Skip to content

Install Node hooks through git url - #2394

Merged
j178 merged 5 commits into
masterfrom
agent/node-git-install
Jul 24, 2026
Merged

Install Node hooks through git url#2394
j178 merged 5 commits into
masterfrom
agent/node-git-install

Conversation

@j178

@j178 j178 commented Jul 24, 2026

Copy link
Copy Markdown
Owner

Install remote Node hook repositories through a local git+file:// spec so npm 12 can install build-time dependencies before prepare without modifying prek's shared checkout.

Pass --allow-git=root only on npm 12, preserving npm 11 compatibility.

@codecov

codecov Bot commented Jul 24, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 91.17647% with 3 lines in your changes missing coverage. Please review.
✅ Project coverage is 93.45%. Comparing base (928dc5c) to head (875112d).
⚠️ Report is 3 commits behind head on master.

Files with missing lines Patch % Lines
crates/prek/src/languages/node/node.rs 86.95% 3 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #2394      +/-   ##
==========================================
+ Coverage   93.38%   93.45%   +0.06%     
==========================================
  Files         129      130       +1     
  Lines       27637    27964     +327     
==========================================
+ Hits        25810    26133     +323     
- Misses       1827     1831       +4     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@prek-ci-bot

prek-ci-bot Bot commented Jul 24, 2026

Copy link
Copy Markdown

📦 Cargo Bloat Comparison

Binary size change: +0.00% (29.3 MiB → 29.3 MiB)

Expand for cargo-bloat output

Head Branch Results

 File  .text     Size             Crate Name
 1.1%   2.3% 332.0KiB        aws_lc_sys aws_lc_0_42_0_aes_gcm_encrypt_avx512
 1.1%   2.3% 332.0KiB        aws_lc_sys aws_lc_0_42_0_aes_gcm_decrypt_avx512
 0.3%   0.6%  79.4KiB              prek <prek::cli::Command as clap_builder::derive::Subcommand>::augment_subcommands
 0.2%   0.4%  58.0KiB              prek <<prek::config::Config as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.2%   0.3%  49.4KiB annotate_snippets annotate_snippets::renderer::render::render
 0.2%   0.3%  48.3KiB              prek prek::run::{closure#0}
 0.1%   0.3%  39.8KiB              prek prek::cli::run::run::run::{closure#0}
 0.1%   0.2%  34.2KiB              prek <prek::cli::RunOptions as clap_builder::derive::Args>::augment_args
 0.1%   0.2%  30.1KiB     granit_parser <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
 0.1%   0.2%  29.3KiB              prek <<prek::config::RemoteHook as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.1%   0.2%  28.6KiB    cargo_metadata <&mut serde_json::de::Deserializer<serde_json::read::StrRead> as serde_core::de::Deserializer>::deserialize_struct::<<cargo_metadata::Package as serde_core::de::Deserialize>::deserialize::__Visitor>
 0.1%   0.2%  28.0KiB        aws_lc_sys aws_lc_0_42_0_edwards25519_scalarmuldouble_alt
 0.1%   0.2%  27.5KiB        aws_lc_sys aws_lc_0_42_0_edwards25519_scalarmuldouble
 0.1%   0.2%  26.2KiB              prek <prek::languages::bun::bun::Bun as prek::languages::LanguageBackend>::install::{closure#0}
 0.1%   0.2%  25.6KiB              prek prek::cli::try_repo::try_repo::{closure#0}
 0.1%   0.2%  25.6KiB              prek <<prek::config::LocalHook as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.1%   0.2%  25.2KiB              prek <<prek::config::UpdateOptions as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.1%   0.2%  24.9KiB               xml <xml::reader::parser::PullParser>::dispatch_token
 0.1%   0.2%  24.5KiB              prek <prek::languages::node::installer::NodeInstaller>::install::{closure#0}
 0.1%   0.2%  24.0KiB     granit_parser <granit_parser::scanner::Scanner<serde_saphyr::de::buffered_input::ReaderInput>>::fetch_more_tokens
42.3%  88.2%  12.4MiB                   And 25987 smaller methods. Use -n N to show more.
47.9% 100.0%  14.1MiB                   .text section size, the file size is 29.3MiB

Base Branch Results

 File  .text     Size             Crate Name
 1.1%   2.3% 332.0KiB        aws_lc_sys aws_lc_0_42_0_aes_gcm_encrypt_avx512
 1.1%   2.3% 332.0KiB        aws_lc_sys aws_lc_0_42_0_aes_gcm_decrypt_avx512
 0.2%   0.5%  65.6KiB              prek <prek::cli::Command as clap_builder::derive::Subcommand>::augment_subcommands
 0.2%   0.4%  55.5KiB              prek <<prek::config::Config as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.2%   0.3%  49.4KiB annotate_snippets annotate_snippets::renderer::render::render
 0.1%   0.3%  39.0KiB              prek prek::cli::run::run::run::{closure#0}
 0.1%   0.3%  37.8KiB              prek prek::run::{closure#0}
 0.1%   0.2%  34.3KiB              prek <prek::cli::RunOptions as clap_builder::derive::Args>::augment_args
 0.1%   0.2%  30.1KiB     granit_parser <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
 0.1%   0.2%  28.1KiB              prek <<prek::config::RemoteHook as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.1%   0.2%  28.0KiB        aws_lc_sys aws_lc_0_42_0_edwards25519_scalarmuldouble_alt
 0.1%   0.2%  27.5KiB        aws_lc_sys aws_lc_0_42_0_edwards25519_scalarmuldouble
 0.1%   0.2%  25.8KiB              prek prek::cli::try_repo::try_repo::{closure#0}
 0.1%   0.2%  24.9KiB               xml <xml::reader::parser::PullParser>::dispatch_token
 0.1%   0.2%  24.8KiB              prek <<prek::config::LocalHook as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.1%   0.2%  24.6KiB              prek <prek::languages::node::installer::NodeInstaller>::install::{closure#0}
 0.1%   0.2%  24.4KiB              prek prek::cli::update::update::{closure#0}
 0.1%   0.2%  24.4KiB              prek <<prek::config::UpdateOptions as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<<serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
 0.1%   0.2%  24.0KiB     granit_parser <granit_parser::scanner::Scanner<serde_saphyr::de::buffered_input::ReaderInput>>::fetch_more_tokens
 0.1%   0.2%  23.3KiB              prek prek::archive::unzip::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
42.4%  88.4%  12.4MiB                   And 25980 smaller methods. Use -n N to show more.
47.9% 100.0%  14.0MiB                   .text section size, the file size is 29.3MiB

@prek-ci-bot

prek-ci-bot Bot commented Jul 24, 2026

Copy link
Copy Markdown

⚡️ Hyperfine Benchmarks

Summary: 1 regressions, 0 improvements above the 10% threshold.

Environment
  • OS: Linux 6.17.0-1020-azure
  • CPU: 4 cores
  • prek version: prek 0.4.10+36 (ec1007d 2026-07-24)
  • Rust version: rustc 1.97.1 (8bab26f4f 2026-07-14)
  • Hyperfine version: hyperfine 1.20.0
CLI Commands

Benchmarking basic commands in the main repo:

prek --version

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base --version 2.3 ± 0.1 2.1 2.6 1.06 ± 0.06
prek-head --version 2.1 ± 0.1 2.0 2.4 1.00

prek list

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base list 9.3 ± 0.1 9.0 9.6 1.01 ± 0.03
prek-head list 9.2 ± 0.2 8.9 10.4 1.00

prek validate-config .pre-commit-config.yaml

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base validate-config .pre-commit-config.yaml 3.1 ± 0.1 3.0 3.3 1.01 ± 0.02
prek-head validate-config .pre-commit-config.yaml 3.1 ± 0.0 3.0 3.2 1.00

prek sample-config

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base sample-config 2.5 ± 0.1 2.4 2.6 1.01 ± 0.04
prek-head sample-config 2.4 ± 0.1 2.3 2.9 1.00
Cold vs Warm Runs

Comparing first run (cold) vs subsequent runs (warm cache):

prek run --all-files (cold - no cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 64.0 ± 1.4 62.0 66.3 1.00
prek-head run --all-files 64.1 ± 0.6 63.3 65.3 1.00 ± 0.02

prek run --all-files (warm - with cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 64.3 ± 1.0 62.8 66.5 1.00
prek-head run --all-files 64.5 ± 1.2 62.0 66.3 1.00 ± 0.02
Full Hook Suite

Running the builtin hook suite on the benchmark workspace:

prek run --all-files (full builtin hook suite)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 63.7 ± 1.2 60.3 67.2 1.00
prek-head run --all-files 63.8 ± 1.0 62.1 67.0 1.00 ± 0.02
Individual Hook Performance

Benchmarking each hook individually on the test repo:

prek run trailing-whitespace --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run trailing-whitespace --all-files 19.5 ± 0.3 19.0 20.4 1.01 ± 0.03
prek-head run trailing-whitespace --all-files 19.2 ± 0.4 18.6 20.4 1.00

prek run end-of-file-fixer --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run end-of-file-fixer --all-files 19.2 ± 0.8 18.1 21.1 1.01 ± 0.05
prek-head run end-of-file-fixer --all-files 19.1 ± 0.5 18.4 20.8 1.00

prek run check-json --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-json --all-files 7.5 ± 0.2 7.2 8.1 1.00 ± 0.04
prek-head run check-json --all-files 7.5 ± 0.2 7.2 8.1 1.00

prek run check-yaml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-yaml --all-files 7.4 ± 0.2 7.1 7.8 1.02 ± 0.03
prek-head run check-yaml --all-files 7.3 ± 0.2 7.0 7.8 1.00

prek run check-toml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-toml --all-files 7.6 ± 0.3 7.0 8.5 1.03 ± 0.06
prek-head run check-toml --all-files 7.3 ± 0.2 6.9 7.8 1.00

prek run check-xml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-xml --all-files 7.4 ± 0.5 6.9 9.3 1.00
prek-head run check-xml --all-files 7.6 ± 0.4 7.2 8.9 1.03 ± 0.09

prek run detect-private-key --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run detect-private-key --all-files 10.7 ± 0.6 10.0 12.1 1.00
prek-head run detect-private-key --all-files 11.1 ± 0.7 9.8 12.2 1.04 ± 0.08

prek run fix-byte-order-marker --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run fix-byte-order-marker --all-files 17.4 ± 0.7 16.2 18.8 1.00 ± 0.06
prek-head run fix-byte-order-marker --all-files 17.3 ± 0.8 15.8 18.6 1.00
Installation Performance

Benchmarking hook installation (fast path hooks skip Python setup):

prek install-hooks (cold - no cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base install-hooks 4.4 ± 0.1 4.4 4.5 1.01 ± 0.02
prek-head install-hooks 4.4 ± 0.1 4.3 4.5 1.00

prek install-hooks (warm - with cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base install-hooks 4.5 ± 0.2 4.3 4.8 1.03 ± 0.05
prek-head install-hooks 4.3 ± 0.1 4.3 4.4 1.00
File Filtering/Scoping Performance

Testing different file selection modes:

prek run (staged files only)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run 35.3 ± 0.4 34.7 36.4 1.00
prek-head run 35.5 ± 0.3 34.8 36.2 1.01 ± 0.01

prek run --files '*.json' (specific file type)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --files '*.json' 7.8 ± 0.1 7.7 8.0 1.00 ± 0.02
prek-head run --files '*.json' 7.7 ± 0.1 7.6 7.9 1.00
Workspace Discovery & Initialization

Benchmarking hook discovery and initialization overhead:

prek run --dry-run --all-files (measures init overhead)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --dry-run --all-files 6.7 ± 0.1 6.6 6.9 1.02 ± 0.01
prek-head run --dry-run --all-files 6.6 ± 0.0 6.5 6.7 1.00
Meta Hooks Performance

Benchmarking meta hooks separately:

prek run check-hooks-apply --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-hooks-apply --all-files 11.7 ± 0.1 11.6 11.8 1.00
prek-head run check-hooks-apply --all-files 32.0 ± 44.9 10.3 139.4 2.74 ± 3.85

⚠️ Warning: Performance regression for prek run check-hooks-apply --all-files: 174.3300% slower

prek run check-useless-excludes --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-useless-excludes --all-files 10.4 ± 0.1 10.2 10.6 1.00
prek-head run check-useless-excludes --all-files 10.4 ± 0.1 10.3 10.7 1.01 ± 0.01

prek run identity --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run identity --all-files 9.7 ± 0.1 9.6 9.9 1.01 ± 0.01
prek-head run identity --all-files 9.6 ± 0.1 9.4 9.8 1.00

@j178 j178 added the enhancement New feature or request label Jul 24, 2026
@j178
j178 force-pushed the agent/node-git-install branch from e360fb4 to 5f409d7 Compare July 24, 2026 14:58
@j178
j178 marked this pull request as ready for review July 24, 2026 15:00
Copilot AI review requested due to automatic review settings July 24, 2026 15:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@j178 j178 changed the title Fix Node hook preparation through Git installs Prepare Node hook through git installs Jul 24, 2026
@j178 j178 changed the title Prepare Node hook through git installs Install Node hooks through git url Jul 24, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5f409d7fc8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/prek/src/languages/node/node.rs
Copilot AI review requested due to automatic review settings July 24, 2026 15:19
@j178
j178 force-pushed the agent/node-git-install branch from 5f409d7 to b184d9b Compare July 24, 2026 15:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b184d9b12e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/prek/src/languages/node/node.rs
Copilot AI review requested due to automatic review settings July 24, 2026 15:34
@j178
j178 force-pushed the agent/node-git-install branch from b184d9b to 875112d Compare July 24, 2026 15:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 875112d48e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/prek/src/languages/node/node.rs
@j178
j178 merged commit 3b8b5c5 into master Jul 24, 2026
37 checks passed
@j178
j178 deleted the agent/node-git-install branch July 24, 2026 15:42
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |
| `rumdl` | `0.2.36` → `0.2.43` | `0.2.36` → `0.2.43` |
| `tombi` | `1.2.3` → `1.2.4` | `1.2.3` → `1.2.4` |
| `uv` | `latest` → `latest` | `0.11.29` → `0.11.32` |
| `zizmor` | `latest` → `latest` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (5 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>
<details>
<summary>rumdl: `0.2.36` → `0.2.43` (rvben/rumdl)</summary>

### v0.2.37

### Added

- **reflow**: add atomic_spans configuration and refactor inline wrapping (#742) ([aeabec1](rvben/rumdl@aeabec1))

### Changed

- **BREAKING**: the MD013 `emphasis-spans` option is renamed to `atomic-spans` (default `true`), with inverted meaning (`emphasis-spans = true` is now `atomic-spans = false`). Configs setting the old key should migrate; it is no longer recognized

### Fixed

- **reflow**: keep code spans atomic when wrapping would collapse whitespace ([d43618b](rvben/rumdl@d43618b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/rel… (truncated)

### v0.2.38

### Added

- **md044**: add ignore-frontmatter-fields option ([b664e5a](rvben/rumdl@b664e5a))
- **config**: warn when an inline enable cannot re-enable a config-disabled rule ([a74a923](rvben/rumdl@a74a923))

### Fixed

- **md044**: stop flagging proper names inside frontmatter file paths ([35649d9](rvben/rumdl@35649d9))
- **md022**: stop panicking when one blank-line requirement is unlimited ([8a25eb2](rvben/rumdl@8a25eb2))
- **config**: report unknown option keys in inline configure-file comments ([8f4c0ea](rvben/rumdl@8f4c0ea))
- **config**: apply markdownlint-configure-file when the comment spans lines ([7a023a5](rvben/rumdl@7a023a5))
- **config**: honor booleans and alias keys in markdownlint-configure-file (#745) ([acefc19](rvben/rumdl@acefc19))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unkn… (truncated)

### v0.2.39

### Added

- **config**: expand ~ to the home directory in path settings ([70f91aa](rvben/rumdl@70f91aa))

### Fixed

- **md013**: wrap over-long emphasis spans that contain nested markup ([ddc73f4](rvben/rumdl@ddc73f4))
- **discovery**: strip Windows verbatim prefix from canonicalized paths ([a85ab87](rvben/rumdl@a85ab87))
- **discovery**: apply absolute exclude patterns during directory discovery ([0d20fc8](rvben/rumdl@0d20fc8))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-apple-darw… (truncated)

### v0.2.40

### Fixed

- **md003**: consume the setext underline when converting a heading to ATX. Converting a setext heading left the underline behind, where a following blank line turned it into a thematic break, so `rumdl fmt` added a horizontal rule the document never had ([7363c34](rvben/rumdl@7363c34))
- **md077**: stop scoping list items inside blockquotes, which made a lazy continuation line gain indentation on every pass so the formatter never converged ([58fb25b](rvben/rumdl@58fb25b))
- **reflow**: keep wiki links, shortcodes and math whole inside a wrapped span ([db12c2c](rvben/rumdl@db12c2c))
- **config**: honor the documented MD033 `table_allowed` alias, which silently dropped the configured value ([db2c204](rvben/rumdl@db2c204))
- **config**: stop reporting MD013's documented `semantic-link-understanding` alias as an unknown option ([1539a64](rvben/rumdl@1539a64))
- **parity**: make the markdownlint comparison harness actually run ([182763c](rvben/rumdl@182763c))

### Documentation

- **md013**: document that `ignore-link-urls` affects reporting only. Reflow measures the markdown as written, matching prettier and mdformat ([c4f8bad](rvben/rumdl@c4f8bad))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.40-x86_64-u… (truncated)

### v0.2.41

### Added

- **flavor**: add Hugo flavor and skip block attribute lists in blanks-around rules ([e6bb033](rvben/rumdl@e6bb033))

### Fixed

- **md044**: recognize indented HTML comments so links and code escape the rule ([3d6191c](rvben/rumdl@3d6191c))
- **md013**: keep an attr list whole inside a wrapped span ([e06f03d](rvben/rumdl@e06f03d))
- **md013**: keep a reference-style link whole inside a wrapped span ([de42709](rvben/rumdl@de42709))
- **md013**: wrap an over-long span whose whole content is another span ([f6c7c9c](rvben/rumdl@f6c7c9c))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz) | Linux… (truncated)

### v0.2.42

### Added

- **mojibake**: new rule MD083 for mojibake detection (#753) ([552842b](rvben/rumdl@552842b))

### Fixed

- **lint_context**: prevent panic when HTML tag window splits a UTF-8 char ([d14b252](rvben/rumdl@d14b252))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/relea… (truncated)

### v0.2.43

### Added

- **invisiblechars**: new rule MD084 for detecting invisible characters (#758) ([0a6354a](rvben/rumdl@0a6354a))

### Fixed

- **md084**: treat a zero width joiner between visible characters as presentation ([4fbb1cc](rvben/rumdl@4fbb1cc))
- **md084**: keep attached variation selectors in consecutive-character detection ([f4e9fd3](rvben/rumdl@f4e9fd3))
- **md084**: don't flag variation selectors attached to a base character ([14941bb](rvben/rumdl@14941bb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz.sha256)… (truncated)

</details>
<details>
<summary>tombi: `1.2.3` → `1.2.4` (tombi-toml/tombi)</summary>

### v1.2.4

<!-- Release notes generated using configuration in .github/release.yml at v1.2.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(date-time): accept leap second 60 in date-time values by @​LordAizen1 in tombi-toml/tombi#2024

## New Contributors
* @​LordAizen1 made their first contribution in tombi-toml/tombi#2024

**Full Changelog**: tombi-toml/tombi@v1.2.3...v1.2.4

</details>
<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>
<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |
| `rumdl` | `0.2.36` → `0.2.43` | `0.2.36` → `0.2.43` |
| `tombi` | `1.2.3` → `1.2.4` | `1.2.3` → `1.2.4` |
| `uv` | `latest` → `latest` | `0.11.29` → `0.11.32` |
| `zizmor` | `latest` → `latest` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (5 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>
<details>
<summary>rumdl: `0.2.36` → `0.2.43` (rvben/rumdl)</summary>

### v0.2.37

### Added

- **reflow**: add atomic_spans configuration and refactor inline wrapping (#742) ([aeabec1](rvben/rumdl@aeabec1))

### Changed

- **BREAKING**: the MD013 `emphasis-spans` option is renamed to `atomic-spans` (default `true`), with inverted meaning (`emphasis-spans = true` is now `atomic-spans = false`). Configs setting the old key should migrate; it is no longer recognized

### Fixed

- **reflow**: keep code spans atomic when wrapping would collapse whitespace ([d43618b](rvben/rumdl@d43618b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/rel… (truncated)

### v0.2.38

### Added

- **md044**: add ignore-frontmatter-fields option ([b664e5a](rvben/rumdl@b664e5a))
- **config**: warn when an inline enable cannot re-enable a config-disabled rule ([a74a923](rvben/rumdl@a74a923))

### Fixed

- **md044**: stop flagging proper names inside frontmatter file paths ([35649d9](rvben/rumdl@35649d9))
- **md022**: stop panicking when one blank-line requirement is unlimited ([8a25eb2](rvben/rumdl@8a25eb2))
- **config**: report unknown option keys in inline configure-file comments ([8f4c0ea](rvben/rumdl@8f4c0ea))
- **config**: apply markdownlint-configure-file when the comment spans lines ([7a023a5](rvben/rumdl@7a023a5))
- **config**: honor booleans and alias keys in markdownlint-configure-file (#745) ([acefc19](rvben/rumdl@acefc19))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unkn… (truncated)

### v0.2.39

### Added

- **config**: expand ~ to the home directory in path settings ([70f91aa](rvben/rumdl@70f91aa))

### Fixed

- **md013**: wrap over-long emphasis spans that contain nested markup ([ddc73f4](rvben/rumdl@ddc73f4))
- **discovery**: strip Windows verbatim prefix from canonicalized paths ([a85ab87](rvben/rumdl@a85ab87))
- **discovery**: apply absolute exclude patterns during directory discovery ([0d20fc8](rvben/rumdl@0d20fc8))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-apple-darw… (truncated)

### v0.2.40

### Fixed

- **md003**: consume the setext underline when converting a heading to ATX. Converting a setext heading left the underline behind, where a following blank line turned it into a thematic break, so `rumdl fmt` added a horizontal rule the document never had ([7363c34](rvben/rumdl@7363c34))
- **md077**: stop scoping list items inside blockquotes, which made a lazy continuation line gain indentation on every pass so the formatter never converged ([58fb25b](rvben/rumdl@58fb25b))
- **reflow**: keep wiki links, shortcodes and math whole inside a wrapped span ([db12c2c](rvben/rumdl@db12c2c))
- **config**: honor the documented MD033 `table_allowed` alias, which silently dropped the configured value ([db2c204](rvben/rumdl@db2c204))
- **config**: stop reporting MD013's documented `semantic-link-understanding` alias as an unknown option ([1539a64](rvben/rumdl@1539a64))
- **parity**: make the markdownlint comparison harness actually run ([182763c](rvben/rumdl@182763c))

### Documentation

- **md013**: document that `ignore-link-urls` affects reporting only. Reflow measures the markdown as written, matching prettier and mdformat ([c4f8bad](rvben/rumdl@c4f8bad))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.40-x86_64-u… (truncated)

### v0.2.41

### Added

- **flavor**: add Hugo flavor and skip block attribute lists in blanks-around rules ([e6bb033](rvben/rumdl@e6bb033))

### Fixed

- **md044**: recognize indented HTML comments so links and code escape the rule ([3d6191c](rvben/rumdl@3d6191c))
- **md013**: keep an attr list whole inside a wrapped span ([e06f03d](rvben/rumdl@e06f03d))
- **md013**: keep a reference-style link whole inside a wrapped span ([de42709](rvben/rumdl@de42709))
- **md013**: wrap an over-long span whose whole content is another span ([f6c7c9c](rvben/rumdl@f6c7c9c))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz) | Linux… (truncated)

### v0.2.42

### Added

- **mojibake**: new rule MD083 for mojibake detection (#753) ([552842b](rvben/rumdl@552842b))

### Fixed

- **lint_context**: prevent panic when HTML tag window splits a UTF-8 char ([d14b252](rvben/rumdl@d14b252))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/relea… (truncated)

### v0.2.43

### Added

- **invisiblechars**: new rule MD084 for detecting invisible characters (#758) ([0a6354a](rvben/rumdl@0a6354a))

### Fixed

- **md084**: treat a zero width joiner between visible characters as presentation ([4fbb1cc](rvben/rumdl@4fbb1cc))
- **md084**: keep attached variation selectors in consecutive-character detection ([f4e9fd3](rvben/rumdl@f4e9fd3))
- **md084**: don't flag variation selectors attached to a base character ([14941bb](rvben/rumdl@14941bb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz.sha256)… (truncated)

</details>
<details>
<summary>tombi: `1.2.3` → `1.2.4` (tombi-toml/tombi)</summary>

### v1.2.4

<!-- Release notes generated using configuration in .github/release.yml at v1.2.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(date-time): accept leap second 60 in date-time values by @​LordAizen1 in tombi-toml/tombi#2024

## New Contributors
* @​LordAizen1 made their first contribution in tombi-toml/tombi#2024

**Full Changelog**: tombi-toml/tombi@v1.2.3...v1.2.4

</details>
<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>
<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `prek`

Command: `mise upgrade --bump --local prek`

<details>
<summary>Version changelog (prek)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants