Skip to content

Stop escaping extends-environment in pyvenv.cfg - #20466

Merged
zanieb merged 3 commits into
mainfrom
tk/fix-extends-environment-path
Jul 16, 2026
Merged

Stop escaping extends-environment in pyvenv.cfg#20466
zanieb merged 3 commits into
mainfrom
tk/fix-extends-environment-path

Conversation

@EliteTK

@EliteTK EliteTK commented Jul 16, 2026

Copy link
Copy Markdown
Member

Summary

This would produce broken results on *nix.

I also made it error on UTF-8 encoding but maybe a warning (and not writing the result) is more appropriate?

Test Plan

I adjusted the test, I moved the filter inline so it could be tailored to specifically look for the path. The original one was not doing that.

EliteTK added 2 commits July 16, 2026 09:57
The filter is very broad to the point that it cannot be used to verify
expectations. But making it narrow enough for that would require
parametrization or a second filter, and only one test exercises this
path at the moment, so I've decided to inline it.
Ty is the only consumer, it doesn't unescape the result.

This probably worked fine for Windows because it eats duplicate
backslashes, it would only break there if someone put a double-quote in
their path (which nobdy does). On *nix it would break in both cases but
again nobody does that.

Regardless, it shouldn't be escaped, and eating the utf-8 error silently
would just produce a weird broken result. So I opted to make it loud...
Could make it a warning?

[^ty]: <https://github.com/astral-sh/ruff/blob/db195f3a494c55feeef225daa5de0b803a5253ac/crates/ty_site_packages/src/lib.rs#L1081-L1117>
@EliteTK EliteTK added the bug Something isn't working label Jul 16, 2026
@EliteTK
EliteTK requested review from zanieb and zsol July 16, 2026 08:00
@zsol

zsol commented Jul 16, 2026

Copy link
Copy Markdown
Member

FWIW I don't mind the error here - uv already refuses to create venvs with non-utf8 paths

@EliteTK

EliteTK commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

<world if CI worked meme>

Comment thread crates/uv/tests/project/run.rs Outdated
Comment on lines +1668 to +1676
let parent_environment = context.temp_dir.child(if cfg!(windows) {
"parent-environment"
} else {
"parent\"environment"
});
let parent_environment_path = parent_environment.path().to_path_buf();
fs_err::rename(context.venv.path(), &parent_environment_path)?;
context.venv = parent_environment;
let context = context.with_filtered_path(&parent_environment_path, "PARENT_VENV");

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is pretty weird looking?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you mind elaborating? Is there a question the comment above doesn't answer?

I guess the cfg!( is kind of superfluous, it could use " in both cases...

I could create a fresh venv instead of using context.venv.path() and overwriting it...

Let me push those as an addendum.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

see now

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I forgot that windows fundamentally doesn't allow double quotes in paths, so there has to be a split. The other cleanup is still there. I made the comment cleaner though.

@zanieb

zanieb commented Jul 16, 2026

Copy link
Copy Markdown
Member

A broken result how? What would the pyvenv.cfg look like in the regression case?

@EliteTK

EliteTK commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

A broken result how? What would the pyvenv.cfg look like in the regression case?

It would have escaped backslashes and double quotes (our escape for python function is also broken).

E.g. on *nix, the path /home/tk/test"test\test would be stored as extends-environment = /home/tk/test\"test\\test which ty would not unescape (see commit message for permalink to the relevant code) and so it would resolve a different path with extra backslashes in it.

@zanieb

zanieb commented Jul 16, 2026

Copy link
Copy Markdown
Member

What about other consumers? Like whatever Python uses for parsing ini files?

@EliteTK

EliteTK commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

What about other consumers? Like whatever Python uses for parsing ini files?

pyvenv.cfg isn't parsed by other consumers with INI parsers. It's a format entirely (vaguely) described by PEP405. Everyone uses hand rolled parsers like the ty one. They all look only for keys they care about. I did a check to make sure this change wouldn't cause problems with any existing tooling parsing the format but I only skimmed the code. I will run some actual tests later to confirm...

@EliteTK

EliteTK commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

I actually found two things that use ConfigParser with a fudge (they prepend a section, otherwise it't not valid), specifically Sublime's LSP-pyright and pipx. But, in any case, ConfigParser doesn't unescape.

I think the best justification is this: https://github.com/python/cpython/blob/b090d06e7331c40b3c94e70b35a09f785b279e17/Lib/venv/__init__.py#L228

python -m venv produces a home key with no escaping.

But just to confirm, I took a bunch of snippets and verified them (where possible - i.e. it's in python) to make sure things work. I checked the following:

Nothing other than ty looks at the value.

@zanieb

zanieb commented Jul 16, 2026

Copy link
Copy Markdown
Member

Like, they specifically all prefer no escaping for the home key? (It doesn't really matter to me that none of them read this specific key we made up, I want to know if they can parse this properly in general)

@EliteTK
EliteTK force-pushed the tk/fix-extends-environment-path branch from 7367964 to e4a8528 Compare July 16, 2026 16:02
@EliteTK

EliteTK commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

Escapes are not a concept in ini nor in this specific pseudo-ini format. And yes, after a quick glance, the parsers for those that use the value of home also don't unescape it on read. They take any backslashes verbatim, they don't treat them as an escape character.

@zanieb
zanieb merged commit eadaf43 into main Jul 16, 2026
60 checks passed
@zanieb
zanieb deleted the tk/fix-extends-environment-path branch July 16, 2026 21:01
luketainton pushed a commit to luketainton/repos_labmcp that referenced this pull request Jul 20, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | final | patch | `0.11.29` → `0.11.30` |

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.11.30`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01130)

Released on 2026-07-20.

##### Python

- Add CPython 3.15.0b4 ([#&#8203;20519](astral-sh/uv#20519))

##### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#&#8203;20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#&#8203;20436](astral-sh/uv#20436))

##### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#&#8203;20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#&#8203;20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#&#8203;20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#&#8203;20463](astral-sh/uv#20463), [#&#8203;20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#&#8203;20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#&#8203;20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#&#8203;20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#&#8203;20462](astral-sh/uv#20462))

##### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#&#8203;20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#&#8203;20466](astral-sh/uv#20466))

##### Documentation

- Add a contribution guide ([#&#8203;20511](astral-sh/uv#20511), [#&#8203;20552](astral-sh/uv#20552))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==-->Reviewed-on: https://git.tainton.uk/repos/labmcp/pulls/16

Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request Jul 21, 2026
This MR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [uv](https://github.com/astral-sh/uv) | patch | `0.11.29` → `0.11.30` |

MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot).

**Proposed changes to behavior should be submitted there as MRs.**

---

### Release Notes

<details>
<summary>astral-sh/uv (uv)</summary>

### [`v0.11.30`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#01130)

[Compare Source](astral-sh/uv@0.11.29...0.11.30)

Released on 2026-07-20.

##### Python

- Add CPython 3.15.0b4 ([#&#8203;20519](astral-sh/uv#20519))

##### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#&#8203;20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#&#8203;20436](astral-sh/uv#20436))

##### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#&#8203;20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#&#8203;20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#&#8203;20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#&#8203;20463](astral-sh/uv#20463), [#&#8203;20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#&#8203;20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#&#8203;20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#&#8203;20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#&#8203;20462](astral-sh/uv#20462))

##### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#&#8203;20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#&#8203;20466](astral-sh/uv#20466))

##### Documentation

- Add a contribution guide ([#&#8203;20511](astral-sh/uv#20511), [#&#8203;20552](astral-sh/uv#20552))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this MR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI2NS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6cGF0Y2giXX0=-->
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.29` → `0.11.32` | `0.11.29` → `0.11.32` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.29` → `0.11.32` | `0.11.29` → `0.11.32` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.29` → `0.11.32` | `0.11.29` → `0.11.32` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.29` → `0.11.32` | `0.11.29` → `0.11.32` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `uv`

Command: `mise upgrade --bump --local uv`

<details>
<summary>Version changelog (uv)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `uv` | `0.11.29` → `0.11.32` | `0.11.29` → `0.11.32` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |
| `rumdl` | `0.2.36` → `0.2.43` | `0.2.36` → `0.2.43` |
| `tombi` | `1.2.3` → `1.2.4` | `1.2.3` → `1.2.4` |
| `uv` | `latest` → `latest` | `0.11.29` → `0.11.32` |
| `zizmor` | `latest` → `latest` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (5 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>
<details>
<summary>rumdl: `0.2.36` → `0.2.43` (rvben/rumdl)</summary>

### v0.2.37

### Added

- **reflow**: add atomic_spans configuration and refactor inline wrapping (#742) ([aeabec1](rvben/rumdl@aeabec1))

### Changed

- **BREAKING**: the MD013 `emphasis-spans` option is renamed to `atomic-spans` (default `true`), with inverted meaning (`emphasis-spans = true` is now `atomic-spans = false`). Configs setting the old key should migrate; it is no longer recognized

### Fixed

- **reflow**: keep code spans atomic when wrapping would collapse whitespace ([d43618b](rvben/rumdl@d43618b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/rel… (truncated)

### v0.2.38

### Added

- **md044**: add ignore-frontmatter-fields option ([b664e5a](rvben/rumdl@b664e5a))
- **config**: warn when an inline enable cannot re-enable a config-disabled rule ([a74a923](rvben/rumdl@a74a923))

### Fixed

- **md044**: stop flagging proper names inside frontmatter file paths ([35649d9](rvben/rumdl@35649d9))
- **md022**: stop panicking when one blank-line requirement is unlimited ([8a25eb2](rvben/rumdl@8a25eb2))
- **config**: report unknown option keys in inline configure-file comments ([8f4c0ea](rvben/rumdl@8f4c0ea))
- **config**: apply markdownlint-configure-file when the comment spans lines ([7a023a5](rvben/rumdl@7a023a5))
- **config**: honor booleans and alias keys in markdownlint-configure-file (#745) ([acefc19](rvben/rumdl@acefc19))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unkn… (truncated)

### v0.2.39

### Added

- **config**: expand ~ to the home directory in path settings ([70f91aa](rvben/rumdl@70f91aa))

### Fixed

- **md013**: wrap over-long emphasis spans that contain nested markup ([ddc73f4](rvben/rumdl@ddc73f4))
- **discovery**: strip Windows verbatim prefix from canonicalized paths ([a85ab87](rvben/rumdl@a85ab87))
- **discovery**: apply absolute exclude patterns during directory discovery ([0d20fc8](rvben/rumdl@0d20fc8))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-apple-darw… (truncated)

### v0.2.40

### Fixed

- **md003**: consume the setext underline when converting a heading to ATX. Converting a setext heading left the underline behind, where a following blank line turned it into a thematic break, so `rumdl fmt` added a horizontal rule the document never had ([7363c34](rvben/rumdl@7363c34))
- **md077**: stop scoping list items inside blockquotes, which made a lazy continuation line gain indentation on every pass so the formatter never converged ([58fb25b](rvben/rumdl@58fb25b))
- **reflow**: keep wiki links, shortcodes and math whole inside a wrapped span ([db12c2c](rvben/rumdl@db12c2c))
- **config**: honor the documented MD033 `table_allowed` alias, which silently dropped the configured value ([db2c204](rvben/rumdl@db2c204))
- **config**: stop reporting MD013's documented `semantic-link-understanding` alias as an unknown option ([1539a64](rvben/rumdl@1539a64))
- **parity**: make the markdownlint comparison harness actually run ([182763c](rvben/rumdl@182763c))

### Documentation

- **md013**: document that `ignore-link-urls` affects reporting only. Reflow measures the markdown as written, matching prettier and mdformat ([c4f8bad](rvben/rumdl@c4f8bad))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.40-x86_64-u… (truncated)

### v0.2.41

### Added

- **flavor**: add Hugo flavor and skip block attribute lists in blanks-around rules ([e6bb033](rvben/rumdl@e6bb033))

### Fixed

- **md044**: recognize indented HTML comments so links and code escape the rule ([3d6191c](rvben/rumdl@3d6191c))
- **md013**: keep an attr list whole inside a wrapped span ([e06f03d](rvben/rumdl@e06f03d))
- **md013**: keep a reference-style link whole inside a wrapped span ([de42709](rvben/rumdl@de42709))
- **md013**: wrap an over-long span whose whole content is another span ([f6c7c9c](rvben/rumdl@f6c7c9c))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz) | Linux… (truncated)

### v0.2.42

### Added

- **mojibake**: new rule MD083 for mojibake detection (#753) ([552842b](rvben/rumdl@552842b))

### Fixed

- **lint_context**: prevent panic when HTML tag window splits a UTF-8 char ([d14b252](rvben/rumdl@d14b252))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/relea… (truncated)

### v0.2.43

### Added

- **invisiblechars**: new rule MD084 for detecting invisible characters (#758) ([0a6354a](rvben/rumdl@0a6354a))

### Fixed

- **md084**: treat a zero width joiner between visible characters as presentation ([4fbb1cc](rvben/rumdl@4fbb1cc))
- **md084**: keep attached variation selectors in consecutive-character detection ([f4e9fd3](rvben/rumdl@f4e9fd3))
- **md084**: don't flag variation selectors attached to a base character ([14941bb](rvben/rumdl@14941bb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz.sha256)… (truncated)

</details>
<details>
<summary>tombi: `1.2.3` → `1.2.4` (tombi-toml/tombi)</summary>

### v1.2.4

<!-- Release notes generated using configuration in .github/release.yml at v1.2.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(date-time): accept leap second 60 in date-time values by @​LordAizen1 in tombi-toml/tombi#2024

## New Contributors
* @​LordAizen1 made their first contribution in tombi-toml/tombi#2024

**Full Changelog**: tombi-toml/tombi@v1.2.3...v1.2.4

</details>
<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>
<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |
| `rumdl` | `0.2.36` → `0.2.43` | `0.2.36` → `0.2.43` |
| `tombi` | `1.2.3` → `1.2.4` | `1.2.3` → `1.2.4` |
| `uv` | `latest` → `latest` | `0.11.29` → `0.11.32` |
| `zizmor` | `latest` → `latest` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (5 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>
<details>
<summary>rumdl: `0.2.36` → `0.2.43` (rvben/rumdl)</summary>

### v0.2.37

### Added

- **reflow**: add atomic_spans configuration and refactor inline wrapping (#742) ([aeabec1](rvben/rumdl@aeabec1))

### Changed

- **BREAKING**: the MD013 `emphasis-spans` option is renamed to `atomic-spans` (default `true`), with inverted meaning (`emphasis-spans = true` is now `atomic-spans = false`). Configs setting the old key should migrate; it is no longer recognized

### Fixed

- **reflow**: keep code spans atomic when wrapping would collapse whitespace ([d43618b](rvben/rumdl@d43618b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/rel… (truncated)

### v0.2.38

### Added

- **md044**: add ignore-frontmatter-fields option ([b664e5a](rvben/rumdl@b664e5a))
- **config**: warn when an inline enable cannot re-enable a config-disabled rule ([a74a923](rvben/rumdl@a74a923))

### Fixed

- **md044**: stop flagging proper names inside frontmatter file paths ([35649d9](rvben/rumdl@35649d9))
- **md022**: stop panicking when one blank-line requirement is unlimited ([8a25eb2](rvben/rumdl@8a25eb2))
- **config**: report unknown option keys in inline configure-file comments ([8f4c0ea](rvben/rumdl@8f4c0ea))
- **config**: apply markdownlint-configure-file when the comment spans lines ([7a023a5](rvben/rumdl@7a023a5))
- **config**: honor booleans and alias keys in markdownlint-configure-file (#745) ([acefc19](rvben/rumdl@acefc19))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unkn… (truncated)

### v0.2.39

### Added

- **config**: expand ~ to the home directory in path settings ([70f91aa](rvben/rumdl@70f91aa))

### Fixed

- **md013**: wrap over-long emphasis spans that contain nested markup ([ddc73f4](rvben/rumdl@ddc73f4))
- **discovery**: strip Windows verbatim prefix from canonicalized paths ([a85ab87](rvben/rumdl@a85ab87))
- **discovery**: apply absolute exclude patterns during directory discovery ([0d20fc8](rvben/rumdl@0d20fc8))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-apple-darw… (truncated)

### v0.2.40

### Fixed

- **md003**: consume the setext underline when converting a heading to ATX. Converting a setext heading left the underline behind, where a following blank line turned it into a thematic break, so `rumdl fmt` added a horizontal rule the document never had ([7363c34](rvben/rumdl@7363c34))
- **md077**: stop scoping list items inside blockquotes, which made a lazy continuation line gain indentation on every pass so the formatter never converged ([58fb25b](rvben/rumdl@58fb25b))
- **reflow**: keep wiki links, shortcodes and math whole inside a wrapped span ([db12c2c](rvben/rumdl@db12c2c))
- **config**: honor the documented MD033 `table_allowed` alias, which silently dropped the configured value ([db2c204](rvben/rumdl@db2c204))
- **config**: stop reporting MD013's documented `semantic-link-understanding` alias as an unknown option ([1539a64](rvben/rumdl@1539a64))
- **parity**: make the markdownlint comparison harness actually run ([182763c](rvben/rumdl@182763c))

### Documentation

- **md013**: document that `ignore-link-urls` affects reporting only. Reflow measures the markdown as written, matching prettier and mdformat ([c4f8bad](rvben/rumdl@c4f8bad))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.40-x86_64-u… (truncated)

### v0.2.41

### Added

- **flavor**: add Hugo flavor and skip block attribute lists in blanks-around rules ([e6bb033](rvben/rumdl@e6bb033))

### Fixed

- **md044**: recognize indented HTML comments so links and code escape the rule ([3d6191c](rvben/rumdl@3d6191c))
- **md013**: keep an attr list whole inside a wrapped span ([e06f03d](rvben/rumdl@e06f03d))
- **md013**: keep a reference-style link whole inside a wrapped span ([de42709](rvben/rumdl@de42709))
- **md013**: wrap an over-long span whose whole content is another span ([f6c7c9c](rvben/rumdl@f6c7c9c))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz) | Linux… (truncated)

### v0.2.42

### Added

- **mojibake**: new rule MD083 for mojibake detection (#753) ([552842b](rvben/rumdl@552842b))

### Fixed

- **lint_context**: prevent panic when HTML tag window splits a UTF-8 char ([d14b252](rvben/rumdl@d14b252))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/relea… (truncated)

### v0.2.43

### Added

- **invisiblechars**: new rule MD084 for detecting invisible characters (#758) ([0a6354a](rvben/rumdl@0a6354a))

### Fixed

- **md084**: treat a zero width joiner between visible characters as presentation ([4fbb1cc](rvben/rumdl@4fbb1cc))
- **md084**: keep attached variation selectors in consecutive-character detection ([f4e9fd3](rvben/rumdl@f4e9fd3))
- **md084**: don't flag variation selectors attached to a base character ([14941bb](rvben/rumdl@14941bb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz.sha256)… (truncated)

</details>
<details>
<summary>tombi: `1.2.3` → `1.2.4` (tombi-toml/tombi)</summary>

### v1.2.4

<!-- Release notes generated using configuration in .github/release.yml at v1.2.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(date-time): accept leap second 60 in date-time values by @​LordAizen1 in tombi-toml/tombi#2024

## New Contributors
* @​LordAizen1 made their first contribution in tombi-toml/tombi#2024

**Full Changelog**: tombi-toml/tombi@v1.2.3...v1.2.4

</details>
<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>
<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants