Skip to content

feat(schema): support JSON Schema compound documents with embedded $id - #2181

Merged
ya7010 merged 5 commits into
tombi-toml:mainfrom
ya7010:ya7010/support-json-schema-compound
Sep 13, 2026
Merged

ya7010 merged 5 commits into
tombi-toml:mainfrom
ya7010:ya7010/support-json-schema-compound

Conversation

@ya7010

@ya7010 ya7010 commented Sep 13, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • JSON Schema compound document 内の埋め込み $id resource を索引化し、文書内・文書間の重複 $id を fail-closed で拒否する
  • schema_document_uri / schema_resource_uri / schema_base_uri を分離し、store・validator・LSP(completion / hover / goto-type-definition)を追従
  • issue 🦅 Feature Request: Support JSON Schema Compound Schema Documents #2164 向け fixture と schema identity / diagnostic / completion / hover / goto の回帰テストを追加

Test plan

  • cargo test -p tombi-schema-store -p tombi-validator -p tombi-lsp -p tombi-formatter -p tombi-extension -p tombi-extension-cargo -p tombi-comment-directive-store --locked
  • 独立 review-quality レビュー(actionable findings 解消後 NONE)
  • CI 全チェック通過

Index embedded schema resources by $id, reject duplicates, and keep
schema_document_uri / schema_resource_uri / schema_base_uri distinct
across store, validator, and LSP.

Co-authored-by: Cursor <cursoragent@cursor.com>
Copilot AI lite review requested due to automatic review settings September 13, 2026 08:54
Co-authored-by: Cursor <cursoragent@cursor.com>
@ya7010 ya7010 added rust Pull requests that update rust code enhancement New feature or request labels Sep 13, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

SubSchemaLink and TableStrictAdditionalKeys need the fragment-bearing
instance URI so config-scoped strict overrides and diagnostics stay correct.

Co-authored-by: Cursor <cursoragent@cursor.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical schema-store defects and URI/resource-resolution issues remain.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (5)

crates/tombi-lsp/src/completion.rs:366

  • ここでも embedded resource の canonical $id を completion tooltip の Markdown URL にしています。get_schema_link_uri は shoko://... のような opaque scheme を変換しないため、completion から表示される Schema リンクが bundle 内の定義へ移動できなくなります。tooltip 用には schema_document_uri/store の source mapping を使い、canonical URI は識別情報として別に保持してください。
            tombi_extension::get_schema_link_uri(
                current_schema.schema_base_uri.as_ref(),
                current_schema.schema_view.range().start,
            )
            .into(),

crates/tombi-lsp/src/completion/schema_completion.rs:21

  • schema completion のリンク生成も canonical $id をそのまま Markdown URL にしています。embedded resource が shoko://... の場合、get_schema_link_uri は変換せず返すため、completion の Schema リンクはローカル compound document を開けません。completion 用の source link は物理 schema_document_uri に解決し、canonical URI は別途 identity として扱ってください。
    let schema_uri = tombi_extension::get_schema_link_uri(
        current_schema.schema_base_uri.as_ref(),
        current_schema.schema_view.range().start,

crates/tombi-lsp/src/hover.rs:78

  • embedded resource の canonical $id(例: shoko://...)をリンク先に渡していますが、get_schema_link_uri は tombi/HTTP 以外の URI をそのまま返すため、物理 bundle file を開けるリンクから opaque URI のリンクに変わります。Issue の前提どおり専用 URI handler が不要な構成では hover の Schema リンクが開けないため、canonical URI と source document URI を分け、表示リンクは store から物理 source に変換してください。
    crates/tombi-schema-store/src/schema/schema_document_resources.rs:315
  • $id の非空 fragment を dialect に関係なく None として扱っているため、Draft 7 で有効な fragment 付き $id(例: "#foo")が失われ、そこへの参照や従来の base/anchor semantics が解決できません。Draft 2019-09/2020-12 の resource 制約と Draft 7 の $id 互換処理を分ける必要があります。
    crates/tombi-schema-store/src/schema/schema_document_resources.rs:83
  • resources は HashMap なので、このメソッドが返す alias の順序が実行ごとに変わります。replace_schema_resources はこの順で cross-document duplicate を検査して最初の衝突だけを返すため、複数の重複 $id を持つ document では診断対象とメッセージが非決定的になり、fail-closed の deterministic rejection という要件を満たしません。返却前に canonical URI(および physical-document alias)を安定した順序で sort してください。
  • Files reviewed: 101/102 changed files
  • Comments generated: 4
  • Review effort level: Lite

Comment thread crates/tombi-schema-store/src/schema/document_schema.rs
Comment thread crates/tombi-schema-store/src/schema/referable_schema.rs
Comment thread crates/tombi-schema-store/src/store.rs
Comment thread crates/tombi-schema-store/src/store.rs
Use physical schema_document_uri for LSP schema links, fail-closed
reload with same-task cycle detection, and drop thin helpers from the
compound-schema path.

Co-authored-by: Cursor <cursoragent@cursor.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical URI-base defects and a moderate external-fallback defect remain.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (1)

crates/tombi-schema-store/src/store.rs:591

  • Weak の所有元が破棄された場合、この分岐は古い index エントリを削除した後に Ok(None) を返すため、下の通常の file/HTTP fetch へ進みません。fetch_schema_value を直接使う JSON Pointer 解決では、埋め込みリソースがもう存在せず外部リソースが利用可能でも解決に失敗し、埋め込み優先・外部 fallback の契約に反します。削除後は early return せず、通常の取得処理へ fall through させてください。
  • Files reviewed: 102/103 changed files
  • Comments generated: 2
  • Review effort level: Lite

Comment thread crates/tombi-schema-store/src/schema.rs Outdated
Comment thread crates/tombi-schema-store/src/schema/referable_schema.rs Outdated
Treat non-fragment $id under properties like $defs (load embedded
resource), use root $id as pointer schema_base_uri, and fall through
stale Weak index entries to external fetch.

Co-authored-by: Cursor <cursoragent@cursor.com>
@ya7010
ya7010 merged commit f4d1816 into tombi-toml:main Sep 13, 2026
29 checks passed
jylenhof pushed a commit to jylenhof/github-actions-resources that referenced this pull request Sep 28, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint
editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek
rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `pipx:gh-action-pulse` | `1.5.0` → `1.5.3` | `1.5.0` → `1.5.3` |
| `rumdl` | `0.2.74` → `0.2.77` | `0.2.74` → `0.2.77` |
| `tombi` | `1.5.5` → `1.5.6` | `1.5.5` → `1.5.6` |
| `uv` | `0.12.17` → `0.12.19` | `0.12.17` → `0.12.19` |

</details>

<details>
<summary>Release notes (3 tools)</summary>

<details>
<summary>rumdl: `0.2.74` → `0.2.77` (rvben/rumdl)</summary>

### v0.2.75

### Added

- **md093**: add opt-in rule for inline formatting in headings
([ed627ef](rvben/rumdl@ed627ef))

### Fixed

- **md013**: add opt-in link text wrapping
([effdb6a](rvben/rumdl@effdb6a))
- **MD013**: protect opt-in bracket display math during reflow
([e2c7fe8](rvben/rumdl@e2c7fe8))
- **MD044**: add opt-in whole-word matching for identifiers
([013621e](rvben/rumdl@013621e))


## Downloads

| File | Platform | Checksum |
|------|----------|----------|
|
[rumdl-v0.2.75-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-x86_64-unknown-linux-gnu.tar.gz)
| Linux x86_64 |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-x86_64-unknown-linux-gnu.tar.gz.sha256)
|
|
[rumdl-v0.2.75-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-x86_64-unknown-linux-musl.tar.gz)
| Linux x86_64 (musl) |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-x86_64-unknown-linux-musl.tar.gz.sha256)
|
|
[rumdl-v0.2.75-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-aarch64-unknown-linux-gnu.tar.gz)
| Linux ARM64 |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-aarch64-unknown-linux-gnu.tar.gz.sha256)
|
|
[rumdl-v0.2.75-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-aarch64-unknown-linux-musl.tar.gz)
| Linux ARM64 (musl) |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.75/rumdl-v0.2.75-aarch64-unknown-linux-musl.tar.gz.sha256)
|
|
[rumdl-v0.2.75-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/…
(truncated)

### v0.2.76

### Added

- **MD094**: report each invalid UTF-8 sequence, with its position
([6c25d76](rvben/rumdl@6c25d76))
- **encoding**: lint files containing invalid UTF-8 instead of skipping
them
([f531bf4](rvben/rumdl@f531bf4))

### Fixed

- **MD013**: leave definition lists as written when reflowing, instead
of moving a definition's later paragraph out of the list
([93ab135](rvben/rumdl@93ab135))
- **MD013**: keep every block of consecutive mkdocstrings blocks out of
reflow
([7199b0a](rvben/rumdl@7199b0a))
- **MD013**: recognize mkdocstrings blocks whose identifier has no dot
([31b56ea](rvben/rumdl@31b56ea))
- **cli**: report a skipped file on the same stream as the run's other
findings, not always stderr
([9558bc5](rvben/rumdl@9558bc5))
- **MD092**: follow the invocation's rule selection
([b0dfbe2](rvben/rumdl@b0dfbe2))
- **lint-context**: record only CommonMark headings as headings
([1479a1e](rvben/rumdl@1479a1e))
- **cli**: name every ignore file --respect-gitignore controls
([268a54d](rvben/rumdl@268a54d))
- **discovery**: attribute empty runs to .markdownlintignore separately
([834e10c](rvben/rumdl@834e10c))


## Downloads

| File | Platform | Checksum |
|------|----------|----------|
|
[rumdl-v0.2.76-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.76/rumdl-v0.2.76-x86_64-unknown-linux-gnu.tar.gz)
| Linux x86_64 | [checksum](https://gith… (truncated)

### v0.2.77

### Fixed

- **release**: never replace published GitHub Release assets
([471d97e](rvben/rumdl@471d97e))

### Performance

- **release**: cut published wheel size 6% with fat LTO
([7605780](rvben/rumdl@7605780))


## Downloads

| File | Platform | Checksum |
|------|----------|----------|
|
[rumdl-v0.2.77-x86_64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-x86_64-unknown-linux-gnu.tar.gz)
| Linux x86_64 |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-x86_64-unknown-linux-gnu.tar.gz.sha256)
|
|
[rumdl-v0.2.77-x86_64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-x86_64-unknown-linux-musl.tar.gz)
| Linux x86_64 (musl) |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-x86_64-unknown-linux-musl.tar.gz.sha256)
|
|
[rumdl-v0.2.77-aarch64-unknown-linux-gnu.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-aarch64-unknown-linux-gnu.tar.gz)
| Linux ARM64 |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-aarch64-unknown-linux-gnu.tar.gz.sha256)
|
|
[rumdl-v0.2.77-aarch64-unknown-linux-musl.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-aarch64-unknown-linux-musl.tar.gz)
| Linux ARM64 (musl) |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-aarch64-unknown-linux-musl.tar.gz.sha256)
|
|
[rumdl-v0.2.77-x86_64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-x86_64-apple-darwin.tar.gz)
| macOS x86_64 |
[checksum](https://github.com/rvben/rumdl/releases/download/v0.2.77/rumdl-v0.2.77-x86_64-apple-darwin.tar.gz.sha256)
|
|
[rumdl-v0.2.77-aarch64-apple-darwin.tar.gz](https://github.com/rvben/rumdl/releases/download/…
(truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.5.6` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

</details>
<details>
<summary>uv: `0.12.17` → `0.12.19` (astral-sh/uv)</summary>

### 0.12.18

## Release Notes

Released on 2026-09-22.

This release addresses
[GHSA-2cv4-cqwr-gwf7](GHSA-2cv4-cqwr-gwf7),
which is a path traversal weakness during wheel installation on Windows.
No other platforms are affected by this advisory.

### Enhancements

- Add `--output-format json` to `uv pip install` and `uv pip sync`,
including for `--dry-run` and `--check`
([#21893](astral-sh/uv#21893))
- Add `--check` to `uv pip install` and `uv pip sync` to report planned
changes without modifying the environment
([#21844](astral-sh/uv#21844))
- Identify failures from `get_requires_for_build_*` hooks correctly in
build errors ([#21881](astral-sh/uv#21881))

### Preview features

- Validate build requirements for `uv build --no-build-isolation` with
`--preview-features build-dependency-check`; use
`--skip-dependency-check` to opt out
([#21880](astral-sh/uv#21880))

### Performance

- Speed up `uv_build` editable wheel creation by omitting compression
from temporary wheels
([#21918](astral-sh/uv#21918))

### Bug fixes

- Select package versions with wheels compatible with each Python
resolution fork, correctly interpreting generic and stable-ABI wheel
tags ([#21835](astral-sh/uv#21835),
[#21836](astral-sh/uv#21836))
- Restore project, script, and lock files when `uv add`, `uv remove`, or
`uv version` fails or is interrupted
([#21860](astral-sh/uv#21860),
[#21856](astral-sh/uv#21856))
- Use configured `dependency-metadata` when checking whether installed
requirements are satisfied
([#21843](astral-sh/uv#21843))
- Reject archive entries that normalize to absolute Windows paths
([#21923](astral-sh/uv#21923))
- Recognize distribution fil… (truncated)

### 0.12.19

## Release Notes

Released on 2026-09-24.

### Python

- Add PyPy 3.11.16 and 3.12.14
([#21847](astral-sh/uv#21847))
- Update GraalPy 3.13.0 to build 25.4.4
([#21847](astral-sh/uv#21847))

### Enhancements

- Format upload URLs with backticks in `uv publish` errors
([#21934](astral-sh/uv#21934))

### Preview features

- Run build-backend hooks with lazy imports on CPython 3.15 and later
using the `build-lazy-imports` preview feature
([#21967](astral-sh/uv#21967))
- Omit unused resolution settings from `uv.lock` and ignore changes to
them when checking lockfile freshness with the `resolution-inputs`
preview feature ([#21913](astral-sh/uv#21913))

### Bug fixes

- Preserve signed and encoded query parameters in direct-URL metadata to
avoid reinstalling unchanged packages
([#21971](astral-sh/uv#21971))
- Recognize `1.0.0` as satisfying `===1` during installed-package
checks, matching resolution
([#21931](astral-sh/uv#21931))
- Avoid collisions between Git checkout readiness markers and `.ok`
files in dependencies
([#21891](astral-sh/uv#21891))
- Preserve always-false `python_version` markers when parsing their
serialized form ([#21939](astral-sh/uv#21939))

### Rust API

- Restore the public `FlatDistributions` export and its `BTreeMap`
conversion for downstream resolvers
([#21965](astral-sh/uv#21965))

### Documentation

- Make individual preview-feature reference entries linkable by name
([#21950](astral-sh/uv#21950))

## Install uv 0.12.19

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -Execut… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-tips that referenced this pull request Sep 28, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.5.5` → `1.5.6` | `1.5.5` → `1.5.6` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.5.5` → `1.5.6` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint aube
editorconfig-checker ghalint pinact pipx:gh-action-pulse prek rumdl
shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with
some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files
([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer`
([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter`
([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer`
([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace`
([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion`
([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration
([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks
([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS
([#2726](j178/prek#2726))
- Combine and cache Git repository path queries
([#2724](j178/prek#2724))
- Optimize common builtin hook execution
([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace`
([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks
([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and
`check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows
([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts
([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a
space
([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions
([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in
semantic-line-breaks mode
([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one
space
([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool
changes
([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure
([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and
honor on-error in check
([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at
deploy time
([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings
([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification
([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity
([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse
([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6…
(truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically
equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel
scripts with CRLF shebangs
([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the
`lockfile-normalization` preview feature
([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from
`pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the
output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks`
requirements resolve to the same package
([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with
distinct base and extra requirement specifiers
([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv
tree --format json` output
([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries
([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating
severe cache-revalidation stalls on ext4 filesystems
([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under
`--require-hashes` and `--verify-hashes`
([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under
`--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including
`--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9
([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only
manifest subtables
([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those
involving pre-releases, with the `resolution-inputs` preview feature
([#22004](astral-sh/uv#22004),
[#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions`
file without `--global`
([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as
incompatible with exclusive lower bounds on pre-releases
([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256)
|
|
[uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz)
| Intel macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256)
|
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8
([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags
([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles
([#22010](astral-sh/uv#22010),
[#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in
lockfiles ([#22044](astral-sh/uv#22044),
[#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles
([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace
roots in lockfiles
([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages
([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help
([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit`
([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline
and hide the unsupported option from help
([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture
independently of its Python version
([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download
metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when
relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace
roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3
([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync
--frozen` with `frozen-lockfile`
([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export
--frozen` with `frozen-lockfile`
([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest
using `uv tree --frozen` with `frozen-lockfile`
([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from
`uv.lock` without a workspace manifest using `uv workspace metadata
--frozen` with `frozen-lockfile`
([#22017](astral-sh/uv#22017),
[#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting
dependency selections, avoiding lockfiles that cannot be installed
([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows
ARM64 to install compatible `win_amd64` wheels instead of building from
source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/gh-action-pulse that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `tombi`

Command: `mise upgrade --bump --local tombi`

<details>
<summary>Version changelog (tombi)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |

</details>

<details>
<summary>Release notes (1 tools)</summary>

<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files ([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer` ([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter` ([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer` ([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace` ([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion` ([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration ([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks ([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS ([#2726](j178/prek#2726))
- Combine and cache Git repository path queries ([#2724](j178/prek#2724))
- Optimize common builtin hook execution ([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace` ([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks ([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and `check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows ([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts ([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a space ([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions ([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in semantic-line-breaks mode ([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one space ([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool changes ([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure ([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and honor on-error in check ([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at deploy time ([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings ([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification ([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity ([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse ([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6… (truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010 in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the primary SchemaView by @​ya7010 in tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in package.json and pnpm-lock.yaml; add new tumbi-lib module with initial implementation by @​ya7010 in tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010 in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in tombi-toml/tombi#2225

**Full Changelog**: tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by @​ya7010 in tombi-toml/tombi#2226

**Full Changelog**: tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm workspace injection by @​ya7010 in tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by @​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by @​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by @​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by @​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010 in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by @​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by @​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by @​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now available on [pypi](https://tombi-toml.github.io/tombi/docs/library/python) / [npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing `format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by @​ya7010 in tombi-toml/tombi#2247

**Full Changelog**: tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by combinator branches by @​ya7010 in tombi-toml/tombi#2249

**Full Changelog**: tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the CLI, along with output formats such as `github` and `gitlab`.

Please refer to the [documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output) for details.

### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010 in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with LineIndex at the output boundary by @​ya7010 in tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by @​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on nested arrays by @​ya7010 in tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by @​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at the output boundary by @​ya7010 in tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text inline by @​ya7010 in tombi-toml/tombi#2264

**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by @​ya7010 in tombi-toml/tombi#2266

**Full Changelog**: tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs ([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the `lockfile-normalization` preview feature ([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from `pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks` requirements resolve to the same package ([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with distinct base and extra requirement specifiers ([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv tree --format json` output ([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries ([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems ([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under `--require-hashes` and `--verify-hashes` ([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under `--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including `--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9 ([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only manifest subtables ([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those involving pre-releases, with the `resolution-inputs` preview feature ([#22004](astral-sh/uv#22004), [#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions` file without `--global` ([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases ([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256) |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz) | Intel macOS | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256) |
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 ([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags ([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles ([#22010](astral-sh/uv#22010), [#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in lockfiles ([#22044](astral-sh/uv#22044), [#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles ([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace roots in lockfiles ([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages ([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help ([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit` ([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline and hide the unsupported option from help ([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture independently of its Python version ([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3 ([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync --frozen` with `frozen-lockfile` ([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export --frozen` with `frozen-lockfile` ([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest using `uv tree --frozen` with `frozen-lockfile` ([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from `uv.lock` without a workspace manifest using `uv workspace metadata --frozen` with `frozen-lockfile` ([#22017](astral-sh/uv#22017), [#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed ([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible `win_amd64` wheels instead of building from source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz) | Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`
jylenhof pushed a commit to jylenhof/mise-en-place-resources that referenced this pull request Oct 5, 2026
Automated mise tool upgrades from local config.

mise-managed tools:
- `action-validator`
- `actionlint`
- `editorconfig-checker`
- `ghalint`
- `lychee`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`

Command: `mise upgrade --bump --local action-validator actionlint
editorconfig-checker ghalint lychee pinact pipx:gh-action-pulse prek
rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`

<details>
<summary>Version changelog (4 tools)</summary>

| Tool | Requested | Installed |
|------|-----------|-----------|
| `prek` | `0.5.3` → `0.5.4` | `0.5.3` → `0.5.4` |
| `rumdl` | `0.2.77` → `0.2.78` | `0.2.77` → `0.2.78` |
| `tombi` | `1.5.5` → `1.7.1` | `1.5.5` → `1.7.1` |
| `uv` | `0.12.19` → `0.12.23` | `0.12.19` → `0.12.23` |

</details>

<details>
<summary>Release notes (4 tools)</summary>

<details>
<summary>prek: `0.5.3` → `0.5.4` (j178/prek)</summary>

### v0.5.4

## Release Notes

Released on 2026-09-28.

### Highlights

#### Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with
some builtin
hooks up to 273% faster (`check-yaml`: 273%, `check-json`: 80%,
`check-merge-conflict`: 71%).

### Enhancements

- Add `include_deleted` to allow hooks to include deleted files
([#2733](j178/prek#2733))
- Add `--check` and simplify `end-of-file-fixer`
([#2764](j178/prek#2764))
- Add `--check` to `file-contents-sorter`
([#2765](j178/prek#2765))
- Add `--check` to `requirements-txt-fixer`
([#2766](j178/prek#2766))
- Add `--check` to `trailing-whitespace`
([#2763](j178/prek#2763))
- Expose and document `prek util generate-shell-completion`
([#2727](j178/prek#2727))
- Support `hide_status` in project and user configuration
([#2760](j178/prek#2760))
- Support look-around regex in builtin pattern hooks
([#2732](j178/prek#2732))

### Performance

- Cache the resolved Git executable on macOS
([#2726](j178/prek#2726))
- Combine and cache Git repository path queries
([#2724](j178/prek#2724))
- Optimize common builtin hook execution
([#2768](j178/prek#2768))
- Optimize scanning in `mixed-line-ending` and `trailing-whitespace`
([#2769](j178/prek#2769))
- Scan `check-merge-conflict` files in fixed-size blocks
([#2781](j178/prek#2781))
- Use SIMD UTF-8 validation in `check-json`, `check-toml`, and
`check-yaml` ([#2770](j178/prek#2770))

### Bug fixes

- Retry transient rename failures on Windows
([#2756](j178/prek#2756))
- Use PATH to resolve prek in completion scripts
([#2719](j178/prek#2719))

### Documentation

- Clarify… (truncated)

</details>
<details>
<summary>rumdl: `0.2.77` → `0.2.78` (rvben/rumdl)</summary>

### v0.2.78

### Added

- **MD013**: add cjk-soft-break option to join CJK line breaks without a
space
([5b5a744](rvben/rumdl@5b5a744))
- **MD013**: reflow definition list definitions
([f07ddc8](rvben/rumdl@f07ddc8))

### Fixed

- **MD013**: keep CJK sentences on separate lines in
semantic-line-breaks mode
([ea2798d](rvben/rumdl@ea2798d))
- **MD013**: join soft breaks in MkDocs admonitions and tabs with one
space
([962f1ee](rvben/rumdl@962f1ee))
- **code-block-tools**: invalidate cached results when a lint tool
changes
([5ff393b](rvben/rumdl@5ff393b))
- **code-block-tools**: treat empty formatter output as a tool failure
([8e1a0e7](rvben/rumdl@8e1a0e7))
- **code-block-tools**: report lint tool failures at their block and
honor on-error in check
([9f3ea71](rvben/rumdl@9f3ea71))
- **playground**: build the playground engine from the repository at
deploy time
([e342590](rvben/rumdl@e342590))
- keep each line's ending when fixing a file with mixed line endings
([6491db8](rvben/rumdl@6491db8))
- **lsp**: apply every content change in a didChange notification
([499d132](rvben/rumdl@499d132))
- **output**: map rule severity onto GitLab Code Quality severity
([9e795b9](rvben/rumdl@9e795b9))
- **MD032**: withhold blank lines that would change how the lists parse
([0db96d9](https://github.com/rvben/rumdl/commit/0db96d9198a0637153dee45c53f6…
(truncated)

</details>
<details>
<summary>tombi: `1.5.5` → `1.7.1` (tombi-toml/tombi)</summary>

### v1.5.6

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.6 -->

## What's Changed
### 🦅 New Features
* feat(schema): support JSON Schema compound documents with embedded $id
by @​ya7010 in tombi-toml/tombi#2181
* feat(test): add Definition A JSON Schema Test Suite runner by @​ya7010
in tombi-toml/tombi#2182
* perf(schema): reduce resource index lock overhead by @​ya7010 in
tombi-toml/tombi#2223
* perf(comment): reuse cached directive schemas by @​ya7010 in
tombi-toml/tombi#2224
### 🐝 Bug Fixes
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2212
### 🛠️ Other Changes
* fix(deps): resolve OSV scanner vulnerabilities by @​ya7010 in
tombi-toml/tombi#2180
* Ya7010/json schema suite gap by @​ya7010 in
tombi-toml/tombi#2193
* fix(validator): validate sibling oneOf/anyOf/allOf when one is not the
primary SchemaView by @​ya7010 in
tombi-toml/tombi#2194
* fix: update rustls for security advisory by @​ya7010 in
tombi-toml/tombi#2195
* update: status bar name. by @​ya7010 in
tombi-toml/tombi#2199
* chore: update pnpm to version 12.5.1 and adjust dependencies in
package.json and pnpm-lock.yaml; add new tumbi-lib module with initial
implementation by @​ya7010 in
tombi-toml/tombi#2208
* Add py tombi lib by @​ya7010 in
tombi-toml/tombi#2209
* fix: preserve sibling assertions beside schema combinators by @​ya7010
in tombi-toml/tombi#2211
* fix(schema): preserve dynamic reference annotations by @​ya7010 in
tombi-toml/tombi#2214
* fix(schema): honor disabled validation vocabulary by @​ya7010 in
tombi-toml/tombi#2215
* ci: gate JSON Schema Test Suite on PRs b… (truncated)

### v1.5.7

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.7 -->

## What's Changed
### 🛠️ Other Changes
* fix(lsp): prevent composite tooltip headings by @​ya7010 in
tombi-toml/tombi#2225


**Full Changelog**:
tombi-toml/tombi@v1.5.6...v1.5.7

### v1.5.8

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.8 -->

## What's Changed
### 🛠️ Other Changes
* fix(release): skip unready tombi-lib package in npm publish loop by
@​ya7010 in tombi-toml/tombi#2226


**Full Changelog**:
tombi-toml/tombi@v1.5.7...v1.5.8

### v1.5.10

<!-- Release notes generated using configuration in .github/release.yml
at v1.5.10 -->

## What's Changed
### 🛠️ Other Changes
* fix: route file:// resolution through tombi_fs and share wasm
workspace injection by @​ya7010 in
tombi-toml/tombi#2227
* feat(tombi-lib): add shared core crate for format/lint by @​ya7010 in
tombi-toml/tombi#2228
* feat(tombi-lib): add PyO3 bindings and python/tombi-lib package by
@​ya7010 in tombi-toml/tombi#2229
* feat(tombi-lib): add napi-rs Node.js binding and npm packaging by
@​ya7010 in tombi-toml/tombi#2230
* feat(tombi-lib): add formatSync/lintSync to the Node.js binding by
@​ya7010 in tombi-toml/tombi#2232
* ci(npm): publish the Node.js library as @​tombi-toml/lib and tombi-lib
by @​ya7010 in tombi-toml/tombi#2233
* refactor(npm): rename @​tombi-toml/tombi to @​tombi-toml/cli by
@​ya7010 in tombi-toml/tombi#2234
* docs: add tombi-lib documentation for Python and Node.js by @​ya7010
in tombi-toml/tombi#2231
* ci(pypi): build and publish tombi-lib to PyPI by @​ya7010 in
tombi-toml/tombi#2235
* fix(deps): bump fast-uri to 3.1.7 and undici to 7.29.1 by @​ya7010 in
tombi-toml/tombi#2237
* ci(wasm): avoid double wasm builds and parallelize lib/lsp jobs by
@​ya7010 in tombi-toml/tombi#2238
* feat(wasm-lib): restore TombiWasmError as deprecated alias of
TombiError by @​ya7010 in tombi-toml/tombi#2239
* docs: highlight Python code and clarify tombi-lib vs tombi-wasm-lib by
@​ya7010 in tombi-toml/tombi#2240
* fix(lsp): complete $key for tables with additionalProperties: true by
@​ya7010 in tombi-toml/tombi#2241
* fix(lib): unify tombi-lib and wasm-lib interfaces by @​ya7010 in
https://github.com/t… (truncated)

### v1.6.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.0 -->

## What's Changed

[tombi-lib](https://tombi-toml.github.io/tombi/docs/library) is now
available on
[pypi](https://tombi-toml.github.io/tombi/docs/library/python) /
[npm](https://tombi-toml.github.io/tombi/docs/library/nodejs), allowing
`format` and `lint` to be executed from programming languages.

### 🛠️ Other Changes
* fix(ci): publish VSCode extensions in dedicated jobs by @​ya7010 in
tombi-toml/tombi#2245
* fix(deps): bump markdown-it to 14.3.1 by @​ya7010 in
tombi-toml/tombi#2246
* fix(vscode): look up node_modules/tombi before scoped packages by
@​ya7010 in tombi-toml/tombi#2247


**Full Changelog**:
tombi-toml/tombi@v1.5.10...v1.6.0

### v1.6.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.6.1 -->

## What's Changed
### 🛠️ Other Changes
* ci(npm): stop publishing the @​tombi-toml/tombi alias by @​ya7010 in
tombi-toml/tombi#2248
* fix(validator): don't report unused-noqa for deprecated rules used by
combinator branches by @​ya7010 in
tombi-toml/tombi#2249


**Full Changelog**:
tombi-toml/tombi@v1.6.0...v1.6.1

### v1.7.0

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.0 -->

## What's Changed
We have added `--diagnostics-format` and `--diagnostics-file` to the
CLI, along with output formats such as `github` and `gitlab`.

Please refer to the
[documentation](https://tombi-toml.github.io/tombi/docs/cli/diagnostics-output)
for details.


### 🦅 New Features
* feat(cli): add --diagnostics-format and --diagnostics-file by @​ya7010
in tombi-toml/tombi#2250

### 🛠️ Other Changes
* refactor: keep Span through diagnostics and convert to Range with
LineIndex at the output boundary by @​ya7010 in
tombi-toml/tombi#2254
* perf(formatter): only scan the last line in current_line_width by
@​ya7010 in tombi-toml/tombi#2255
* perf(document-tree): avoid O(n^2) scan in Table::merge for key-value
tables by @​ya7010 in tombi-toml/tombi#2256
* perf(formatter): memoize exceeds_line_width to fix exponential time on
nested arrays by @​ya7010 in
tombi-toml/tombi#2257
* fix(deps): bump brace-expansion, dompurify and fast-uri overrides by
@​ya7010 in tombi-toml/tombi#2258
* perf: build a per-tree header index to remove O(n^2) sibling header
walks by @​ya7010 in tombi-toml/tombi#2260
* refactor: keep JSON positions as Span and convert with LineIndex at
the output boundary by @​ya7010 in
tombi-toml/tombi#2261
* perf: scan JSON bytes, stream tokens into the parser and share parsed
containers by @​ya7010 in tombi-toml/tombi#2263
* perf: borrow the source and LineIndex instead of reference-counting
them by @​ya7010 in tombi-toml/tombi#2262
* test: keep the issue-2164 fixture valid and pass the invalid text
inline by @​ya7010 in tombi-toml/tombi#2264


**Full Changelog**: https://github.c… (truncated)

### v1.7.1

<!-- Release notes generated using configuration in .github/release.yml
at v1.7.1 -->

## What's Changed
### 🛠️ Other Changes
* fix: do not truncate the file before writing formatted text by
@​ya7010 in tombi-toml/tombi#2266


**Full Changelog**:
tombi-toml/tombi@v1.7.0...v1.7.1

</details>
<details>
<summary>uv: `0.12.19` → `0.12.23` (astral-sh/uv)</summary>

### 0.12.20

## Release Notes

Released on 2026-09-28.

### Enhancements

- Reuse lockfiles when dependency declarations are semantically
equivalent ([#21951](astral-sh/uv#21951))
- Preserve second-line encoding declarations when installing wheel
scripts with CRLF shebangs
([#21990](astral-sh/uv#21990))

### Preview features

- Write normalized requirement declarations with the
`lockfile-normalization` preview feature
([#21951](astral-sh/uv#21951))
- Honor synthetic default groups when installing or syncing from
`pylock.toml` ([#22003](astral-sh/uv#22003))
- Resolve local paths in exported `pylock.toml` files relative to the
output file ([#22042](astral-sh/uv#22042))
- Install each package only once when repeated `tool-install-locks`
requirements resolve to the same package
([#22000](astral-sh/uv#22000))
- Reuse `lock-without-metadata` lockfiles for conflicting groups with
distinct base and extra requirement specifiers
([#22055](astral-sh/uv#22055))
- Use consistent root-package paths in `uv workspace metadata` and `uv
tree --format json` output
([#22050](astral-sh/uv#22050))

### Configuration

- Continue searching `XDG_CONFIG_DIRS` after empty entries
([#21987](astral-sh/uv#21987))

### Performance

- Restore the previous HTTP cache-write scheduling while investigating
severe cache-revalidation stalls on ext4 filesystems
([#22051](astral-sh/uv#22051))

### Bug fixes

- Apply hash constraints to every repeated requirement under
`--require-hashes` and `--verify-hashes`
([#21996](astral-sh/uv#21996))
- Allow metadata builds for first-party workspace projects under
`--no-build` ([#21988](astral-sh/uv#21988))
- Honor project exclusion flags with `--all-packages`, including
`--no-install… (truncated)

### 0.12.21

## Release Notes

Released on 2026-09-29.

### Python

- Update CPython to use OpenSSL 3.5.9
([#22076](astral-sh/uv#22076))

### Enhancements

- Omit empty `[manifest]` tables from lockfiles that contain only
manifest subtables
([#22070](astral-sh/uv#22070))

### Preview features

- Omit redundant runtime constraints from `uv.lock`, including those
involving pre-releases, with the `resolution-inputs` preview feature
([#22004](astral-sh/uv#22004),
[#22068](astral-sh/uv#22068))

### Bug fixes

- Prevent `uv python pin --rm` from removing a global `.python-versions`
file without `--global`
([#21992](astral-sh/uv#21992))
- Fix installed-package checks incorrectly reporting post-releases as
incompatible with exclusive lower bounds on pre-releases
([#22049](astral-sh/uv#22049))

## Install uv 0.12.21

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"
```

## Download uv 0.12.21

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-aarch64-apple-darwin.tar.gz.sha256)
|
|
[uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz)
| Intel macOS |
[checksum](https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-x86_64-apple-darwin.tar.gz.sha256)
|
| [uv-aarch64-pc-windows-msvc.zip](https://r… (truncated)

### 0.12.22

## Release Notes

Released on 2026-10-01.

### Python

- Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8
([#22147](astral-sh/uv#22147))

### Enhancements

- Accept uppercase release suffixes in wheel platform tags
([#22113](astral-sh/uv#22113))
- Record workspace-member default groups in lockfiles
([#22010](astral-sh/uv#22010),
[#22103](astral-sh/uv#22103))
- Record workspace-member dependency-group Python requirements in
lockfiles ([#22044](astral-sh/uv#22044),
[#22103](astral-sh/uv#22103))
- Record default groups for non-project workspace roots in lockfiles
([#22104](astral-sh/uv#22104))
- Record dependency-group Python requirements for non-project workspace
roots in lockfiles
([#22104](astral-sh/uv#22104))
- Format URLs and paths consistently in CLI messages
([#21937](astral-sh/uv#21937))
- Hide the unsupported `--offline` option from `uv publish` help
([#22124](astral-sh/uv#22124))

### Preview features

- Honor `--no-default-groups` in `uv audit`
([#22090](astral-sh/uv#22090))
- Report a clear error when `uv audit` or `uv tool audit` runs offline
and hide the unsupported option from help
([#22114](astral-sh/uv#22114))

### Configuration

- Add `UV_PYTHON_ARCH` to select an interpreter architecture
independently of its Python version
([#22098](astral-sh/uv#22098))

### Performance

- Reduce uv's binary size by compressing embedded Python download
metadata ([#22126](astral-sh/uv#22126))

### Bug fixes

- Verify unchanged requirements against existing lockfile hashes when
relocking ([#22083](astral-sh/uv#22083))
- Honor dependency-group Python requirements at non-project workspace
roots… (truncated)

### 0.12.23

## Release Notes

Released on 2026-10-03.

### Python

- Add CPython 3.15.0rc3
([#22164](astral-sh/uv#22164))

### Preview features

- Sync from `uv.lock` without a workspace manifest using `uv sync
--frozen` with `frozen-lockfile`
([#22018](astral-sh/uv#22018))
- Export from `uv.lock` without a workspace manifest using `uv export
--frozen` with `frozen-lockfile`
([#22007](astral-sh/uv#22007))
- Inspect dependency trees from `uv.lock` without a workspace manifest
using `uv tree --frozen` with `frozen-lockfile`
([#22016](astral-sh/uv#22016))
- Inspect workspace metadata and optionally sync its environment from
`uv.lock` without a workspace manifest using `uv workspace metadata
--frozen` with `frozen-lockfile`
([#22017](astral-sh/uv#22017),
[#22018](astral-sh/uv#22018))

### Bug fixes

- Reject alternate sources for workspace members across conflicting
dependency selections, avoiding lockfiles that cannot be installed
([#22153](astral-sh/uv#22153))
- Allow x86-64 Python interpreters running under emulation on Windows
ARM64 to install compatible `win_amd64` wheels instead of building from
source ([#22099](astral-sh/uv#22099))

## Install uv 0.12.23

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"
```

## Download uv 0.12.23

|  File  | Platform | Checksum |
|--------|----------|----------|
|
[uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-aarch64-apple-darwin.tar.gz)
| Apple Silicon macOS | [checksum](… (truncated)

</details>

</details>

Modified files:
- `.mise.toml`

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants