chore(deps): update dependency aube to v2 - #48
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/aube-2.x
branch
3 times, most recently
from
September 9, 2026 01:21
61dacda to
804a2d3
Compare
renovate
Bot
force-pushed
the
renovate/aube-2.x
branch
from
September 12, 2026 17:43
804a2d3 to
51f7493
Compare
◈ PR LensNote This drawing shows
Architecture 1 component touched across 1 lane. Data flow No data-flow sequence changed in this PR. View
Tip Open a diagram on the canvas, then press W or click play to walk through the change one step at a time. 🪧 More tips
Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. |
renovate
Bot
force-pushed
the
renovate/aube-2.x
branch
4 times, most recently
from
September 18, 2026 20:48
72dc90e to
d38fa5b
Compare
renovate
Bot
force-pushed
the
renovate/aube-2.x
branch
from
September 25, 2026 21:08
d38fa5b to
6de4709
Compare
RedStar071
approved these changes
Sep 26, 2026
renovate
Bot
force-pushed
the
renovate/aube-2.x
branch
4 times, most recently
from
October 1, 2026 22:12
14185b7 to
3af6a59
Compare
renovate
Bot
force-pushed
the
renovate/aube-2.x
branch
from
October 3, 2026 00:43
3af6a59 to
a70da31
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.25.0→2.6.1Release Notes
jdx/aube (aube)
v2.6.1: : Maintenance releaseCompare Source
The commit range for this release has no user-facing changes.
Full Changelog: aubepkg/aube@bd94e42...v2.6.1
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.6.0: : Maintenance releaseCompare Source
There are no user-facing changes in the commit range for this release.
Full Changelog: aubepkg/aube@f43833c...v2.6.0
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.5.1: : Faster repeated fresh installs and faster startup on LinuxCompare Source
Repeated fresh installs skip redundant OSV lookups, and the Linux release binaries start a little faster.
Changed
node_modulesandaube-lock.yamlremoved went from a 346 ms median to 107 ms.add/update/dlxchecks,advisoryCheck = requiredandadvisoryCheckEveryInstall = truestill query OSV live every time.aube,aubrandaubxare now linked as non-PIE. The loader no longer has to patch about 56k pointers at each launch, soaube --versiondrops from about 2.2 ms to 1.6 ms.cargo install, source builds and the PPA/COPR packages.Full Changelog: aubepkg/aube@98be8d1...v2.5.1
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.5.0: : Choose range or latest per package inaube update --interactiveCompare Source
aube update --interactivenow lets you pick, for each package, whether to keep the current version, move to the newest version its range allows, or jump tolatest. Repeated frozen installs and fresh installs without a lockfile are also faster, and a reinstall that failed after you deleted the cache and lockfile now works.Added
Per-package version choice in
aube update --interactive(#1612 by @jdx): The picker used to be one checkbox per dependency, with the target set by flags. It is now a table, like Yarn Berry'supgrade-interactive. Each row shows the current version, the newest version the range allows, and the registry'slatest. Use ↑/↓ to move between rows and ←/→ to choose a version. Rows left on Current are skipped, and/filters by name. Closes #1611.--latest. Pressing Enter right away does the same thing as the non-interactive command.-Estill forces exact pins.--no-savehides Latest and pin bumps, because both would rewritepackage.json.update -r -i, the version you choose for a shared catalog entry is used for later workspace packages without asking again.dependencies/devDependencies).Changed
--frozen-lockfileand lifecycle scripts disabled (for exampleaube install --frozen-lockfile --offline --ignore-scripts). On the benchmark fixture, a no-op install went from about 82 ms to about 7 ms. The freshness check hashes the lockfile and manifest contents, so a change is caught even when file size and modification time stay the same. A missing dependency link also counts as a change. Workspaces, patches, local sources, enabled scripts, custom lockfile locations and active per-install advisory policies still go through full validation.advisoryCheck: on, graphs with more than 10 distinct package/version pairs are now screened with the advisory Bloom filter first, and only probable hits are checked against the live API. On the benchmark fixtures this cut fresh install time by 36–67%.aube add/aube update, for transientaube dlxinstalls, and withadvisoryCheck: requiredoradvisoryCheckEveryInstall: true.Fixed
node_modules. Now an existing package directory is reused only when its dependency subtree matches the previous install and the directory still exists. Anything else is looked up in the store again, or downloaded again, before linking.Full Changelog: aubepkg/aube@d79acaa...v2.5.0
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.4.0: : Reuse node_modules/.aube-lock.yaml when the lockfile is missingCompare Source
aube installcan now rebuild a deleted lockfile from a hidden copy kept innode_modules, so it doesn't re-resolve from the registry. This release also makes cold installs on Linux faster and lighter on memory, and fixes lifecycle scripts on Windows and a workspaceaube updatethat could drop members from the lockfile.Added
Hidden lockfile in
node_modules(#1594 by @jdx): Every install now writes a copy of the resolved graph tonode_modules/.aube-lock.yaml. If the project has no lockfile of any supported kind,aube installstarts from that copy, as pnpm does with its current lockfile. If the manifests haven't changed, the graph is reused with no resolve. If they have changed, only the specs that changed are resolved again, and the other packages keep their locked versions.aube-lock.yamlis then written again.--frozen-lockfileandaube cistill fail when there is no lockfile.--no-frozen-lockfileignores the hidden copy.CI=truewith no explicit flags), an install that seeds from the hidden copy is treated as prefer-frozen.WARN_AUBE_HIDDEN_LOCKFILE_BROKENand resolves normally.lockfile=false, which also deletes any existing copy, or withsharedWorkspaceLockfile=false. It is also skipped for reuse installs from npm, yarn or bun lockfiles.Changed
AUBE_TOKIO_BLOCKINGstill overrides the default, and macOS and Windows keep 128.Fixed
EISDIR: illegal operation on a directory, lstat 'C:'(#1591 by @jdx): This affected scripts that start node through a.binshim (for examplenode-gyp-build) duringaube add,remove,update,dedupeandci, and during installs from embedding hosts such as mise'snpm:backend. The install root and the Node-API embedding's project directory no longer carry the\\?\verbatim prefix. Fixes #1590.aube updateat a workspace root dropping workspace members fromaube-lock.yaml(#1579 by @jdx): With a shared lockfile, runningaube updateoraube update -wat the root could delete every workspace member's entry inaube-lock.yaml. Member entries, their packages, patch hashes and catalog snapshots are now kept, and only the root's direct dependencies are updated.aube installalso treats a workspace member that declares dependencies but has no entry in the lockfile as stale, so installing again repairs lockfiles already damaged by this bug.Full Changelog: aubepkg/aube@v2.3.0...v2.4.0
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.3.0: : Host-bound Node launchers for embedders, plus hoisted.bin, lockfile patch-hash, and terminal-cleanup fixesCompare Source
Embedding hosts such as mise can now bind installed Node CLIs to a specific Node executable, and a batch of fixes covers hoisted-install bin linking,
aube-lock.yamlpatch hashes,ignoreScriptsresolution, signal delivery indlx --shell-mode, and terminal state after failed or interrupted installs.Added
Bind installed CLIs to a host-managed Node runtime (#1576 by @jdx) — Installed Node CLIs previously found their interpreter through the caller's
PATH, so a tool manager could not give an application its own runtime without also changing which Node its project subprocesses see.EmbedderRuntime::bind_bins_togenerates launchers that invoke the supplied absolute Node executable directly while leaving the inheritedPATHunchanged; it works with both embeddedinstallandadd:The path is kept as written (symlinks are not canonicalized), so a moving major-version path like mise's
installs/node/25/bin/nodeworks; a missing runtime fails rather than falling back to ambient Node. Changing or removing the binding regenerates launchers on the next install, including frozen ones. Bound installs always materialize locally and disable the global virtual store so runtime-specific launchers stay out of shared trees. Simple Node shebang flags are preserved; quoted shebang arguments and environment assignments are rejected. Standalone aube's runtime selection is unchanged — this is the launcher support a host needs to implement its own policy (see jdx/mise#13477).Fixed
--node-linker=hoisted, only importers' direct dependencies were linked intonode_modules/.bin, so packages whose lifecycle scripts call a binary from their own dependencies failed with errors likesh: node-pre-gyp: command not found(bcrypt,prebuild-install,napi-postinstall; see discussion #1543). Hoisted installs now follow npm's rule: each package's bins are linked into the.bin/of thenode_modules/it sits in, and a dependency's lifecycle script sees its own nested.binfirst so a version conflict no longer silently runs the hoisted winner. An importer's ownbinand its direct dependencies always take precedence over transitive packages on a name collision. Isolated installs are unaffected.aube rebuildrelinks the full bin surface (#1550 by @jdx) —rebuildonly relinked per-dependency shims, so a command added or retargeted inpackage.json#binafter install stayed missing or stale until the nextaube install.rebuildnow uses the same bin-linking entry point asinstall(importer bins, workspace member bins, then dependency bins). If a workspace member manifest is unreadable, it warns and reconciles the root importer instead of aborting.aube rebuild --filter <member>is not covered by this change.ignoreScriptsis honored from env,.npmrc, andaube-workspace.yaml(#1552 by @jdx, fixes #1551) — Only the--ignore-scriptsflag reached the installer;AUBE_IGNORE_SCRIPTS,npm_config_ignore_scripts,ignore-scripts=truein.npmrc, andignoreScripts: truein the workspace yaml were parsed and then discarded, soaube config get ignore-scriptsprintedtruewhile the next install ran scripts anyway. All sources now apply acrossinstall,ci,add,remove,update(including itspnpm:devPreinstallhook),dlx,deploy, and the auto-installaube runperforms on a stale tree — which previously had no way to skip scripts at all. An explicit flag still wins over a lower-precedencefalse.pack,publish, andversionkeep their own--ignore-scriptsflags.aube-lock.yamlkeeps patch hashes on re-resolve (#1577 by @jdx) — In a project withpatchedDependencies, runningaube adddropped the(patch_hash=…)suffix from patched entries inaube-lock.yaml, producing a spurious lockfile diff on every add and anode_modules/.aube/directory name that varied by how the lockfile was produced (reported in jdx/mise#13456).aube-lock.yamlnow records patch identities the same waypnpm-lock.yamldoes — a top-levelpatchedDependencies:map and(patch_hash=…)in entry names — consistently after install, add, and import, and a plainaube installnow detects edited, added, or removed patches. Upgrade note: existing hashlessaube-lock.yamlfiles still pass--frozen-lockfileunchanged; the next non-frozen install oraddrecords the hashes as a one-time diff. Projects without patches are unaffected.npm_execpathwhen aube is embedded (#1565 by @jdx) — Embedded aube setnpm_execpathto the host's binary, so a package running${npm_execpath} run verify-build(e.g.install-artifact-from-github, used byre2) invoked the host's own CLI and failed, causing a needless source build or a failed install (jdx/mise#13451). Embedded aube now exports a shim that re-enters aube's CLI through the host via a private__aube-cliargv token (embed::CLI_TRAMPOLINE_ARG); hosts dispatch it the same way as the existing node-gyp trampoline, anddocs/embedding/rust.mdnow documents both. If the shim cannot be written,npm_execpathis left unset rather than naming the host.AUBE_CLI_EXEis new in the lifecycle environment, and an inherited outernpm_execpathis now cleared before stamping. Standalone aube is unchanged.aube dlx --shell-modedelivers termination signals to the tool (#1562 by @jdx) — Signaling anaube dlx --shell-mode(oraubx -c) process stopped at the intermediatesh -c, leaving the tool running and aube hung waiting on it. A shell-mode line that is a single plain command now runs without a shell (using the same strict allowlist asaube run), so the tool is aube's direct child, receives the forwarded signal, and its exit code propagates. Pipelines, redirects, expansions, quoting, and shell builtins still run undershwith unchanged behavior, and the--shell-modehelp text now describes this contract.SIGINT/SIGTERM/SIGHUP/SIGQUITand panics to restore the terminal before re-raising — Ctrl-C still exits 130. Signals already ignored or handled (e.g. undernohup, or by an embedding host) are left alone. Windows gets the panic restore but not the signal handling.Full Changelog: aubepkg/aube@v2.2.17...v2.3.0
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.17: : Maintenance releaseCompare Source
This release only refreshes
Cargo.lockdependencies and contains no user-facing changes.Full Changelog: aubepkg/aube@v2.2.16...v2.2.17
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.16: : aube add installs local tarballs by their manifest nameCompare Source
aube add ./package.tgznow records the package under the name declared in the tarball'spackage.json, and localfile:/link:/portal:dependencies now install theiroptionalDependencies.Fixed
package.tgz, andaube addpreviously derived the dependency key from that filename, producing a bogus"package": "file:./package.tgz"entry alongside any existing dependency on the real package. For an unaliased local tarball or directory,aube addnow readspackage.json#nameand uses it as the key, so the add replaces an existing dependency on the same package instead of adding a second one. Explicit aliases (aube add alias@file:./package.tgz) remain authoritative, and a local package whose manifest has nonameis now rejected with an error. This fixes Bun checksum installs through mise (jdx/mise#13125), which download the verified artifact aspackage.tgz.optionalDependencies(#1532 by @jdx) —file:,link:, andportal:directory and tarball dependencies previously only resolveddependencies, so optional platform packages declared by a local package (such as Bun's per-platform binaries) were silently dropped. They are now resolved and linked under the local package, honoringignoredOptionalDependenciesandblockExoticSubdeps, and skipping any optional dependency already listed underdependenciesso it is not installed twice.Full Changelog: aubepkg/aube@v2.2.15...v2.2.16
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.15: : Embeddedaube addconfirmations distinguish "unavailable" from "declined"Compare Source
Embedding hosts can now tell aube that an install confirmation could not be shown, instead of being forced to report it as a user abort.
Fixed
Unavailable embedded confirmations no longer look like user aborts (#1530 by @jdx) — The
aube addreputation gates (low downloads, newly published names, similar names) previously asked embedded hosts for a boolean answer. A host that could not present a prompt had to returnfalse, which aube reported as an explicit user abort and could invent a host command such asmise addin the diagnostic. A new, backward-compatible tri-state API lets hosts answerAccept,Decline, orUnavailable:Unavailablereturns the gate's normal structured refusal with its stable error code and remediation;Declinenow producesuser declined to add <name>without referencing the embedding process. ExistingInstallPromptHandlerimplementations keep working, withfalsetreated as an explicit decline.Gate remediation moved into structured diagnostic help (#1530 by @jdx) — The
--allow-low-downloads/lowDownloadThreshold/minimumPackageAgehints for the three gates are now attached as diagnostichelprather than embedded in the message text, so embedders can replace them with host-native guidance while keeping the measured reason and error code.Full Changelog: aubepkg/aube@v2.2.14...v2.2.15
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.14: : Match GHSA IDs found in advisory URLsCompare Source
This is a small bug-fix release with a single user-facing change to
aube audit.Fixed
urlfield (e.g. an advisory whose URL ends inGHSA-w3rx-r6r6-pgpr), so advisories likeGHSA-w3rx-r6r6-pgprandGHSA-5p2g-fcmc-qvqqwere still reported even when passed to--ignoreor listed underaudit.ignorein a workspace's YAML. The matcher now extracts the trailing advisory ID from the URL and compares it using the existing case-insensitive exact match, correctly handling trailing slashes, query strings, and fragments.New Contributors
Full Changelog: aubepkg/aube@v2.2.13...v2.2.14
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.13: : Documentation & Site OverhaulCompare Source
This is a documentation-focused release. There are no functional changes to the aube binary — the work is a broad refresh of the guides, CLI references, and documentation site.
Changed
--ignore-scriptshelp text (#1503 by @jdx) — The help text for--ignore-scriptsnow accurately describes its behavior, alongside corrections to build-script policy, jail limitations, lockfile compatibility, and command examples throughout the docs.Full Changelog: aubepkg/aube@v2.2.12...v2.2.13
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.12: : HousekeepingCompare Source
This is a maintenance-only release. There are no user-facing changes since v2.2.11 — the only change is an internal CodeRabbit configuration update following the repository transfer to the
aubepkgorganization.Full Changelog: aubepkg/aube@v2.2.11...v2.2.12
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.11: : Housekeeping releaseCompare Source
This is a small housekeeping release cut immediately after v2.2.10. There are no new user-facing changes since v2.2.10 — the two
aube configfixes listed below already shipped in that release and are carried forward here for completeness.Fixed
Both of these first shipped in v2.2.10.
Redact credentials from
configoutput (#1483 by @jdx) —aube config list(text and--json) andaube config setrender authentication fields such as_authToken,username,password,key, andemailas(protected)instead of echoing the secret, and embedded URL credentials are masked. Secrets are still written to disk as expected — only the terminal output is redacted.Preserve comments and ordering in
config.toml(#1480 by @jdx) — Config edits go throughtoml_editinstead of rebuilding the file from a semantic map, so comments, whitespace, quoting, and setting order survive aconfig set.Full Changelog: aubepkg/aube@v2.2.10...v2.2.11
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.10: : Safer, tidier config editingCompare Source
A small release focused on
aube config: credentials are now redacted from command output, and editingconfig.tomlno longer clobbers your formatting.Fixed
Redact credentials from
configoutput (#1483 by @jdx) —aube config list(text and--json) andaube config setnow render authentication fields such as_authToken,username,password,key, andemailas(protected)instead of echoing the secret. Embedded URL credentials in values like proxies are masked (userinfo is replaced with***), while non-secret URLs still display normally. Secrets are still written to disk as expected — only the terminal output is redacted.Preserve comments and ordering in
config.toml(#1480 by @jdx) — Config edits now go throughtoml_editinstead of rebuilding the file from a semantic map, so your comments, whitespace, quoting, multiline array formatting, and setting order survive aconfig set. Updated settings keep their existing formatting and genuinely new settings are appended.Full Changelog: aubepkg/aube@v2.2.9...v2.2.10
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.9: : Restore the ARM64 release buildCompare Source
A small release that fixes aube's ARM64 release build so the
aarch64-unknown-linux-gnuartifact ships again.Fixed
targetdirectory before Docker mounts it (#1478 by @jdx) — Docker creates a missing bind-mount source as root, but the ARM64 release job runs its container as the runner user, sobenchmarks/pgo.bashcouldn't writetarget/pgo-dataand the PGO build failed. The workspacetargetdirectory is now created up front as the runner user (with a writability check before PGO starts), restoring the ARM64 release artifact.Full Changelog: aubepkg/aube@v2.2.8...v2.2.9
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.8: : Dependency refreshCompare Source
A small maintenance release. There are no user-facing changes — this release only refreshes pinned dependency versions in
Cargo.lock.Changed
Cargo.lockdependencies to their latest compatible versions. No behavior changes for users.Full Changelog: aubepkg/aube@v2.2.7...v2.2.8
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.7: : Unblock the ARM64 release buildCompare Source
A small release that fixes aube's ARM64 release build so the
aarch64-unknown-linux-gnuartifact ships again.Fixed
mbxcheck from the ARM64 release image (#1473 by @jdx) — The ARM64 PGO release container ran ambx --versionverification step even though its scoped mise configuration only installs Node and Rust. That check failed the build and blocked theaarch64-unknown-linux-gnuartifact and the final publish gate. The verification is now aligned with the image's actual toolchain, restoring the ARM64 release.Full Changelog: aubepkg/aube@v2.2.6...v2.2.7
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.6: : Restore ARM64 glibc compatibilityCompare Source
A small release that restores broad glibc compatibility for aube's ARM64 builds.
Fixed
Full Changelog: aubepkg/aube@v2.2.5...v2.2.6
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.5: : Moving to aube.sh with a faster Linux store pathCompare Source
A modest release: aube's home moves to
aubepkg/aubeand the newaube.shdomain, the Linux content-addressed store gains a direct-write fast path when it holds the install lock, and the CLI help and docs get a substantial accuracy pass.Changed
aubepkg/aubeandaube.sh(#1460 by @jdx) — Public documentation and the built-in update-check URLs now point ataube.shinstead ofaube.jdx.dev, and canonical repository, release, package, and support links reflect the transfer toaubepkg/aube. If you have bookmarks, scripts, or configuration referencing the old domain or repo, update them to the new locations.Performance
O_TMPFILE+linkatpublication step. Atomic publication is retained whenever another installer holds the lock, and torn-entry recovery now acquires and rechecks under the same cross-process lock before unlinking, backed by new regression tests. Benchmarks show a modest ~1.3% wall-time and ~3.3% system-CPU reduction on cold installs.Fixed
--network-concurrencydefault range (16–128, not 16–64), the virtual-store path in--disable-gvshelp, and the full list of commands honoring--filter(outdated,query,rebuild). Settings summaries forsharedWorkspaceLockfileandunsafePermthat described the inverse of the actual behavior are fixed, the npm-onlystagestub is now hidden, and several dead documentation anchors, aminimumReleaseAgeunit error, and a missing FFI header declaration are corrected.Full Changelog: aubepkg/aube@v2.2.4...v2.2.5
💚 Sponsor aube
aube is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.
v2.2.4: : Trust the lockfile, skip the revalidationCompare Source
A small but impactful release: aube now treats versions recorded in your lockfile as already-accepted trust decisions, eliminating a costly per-package metadata re-fetch on frozen and repeat installs. In benchmarking this cut a cold install with a frozen lockfile by roughly 62% (from ~7.1s to ~2.7s), with lockfile trust resolution dropping from ~5.7s to ~15ms.
Fixed
trustPolicy=no-downgrade(the default), aube previously re-fetched publishing trust evidence for every package name in the lockfile on each install, which dominated cold-install time. Nowno-downgradeis enforced only when a version is newly resolved; versions already present in the active lockfile are trusted without re-fetching their evidence. Integrity checks and the rest of the install-time security pipeline are unchanged, andparanoidstill forces the full pipeline.Behavior Notes
no-downgradeas before. See the updated security docs for details on the lockfile trust boundary.Full Changelog: aubepkg/aube@v2.2.3...v2.2.4
💚 Sponsor aube
aube is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.
If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.
v2.2.3: : Land the ARM64 PGO Binary on the HostCompare Source
Another small release-plumbing patch that continues fixing the ARM64 Linux PGO build. The writable-home fix from v2.2.2 let the build complete, but Namespace mounts the cached
targetdirectory as a separate mount that the parent workspace bind didn't expose inside Docker — so the finished binary was stranded in a container-only tree and later host steps couldn't find it. This release wires that mount through so ARM64 builds can validate and publish. There are no user-facing changes to aube itself.Fixed
$GITHUB_WORKSPACE/targetto/workspace/target, so the PGO+BOLT output and the Namespace-cached target directory are the same on the host. This lets the glibc validation, archive, and upload/attest steps find the built binary.Full Changelog: aubepkg/aube@v2.2.2...v2.2.3
💚 Sponsor aube
aube is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.
If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.
v2.2.2: : Unblock ARM64 PGO release buildsCompare Source
A tiny release-plumbing patch. The v2.2.1 ARM64 Linux PGO build failed because
HOME=/tmp/aube-homewas backed only by nested Docker mounts, leaving the home directory itself root-owned and unwritable, so mise couldn't create its state directory. This release fixes the workflow so those builds can publish. There are no user-facing changes to aube itself.Fixed
/tmp/aube-home(with the Cargo registry and git caches nested inside), so the non-root container user can write mise state and Cargo metadata during the build.Full Changelog: aubepkg/aube@v2.2.1...v2.2.2
💚 Sponsor aube
aube is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.
If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.
v2.2.1: : Install path self-healing and cold-install speedupsCompare Source
A patch release focused on the install path: several fixes make
aube installrecover from stale caches and links on its own, node-gyp shims stay correct after dependency builds, peer resolution more closely matches pnpm, and cold/repeat installs on large repos get meaningfully faster.Fixed
.binwrappers as healthy after their virtual-store targets are gone. A cache hit is now accepted only when the decoded wrapper's target still exists, so deleting the global virtual store triggers a clean re-bootstrap instead of returning a brokennode-gyppath.aube installcould fail repeatedly withfailed to link node_moduleswhen anode_modules/.aube/<dep>entry still resolved but pointed at an outdated virtual-store subdir. The fetch phase now verifies the resolved target against the subdir the current graph expects, so a mismatched entry is re-fetched and the install recovers on the next run.node_modules/.binshims after dependency builds and side-effects-cache restores, while preserving lifecycle-created replacements, so shims reflect the final binaries before root scripts or user commands run.autoInstallPeers, only an importer's own required peers (respectingpeerDependenciesMeta.optional) are seeded as direct dependencies and linked at the workspace root; peers required by transitive dependencies stay in their peer context instead of getting synthetic importer rows and top-level links. Frozen-lockfile drift checks accept pnpm-generated importer peers and rewrite legacy Aube hoists, andaube checknow reports a newdanglingissue (human-readable and JSON) when an importer's virtual-store cell is missing.Performance
trustPolicy=no-downgrade, lockfile validation no longer downloads and re-serializes full packuments for every locked package. It now fetches one compact trust history per registry name, decodes only what the check reads, and caches it undertrust-history-v1/. On the benchmark fixture this cut on-disk cache from 739 MB to 381 MB and shaved the resolve phase from 6.1s to 5.4s. Online installs can also skip re-validation via a lockfile-content stamp when validation would have been a cache hit anyway.state.jsonin finalize, an early exit in project-link detection, a(size, mtime)fast path for the root lockfile on everyaube run/exec/teststartup, and compact JSON forstate.json/fresh.json. Measured at −2.33% install instructions with no regressions.Full Changelog: aubepkg/aube@v2.2.0...v2.2.1
💚 Sponsor aube
aube is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.
If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.
v2.2.0: : Bundled compatibility catalog and embeddable node-gyp bootstrapCompare Source
A small release that gives standalone aube a bundled package-extensions compatibility catalog and exposes its node-gyp bootstrap through the public embedding facade.
Added
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.