Skip to content

github-env: don't flag all-literal printf arguments - #2201

Merged
woodruffw merged 5 commits into
mainfrom
ww/fix-2200
Jul 17, 2026
Merged

github-env: don't flag all-literal printf arguments#2201
woodruffw merged 5 commits into
mainfrom
ww/fix-2200

Conversation

@woodruffw

@woodruffw woodruffw commented Jul 16, 2026

Copy link
Copy Markdown
Member

WIP. See #2200.

@woodruffw woodruffw self-assigned this Jul 16, 2026
@woodruffw woodruffw added the bugfix Fixes a known bug label Jul 16, 2026
@woodruffw woodruffw changed the title github-env: don't flag all-literal insertions github-env: don't flag all-literal printf arguments Jul 17, 2026
@woodruffw
woodruffw marked this pull request as ready for review July 17, 2026 22:32
@woodruffw
woodruffw enabled auto-merge (squash) July 17, 2026 22:32
@woodruffw
woodruffw merged commit 82f5bf6 into main Jul 17, 2026
23 checks passed
@woodruffw
woodruffw deleted the ww/fix-2200 branch July 17, 2026 22:35
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `zizmor`

Command: `mise upgrade --bump --local zizmor`

<details>
<summary>Version changelog (zizmor)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `zizmor` | `1.27.0` → `1.28.0` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `zizmor`

Command: `mise upgrade --bump --local zizmor`

<details>
<summary>Version changelog (zizmor)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `zizmor` | `1.27.0` → `1.28.0` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `zizmor`

Command: `mise upgrade --bump --local zizmor`

<details>
<summary>Version changelog (zizmor)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `zizmor` | `1.27.0` → `1.28.0` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `zizmor`

Command: `mise upgrade --bump --local zizmor`

<details>
<summary>Version changelog (zizmor)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `zizmor` | `1.27.0` → `1.28.0` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |
| `rumdl` | `0.2.36` → `0.2.43` | `0.2.36` → `0.2.43` |
| `tombi` | `1.2.3` → `1.2.4` | `1.2.3` → `1.2.4` |
| `uv` | `latest` → `latest` | `0.11.29` → `0.11.32` |
| `zizmor` | `latest` → `latest` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (5 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>
<details>
<summary>rumdl: `0.2.36` → `0.2.43` (rvben/rumdl)</summary>

### v0.2.37

### Added

- **reflow**: add atomic_spans configuration and refactor inline wrapping (#742) ([aeabec1](rvben/rumdl@aeabec1))

### Changed

- **BREAKING**: the MD013 `emphasis-spans` option is renamed to `atomic-spans` (default `true`), with inverted meaning (`emphasis-spans = true` is now `atomic-spans = false`). Configs setting the old key should migrate; it is no longer recognized

### Fixed

- **reflow**: keep code spans atomic when wrapping would collapse whitespace ([d43618b](rvben/rumdl@d43618b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/rel… (truncated)

### v0.2.38

### Added

- **md044**: add ignore-frontmatter-fields option ([b664e5a](rvben/rumdl@b664e5a))
- **config**: warn when an inline enable cannot re-enable a config-disabled rule ([a74a923](rvben/rumdl@a74a923))

### Fixed

- **md044**: stop flagging proper names inside frontmatter file paths ([35649d9](rvben/rumdl@35649d9))
- **md022**: stop panicking when one blank-line requirement is unlimited ([8a25eb2](rvben/rumdl@8a25eb2))
- **config**: report unknown option keys in inline configure-file comments ([8f4c0ea](rvben/rumdl@8f4c0ea))
- **config**: apply markdownlint-configure-file when the comment spans lines ([7a023a5](rvben/rumdl@7a023a5))
- **config**: honor booleans and alias keys in markdownlint-configure-file (#745) ([acefc19](rvben/rumdl@acefc19))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unkn… (truncated)

### v0.2.39

### Added

- **config**: expand ~ to the home directory in path settings ([70f91aa](rvben/rumdl@70f91aa))

### Fixed

- **md013**: wrap over-long emphasis spans that contain nested markup ([ddc73f4](rvben/rumdl@ddc73f4))
- **discovery**: strip Windows verbatim prefix from canonicalized paths ([a85ab87](rvben/rumdl@a85ab87))
- **discovery**: apply absolute exclude patterns during directory discovery ([0d20fc8](rvben/rumdl@0d20fc8))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-apple-darw… (truncated)

### v0.2.40

### Fixed

- **md003**: consume the setext underline when converting a heading to ATX. Converting a setext heading left the underline behind, where a following blank line turned it into a thematic break, so `rumdl fmt` added a horizontal rule the document never had ([7363c34](rvben/rumdl@7363c34))
- **md077**: stop scoping list items inside blockquotes, which made a lazy continuation line gain indentation on every pass so the formatter never converged ([58fb25b](rvben/rumdl@58fb25b))
- **reflow**: keep wiki links, shortcodes and math whole inside a wrapped span ([db12c2c](rvben/rumdl@db12c2c))
- **config**: honor the documented MD033 `table_allowed` alias, which silently dropped the configured value ([db2c204](rvben/rumdl@db2c204))
- **config**: stop reporting MD013's documented `semantic-link-understanding` alias as an unknown option ([1539a64](rvben/rumdl@1539a64))
- **parity**: make the markdownlint comparison harness actually run ([182763c](rvben/rumdl@182763c))

### Documentation

- **md013**: document that `ignore-link-urls` affects reporting only. Reflow measures the markdown as written, matching prettier and mdformat ([c4f8bad](rvben/rumdl@c4f8bad))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.40-x86_64-u… (truncated)

### v0.2.41

### Added

- **flavor**: add Hugo flavor and skip block attribute lists in blanks-around rules ([e6bb033](rvben/rumdl@e6bb033))

### Fixed

- **md044**: recognize indented HTML comments so links and code escape the rule ([3d6191c](rvben/rumdl@3d6191c))
- **md013**: keep an attr list whole inside a wrapped span ([e06f03d](rvben/rumdl@e06f03d))
- **md013**: keep a reference-style link whole inside a wrapped span ([de42709](rvben/rumdl@de42709))
- **md013**: wrap an over-long span whose whole content is another span ([f6c7c9c](rvben/rumdl@f6c7c9c))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz) | Linux… (truncated)

### v0.2.42

### Added

- **mojibake**: new rule MD083 for mojibake detection (#753) ([552842b](rvben/rumdl@552842b))

### Fixed

- **lint_context**: prevent panic when HTML tag window splits a UTF-8 char ([d14b252](rvben/rumdl@d14b252))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/relea… (truncated)

### v0.2.43

### Added

- **invisiblechars**: new rule MD084 for detecting invisible characters (#758) ([0a6354a](rvben/rumdl@0a6354a))

### Fixed

- **md084**: treat a zero width joiner between visible characters as presentation ([4fbb1cc](rvben/rumdl@4fbb1cc))
- **md084**: keep attached variation selectors in consecutive-character detection ([f4e9fd3](rvben/rumdl@f4e9fd3))
- **md084**: don't flag variation selectors attached to a base character ([14941bb](rvben/rumdl@14941bb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz.sha256)… (truncated)

</details>
<details>
<summary>tombi: `1.2.3` → `1.2.4` (tombi-toml/tombi)</summary>

### v1.2.4

<!-- Release notes generated using configuration in .github/release.yml at v1.2.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(date-time): accept leap second 60 in date-time values by @​LordAizen1 in tombi-toml/tombi#2024

## New Contributors
* @​LordAizen1 made their first contribution in tombi-toml/tombi#2024

**Full Changelog**: tombi-toml/tombi@v1.2.3...v1.2.4

</details>
<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>
<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Jul 27, 2026
Automated mise tool upgrades from local config.

Updated tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (5 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.4.10` → `0.4.11` | `0.4.10` → `0.4.11` |
| `rumdl` | `0.2.36` → `0.2.43` | `0.2.36` → `0.2.43` |
| `tombi` | `1.2.3` → `1.2.4` | `1.2.3` → `1.2.4` |
| `uv` | `latest` → `latest` | `0.11.29` → `0.11.32` |
| `zizmor` | `latest` → `latest` | `1.27.0` → `1.28.0` |

</details>

<details>
<summary>Release notes (5 tools)</summary>

<details>
<summary>prek: `0.4.10` → `0.4.11` (j178/prek)</summary>

### v0.4.11

## Release Notes

Released on 2026-07-25.

### Highlights

- This release adds two new builtin hooks, `deny-pattern` and `require-pattern`,
  as native alternatives for `pygrep` use cases. `deny-pattern` fails when a
  configured pattern is found, while `require-pattern` ensures every selected
  file contains a match. By matching natively without spawning a Python
  subprocess, they run over 4x faster than `pygrep` in benchmarks. Note that
  they use [Rust `regex` syntax](https://docs.rs/regex/latest/regex/#syntax), which does
  not support look-around features such as negative lookbehind.

- `prek run` now supports `--glob <PATTERN>` to run hooks on tracked files
  matching a glob. It can be repeated or combined with `--files` and
  `--directory`.

- Hook priorities now support reusable aliases:

    ```toml
    [priorities]
    checks = 10

    [[repos]]
    repo = "builtin"
    hooks = [
      { id = "check-json", priority = "checks" },
      { id = "check-yaml", priority = "checks" },
    ]
    ```

    This makes parallel scheduling easier to read and maintain.

### Enhancements

- Add `deny-pattern` and `require-pattern` builtin hooks ([#2359](j178/prek#2359))
- Support `--glob` patterns in `prek run` ([#2381](j178/prek#2381))
- Support reusable aliases for hook priorities ([#2331](j178/prek#2331))
- Implement `requirements-txt-fixer` as a builtin hook ([#2390](j178/prek#2390))
- Improve user-facing warnings and errors ([#2380](j178/prek#2380))
- Install Node hooks through git url ([#2394](j178/prek#2394))

### Performance

- Reduce blocking-pool overhead in file hooks ([#2384](j178/prek#2384))
- Speed up mixed-line-ending scans with memchr2 ([#2391](j178/prek#2391))

### Bug fixes

- Honor filenames in builti… (truncated)

</details>
<details>
<summary>rumdl: `0.2.36` → `0.2.43` (rvben/rumdl)</summary>

### v0.2.37

### Added

- **reflow**: add atomic_spans configuration and refactor inline wrapping (#742) ([aeabec1](rvben/rumdl@aeabec1))

### Changed

- **BREAKING**: the MD013 `emphasis-spans` option is renamed to `atomic-spans` (default `true`), with inverted meaning (`emphasis-spans = true` is now `atomic-spans = false`). Configs setting the old key should migrate; it is no longer recognized

### Fixed

- **reflow**: keep code spans atomic when wrapping would collapse whitespace ([d43618b](rvben/rumdl@d43618b))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.37-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/rel… (truncated)

### v0.2.38

### Added

- **md044**: add ignore-frontmatter-fields option ([b664e5a](rvben/rumdl@b664e5a))
- **config**: warn when an inline enable cannot re-enable a config-disabled rule ([a74a923](rvben/rumdl@a74a923))

### Fixed

- **md044**: stop flagging proper names inside frontmatter file paths ([35649d9](rvben/rumdl@35649d9))
- **md022**: stop panicking when one blank-line requirement is unlimited ([8a25eb2](rvben/rumdl@8a25eb2))
- **config**: report unknown option keys in inline configure-file comments ([8f4c0ea](rvben/rumdl@8f4c0ea))
- **config**: apply markdownlint-configure-file when the comment spans lines ([7a023a5](rvben/rumdl@7a023a5))
- **config**: honor booleans and alias keys in markdownlint-configure-file (#745) ([acefc19](rvben/rumdl@acefc19))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unkn… (truncated)

### v0.2.39

### Added

- **config**: expand ~ to the home directory in path settings ([70f91aa](rvben/rumdl@70f91aa))

### Fixed

- **md013**: wrap over-long emphasis spans that contain nested markup ([ddc73f4](rvben/rumdl@ddc73f4))
- **discovery**: strip Windows verbatim prefix from canonicalized paths ([a85ab87](rvben/rumdl@a85ab87))
- **discovery**: apply absolute exclude patterns during directory discovery ([0d20fc8](rvben/rumdl@0d20fc8))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.39/rumdl-v0.2.39-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.39-x86_64-apple-darw… (truncated)

### v0.2.40

### Fixed

- **md003**: consume the setext underline when converting a heading to ATX. Converting a setext heading left the underline behind, where a following blank line turned it into a thematic break, so `rumdl fmt` added a horizontal rule the document never had ([7363c34](rvben/rumdl@7363c34))
- **md077**: stop scoping list items inside blockquotes, which made a lazy continuation line gain indentation on every pass so the formatter never converged ([58fb25b](rvben/rumdl@58fb25b))
- **reflow**: keep wiki links, shortcodes and math whole inside a wrapped span ([db12c2c](rvben/rumdl@db12c2c))
- **config**: honor the documented MD033 `table_allowed` alias, which silently dropped the configured value ([db2c204](rvben/rumdl@db2c204))
- **config**: stop reporting MD013's documented `semantic-link-understanding` alias as an unknown option ([1539a64](rvben/rumdl@1539a64))
- **parity**: make the markdownlint comparison harness actually run ([182763c](rvben/rumdl@182763c))

### Documentation

- **md013**: document that `ignore-link-urls` affects reporting only. Reflow measures the markdown as written, matching prettier and mdformat ([c4f8bad](rvben/rumdl@c4f8bad))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.40/rumdl-v0.2.40-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.40-x86_64-u… (truncated)

### v0.2.41

### Added

- **flavor**: add Hugo flavor and skip block attribute lists in blanks-around rules ([e6bb033](rvben/rumdl@e6bb033))

### Fixed

- **md044**: recognize indented HTML comments so links and code escape the rule ([3d6191c](rvben/rumdl@3d6191c))
- **md013**: keep an attr list whole inside a wrapped span ([e06f03d](rvben/rumdl@e06f03d))
- **md013**: keep a reference-style link whole inside a wrapped span ([de42709](rvben/rumdl@de42709))
- **md013**: wrap an over-long span whose whole content is another span ([f6c7c9c](rvben/rumdl@f6c7c9c))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz) | Linux… (truncated)

### v0.2.42

### Added

- **mojibake**: new rule MD083 for mojibake detection (#753) ([552842b](rvben/rumdl@552842b))

### Fixed

- **lint_context**: prevent panic when HTML tag window splits a UTF-8 char ([d14b252](rvben/rumdl@d14b252))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.42-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz) | macOS x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256) |
| [rumdl-v0.2.42-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/relea… (truncated)

### v0.2.43

### Added

- **invisiblechars**: new rule MD084 for detecting invisible characters (#758) ([0a6354a](rvben/rumdl@0a6354a))

### Fixed

- **md084**: treat a zero width joiner between visible characters as presentation ([4fbb1cc](rvben/rumdl@4fbb1cc))
- **md084**: keep attached variation selectors in consecutive-character detection ([f4e9fd3](rvben/rumdl@f4e9fd3))
- **md084**: don't flag variation selectors attached to a base character ([14941bb](rvben/rumdl@14941bb))

## Downloads

| File | Platform | Checksum |
|------|----------|----------|
| [rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz) | Linux x86_64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz) | Linux x86_64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-x86_64-unknown-linux-musl.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz) | Linux ARM64 | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-gnu.tar.gz.sha256) |
| [rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz) | Linux ARM64 (musl) | [checksum](https://github.com/rvben/rumdl/releases/download/v0.2.43/rumdl-v0.2.43-aarch64-unknown-linux-musl.tar.gz.sha256)… (truncated)

</details>
<details>
<summary>tombi: `1.2.3` → `1.2.4` (tombi-toml/tombi)</summary>

### v1.2.4

<!-- Release notes generated using configuration in .github/release.yml at v1.2.4 -->

## What's Changed
### 🛠️ Other Changes
* fix(date-time): accept leap second 60 in date-time values by @​LordAizen1 in tombi-toml/tombi#2024

## New Contributors
* @​LordAizen1 made their first contribution in tombi-toml/tombi#2024

**Full Changelog**: tombi-toml/tombi@v1.2.3...v1.2.4

</details>
<details>
<summary>uv: `0.11.29` → `0.11.32` (astral-sh/uv)</summary>

### 0.11.30

## Release Notes

Released on 2026-07-20.

### Python

- Add CPython 3.15.0b4 ([#20519](astral-sh/uv#20519))

### Preview features

- Allow `uv workspace metadata --sync` to target the active virtual environment with `--active` ([#20500](astral-sh/uv#20500))
- Reuse centralized project environments when workspaces are accessed through symlinks ([#20436](astral-sh/uv#20436))

### Performance

- Skip resolver candidates whose files are all excluded by `exclude-newer` ([#20460](astral-sh/uv#20460))
- Limit parallel cache reads to reduce resolver scheduling and allocation overhead ([#20427](astral-sh/uv#20427))
- Accelerate lockfile serialization with `toml_writer` ([#20450](astral-sh/uv#20450))
- Compact cached Simple API distribution metadata and hashes ([#20463](astral-sh/uv#20463), [#20483](astral-sh/uv#20483))
- Decode stale cache entries in a single blocking task ([#20486](astral-sh/uv#20486))
- Decode cached payloads outside resolver workers ([#20464](astral-sh/uv#20464))
- Cache resolver Python requirement markers ([#20461](astral-sh/uv#20461))
- Reuse resolver fork markers while recording preferences ([#20462](astral-sh/uv#20462))

### Bug fixes

- Prevent skipped tar-wheel entries from causing unrelated files to be removed during uninstall ([#20429](astral-sh/uv#20429))
- Preserve literal `extends-environment` paths in `pyvenv.cfg` on Unix ([#20466](astral-sh/uv#20466))

### Documentation

- Add a contribution guide ([#20511](astral-sh/uv#20511), [#20552](astral-sh/uv#20552))

## Install uv 0.11.30

### Install prebuilt binaries via shell script

```sh
curl --proto '=htt… (truncated)

### 0.11.31

## Release Notes

Released on 2026-07-21.

### Enhancements

- Allow workspace sources to reference members in another workspace by path ([#18401](astral-sh/uv#18401))
- Support `.venv` files containing paths to centralized project environments ([#20022](astral-sh/uv#20022))
- Update bundled Windows timezone data to IANA 2026c ([#20554](astral-sh/uv#20554))

### Preview features

- Add an index-specific `hash-algorithm` setting for lockfile generation ([#20605](astral-sh/uv#20605))

### Configuration

- Add `audit.malware-check` and `audit.malware-check-url` settings ([#20587](astral-sh/uv#20587))

### Performance

- Avoid quadratic work when deduplicating transitive conflicts ([#20578](astral-sh/uv#20578))

### Bug fixes

- Suggest `--emit-build-options` for unsupported `uv pip compile --emit-options` ([#20582](astral-sh/uv#20582))
- Reject source distributions and wheels with mismatched package names ([#20432](astral-sh/uv#20432))
- Avoid retrying TLS certificate verification failures ([#16245](astral-sh/uv#16245))
- Avoid warnings about `uv_build` settings for in-tree build backends ([#20153](astral-sh/uv#20153))

## Install uv 0.11.31

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-installer.ps1 | iex"
```

## Download uv 0.11.31

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.31/uv-aarch64-apple-darwin.ta… (truncated)

### 0.11.32

## Release Notes

Released on 2026-07-23.

### Preview features

- Add `--package` and `--all-packages` selection to `uv check` ([#20628](astral-sh/uv#20628))
- Allow `uv upgrade` to update multiple marker-specific declarations of the same package ([#20335](astral-sh/uv#20335))
- Reject non-canonically formatted lockfiles in `uv lock --check` and commands using `--locked` ([#20646](astral-sh/uv#20646))
- Regenerate non-canonically formatted lockfiles with `uv lock --refresh` ([#20634](astral-sh/uv#20634))
- Include best-effort information about the active environment in `uv workspace metadata` by default ([#20643](astral-sh/uv#20643))

### Performance

- Skip dependency-group conflict expansion when no additional conflicts can be inferred ([#20611](astral-sh/uv#20611))

### Bug fixes

- Fork universal resolutions when `Requires-Python` is discovered only from distribution metadata ([#20586](astral-sh/uv#20586))

## Install uv 0.11.32

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-installer.ps1 | iex"
```

## Download uv 0.11.32

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.11.32/uv-x86_64-apple-darwin.tar.gz) | Intel… (truncated)

</details>
<details>
<summary>zizmor: `1.27.0` → `1.28.0` (zizmorcore/zizmor)</summary>

### v1.28.0

## Security 🔒[🔗](https://docs.zizmor.sh/release-notes/#security)

- v1.27.0 contained a logging defect that would print any configured GitHub credentials as part of zizmor's cleartext logging. No versions other than v1.27.0 were affected. See [GHSA-f42p-wjw5-97qh](GHSA-f42p-wjw5-97qh) for full information.

    Many thanks to [@​shaanmajid](https://github.com/shaanmajid) for finding and reporting this vulnerability.

## Enhancements 🌱[🔗](https://docs.zizmor.sh/release-notes/#enhancements)

- The JSON (v1) output format now includes metadata for each finding's fixes, if the finding has fixes ([#2186](zizmorcore/zizmor#2186))

- The [dependabot-cooldown](https://docs.zizmor.sh/audits/#dependabot-cooldown) audit is now aware of GitHub's new three-day default cooldown ([#2193](zizmorcore/zizmor#2193))

- sbt is now recognized as a package-ecosystem in dependabot.yml ([#2211](zizmorcore/zizmor#2211))

## Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where the [template-injection](https://docs.zizmor.sh/audits/#template-injection) audit would incorrectly flag `steps.*.outcome` and `steps.*.conclusion` as injection risks in the default persona ([#2199](zizmorcore/zizmor#2199))

- Fixed a bug where the [github-env](https://docs.zizmor.sh/audits/#github-env) audit would incorrectly flag some printf calls as exploitable ([#2201](zizmorcore/zizmor#2201))

- Fixed a bug where zizmor would produce a misleading and confusing error message when asked to audit an ambiguous remote input ([#2205](zizmorcore/zizmor#2205))

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes a known bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant