Skip to content

chore(deps): update dependency jdx/mise to v2026 - #220

Open
renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x
Open

renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x

Conversation

@renovate

@renovate renovate Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update New value References Sourcegraph
jdx/mise uses-with major 2026.10.4 source code search for "jdx/mise"

Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.


Release Notes

jdx/mise (jdx/mise)

v2026.10.4: : Task-scoped fnox secrets, automatic global tool updates, and an opt-in identity install layout

Compare Source

This release adds experimental task-scoped secrets backed by fnox, automatic updates for global tools, and an experimental opt-in install layout that names installations by what they contain. It also adds dotfile merge entries, headers auth for the http: backend, npm installs from git, and a set of prune, install and lockfile fixes.

Added

Secrets (experimental)

These need mise settings experimental=true and fnox 1.39.0 or newer. They are refused in safe mode.

  • [secrets.fnox] and mise secrets ls. A project can name fnox as its secrets source in its own mise.toml. mise secrets ls lists key names and metadata but never values. -J prints JSON. Global, system and home-level [secrets] config is ignored, and mise doctor reports it. #​13967

  • Tasks get only the secrets they list. Add secrets = [...] to a task, or #MISE secrets=[...] in a file task header. Only that task gets the values, only while it runs, and they are redacted from its output. Dependencies, hooks, mise env, hook-env and shims get nothing. A task without grants never calls fnox. Tasks that list secrets need a trusted config, aren't artifact-cached, and ignore --raw unless the task sets raw or interactive. Hooks, watch_files, daemons and mise bootstrap can't run them, and remote or global-config tasks can't list secrets. #​13974

    min_version = "2026.10.4"   # older mise rejects `secrets` on a task
    
    [secrets.fnox]
    profile = "prod"
    
    [tasks.deploy]
    depends = ["build"]                       # build receives nothing
    secrets = ["DEPLOY_KEY", "DATABASE_URL"]
    run = "./deploy.sh"
  • One-off grants from the command line. --secrets KEY[,KEY] and --secrets-all work on mise run, mise tasks run and mise x. For mise run, only the tasks named on the command line get them, not their dependencies. mise x gets nothing unless you pass a flag, and it can't receive file secrets. Flags placed after the task name go to the task, and mise warns when that happens. #​13975

    mise run --secrets STRIPE_KEY deploy
    mise x --secrets GH_TOKEN -- gh release list
  • {{ secrets.X }} in task env values. A task can build an env var from a secret, for example env.PGURL = "postgres://app:{{ secrets.DB_PASSWORD }}@db/app". The reference counts as the grant. References are rejected in run, [env], [vars] and other fields. #​13978

  • fnox daemon cache. If the project's fnox config enables the daemon and it's running, an interactive run reads cached values over its socket without starting an fnox process. mise never starts the daemon itself. CI, non-TTY runs and Windows always use the fnox CLI. #​13979

Automatic global tool updates
  • auto_update for global tools. Set auto_update on a tool in your global config. When a shim or mise x is about to run that tool and its check interval is due, mise upgrades it within the configured range and then runs the new version. true uses the new tool_update.check_duration setting (default 24h), and a duration string sets that tool's own interval (minimum 1h). #​14026

    • Exact pins never update.
    • It never runs offline, in CI, with locked = true, from tasks or hook-env, or from project configs.
    • If an update fails, mise warns and runs the installed version. The failure shows in mise doctor.
    # ~/.config/mise/config.toml
    [tools]
    claude = { version = "latest", auto_update = true }
    node = { version = "22", auto_update = "6h" }   # newest 22.x, never 23
  • Background tool-update service. A built-in bootstrap service checks auto_update tools hourly, so launches don't wait for downloads and tools run directly from PATH under activation also stay current. It installs a systemd user unit, LaunchAgent or scheduled task. #​14040

    [bootstrap.services.mise-tool-update]
    builtin = "tool-update"
Identity install layout (experimental, opt-in)
  • install_layout = "identity". With experimental = true, each installation lives in installs/<label>-<hash>/. The hash covers the canonical backend, version, platform and install-affecting options. installs/<tool>/<version> becomes a link to that directory, a real junction on Windows. As a result: #​13951

    • age and aqua:FiloSottile/age share one installation.
    • Variants of one version with different options can exist side by side.
    • Windows IDEs can follow the version links.

    Existing installs keep working and aren't moved. Nothing changes unless you set this. MISE_INSTALL_LAYOUT=identity also turns it on. See the new install layout docs.

  • On Windows, identity-layout installations go into the shorter %LOCALAPPDATA%\mise\i\, while version links stay in installs\. MISE_INSTALL_STORE_DIR sets the location on any platform. #​13952

  • mise installs ls lists installations as selected, pinned or shared. mise installs select <dir> chooses which installation requests without a lockfile use. When several installations match and none is selected, mise lists them instead of guessing. #​13953

  • mise installs migrate [--dry-run] [TOOL[@VERSION]] reinstalls legacy installations into the new layout and leaves a link at the old path. If a run is interrupted, the next run recovers it. #​13955

  • In the layout, mise backends switch installs the new backend's version and points the link at it. mise where and the other commands now resolve versions named on the command line the same way, and mise where lists variants instead of picking one. #​13957

  • mise prune handles templated tool versions such as node = "{{ vars.node }}". It uses snapshots of what each project last rendered and keeps installs when it isn't sure they are unused. #​14025

Other additions
  • Dotfile merge entries. A merge = true entry sets only the keys from its source in a JSON, TOML or YAML file, and leaves keys added by the application (Codex, Claude Code, etc.) alone. TOML and YAML keep comments and formatting. mise dot status and mise dot diff only report drift in those keys. A target that doesn't parse is never overwritten. #​14012

    [dotfiles]
    "~/.codex/config.toml/shared" = { source = "codex/shared.toml", merge = true }
  • headers for the http: backend. You can now authenticate with bearer tokens or API keys, for example to download OCI blobs from ghcr.io. Values are templates. Headers are sent with downloads, version_list_url and checksum_url requests, and dropped on cross-host redirects unless the host is listed in headers_forward. Changing a token doesn't trigger a reinstall. #​14022

    [tools."http:polaris"]
    version = "0.9.2"
    headers = { Authorization = "Bearer {{ env.GITHUB_TOKEN | b64_encode }}" }
  • npm packages from git. git+ URLs and github:, gitlab: and bitbucket: specs now install. The version is a git ref, and latest is the default branch. #​14044

    mise use 'npm:github:owner/repo@v1.2.0'
  • settings.write_targets. Sends new global [tools], [bootstrap.packages] and [dotfiles] entries to separate conf.d files. Existing entries are updated where they're already declared. #​14018

    [settings.write_targets]
    tools = "~/.config/mise/conf.d/10-tools.toml"
    dotfiles = "~/.config/mise/conf.d/30-dotfiles.toml"
  • prune.exclude (or MISE_PRUNE_EXCLUDE) lists tools that mise prune, mise ls --prunable and upgrade pruning never remove. Short and full names both work, e.g. node or aqua:BurntSushi/ripgrep. #​14030

  • lockfile_auto_prune = false keeps lockfile entries for tools missing from the active config. This is useful when profiles share one lockfile. The default (true) keeps the current pruning behavior. #​13980

  • mise dot notify sends a test desktop notification, which also triggers the macOS permission prompt. mise doctor and mise dot status now show whether notifications can be delivered. #​14009

Changed

  • mise's own auto-update settings moved under self_update.*. auto_update is now self_update.auto (MISE_SELF_UPDATE_AUTO), and auto_update_check_duration is now self_update.check_duration (MISE_SELF_UPDATE_CHECK_DURATION). The old names keep working. The new key wins when both are set. Deprecation warnings start in 2027.4.0. Older mise versions ignore a settings file that has unknown self_update keys, so keep the old spelling if a config has to work with both. #​14038

  • mise prune, mise unuse --prune, mise ls --prunable and deferred pruning after an upgrade now keep any version a running process was started from, on Linux, macOS and Windows. They say which process kept it. #​14020

  • pypi:/pipx: tools installed with uv are now built on mise's Python when mise manages one. Previously uv could use its own downloaded interpreter, which broke CI caches that only restore the mise data dir. A package whose requires-python excludes mise's Python now fails; to override, pass --python in uvx_args. #​14024

  • With python.uv_venv_auto, mise install now creates the project venv with mise's Python instead of whatever uv found. #​13981 by @​halms

  • Inherited secrets: when a parent mise marks variables as secrets in __MISE_SECRET_KEYS, a nested mise now does the following #​13966:

    • redacts them from logs
    • hides them from templates, get_env() and exec()
    • disables the env cache
    • keeps them out of __MISE_DIFF, other tasks and pitchfork

    mise x and shims still pass them through.

Fixed

  • Install state
    • A failed tool-level postinstall hook no longer leaves its version listed as installed or selectable. The next install retries it. #​14037
    • Incomplete-install markers moved from the cache to $MISE_STATE_DIR, so mise cache clear no longer makes a half-installed version look installed. Existing markers are migrated. #​14051
  • Lockfiles and backends
    • mise install --locked now works for dotnet: tools. #​13971 by @​james-newell-forge
    • mise lock for pypi: tools on registries with a <root>/pypi/{}/json template, such as Artifactory, now uses <root>/simple/. #​14007 by @​deiga
    • Parallel cargo: installs that fall back to cargo install no longer corrupt the shared rustup toolchain. #​14042
    • mise upgrade --bump and mise outdated --bump no longer rewrite vendor-only requests like java = "temurin" to a bare version from another vendor. #​14031
    • A registry move within the same backend kind, such as vfox:mise-plugins/* to vfox:jdx/*, no longer triggers the backend-switch warning or appears in mise backends switch or mise doctor. #​14032
    • mise doctor only warns about a backend mismatch when the registry's backend actually serves the installed version. It now suggests mise backends switch. #​14005
    • mise uninstall --dry-run lists each version once. #​13992
  • Network
    • Downloads are retried when an HTTP/2 stream reset breaks reading the response body. #​14049
    • mise no longer retries a 429 whose Retry-After is longer than the backoff. #​14027
    • Fewer duplicate requests: concurrent callers share one fetch of a cached GitHub release, and packslip release lists are read once per command. #​13990, #​13991
    • mise oci push uploads layers larger than 64 MiB in a single streamed PATCH. GHCR previously rejected these with 416. #​14017
  • GitHub attestations
    • mise warns when some attestations were skipped because the Sigstore or GitHub TUF trust root couldn't be reached, even if verification passed on the others. #​14036
    • Attestations that failed partway are now logged at debug level. #​14035
  • Config and bootstrap
    • A project's ignored_config_paths no longer hides your global config when ~/.config/mise is a symlink into that project. A global config can no longer be ignored only through its symlink target. #​14006
    • mise bootstrap no longer fails with another history operation is running when it has no file history to record. Parallel CI jobs that share a state dir no longer block each other. #​14029
  • Dotfiles
    • Conflicting declaration errors now explain when a source file is missing. #​13973 by @​himkt
    • Group entries no longer go through legacy link discovery. #​14023
  • Secrets, MCP and tasks
    • Secrets are fully redacted when redaction values overlap. #​13962
    • The MCP run_task tool rejects task names that start with a dash. #​13961
    • The mise://tasks MCP resource now lists tasks from monorepo subprojects. #​14053
  • Changing a Ruby version file that a Gemfile references no longer prints a watch_file hook has neither run nor task set warning. #​13985 by @​DahanItamar

Documentation

  • url_replacements docs now include a package proxy example. #​14050

Breaking Changes

  • mise secrets is now a built-in command. If you have a task named secrets, run it with mise run secrets. #​13967

New Contributors

Full Changelog: jdx/mise@vfox-v2026.10.3...v2026.10.4

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.3: : Dotfile groups, templated Compose projects, and secret hygiene for shell state

Compare Source

This release adds dotfile groups for Stow-style dotfiles repositories, templated [bootstrap.compose] values, and custom labels for task confirm prompts. Secret values no longer get copied into __MISE_DIFF/__MISE_SESSION or written to the env cache. It also fixes dotenv ${VAR} expansion, mise x tool@latest reporting other tools as missing, and Ruby source builds ignoring depends tools.

Added

  • Dotfile groups. You can now declare a directory tree as a group with [dotfile_groups.<name>], using one directory per app or machine role like GNU Stow. mise walks the group's root and deploys each file to the same path under target (default ~), so you don't have to list files one by one. A machine picks which groups to apply with [bootstrap] dotfile_groups. If that list isn't set, every group applies. #​13945

    [dotfile_groups.home]
    root = "home"            # relative to dotfiles.root
    dot_prefix = true        # dot-config/ deploys as .config/
    exclude = ["README.md"]
    
    [dotfile_groups.home.entries]
    "~/.config/kitty" = { mode = "symlink" }                            # link this directory whole
    "~/.gitconfig" = { source = "git/config.tmpl", mode = "template" }
    
    [bootstrap]
    dotfile_groups = ["home", "zsh"]
    • Groups support mode (symlink-each by default, or copy or symlink), exclude, dot_prefix, manifest and relative. A [dotfile_groups.<name>.entries] table uses the same syntax as [dotfiles] and removes those paths from the walk, so you can link a directory whole, render a template, or mark a file absent.
    • If two selected groups write the same file, apply and status fail before anything is written, and the error names both groups.
    • mise records what each group deployed under $MISE_STATE_DIR/dotfiles/groups/. mise dot status shows files that no active entry deploys any more as orphaned. mise dot apply --prune removes them after asking you, and mise dot unapply --group <name> removes one group's files even after the group is gone from config. mise only removes links that still point at their source and copies that still match what it wrote, unless you pass --force.
    • mise dot add and mise dot edit put files under a group's target into that group's root, and both accept --group when more than one group could match.
    • mise oci build does not include group trees.
  • Templates in [bootstrap.compose]. Every string field in a Compose project, including project_dir, files, env_files, command and depends_on, is now rendered as a Tera template in the context of the config that declares it. Shared configs can use {{ config_root }}, {{ vars.* }} or {{ env.* }} instead of hardcoded absolute paths. exec() isn't allowed in these templates. #​13938

    [bootstrap.compose.mempalace]
    project_dir = "{{ config_root }}/mempalace"
    files = ["compose.yaml"]
    env_files = [".env"]
  • Custom labels for task confirm prompts. The object form of confirm now accepts yes and no labels, which support the same templates as message. default is now optional and still defaults to yes. Piped answers still take y/n, and --yes still skips the prompt. #​13944

    [tasks.deploy]
    confirm = { message = "Deploy to production?", yes = "Deploy", no = "Cancel", default = "no" }
    run = "deploy.sh"

Fixed

  • Dotenv ${VAR} expansion checks the file's own values first. Before, ${VAR} in a dotenv file read the process environment first. With mise activate exporting another .env, a reference could expand against the shell instead of an earlier line in the same file. Now the file's own earlier assignments come first, then values already loaded (with expand = true) or the process environment. The ${VAR:-default}, ${VAR:+alt} and ${VAR:?message} forms now work too. When the env_file setting hits a syntax error, mise keeps the assignments it read before the error and shows one warning for the file. #​13946
  • mise x tool@latest no longer reports other tools as missing. Passing any @latest argument used to resolve every configured tool against its newest release and ignore the lockfile, so tools that were installed and locked showed up as missing. Now only the tools named on the command line resolve to latest. #​13943
  • Ruby source builds can see depends tools. ruby-build now gets the declared dependencies on PATH. For example, JRuby builds use a mise-managed java instead of the system JDK. PATH stays the same when no dependencies are declared. #​13942 by @​seuros

Security

  • No extra plaintext copies of secrets. #​13950
    • Shell state: __MISE_DIFF and __MISE_SESSION are passed to every child process. They now store a blake3: digest of each value mise sets instead of the value itself. The previous (old) values are still stored in plain text because mise needs them to restore the environment. These are plain hashes, not keyed ones, so a low-entropy value could be brute-forced from its digest.
    • Env cache: mise no longer writes environments that contain secrets to the env cache. This covers age values (also when used through [vars]), sops-encrypted _.file entries, any directive with redact = true, and env modules that return cacheable = false. Before, a non-tool module's cacheable = false was ignored.
    • Env module redact: a redact setting on an env module, such as _.my-plugin = { redact = false }, now overrides the plugin's own preference. Before, it was ignored. A non-boolean value is now a config error.
    • mise x -- fish: env values no longer go in fish's command-line arguments, where ps could read them. --deny-env now applies there too.
    • Upgrading: shells started with an older mise still restore their environment correctly. mise rewrites their state in the new format at the next prompt.

Registry

  • Added jactionlint (github:jdx/jactionlint), a maintained fork of actionlint with upstream fixes and new checks. actionlint is now deprecated, with a message pointing to jactionlint. Existing actionlint installs keep working. #​13960

Documentation

  • The installation guide shows how to pin the packslip bootstrapper while letting mise install the latest release. The Docker cookbook has a new multi-stage Debian example with a digest-pinned packslip image. #​13935

Full Changelog: jdx/mise@vfox-v2026.10.2...v2026.10.3

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.2: : Experimental spinel backend, typed tool options in the schema, and daemon presets on Windows

Compare Source

This release adds an experimental spinel: backend for compiling Ruby CLIs to native binaries. The mise.toml schema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting.

Added

  • Experimental spinel: backend. It builds a Ruby command-line tool from a GitHub repository into a native executable using Spinel, Matz's Ruby AOT compiler. Versions come from git tags through git ls-remote, so listing them doesn't call the GitHub API. Available options: entrypoint, bin, tag_prefix, source_ref and spinel. You need the spinel compiler on PATH (mise doesn't install it yet) and mise settings experimental=true. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on nateberkopec/mise-backend-spinel. #​13922

    [tools."spinel:tobi/try"]
    version = "1.10.1"
    entrypoint = "try.rb"
    bin = "try"
    tag_prefix = "v"
  • Typed tool options in the JSON schema. Editors that use schema/mise.json now validate and autocomplete options for each backend, based on the tool's prefix. This covers github, gitlab, forgejo, ubi, http, s3, aqua, cargo, npm, pypi/pipx, gem, go, conda, spm, packslip and spinel. It also covers core-tool options for python, java, rust and dotnet, per-platform overrides (platforms.<os>-<arch>) and [tasks.*.tools] tables. For example, a numeric asset_pattern or java release_type = "stable" is now flagged. Boolean options accept true/false, "true"/"false" and 1/0, the same values mise accepts. lazy_bins accepts a single string. The deprecated experimental_monorepo_root key is allowed again. Runtime behavior is unchanged, but your editor may now flag mistakes in existing configs. #​13924

  • Daemon presets on Windows. mise daemons start no longer refuses preset daemons on Windows. Every preset except redis, which has no Windows build, now runs under pitchfork's default cmd /C shell. For PostgreSQL to stop cleanly, you need pitchfork 2.29.0 or later. PostgreSQL also won't start from an elevated prompt. Windows reserves some port ranges for Hyper-V and WSL, so a preset's default port can be blocked. If it is, set a different one with ports. #​13929 by @​JamBalaya56562

    [daemons.db]
    preset = "postgres"
    version = "18"
    options = { database = "app" }
  • Install mise with packslip. The installation guide now covers installing mise's signed release without running an install script. packslip verifies the Sigstore signature and the archive digest. mise self-update works with this install method. #​13710

    packslip install github.com/jdx/mise --pin ps1_nlhmwtfeufglxv5myvwvronk7a

Fixed

Config and activation
  • An untrusted project config no longer breaks shell activation. Before, mise hook-env failed completely, so tools and env from your trusted global config were not applied either. Now it skips the untrusted file, prints the usual one-time warning and loads everything else. Explicit commands such as mise run and mise x still error on untrusted configs. #​13919
  • A failed settings reload is reported as an error instead of crashing. Commands such as mise install, mise use, mise upgrade and mise ls-remote --prerelease reload settings partway through. Before, a failed reload aborted mise with SIGABRT and a core dump. Now mise prints failed to reload settings with the cause and keeps using the previous settings. #​13925
  • --no-config and MISE_NO_CONFIG=1 now skip .miserc.toml discovery. Before, a malformed project, global or system miserc broke commands like mise --no-config version. #​13926 by @​donbeave
Tasks
  • A timed-out task fails even if it exits cleanly. On Unix, a task that caught SIGTERM and exited 0 after its timeout was reported as successful. Now mise run reports timed out and exits non-zero. #​13930 by @​Marukome0743
  • Timed-out tasks on Windows can clean up. When a task hits its timeout, mise now sends it Ctrl+C and gives it 5 seconds before ending its process tree, the way Unix uses SIGTERM followed by SIGKILL. For example, PowerShell finally blocks now run. Only the timed-out task gets the Ctrl+C. The whole-run mise run --timeout still stops tasks immediately on Windows. #​13889 by @​JamBalaya56562
Windows
  • mise exec -- cmd /c keeps double quotes. Before, mise exec -- cmd /c 'echo "a b"' printed \"a b\". Pitchfork daemons with mise = true whose run contained a quote, such as a quoted program path with a space, also failed to start. mise now passes a single quoted command after /c or /k to cmd unchanged. #​13887 by @​JamBalaya56562
  • Task daemons with init steps start under cmd.exe. Before, they failed with 'exec' is not recognized. On Windows, mise now builds the command with cmd quoting and escaping. Write init steps as cmd commands. #​13928 by @​JamBalaya56562
Other
  • packslip follows repositories that moved to a new owner. mise now treats a transfer like a rename, matching on repository ID with a one-time warning. It still refuses a different repository that reuses a deleted repository's name. Refusal messages now tell you which records to clear: mise packslip forget, the tool's mise.lock entries, or both. Existing pins and lockfile entries still load. #​13710
  • mise dot save and history sync work after a tracked directory is replaced by a symlink. Before, they failed while reading older checkpoints. #​13931

Registry

  • helmfile (1.8.1 and later) and dagu (2.18.0 and later) now install from signed packslip manifests. Older versions still install through aqua:. To list them, run mise ls-remote aqua:helmfile/helmfile or mise ls-remote aqua:dagucloud/dagu. #​13933
  • New aqua packages: goccy/tobari, ymmt2005/pbschema-lens.

Full Changelog: jdx/mise@v2026.10.1...v2026.10.2

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.1: : Task timeout and Ctrl-C fixes, Windows daemon and shim fixes

Compare Source

This release is mostly bug fixes. mise run now stops tasks properly when --timeout expires or you press Ctrl-C. Task daemons and native shims work better on Windows. core:rust now follows mise.lock and picks up new stable and beta toolchains. Lockfile, GitHub asset selection, Homebrew cask and plugin update problems are also fixed.

Fixed

Tasks
  • mise run --timeout now stops the tasks it was running. Before, mise printed the timeout error and exited, but the task processes could keep running in the background. Now the whole-run timeout (--timeout or the task.timeout setting) stops tasks the same way a per-task timeout does. On Unix, mise sends SIGTERM and then SIGKILL after 5 seconds. On Windows, it runs taskkill /F /T. Tasks with raw = true are not stopped by the whole-run timeout. #​13876 by @​Marukome0743
  • A single Ctrl-C lets tasks shut down cleanly. Before, one Ctrl-C could make mise exit right away while tasks were still cleaning up. This happened in three cases: a task that runs mise run itself got SIGINT twice; a tool like docker compose up treated the duplicate SIGINT as a force-quit; and a task that exits non-zero on SIGINT caused mise to send SIGTERM to its sibling tasks. Now mise waits for tasks to finish and then exits with status 130. A second Ctrl-C still force-quits. #​13904
  • Tab completion for the :task shorthand. In a monorepo, mise run :<TAB> now suggests tasks from the current config root, and task flags complete after the shorthand. #​13882 by @​pikeas
Daemons
  • Task daemons start on Windows. A daemon declared with task = failed under cmd /C with 'exec' is not recognized. mise now registers it as an argv command that pitchfork starts without a shell, so args reach the task exactly as written on every platform. This needs pitchfork 2.28.0 or later. With an older pitchfork, mise shows an error that tells you to upgrade, for example with mise use pitchfork@latest. Task daemons that use init still run through a shell, so they still don't work under cmd /C. #​13714 by @​JamBalaya56562

  • Daemon run commands can use [env] and [vars]. Before, a template such as {{ vars.test_var }} failed with Variable 'vars' is not defined. mise x now renders the command when the daemon starts, using the project's [env], [vars] and mise template filters. Pitchfork's own variables, such as {{ name }}, still work. This applies only to run and requires a pitchfork release newer than 2.29.0. #​13894

    [vars]
    greeting = "it's"
    
    [daemons.hello]
    run = "exec echo {{ vars.greeting | quote }} from {{ name }}"
Windows shims
  • No more endless process chains from duplicate shim copies. If two copies of mise-shim.exe were on PATH (for example, one from winget's Links directory), they could keep calling each other through mise x. Running mise-shim by its own name now exits with an error. If mise x resolves a tool to another shim copy, mise stops after one step and names the PATH directory to remove. #​13681 by @​JamBalaya56562
  • Node IPC works through the node.exe shim. A Node parent that spawned the shim with an 'ipc' stdio entry used to wait forever. JSON IPC messages and disconnects now pass through the shim. Passing socket or server handles over the channel is still not supported. #​13903
Rust
  • mise upgrade rust updates stable and beta. mise didn't recognize rustup 1.29's new update available: text. Even when it detected an update, the upgrade skipped the toolchain as already installed. mise now reads both spellings, counts only updates for the toolchain it manages, and updates the toolchain in place. If the update fails, the old toolchain stays usable. #​13898
  • core:rust follows mise.lock. mise mistook rustup's symlinks for mise linked versions, so it ignored the lockfile and installed the newest version even with locked = true. #​13915
Backends, lockfiles and bootstrap
  • GitHub auto-detection no longer installs metadata files. SBOMs, signatures, checksums and other sidecar files with platform names, such as *.tar.gz.sbom.json, could be chosen as the tool and saved to mise.lock. Automatic selection now skips them. Explicit url and asset_pattern options are unchanged. #​13908
  • mise lock removes outdated duplicate entries. After you changed a tool option, for example by adding uvx = false to a pipx: tool, mise lock --upgrade could leave the old unbound entry next to the new bound one. Unfiltered mise lock runs now remove the old entry, unless it has platform data (checksum or URL) that the new entry doesn't have. #​13909
  • Aqua registry cache errors after upgrading. Compiled registry caches from earlier versions could load but then fail when a package was resolved. mise now ignores those caches and rebuilds them. #​13884
  • Packslip installs retry missing skills. If the binary installed but a declared skill couldn't be fetched, mise still marked the install as complete. Now the install fails with an error. The next mise install fetches only the missing skills and doesn't reinstall the tool. #​13885
  • Pkg-based brew-cask packages are no longer reinstalled on every run. Casks such as google-drive list package IDs for several architectures, and mise expected every one of them to be installed. Receipts now store only the patterns that match on your machine. Casks recorded by earlier versions are reinstalled once to write a corrected receipt. #​13893
  • mise plugins update works when the remote isn't named origin. This happens, for example, when git's clone.defaultRemoteName is set to something else. mise uses origin if it exists and otherwise uses the first remote. #​13914

Changed

  • mise skills sync, the table output of mise skills ls, and other human-facing messages now show paths under your home directory with ~. This includes output from mise deps install, task source lines, mise completion --install and daemon messages. --json output and script-oriented commands still print full paths. #​13910

Full Changelog: jdx/mise@vfox-v2026.10.0...v2026.10.1

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.0: : Stricter signer checks for cosign and GitHub attestations, trust for inline options in .tool-versions

Compare Source

This release tightens supply-chain verification. Keyless cosign bundles must now match a pinned signer identity, and GitHub attestation workflow checks no longer accept partial matches. It also closes a .tool-versions trust gap that could leak GITHUB_TOKEN, adds a per-cask appdir option for Homebrew casks, and fixes problems with locked SLSA installs, musl hosts and mise backends switch.

Security

  • Inline tool options in .tool-versions now require trust. This is the .tool-versions version of the mise.toml fix in 2026.9.18. An untrusted project could ship a github: entry with inline options, such as [api_url=...], pointing at another host. Commands such as mise ls, env, current, outdated and latest would then send your GITHUB_TOKEN to that host without asking for trust. Any entry whose tool name contains [ now requires trust, the same as Tera templates. Plain lines like node 20.0.0 still load without trust, and a [ inside a comment is ignored. Run mise trust for projects you rely on. MISE_SAFE=1 still skips trust checks. (GHSA-wcqh-j26q-g44x) #​13869
  • Keyless cosign verification now checks who signed. Before, the aqua backend only checked that a bundle chained to Sigstore's Fulcio CA. Any GitHub Actions workflow in any repository can get such a certificate, so a bundle signed by the wrong workflow would still pass. mise now applies the registry's --certificate-identity[-regexp], --certificate-oidc-issuer[-regexp] and --certificate-github-workflow-{repository,ref,name,trigger,sha} options to the signing certificate. It does this for both current and legacy bundles. Keyless verification now requires a pinned identity, and an unknown or empty --certificate-* option is an error. Key-based verification (--key) is unchanged. Registry patterns that use RE2 \Q…\E quoted literals, such as the one for vfox, are supported. #​13875, #​13879
  • GitHub attestation signer workflow matching is anchored. The expected signer_workflow must now match the end of the certificate's workflow path as whole path segments. Before, it was a substring match against the whole identity, so a longer workflow file name such as release.yml.evil.yml, or a ref that contained the expected path, would pass. An empty signer_workflow now fails verification. Both the bare form (.github/workflows/release.yml) and the repository-qualified form (owner/repo/.github/workflows/release.yml) still work. #​13877

Added

  • Per-cask app directories. A brew-cask: bootstrap package can set its own appdir. This overrides the global MISE_BREW_CASK_OPT_APPDIR setting, expands ~/, and also applies to the cask's dependencies. #​13865

    [bootstrap.packages]
    "brew-cask:1password" = { appdir = "/Applications" }

    The setting only applies to installs and upgrades: apps that are already installed are not moved. A first install into a new appdir won't replace an existing app it doesn't own unless you set adopt = true. Other package managers ignore appdir and print a warning.

  • slsa_signer_identity and slsa_signer_issuer options for aqua tools. These work the same as in the github backend. They let mise lock verify and record SLSA provenance for packages whose registry entry has no signer, such as aqua:google/osv-scanner. You must set both options to non-empty strings, and together they override any signer in the registry, including version overrides. #​13856

  • Registry: cloudflare-cf, Cloudflare's cf CLI, which is in beta and installs from npm:cf. It provides the cf and cloudflare binaries. Pin a beta version for now, such as mise use cloudflare-cf@1.0.0-beta.10. An unpinned install currently resolves to an unrelated old 0.x release. #​13871

  • Docs: a new Releases page (under About in the docs) shows a timeline of release sizes, the issues each release resolved, and expandable release notes. #​13855

Fixed

  • Locked SLSA installs work again without a registry signer. Since 2026.9.17, a lockfile that recorded a checksum and SLSA provenance failed with "Aqua registry metadata has no signer_identity and signer_issuer" for tools such as aqua:google/osv-scanner and aqua:fluxcd/flux2. A lock entry with a checksum and recorded provenance is now trusted for SLSA too: the install only checks the artifact digest, as it already did for other provenance types. locked_verify_provenance or paranoid mode still re-verify and still require a signer. #​13856
  • aqua on musl hosts. On Alpine and other musl hosts, an aqua tool whose registry entry only names a glibc build (such as zizmor) failed with "no asset found: ...-unknown-linux-musl...". mise now installs the asset the registry names. The binary still needs glibc or gcompat to run. mise lock for linux-x64-musl records the same asset. #​13857
  • mise backends switch handles stale lock entries. Sometimes mise install warned that a tool was locked to a replaced backend, for example asdf:clojure instead of vfox:jdx/vfox-clojure, but mise backends switch then reported there was nothing to switch. This happened when the config's version no longer matched the lock entry. The command now switches those entries too. Entries at a version the config no longer resolves to are relocked at the config's version and reported as replacing stale <tool>@<version>. #​13859
  • Ctrl-C exits with status 130. Interrupting mise install, upgrade, exec and similar commands used to exit with 1, the same as an ordinary failure. They now exit with 130 (128 + SIGINT), matching mise run, so shells and scripts can tell when a user interrupted. A repeated Ctrl-C during mise run also exits with 130. This applies on Unix and Windows. #​13862
  • Declining a trust prompt skips the config for that run. Before, declining still failed the current command with "not trusted". #​13868
  • The one-time startup migration for stale latest runtime directories has been removed. It was due to expire in this release and would have blocked normal installs. mise install still repairs a stale latest directory, but passive commands such as mise ls no longer touch it. #​13868
  • Stale dotfile history watchers are diagnosed. A history watcher started on an older mise can fail every capture with an unknown-field error for newer settings such as exclude. mise doctor and mise dot status now report that the watcher is outdated and tell you to run mise bootstrap services apply, which restarts it. #​13864
  • Java: the missing-metadata error now names the target platform, for example no metadata found for version zulu-8 on windows-arm64. #​13873 (@​jsiu93)

Breaking Changes

  • --from-git removed from mise bootstrap. mise bootstrap --from-git and mise bootstrap remote --from-git now fail with an unexpected-argument error. Use --adopt, which has been the documented flag since 2026.9.3: #​13872

    mise bootstrap --adopt git@github.com:me/dotfiles.git
  • vfox tool plugins that use keyless cosign must pin an identity. If a PreInstall attestation sets cosign_sig_or_bundle_path without cosign_public_key_path, it must also set cosign_certificate_identity or cosign_certificate_identity_regexp. You can also set cosign_certificate_oidc_issuer. Without an identity, the attestation is rejected. Registry entries that already work with the aqua CLI are not affected. #​13875

  • Alpine/musl: if a registry entry names a gnu asset but the release also ships a musl build, mise now installs the gnu build. Before, it switched to musl. Set libc = "musl" on that tool to keep the musl build. #​13857

  • Exit code on Ctrl-C: scripts that checked for exit status 1 after an interrupt should now check for 130. #​13862

New Contributors

Full Changelog: jdx/mise@vfox-v2026.9.20...v2026.10.0

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.18: : Remote config includes, OCI task catalogs, and a trust fix for inline tool options

Compare Source

mise.toml can now include a shared config file from a git repository or OCI registry, and task_config.includes accepts OCI artifacts. The release also closes a trust bypass that could send GITHUB_TOKEN to an attacker-controlled host, adds gem registry sources, and fixes several daemon and dotfiles problems.

Security

  • Inline tool options now require trust. Before this change, a mise.toml in an untrusted directory could hide options in a tool key, for example a github: tool key with [api_url=...] pointing at another host. mise loaded the file without trust because the value was a plain version string. Commands such as mise ls, env, current, outdated, upgrade --dry-run and latest then sent GITHUB_TOKEN to that api_url. Now any tool key that contains [ requires trust, the same as { ... } option tables already did. Plain keys like node or "cargo:eza" still load without trust. If you use inline options in a project you haven't trusted yet, run mise trust. MISE_SAFE=1 still skips trust checks entirely. #​13849

Added

  • Include shared config from git or OCI. Organizations can keep tool versions, env and hooks in one place and pull them into every repo: #​13843

    include = [
      "git::<repo-url>//mise.toml?ref=main",
      "oci::ghcr.io/myorg/platform-config@sha256:0f1e2d3c...",
    ]
    
    [tools]
    node = "22"   # the file's own entries override the included ones

    A git:: include points at a .toml file in a repository. An oci:: include points at an artifact with a mise.toml at its root. The included file is merged beneath the file that includes it, and a later include overrides an earlier one. It uses that file's trust, config root and lockfile. A fragment may contain [tools], [tool_alias], [env], [vars], [hooks], [alias], [shell_alias], [plugins], [wrappers] and min_version. Anything else is an error, including nested include, [settings], tasks, [dotfiles] and [daemons].

    • An untrusted config never fetches, and safe mode never fetches for project config.
    • Paranoid mode requires a full commit sha or an OCI digest.
    • Fragments are cached in MISE_CACHE_DIR/config-includes. Pinned refs are never fetched again. Branches and tags are refreshed after fetch_remote_versions_cache expires, and only by commands that check remote versions, such as install, up and use. If a refresh fails, the cached copy is used with a warning.
  • OCI task catalogs. task_config.includes accepts oci:: references, in addition to git::. The artifact is pulled, verified against its digests, cached in MISE_CACHE_DIR/remote-oci-tasks-cache, and loaded like a local task directory. Credentials come from docker login/podman login. Artifacts with symlinks or special files are rejected. Signatures are not verified, so pin @sha256: if you need the contents to stay the same. #​13820

    [task_config]
    includes = ["oci::ghcr.io/myorg/shared-tasks:1.0.0"]
    oras push ghcr.io/myorg/shared-tasks:1.0.0 build.toml scripts/deploy
  • mise bootstrap --from accepts ?ref= to select a branch, tag or commit, for example mise bootstrap --from 'git::<repo-url>?ref=v1'. The git:: prefix is optional. With --update, mise resolves the ref on origin again and fast-forwards branches. A ref that was deleted upstream is an error. #​13822

  • Install a gem from a specific registry. The new source option sends version lookup and install for one gem to that registry, and leaves the machine's gem sources unchanged. Credentials in the URL are redacted from logs and install metadata. #​13391 (@​waynehoover)

    [tools]
    "gem:internal-tool" = { version = "latest", source = "<registry-url>" }

    A GitHub Packages source (the rubygems.pkg.github.com host) without credentials now uses the GitHub token mise already resolves. The token needs read:packages. GitHub Packages has no versions API, so you must pin an exact version there. #​13832 (@​waynehoover)

  • mise lock --sidecars lists the native dependency sidecar directories (aube for npm, uv for Python) that must be committed along with `mis

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the bot label Jul 20, 2026
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from b069281 to 4210d96 Compare July 30, 2026 03:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 7255dd3 to 18a73a9 Compare August 5, 2026 03:26
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 2752ba1 to 661a5bf Compare August 12, 2026 20:16
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 6445a85 to c5325ef Compare August 20, 2026 23:10
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 9dd559c to fac6f2e Compare August 26, 2026 03:48
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 61548e9 to 844f10e Compare September 3, 2026 00:28
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from b504efd to 25c7628 Compare September 11, 2026 04:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from 5986910 to e80a868 Compare September 18, 2026 07:31
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 64f8ae1 to 980f1fd Compare September 27, 2026 11:53
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 7 times, most recently from 224319d to e51efa8 Compare October 5, 2026 11:58
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch from e51efa8 to f1ad039 Compare October 7, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants