Skip to content

chore(deps): update dependency aube to v2 - #48

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/aube-2.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/aube-2.x

Conversation

@renovate

@renovate renovate Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
aube tools major 1.25.0 → 2.6.1

Release Notes

jdx/aube (aube)

v2.6.1: : Maintenance release

Compare Source

The commit range for this release has no user-facing changes.

Full Changelog: aubepkg/aube@bd94e42...v2.6.1

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.6.0: : Maintenance release

Compare Source

There are no user-facing changes in the commit range for this release.

Full Changelog: aubepkg/aube@f43833c...v2.6.0

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.5.1: : Faster repeated fresh installs and faster startup on Linux

Compare Source

Repeated fresh installs skip redundant OSV lookups, and the Linux release binaries start a little faster.

Changed

  • Faster repeated fresh installs (#​1631 by @​jdx): When the OSV Bloom filter flags a package that turns out to have no malicious advisory, aube used to confirm it with a live OSV query on every install. That added about 220–250 ms each time. aube now caches a clean result for 30 seconds. A cached result is reused only when both the exact package/version pairs and the validated Bloom filter match. On a warmed Svelte fixture, installing with node_modules and aube-lock.yaml removed went from a 346 ms median to 107 ms.
    • Failed OSV queries, failed Bloom filter refreshes and confirmed malicious hits are never cached.
    • Explicit add/update/dlx checks, advisoryCheck = required and advisoryCheckEveryInstall = true still query OSV live every time.
    • Tradeoff: if a malicious-package advisory is published for a version that was just cleared, a repeated ordinary install may take up to 30 seconds to catch it.
  • About 0.6 ms faster startup on Linux (#​1625 by @​jdx): The Linux GNU release binaries (x86_64 and aarch64) for aube, aubr and aubx are now linked as non-PIE. The loader no longer has to patch about 56k pointers at each launch, so aube --version drops from about 2.2 ms to 1.6 ms.
    • Tradeoff: ASLR no longer randomizes aube's own code and data. The heap, stack and shared libraries are still randomized.
    • musl, macOS and Windows builds are unchanged, as are cargo install, source builds and the PPA/COPR packages.

Full Changelog: aubepkg/aube@98be8d1...v2.5.1

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.5.0: : Choose range or latest per package in aube update --interactive

Compare Source

aube update --interactive now lets you pick, for each package, whether to keep the current version, move to the newest version its range allows, or jump to latest. Repeated frozen installs and fresh installs without a lockfile are also faster, and a reinstall that failed after you deleted the cache and lockfile now works.

Added

  • Per-package version choice in aube update --interactive (#​1612 by @​jdx): The picker used to be one checkbox per dependency, with the target set by flags. It is now a table, like Yarn Berry's upgrade-interactive. Each row shows the current version, the newest version the range allows, and the registry's latest. Use ↑/↓ to move between rows and ←/→ to choose a version. Rows left on Current are skipped, and / filters by name. Closes #​1611.

    $ aube update -i
    Choose which dependencies to update
                  Current     Range      Latest
     > chalk      [•] ^4.1.2             [ ] ^6.0.0
       is-number  [•] ^6.0.0             [ ] ^7.0.0
       ms         [ ] 2.0.0   [•] 2.1.3
       semver     [ ] 7.5.0   [•] 7.8.5
    ↑/↓/k/j up/down • ←/→/h/l choose • / filter • enter confirm
    
    • Rows start on Range, or on Latest with --latest. Pressing Enter right away does the same thing as the non-interactive command.
    • Updates keep the manifest's range operator. Exact pins are now listed: each one is offered the newest release its caret range would allow, and it stays an exact pin after the update. -E still forces exact pins.
    • --no-save hides Latest and pin bumps, because both would rewrite package.json.
    • Latest is offered only when it is newer than the installed version, so the picker never offers a downgrade.
    • With update -r -i, the version you choose for a shared catalog entry is used for later workspace packages without asking again.
    • Rows no longer show the dependency section (dependencies / devDependencies).

Changed

  • Faster repeated frozen installs (#​1615 by @​jdx): Standalone projects can now reuse the installed state when nothing has changed. This applies to projects with registry dependencies and no declared patches, installed with an explicit --frozen-lockfile and lifecycle scripts disabled (for example aube install --frozen-lockfile --offline --ignore-scripts). On the benchmark fixture, a no-op install went from about 82 ms to about 7 ms. The freshness check hashes the lockfile and manifest contents, so a change is caught even when file size and modification time stay the same. A missing dependency link also counts as a change. Workspaces, patches, local sources, enabled scripts, custom lockfile locations and active per-install advisory policies still go through full validation.
  • Faster advisory checks on fresh installs (#​1616 by @​jdx): A fresh install without a lockfile used to query OSV for every resolved public-npm package. Under the default advisoryCheck: on, graphs with more than 10 distinct package/version pairs are now screened with the advisory Bloom filter first, and only probable hits are checked against the live API. On the benchmark fixtures this cut fresh install time by 36–67%.
    • Full live checks are still used for smaller graphs, for explicit aube add / aube update, for transient aube dlx installs, and with advisoryCheck: required or advisoryCheckEveryInstall: true.
    • If the filter can't be refreshed or validated, every package is checked live.
    • The filter cache refreshes every 15 minutes, so a newly published advisory may take up to that long to be caught.

Fixed

  • "missing package index" after deleting the cache and lockfile (#​1613 by @​jdx): A reinstall could fail with this error if you had deleted aube's cache/store and the root lockfile but kept node_modules. Now an existing package directory is reused only when its dependency subtree matches the previous install and the directory still exists. Anything else is looked up in the store again, or downloaded again, before linking.

Full Changelog: aubepkg/aube@d79acaa...v2.5.0

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.4.0: : Reuse node_modules/.aube-lock.yaml when the lockfile is missing

Compare Source

aube install can now rebuild a deleted lockfile from a hidden copy kept in node_modules, so it doesn't re-resolve from the registry. This release also makes cold installs on Linux faster and lighter on memory, and fixes lifecycle scripts on Windows and a workspace aube update that could drop members from the lockfile.

Added

  • Hidden lockfile in node_modules (#​1594 by @​jdx): Every install now writes a copy of the resolved graph to node_modules/.aube-lock.yaml. If the project has no lockfile of any supported kind, aube install starts from that copy, as pnpm does with its current lockfile. If the manifests haven't changed, the graph is reused with no resolve. If they have changed, only the specs that changed are resolved again, and the other packages keep their locked versions. aube-lock.yaml is then written again.

    $ aube install      # writes aube-lock.yaml + node_modules/.aube-lock.yaml
    $ rm aube-lock.yaml
    $ aube install      # seeds from node_modules/.aube-lock.yaml, no registry resolve
    • --frozen-lockfile and aube ci still fail when there is no lockfile.
    • --no-frozen-lockfile ignores the hidden copy.
    • In auto-CI mode (CI=true with no explicit flags), an install that seeds from the hidden copy is treated as prefer-frozen.
    • If the hidden copy is broken, aube shows WARN_AUBE_HIDDEN_LOCKFILE_BROKEN and resolves normally.
    • The hidden copy is not used with lockfile=false, which also deletes any existing copy, or with sharedWorkspaceLockfile=false. It is also skipped for reuse installs from npm, yarn or bun lockfiles.

Changed

  • Faster, lighter cold installs on Linux (#​1598, #​1603, #​1604, #​1605 by @​jdx):
    • On Linux, the blocking thread pool now defaults to 8 threads instead of 128. On the benchmark fixture this cut peak memory from about 1.5 GB to about 400 MB and reduced kernel CPU time. AUBE_TOKIO_BLOCKING still overrides the default, and macOS and Windows keep 128.
    • Small tarballs (up to 1 MiB) are downloaded in full before their store import begins, so an import no longer ties up a thread while it waits on the network. Memory for these buffered downloads is capped at 64 MiB in total.
    • Installs with the global virtual store no longer read back dependency links they just wrote.

Fixed

  • Windows lifecycle scripts failing with EISDIR: illegal operation on a directory, lstat 'C:' (#​1591 by @​jdx): This affected scripts that start node through a .bin shim (for example node-gyp-build) during aube add, remove, update, dedupe and ci, and during installs from embedding hosts such as mise's npm: backend. The install root and the Node-API embedding's project directory no longer carry the \\?\ verbatim prefix. Fixes #​1590.
  • aube update at a workspace root dropping workspace members from aube-lock.yaml (#​1579 by @​jdx): With a shared lockfile, running aube update or aube update -w at the root could delete every workspace member's entry in aube-lock.yaml. Member entries, their packages, patch hashes and catalog snapshots are now kept, and only the root's direct dependencies are updated. aube install also treats a workspace member that declares dependencies but has no entry in the lockfile as stale, so installing again repairs lockfiles already damaged by this bug.

Full Changelog: aubepkg/aube@v2.3.0...v2.4.0

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.3.0: : Host-bound Node launchers for embedders, plus hoisted .bin, lockfile patch-hash, and terminal-cleanup fixes

Compare Source

Embedding hosts such as mise can now bind installed Node CLIs to a specific Node executable, and a batch of fixes covers hoisted-install bin linking, aube-lock.yaml patch hashes, ignoreScripts resolution, signal delivery in dlx --shell-mode, and terminal state after failed or interrupted installs.

Added

  • Bind installed CLIs to a host-managed Node runtime (#​1576 by @​jdx) — Installed Node CLIs previously found their interpreter through the caller's PATH, so a tool manager could not give an application its own runtime without also changing which Node its project subprocesses see. EmbedderRuntime::bind_bins_to generates launchers that invoke the supplied absolute Node executable directly while leaving the inherited PATH unchanged; it works with both embedded install and add:

    let mut options = aube::embed::InstallOptions::new("/tools/my-cli");
    options.runtime = Some(
        aube::embed::EmbedderRuntime::selector("/runtimes/node/25/bin")
            .bind_bins_to("/runtimes/node/25/bin/node"),
    );
    aube::embed::install(options).await?;

    The path is kept as written (symlinks are not canonicalized), so a moving major-version path like mise's installs/node/25/bin/node works; a missing runtime fails rather than falling back to ambient Node. Changing or removing the binding regenerates launchers on the next install, including frozen ones. Bound installs always materialize locally and disable the global virtual store so runtime-specific launchers stay out of shared trees. Simple Node shebang flags are preserved; quoted shebang arguments and environment assignments are rejected. Standalone aube's runtime selection is unchanged — this is the launcher support a host needs to implement its own policy (see jdx/mise#13477).

Fixed

  • Hoisted installs link transitive dependency bins (#​1548 by @​jdx) — With --node-linker=hoisted, only importers' direct dependencies were linked into node_modules/.bin, so packages whose lifecycle scripts call a binary from their own dependencies failed with errors like sh: node-pre-gyp: command not found (bcrypt, prebuild-install, napi-postinstall; see discussion #​1543). Hoisted installs now follow npm's rule: each package's bins are linked into the .bin/ of the node_modules/ it sits in, and a dependency's lifecycle script sees its own nested .bin first so a version conflict no longer silently runs the hoisted winner. An importer's own bin and its direct dependencies always take precedence over transitive packages on a name collision. Isolated installs are unaffected.
  • aube rebuild relinks the full bin surface (#​1550 by @​jdx) — rebuild only relinked per-dependency shims, so a command added or retargeted in package.json#bin after install stayed missing or stale until the next aube install. rebuild now uses the same bin-linking entry point as install (importer bins, workspace member bins, then dependency bins). If a workspace member manifest is unreadable, it warns and reconciles the root importer instead of aborting. aube rebuild --filter <member> is not covered by this change.
  • ignoreScripts is honored from env, .npmrc, and aube-workspace.yaml (#​1552 by @​jdx, fixes #​1551) — Only the --ignore-scripts flag reached the installer; AUBE_IGNORE_SCRIPTS, npm_config_ignore_scripts, ignore-scripts=true in .npmrc, and ignoreScripts: true in the workspace yaml were parsed and then discarded, so aube config get ignore-scripts printed true while the next install ran scripts anyway. All sources now apply across install, ci, add, remove, update (including its pnpm:devPreinstall hook), dlx, deploy, and the auto-install aube run performs on a stale tree — which previously had no way to skip scripts at all. An explicit flag still wins over a lower-precedence false. pack, publish, and version keep their own --ignore-scripts flags.
  • aube-lock.yaml keeps patch hashes on re-resolve (#​1577 by @​jdx) — In a project with patchedDependencies, running aube add dropped the (patch_hash=…) suffix from patched entries in aube-lock.yaml, producing a spurious lockfile diff on every add and a node_modules/.aube/ directory name that varied by how the lockfile was produced (reported in jdx/mise#13456). aube-lock.yaml now records patch identities the same way pnpm-lock.yaml does — a top-level patchedDependencies: map and (patch_hash=…) in entry names — consistently after install, add, and import, and a plain aube install now detects edited, added, or removed patches. Upgrade note: existing hashless aube-lock.yaml files still pass --frozen-lockfile unchanged; the next non-frozen install or add records the hashes as a one-time diff. Projects without patches are unaffected.
  • Lifecycle scripts get a working npm_execpath when aube is embedded (#​1565 by @​jdx) — Embedded aube set npm_execpath to the host's binary, so a package running ${npm_execpath} run verify-build (e.g. install-artifact-from-github, used by re2) invoked the host's own CLI and failed, causing a needless source build or a failed install (jdx/mise#13451). Embedded aube now exports a shim that re-enters aube's CLI through the host via a private __aube-cli argv token (embed::CLI_TRAMPOLINE_ARG); hosts dispatch it the same way as the existing node-gyp trampoline, and docs/embedding/rust.md now documents both. If the shim cannot be written, npm_execpath is left unset rather than naming the host. AUBE_CLI_EXE is new in the lifecycle environment, and an inherited outer npm_execpath is now cleared before stamping. Standalone aube is unchanged.
  • aube dlx --shell-mode delivers termination signals to the tool (#​1562 by @​jdx) — Signaling an aube dlx --shell-mode (or aubx -c) process stopped at the intermediate sh -c, leaving the tool running and aube hung waiting on it. A shell-mode line that is a single plain command now runs without a shell (using the same strict allowlist as aube run), so the tool is aube's direct child, receives the forwarded signal, and its exit code propagates. Pipelines, redirects, expansions, quoting, and shell builtins still run under sh with unchanged behavior, and the --shell-mode help text now describes this contract.
  • Terminal state is restored when an install fails, is interrupted, or panics (#​1559, #​1560 by @​jdx) — A failing install (trust-policy rejection, unresolvable dependency, network error) exited without retiring the progress renderer, leaving the cursor hidden and the OSC 9;4 taskbar indicator lit in iTerm2, Ghostty, and VS Code (discussions #​1557 and #​1558). Every error path now restores both before the diagnostic prints, and while the progress bar is active aube also handles SIGINT/SIGTERM/SIGHUP/SIGQUIT and panics to restore the terminal before re-raising — Ctrl-C still exits 130. Signals already ignored or handled (e.g. under nohup, or by an embedding host) are left alone. Windows gets the panic restore but not the signal handling.

Full Changelog: aubepkg/aube@v2.2.17...v2.3.0

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.17: : Maintenance release

Compare Source

This release only refreshes Cargo.lock dependencies and contains no user-facing changes.

Full Changelog: aubepkg/aube@v2.2.16...v2.2.17

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.16: : aube add installs local tarballs by their manifest name

Compare Source

aube add ./package.tgz now records the package under the name declared in the tarball's package.json, and local file: / link: / portal: dependencies now install their optionalDependencies.

Fixed

  • Local tarballs are added by manifest name, not filename (#​1532 by @​jdx) — Downloaded npm artifacts are commonly named package.tgz, and aube add previously derived the dependency key from that filename, producing a bogus "package": "file:./package.tgz" entry alongside any existing dependency on the real package. For an unaliased local tarball or directory, aube add now reads package.json#name and uses it as the key, so the add replaces an existing dependency on the same package instead of adding a second one. Explicit aliases (aube add alias@file:./package.tgz) remain authoritative, and a local package whose manifest has no name is now rejected with an error. This fixes Bun checksum installs through mise (jdx/mise#13125), which download the verified artifact as package.tgz.
  • Local packages install their optionalDependencies (#​1532 by @​jdx) — file:, link:, and portal: directory and tarball dependencies previously only resolved dependencies, so optional platform packages declared by a local package (such as Bun's per-platform binaries) were silently dropped. They are now resolved and linked under the local package, honoring ignoredOptionalDependencies and blockExoticSubdeps, and skipping any optional dependency already listed under dependencies so it is not installed twice.

Full Changelog: aubepkg/aube@v2.2.15...v2.2.16

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.15: : Embedded aube add confirmations distinguish "unavailable" from "declined"

Compare Source

Embedding hosts can now tell aube that an install confirmation could not be shown, instead of being forced to report it as a user abort.

Fixed

  • Unavailable embedded confirmations no longer look like user aborts (#​1530 by @​jdx) — The aube add reputation gates (low downloads, newly published names, similar names) previously asked embedded hosts for a boolean answer. A host that could not present a prompt had to return false, which aube reported as an explicit user abort and could invent a host command such as mise add in the diagnostic. A new, backward-compatible tri-state API lets hosts answer Accept, Decline, or Unavailable:

    use aube::embed::{InstallControl, InstallPromptDecision, InstallPromptDecisionHandler};
    
    let control = InstallControl::silent().with_prompt_decision_handler(handler);

    Unavailable returns the gate's normal structured refusal with its stable error code and remediation; Decline now produces user declined to add <name> without referencing the embedding process. Existing InstallPromptHandler implementations keep working, with false treated as an explicit decline.

  • Gate remediation moved into structured diagnostic help (#​1530 by @​jdx) — The --allow-low-downloads / lowDownloadThreshold / minimumPackageAge hints for the three gates are now attached as diagnostic help rather than embedded in the message text, so embedders can replace them with host-native guidance while keeping the measured reason and error code.

Full Changelog: aubepkg/aube@v2.2.14...v2.2.15

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.14: : Match GHSA IDs found in advisory URLs

Compare Source

This is a small bug-fix release with a single user-facing change to aube audit.

Fixed

  • Audit ignores now match GHSA IDs exposed only in advisory URLs (#​1517 by @​typevolant) — Some npm bulk advisory responses expose the GHSA identifier only in the url field (e.g. an advisory whose URL ends in GHSA-w3rx-r6r6-pgpr), so advisories like GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq were still reported even when passed to --ignore or listed under audit.ignore in a workspace's YAML. The matcher now extracts the trailing advisory ID from the URL and compares it using the existing case-insensitive exact match, correctly handling trailing slashes, query strings, and fragments.

New Contributors

Full Changelog: aubepkg/aube@v2.2.13...v2.2.14

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.13: : Documentation & Site Overhaul

Compare Source

This is a documentation-focused release. There are no functional changes to the aube binary — the work is a broad refresh of the guides, CLI references, and documentation site.

Changed

  • Overhauled guides and site design (#​1503 by @​jdx) — Reworked the README and onboarding, migration, configuration, security, troubleshooting, and embedding guides, added CI and container guidance, and redesigned the landing page with improved typography, responsive layouts, and light/dark themes. All 105 generated CLI pages now include examples and navigation, and the settings reference was improved. The generators were updated so these improvements survive regeneration.
  • Fixed misleading --ignore-scripts help text (#​1503 by @​jdx) — The help text for --ignore-scripts now accurately describes its behavior, alongside corrections to build-script policy, jail limitations, lockfile compatibility, and command examples throughout the docs.

Full Changelog: aubepkg/aube@v2.2.12...v2.2.13

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.12: : Housekeeping

Compare Source

This is a maintenance-only release. There are no user-facing changes since v2.2.11 — the only change is an internal CodeRabbit configuration update following the repository transfer to the aubepkg organization.

Full Changelog: aubepkg/aube@v2.2.11...v2.2.12

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.11: : Housekeeping release

Compare Source

This is a small housekeeping release cut immediately after v2.2.10. There are no new user-facing changes since v2.2.10 — the two aube config fixes listed below already shipped in that release and are carried forward here for completeness.

Fixed

Both of these first shipped in v2.2.10.

  • Redact credentials from config output (#​1483 by @​jdx) — aube config list (text and --json) and aube config set render authentication fields such as _authToken, username, password, key, and email as (protected) instead of echoing the secret, and embedded URL credentials are masked. Secrets are still written to disk as expected — only the terminal output is redacted.

  • Preserve comments and ordering in config.toml (#​1480 by @​jdx) — Config edits go through toml_edit instead of rebuilding the file from a semantic map, so comments, whitespace, quoting, and setting order survive a config set.

Full Changelog: aubepkg/aube@v2.2.10...v2.2.11

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.10: : Safer, tidier config editing

Compare Source

A small release focused on aube config: credentials are now redacted from command output, and editing config.toml no longer clobbers your formatting.

Fixed

  • Redact credentials from config output (#​1483 by @​jdx) — aube config list (text and --json) and aube config set now render authentication fields such as _authToken, username, password, key, and email as (protected) instead of echoing the secret. Embedded URL credentials in values like proxies are masked (userinfo is replaced with ***), while non-secret URLs still display normally. Secrets are still written to disk as expected — only the terminal output is redacted.

  • Preserve comments and ordering in config.toml (#​1480 by @​jdx) — Config edits now go through toml_edit instead of rebuilding the file from a semantic map, so your comments, whitespace, quoting, multiline array formatting, and setting order survive a config set. Updated settings keep their existing formatting and genuinely new settings are appended.

Full Changelog: aubepkg/aube@v2.2.9...v2.2.10

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.9: : Restore the ARM64 release build

Compare Source

A small release that fixes aube's ARM64 release build so the aarch64-unknown-linux-gnu artifact ships again.

Fixed

  • Create the ARM64 target directory before Docker mounts it (#​1478 by @​jdx) — Docker creates a missing bind-mount source as root, but the ARM64 release job runs its container as the runner user, so benchmarks/pgo.bash couldn't write target/pgo-data and the PGO build failed. The workspace target directory is now created up front as the runner user (with a writability check before PGO starts), restoring the ARM64 release artifact.

Full Changelog: aubepkg/aube@v2.2.8...v2.2.9

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.8: : Dependency refresh

Compare Source

A small maintenance release. There are no user-facing changes — this release only refreshes pinned dependency versions in Cargo.lock.

Changed

  • Updated Cargo.lock dependencies to their latest compatible versions. No behavior changes for users.

Full Changelog: aubepkg/aube@v2.2.7...v2.2.8

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.7: : Unblock the ARM64 release build

Compare Source

A small release that fixes aube's ARM64 release build so the aarch64-unknown-linux-gnu artifact ships again.

Fixed

  • Remove stray mbx check from the ARM64 release image (#​1473 by @​jdx) — The ARM64 PGO release container ran a mbx --version verification step even though its scoped mise configuration only installs Node and Rust. That check failed the build and blocked the aarch64-unknown-linux-gnu artifact and the final publish gate. The verification is now aligned with the image's actual toolchain, restoring the ARM64 release.

Full Changelog: aubepkg/aube@v2.2.6...v2.2.7

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.6: : Restore ARM64 glibc compatibility

Compare Source

A small release that restores broad glibc compatibility for aube's ARM64 builds.

Fixed

  • Restore Focal ARM64 build image (#​1470 by @​jdx) — The ARM64 release container had been inadvertently bumped to Ubuntu 26.04, which built against a newer glibc and broke compatibility with older Linux systems. The build base is back on Ubuntu 20.04 (Focal) with glibc 2.31, and Renovate is now pinned to the Focal tag for this image so future updates won't reintroduce the regression.

Full Changelog: aubepkg/aube@v2.2.5...v2.2.6

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.5: : Moving to aube.sh with a faster Linux store path

Compare Source

A modest release: aube's home moves to aubepkg/aube and the new aube.sh domain, the Linux content-addressed store gains a direct-write fast path when it holds the install lock, and the CLI help and docs get a substantial accuracy pass.

Changed

  • Project moved to aubepkg/aube and aube.sh (#​1460 by @​jdx) — Public documentation and the built-in update-check URLs now point at aube.sh instead of aube.jdx.dev, and canonical repository, release, package, and support links reflect the transfer to aubepkg/aube. If you have bookmarks, scripts, or configuration referencing the old domain or repo, update them to the new locations.

Performance

  • Direct-write Linux CAS under the install lock (#​1430 by @​jdx) — The exclusive-lock fast path that already existed on macOS now extends to Linux: when an install owns the store lock, new content-addressed objects are written straight to their final paths, skipping the O_TMPFILE+linkat publication step. Atomic publication is retained whenever another installer holds the lock, and torn-entry recovery now acquires and rechecks under the same cross-process lock before unlinking, backed by new regression tests. Benchmarks show a modest ~1.3% wall-time and ~3.3% system-CPU reduction on cold installs.

Fixed

  • Documentation and CLI help accuracy pass (#​1455 by @​jdx) — A broad prose and content cleanup that removes internal implementation names (clap, tokio, reqwest, Rust types) from user-facing help, and corrects several factual details, including the --network-concurrency default range (16–128, not 16–64), the virtual-store path in --disable-gvs help, and the full list of commands honoring --filter (outdated, query, rebuild). Settings summaries for sharedWorkspaceLockfile and unsafePerm that described the inverse of the actual behavior are fixed, the npm-only stage stub is now hidden, and several dead documentation anchors, a minimumReleaseAge unit error, and a missing FFI header declaration are corrected.

Full Changelog: aubepkg/aube@v2.2.4...v2.2.5

💚 Sponsor aube

aube is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If aube saves your team install time or CI minutes, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep aube fast, free, and independent.

v2.2.4: : Trust the lockfile, skip the revalidation

Compare Source

A small but impactful release: aube now treats versions recorded in your lockfile as already-accepted trust decisions, eliminating a costly per-package metadata re-fetch on frozen and repeat installs. In benchmarking this cut a cold install with a frozen lockfile by roughly 62% (from ~7.1s to ~2.7s), with lockfile trust resolution dropping from ~5.7s to ~15ms.

Fixed

  • Trust locked packages without revalidation (#​1418 by @​jdx) — With trustPolicy=no-downgrade (the default), aube previously re-fetched publishing trust evidence for every package name in the lockfile on each install, which dominated cold-install time. Now no-downgrade is enforced only when a version is newly resolved; versions already present in the active lockfile are trusted without re-fetching their evidence. Integrity checks and the rest of the install-time security pipeline are unchanged, and paranoid still forces the full pipeline.

Behavior Notes

  • Trust downgrade detection for a locked version no longer re-runs on every reuse — it applies when the version is first resolved. A fresh resolve (e.g. a new or changed dependency) still enforces no-downgrade as before. See the updated security docs for details on the lockfile trust boundary.

Full Changelog: aubepkg/aube@v2.2.3...v2.2.4

💚 Sponsor aube

aube is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.

If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.

v2.2.3: : Land the ARM64 PGO Binary on the Host

Compare Source

Another small release-plumbing patch that continues fixing the ARM64 Linux PGO build. The writable-home fix from v2.2.2 let the build complete, but Namespace mounts the cached target directory as a separate mount that the parent workspace bind didn't expose inside Docker — so the finished binary was stranded in a container-only tree and later host steps couldn't find it. This release wires that mount through so ARM64 builds can validate and publish. There are no user-facing changes to aube itself.

Fixed

  • Mount the cached ARM64 build target into the container (#​1412 by @​jdx) — The ARM64 PGO container now explicitly bind-mounts $GITHUB_WORKSPACE/target to /workspace/target, so the PGO+BOLT output and the Namespace-cached target directory are the same on the host. This lets the glibc validation, archive, and upload/attest steps find the built binary.

Full Changelog: aubepkg/aube@v2.2.2...v2.2.3

💚 Sponsor aube

aube is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.

If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.

v2.2.2: : Unblock ARM64 PGO release builds

Compare Source

A tiny release-plumbing patch. The v2.2.1 ARM64 Linux PGO build failed because HOME=/tmp/aube-home was backed only by nested Docker mounts, leaving the home directory itself root-owned and unwritable, so mise couldn't create its state directory. This release fixes the workflow so those builds can publish. There are no user-facing changes to aube itself.

Fixed

  • Mount a writable home for ARM64 PGO builds (#​1409 by @​jdx) — The ARM64 PGO release container now bind-mounts a runner-owned writable home at /tmp/aube-home (with the Cargo registry and git caches nested inside), so the non-root container user can write mise state and Cargo metadata during the build.

Full Changelog: aubepkg/aube@v2.2.1...v2.2.2

💚 Sponsor aube

aube is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.

If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.

v2.2.1: : Install path self-healing and cold-install speedups

Compare Source

A patch release focused on the install path: several fixes make aube install recover from stale caches and links on its own, node-gyp shims stay correct after dependency builds, peer resolution more closely matches pnpm, and cold/repeat installs on large repos get meaningfully faster.

Fixed

  • Self-heal stale node-gyp caches (#​1407 by @​jdx) — The node-gyp bootstrap cache no longer treats leftover .bin wrappers as healthy after their virtual-store targets are gone. A cache hit is now accepted only when the decoded wrapper's target still exists, so deleting the global virtual store triggers a clean re-bootstrap instead of returning a broken node-gyp path.
  • Self-heal stale links on non-workspace installs (#​1406 by @​jdx) — A non-workspace aube install could fail repeatedly with failed to link node_modules when a node_modules/.aube/<dep> entry still resolved but pointed at an outdated virtual-store subdir. The fetch phase now verifies the resolved target against the subdir the current graph expects, so a mismatched entry is re-fetched and the install recovers on the next run.
  • Refresh bin shims after dependency builds (#​1404 by @​jdx) — Approved dependency lifecycle scripts can change what a bin actually is (for example, pnpm 12's preinstall swaps a text placeholder for a native executable). Aube now relinks node_modules/.bin shims after dependency builds and side-effects-cache restores, while preserving lifecycle-created replacements, so shims reflect the final binaries before root scripts or user commands run.
  • Match pnpm importer peer semantics (#​1399 by @​jdx) — With autoInstallPeers, only an importer's own required peers (respecting peerDependenciesMeta.optional) are seeded as direct dependencies and linked at the workspace root; peers required by transitive dependencies stay in their peer context instead of getting synthetic importer rows and top-level links. Frozen-lockfile drift checks accept pnpm-generated importer peers and rewrite legacy Aube hoists, and aube check now reports a new dangling issue (human-readable and JSON) when an importer's virtual-store cell is missing.

Performance

  • Faster cold installs under the default trust policy (#​1403 by @​jdx) — With the default trustPolicy=no-downgrade, lockfile validation no longer downloads and re-serializes full packuments for every locked package. It now fetches one compact trust history per registry name, decodes only what the check reads, and caches it under trust-history-v1/. On the benchmark fixture this cut on-disk cache from 739 MB to 381 MB and shaved the resolve phase from 6.1s to 5.4s. Online installs can also skip re-validation via a lockfile-content stamp when validation would have been a cache hit anyway.
  • Cut freshness and repeat-install overhead on large repos (#​1400 by @​jdx) — Several structural costs behind slow no-op/repeat installs on big monorepos were removed: parallelized virtual-store link scans, a single parse of state.json in finalize, an early exit in project-link detection, a (size, mtime) fast path for the root lockfile on every aube run/exec/test startup, and compact JSON for state.json/fresh.json. Measured at −2.33% install instructions with no regressions.

Full Changelog: aubepkg/aube@v2.2.0...v2.2.1

💚 Sponsor aube

aube is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise. Work on aube is funded by sponsors.

If aube is saving your team install time or CI minutes, please consider sponsoring at jdx.dev. Individual and company sponsorships are what keep the project fast, free, and independent.

v2.2.0: : Bundled compatibility catalog and embeddable node-gyp bootstrap

Compare Source

A small release that gives standalone aube a bundled package-extensions compatibility catalog and exposes its node-gyp bootstrap through the public embedding facade.

Added

  • Embeddable node-gyp bootstrap (#​1365 by @​jdx) — aube's locked, in-process node-gyp bootstrap is now available through the stable embedding facade and returns the resolved executable path. This lets embedders (e.g. mise) service aube's lazy shim command without an ambient `npm

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 12pm on Sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from RedStar071 as a code owner August 30, 2026 00:50
@renovate
renovate Bot force-pushed the renovate/aube-2.x branch 3 times, most recently from 61dacda to 804a2d3 Compare September 9, 2026 01:21
@renovate
renovate Bot force-pushed the renovate/aube-2.x branch from 804a2d3 to 51f7493 Compare September 12, 2026 17:43
@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

◈ PR Lens

Note

This drawing shows d38fa5b, and the branch has new commits since. Tick Redraw to draw the latest one

  • Redraw

🟢 +0 new · 🟠 ~1 changed · 🔴 -0 removed · 0 flows · 1 file · commit d38fa5b


Architecture

Architecture diagram for wolfstar-project/.github at d38fa5b

1 component touched across 1 lane.

Open the interactive canvas


Data flow

No data-flow sequence changed in this PR.


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Open a diagram on the canvas, then press W or click play to walk through the change one step at a time.

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists.
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds.
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through.
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change.
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time.
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs on every push.
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works.
  • Push a commit and the comment redraws for the new head. A slow older run never overwrites a newer one.
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion.

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@renovate
renovate Bot force-pushed the renovate/aube-2.x branch 4 times, most recently from 72dc90e to d38fa5b Compare September 18, 2026 20:48
@renovate
renovate Bot force-pushed the renovate/aube-2.x branch from d38fa5b to 6de4709 Compare September 25, 2026 21:08
@renovate
renovate Bot force-pushed the renovate/aube-2.x branch 4 times, most recently from 14185b7 to 3af6a59 Compare October 1, 2026 22:12
@renovate
renovate Bot force-pushed the renovate/aube-2.x branch from 3af6a59 to a70da31 Compare October 3, 2026 00:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant