chore(deps): update ⬆️ mise-packages - #1025
Conversation
Renovate Release NotesGenerated from Renovate's update table by the Packages that cannot be summarized from GitHub releases are listed explicitly below. LuaLS/lua-language-server (aqua:LuaLS/lua-language-server)3.19.1: 3.19.1What's Changed
Full Changelog: LuaLS/lua-language-server@3.19.0...3.19.1 aquasecurity/trivy (aqua:aquasecurity/trivy)v0.74.0: v0.74.0⚡ Highlights ⚡Changeloghttps://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0740-2026-08-14 astral-sh/ruff (aqua:astral-sh/ruff)0.16.3: 0.16.3Release NotesReleased on 2026-08-13. Preview features
Bug fixes
Rule changes
Performance
CLI
Documentation
Other changes
Contributors
Install ruff 0.16.3Install prebuilt binaries via shell scriptcurl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.3/ruff-installer.sh | shInstall prebuilt binaries via powershell scriptpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.3/ruff-installer.ps1 | iex"Download ruff 0.16.3Verifying GitHub Artifact AttestationsThe artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI: gh attestation verify <file-path of downloaded artifact> --repo astral-sh/ruffYou can also download the attestation from GitHub and verify against that directly: gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>astral-sh/uv (aqua:astral-sh/uv)0.12.5: 0.12.5Release NotesReleased on 2026-08-14. Python
Enhancements
Preview features
Bug fixes
Install uv 0.12.5Install prebuilt binaries via shell scriptcurl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.sh | shInstall prebuilt binaries via powershell scriptpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.5/uv-installer.ps1 | iex"Download uv 0.12.5Verifying GitHub Artifact AttestationsThe artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI: gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly: gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.12.4: 0.12.4Release NotesReleased on 2026-08-13. Enhancements
Preview features
Performance
Bug fixes
Install uv 0.12.4Install prebuilt binaries via shell scriptcurl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.4/uv-installer.sh | shInstall prebuilt binaries via powershell scriptpowershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.4/uv-installer.ps1 | iex"Download uv 0.12.4Verifying GitHub Artifact AttestationsThe artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI: gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uvYou can also download the attestation from GitHub and verify against that directly: gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>borghei/ink (aqua:borghei/ink)v0.7.0: v0.7.0What's Changed
New Contributors
Full Changelog: borghei/ink@v0.6.7...v0.7.0 earendil-works/pi (aqua:earendil-works/pi)v0.84.2: v0.84.2New Features
Added
Changed
Fixed
fastfetch-cli/fastfetch (aqua:fastfetch-cli/fastfetch)2.67.1: 2.67.1Bugfixes:
Features:
SHA256SUMsSHA512SUMsgoogle/osv-scanner (aqua:google/osv-scanner)v2.5.1: v2.5.1What's ChangedFixes:
Full Changelog: google/osv-scanner@v2.5.0...v2.5.1 |
helm/helm (aqua:helm/helm)v4.2.4: Helm v4.2.4Helm v4.2.4 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there!
Notable Changes
Installation and UpgradingDownload Helm v4.2.4. The common platform binaries are here:
This release was signed with The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with What's Next
Changelog
Full Changelog: helm/helm@v4.2.3...v4.2.4 junegunn/fzf (aqua:junegunn/fzf)v0.74.3: 0.74.3
nushell/nushell (aqua:nushell/nushell)0.115.0: 0.115.0This is the 0.115.0 release of Nushell. You can learn more about this release here: https://www.nushell.sh/blog/2026-08-15-nushell_v0_115_0.html For convenience, we are providing full builds for Windows, Linux, and macOS. Be sure you have the requirements to enable all capabilities: https://www.nushell.sh/book/installation.html#dependencies This release was made possible by PR contributions from @ahmojo, @aionescu, @Alb-O, @alerque, @app/dependabot, @ayax79, @Bahex, @brandondong, @cablehead, @cacdu, @coyaSONG, @cpea2506, @cptpiepmatz, @danielcadev, @dmatos2012, @drbrain, @fdncred, @hexbinoct, @ian-h-chamberlain, @jakobwsmnn, @Juhan280, @kobihikri, @kronberger-droid, @latent-9, @m-novotny, @Mrfiregem, @oh-summy, @pheenty, @philocalyst, @pyz4, @rabindra789, @rvhelden, @santhreal, @sid-6581, @skyrocket1643, @sylvestre, @Totara-thib, @Tyarel8, @xtqqczze, @ZayanKhan-12 snyk/cli (aqua:snyk/cli)v1.1306.4: v1.1306.41.1306.4 (2026-08-13)The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their Bug Fixes
suzuki-shunsuke/ghtkn (aqua:suzuki-shunsuke/ghtkn)v0.4.0: v0.4.0suzuki-shunsuke/ghtkn@v0.3.6...v0.4.0
|
backnotprop/plannotator (github:backnotprop/plannotator)v0.27.4: v0.27.4Follow @plannotator on X for updates Missed recent releases?
What's New in v0.27.4A Guided Review can now leave Plannotator. This release ships portable guide exports, share links on guides.show, and a guide CLI any agent can drive, alongside a favicon style switcher, jj support for Call Flow, GitLab artifact fixes in PR review, and a smoother call-flow Lens. Eighteen PRs, four from community contributors, two of them first-timers. Portable Guided Reviews and guides.showGuided Reviews used to live and die inside your review session. Now a guide has three ways out: Download it. Every guide gets a "Download portable guide" button that produces one HTML file containing the full guide and the diff it describes. It opens anywhere, renders exactly like the in-app guide with side-by-side diffs and per-section reviewed checkboxes, and needs no Plannotator install. The file stays small because it carries your content, not the renderer: the viewer loads from guides.show, pinned by filename and cryptographic checksum, so a tampered or wrong viewer never executes. Offline, the file degrades to a readable plain-text version of the guide. Share it. "Create share link" uploads the guide to guides.show and hands you a link anyone can open in a browser. Shares are end-to-end encrypted by default: the key lives in the URL fragment after the Author it from anywhere. The new Saved guides from v0.27.x load unchanged. The share service runs on Cloudflare with add-only, content-hashed viewer publishing and per-IP rate limiting on creation. Choose your favicon: Totman or the classic PThe browser-tab icon is now a setting. Appearance settings offer two styles with visual previews: Totman, the current mascot, and Classic P, the original Plannotator mark restored byte-for-byte from the pre-mascot era. The server remembers your choice and serves it directly, so tabs show the right icon from the first paint without flashing the default. Hosts that embed the published UI packages are unaffected unless they opt in.
Call Flow analysis on jj repositoriesCall Flow previously required a plain Git checkout. Reviews running on jj (Jujutsu) colocated repos now get the same changed-call-path analysis: the jj snapshot is resolved to the underlying Git objects and fed to the same CallDiff engine, with the same per-file Lens and dock views. Diff collection is untouched; this only extends where the analysis can run.
GitLab PR artifacts fetch reliably and more safelyReviewing GitLab merge requests with uploaded artifacts (screenshots, logs, design files) got a hardening pass. Uploads now fetch through the authenticated API with a strict rewrite that only touches real upload URLs, falls back to the original web route when a self-hosted GitLab predates the API route, maps 401/403 responses to a clear "run glab auth login" hint, and no longer serves HTML or JavaScript content types through the artifact proxy. A regression test pins the invariant that credentials never follow a cross-origin redirect.
The call-flow Lens stops fighting your scrollCommunity feedback within hours of trying Call Flow in Safari: the per-file Lens popover closed randomly mid-scroll and popped open for every badge that passed under the cursor. Three causes, three fixes: the Lens's internal scroll no longer chains to the page when momentum hits its edge (the chain moved the popup out from under a stationary pointer, which read as a random close and was worst under Safari rubber-banding); hover now has a 100ms intent delay so drive-by badges stay closed; and an in-flight page scroll holds any pending close until the scroll settles. Reported by Rustan (@acewhocares on X).
Additional Changes
Install / UpdatemacOS / Linux: curl -fsSL https://plannotator.ai/install.sh | bashWindows: irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: Run OpenCode: Clear cache and restart: rm -rf ~/.bun/install/cache/@​plannotatorWhat's Changed
New Contributors
ContributorsFour community authors shipped code in this release, two for the first time:
Full Changelog: backnotprop/plannotator@v0.27.3...v0.27.4 v0.27.3: v0.27.3Follow @plannotator on X for updates Missed recent releases?
What's New in v0.27.3One fix on top of v0.27.2. If you are coming from an earlier version, the full v0.27.2 notes follow below; v0.27.3 is that release plus: Folder annotate no longer freezes the session on large reposCommunity-reported within hours of v0.27.2: opening a folder annotate session on a repo with hundreds of directories could freeze the entire local server while the file-tree watcher ran its initial scan, and a browser reconnect rebuilt the watcher from scratch, so on big repos the freeze fed itself and file switching appeared permanently dead. The bug predates v0.27.2 by six releases; the reporter's repo was simply large enough to make it unbearable. Three changes close the whole class: the watcher now warms up off the request path, so the session answers immediately while the scan runs behind it; disconnects reuse the warm watcher for 30 seconds instead of rescanning, which breaks the freeze loop; and macOS and Windows now use the operating system's native recursive watcher, measured at about 3ms to start versus 9 seconds for the previous scan on a 228-directory repo. The regression test pins it: a nested 780-directory tree that blocked the server for 79 seconds before now answers in under one second, and that test runs in CI so this cannot quietly return. Reported by @abanoub-ashraf in #1313. This is also the first release whose pipeline publishes a CycloneDX SBOM and attests it alongside the existing build provenance. What's New in v0.27.2Plannotator now works on your phone. This release ships a full mobile experience for plan review, code review, and annotation, alongside a security hardening pass, a fix for Codex review jobs on current Codex CLI versions, a large folder-mode performance win, and configurable markdown extensions. Fourteen PRs, including a community fix from @leoreisdias and a community-requested feature from @sgiath. Plan and code review on phones and tabletsReview a plan from your couch. Approve a diff from the train. Plannotator's plan review, code review, and annotate surfaces now adapt to phones and tablets with a compact touch experience: full-width reading layouts, a full-screen navigator for files and contents, touch-safe comment composition that stays clear of the software keyboard, 44px touch targets, and safe-area-aware layouts that respect notches and home indicators. On iPhone Safari, plans use the browser's natural document scroll so the address bar collapses as you read. Desktop behavior is unchanged. The compact experience activates only on coarse-pointer devices at tablet widths and below, so a narrow desktop window keeps the workspace you know. Pair it with v0.27.0's This shipped as a five-part stack: viewport and safe-area foundation, keyboard-safe comment composition, touch and dialog primitives, the code review shell, and the plan shell. Codex review jobs work again on current Codex CLIsCodex CLI 0.147.0 removed the Note the floor this implies: Codex review jobs now require codex-cli 0.147.0 or newer. Older Codex CLIs do not recognize the new flag. Thanks to @tgenov for independently reporting the breakage and pushing on a read-only sandbox for review jobs, an idea now tracked in #1310.
Folder annotate opens in milliseconds on large reposOpening a folder annotate session initialized a file watcher across the entire
Annotate any markdown-like file with configurable extensionsLivebook notebooks, Quarto documents, and other markdown-dialect files were rejected by annotate because the accepted extensions were hardcoded. A new config-only setting registers extra extensions to treat as markdown: { "markdownExtensions": [".livemd"] }in
Security hardening across the supply chainFour security-focused changes landed in this cycle:
Additional Changes
Install / UpdatemacOS / Linux: curl -fsSL https://plannotator.ai/install.sh | bashWindows: irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: Run OpenCode: Clear cache and restart: rm -rf ~/.bun/install/cache/@​plannotatorWhat's Changed
CommunityThis release carries a lot of community fingerprints:
Full Changelog: backnotprop/plannotator@v0.27.2...v0.27.3 v0.27.2: v0.27.2Follow @plannotator on X for updates Missed recent releases?
What's New in v0.27.2Plannotator now works on your phone. This release ships a full mobile experience for plan review, code review, and annotation, alongside a security hardening pass, a fix for Codex review jobs on current Codex CLI versions, a large folder-mode performance win, and configurable markdown extensions. Fourteen PRs, including a community fix from @leoreisdias and a community-requested feature from @sgiath. Plan and code review on phones and tabletsReview a plan from your couch. Approve a diff from the train. Plannotator's plan review, code review, and annotate surfaces now adapt to phones and tablets with a compact touch experience: full-width reading layouts, a full-screen navigator for files and contents, touch-safe comment composition that stays clear of the software keyboard, 44px touch targets, and safe-area-aware layouts that respect notches and home indicators. On iPhone Safari, plans use the browser's natural document scroll so the address bar collapses as you read. Desktop behavior is unchanged. The compact experience activates only on coarse-pointer devices at tablet widths and below, so a narrow desktop window keeps the workspace you know. Pair it with v0.27.0's This shipped as a five-part stack: viewport and safe-area foundation, keyboard-safe comment composition, touch and dialog primitives, the code review shell, and the plan shell. Codex review jobs work again on current Codex CLIsCodex CLI 0.147.0 removed the Note the floor this implies: Codex review jobs now require codex-cli 0.147.0 or newer. Older Codex CLIs do not recognize the new flag. Thanks to @tgenov for independently reporting the breakage and pushing on a read-only sandbox for review jobs, an idea now tracked in #1310.
Folder annotate opens in milliseconds on large reposOpening a folder annotate session initialized a file watcher across the entire
Annotate any markdown-like file with configurable extensionsLivebook notebooks, Quarto documents, and other markdown-dialect files were rejected by annotate because the accepted extensions were hardcoded. A new config-only setting registers extra extensions to treat as markdown: { "markdownExtensions": [".livemd"] }in
Security hardening across the supply chainFour security-focused changes landed in this cycle:
Additional Changes
Install / UpdatemacOS / Linux: curl -fsSL https://plannotator.ai/install.sh | bashWindows: irm https://plannotator.ai/install.ps1 | iexClaude Code Plugin: Run OpenCode: Clear cache and restart: rm -rf ~/.bun/install/cache/@​plannotatorWhat's Changed
CommunityThis release carries a lot of community fingerprints:
Full Changelog: backnotprop/plannotator@v0.27.1...v0.27.2 janosmiko/lfk (github:janosmiko/lfk)v0.17.3: v0.17.30.17.3 (2026-08-17)Features
v0.17.2: v0.17.20.17.2 (2026-08-15)Bug Fixesv0.17.1: v0.17.10.17.1 (2026-08-14)Featuresmax-sixty/worktrunk (github:max-sixty/worktrunk)v0.74.0: 0.74.0Release NotesImproved
Fixed
Documentation
Internal
Install worktrunk 0.74.0Install prebuilt binaries via shell scriptcurl --proto '=https' --tlsv1.2 -LsSf https://github.com/max-sixty/worktrunk/releases/download/v0.74.0/worktrunk-installer.sh | sh && wt config shell installInstall prebuilt binaries via powershell scriptpowershell -ExecutionPolicy Bypass -c "irm https://github.com/max-sixty/worktrunk/releases/download/v0.74.0/worktrunk-installer.ps1 | iex"; git-wt config shell installInstall prebuilt binaries via Homebrewbrew install worktrunk && wt config shell installDownload worktrunk 0.74.0
Install via Cargocargo install worktrunk && wt config shell installInstall via Winget (Windows)winget install max-sixty.worktrunk && git-wt config shell installInstall via AUR (Arch Linux)paru worktrunk-bin && wt config shell installmodem-dev/hunk (github:modem-dev/hunk)v0.19.0: v0.19.0What's Changedhunk-v0.19.0-launch.mp4Highlights
Full Changelog: modem-dev/hunk@v0.18.2...v0.19.0 v0.18.2: v0.18.2What's Changed
Full Changelog: modem-dev/hunk@v0.18.1...v0.18.2 SocketDev/socket-cli (npm:socket)v1.1.158: v1.1.158What's Changed
Full Changelog: SocketDev/socket-cli@v1.1.157...v1.1.158 semgrep/semgrep (pipx:semgrep)v1.173.0: Release v1.173.01.173.0 - 2026-08-12### Added
### Changed
### Fixed
Skipped PackagesGitHub Release Notes Unavailable
|
This PR contains the following updates:
3.19.0→3.19.10.73.0→0.74.00.16.2→0.16.30.16.40.12.3→0.12.50.6.7→0.7.00.84.1→0.84.22.67.0→2.67.12.5.0→2.5.14.2.3→4.2.40.74.2→0.74.30.114.1→0.115.01.1306.3→1.1306.40.3.6→0.4.026.5.6→26.8.152.16.3→2.17.0v0.21.0→v0.22.0v0.23.1(+1)v2.1.231→v2.1.234v2.1.239(+4)v0.27.1→v0.27.4v0.27.6(+1)v0.17.0→v0.17.3v0.18.0(+2)v0.73.0→v0.74.0v0.18.1→v0.19.01.26.5→1.26.61.27.0(+1)1.1.412→1.1.4131.1.157→1.1.1582.3.0→2.3.11.172.0→1.173.01.174.0Release notes are maintained in a PR comment by the
renovate-release-notes-commentworkflow.Configuration
📅 Schedule: (in timezone America/Los_Angeles)
* 3-5 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.