A small patch release with two user-facing fixes: mise downloads are now verified against minisign-signed release checksums by default, and the env input no longer leaks the runner's PATH into subsequent steps.
Fixed
Verify mise downloads with signed checksums (#548) by @jdx
The action now embeds mise's minisign public key and verifies SHASUMS256.txt.minisig before trusting any release checksums, then checks the downloaded mise binary's SHA256 against the verified list. This applies to both GitHub release archives (verified before extraction) and the default mise.jdx.dev CDN path (verified against the signed checksum for the matching release asset). If a CDN download fails verification, the action warns and falls back to the signed GitHub release asset instead of installing an unverified binary.
The existing sha256 input still works as an explicit override.
Pinned mise versions older than 2024.12.24 (which predate minisign checksums) get a warning and skip signed verification rather than failing.
Because tar installs now extract from a verified file on disk, the previous streaming download | tar fast path is replaced with a download-then-verify-then-extract flow.
Thanks to @potiuk for the detailed threat-model writeup in #547.
Exclude PATH from environment export (#556) by @jdx
The env input has always documented that "PATH modifications are not part of this", but since the switch to mise env --json in #252 (needed for redaction support), the action was exporting every string value returned by mise — including the computed PATH — into GITHUB_ENV. That effectively snapshotted the runner's entire PATH into subsequent steps and let [env] _.path entries in mise.toml leak past the action's own PATH management.
exportMiseEnv now skips PATH (case-insensitive) when exporting JSON env vars, restoring the documented behavior. Normal mise env vars are still exported, and PATH continues to be managed by the action's own setup (e.g. add_shims_to_path). Fixes #555.
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [https://github.com/jdx/mise-action](https://github.com/jdx/mise-action) | action | patch | `v4.2.0` → `v4.2.1` |
---
### Release Notes
<details>
<summary>jdx/mise-action (https://github.com/jdx/mise-action)</summary>
### [`v4.2.1`](https://github.com/jdx/mise-action/releases/tag/v4.2.1): : Signed checksums and PATH export fix
[Compare Source](https://github.com/jdx/mise-action/compare/v4.2.0...v4.2.1)
A small patch release with two user-facing fixes: mise downloads are now verified against minisign-signed release checksums by default, and the `env` input no longer leaks the runner's `PATH` into subsequent steps.
#### Fixed
##### Verify mise downloads with signed checksums ([#​548](https://github.com/jdx/mise-action/pull/548)) by [@​jdx](https://github.com/jdx)
The action now embeds mise's minisign public key and verifies `SHASUMS256.txt.minisig` before trusting any release checksums, then checks the downloaded mise binary's SHA256 against the verified list. This applies to both GitHub release archives (verified before extraction) and the default `mise.jdx.dev` CDN path (verified against the signed checksum for the matching release asset). If a CDN download fails verification, the action warns and falls back to the signed GitHub release asset instead of installing an unverified binary.
- The existing `sha256` input still works as an explicit override.
- Pinned mise versions older than `2024.12.24` (which predate minisign checksums) get a warning and skip signed verification rather than failing.
- Because tar installs now extract from a verified file on disk, the previous streaming `download | tar` fast path is replaced with a download-then-verify-then-extract flow.
Thanks to [@​potiuk](https://github.com/potiuk) for the detailed threat-model writeup in [#​547](https://github.com/jdx/mise-action/issues/547).
##### Exclude `PATH` from environment export ([#​556](https://github.com/jdx/mise-action/pull/556)) by [@​jdx](https://github.com/jdx)
The `env` input has always documented that "PATH modifications are not part of this", but since the switch to `mise env --json` in [#​252](https://github.com/jdx/mise-action/pull/252) (needed for redaction support), the action was exporting every string value returned by mise — including the computed `PATH` — into `GITHUB_ENV`. That effectively snapshotted the runner's entire `PATH` into subsequent steps and let `[env] _.path` entries in `mise.toml` leak past the action's own PATH management.
`exportMiseEnv` now skips `PATH` (case-insensitive) when exporting JSON env vars, restoring the documented behavior. Normal mise env vars are still exported, and PATH continues to be managed by the action's own setup (e.g. `add_shims_to_path`). Fixes [#​555](https://github.com/jdx/mise-action/issues/555).
**Full Changelog**: <https://github.com/jdx/mise-action/compare/v4.2.0...v4.2.1>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI3MC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v4.2.0→v4.2.1Release Notes
jdx/mise-action (https://github.com/jdx/mise-action)
v4.2.1: : Signed checksums and PATH export fixCompare Source
A small patch release with two user-facing fixes: mise downloads are now verified against minisign-signed release checksums by default, and the
envinput no longer leaks the runner'sPATHinto subsequent steps.Fixed
Verify mise downloads with signed checksums (#548) by @jdx
The action now embeds mise's minisign public key and verifies
SHASUMS256.txt.minisigbefore trusting any release checksums, then checks the downloaded mise binary's SHA256 against the verified list. This applies to both GitHub release archives (verified before extraction) and the defaultmise.jdx.devCDN path (verified against the signed checksum for the matching release asset). If a CDN download fails verification, the action warns and falls back to the signed GitHub release asset instead of installing an unverified binary.sha256input still works as an explicit override.2024.12.24(which predate minisign checksums) get a warning and skip signed verification rather than failing.download | tarfast path is replaced with a download-then-verify-then-extract flow.Thanks to @potiuk for the detailed threat-model writeup in #547.
Exclude
PATHfrom environment export (#556) by @jdxThe
envinput has always documented that "PATH modifications are not part of this", but since the switch tomise env --jsonin #252 (needed for redaction support), the action was exporting every string value returned by mise — including the computedPATH— intoGITHUB_ENV. That effectively snapshotted the runner's entirePATHinto subsequent steps and let[env] _.pathentries inmise.tomlleak past the action's own PATH management.exportMiseEnvnow skipsPATH(case-insensitive) when exporting JSON env vars, restoring the documented behavior. Normal mise env vars are still exported, and PATH continues to be managed by the action's own setup (e.g.add_shims_to_path). Fixes #555.Full Changelog: https://github.com/jdx/mise-action/compare/v4.2.0...v4.2.1
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.