https://redirect.github.com/jdx/mise/pull/11838) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **task:** editing a root `[task_templates.*]` definition or a monorepo
task default now correctly invalidates affected tasks, so stale outputs
are no longer marked up to date after a template change.
([#​11858](https://redirect.github.com/jdx/mise/pull/11858) by
[@​jdx](https://redirect.github.com/jdx))
- **rust:** mise now reuses a complete external rustup installation (for
example one installed by Homebrew) when the default Rust homes are not
initialized, instead of downloading and initializing its own. Explicitly
configured Cargo/Rustup homes continue using the mise-managed path.
([#​11840](https://redirect.github.com/jdx/mise/pull/11840) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **conda:** conda package commands now run through prefix-aware
launchers that activate each command's own conda prefix, fixing tools
like `jdtls` that expand `${CONDA_PREFIX}` and rely on activation
scripts. Dependency executables stay isolated from the user's shell
`PATH`.
([#​11855](https://redirect.github.com/jdx/mise/pull/11855) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **python:** `disable_tools = ["python"]` (and allowlist forms like
`enable_tools = ["node"]`) now also suppress the `_.python.venv`
directive, so a disabled Python no longer leaves its virtualenv
activated on `PATH`.
([#​11885](https://redirect.github.com/jdx/mise/pull/11885) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **vfox:** configured vfox tool options are now exposed to plugin hooks
through `MISE_TOOL_OPTS__*` (with legacy `RTX_TOOL_OPTS__*` aliases), so
hooks reading `os.getenv("MISE_TOOL_OPTS__...")` see the resolved
options during install, uninstall, exec-env, and lock paths.
([#​11884](https://redirect.github.com/jdx/mise/pull/11884) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **aqua:** explicit `github_release` package-type overrides from
version and platform overrides are now applied, fixing installs such as
recent Claude Code releases that failed with "relative URL without a
base". ([#​11901](https://redirect.github.com/jdx/mise/pull/11901)
by [@​Marukome0743](https://redirect.github.com/Marukome0743))
#### Changed
- **cache:** remote build-cache prefetch now downloads output blobs
concurrently (up to 48 in parallel) while reserving foreground slots for
compiler lookups, dramatically speeding up large Rust cache restores
that previously downloaded thousands of small artifacts serially.
([#​11905](https://redirect.github.com/jdx/mise/pull/11905) by
[@​jdx](https://redirect.github.com/jdx))
#### Documentation
- **env:** clarified `_.source` PATH handling.
([#​11889](https://redirect.github.com/jdx/mise/pull/11889) by
[@​jdx](https://redirect.github.com/jdx))
- **task:** fixed boolean flag usage examples.
([#​11887](https://redirect.github.com/jdx/mise/pull/11887) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
#### Registry
- Use aqua for helmsman.
([#​11908](https://redirect.github.com/jdx/mise/pull/11908) by
[@​scop](https://redirect.github.com/scop))
#### Breaking Changes
- If you relied on `disable_tools = ["python"]` while still keeping a
`_.python.venv` activated, that virtualenv will no longer be activated.
The existing venv remains on disk and is restored automatically when
Python is re-enabled.
([#​11885](https://redirect.github.com/jdx/mise/pull/11885))
**Full Changelog**:
<https://github.com/jdx/mise/compare/v2026.8.4...v2026.8.5>
#### 💚 Sponsor mise
mise is maintained by [@​jdx](https://redirect.github.com/jdx), an
open source developer for [**entire.io**](https://entire.io), the title
sponsor of the [jdx.dev](https://jdx.dev) open source tools. Development
is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at
[jdx.dev](https://jdx.dev/sponsors.html). Individual and company
sponsorships keep mise fast, free, and independent.
###
[`v2026.8.4`](https://redirect.github.com/jdx/mise/releases/tag/v2026.8.4):
: Cross-backend ls, semver ordering, and bootstrap cask pruning
[Compare
Source](https://redirect.github.com/jdx/mise/compare/mise-interactive-config-v2026.8.3...mise-interactive-config-v2026.8.4)
This release adds explicit semantic version ordering for major backends,
teaches `mise ls` and `mise install --force` to work across backends,
extends bootstrap package management with platform filters and cask
pruning, and lands a broad batch of task, config, and platform-specific
fixes.
#### Added
- **backend:** tools can now declare an explicit `version_order`
(`source` or `semver`) so that `latest` and version-prefix resolution
follow semantic precedence instead of source/chronological order. This
is enabled for Aqua, GitHub, GitLab, Forgejo, and HTTP backends, and
fixes cases where a backport or older release line was picked ahead of a
newer version (for example neo4j, victoria-metrics, go-getter, talosctl,
rpk, and tealdeer). `mise ls-remote` continues to show upstream source
order. ([#​11774](https://redirect.github.com/jdx/mise/pull/11774)
by [@​jdx](https://redirect.github.com/jdx))
- **ls:** `mise ls <name>` now matches a tool installed from multiple
backends. Previously, installing a tool from both its registry backend
and, say, a `cargo:` or `ubi:` build would show only one of them under
`mise ls <name>` even though both were on PATH. Spelling out a backend
(e.g. `mise ls ubi:jqlang/jq`) still narrows to that single backend.
([#​11822](https://redirect.github.com/jdx/mise/pull/11822) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **install:** `mise install --force` now works without tool arguments,
reinstalling every configured, OS-supported tool (or the monorepo union
with `--monorepo`).
([#​11802](https://redirect.github.com/jdx/mise/pull/11802) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **upgrade:** add an `upgrade.auto_prune` setting (default `true`) that
controls whether `mise upgrade` removes the version it replaced, plus a
`--prune` flag to force removal on for a single run when the setting is
off. Useful when a mise-managed interpreter backs a virtualenv you do
not want deleted on unattended upgrades.
([#​11788](https://redirect.github.com/jdx/mise/pull/11788) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
```toml
[settings]
upgrade.auto_prune = false
```
- **bootstrap:** `mise bootstrap packages prune --manager brew-cask` can
now conservatively remove mise-owned Homebrew casks that are no longer
declared in `[bootstrap.packages]`. Removal is gated by install-time
receipt metadata, fingerprint checks, and ownership validation, and
Homebrew-owned, pkg, lifecycle, drifted, or shared casks are skipped
with an explicit reason.
([#​11810](https://redirect.github.com/jdx/mise/pull/11810) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** `[bootstrap.packages]` entries can now use table form
with a `version` and `[tools]`-style `os` selectors, so a single config
can target macOS-only casks and Linux fonts. Platform-incompatible
packages surface as unavailable in status output instead of aborting the
run, while explicit requests for unsupported packages still error.
([#​11809](https://redirect.github.com/jdx/mise/pull/11809) by
[@​jdx](https://redirect.github.com/jdx))
- **brew:** the `brew-cask` manager now supports installing font casks
directly from git URLs, including selecting a branch and staging files
from a subdirectory.
([#​11781](https://redirect.github.com/jdx/mise/pull/11781) by
[@​roele](https://redirect.github.com/roele))
- **aqua:** relative `aqua.registries` entries in a config file are now
resolved against that config's root, so a `registry.yaml` committed
inside a project repository can be referenced without a machine-specific
absolute path.
([#​11804](https://redirect.github.com/jdx/mise/pull/11804) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
```toml
[settings]
aqua.registries = ["registry.yaml"]
```
- **spm:** `spm:` installs can now be pinned to a commit via
`rev:<commit>` (and compatible `ref:<commit>`), building from source.
([#​11815](https://redirect.github.com/jdx/mise/pull/11815) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **generate:** generated git hooks can now carry extra mise flags.
Anything after `--` is inserted between `mise` and `run`, so a hook can
target config in a subdirectory or set other global flags.
([#​11820](https://redirect.github.com/jdx/mise/pull/11820) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
```bash
mise generate git-pre-commit --task lint -- -C subdir -E ci
```
#### Fixed
- **watch:** `mise watch` with no task name now runs the `default` task,
matching `mise run`, instead of failing with "No tasks specified".
([#​11836](https://redirect.github.com/jdx/mise/pull/11836) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **activate:** `--silent` and `--log-level` are now forwarded into the
generated activation hook, so per-directory `hook-env` output can
actually be silenced.
([#​11831](https://redirect.github.com/jdx/mise/pull/11831) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **sops:** SOPS files decrypted through the external `sops` CLI
(`sops.rops = false`) are no longer skipped when no age key is present,
so KMS, Vault, PGP, and other key services work in non-strict mode.
([#​11834](https://redirect.github.com/jdx/mise/pull/11834) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **conda:** on Windows, dependency DLLs are now placed beside the
binaries in `.mise-bins`, fixing tools such as `conda:postgresql` and
`conda:zstd` that previously failed to start with a missing-DLL error.
([#​11825](https://redirect.github.com/jdx/mise/pull/11825) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **ruby:** on Windows, mise now installs the highest RubyInstaller2
build revision (`-2`, `-3`, …) instead of always using the superseded
`-1` build.
([#​11807](https://redirect.github.com/jdx/mise/pull/11807) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **rust:** concurrent toolchain installs are now serialized to avoid
conflicts, and Rust homes are resolved from the config environment.
([#​11794](https://redirect.github.com/jdx/mise/pull/11794),
[#​11798](https://redirect.github.com/jdx/mise/pull/11798) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **task:** Azure DevOps remote git includes are now handled correctly.
([#​11768](https://redirect.github.com/jdx/mise/pull/11768) by
[@​cheesemans](https://redirect.github.com/cheesemans))
- **task:** project-qualified monorepo tasks now match without requiring
the leading `//`.
([#​11782](https://redirect.github.com/jdx/mise/pull/11782) by
[@​williamsjokvist](https://redirect.github.com/williamsjokvist))
- **task:** incomplete task outputs are now detected, and task arguments
are validated before dependencies run.
([#​11786](https://redirect.github.com/jdx/mise/pull/11786),
[#​11787](https://redirect.github.com/jdx/mise/pull/11787) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **hooks:** hook arrays are now parsed before run tables, fixing
certain hook configurations.
([#​11792](https://redirect.github.com/jdx/mise/pull/11792) by
[@​jgillich](https://redirect.github.com/jgillich))
- **vfox:** a non-table hook response now returns an error instead of
panicking, and URL replacements are honored.
([#​11793](https://redirect.github.com/jdx/mise/pull/11793) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562),
[#​11795](https://redirect.github.com/jdx/mise/pull/11795) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **aqua:** package metadata is now looked up by aqua package name, and
version bounds with four components and the `!=` operator are accepted.
([#​11828](https://redirect.github.com/jdx/mise/pull/11828),
[#​11832](https://redirect.github.com/jdx/mise/pull/11832) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **generate:** generated git hooks forward hook arguments, and nested
task stub conflicts are handled.
([#​11801](https://redirect.github.com/jdx/mise/pull/11801) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562),
[#​11800](https://redirect.github.com/jdx/mise/pull/11800) by
[@​Marukome0743](https://redirect.github.com/Marukome0743))
- **config:** dropped the `--file` alias where `-f` means `--force`, and
`ignored_config_paths` now matches on Windows.
([#​11789](https://redirect.github.com/jdx/mise/pull/11789),
[#​11818](https://redirect.github.com/jdx/mise/pull/11818) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **settings:** config-file writes are now refused for env-only
settings, list settings no longer panic when set from the environment,
and the `go.set_gopath` deprecation message is corrected.
([#​11791](https://redirect.github.com/jdx/mise/pull/11791),
[#​11799](https://redirect.github.com/jdx/mise/pull/11799) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562),
[#​11835](https://redirect.github.com/jdx/mise/pull/11835) by
[@​jdx](https://redirect.github.com/jdx))
- **exec:** resolution failures now name installed-but-inactive tools to
point you at the fix.
([#​11803](https://redirect.github.com/jdx/mise/pull/11803) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **go:** `go list` diagnostics are kept out of default output.
([#​11816](https://redirect.github.com/jdx/mise/pull/11816) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **tera:** the `pat` argument is honored on v1 `trim_start`/`trim_end`.
([#​11811](https://redirect.github.com/jdx/mise/pull/11811) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **link:** install path aliases are now rejected.
([#​11785](https://redirect.github.com/jdx/mise/pull/11785) by
[@​NgoQuocViet2001](https://redirect.github.com/NgoQuocViet2001))
- **cli:** the base of `sub-N:` version prefixes is resolved before
subtracting.
([#​11796](https://redirect.github.com/jdx/mise/pull/11796) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
- **core:** zero jobs is now treated as one, and forced colors are
honored in tables.
([#​11790](https://redirect.github.com/jdx/mise/pull/11790) by
[@​Marukome0743](https://redirect.github.com/Marukome0743),
[#​11847](https://redirect.github.com/jdx/mise/pull/11847) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** compose is now planned before dependency installation.
([#​11829](https://redirect.github.com/jdx/mise/pull/11829) by
[@​jdx](https://redirect.github.com/jdx))
- **registry:** flutter URLs no longer double the `-stable` suffix.
([#​11808](https://redirect.github.com/jdx/mise/pull/11808) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562))
#### Documentation
- Clarified what the not-found handler can install
([#​11830](https://redirect.github.com/jdx/mise/pull/11830) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562)),
what libc detection actually does
([#​11813](https://redirect.github.com/jdx/mise/pull/11813) by
[@​JamBalaya56562](https://redirect.github.com/JamBalaya56562)),
and `task_config.shell` in the `task.shell` defaults
([#​11775](https://redirect.github.com/jdx/mise/pull/11775) by
[@​pynappo](https://redirect.github.com/pynappo)).
- Linked the Homebrew cask cookbook for cask lifecycle concepts
([#​11773](https://redirect.github.com/jdx/mise/pull/11773) by
[@​himkt](https://redirect.github.com/himkt)) and fixed dead
bootstrap package-plugin example URLs
([#​11780](https://redirect.github.com/jdx/mise/pull/11780) by
[@​Bartok9](https://redirect.github.com/Bartok9)).
#### Registry
- Added android-cli
([#​11797](https://redirect.github.com/jdx/mise/pull/11797) by
[@​ggoggam](https://redirect.github.com/ggoggam)) and zk
([#​11827](https://redirect.github.com/jdx/mise/pull/11827) by
[@​laraochan](https://redirect.github.com/laraochan)).
#### New Contributors
- [@​laraochan](https://redirect.github.com/laraochan) made their
first contribution in
[#​11827](https://redirect.github.com/jdx/mise/pull/11827)
- [@​williamsjokvist](https://redirect.github.com/williamsjokvist)
made their first contribution in
[#​11782](https://redirect.github.com/jdx/mise/pull/11782)
- [@​NgoQuocViet2001](https://redirect.github.com/NgoQuocViet2001)
made their first contribution in
[#​11785](https://redirect.github.com/jdx/mise/pull/11785)
- [@​jgillich](https://redirect.github.com/jgillich) made their
first contribution in
[#​11792](https://redirect.github.com/jdx/mise/pull/11792)
- [@​pynappo](https://redirect.github.com/pynappo) made their
first contribution in
[#​11775](https://redirect.github.com/jdx/mise/pull/11775)
- [@​cheesemans](https://redirect.github.com/cheesemans) made
their first contribution in
[#​11768](https://redirect.github.com/jdx/mise/pull/11768)
**Full Changelog**:
<https://github.com/jdx/mise/compare/v2026.8.3...v2026.8.4>
#### 💚 Sponsor mise
mise is maintained by [@​jdx](https://redirect.github.com/jdx), an
open source developer for [**entire.io**](https://entire.io), the title
sponsor of the [jdx.dev](https://jdx.dev) open source tools. Development
is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at
[jdx.dev](https://jdx.dev/sponsors.html). Individual and company
sponsorships keep mise fast, free, and independent.
###
[`v2026.8.3`](https://redirect.github.com/jdx/mise/releases/tag/v2026.8.3):
: Flatpak, Font Casks, and Task Precedence Fixes
[Compare
Source](https://redirect.github.com/jdx/mise/compare/mise-cache-rustc-v2026.8.2...mise-interactive-config-v2026.8.3)
This release expands bootstrap package management with per-user Flatpak
support and Linux font casks, adds a per-tool pipx registry option and a
shim safety setting, and lands a batch of task precedence, lockfile, and
Python fixes.
##### Added
- **bootstrap:** manage per-user Flatpak installations with a new
`flatpak-user` package manager. The existing `flatpak:<id>` entries stay
system-scoped, and you can now declare both scopes in the same config,
including the same application ID.
([#​11757](https://redirect.github.com/jdx/mise/pull/11757) by
[@​jdx](https://redirect.github.com/jdx))
- **brew:** the built-in `brew-cask` manager now works on Linux for
font-only casks, installing fonts under `$XDG_DATA_HOME/fonts` via
Linuxbrew. Non-font casks on Linux fail with a clear
unsupported-platform error.
([#​11758](https://redirect.github.com/jdx/mise/pull/11758) by
[@​jdx](https://redirect.github.com/jdx))
```bash
mise bootstrap packages use brew-cask:font-heavy-data-nerd-font
```
- **pipx:** add a per-tool `registry_url` option so version listing and
`latest` resolution can target a private PyPI-style index without
changing the global `pipx.registry_url`. The latest-version cache is
keyed by registry URL to avoid cross-registry reuse.
([#​11754](https://redirect.github.com/jdx/mise/pull/11754) by
[@​jdx](https://redirect.github.com/jdx))
- **shim:** add a `not_found_system_fallback` setting
(`MISE_NOT_FOUND_SYSTEM_FALLBACK`, default `true`). Setting it to
`false` prevents a shim for a missing tool from silently falling back to
a same-named binary on `PATH`, failing loudly instead — useful for
hardened environments that pin an explicit allowlist of tools.
([#​11755](https://redirect.github.com/jdx/mise/pull/11755) by
[@​richid](https://redirect.github.com/richid))
##### Fixed
- **task:** inline `[tasks.<name>]` definitions now take precedence over
a same-named task from an included TOML file instead of being silently
discarded. Metadata-only inline blocks overlay the included command
rather than replacing it.
([#​11734](https://redirect.github.com/jdx/mise/pull/11734) by
[@​jdx](https://redirect.github.com/jdx))
- **task:** a metadata-only inline task in a higher-precedence file such
as `mise.local.toml` now overlays the command-bearing definition from a
lower file instead of wiping out its `run`. Command-bearing
higher-precedence tasks still fully replace the lower one.
([#​11745](https://redirect.github.com/jdx/mise/pull/11745) by
[@​jdx](https://redirect.github.com/jdx))
- **task:** tasks declaring `double_dash="required"` again accept values
passed after `--`, which had regressed to being rejected.
([#​11729](https://redirect.github.com/jdx/mise/pull/11729) by
[@​jdx](https://redirect.github.com/jdx))
- **config:** configured backend options such as `postinstall` are now
applied to explicitly requested runtime versions (e.g. `mise install
solidity@0.8.2`) that carry registry defaults, instead of being skipped.
([#​11550](https://redirect.github.com/jdx/mise/pull/11550) by
[@​risu729](https://redirect.github.com/risu729))
- **lockfile:** setting `lockfile = true` now creates missing project
lockfiles during `mise use`, `mise install`, and upgrade flows. An unset
setting continues to update existing lockfiles only.
([#​11746](https://redirect.github.com/jdx/mise/pull/11746) by
[@​jdx](https://redirect.github.com/jdx))
- **python:** a plain `mise lock` now preserves the
python-build-standalone artifact already recorded for each platform
instead of churning the lockfile to the newest build. Use `mise lock
--bump` to advance the PBS build explicitly.
([#​11747](https://redirect.github.com/jdx/mise/pull/11747) by
[@​jdx](https://redirect.github.com/jdx))
- **python:** skip junctions when syncing installs to uv to avoid errors
on Windows.
([#​11683](https://redirect.github.com/jdx/mise/pull/11683) by
[@​risu729](https://redirect.github.com/risu729))
- **github:** release-age filters like `minimum_release_age` now use
GitHub's `published_at` timestamp rather than the commit `created_at`,
so a newly published release pointing at an older commit no longer
bypasses the filter. Applies across Aqua, GitHub, Ubi, SPM, Pipx, and
GitHub-backed core tools.
([#​11756](https://redirect.github.com/jdx/mise/pull/11756) by
[@​jdx](https://redirect.github.com/jdx))
- **use:** adding multiple tools in a single `mise use` now keeps an
already-sorted `[tools]` table alphabetically ordered.
([#​11713](https://redirect.github.com/jdx/mise/pull/11713) by
[@​jdx](https://redirect.github.com/jdx))
- **rust:** expand `~` in the `home` setting.
([#​11752](https://redirect.github.com/jdx/mise/pull/11752) by
[@​xqm32](https://redirect.github.com/xqm32))
- **vfox:** resolve backend aliases for custom plugins.
([#​11736](https://redirect.github.com/jdx/mise/pull/11736) by
[@​jdx](https://redirect.github.com/jdx))
- **vfox:** cancel in-flight HTTP retries when interrupted with Ctrl-C.
([#​11735](https://redirect.github.com/jdx/mise/pull/11735) by
[@​jdx](https://redirect.github.com/jdx))
- **npm shim:** `npm link <package-name>` (and its `npm ln` alias) now
triggers an auto-reshim, since it installs a package globally.
([#​11748](https://redirect.github.com/jdx/mise/pull/11748) by
[@​cheezmil](https://redirect.github.com/cheezmil))
- **ls-remote:** suppress the `minimum_release_age` warning during shell
completions.
([#​11727](https://redirect.github.com/jdx/mise/pull/11727) by
[@​beisenherz](https://redirect.github.com/beisenherz))
- **docs:** fix an incorrect ripgrep URL in the tool-stub docs.
([#​11725](https://redirect.github.com/jdx/mise/pull/11725) by
[@​arti5an](https://redirect.github.com/arti5an))
##### New Contributors
- [@​richid](https://redirect.github.com/richid) made their first
contribution in
[#​11755](https://redirect.github.com/jdx/mise/pull/11755)
- [@​xqm32](https://redirect.github.com/xqm32) made their first
contribution in
[#​11752](https://redirect.github.com/jdx/mise/pull/11752)
- [@​cheezmil](https://redirect.github.com/cheezmil) made their
first contribution in
[#​11748](https://redirect.github.com/jdx/mise/pull/11748)
- [@​arti5an](https://redirect.github.com/arti5an) made their
first contribution in
[#​11725](https://redirect.github.com/jdx/mise/pull/11725)
- [@​beisenherz](https://redirect.github.com/beisenherz) made
their first contribution in
[#​11727](https://redirect.github.com/jdx/mise/pull/11727)
**Full Changelog**:
<https://github.com/jdx/mise/compare/v2026.8.2...v2026.8.3>
##### 💚 Sponsor mise
mise is maintained by [@​jdx](https://redirect.github.com/jdx), an
open source developer for [**entire.io**](https://entire.io), the title
sponsor of the [jdx.dev](https://jdx.dev) open source tools. Development
is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at
[jdx.dev](https://jdx.dev/sponsors.html). Individual and company
sponsorships keep mise fast, free, and independent.
###
[`v2026.8.2`](https://redirect.github.com/jdx/mise/releases/tag/v2026.8.2):
: Declarative System Bootstrap
[Compare
Source](https://redirect.github.com/jdx/mise/compare/mise-cache-rustc-v2026.8.1...mise-cache-rustc-v2026.8.2)
This release turns `mise bootstrap` into a full declarative
host-provisioning system: alongside packages, mise can now converge
privileged files, Linux users and groups, systemd services, Docker
Compose projects, and firewall rules — all with plan/apply/status
workflows, secret handling, and the ability to run over SSH against
remote hosts. It also makes Ruby's `ruby.compile=false` a strict
precompiled-only mode and lands a batch of install and lockfile fixes.
#### Highlights
- `mise bootstrap` gains a Terraform-style declarative model. A new
`mise bootstrap plan` previews changes with table or JSON output and
detailed exit codes, and each resource type has its own `apply`/`status`
commands that converge only when something actually differs.
- Bootstrap can now provision far more than tools and packages:
privileged files and directories, Linux accounts, systemd services,
Compose projects, and host firewall rules, with dependency ordering,
fail-closed safety checks, and secret inputs sourced from environment
variables (never stored in config).
- The same bootstrap project can be applied to remote machines over SSH
via `mise bootstrap remote`, including automatic detection of the
target's OS/arch/libc and signature-verified download of the matching
mise binary.
#### Added
- **bootstrap:** declarative resource plans. `mise bootstrap plan`
previews what bootstrap would change before applying, with table or
`--json` output and optional `--detailed-exitcode` (0 = no changes, 2 =
changes, 1 = error). Resources have stable identities, dependency
graphs, and validation for duplicates, missing dependencies, and cycles.
([#​11669](https://redirect.github.com/jdx/mise/pull/11669) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** manage privileged files and directories via
`[bootstrap.files]` and `[bootstrap.directories]`, with content (inline
or from a source), ownership, mode, and explicit `present`/`absent`
state. Writes are atomic, removal is opt-in (and requires `recursive =
true` for non-empty directories), and privileged work runs through
hidden helpers that never expose file content in argv or logs.
([#​11674](https://redirect.github.com/jdx/mise/pull/11674) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** secret inputs for managed files. `[bootstrap.secrets]`
references sensitive values through environment variables so nothing is
stored in config, and managed files with `template = true` can render
them via `{{ secret(name="...") }}`. `mise bootstrap secrets status`
reports availability without revealing values, and `--prompt-secrets`
prompts securely for anything missing.
([#​11680](https://redirect.github.com/jdx/mise/pull/11680) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** manage Linux users and groups via `[bootstrap.users]`
and `[bootstrap.groups]`, with create/update/remove, supplementary
groups, home handling, and explicit `state = "absent"`. Accounts
converge before the files that reference them, and UID/GID collisions
fail closed.
([#​11681](https://redirect.github.com/jdx/mise/pull/11681) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** manage Linux systemd services via
`[bootstrap.services]` for running/stopped, enabled/disabled, and masked
state. Managed files and directories can set `notify` to trigger
`reload`, `restart`, or `reload_or_restart` handlers, but only after a
real file change.
([#​11688](https://redirect.github.com/jdx/mise/pull/11688) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** manage Docker Compose projects via
`[bootstrap.compose]` for running, stopped, and absent states, with
pull/build/recreate/wait policies, one-shot services,
orphan/volume/image removal, and explicit dependencies. Convergence
compares live container runtime and health to the rendered Compose model
(Compose v2 only).
([#​11689](https://redirect.github.com/jdx/mise/pull/11689) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** manage Linux host firewall rules via
`[bootstrap.linux.firewall]` with nftables, firewalld, and UFW backends
(`backend = "auto"`). Includes SSH-lockout protection (default-deny
requires a covering allow rule or `allow_lockout = true`), drift
detection, and preservation of undeclared rules unless `exclusive` is
set. ([#​11694](https://redirect.github.com/jdx/mise/pull/11694)
by [@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** run bootstrap over SSH with `mise bootstrap remote`,
targeting a named `[bootstrap.remote.hosts]` inventory or ad-hoc
`user@host` targets. mise archives and stages your project, provisions a
compatible mise binary on the host, runs bootstrap with forwarded flags,
and cleans up staging afterward.
([#​11690](https://redirect.github.com/jdx/mise/pull/11690) by
[@​jdx](https://redirect.github.com/jdx))
- **bootstrap:** remote provisioning now detects each target's OS,
architecture, and Linux libc (glibc vs musl) and, when the local binary
is not compatible, downloads the matching raw executable for the same
release from GitHub with minisign-verified checksums. Custom or debug
builds fail closed and require an explicit `mise_bin`, `remote_mise`, or
`bootstrap_command`.
([#​11693](https://redirect.github.com/jdx/mise/pull/11693) by
[@​jdx](https://redirect.github.com/jdx))
#### Changed
- **ruby:** `ruby.compile = false` is now a strict precompiled-only
mode, matching `python.compile`. Installs error with `no precompiled
ruby found` instead of silently falling back to ruby-build, and version
listings (`mise ls-remote ruby`, fuzzy resolution) are filtered to
versions that actually have a precompiled binary for your platform.
Previously `false` was a no-op after precompiled binaries became the
default in 2026.8.0. Unset and `compile = true` are unchanged; Windows
is unaffected.
([#​11710](https://redirect.github.com/jdx/mise/pull/11710) by
[@​jdx](https://redirect.github.com/jdx))
- **task:** workspace task inference is now opt-in per provider via
`task.auto_infer` (e.g. `task.auto_infer = ["node"]`) instead of running
whenever experimental features are enabled. Explicit mise tasks always
take precedence over inferred package scripts on name and alias
collisions.
([#​11706](https://redirect.github.com/jdx/mise/pull/11706) by
[@​jdx](https://redirect.github.com/jdx))
#### Fixed
- **brew:** `:any_skip_relocation` bottles no longer leave unresolved
`@@HOMEBREW_*@@` placeholders in scripts and config files. That tag now
only skips binary linkage relocation while text placeholders are still
replaced.
([#​11665](https://redirect.github.com/jdx/mise/pull/11665) by
[@​jdx](https://redirect.github.com/jdx))
- **brew-cask:** detect extensionless DMG downloads (such as Raycast) by
their UDIF trailer instead of treating them as raw executables and
failing to find the app bundle.
([#​11692](https://redirect.github.com/jdx/mise/pull/11692) by
[@​jacobbednarz](https://redirect.github.com/jacobbednarz))
- **lock:** `mise lock --bump` now errors instead of writing an
incomplete lockfile when a version bump would drop platform coverage
that the previous locked version had. Best-effort skips are retained for
platforms a tool never supported.
([#​11664](https://redirect.github.com/jdx/mise/pull/11664) by
[@​jdx](https://redirect.github.com/jdx))
- **pipx:** release-age gating now uses PyPI's precise RFC3339
`upload_time_iso_8601` timestamp instead of the timezone-naive
`upload_time`, which previously made freshly released packages appear up
to \~24h younger and over-gated them under `minimum_release_age`.
([#​11662](https://redirect.github.com/jdx/mise/pull/11662) by
[@​Guria](https://redirect.github.com/Guria))
- **pacman:** `pacman -Q` is now parsed under `LC_ALL=C` so
missing-package detection works in non-English locales; previously
`[bootstrap.packages]` could bail on a translated "was not found"
message.
([#​11673](https://redirect.github.com/jdx/mise/pull/11673) by
[@​rarandeyo](https://redirect.github.com/rarandeyo))
- **sync:** clear stale `incomplete` markers when an external link (from
uv, nvm, pyenv, nodenv, or Homebrew) is confirmed healthy, so `mise
where` no longer treats a working external version as incomplete after
an interrupted install.
([#​11172](https://redirect.github.com/jdx/mise/pull/11172) by
[@​risu729](https://redirect.github.com/risu729))
- **completions:** an explicit `--` no longer hijacks task argument
completion after usage v5. `mise run <task> -- <TAB>` again offers the
task's declared choices instead of falling back to filenames, while
still forwarding extra arguments.
([#​11711](https://redirect.github.com/jdx/mise/pull/11711) by
[@​jdx](https://redirect.github.com/jdx))
- **registry:** shim auto-install uses new declared `bins` metadata to
pick the correct provider before falling back to incidental executables,
fixing cases where invoking the `npm` shim could run Node's bundled npm
instead of the configured npm version.
([#​11666](https://redirect.github.com/jdx/mise/pull/11666),
[#​11671](https://redirect.github.com/jdx/mise/pull/11671),
[#​11676](https://redirect.github.com/jdx/mise/pull/11676),
[#​11677](https://redirect.github.com/jdx/mise/pull/11677),
[#​11678](https://redirect.github.com/jdx/mise/pull/11678) by
[@​jdx](https://redirect.github.com/jdx))
#### New Contributors
- [@​jacobbednarz](https://redirect.github.com/jacobbednarz) made
their first contribution in
[#​11692](https://redirect.github.com/jdx/mise/pull/11692)
- [@​rarandeyo](https://redirect.github.com/rarandeyo) made their
first contribution in
[#​11673](https://redirect.github.com/jdx/mise/pull/11673)
**Full Changelog**:
<https://github.com/jdx/mise/compare/v2026.8.1...v2026.8.2>
#### 💚 Sponsor mise
mise is maintained by [@​jdx](https://redirect.github.com/jdx), an
open source developer for [**entire.io**](https://entire.io), the title
sponsor of the [jdx.dev](https://jdx.dev) open source tools. Development
is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at
[jdx.dev](https://jdx.dev/sponsors.html). Individual and company
sponsorships keep mise fast, free, and independent.
###
[`v2026.8.1`](https://redirect.github.com/jdx/mise/releases/tag/v2026.8.1):
: Task Cache Goes Remote, Affected Tasks, and Config Ergonomics
[Compare
Source](https://redirect.github.com/jdx/mise/compare/mise-cache-rustc-v2026.8.0...mise-cache-rustc-v2026.8.1)
This release rounds out mise's experimental task artifact cache with
size/age limits, inspection tooling, and a full local-plus-remote cache
backend (including authenticated CI caching), adds experimental `mise
run --affected` for monorepos, and lands a batch of config, upgrade, and
install fixes.
#### Highlights
- The experimental task output cache now supports remote sharing: a
composite store reads locally first, promotes remote hits, and mirrors
writes, with authenticated requests backed by token files or GitHub
Actions OIDC. Cache entries can be inspected, cleared per-task, and
bounded by size and age.
- Experimental `mise run --affected` runs only the tasks in monorepo
projects touched by your Git changes, using workspace dependency graphs,
global task inputs, and provider lockfile attribution to decide what is
affected.
- The config-writing flags are now more forgiving: `--file` and `--path`
are interchangeable across the commands that write config, so you no
longer have to remember which name each subcommand expects.
#### Added
- **task:** experimental `mise run --affected` selects and runs only the
tasks in projects affected by Git changes, combining the workspace
dependency graph, `global_inputs`, and provider lockfile diffs. Base and
head revisions can be overridden with
`--affected-base`/`--affected-head` or `MISE_AFFECTED_*`. Includes JSON
output and an `--explain` breakdown of why each task was selected.
([#​11590](https://redirect.github.com/jdx/mise/pull/11590),
[#​11587](https://redirect.github.com/jdx/mise/pull/11587),
[#​11589](https://redirect.github.com/jdx/mise/pull/11589),
[#​11591](https://redirect.github.com/jdx/mise/pull/11591),
[#​11593](https://redirect.github.com/jdx/mise/pull/11593) by
[@​jdx](https://redirect.github.com/jdx))
```bash
mise run --affected test
mise run --affected --affected-base main test
```
- **task:** remote task cache. A composite store layers local and remote
backends, reading local first and promoting remote hits, then committing
locally be
> ✂ **Note**
>
> PR body was truncated to here.
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- "before 4am on Monday"
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4yOS41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
---------
Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
## Summary - use the released Flint 0.22.10 Checkstyle implementation - add Checkstyle 13.8.0 as the direct `checkstyle` mise entry - update CI to mise 2026.7.15 so that direct registry entry is available in every workflow - allow the verified `@yarnpkg/libzip` 3.2.2 release for Renovate because it was published without provenance - remove the Maven Checkstyle plugin and its obsolete skip settings so Checkstyle runs only once, through Flint - preserve the repository's previous main-source scope with narrow suppressions for test and archived Java sources - suppress `VariableDeclarationUsageDistance` for examples, where setup declarations intentionally precede simulated work Flint Checkstyle support is released in [v0.22.10](https://github.com/grafana/flint/releases/tag/v0.22.10), and this PR uses the standard `aqua:grafana/flint` backend for Flint itself. ## Testing - `mise exec -- flint run --full checkstyle` - `mise run lint:fix` - `mise run build` --------- Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
…pendencies to v7.6.0 (prometheus#2386) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [org.mock-server:mockserver-netty-no-dependencies](https://www.mock-server.com) ([source](https://redirect.github.com/mock-server/mockserver-monorepo)) | `7.5.0` → `7.6.0` |  |  | --- ### Release Notes <details> <summary>mock-server/mockserver-monorepo (org.mock-server:mockserver-netty-no-dependencies)</summary> ### [`v7.6.0`](https://redirect.github.com/mock-server/mockserver-monorepo/blob/HEAD/changelog.md#760---2026-08-17) ##### Changed - The three Kubernetes container-integration cases that need Java-built images — `helm_sidecar_injection` (admission-webhook sidecar injection), `helm_clustered_convergence`, and `helm_jgroups_dns_ping` (both the `-clustered` Infinispan image) — now run **blocking in CI** instead of recording a skip. Previously the CI helm step ran with no JDK and never built those images, so all three recorded an honest but permanent SKIP — coverage that looked green while proving nothing. A new `:maven: build container-test images (jars)` step in the `mockserver-container-tests` pipeline builds the `mockserver-netty`, `mockserver-k8s-webhook`, and `mockserver-state-infinispan` jars **from the tree** (once, via the Maven-in-Docker reactor) and hands them to the helm step as Buildkite artifacts; the helm step downloads them and does cheap `docker build`s (a COPY into distroless) to produce the `-clustered` and `mockserver-webhook` images, then runs the suite. The jars travel as artifacts (\~200 MB total) rather than `docker save`d images (\~1.3 GB), mirroring the node-launcher / WAR hand-off. Both layers **fail closed**: the helm step exits non-zero if any jar artifact is absent, and the harness runs with `REQUIRE_CLUSTERED_IMAGE=true`/`REQUIRE_WEBHOOK_IMAGE=true` so an image that is expected-but-absent is recorded as a **FAILURE**, never a skip — a skip in CI is now impossible. Local `container_integration_tests/integration_tests.sh` is unchanged for a developer without the images: it still records a comprehensible SKIP (no fail-closed flag set), and the harness now also builds the `mockserver-webhook` image locally (`build_webhook_docker`) so the sidecar case runs blocking in local dev too — it was never built by the harness before, so that case had always skipped. ##### Added - Two new rules in the always-on `check-false-green-guards.sh` CI gate. **Rule 4** fails the build if a CI step runs the container-integration harness with the helm/k3d cases active but does not export both `REQUIRE_CLUSTERED_IMAGE=true` and `REQUIRE_WEBHOOK_IMAGE=true` — the exact way the three image-dependent Kubernetes cases could silently revert to a green SKIP. It is keyed on the step's *behaviour* (invokes `integration_tests.sh` without `SKIP_HELM_TESTS=true`), not on a filename, so a rename or a second helm-running step is covered automatically. **Rule 5** fails the build if a `mockserver-core` test that performs a JVM-global logging side effect (reaching `LogManager.readConfiguration`'s handler `reset()` via the static `ConfigurationProperties` logging setters or a forced fresh `<clinit>`) is not in the `sequential-tests` include list — the shape behind a release-blocking flake that `ParallelStaticStateGuardTest` structurally cannot catch. Both rules fail closed on an empty corpus and carry a rotating allow-list. See [docs/operations/false-green-guards.md](docs/operations/false-green-guards.md). - A `jarPath` launcher option and matching `MOCKSERVER_JAR_PATH` environment variable for `mockserver-node`, pointing `start_mockserver` at a pre-provisioned `mockserver-netty` jar-with-dependencies instead of downloading one from Maven Central. When set, that exact jar is launched and no download is attempted; a configured-but-missing path is a **hard error** (`... refusing to fall back to downloading a release`) rather than a silent fall-back to a released jar, so a missing artifact fails loudly. Mirrors the existing `MOCKSERVER_BINARY_BASE_URL` bring-your-own-artifact path for the standalone binary, and serves air-gapped/corporate installs as well as testing a locally-built jar (`jarPath` takes precedence over `mockServerVersion`/`artifactory*`; the option beats the env var). The Node launcher integration tests now use it in CI: a new `:maven: build node launcher jar` step builds the jar **from the tree** and the launcher-test step downloads it as an artifact and launches it via `MOCKSERVER_JAR_PATH` — so the suite finally tests the repo's own code instead of the last release. Previously it ran a downloaded release chosen by `package.json`'s version, so a `mockserver-core` fix could not green it and a regression could not red it; that released jar also carried the shipped dynamic-CA generation race (fixed on master in `4cff56e61`) and flaked \~8% of runs. The launcher step **fails closed** if the tree-built jar is absent rather than reverting to a download, and local `npm test` outside CI is unchanged (with neither the option nor the env var set it still downloads as before). - A structural wire-contract test for the LLM provider codecs (`LlmCodecStructuralContractTest`), breaking the self-derivation weakness in the golden-file drift test. `LlmCodecGoldenFileTest` regenerates its golden **bodies** from the codec itself (`-Dmockserver.updateLlmGoldens=true`), so a structural codec defect — a renamed field, a wrong SSE event name, a dropped `finish_reason` — bakes straight into its own golden and the byte-for-byte drift test then passes forever, confirming only that the codec is consistent with itself (token *counts* were already pinned separately by `shouldEncodeCanonicalTokenUsageCounts`; the bodies were not). The new test asserts the live codec output against **hand-authored expectations taken from each provider's published API schema** — required fields, JSON types, the enum discriminators each provider uses (`object`/`type`/`finish_reason`/`stop_reason`/ `finishReason`/`status`/`done`), the tool-call envelope shape (arguments as a JSON *string* for OpenAI/Responses vs a structured *object* for Anthropic/Gemini/Ollama), and the exact SSE event-name sequence for the event-typed providers — across all seven chat/completion providers (Azure and Bedrock via their delegate codecs). Crucially it **never reads the golden files and is unaffected by `-Dmockserver.updateLlmGoldens=true`**, so regenerating goldens cannot silence it. Each named defect class was injected into a codec and confirmed to turn the test red without regenerating goldens (OpenAI renamed `finish_reason`; Anthropic SSE `content_block_delta`→`content_delta`; Gemini dropped `finishReason`; Responses renamed `status`; Ollama renamed terminal `done`), then reverted. Residual streaming-over-the-wire behaviour remains covered by `LlmAgentLoopE2eTest`. - Endpoint-level test (`HttpStateCassetteEndpointTest`) and an authoritative `CassetteRegistry` javadoc note pinning the settled decision that **loading and recording register a cassette automatically**. The `record_llm_fixtures` and `load_expectations_from_file` MCP tools already auto-register the fixture in the process-wide `CassetteRegistry` (keyed by file path, origin `recorded`/`loaded`, upserting on re-load/re-record) so it surfaces under `GET /mockserver/cassettes` and in the dashboard's Cassettes tab without a manual `PUT /mockserver/cassettes` — but nothing pinned that a so-registered cassette is actually retrievable *through the GET endpoint*, and the registration policy lived only in the two MCP callers, inviting the question to be re-opened. The new test drives `GET /mockserver/cassettes` (and the bare `/cassettes` alias) against a registry populated the way the load/record handlers populate it and asserts the documented body shape (path, derived filename, expectation count, origin, lastUsed), that record-then-load on one path yields a single upserted entry, and that a server reset clears it. The MCP tools and consumer docs (`ai_mcp_tools.html`) already stated this behaviour; both are now clarified to say the fixture is registered automatically. This closes the "CassetteRegistry auto-population" product-decision item by recording the decision in code, docs, and a test rather than leaving it to resurface. - Compile gates for the dashboard composer's generated client code in Python, Ruby, Go and Rust (`.buildkite/scripts/steps/ui-client-codegen-compile.sh`, wired into `pipeline-ui.yml`), closing the gap where five of the composer's seven languages had no compile check — only Java (`ui-java-codegen-compile.sh`) and C# (`ComposerCodegenEquivalenceTests.cs`) were gated, so an emitter bug or a client-API rename would ship broken generated code to users caught by nothing (the existing per-language tests only string/byte-compare the emitter output, never feed it to a compiler). Each gate drives the shared representative composer matrix (`extractParityCases.ts` — the exact `combos` the byte-identity parity tests use) through that language's emitter and runs the lightest credible toolchain check: `python -m py_compile` and `ruby -c` catch any emitter bug that produces malformed source (the strongest static check for a dynamically-typed client with no shipped type stubs), while **Go** (`go build`/`go vet ./...`) and **Rust** (`cargo check`) compile the generated code against the real in-repo `mockserver-client-go` / `mockserver-client-rust`, so a renamed client method fails the build — the direct analog of the Java `javac` gate. Node was already covered: the `tsc` type-proof in `node.test.ts` (`typecheck-node-codegen.mjs`) runs under `npm test`, so the orphaned-script concern was already resolved by that test. All four new gates are proven to go red (emitter drift → non-zero exit) and green. Each phase runs in its toolchain's Docker image via `run-in-docker.sh`; set `CODEGEN_COMPILE_USE_DOCKER=false` for host validation. - Config-to-client wiring tests for the GCS and Azure blob-store backends (`GcsBlobStoreRegistrarConfigWiringTest`, `AzureBlobStoreRegistrarConfigWiringTest`), closing the gap where only S3 (`S3BlobStoreRegistrarConfigWiringTest`) proved that `blobStoreType` configuration is turned into a working client. The GCS and Azure contract tests hand-build their clients (`new GcsBlobStore(storage, …)`, `new AzureBlobStore(containerClient, …)`), so the registrar that reads the bucket/container name, endpoint, credentials and project from configuration and constructs the client was never exercised — a wiring bug there would ship silently because the contract tests bypass it. The new tests drive each registrar from configuration only (as production does) against the same Docker emulator the contract tests use (fake-gcs-server for GCS, Azurite `3.36.0 --skipApiVersionCheck` for Azure) and assert the wiring that can actually be got wrong: endpoint override, credentials, project id, and that a round-tripped object lands in the *configured* bucket/container under the *configured* key prefix — verified through an independent admin client so a mis-wired name cannot pass. Docker-gated via the canonical `DockerAvailability.isAvailable(...)` probe. - The Node and Python Testcontainers modules (`mockserver-testcontainers/node`, `mockserver-testcontainers/python`) now start a real MockServer container in CI and assert against it, closing a false-green gap where both published client libraries had jobs that passed having exercised nothing (`npm run test:unit` and `pytest -m "not docker"` both skipped the container). Their CI steps now mount the Docker socket, run the existing integration tests that start a `mockserver/mockserver` container and drive it over HTTP, and — mirroring the Go/.NET/Rust steps — fail closed by grepping for an evidence marker the test prints only after a real container answered `PUT /mockserver/status` with `200`. A skip (test filtered out, renamed, or Docker unusable) therefore fails the CI build loudly instead of reading as green, while the tests still degrade gracefully to a skip off-CI. - A GitHub Actions workflow (`.github/workflows/dependency-submission.yml`) now submits the resolved Maven dependency graph so Dependabot vulnerability **alerts** stay accurate for the monorepo layout. GitHub's managed Maven auto-submission only discovers a project at the repository root, so it silently stopped when the Java project moved into `mockserver/` — freezing the alerting graph at a pre-move snapshot that produced phantom Spring advisories and hid already-landed `log4j-api`/`jsoup` fixes. The workflow resolves and submits the `mockserver/` reactor (which includes `examples/java`) and the separate `mockserver-maven-plugin` build under distinct correlators, path-gated to `mockserver/**/pom.xml`. Dependabot's security-update pull requests were unaffected — they read manifests directly; it was only the alerting graph that had gone stale. - A CI guard (`.buildkite/scripts/steps/check-certificate-expiry.sh`, wired into the Java pipeline) now sweeps every committed certificate PEM and fails the build when any certificate is already expired or expires within 30 days, warning between 30 and 180 days. It checks every certificate in a chain file, allow-lists the one intentional expired test fixture while asserting it stays expired, and enforces two structural invariants that previously had no automation: every `leaf-cert.pem` must expire on or before its sibling `ca.pem`, and the shipped default CA files must stay in lockstep (the [PKCS#1](https://redirect.github.com/PKCS/mockserver-monorepo/issues/1) and [PKCS#8](https://redirect.github.com/PKCS/mockserver-monorepo/issues/8) CA private keys are the same key, that key matches the CA certificate, and the two committed copies of the CA certificate remain byte-identical). Certificate expiry had previously only ever been discovered by the build going red. - A standing CI guard (`check-false-green-guards.sh`) that fails closed when a new "false-green" test shape is introduced — a test or CI step that reports success while verifying nothing. The 2026-07-21 coverage audit named these shapes but they lived only in plan documents, and the repository then produced \~a dozen fresh instances in a single day. The guard enforces the three that can be pinned down precisely and each caused a real shipped false green: (1) every JUnit suite gated by `Assume.assumeTrue(DockerAvailability.isAvailable(...))` must be paired with `assert-suite-ran.sh` over its reports, or a broken Docker socket skips it while the build stays green; (2) no CI step may mount the Docker socket and then deselect the Docker-marked tests (e.g. `pytest -m "not docker"`), starting no container yet passing; (3) no container-integration `logTestSkip` may park deferred work ("CI wiring is a follow-up") as a green skip. It runs always-on (a new false green can enter from any of several pipelines) and carries a justified, self-verifying allow-list that fails if an entry no longer names what it claims. Wiring this up also closed a live gap it found — the `Gcs`/`Azure` `RegistrarConfigWiringTest` cloud suites ran under a Docker socket in CI but were not fail-closed-asserted. See `docs/operations/false-green-guards.md`. - A local-only, opt-in `K3D_LOCAL_CA_BUNDLE` hook in `container_integration_tests/helm-deploy.sh` so the Helm integration suite's k3d cluster can be stood up on a developer machine behind a corporate TLS-inspection proxy. When set, `start-up-k8s` overmounts the given **combined** CA bundle (system/public roots + corporate root) as the k3s node's containerd trust store at cluster-create time; when unset the `k3d cluster create` command is byte-identical to before, so CI (which never sets it) is unchanged. Warns rather than fails if the variable is set but the file is missing, mirroring `LOCAL_DOCKER_CA_BUNDLE` in `.buildkite/scripts/run-in-docker.sh`. This unblocks the three Kubernetes test-coverage gaps that were previously (and incorrectly) deferred as impossible behind the proxy: the host Docker daemon already trusts the corporate root so the node image pulls, but the *in-node* containerd has its own public-roots-only trust store and otherwise cannot pull even the `rancher/mirrored-pause` sandbox image (every pod fails sandbox creation with `x509: certificate signed by unknown authority`). See `docs/operations/build-system.md` → *Local Development Behind a Corporate TLS-Inspection Proxy*. - Two live Kubernetes container-integration tests that exercise admission-webhook and JGroups discovery paths which previously shipped unproven. `helm_sidecar_injection` deploys the chart with `webhook.enabled=true` (self-signed TLS bootstrap Jobs + webhook handler Deployment + `MutatingWebhookConfiguration`), drives a real labelled pod `CREATE` through the admission path, and asserts the resulting pod **spec** carries the injected `mockserver-sidecar` container, `mockserver-iptables-init` init container, and `mockserver.org/injected` annotation — with a negative-control pod (no opt-in annotation) that must **not** be injected, so a webhook that injects unconditionally fails the test. `helm_jgroups_dns_ping` deploys two clustered replicas and asserts the headless Service is truly headless (`clusterIP: None`), that `JGROUPS_DNS_QUERY` is wired to its FQDN, that it resolves to ≥2 pod IPs (Endpoints plus an in-cluster `nslookup`), that a ≥2-node JGroups/Infinispan view forms (the anti "two clusters of one" guard), and that state converges across the pods — exercising the Kubernetes DNS discovery path that `JGroupsKubernetesStackTest` (XML-parse only) and `ClusteredTwoNodeTest` (loopback MPING) never run. Both were proven red by degrading the exact behaviour they name (deleting the `MutatingWebhookConfiguration`; deleting the headless Service and rolling the pods). Both depend on Java-built images (the `-clustered` variant and the `mockserver-webhook` handler); when those images are absent — e.g. the CI helm step runs with `SKIP_JAVA_BUILD=true` and no JDK — the cases record an honest **SKIP** rather than a misleading pass, and run **blocking** only where the images exist. ##### Changed - `helm_clustered_convergence` is now a **blocking** container-integration test rather than `non_blocking || true`. The swallowed `k3d image import ... 2>/dev/null || true` is replaced by a deterministic import that verifies the image is present in the k3d node's containerd (via `crictl`) before deploying, and a pre-deploy `ensure_namespace_absent` guard removes the real back-to-back flake (`helm install` into a still-`Terminating` namespace left by a prior run/retry). When the `-clustered` image is absent (CI helm step, no JDK) the case records an honest **SKIP**; when present it runs blocking so a genuine clustering regression reds the suite. - The `docker_compose_war_tomcat` container integration test (MockServer deployed as a WAR into Tomcat 10.1) now actually runs in CI, closing a false-green gap where it silently skipped with *"WAR artifact not present … CI wiring is a follow-up"* — a working behavioural test that never ran, in a demonstrated weak spot (the ROOT-context percent-decode regression `66b5d51d2` shipped and broke builds, and this is the suite that would have caught it). Buildkite steps share no filesystem, so the WAR (already built by the reactor in the `:maven: build` step but never published) is now uploaded via that step's `artifact_paths` and downloaded by `container-tests-run.sh` into the path the test globs. A missing WAR now fails the step **closed** (both an explicit presence check in `container-tests-run.sh` and, defensively, `prepare_war` in `integration_test.sh` red the case) instead of skipping — a skip that reads as green is the exact defect being closed. The case runs in the Java pipeline's master-only `:docker: container integration tests` step (triggered by `mockserver/`, `mockserver-ui/`, `test-fixtures/` changes); it was already declared required in `expected_tests.manifest`, so no manifest change was needed. - Upgraded Netty from `4.2.16.Final` to `4.2.17.Final` and, in lockstep, `netty-tcnative-boringssl-static` from `2.0.78.Final` to `2.0.81.Final` (the tcnative version the Netty 4.2.17 BOM aligns to). The two must move together: the Netty BOM pins the transitively-resolved native-classifier tcnative jars to `2.0.81.Final`, so a mismatched main-artifact pin fails the enforcer `DependencyConvergence` rule in `mockserver-core`. The `NETTY_TCNATIVE` build args in every `docker/*/Dockerfile` were updated to match. This unblocks Dependabot PRs [#​2523](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2523) and [#​2532](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2532). - Removed the manual `netty-tcnative` version-synchronisation step that made every Netty upgrade a convergence trap. `netty-tcnative-boringssl-static` no longer has its own version property or `dependencyManagement` override — the imported `netty-bom` now governs the base artifact and every OS/arch native classifier together, so the two can no longer diverge and break the enforcer `DependencyConvergence` rule. The server jars (which ship tcnative classes but, per [#​1778](https://redirect.github.com/mock-server/mockserver-monorepo/issues/1778), no natives) are stamped at build time with their resolved tcnative version at `META-INF/mockserver-tcnative.version`, and every `docker/*/Dockerfile` now derives the native `.so` download from that stamp instead of a hardcoded `NETTY_TCNATIVE=` build arg (SHA256 verification of the download is unchanged). Both jars a Dockerfile can consume carry the stamp: the shaded `mockserver-netty-no-dependencies` jar used by the `source=copy` path (release/snapshot/CI) and the `mockserver-netty` assembly `-jar-with-dependencies.jar` used by the default `source=download` path (the public reference build), stamped via the same script so they cannot drift. A Netty bump therefore needs no tcnative pin update and no Docker edit, and the native `.so` can never be a different version than the tcnative classes it pairs with. - **BREAKING BEHAVIOUR: the default enabled TLS protocols are now `TLSv1.2,TLSv1.3` (previously `TLSv1,TLSv1.1,TLSv1.2`), and `tlsAllowInsecureProtocols` now defaults to `false` (previously `true`).** TLSv1 and TLSv1.1 are deprecated by RFC 8996 and vulnerable to BEAST/POODLE, and TLSv1.3 was previously never negotiated unless explicitly configured. This is a breaking change for a client that can only speak TLSv1 or TLSv1.1: its handshake to MockServer will now fail. To restore the legacy protocols set `mockserver.tlsProtocols=TLSv1,TLSv1.1,TLSv1.2` AND `mockserver.tlsAllowInsecureProtocols=true` (both are required — the insecure-protocol filter strips TLSv1/TLSv1.1 unless it is explicitly allowed). The inbound server always applies the strong `Http2SecurityUtil` cipher suites, so no weak-cipher combination becomes reachable as a result of this change. - Renewed the TLS/mTLS test-certificate fixtures. The two mutual-TLS authentication CAs (which were 151 days from expiry) and the three Netty TLS integration CAs were re-issued with a 10-year validity, and every leaf they sign was re-issued with a shorter 5-year validity so that a leaf can no longer outlive its issuing CA. The existing CA and leaf private keys were preserved (so key encodings, Subject/Authority Key Identifiers and existing signatures are unchanged); only the certificates were re-minted. ##### Security - Pinned `org.apache.logging.log4j:log4j-api` to `2.25.5` to resolve GHSA-qv9r-c865-cp47. It is pulled in transitively at compile scope (via `spring-boot-starter-logging` -> `log4j-to-slf4j`) and lands in a shaded artifact, so it is shipped; the pin manages `log4j-api` only (`log4j-core` is not on the dependency tree). - Pinned `org.jsoup:jsoup` to `1.23.1` to resolve GHSA-pmhh-3w7g-xqp8. jsoup is used only at test scope (never shipped); the pin guards against a future transitive downgrade below the fixed version. - Upgraded `com.azure:azure-storage-blob` from `12.29.1` to `12.35.0` in the optional `mockserver-blob-azure` module to resolve the `io.projectreactor.netty:reactor-netty-http` chained-redirect credential-leak advisory (fixed in reactor-netty `1.2.8`). The old stack pulled `azure-core-http-netty:1.15.10`, which pins the vulnerable reactor-netty `1.0.48` pair transitively; `12.35.0` pulls `azure-core-http-netty:1.16.5`, which advances both `reactor-netty-http` and `reactor-netty-core` to `1.2.18` as a matched pair. This exposure surfaced only when GitHub's Maven dependency-graph submission was restored (submission had silently frozen at a pre-move snapshot, so the alert had been invisible to Dependabot). The whole Azure stack (azure-core `1.58.1`, reactor-netty `1.2.18`, reactor-core `3.7.19`) remains Java-8 bytecode, so the Java 17 floor is preserved. A module-scoped `dependencyManagement` pin of `io.projectreactor:reactor-core` to `3.7.19` reconciles the one internal off-by-one in the 12.35.0 stack (azure-core declares `3.7.18`, reactor-netty declares `3.7.19`) so the enforcer `DependencyConvergence` rule stays satisfied. The Docker-gated Azurite contract test moves to Azurite `3.36.0` with `--skipApiVersionCheck`, since the newer SDK negotiates a Storage REST API version that runs ahead of every released Azurite build. - Pinned three transitive dependencies to close vulnerability alerts that surfaced only when GitHub's Maven dependency-graph submission was restored (submission had silently frozen at a pre-move snapshot on 5 May, so these real exposures had been invisible to Dependabot). None required moving the direct dependency that introduces them: - Jackson 3 (`tools.jackson.core:jackson-databind`, `:jackson-core`, `tools.jackson.dataformat:jackson-dataformat-yaml`) pinned to `3.1.5` to resolve GHSA-5gvw-p9qm-jgwh (vulnerable `>=3.0.0, <=3.1.4`). It arrives at compile scope via `com.networknt:json-schema-validator:3.0.6` and is shade-relocated into `shaded_package.tools.jackson`, so it ships in every distributed jar — the one broad, shipped, runtime exposure of the three. All three artifacts resolve in lockstep and are pinned together so the enforcer `DependencyConvergence` rule stays satisfied. The pin is inherited by the separate `mockserver-maven-plugin` build (same parent pom), closing its alert too. - `at.yawk.lz4:lz4-java` pinned to `1.11.1` to resolve GHSA-6qcp-4vqm-vf35 (native XXHash JVM crash; vulnerable `<=1.11.0`). Arrives via `org.apache.kafka:kafka-clients:3.9.2` — optional in `mockserver-netty`, runtime in `mockserver-async`. Note this is the `at.yawk.lz4` fork coordinate, not `org.lz4`. - `org.apache.commons:commons-compress` pinned to `1.27.1` to resolve the `>=1.21, <1.26.0` advisories. Arrives at test scope via `org.testcontainers:testcontainers:1.21.4`, which resolves it at `1.24.0`. The direct pin overrides that transitive version without bumping Testcontainers, which is deliberately held at `1.21.4` for Docker Desktop 4.67+ compatibility. - Made outbound TLS host name verification consistent and controllable for the forward/proxy client (Wave 3). When `forwardProxyTLSX509CertificatesTrustManagerType` is `JVM` or `CUSTOM` — the modes that actually validate the upstream certificate chain — MockServer now verifies the upstream host name against the certificate (RFC 2818 / HTTPS endpoint identification) on every outbound path. Netty already enabled this for client connections opened with a known host/port, but NOT for the no-host relay paths, so verification was silently skipped on some paths and there was no way to turn it off; without the host-name binding a certificate signed by a trusted CA for any host name would be accepted, leaving a user who had opted into real upstream validation open to a man-in-the-middle. It is now forced uniformly at the single point every outbound path shares (HTTP/1.1, HTTP/2, CONNECT-tunnelled relay, websocket relay, the reverse-proxy relay — which verifies against the CONNECT target host/port, not the connected socket address — and the LLM forward paths). It has no effect on the default `ANY` trust manager, which deliberately trusts everything and performs no host-name verification. A new `forwardProxyTLSHostnameVerificationEnabled` property (default `true`) turns off just the host-name check while keeping chain validation, for the legitimate testing case of an upstream whose certificate host name does not match the address connected to (it actively clears the algorithm Netty would otherwise default on); it is carried by `ConfigurationDTO` and folded into the client SSL-context cache key so a runtime change takes effect. The trust-manager javadoc, which previously implied only `ANY` skipped host-name verification, has been corrected. - Added a single startup WARN when the publicly-published bundled Certificate Authority (whose private key ships in the MockServer jar) is the trust anchor signing served traffic, naming the two supported fixes (`dynamicallyCreateCertificateAuthorityCertificate=true`, or `--proxy-setup`). Shipping the CA key is intentional and documented and the default is unchanged; the warning just makes the trade-off visible so an operator does not mistake the bundled CA for real interception security. Logged once per JVM, never per handshake. - A user-supplied FIXED server certificate is now re-checked on a cheap, time-bounded schedule (at most once a minute, stat only — never a per-handshake re-parse) so a long-running server surfaces a problem instead of silently serving it: a certificate rotated in place on disk forces a rebuild (which re-runs validation and picks up the replacement, failing loudly if it too is expired), and an unchanged-but-expired certificate is surfaced with a single WARN. Wave 1 had deliberately left this gap (self-generated leaves already self-renew; fixed certificates were validated only at startup). - Added a control-plane audit WARN when a `PUT /mockserver/configuration` lowers or alters TLS security posture — downgrading the forward-proxy trust manager to `ANY`, turning off `tlsMutualAuthenticationRequired`, turning off `forwardProxyTLSHostnameVerificationEnabled`, or repointing the TLS key/certificate/CA paths. Control-plane authentication is off by default, so such a runtime downgrade would otherwise be silent. The change is audited, not blocked (blocking would be an init-only breaking change). - Hardened the dynamic TLS certificate cache so it can no longer serve stale, torn or over-broad material (Wave 1, resilience only — certificate validity periods and extensions are unchanged). The cached server SSL context now regenerates a fresh leaf once the current one passes a renewal threshold (80% of its validity elapsed) instead of serving an expired certificate for the JVM lifetime; the cache-reuse decision is driven by a content signature over the Subject-Alternative-Name set, certificate-authority identity, key/cert paths, mTLS and protocol inputs (replacing a single consumable boolean that could return a certificate missing a just-added SAN under concurrency); client SSL contexts and the memoised certificate authority now self-invalidate when their inputs are rotated at runtime. Certificate generation now publishes the new private key and certificate atomically (a mid-flight failure keeps the previous working pair instead of leaving a new key paired with the old certificate), and SNI-driven provisioning runs off the Netty event loop with per-host coalescing. Only the leaf drives that renewal trigger: a dynamically-generated certificate authority nearing its own expiry is warned about once (it is never rotated automatically, which would invalidate every client trust store that imported it) rather than demanding a leaf regeneration the certificate-authority guard can never satisfy — which would otherwise re-mint the leaf on every handshake indefinitely. - Bounded the dynamically-grown Subject-Alternative-Name list with a new `maxSubjectAlternativeNames` property (default 100; when the cap is reached the genuinely oldest dynamically-discovered entry is evicted first, in FIFO order, with a warning, while configured and default SANs such as localhost are never evicted) and now normalise/validate each SNI hostname and `Host` header (lowercase, length and label-charset checked) before it is added, closing a denial-of-service vector where any client could force the leaf certificate to be re-minted with an unbounded SAN list. Both `maxSubjectAlternativeNames` and `sslCertificateLeafValidityInDays` are now carried by `ConfigurationDTO`, so they round-trip through `GET`/`PUT /mockserver/configuration` and can be set per-instance rather than only via the static store (a runtime change to `maxSubjectAlternativeNames` takes effect on the next SAN added). - Dynamically-generated private key material (leaf key, certificate-authority key, and the JKS key store) is now written owner-readable-only (`0600`) and atomically, and public certificates `0644`; a corrupt or unreadable certificate-authority PEM now fails loudly instead of being silently treated as absent and overwritten (which would invalidate every pinned client trust store), with cross-process locking around certificate-authority generation. - Deferred BouncyCastle registration in `PEMToFile` off the class-load path, restoring the lazy-BouncyCastle startup optimisation. - Shortened the auto-generated TLS **leaf** (server) certificate to a 397-day validity by default (Wave 2), so it stays inside Apple's 825-day maximum for TLS server certificates (iOS 13 / macOS 10.15) — the previous 10-year leaf exceeded that cap and is the likely cause of TLS handshake failures on Apple platforms ([#​2531](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2531)). The generated Certificate Authority keeps its long (10-year) life, and the Wave 1 proactive renewal (regenerating the leaf once 80% of its validity has elapsed) means a long-running server never serves an expired leaf; the previous long-lived behaviour can be restored with the new `sslCertificateLeafValidityInDays` property (e.g. `3650`). That override is clamped to a usable range of 30–3650 days (a WARN is logged when a value is clamped): a value below 30 would mint a leaf that — because the `notBefore` is back-dated 5 days — is either already expired at issuance or already past its renewal threshold (so it would be re-minted on every handshake), and a value above 3650 could push the expiry past the X.509 date ceiling; a non-positive value still falls back to the 397-day default. The generated leaf now also carries a `serverAuth`+`clientAuth` extended-key-usage (Apple requires `serverAuth` on the leaf independently of validity), a critical `digitalSignature`+`keyEncipherment` key-usage, and an authority-key-identifier derived from the CA; the root CA no longer carries a (non-idiomatic) extended-key-usage. Certificate serial numbers are now forced positive as required by RFC 5280, and the HTTP/3 legacy echo-mode self-signed fallback gained a back-dated `notBefore`, subject-alternative-names, `serverAuth` extended-key-usage and a key-usage (it keeps the long validity because it is both trust anchor and server certificate with no renewal loop). ##### Removed - Removed the unused `PKCS1CertificateAuthorityPrivateKey.pem` resource from the published `mockserver-core` jar. It was the explicit [PKCS#1](https://redirect.github.com/PKCS/mockserver-monorepo/issues/1) half of an encoding pair added in 2020 for the since-removed JDK key/certificate builder, whose deletion in 2022 left it with no references for around four years. It was byte-identical to the original `CertificateAuthorityPrivateKey.pem`, which is retained (it backs a published raw-URL link and remains the stable [PKCS#1](https://redirect.github.com/PKCS/mockserver-monorepo/issues/1) form); the code continues to load `PKCS8CertificateAuthorityPrivateKey.pem`. ##### Fixed - Fixed a rare `mockserver-core` unit-test flake (`ConfigurationValueRedactionTest` / `ConfigurationDTOCredentialMaskingTest` failing with `Expected: is <1> but: was <0>` when asserting an exact count of captured log records). These tests attach a `java.util.logging` handler and assert what is emitted. Two other tests — `ClassInitializationDeadlockTest` and `ConfigurationPropertiesInitializationTest` — force a fresh `<clinit>` of MockServer classes in an isolated child-first classloader; that initialisation reaches `MockServerLogger.installDefaultJavaLoggingFormat()` → `LogManager.getLogManager().readConfiguration(...)`, and `java.util.logging.LogManager` is a **JVM-global singleton the child-first classloader does not isolate**, so its `readConfiguration` performs a `reset()` that removes every handler from every logger in the JVM. When one of those classes ran in the parallel Surefire phase alongside a handler-capturing test, the reset detached the capturing handler mid-test and a subsequent emit went uncounted. Both fresh-`<clinit>` classes are now pinned to the sequential (`parallel=none`) Surefire phase in `mockserver-core/pom.xml`, so they can never run concurrently with a handler-capturing test. No production behaviour changes. - Fixed the Helm chart's sidecar-injection webhook being broken out of the box. The default TLS-bootstrap image `webhook.tls.setupImage: bitnami/kubectl:1.31` no longer exists — Bitnami withdrew the tag from Docker Hub — so both bootstrap Jobs failed, the `MutatingWebhookConfiguration`'s `caBundle` was never patched, and because `failurePolicy: Fail` the webhook then **rejected every matched pod CREATE**. Anyone enabling `webhook.enabled=true` from the shipped defaults got an admission path that blocked pod creation rather than injecting a sidecar. The bootstrap now uses `registry.k8s.io/ingress-nginx/kube-webhook-certgen`, the purpose-built tool for exactly this job, published on the most stable-publication registry available and self-contained (no shell, no `openssl` CLI, no install-at-runtime step that would fail on an airgapped or proxied cluster). Phase 2's ClusterRole also gains the `update` verb, which the patch step genuinely needs. `helm_sidecar_injection` now renders and asserts the **chart default** is pullable rather than overriding it, so this cannot silently rot again. - Fixed the Kubernetes sidecar-injection webhook rejecting valid TLS private keys. `WebhookServer` parsed [PKCS#8](https://redirect.github.com/PKCS/mockserver-monorepo/issues/8) only and explicitly rejected anything else, which broke the **cert-manager** path as well: the chart's `Certificate` requests `algorithm: RSA` without `encoding: PKCS8`, i.e. [PKCS#1](https://redirect.github.com/PKCS/mockserver-monorepo/issues/1), so a cert-manager-issued key could not be loaded. It now accepts any standard unencrypted PEM private key — [PKCS#8](https://redirect.github.com/PKCS/mockserver-monorepo/issues/8), [PKCS#1](https://redirect.github.com/PKCS/mockserver-monorepo/issues/1), and SEC1 EC. This coupling is why the broken bootstrap image above could not simply be swapped: the handler only tolerated the one format that one withdrawn image happened to emit. - Fixed a thread race in dynamic Certificate Authority generation that could leave a standalone / CLI / Docker MockServer serving broken TLS for the rest of the process's lifetime. When `dynamicallyCreateCertificateAuthorityCertificate` is enabled, two startup paths could generate the CA concurrently — the proxy-setup log (`proxySetupLogging`, on by default in the CLI) writing the CA to disk, and the first HTTPS handshake building the server certificate. Generation was serialised only by a cross-process file lock; a second lock attempt **within the same JVM** threw `OverlappingFileLockException`, which was caught and treated as "proceed without serialisation", so both threads minted different CA key pairs and interleaved their writes. The result was a torn CA key/certificate pair on disk: every leaf certificate was then signed with one generation's CA key but verified against the other's CA public key, failing with `SignatureException: certificate does not verify with supplied key` — and because the mismatched CA was memoised, **every subsequent TLS handshake failed for the life of the process**. CA generation (and the paired load of the CA key + certificate) is now serialised within the JVM on a per-directory monitor in addition to the cross-process file lock, so the key and certificate are always published from the same generation. Embedded `ClientAndServer` users were unaffected (they default `proxySetupLogging` off); standalone, CLI and Docker users generating a dynamic CA could hit it intermittently. - Unblocked the daily Dependabot updater, which had been failing and raising no PRs. The Maven wrappers under `mockserver/` and `mockserver/mockserver-maven-plugin/` were modernised from the legacy Takari format to the Apache `only-script` wrapper (`wrapperVersion` 3.3.4, Maven pinned at 3.9.16), so the `maven-wrapper-updater` can parse them; `mockserver-vscode` was split into its own npm job (a lockfile `EOVERRIDE` there no longer aborts the other npm directories) and pinned `js-yaml` to `^4.1.1` via `overrides`; and `/.opencode` (which had only an orphan lockfile and no tracked manifest) was removed from the npm directories and its lockfile untracked. - Cloning an `X509Certificate` model that contains certificate metadata without an underlying Java certificate no longer throws a `NullPointerException`; metadata-only and certificate-backed models now both preserve their state when cloned ([#​2527](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2527)). - JSON body matching no longer depends on which JSON provider [json-unit](https://redirect.github.com/lukas-krecan/JsonUnit) resolves to. MockServer parses both documents with Jackson and hands json-unit the resulting nodes to avoid re-parsing on every match, but json-unit picks its provider by asking each in turn whether it claims the value and falling back to the last one registered — and only its Jackson provider claims a Jackson node. Where another provider won (for example `org.json`, whether because Jackson was not visible to json-unit or because `json-unit.libraries` pinned it) every JSON match threw `Unsupported type class com.fasterxml.jackson.databind.node.ObjectNode` and **no JSON body ever matched**. MockServer now falls back to giving json-unit the raw JSON text, which it parses with whichever provider it resolved to ([#​2496](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2496)). - Match failures from the JSON body matcher now report why the match failed. When JSON matching threw, the log said only `exception while perform json match failed` and the exception was recorded solely at `TRACE`, so at the default log level there was no way to tell a malformed body from a missing class from a runtime error. The cause is now included in the reported difference, as it already was for the XML schema, JSON path and JSON-RPC matchers. - Resolved the outstanding npm security advisories in the shipped and published Node packages: `dompurify` `3.4.12` → `3.4.13` in the bundled dashboard (`mockserver-ui`), `brace-expansion` `5.0.8` → `5.0.9` (ReDoS) in `mockserver-testcontainers/node`, and `js-yaml` `4.3.0` → `4.3.1` in `mockserver-client-node`, `mockserver-node` and `mockserver-testcontainers/node`. The `brace-expansion` fix bumps only the parent so the `minimatch`/`archiver` glob split is preserved (a blanket override previously broke `archiver`); no `brace-expansion` override was added. - Documented and mitigated a clustered-deployment TLS trust defect: with the default dynamic Certificate Authority generation, every MockServer node in a cluster mints its own distinct CA, so a client that trusts one node's `mockserver-ca.pem` gets an intermittent TLS validation failure when a load balancer routes it to another node. `StateBackendFactory.create()` now logs a WARN when it detects `clusterEnabled=true` together with `dynamicallyCreateCertificateAuthorityCertificate=true`, and the limitation and its fix are now documented in `docs/code/clustered-state.md`, `docs/code/tls-and-security.md`, the Helm chart README, and the Centralized Deployment consumer page. - Added first-class Helm chart support for supplying **one shared TLS Certificate Authority to every replica** via a Kubernetes Secret — the supported fix for the clustered CA defect above. New opt-in values `app.tls.*` create (or reference an existing) Secret, mount it read-only, and set `certificateAuthorityCertificate` / `certificateAuthorityPrivateKey` with `dynamicallyCreateCertificateAuthorityCertificate=false` on every pod. A CA private key now lands in a Secret rather than a ConfigMap. Also added `app.dynamicCertificateDir.*` (a writable `emptyDir` for the single-replica dynamic-CA case, so certificate writes no longer depend on a non-writable working directory) and `app.extraEnv` (arbitrary container environment variables, enabling any `MOCKSERVER_*` property the chart does not expose directly). All new values are opt-in and default to today's behaviour. - Fixed a latent dead condition in the Helm chart Deployment template: the `MOCKSERVER_PROPERTY_FILE` env var was gated on an undeclared `app.mountConfigMap` value (always false). `app.mountConfigMap` is now a declared value (default `false`, preserving prior behaviour) so external-ConfigMap users can opt into having MockServer pointed at the mounted `mockserver.properties`. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…rometheus#2387) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [com.google.guava:guava](https://redirect.github.com/google/guava) | `33.6.0-jre` → `33.7.1-jre` |  |  | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…o v0.159.0 (prometheus#2388) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [otel/opentelemetry-collector-contrib](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases) | minor | `0.158.0` → `0.159.0` | --- ### Release Notes <details> <summary>open-telemetry/opentelemetry-collector-releases (otel/opentelemetry-collector-contrib)</summary> ### [`v0.159.0`](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/blob/HEAD/CHANGELOG.md#v01590) [Compare Source](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/compare/v0.158.0...v0.159.0) ##### 🛑 Breaking changes 🛑 - `contrib`: Remove deprecated kafkatopicsobserver extension from the contrib distribution ([#​1597](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1597)) ##### 🚀 New components 🚀 - `extension/aws_iam_db_auth`: Add `aws_iam_db_auth` to the contrib distribution ([#​1591](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1591)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
## Summary - bound default query parsing by query length and parameter count - return HTTP 400 for malformed or excessive query parameters - deduplicate exact metric-name filters before lookup This is the focused replacement for the prometheus#2285 portion of prometheus#2297. Fixes prometheus#2285 ## Ongoing discussion None currently. The malformed percent-encoding case raised during the earlier review is covered and returns HTTP 400. ## Validation - `mise run lint:fix` - `mise run build` - `./mvnw test -pl prometheus-metrics-exporter-common,prometheus-metrics-model -Dcoverage.skip=true -Dcheckstyle.skip=true` --------- Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
…#2390) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grafana/grafana](https://redirect.github.com/grafana/grafana) | minor | `13.1.3` → `13.2.0` | --- ### Release Notes <details> <summary>grafana/grafana (grafana/grafana)</summary> ### [`v13.2.0`](https://redirect.github.com/grafana/grafana/compare/v13.1.4...v13.2.0) ### [`v13.1.4`](https://redirect.github.com/grafana/grafana/compare/v13.1.3...v13.1.4) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMi42IiwidXBkYXRlZEluVmVyIjoiNDQuMzIuNiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
Owner
Author
|
This draft was created in the fork by mistake; the intended follow-up is being opened against prometheus/client_java. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PrometheusHttpRequestJavaDocFollow-up to prometheus/client_java#2334 and discussion_r3752169308.
Validation
mise run lint:fix(blocked by the pre-existing 403 response for the README CNCF Slack link; the push hook passed using a temporary local-only README substitution, restored before completion)mise run build./mvnw -pl prometheus-metrics-exporter-common test -Dcoverage.skip=true