Repository navigation
chore(deps): update dependency jdx/mise to v2026 - #220
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
6 times, most recently
from
July 30, 2026 03:03
b069281 to
4210d96
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 5, 2026 03:26
7255dd3 to
18a73a9
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
3 times, most recently
from
August 12, 2026 20:16
2752ba1 to
661a5bf
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 20, 2026 23:10
6445a85 to
c5325ef
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 26, 2026 03:48
9dd559c to
fac6f2e
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 3, 2026 00:28
61548e9 to
844f10e
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 11, 2026 04:03
b504efd to
25c7628
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
6 times, most recently
from
September 18, 2026 07:31
5986910 to
e80a868
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 27, 2026 11:53
64f8ae1 to
980f1fd
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
7 times, most recently
from
October 5, 2026 11:58
224319d to
e51efa8
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
from
October 7, 2026 18:45
e51efa8 to
f1ad039
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.
Release Notes
jdx/mise (jdx/mise)
v2026.10.4: : Task-scoped fnox secrets, automatic global tool updates, and an opt-in identity install layoutCompare Source
This release adds experimental task-scoped secrets backed by fnox, automatic updates for global tools, and an experimental opt-in install layout that names installations by what they contain. It also adds dotfile
mergeentries,headersauth for thehttp:backend, npm installs from git, and a set of prune, install and lockfile fixes.Added
Secrets (experimental)
These need
mise settings experimental=trueand fnox 1.39.0 or newer. They are refused in safe mode.[secrets.fnox]andmise secrets ls. A project can name fnox as its secrets source in its ownmise.toml.mise secrets lslists key names and metadata but never values.-Jprints JSON. Global, system and home-level[secrets]config is ignored, andmise doctorreports it. #13967Tasks get only the secrets they list. Add
secrets = [...]to a task, or#MISE secrets=[...]in a file task header. Only that task gets the values, only while it runs, and they are redacted from its output. Dependencies, hooks,mise env, hook-env and shims get nothing. A task without grants never calls fnox. Tasks that list secrets need a trusted config, aren't artifact-cached, and ignore--rawunless the task setsraworinteractive. Hooks,watch_files, daemons andmise bootstrapcan't run them, and remote or global-config tasks can't list secrets. #13974One-off grants from the command line.
--secrets KEY[,KEY]and--secrets-allwork onmise run,mise tasks runandmise x. Formise run, only the tasks named on the command line get them, not their dependencies.mise xgets nothing unless you pass a flag, and it can't receive file secrets. Flags placed after the task name go to the task, and mise warns when that happens. #13975{{ secrets.X }}in task env values. A task can build an env var from a secret, for exampleenv.PGURL = "postgres://app:{{ secrets.DB_PASSWORD }}@db/app". The reference counts as the grant. References are rejected inrun,[env],[vars]and other fields. #13978fnox daemon cache. If the project's fnox config enables the daemon and it's running, an interactive run reads cached values over its socket without starting an fnox process. mise never starts the daemon itself. CI, non-TTY runs and Windows always use the fnox CLI. #13979
Automatic global tool updates
auto_updatefor global tools. Setauto_updateon a tool in your global config. When a shim ormise xis about to run that tool and its check interval is due, mise upgrades it within the configured range and then runs the new version.trueuses the newtool_update.check_durationsetting (default 24h), and a duration string sets that tool's own interval (minimum 1h). #14026locked = true, from tasks or hook-env, or from project configs.mise doctor.Background
tool-updateservice. A built-in bootstrap service checksauto_updatetools hourly, so launches don't wait for downloads and tools run directly from PATH under activation also stay current. It installs a systemd user unit, LaunchAgent or scheduled task. #14040Identity install layout (experimental, opt-in)
install_layout = "identity". Withexperimental = true, each installation lives ininstalls/<label>-<hash>/. The hash covers the canonical backend, version, platform and install-affecting options.installs/<tool>/<version>becomes a link to that directory, a real junction on Windows. As a result: #13951ageandaqua:FiloSottile/ageshare one installation.Existing installs keep working and aren't moved. Nothing changes unless you set this.
MISE_INSTALL_LAYOUT=identityalso turns it on. See the new install layout docs.On Windows, identity-layout installations go into the shorter
%LOCALAPPDATA%\mise\i\, while version links stay ininstalls\.MISE_INSTALL_STORE_DIRsets the location on any platform. #13952mise installs lslists installations asselected,pinnedorshared.mise installs select <dir>chooses which installation requests without a lockfile use. When several installations match and none is selected, mise lists them instead of guessing. #13953mise installs migrate [--dry-run] [TOOL[@VERSION]]reinstalls legacy installations into the new layout and leaves a link at the old path. If a run is interrupted, the next run recovers it. #13955In the layout,
mise backends switchinstalls the new backend's version and points the link at it.mise whereand the other commands now resolve versions named on the command line the same way, andmise wherelists variants instead of picking one. #13957mise prunehandles templated tool versions such asnode = "{{ vars.node }}". It uses snapshots of what each project last rendered and keeps installs when it isn't sure they are unused. #14025Other additions
Dotfile
mergeentries. Amerge = trueentry sets only the keys from its source in a JSON, TOML or YAML file, and leaves keys added by the application (Codex, Claude Code, etc.) alone. TOML and YAML keep comments and formatting.mise dot statusandmise dot diffonly report drift in those keys. A target that doesn't parse is never overwritten. #14012headersfor thehttp:backend. You can now authenticate with bearer tokens or API keys, for example to download OCI blobs fromghcr.io. Values are templates. Headers are sent with downloads,version_list_urlandchecksum_urlrequests, and dropped on cross-host redirects unless the host is listed inheaders_forward. Changing a token doesn't trigger a reinstall. #14022npm packages from git.
git+URLs andgithub:,gitlab:andbitbucket:specs now install. The version is a git ref, andlatestis the default branch. #14044mise use 'npm:github:owner/repo@v1.2.0'settings.write_targets. Sends new global[tools],[bootstrap.packages]and[dotfiles]entries to separateconf.dfiles. Existing entries are updated where they're already declared. #14018prune.exclude(orMISE_PRUNE_EXCLUDE) lists tools thatmise prune,mise ls --prunableand upgrade pruning never remove. Short and full names both work, e.g.nodeoraqua:BurntSushi/ripgrep. #14030lockfile_auto_prune = falsekeeps lockfile entries for tools missing from the active config. This is useful when profiles share one lockfile. The default (true) keeps the current pruning behavior. #13980mise dot notifysends a test desktop notification, which also triggers the macOS permission prompt.mise doctorandmise dot statusnow show whether notifications can be delivered. #14009Changed
mise's own auto-update settings moved under
self_update.*.auto_updateis nowself_update.auto(MISE_SELF_UPDATE_AUTO), andauto_update_check_durationis nowself_update.check_duration(MISE_SELF_UPDATE_CHECK_DURATION). The old names keep working. The new key wins when both are set. Deprecation warnings start in 2027.4.0. Older mise versions ignore a settings file that has unknownself_updatekeys, so keep the old spelling if a config has to work with both. #14038mise prune,mise unuse --prune,mise ls --prunableand deferred pruning after an upgrade now keep any version a running process was started from, on Linux, macOS and Windows. They say which process kept it. #14020pypi:/pipx:tools installed with uv are now built on mise's Python when mise manages one. Previously uv could use its own downloaded interpreter, which broke CI caches that only restore the mise data dir. A package whoserequires-pythonexcludes mise's Python now fails; to override, pass--pythoninuvx_args. #14024With
python.uv_venv_auto,mise installnow creates the project venv with mise's Python instead of whatever uv found. #13981 by @halmsInherited secrets: when a parent mise marks variables as secrets in
__MISE_SECRET_KEYS, a nested mise now does the following #13966:get_env()andexec()__MISE_DIFF, other tasks and pitchforkmise xand shims still pass them through.Fixed
postinstallhook no longer leaves its version listed as installed or selectable. The next install retries it. #14037$MISE_STATE_DIR, somise cache clearno longer makes a half-installed version look installed. Existing markers are migrated. #14051mise install --lockednow works fordotnet:tools. #13971 by @james-newell-forgemise lockforpypi:tools on registries with a<root>/pypi/{}/jsontemplate, such as Artifactory, now uses<root>/simple/. #14007 by @deigacargo:installs that fall back tocargo installno longer corrupt the shared rustup toolchain. #14042mise upgrade --bumpandmise outdated --bumpno longer rewrite vendor-only requests likejava = "temurin"to a bare version from another vendor. #14031vfox:mise-plugins/*tovfox:jdx/*, no longer triggers the backend-switch warning or appears inmise backends switchormise doctor. #14032mise doctoronly warns about a backend mismatch when the registry's backend actually serves the installed version. It now suggestsmise backends switch. #14005mise uninstall --dry-runlists each version once. #13992Retry-Afteris longer than the backoff. #14027mise oci pushuploads layers larger than 64 MiB in a single streamed PATCH. GHCR previously rejected these with416. #14017ignored_config_pathsno longer hides your global config when~/.config/miseis a symlink into that project. A global config can no longer be ignored only through its symlink target. #14006mise bootstrapno longer fails withanother history operation is runningwhen it has no file history to record. Parallel CI jobs that share a state dir no longer block each other. #14029run_tasktool rejects task names that start with a dash. #13961mise://tasksMCP resource now lists tasks from monorepo subprojects. #14053watch_file hook has neither run nor task setwarning. #13985 by @DahanItamarDocumentation
url_replacementsdocs now include a package proxy example. #14050Breaking Changes
mise secretsis now a built-in command. If you have a task namedsecrets, run it withmise run secrets. #13967New Contributors
Full Changelog: jdx/mise@vfox-v2026.10.3...v2026.10.4
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.3: : Dotfile groups, templated Compose projects, and secret hygiene for shell stateCompare Source
This release adds dotfile groups for Stow-style dotfiles repositories, templated
[bootstrap.compose]values, and custom labels for task confirm prompts. Secret values no longer get copied into__MISE_DIFF/__MISE_SESSIONor written to the env cache. It also fixes dotenv${VAR}expansion,mise x tool@latestreporting other tools as missing, and Ruby source builds ignoringdependstools.Added
Dotfile groups. You can now declare a directory tree as a group with
[dotfile_groups.<name>], using one directory per app or machine role like GNU Stow. mise walks the group'srootand deploys each file to the same path undertarget(default~), so you don't have to list files one by one. A machine picks which groups to apply with[bootstrap] dotfile_groups. If that list isn't set, every group applies. #13945mode(symlink-eachby default, orcopyorsymlink),exclude,dot_prefix,manifestandrelative. A[dotfile_groups.<name>.entries]table uses the same syntax as[dotfiles]and removes those paths from the walk, so you can link a directory whole, render a template, or mark a fileabsent.applyandstatusfail before anything is written, and the error names both groups.$MISE_STATE_DIR/dotfiles/groups/.mise dot statusshows files that no active entry deploys any more asorphaned.mise dot apply --pruneremoves them after asking you, andmise dot unapply --group <name>removes one group's files even after the group is gone from config. mise only removes links that still point at their source and copies that still match what it wrote, unless you pass--force.mise dot addandmise dot editput files under a group's target into that group's root, and both accept--groupwhen more than one group could match.mise oci builddoes not include group trees.Templates in
[bootstrap.compose]. Every string field in a Compose project, includingproject_dir,files,env_files,commandanddepends_on, is now rendered as a Tera template in the context of the config that declares it. Shared configs can use{{ config_root }},{{ vars.* }}or{{ env.* }}instead of hardcoded absolute paths.exec()isn't allowed in these templates. #13938Custom labels for task
confirmprompts. The object form ofconfirmnow acceptsyesandnolabels, which support the same templates asmessage.defaultis now optional and still defaults toyes. Piped answers still takey/n, and--yesstill skips the prompt. #13944Fixed
${VAR}expansion checks the file's own values first. Before,${VAR}in a dotenv file read the process environment first. Withmise activateexporting another.env, a reference could expand against the shell instead of an earlier line in the same file. Now the file's own earlier assignments come first, then values already loaded (withexpand = true) or the process environment. The${VAR:-default},${VAR:+alt}and${VAR:?message}forms now work too. When theenv_filesetting hits a syntax error, mise keeps the assignments it read before the error and shows one warning for the file. #13946mise x tool@latestno longer reports other tools as missing. Passing any@latestargument used to resolve every configured tool against its newest release and ignore the lockfile, so tools that were installed and locked showed up asmissing. Now only the tools named on the command line resolve to latest. #13943dependstools. ruby-build now gets the declared dependencies onPATH. For example, JRuby builds use a mise-managedjavainstead of the system JDK. PATH stays the same when no dependencies are declared. #13942 by @seurosSecurity
__MISE_DIFFand__MISE_SESSIONare passed to every child process. They now store ablake3:digest of each value mise sets instead of the value itself. The previous (old) values are still stored in plain text because mise needs them to restore the environment. These are plain hashes, not keyed ones, so a low-entropy value could be brute-forced from its digest.agevalues (also when used through[vars]), sops-encrypted_.fileentries, any directive withredact = true, and env modules that returncacheable = false. Before, a non-tool module'scacheable = falsewas ignored.redact: aredactsetting on an env module, such as_.my-plugin = { redact = false }, now overrides the plugin's own preference. Before, it was ignored. A non-boolean value is now a config error.mise x -- fish: env values no longer go in fish's command-line arguments, wherepscould read them.--deny-envnow applies there too.Registry
jactionlint(github:jdx/jactionlint), a maintained fork of actionlint with upstream fixes and new checks.actionlintis now deprecated, with a message pointing tojactionlint. Existingactionlintinstalls keep working. #13960Documentation
Full Changelog: jdx/mise@vfox-v2026.10.2...v2026.10.3
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.2: : Experimental spinel backend, typed tool options in the schema, and daemon presets on WindowsCompare Source
This release adds an experimental
spinel:backend for compiling Ruby CLIs to native binaries. Themise.tomlschema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting.Added
Experimental
spinel:backend. It builds a Ruby command-line tool from a GitHub repository into a native executable using Spinel, Matz's Ruby AOT compiler. Versions come from git tags throughgit ls-remote, so listing them doesn't call the GitHub API. Available options:entrypoint,bin,tag_prefix,source_refandspinel. You need thespinelcompiler onPATH(mise doesn't install it yet) andmise settings experimental=true. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on nateberkopec/mise-backend-spinel. #13922Typed tool options in the JSON schema. Editors that use
schema/mise.jsonnow validate and autocomplete options for each backend, based on the tool's prefix. This covers github, gitlab, forgejo, ubi, http, s3, aqua, cargo, npm, pypi/pipx, gem, go, conda, spm, packslip and spinel. It also covers core-tool options forpython,java,rustanddotnet, per-platform overrides (platforms.<os>-<arch>) and[tasks.*.tools]tables. For example, a numericasset_patternorjavarelease_type = "stable"is now flagged. Boolean options accepttrue/false,"true"/"false"and1/0, the same values mise accepts.lazy_binsaccepts a single string. The deprecatedexperimental_monorepo_rootkey is allowed again. Runtime behavior is unchanged, but your editor may now flag mistakes in existing configs. #13924Daemon presets on Windows.
mise daemons startno longer refuses preset daemons on Windows. Every preset exceptredis, which has no Windows build, now runs under pitchfork's defaultcmd /Cshell. For PostgreSQL to stop cleanly, you need pitchfork 2.29.0 or later. PostgreSQL also won't start from an elevated prompt. Windows reserves some port ranges for Hyper-V and WSL, so a preset's default port can be blocked. If it is, set a different one withports. #13929 by @JamBalaya56562Install mise with packslip. The installation guide now covers installing mise's signed release without running an install script. packslip verifies the Sigstore signature and the archive digest.
mise self-updateworks with this install method. #13710Fixed
Config and activation
mise hook-envfailed completely, so tools and env from your trusted global config were not applied either. Now it skips the untrusted file, prints the usual one-time warning and loads everything else. Explicit commands such asmise runandmise xstill error on untrusted configs. #13919mise install,mise use,mise upgradeandmise ls-remote --prereleasereload settings partway through. Before, a failed reload aborted mise with SIGABRT and a core dump. Now mise printsfailed to reload settingswith the cause and keeps using the previous settings. #13925--no-configandMISE_NO_CONFIG=1now skip.miserc.tomldiscovery. Before, a malformed project, global or system miserc broke commands likemise --no-config version. #13926 by @donbeaveTasks
timeoutwas reported as successful. Nowmise runreportstimed outand exits non-zero. #13930 by @Marukome0743timeout, mise now sends it Ctrl+C and gives it 5 seconds before ending its process tree, the way Unix uses SIGTERM followed by SIGKILL. For example, PowerShellfinallyblocks now run. Only the timed-out task gets the Ctrl+C. The whole-runmise run --timeoutstill stops tasks immediately on Windows. #13889 by @JamBalaya56562Windows
mise exec -- cmd /ckeeps double quotes. Before,mise exec -- cmd /c 'echo "a b"'printed\"a b\". Pitchfork daemons withmise = truewhoseruncontained a quote, such as a quoted program path with a space, also failed to start. mise now passes a single quoted command after/cor/kto cmd unchanged. #13887 by @JamBalaya56562initsteps start undercmd.exe. Before, they failed with'exec' is not recognized. On Windows, mise now builds the command with cmd quoting and escaping. Writeinitsteps as cmd commands. #13928 by @JamBalaya56562Other
mise packslip forget, the tool'smise.lockentries, or both. Existing pins and lockfile entries still load. #13710mise dot saveand history sync work after a tracked directory is replaced by a symlink. Before, they failed while reading older checkpoints. #13931Registry
helmfile(1.8.1 and later) anddagu(2.18.0 and later) now install from signed packslip manifests. Older versions still install throughaqua:. To list them, runmise ls-remote aqua:helmfile/helmfileormise ls-remote aqua:dagucloud/dagu. #13933goccy/tobari,ymmt2005/pbschema-lens.Full Changelog: jdx/mise@v2026.10.1...v2026.10.2
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.1: : Task timeout and Ctrl-C fixes, Windows daemon and shim fixesCompare Source
This release is mostly bug fixes.
mise runnow stops tasks properly when--timeoutexpires or you press Ctrl-C. Task daemons and native shims work better on Windows.core:rustnow followsmise.lockand picks up new stable and beta toolchains. Lockfile, GitHub asset selection, Homebrew cask and plugin update problems are also fixed.Fixed
Tasks
mise run --timeoutnow stops the tasks it was running. Before, mise printed the timeout error and exited, but the task processes could keep running in the background. Now the whole-run timeout (--timeoutor thetask.timeoutsetting) stops tasks the same way a per-tasktimeoutdoes. On Unix, mise sends SIGTERM and then SIGKILL after 5 seconds. On Windows, it runstaskkill /F /T. Tasks withraw = trueare not stopped by the whole-run timeout. #13876 by @Marukome0743mise runitself got SIGINT twice; a tool likedocker compose uptreated the duplicate SIGINT as a force-quit; and a task that exits non-zero on SIGINT caused mise to send SIGTERM to its sibling tasks. Now mise waits for tasks to finish and then exits with status 130. A second Ctrl-C still force-quits. #13904:taskshorthand. In a monorepo,mise run :<TAB>now suggests tasks from the current config root, and task flags complete after the shorthand. #13882 by @pikeasDaemons
Task daemons start on Windows. A daemon declared with
task =failed undercmd /Cwith'exec' is not recognized. mise now registers it as an argv command that pitchfork starts without a shell, soargsreach the task exactly as written on every platform. This needs pitchfork 2.28.0 or later. With an older pitchfork, mise shows an error that tells you to upgrade, for example withmise use pitchfork@latest. Task daemons that useinitstill run through a shell, so they still don't work undercmd /C. #13714 by @JamBalaya56562Daemon
runcommands can use[env]and[vars]. Before, a template such as{{ vars.test_var }}failed withVariable 'vars' is not defined.mise xnow renders the command when the daemon starts, using the project's[env],[vars]and mise template filters. Pitchfork's own variables, such as{{ name }}, still work. This applies only torunand requires a pitchfork release newer than 2.29.0. #13894Windows shims
mise-shim.exewere on PATH (for example, one from winget'sLinksdirectory), they could keep calling each other throughmise x. Runningmise-shimby its own name now exits with an error. Ifmise xresolves a tool to another shim copy, mise stops after one step and names the PATH directory to remove. #13681 by @JamBalaya56562node.exeshim. A Node parent that spawned the shim with an'ipc'stdio entry used to wait forever. JSON IPC messages and disconnects now pass through the shim. Passing socket or server handles over the channel is still not supported. #13903Rust
mise upgrade rustupdatesstableandbeta. mise didn't recognize rustup 1.29's newupdate available:text. Even when it detected an update, the upgrade skipped the toolchain as already installed. mise now reads both spellings, counts only updates for the toolchain it manages, and updates the toolchain in place. If the update fails, the old toolchain stays usable. #13898core:rustfollowsmise.lock. mise mistook rustup's symlinks formise linked versions, so it ignored the lockfile and installed the newest version even withlocked = true. #13915Backends, lockfiles and bootstrap
*.tar.gz.sbom.json, could be chosen as the tool and saved tomise.lock. Automatic selection now skips them. Expliciturlandasset_patternoptions are unchanged. #13908mise lockremoves outdated duplicate entries. After you changed a tool option, for example by addinguvx = falseto apipx:tool,mise lock --upgradecould leave the old unbound entry next to the new bound one. Unfilteredmise lockruns now remove the old entry, unless it has platform data (checksum or URL) that the new entry doesn't have. #13909mise installfetches only the missing skills and doesn't reinstall the tool. #13885brew-caskpackages are no longer reinstalled on every run. Casks such asgoogle-drivelist package IDs for several architectures, and mise expected every one of them to be installed. Receipts now store only the patterns that match on your machine. Casks recorded by earlier versions are reinstalled once to write a corrected receipt. #13893mise plugins updateworks when the remote isn't namedorigin. This happens, for example, when git'sclone.defaultRemoteNameis set to something else. mise usesoriginif it exists and otherwise uses the first remote. #13914Changed
mise skills sync, the table output ofmise skills ls, and other human-facing messages now show paths under your home directory with~. This includes output frommise deps install, task source lines,mise completion --installand daemon messages.--jsonoutput and script-oriented commands still print full paths. #13910Full Changelog: jdx/mise@vfox-v2026.10.0...v2026.10.1
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.0: : Stricter signer checks for cosign and GitHub attestations, trust for inline options in .tool-versionsCompare Source
This release tightens supply-chain verification. Keyless cosign bundles must now match a pinned signer identity, and GitHub attestation workflow checks no longer accept partial matches. It also closes a
.tool-versionstrust gap that could leakGITHUB_TOKEN, adds a per-caskappdiroption for Homebrew casks, and fixes problems with locked SLSA installs, musl hosts andmise backends switch.Security
.tool-versionsnow require trust. This is the.tool-versionsversion of themise.tomlfix in 2026.9.18. An untrusted project could ship agithub:entry with inline options, such as[api_url=...], pointing at another host. Commands such asmise ls,env,current,outdatedandlatestwould then send yourGITHUB_TOKENto that host without asking for trust. Any entry whose tool name contains[now requires trust, the same as Tera templates. Plain lines likenode 20.0.0still load without trust, and a[inside a comment is ignored. Runmise trustfor projects you rely on.MISE_SAFE=1still skips trust checks. (GHSA-wcqh-j26q-g44x) #13869--certificate-identity[-regexp],--certificate-oidc-issuer[-regexp]and--certificate-github-workflow-{repository,ref,name,trigger,sha}options to the signing certificate. It does this for both current and legacy bundles. Keyless verification now requires a pinned identity, and an unknown or empty--certificate-*option is an error. Key-based verification (--key) is unchanged. Registry patterns that use RE2\Q…\Equoted literals, such as the one forvfox, are supported. #13875, #13879signer_workflowmust now match the end of the certificate's workflow path as whole path segments. Before, it was a substring match against the whole identity, so a longer workflow file name such asrelease.yml.evil.yml, or a ref that contained the expected path, would pass. An emptysigner_workflownow fails verification. Both the bare form (.github/workflows/release.yml) and the repository-qualified form (owner/repo/.github/workflows/release.yml) still work. #13877Added
Per-cask app directories. A
brew-cask:bootstrap package can set its ownappdir. This overrides the globalMISE_BREW_CASK_OPT_APPDIRsetting, expands~/, and also applies to the cask's dependencies. #13865The setting only applies to installs and upgrades: apps that are already installed are not moved. A first install into a new
appdirwon't replace an existing app it doesn't own unless you setadopt = true. Other package managers ignoreappdirand print a warning.slsa_signer_identityandslsa_signer_issueroptions for aqua tools. These work the same as in the github backend. They letmise lockverify and record SLSA provenance for packages whose registry entry has no signer, such asaqua:google/osv-scanner. You must set both options to non-empty strings, and together they override any signer in the registry, including version overrides. #13856Registry:
cloudflare-cf, Cloudflare'scfCLI, which is in beta and installs fromnpm:cf. It provides thecfandcloudflarebinaries. Pin a beta version for now, such asmise use cloudflare-cf@1.0.0-beta.10. An unpinned install currently resolves to an unrelated old0.xrelease. #13871Docs: a new Releases page (under About in the docs) shows a timeline of release sizes, the issues each release resolved, and expandable release notes. #13855
Fixed
aqua:google/osv-scannerandaqua:fluxcd/flux2. A lock entry with a checksum and recorded provenance is now trusted for SLSA too: the install only checks the artifact digest, as it already did for other provenance types.locked_verify_provenanceor paranoid mode still re-verify and still require a signer. #13856zizmor) failed with "no asset found: ...-unknown-linux-musl...". mise now installs the asset the registry names. The binary still needs glibc orgcompatto run.mise lockforlinux-x64-muslrecords the same asset. #13857mise backends switchhandles stale lock entries. Sometimesmise installwarned that a tool was locked to a replaced backend, for exampleasdf:clojureinstead ofvfox:jdx/vfox-clojure, butmise backends switchthen reported there was nothing to switch. This happened when the config's version no longer matched the lock entry. The command now switches those entries too. Entries at a version the config no longer resolves to are relocked at the config's version and reported asreplacing stale <tool>@<version>. #13859mise install,upgrade,execand similar commands used to exit with 1, the same as an ordinary failure. They now exit with 130 (128 + SIGINT), matchingmise run, so shells and scripts can tell when a user interrupted. A repeated Ctrl-C duringmise runalso exits with 130. This applies on Unix and Windows. #13862latestruntime directories has been removed. It was due to expire in this release and would have blocked normal installs.mise installstill repairs a stalelatestdirectory, but passive commands such asmise lsno longer touch it. #13868exclude.mise doctorandmise dot statusnow report that the watcher is outdated and tell you to runmise bootstrap services apply, which restarts it. #13864no metadata found for version zulu-8 on windows-arm64. #13873 (@jsiu93)Breaking Changes
--from-gitremoved frommise bootstrap.mise bootstrap --from-gitandmise bootstrap remote --from-gitnow fail with an unexpected-argument error. Use--adopt, which has been the documented flag since 2026.9.3: #13872vfox tool plugins that use keyless cosign must pin an identity. If a
PreInstallattestation setscosign_sig_or_bundle_pathwithoutcosign_public_key_path, it must also setcosign_certificate_identityorcosign_certificate_identity_regexp. You can also setcosign_certificate_oidc_issuer. Without an identity, the attestation is rejected. Registry entries that already work with the aqua CLI are not affected. #13875Alpine/musl: if a registry entry names a gnu asset but the release also ships a musl build, mise now installs the gnu build. Before, it switched to musl. Set
libc = "musl"on that tool to keep the musl build. #13857Exit code on Ctrl-C: scripts that checked for exit status 1 after an interrupt should now check for 130. #13862
New Contributors
Full Changelog: jdx/mise@vfox-v2026.9.20...v2026.10.0
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.18: : Remote config includes, OCI task catalogs, and a trust fix for inline tool optionsCompare Source
mise.tomlcan nowincludea shared config file from a git repository or OCI registry, andtask_config.includesaccepts OCI artifacts. The release also closes a trust bypass that could sendGITHUB_TOKENto an attacker-controlled host, adds gem registry sources, and fixes several daemon and dotfiles problems.Security
mise.tomlin an untrusted directory could hide options in a tool key, for example agithub:tool key with[api_url=...]pointing at another host. mise loaded the file without trust because the value was a plain version string. Commands such asmise ls,env,current,outdated,upgrade --dry-runandlatestthen sentGITHUB_TOKENto thatapi_url. Now any tool key that contains[requires trust, the same as{ ... }option tables already did. Plain keys likenodeor"cargo:eza"still load without trust. If you use inline options in a project you haven't trusted yet, runmise trust.MISE_SAFE=1still skips trust checks entirely. #13849Added
Include shared config from git or OCI. Organizations can keep tool versions, env and hooks in one place and pull them into every repo: #13843
A
git::include points at a.tomlfile in a repository. Anoci::include points at an artifact with amise.tomlat its root. The included file is merged beneath the file that includes it, and a later include overrides an earlier one. It uses that file's trust, config root and lockfile. A fragment may contain[tools],[tool_alias],[env],[vars],[hooks],[alias],[shell_alias],[plugins],[wrappers]andmin_version. Anything else is an error, including nestedinclude,[settings], tasks,[dotfiles]and[daemons].MISE_CACHE_DIR/config-includes. Pinned refs are never fetched again. Branches and tags are refreshed afterfetch_remote_versions_cacheexpires, and only by commands that check remote versions, such asinstall,upanduse. If a refresh fails, the cached copy is used with a warning.OCI task catalogs.
task_config.includesacceptsoci::references, in addition togit::. The artifact is pulled, verified against its digests, cached inMISE_CACHE_DIR/remote-oci-tasks-cache, and loaded like a local task directory. Credentials come fromdocker login/podman login. Artifacts with symlinks or special files are rejected. Signatures are not verified, so pin@sha256:if you need the contents to stay the same. #13820mise bootstrap --fromaccepts?ref=to select a branch, tag or commit, for examplemise bootstrap --from 'git::<repo-url>?ref=v1'. Thegit::prefix is optional. With--update, mise resolves the ref on origin again and fast-forwards branches. A ref that was deleted upstream is an error. #13822Install a gem from a specific registry. The new
sourceoption sends version lookup and install for one gem to that registry, and leaves the machine'sgem sourcesunchanged. Credentials in the URL are redacted from logs and install metadata. #13391 (@waynehoover)A GitHub Packages source (the
rubygems.pkg.github.comhost) without credentials now uses the GitHub token mise already resolves. The token needsread:packages. GitHub Packages has no versions API, so you must pin an exact version there. #13832 (@waynehoover)mise lock --sidecarslists the native dependency sidecar directories (aube for npm, uv for Python) that must be committed along with `misConfiguration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.