Skip to content

chore(deps): update dependency jdx/mise to v2026 - #220

Open
renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x
Open

renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x

Conversation

@renovate

@renovate renovate Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update New value References Sourcegraph
jdx/mise uses-with major 2026.10.0 source code search for "jdx/mise"

Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.


Release Notes

jdx/mise (jdx/mise)

v2026.10.0

Compare Source

v2026.9.18: : Remote config includes, OCI task catalogs, and a trust fix for inline tool options

Compare Source

mise.toml can now include a shared config file from a git repository or OCI registry, and task_config.includes accepts OCI artifacts. The release also closes a trust bypass that could send GITHUB_TOKEN to an attacker-controlled host, adds gem registry sources, and fixes several daemon and dotfiles problems.

Security

  • Inline tool options now require trust. Before this change, a mise.toml in an untrusted directory could hide options in a tool key, for example a github: tool key with [api_url=...] pointing at another host. mise loaded the file without trust because the value was a plain version string. Commands such as mise ls, env, current, outdated, upgrade --dry-run and latest then sent GITHUB_TOKEN to that api_url. Now any tool key that contains [ requires trust, the same as { ... } option tables already did. Plain keys like node or "cargo:eza" still load without trust. If you use inline options in a project you haven't trusted yet, run mise trust. MISE_SAFE=1 still skips trust checks entirely. #​13849

Added

  • Include shared config from git or OCI. Organizations can keep tool versions, env and hooks in one place and pull them into every repo: #​13843

    include = [
      "git::<repo-url>//mise.toml?ref=main",
      "oci::ghcr.io/myorg/platform-config@sha256:0f1e2d3c...",
    ]
    
    [tools]
    node = "22"   # the file's own entries override the included ones

    A git:: include points at a .toml file in a repository. An oci:: include points at an artifact with a mise.toml at its root. The included file is merged beneath the file that includes it, and a later include overrides an earlier one. It uses that file's trust, config root and lockfile. A fragment may contain [tools], [tool_alias], [env], [vars], [hooks], [alias], [shell_alias], [plugins], [wrappers] and min_version. Anything else is an error, including nested include, [settings], tasks, [dotfiles] and [daemons].

    • An untrusted config never fetches, and safe mode never fetches for project config.
    • Paranoid mode requires a full commit sha or an OCI digest.
    • Fragments are cached in MISE_CACHE_DIR/config-includes. Pinned refs are never fetched again. Branches and tags are refreshed after fetch_remote_versions_cache expires, and only by commands that check remote versions, such as install, up and use. If a refresh fails, the cached copy is used with a warning.
  • OCI task catalogs. task_config.includes accepts oci:: references, in addition to git::. The artifact is pulled, verified against its digests, cached in MISE_CACHE_DIR/remote-oci-tasks-cache, and loaded like a local task directory. Credentials come from docker login/podman login. Artifacts with symlinks or special files are rejected. Signatures are not verified, so pin @sha256: if you need the contents to stay the same. #​13820

    [task_config]
    includes = ["oci::ghcr.io/myorg/shared-tasks:1.0.0"]
    oras push ghcr.io/myorg/shared-tasks:1.0.0 build.toml scripts/deploy
  • mise bootstrap --from accepts ?ref= to select a branch, tag or commit, for example mise bootstrap --from 'git::<repo-url>?ref=v1'. The git:: prefix is optional. With --update, mise resolves the ref on origin again and fast-forwards branches. A ref that was deleted upstream is an error. #​13822

  • Install a gem from a specific registry. The new source option sends version lookup and install for one gem to that registry, and leaves the machine's gem sources unchanged. Credentials in the URL are redacted from logs and install metadata. #​13391 (@​waynehoover)

    [tools]
    "gem:internal-tool" = { version = "latest", source = "<registry-url>" }

    A GitHub Packages source (the rubygems.pkg.github.com host) without credentials now uses the GitHub token mise already resolves. The token needs read:packages. GitHub Packages has no versions API, so you must pin an exact version there. #​13832 (@​waynehoover)

  • mise lock --sidecars lists the native dependency sidecar directories (aube for npm, uv for Python) that must be committed along with mise.lock. It doesn't resolve, install or write anything. It marks missing sidecars, follows symlinked lockfiles, and supports --json for tools such as Renovate. #​13819

  • Daemon presets export their named ports as environment variables, for example CRDB_HTTP_PORT for a cockroachdb daemon named crdb, or AUTHZ_HTTP_PORT and AUTHZ_METRICS_PORT for a spicedb daemon named authz. The values include worktree offsets from port = "auto" and any ports.* overrides, so you can use them in [env] without working out the port yourself. #​13835

  • proxy_idle_timeout for daemons is now documented, typed in the JSON schema and validated. Set a duration such as "30m" to stop a proxy-started daemon, and then its dependencies, after that long without traffic. Set it to false to opt out. mise rejects true, bare numbers and values that don't look like durations, and names the daemon in the error. This requires pitchfork 2.27.0. #​13830, #​13836

  • Registry: added lstk, the CLI that replaces LocalStack's old one. Installing localstack now warns that it is deprecated and suggests mise use lstk. Registry entries can now set a deprecated message. #​13817

Fixed

  • mise generate install-script no longer panics with or without --version. The generated wrapper now passes its pinned version to the installer. Before, a wrapper named for one release could install and keep running an older one. Without --version, the pin is the release mise self-update would pick. #​13816
  • mise oci build, push and run no longer fail on a required env var when the project's [oci.env] gives it a value. You can now use a placeholder for a secret that only exists at runtime. Other commands still require the variable. #​13821
  • mise lock now prints a warning with the cause when it skips a tool, for example a GitHub rate limit, instead of only counting it as skipped. You get one warning per tool. #​13831
  • Daemons:
    • mise daemons start|stop|restart --all now works and applies to every daemon in the current project. Before, pitchfork rejected the command. --all can't be combined with daemon names or --group. #​13827
    • The first mise daemons start or restart now installs the preset's tool. Before, it failed with a false "requires ... but [tools] selects ..." error. Only the tools of the requested daemons and their dependencies are installed. #​13837
    • URLs printed for projects without an explicit [daemons_settings] namespace now route through pitchfork's proxy instead of returning 404. This needs a pitchfork that supports config add --label. mise checks for the flag itself and picks it up when pitchfork is upgraded. #​13833
    • When an automatically allocated daemon port is already taken, mise explains how to pin a different port in mise.local.toml. mise no longer adds its own error lines after pitchfork's message, and it exits with pitchfork's status. #​13839
  • Dotfiles:
    • mise dot and other commands that use mise's internal Git calls work again with Git for Windows 2.56. #​13812 (@​genskyff)
    • After an upgrade, the history watcher now notices that the mise binary was replaced, saves pending edits and exits so the service manager restarts it on the new version. A watcher started by hand with mise dot watch has to be started again. mise dot status now says when captures are failing. #​13845

Full Changelog: jdx/mise@vfox-v2026.9.19...v2026.9.18

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.17: : Self-update waits 24 hours for new releases and verifies signed packslips

Compare Source

mise self-update and the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local global miserc, an opt-in way for command-not-found to install registry tools, and a postinstall mode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode.

Changed

  • Self-update and installs wait for a minimum release age. When no version is pinned, mise self-update, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with --force. The age is taken from, in order: --minimum-release-age, then self_update.minimum_release_age, then the global minimum_release_age setting, then 24h. Use 0s to get releases right away. #​13782

    [settings]
    self_update.minimum_release_age = "7d"
    mise self-update --minimum-release-age 0s
    curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d sh

    The installer reads environment variables only (MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE, MISE_MINIMUM_RELEASE_AGE), and it accepts integer s/m/h/d/w durations. A saved copy of the installer no longer pins a default version, so set MISE_VERSION if you need reproducible installs.

  • Self-update verifies signed packslips. For releases v2026.9.3 and later, mise self-update now requires a valid signed packslip, on top of the embedded archive signature it already checked. mise checks the archive digest and size, the version, the release workflow, and the transparency-log timestamp. Trust is pinned to mise's GitHub repository ID (586920414), so a rename or move to another organization still works, but a different repository that takes over the name is rejected. If the manifest is missing or invalid, mise stops and leaves the current binary in place. Releases 2026.9.2 and older still update with signature-only checks. Custom mirrors must serve the original signed manifests and archives. #​13785

  • mise self-update now downloads with mise's own HTTP client and progress display, and extracts only the expected executable from the verified archive. Plugin-update failures during self-update now show as warnings and no longer fail the command. #​13783

  • Registry: timoni (0.35.0+) and worktrunk (0.80.0+) now install from signed packslips, which include completions and skills. Older versions still install through their existing backends, and you can list them with mise ls-remote aqua:stefanprodan/timoni or mise ls-remote aqua:max-sixty/worktrunk. #​13780

Added

  • Machine-local global miserc. ~/.config/mise/miserc.local.toml applies from any directory and overrides fields in the shared global miserc.toml. You can use it to pick an environment on one machine without editing shared files. Project miserc files, MISE_ENV, and -E still take precedence over it. #​13778

    # ~/.config/mise/miserc.local.toml
    env = ["work"]
  • Command-not-found can install tools you haven't configured (opt-in). With not_found_auto_install_registry = true, running an unknown command installs the matching registry tool at latest and adds it to your global config. This only happens when exactly one registry tool provides that command. mise skips commands with several providers, and it skips disabled tools and tools that don't support your OS. The default is false. #​13781

    [settings]
    not_found_auto_install_registry = true
  • postinstall that runs on every install. With when = "always", a tool's postinstall command runs on every mise install that selects the tool, even when that version is already installed. Dry runs skip it. The plain string form and tables without when still run only on a fresh install or repair. #​13789

    [tools]
    node = { version = "26", postinstall = { run = "npm install -g corepack", when = "always" } }
  • Warnings for outdated lockfile formats. If a lockfile format was replaced more than six months ago, mise warns once per file during commands like mise install, mise exec, and task runs. The warning shows the command to fix it: mise lock --upgrade, or mise lock --global --upgrade for a global config. #​13779

  • Per-machine email for dotfiles history commits. The new [history].git_email setting sets the commit email, and {hostname} is filled in when each commit is made, so you can tell which machine saved a checkpoint. Without the setting, commits still use mise@localhost. #​13791

    [history]
    git_email = "mise@{hostname}"

Fixed

  • Paranoid mode: --yes, MISE_YES=1, and CI auto-confirmation no longer approve trust for new or edited config files. Unattended runs now fail until you approve the file with mise trust or at an interactive prompt. #​13796
  • npm with pnpm 12: mise now passes minimum_release_age to pnpm as --config.minimum-release-age. pnpm 12 silently ignored the camelCase spelling, so the cutoff wasn't applied to transitive dependencies. The new spelling also works on pnpm 10.16+ and 11. #​13764 (@​Nagato-Yuzuru)
  • mise upgrade --bump now updates an exact-release request to the latest release with the same prefix, for example 29.1 to 29.1.1. Before, it kept the old version. #​13759 (@​ryoikarashi)
  • go: installs that resolve latest to a version no longer retry without the v prefix after a failure. That extra retry used to hide Go's original error. Explicit unprefixed versions still get the retry, and if both attempts fail, the error now shows both failures. #​13794
  • Homebrew formula builds:
    • Formulas that write files with Pathname#write no longer fail after the build with super: no superclass method 'write'. This affected generated completions (such as starship) and inreplace. #​13760 (@​jacobbednarz)
    • Formulas that include Homebrew's Language::* mixins (such as qmk) no longer fail with a NameError while mise reads them. Install-time helpers that mise doesn't support now produce a clear error message. #​13328 (@​waynehoover)
    • Source archives whose URL has no file extension, such as GitHub codeload tarballs, are now detected by their contents and unpacked. Before, they were copied into the build directory unextracted. This also applies to casks. #​13750 (@​jacobbednarz)

Documentation

  • The landing page now has a seven-minute showreel of mise, and the mise run music video replaces the theme song. #​13797, #​13799

New Contributors

Full Changelog: jdx/mise@vfox-v2026.9.18...v2026.9.17

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.16: : Per-tool libc for aqua tools, monorepo task path aliases, and packslip pins that survive repo renames

Compare Source

Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in mise run --no-timings, cargo +nightly and the outdated/upgrade version comparison, and speeds up shims and config loading.

Added

  • Per-tool libc for aqua tools. On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such as aqua:domcyrus/rustnet. You can now pick the build for a single tool instead of changing the global libc setting. #​13701

    [tools]
    "aqua:domcyrus/rustnet" = { version = "latest", libc = "musl" }

    The option accepts glibc (or gnu) and musl. mise never falls back to the other libc for that tool. The option applies to install, mise lock, and checksum, signature and provenance lookups, and it is recorded in the lockfile's tool options. A platform that already names a libc (a musl host or a linux-*-musl lockfile platform) still wins. A version that is already installed keeps its build until you run mise install --force. mise ls-remote still uses the host libc. If a registry template uses a variable named libc, set it as vars.libc.

  • Path aliases for monorepo tasks. Deeply nested config roots can now have a short name. #​13756

    monorepo_root = true
    
    [monorepo]
    config_roots = ["foo/bar/baz/abc/123"]
    
    [monorepo.path_aliases]
    "123" = "foo/bar/baz/abc/123"

    mise run //123:build runs //foo/bar/baz/abc/123:build. Aliases also work in task dependencies, in patterns like //123:*, and in child paths like //123/sub:build. Each alias must be a single path segment, must point at a configured root, and can't overlap an existing root path. A task's full path is still its canonical name.

  • Packslip tools keep installing after a repository rename. mise now pins GitHub and GitLab packslip projects by the repository ID recorded in the signing certificate, not only by name. If old/tool is renamed to new/tool under the same owner, packslip:github.com/old/tool keeps installing and prints a warning once, asking you to update the config. You don't need mise packslip forget. mise refuses a transfer to another owner. It also refuses a different repository that takes over a pinned name, which is how a deleted and re-created name looks. To accept either one, run mise packslip forget for the old name, and for a re-created repository also remove the tool's mise.lock entries. #​13702, #​13738

    In lockfile revision 3, the IDs are stored as:

    [tools.hk."platforms.linux-x64"]
    repository_ids = { repository = "922514152", owner = "216188" }
  • mise dot track --allow-plaintext. Directly tracking a file with a credential-like name (for example ~/commit-mossy-token.md) used to report success while every history save quietly left the file out. mise dot track now asks whether to save the file in plaintext, and the default answer is No. In non-interactive use, pass --allow-plaintext. --yes does not approve plaintext. The choice is saved as allow_plaintext = true on the [dotfiles] entry. For real credentials, use --encrypt. #​13749

  • Registry: mise use mbx now resolves to mr-boxington. #​13752

Fixed

  • mise outdated and upgrade warnings no longer offer an older release as an update when the installed version has a v or V prefix. For example, v2.1.280 → 2.1.278 was shown as an update. Versions that differ only in build metadata (for example 1.36.4+k3s1 and 1.36.4+k3s2) are now treated as equal. #​13690 (@​himkt)
  • mise run --no-cache and mise tasks run --no-cache now clone remote git:: task includes again, and fetch remote tasks that run as dependencies again. Before, both kept using the cached copy. #​13697 (@​irisTa56)
  • mise run --no-timings hides each task's "Finished in …" line again, not only the run total. It also overrides MISE_TASK_TIMINGS=1. This had regressed in v2025.11.2. #​13718
  • cargo +nightly works again with rust = "nightly". Since 2026.8.6 mise installs a dated nightly, so rustup had no toolchain named nightly. Depending on rustup's auto-install setting, cargo +nightly then either failed or downloaded a second, unpinned nightly. mise now also sets up rustup's nightly-<host> toolchain from the pinned nightly, using reflinks or hardlinks. It leaves alone a rustup nightly that is newer or has extra components or targets. Explicitly dated requests such as nightly-2026-08-13 don't touch it. Existing installs pick this up on their next nightly install, or right away with mise install -f rust. #​13707
  • Running mise dot track again on a path that is already tracked now reports "already tracked". It no longer prompts, rewrites the config, or records an empty checkpoint. Changed file contents and flags that change the declaration (such as --no-autosave) are still saved. #​13648
  • Blob-pack downloads from the remote cache now retry transient stream errors, the same way single blob downloads do. #​13715

Security

  • SLSA provenance must come from the expected signer. Before, any valid Sigstore signature, even from an unrelated workflow, passed SLSA verification. mise now checks the certificate's URI identity and OIDC issuer against the values configured for the tool:

    • aqua registry entries: signer_identity and signer_issuer under slsa_provenance
    • github: tools: the slsa_signer_identity and slsa_signer_issuer tool options (the identity supports {{version}} templating)
    • vfox plugins: slsa_signer_identity and slsa_signer_issuer returned from PreInstall

    If a tool doesn't configure both values, mise skips the SLSA check and uses any other verification available. For now this applies to the bundled aqua packages that have SLSA metadata but no signer fields. SLSA lock entries are checked again on every install, even when a checksum is present. #​13725

  • Public-key DSSE bundles used by aqua and vfox verification must now have a SHA-256 subject digest that matches the downloaded artifact. Before, a valid bundle could be reused to verify a different download. #​13721

Performance

  • Shims no longer run rustup checks when rust is configured alongside other tools. The same goes for mise exec with auto-install disabled. One report measured the go shim at about 31 ms with rust in the config, compared with 12 ms without it. mise install, and mise exec with auto-install on, still detect and repair missing rustup components. #​13705
  • Config loading and fuzzy version resolution (for example node = "24") do less work: plugin shorthands are built without checking every registry tool's backends, global-config checks stop resolving symlinks for every tool, and fuzzy matching no longer compiles regexes. #​13694, #​13695, #​13696

Documentation

  • The task docs now give the correct default job count (8). They also describe the default output mode correctly: prefix when tasks run in parallel and interleave when they run in sequence. #​13716

Breaking Changes

  • Lockfile revision 3. New and empty mise.lock files are written as lockfile_version = 3, and older mise versions reject them. Existing lockfiles keep their revision when mise writes to them. When a revision 2 lockfile gets packslip repository IDs, mise warns and leaves them out. To store them, run mise lock --upgrade once everyone who shares the lockfile is on this release.
  • SLSA checks for locked tools. A lockfile entry that requires SLSA now fails with an explanation if the tool has no expected signer configured. To fix it, configure the signer or refresh the entry with mise lock.
  • Dotfiles history shared across machines. Older mise versions can't read enrollment metadata that includes allow_plaintext. Upgrade every machine that shares the history before you use --allow-plaintext.

New Contributors

Full Changelog: jdx/mise@vfox-v2026.9.17...v2026.9.16

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.15: : vfox tools in OCI images, faster shell prompts, and safer dotfiles pattern matching

Compare Source

mise oci build can now package tools installed by vfox plugins, and vfox plugins can repair an existing install when its tool options change. Shell prompts, cd, and settings loading are faster. Dotfiles include/exclude patterns now follow .gitignore rules for * and a leading /, which fixes a case where rollback could delete a live file.

Added

  • vfox tools in OCI images (experimental). mise oci build used to reject every tool installed by a vfox plugin. It now builds those tools into the image, with one layer per tool plus one layer per plugin at /mise/plugins/<name>/, so mise inside the image can resolve the tool without cloning the plugin. The plugin's env hook runs on the build host. Install-dir paths are rewritten to their in-image location, and mise warns when a value points into the host's home directory. Changing a plugin invalidates the reused layers of its tools on mise oci push. asdf plugins are still rejected. #​13670

  • vfox plugins can repair installs that no longer match tool options. Plugins can add an optional hooks/mise_install_satisfied.lua hook that tells mise an installed version no longer matches its options, for example after a component is added to a gcloud config. mise install and auto-install (such as mise x) then rerun the plugin's PostInstall and the tool's postinstall script on the existing install without downloading it again. If the hook itself errors, mise warns and keeps the install. Plugins without the hook work as before. See docs/tool-plugin-development.md. #​13668

    [tools]
    gcloud = { version = "latest", components = ["gke-gcloud-auth-plugin"] }
  • Git subdirectory installs for pypi:. Git sources now accept a #subdirectory= fragment (other fragment keys are passed through as written), and git+<scheme>:// URLs work without a trailing .git. Each subdirectory is its own tool with its own install directory. latest still means the repository's newest GitHub release, so pin a branch or commit if those releases predate the subdirectory. #​13607 (@​jakedgy)

    [tools]
    "pypi:git+https://github.com/runpantheon/ltui#subdirectory=ltui" = "main"
    "pypi:runpantheon/ltui#subdirectory=jtui" = "main"
  • max_version for registry backends. Registry entries can now set an exclusive max_version, alone or together with min_version, so older releases can come from a legacy backend and newer ones from another. It requires version_order = "semver". A locked backend is used only for versions it serves. #​13676

  • Mac App Store names in mise bootstrap packages status. Installed mas: packages now show the app name next to the numeric ID (for example 1056643111 (Clocker)), and --json adds a name field. Apps that aren't installed still show only their ID. #​13622

  • Registry: added sofka (#​13612, @​jylenhof), imessage-exporter (#​13640, @​i-api), and spotify-downloader (#​13641, @​i-api). nub 0.9.5 and later now installs from github:nubjs/nub, and the entry lists the nubr bin (#​13643, @​colinhacks). cocogitto now lists cog as its bin (#​13657).

Changed

  • mise exec warns when a missing pinned tool falls back to PATH. When auto-install is off (exec_auto_install = false, auto_install = false, or auto_install_disable_tools) and the command belongs to a pinned tool that isn't installed, mise used to run a same-named binary from PATH without saying anything. It still runs it, but now prints a warning such as jq@1.7.1 is not installed and auto-install is disabled, so mise looks for jq on PATH instead. There's no warning when another configured version of the tool, a command wrapper, or a project env._.path entry provides the command. #​13650, #​13658
  • mise tasks validate fails on unparseable usage specs. A file task's #USAGE spec (or a TOML task's usage) that doesn't parse is now a usage-parse-error error, so validation exits 1, including with --errors-only. Before, it was only a warning and validation passed. mise run and mise tasks ls behave as before. CI that runs mise tasks validate will now fail on these specs. #​13672
  • Linux GNU release binaries are linked non-PIE. Every mise command on Linux x64, arm64, and armv7 (GNU) now starts about 3 ms faster. The tradeoff is that ASLR no longer applies to mise's own code and data, though the heap, stack, and shared libraries are still randomized. musl, macOS, source builds, and cargo install are unchanged. #​13687

Fixed

Dotfiles
  • * no longer crosses / in tracked include patterns. Capture and rollback used to disagree about what rules/*.md selected. After you widened the list, mise dot rollback to an older checkpoint could delete a nested file such as rules/deep/two.md. include now follows .gitignore rules: * stops at /, and you need ** to match nested files. exclude lists keep matching what they matched before, but mise now prints a deprecation warning when an exclusion depends on * crossing /. Use ** in those patterns instead. #​13618
  • A leading / anchors include/exclude patterns to the entry root. Before, these patterns matched nothing at all. Now exclude = ["/cache"] skips only the top-level cache directory, and include = ["/rules/*.md"] works. In the global [history] exclude list, a leading / still means an absolute path. #​13621
Tasks and config
  • Tasks in a conf.d folder fragment now run in that folder, with {{config_root}} and MISE_CONFIG_ROOT pointing there. Each folder's [task_config] applies only to its own tasks, so a fragment's includes no longer hides the default task directories like ~/.config/mise/tasks. #​13662
  • A settings load that was already running could cache a stale snapshot after another thread changed settings, which dropped a just-applied override. This is fixed. #​13646
Plugins and shims
  • mise now warns when an installed git plugin's origin URL or checked-out commit doesn't match its [plugins] entry. The warning appears in mise install, mise plugins install, and mise doctor. Related fixes #​13663:
    • mise plugins install --force <name> now reinstalls from the [plugins] pin.
    • A failed ref checkout no longer leaves an unpinned clone behind.
    • Short SHAs fail with a clear error, since a full SHA is required.
    • Shorthand pins like owner/repo#v1.2.0 keep their ref.
  • On Windows, [wrappers.*] command wrappers (including the cargo wrapper that mr_boxington generates) now run through exe- and file-mode shims and mise x. Before, the real tool ran instead. #​13673
Bootstrap
  • On apt systems, mise now simulates the install first and runs apt-get update once if the simulation fails. This fixes has no installation candidate failures on machines whose package lists cover only the install media. #​13659
  • On macOS, mise bootstrap macos defaults now reads and writes the container plist for sandboxed apps such as Safari, which the app actually uses. Launch the app once first so its container exists. Writing another app's container may require Full Disk Access for your terminal. #​13660
  • When mise bootstrap packages prune fails on a brew: formula it can't resolve, the error now names the config file that declares it. When the name is actually a cask, mise suggests brew-cask:<name>. #​13661

Performance

  • Faster shell prompts. When nothing has changed, mise hook-env no longer loads all settings or starts the async runtime (6.6 ms to 4.9 ms on Linux in the PR's measurements), as long as hook_env.chpwd_only and hook_env.cache_ttl are unset. #​13686
  • Faster cd with npm tools installed. The npm install health check now reads the virtual store's directory listing instead of calling stat on every package. #​13685
  • Faster settings loading. Config discovery skips conf.d globs for directories that don't exist, which halves settings load time in deep checkouts. #​13688
  • Faster brew-cask: lookups. Official casks are resolved from Homebrew's bulk cask.json index, cached locally and re-checked with a conditional request after 7.5 minutes, instead of one request per cask. In the PR's test, bootstrap packages status with 143 casks dropped from about 26s to about 2s. #​13349 (@​waynehoover)
  • Fixed slowdowns from deferred prunes. When a deferred-prune receipt from mise upgrade comes due but the version is still in use, mise now re-checks it once a day instead of on every command. This could make trivial commands about 9x slower. Pruning can now happen up to a day after the last reference is removed. #​13674
  • mise ls, mise prune, and shim rebuilds scan install directories in a single pass. #​13675

Full Changelog: jdx/mise@vfox-v2026.9.16...v2026.9.15

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.14: : conf.d folder fragments, Stow-style dotfiles options, and mise-versions for any public GitHub repo

Compare Source

A folder inside any conf.d directory now loads as its own config fragment and serves as the config root for the files in it, which gives [bootstrap].config_roots users a direct migration path. [dotfiles] gains two GNU Stow-style options: relative symlinks and dot-<name> sources. Release metadata for any public github.com repo now comes from mise-versions, and the registry can require GitHub attestations for specific tools.

Added

  • conf.d folder fragments. A folder in a global, system, or project conf.d directory now loads as a fragment. Relative paths, {{ config_root }}, and task working directories resolve inside that folder, so a bundle can keep its files next to its config. Each folder can hold mise.toml, mise.local.toml, mise.<env>.toml, and mise.<env>.local.toml. Folders are not searched recursively, and folders whose names start with . are skipped. A folder can be a symlink. Folder fragments load after the single-file fragments in the same conf.d (in folder-name order) and before config.toml. mise use/mise set never write to them. #​13603

    ~/.config/mise/conf.d/
    ├── git.toml          # single-file fragment, unchanged
    └── git-tools/        # folder fragment
        ├── mise.toml
        └── gitconfig
    
    # ~/.config/mise/conf.d/git-tools/mise.toml
    [dotfiles]
    "~/.gitconfig" = "gitconfig"   # resolves to conf.d/git-tools/gitconfig

    Compatibility: if a directory inside a conf.d that mise reads already contains a mise.toml, that file now loads.

  • Relative dotfile symlinks. symlink and symlink-each entries can now point at their source by a relative path, so links keep working when a home directory is mounted at a different path or moved. Turn this on for all entries with dotfiles.relative_symlinks = true (or MISE_DOTFILES_RELATIVE_SYMLINKS=1), or per entry with relative = true/false. When you turn it on, existing absolute links are re-pointed on the next apply. Turning it off does not convert relative links back to absolute ones. This option has no effect on Windows. #​13583

    [settings]
    dotfiles.relative_symlinks = true
    
    [dotfiles]
    "~/.config/foo" = { source = "~/dotfiles/foo", mode = "symlink" }   # -> ../dotfiles/foo
    "~/.bashrc"     = { source = "~/dotfiles/bashrc", relative = false } # stays absolute
  • dot_prefix for dotfiles. With dot_prefix = true on a symlink-each or directory copy entry, any path component named dot-<name> deploys as .<name> (for example, home/dot-config/foo deploys as ~/.config/foo). exclude and manifest = "git" still match source names. If two sources map to the same target, apply fails. mise dot add refuses to capture into dot_prefix entries, and mise oci builds use the same mapping. #​13585

    [dotfiles]
    "~" = { source = "home", mode = "symlink-each", dot_prefix = true, exclude = ["README.md"] }
  • mise-versions for any public github.com repo. For github:, aqua:, and packslip: tools that aren't in the registry, version listing, release lookup, and attestation lookup now go through mise-versions, so they no longer use your GitHub API rate limit in the common case. Private repos still use your own token against api.github.com. #​13584

    • mise treats the mirror as untrusted. Download URLs must match the configured repo, release tag, and asset name, and mirrored attestations must name the requested repo.
    • In paranoid mode, mise checks a "no attestations" answer from the mirror against GitHub before skipping verification.
    • If url_replacements reroutes GitHub API paths, mise skips mise-versions for that metadata.
    • If mise-versions fails for any reason other than a 404, mise falls back to api.github.com and logs a warning.
  • Registry-required GitHub attestations. Registry github: backends can declare attestations_since = "<semver>". For versions at or after that boundary:

    • mise lock records github-attestations provenance.
    • Installs require a verified attestation for every downloaded asset. This requirement overrides weaker provenance recorded in a lockfile.
    • A missing attestation is a hard error.

    42 registry tools now set this boundary, including aube, aqua, pixi, ty, pandoc, fnox, doppler, and syncthing. Users who have turned off github_attestations are not affected. #​13586

Fixed

  • Install lock waits: when one process is waiting for another to finish installing the same tool version, the message now names the process holding the lock (waiting for install lock held by pid 61907). This is usually a shim auto-installing the tool. #​13588
  • Slow downloads: mise now warns once per download if throughput stays below 16 KiB/s for a full minute, naming the host and suggesting a mirror. The download is not aborted; http_download_timeout is still the hard limit. #​13589
  • Interrupted installs: a half-installed version no longer appears in version listings, can't be picked as the latest installed version, and doesn't keep latest/1/1.2 runtime symlinks pointing into it. #​13596
  • mise prune: no longer deletes versions pinned by another project when you run it from a directory whose .miserc.toml lists that project in ignored_config_paths. The same fix applies to mise ls --prunable and the stale-version check in mise upgrade. These commands now honor ignored_config_paths only from MISE_IGNORED_CONFIG_PATHS and global or system miserc.toml. #​13602
  • mise oci build: directory [dotfiles] entries (symlink-each and directory copy) now honor exclude and manifest = "git", so the image contains the same files mise dot apply deploys. #​13591
  • pipx/pypi: latest no longer resolves to PEP 440 developmental releases such as 2026.9.16.232951.dev0, matching what pip and uv do. Local labels like 1.1+gpu.dev0 are still treated as stable. #​13601
  • pipx/pypi: mise use 'pypi:git+ssh://git@github.com/psf/black.git' now works. Previously, the @ in git@ was read as the version separator. #​13610
  • MISE_USE_VERSIONS_HOST=0: now fetches the version list from the source instead of reusing a cached, possibly older list from the versions host. #​13605
  • brew source builds: checksum-pinned formula source downloads now follow HTTPS-to-HTTP mirror redirects (such as those from ftpmirror.gnu.org) and still reject tarballs whose checksum doesn't match. This affects Unix only. Every other download still refuses HTTPS-to-HTTP redirects. #​13611
  • npm backend on Windows: updating the bundled aube to v2.4.0 fixes lifecycle scripts failing with EISDIR: illegal operation on a directory, lstat 'C:' during npm: installs. #​13608

Changed

  • The [bootstrap].config_roots deprecation warning now explains how to move each root into a conf.d folder, either by moving it or by symlinking it. The removal date (mise 2027.3.3) is unchanged. #​13598
  • Registry: spin-framework now installs through aqua by default. The previous backend is still available. #​13594 by @​scop

Full Changelog: jdx/mise@vfox-v2026.9.15...v2026.9.14

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.13: : OpenTelemetry for tasks, shared daemon providers, mise backends switch, and declarative dotfile removal

Compare Source

mise run can now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the new mise backends switch command does it when you ask. [dotfiles] and [bootstrap.files] can now remove files and manage permissions, and mise bootstrap unapply removes what a module set up. The experimental pkgx: backend has been removed.

Highlights

  • Observability and shared services (experimental): task runs export OTLP traces and, if you opt in, task output as logs. Global [daemon_providers] run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout.
  • Safer lockfiles: locked tools stay on their locked backend, mise lock --bump checks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project's mise.lock.
  • Declarative cleanup: mode = "absent", remove_empty templates, permissions-only entries, removal of empty directories mise created, and mise bootstrap unapply let a config describe what should not be on a machine.

Added

Tasks
  • OpenTelemetry export for mise run (experimental). Each run becomes one trace, with a span per task (grouped by monorepo package) that carries its exit code and redacted args. W3C TRACEPARENT is read from the environment and passed to each task, so nested mise run calls and instrumented tools appear in the same trace. Nothing is exported unless otel.enabled = true and an OTLP endpoint is set. Offline mode disables export, and each export times out after 3s by default. A separate otel.logs = true setting exports task stdout (INFO) and stderr (WARN) as log records linked to their spans, with redactions applied first. With otel.logs on, tasks in interleave/quiet modes no longer get a TTY; use --raw for tasks that need one. #​13557, #​13558, #​13559 (built on work by @​MatthiasGrandl and @​zeitlinger)

    [settings]
    otel.enabled = true
    otel.logs = true   # optional; exports task output too
    export OTEL_EXPORTER_OTLP_ENDPOINT=<your OTLP/HTTP collector URL>
    mise run build ::: test
Daemons (experimental)
  • Shared server providers. Declare long-lived PostgreSQL, CockroachDB, or NATS servers in global config under [daemon_providers] and manage them with mise daemons providers ls|start|stop|restart. Providers have their own tools, ports, and persistent data. They run in an isolated environment and are not tied to any checkout. #​13534

  • Per-checkout databases and accounts on a shared server. A project daemon with provider = "..." gets its own database (PostgreSQL/CockroachDB) or its own NATS account with separate subjects and JetStream data. Each checkout path gets a stable name, so worktrees share the server but not the data. Give several daemons the same resource name to share data on purpose. Connection env vars point at the right database, and NATS gets an authenticated NATS_URL. #​13536, #​13537

    # ~/.config/mise/config.toml
    [daemon_providers.local-postgres]
    preset = "postgres"
    version = "18"
    port = "auto"
    
    # project mise.toml
    [daemons.db]
    provider = "local-postgres"
    # resource = "shared_app"   # opt in to sharing data
Lockfiles and backends
  • mise backends switch. When the registry moves a tool to a new backend (as happened with hk and communique moving to packslip:), a tool locked to the old backend now stays there. mise install and mise lock print a warning that points to the new command, which moves lock entries to the registry's backend at the same versions, relocks their platforms, and reinstalls. It supports --dry-run, --global, and TOOL@VERSION. If any relock fails, every lockfile it changed is restored. #​13543

  • Tool stubs lock into the project's mise.lock. mise generate tool-stub --lock now records the stub in the nearest project lockfile (listed under tool-stubs), so installs verify the recorded checksums and --locked/MISE_LOCKED=1 accept stubs. Previously the [lock] section written into the stub was never used, so checksums were never checked. #​13502

  • Install from a local archive. The http: backend accepts file:// URLs. It copies the archive instead of downloading it, still verifies checksum, and works offline. #​13574

    [tools]
    "http:my-tool" = { version = "1.0.0", url = "file:///opt/archives/my-tool-v1.0.0-linux-x64.tar.gz", checksum = "sha256:..." }
  • Checksum mismatch hints for re-uploaded GitHub assets. When a github: or aqua: install fails a checksum check, mise asks GitHub for the asset's current digest. If that digest matches the download, the error says the maintainer probably re-uploaded the asset. The install still fails. #​13512

  • vfox BackendUninstall hook. Backend plugins can define hooks/backend_uninstall.lua to clean up outside the install directory. It runs before removal on uninstall, upgrade, and prune. If the hook errors, the install directory is kept. #​13522

CLI
  • mise search checks package registries. Add a prefix to search npm, crates.io, RubyGems, or N

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the bot label Jul 20, 2026
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from b069281 to 4210d96 Compare July 30, 2026 03:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 7255dd3 to 18a73a9 Compare August 5, 2026 03:26
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 2752ba1 to 661a5bf Compare August 12, 2026 20:16
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 6445a85 to c5325ef Compare August 20, 2026 23:10
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 9dd559c to fac6f2e Compare August 26, 2026 03:48
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 61548e9 to 844f10e Compare September 3, 2026 00:28
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from b504efd to 25c7628 Compare September 11, 2026 04:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from 5986910 to e80a868 Compare September 18, 2026 07:31
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 64f8ae1 to 980f1fd Compare September 27, 2026 11:53
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 592af37 to fb21bcb Compare September 30, 2026 23:27
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch from fb21bcb to 8db9151 Compare October 2, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants