chore(deps): update dependency jdx/mise to v2026.9.17 - #2504
Merged
Merged
Conversation
renovate
Bot
requested review from
dhoard,
jaydeluca and
zeitlinger
as code owners
September 28, 2026 00:24
renovate
Bot
force-pushed
the
renovate/mise
branch
from
September 28, 2026 21:13
5123c77 to
68f65bd
Compare
renovate
Bot
force-pushed
the
renovate/mise
branch
from
September 29, 2026 12:32
68f65bd to
df0eb06
Compare
renovate
Bot
force-pushed
the
renovate/mise
branch
from
September 29, 2026 12:41
df0eb06 to
f07c535
Compare
jaydeluca
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2026.9.12→v2026.9.17Release Notes
jdx/mise (jdx/mise)
v2026.9.17: : Self-update waits 24 hours for new releases and verifies signed packslipsCompare Source
mise self-updateand the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local globalmiserc, an opt-in way for command-not-found to install registry tools, and apostinstallmode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode.Changed
Self-update and installs wait for a minimum release age. When no version is pinned,
mise self-update, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with--force. The age is taken from, in order:--minimum-release-age, thenself_update.minimum_release_age, then the globalminimum_release_agesetting, then24h. Use0sto get releases right away. #13782mise self-update --minimum-release-age 0s curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d shThe installer reads environment variables only (
MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE,MISE_MINIMUM_RELEASE_AGE), and it accepts integers/m/h/d/wdurations. A saved copy of the installer no longer pins a default version, so setMISE_VERSIONif you need reproducible installs.Self-update verifies signed packslips. For releases v2026.9.3 and later,
mise self-updatenow requires a valid signed packslip, on top of the embedded archive signature it already checked. mise checks the archive digest and size, the version, the release workflow, and the transparency-log timestamp. Trust is pinned to mise's GitHub repository ID (586920414), so a rename or move to another organization still works, but a different repository that takes over the name is rejected. If the manifest is missing or invalid, mise stops and leaves the current binary in place. Releases 2026.9.2 and older still update with signature-only checks. Custom mirrors must serve the original signed manifests and archives. #13785mise self-updatenow downloads with mise's own HTTP client and progress display, and extracts only the expected executable from the verified archive. Plugin-update failures during self-update now show as warnings and no longer fail the command. #13783Registry:
timoni(0.35.0+) andworktrunk(0.80.0+) now install from signed packslips, which include completions and skills. Older versions still install through their existing backends, and you can list them withmise ls-remote aqua:stefanprodan/timoniormise ls-remote aqua:max-sixty/worktrunk. #13780Added
Machine-local global miserc.
~/.config/mise/miserc.local.tomlapplies from any directory and overrides fields in the shared globalmiserc.toml. You can use it to pick an environment on one machine without editing shared files. Project miserc files,MISE_ENV, and-Estill take precedence over it. #13778Command-not-found can install tools you haven't configured (opt-in). With
not_found_auto_install_registry = true, running an unknown command installs the matching registry tool atlatestand adds it to your global config. This only happens when exactly one registry tool provides that command. mise skips commands with several providers, and it skips disabled tools and tools that don't support your OS. The default isfalse. #13781postinstallthat runs on every install. Withwhen = "always", a tool'spostinstallcommand runs on everymise installthat selects the tool, even when that version is already installed. Dry runs skip it. The plain string form and tables withoutwhenstill run only on a fresh install or repair. #13789Warnings for outdated lockfile formats. If a lockfile format was replaced more than six months ago, mise warns once per file during commands like
mise install,mise exec, and task runs. The warning shows the command to fix it:mise lock --upgrade, ormise lock --global --upgradefor a global config. #13779Per-machine email for dotfiles history commits. The new
[history].git_emailsetting sets the commit email, and{hostname}is filled in when each commit is made, so you can tell which machine saved a checkpoint. Without the setting, commits still usemise@localhost. #13791Fixed
--yes,MISE_YES=1, and CI auto-confirmation no longer approve trust for new or edited config files. Unattended runs now fail until you approve the file withmise trustor at an interactive prompt. #13796minimum_release_ageto pnpm as--config.minimum-release-age. pnpm 12 silently ignored the camelCase spelling, so the cutoff wasn't applied to transitive dependencies. The new spelling also works on pnpm 10.16+ and 11. #13764 (@Nagato-Yuzuru)mise upgrade --bumpnow updates an exact-release request to the latest release with the same prefix, for example29.1to29.1.1. Before, it kept the old version. #13759 (@ryoikarashi)go:installs that resolvelatestto a version no longer retry without thevprefix after a failure. That extra retry used to hide Go's original error. Explicit unprefixed versions still get the retry, and if both attempts fail, the error now shows both failures. #13794Pathname#writeno longer fail after the build withsuper: no superclass method 'write'. This affected generated completions (such as starship) andinreplace. #13760 (@jacobbednarz)Language::*mixins (such asqmk) no longer fail with aNameErrorwhile mise reads them. Install-time helpers that mise doesn't support now produce a clear error message. #13328 (@waynehoover)Documentation
New Contributors
Full Changelog: jdx/mise@vfox-v2026.9.18...v2026.9.17
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.16: : Per-tool libc for aqua tools, monorepo task path aliases, and packslip pins that survive repo renamesCompare Source
Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in
mise run --no-timings,cargo +nightlyand theoutdated/upgradeversion comparison, and speeds up shims and config loading.Added
Per-tool
libcfor aqua tools. On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such asaqua:domcyrus/rustnet. You can now pick the build for a single tool instead of changing the globallibcsetting. #13701The option accepts
glibc(orgnu) andmusl. mise never falls back to the other libc for that tool. The option applies to install,mise lock, and checksum, signature and provenance lookups, and it is recorded in the lockfile's tool options. A platform that already names a libc (a musl host or alinux-*-musllockfile platform) still wins. A version that is already installed keeps its build until you runmise install --force.mise ls-remotestill uses the host libc. If a registry template uses a variable namedlibc, set it asvars.libc.Path aliases for monorepo tasks. Deeply nested config roots can now have a short name. #13756
mise run //123:buildruns//foo/bar/baz/abc/123:build. Aliases also work in task dependencies, in patterns like//123:*, and in child paths like//123/sub:build. Each alias must be a single path segment, must point at a configured root, and can't overlap an existing root path. A task's full path is still its canonical name.Packslip tools keep installing after a repository rename. mise now pins GitHub and GitLab packslip projects by the repository ID recorded in the signing certificate, not only by name. If
old/toolis renamed tonew/toolunder the same owner,packslip:github.com/old/toolkeeps installing and prints a warning once, asking you to update the config. You don't needmise packslip forget. mise refuses a transfer to another owner. It also refuses a different repository that takes over a pinned name, which is how a deleted and re-created name looks. To accept either one, runmise packslip forgetfor the old name, and for a re-created repository also remove the tool'smise.lockentries. #13702, #13738In lockfile revision 3, the IDs are stored as:
mise dot track --allow-plaintext. Directly tracking a file with a credential-like name (for example~/commit-mossy-token.md) used to report success while every history save quietly left the file out.mise dot tracknow asks whether to save the file in plaintext, and the default answer is No. In non-interactive use, pass--allow-plaintext.--yesdoes not approve plaintext. The choice is saved asallow_plaintext = trueon the[dotfiles]entry. For real credentials, use--encrypt. #13749Registry:
mise use mbxnow resolves tomr-boxington. #13752Fixed
mise outdatedand upgrade warnings no longer offer an older release as an update when the installed version has avorVprefix. For example,v2.1.280 → 2.1.278was shown as an update. Versions that differ only in build metadata (for example1.36.4+k3s1and1.36.4+k3s2) are now treated as equal. #13690 (@himkt)mise run --no-cacheandmise tasks run --no-cachenow clone remotegit::task includes again, and fetch remote tasks that run as dependencies again. Before, both kept using the cached copy. #13697 (@irisTa56)mise run --no-timingshides each task's "Finished in …" line again, not only the run total. It also overridesMISE_TASK_TIMINGS=1. This had regressed in v2025.11.2. #13718cargo +nightlyworks again withrust = "nightly". Since 2026.8.6 mise installs a dated nightly, so rustup had no toolchain namednightly. Depending on rustup's auto-install setting,cargo +nightlythen either failed or downloaded a second, unpinned nightly. mise now also sets up rustup'snightly-<host>toolchain from the pinned nightly, using reflinks or hardlinks. It leaves alone a rustup nightly that is newer or has extra components or targets. Explicitly dated requests such asnightly-2026-08-13don't touch it. Existing installs pick this up on their next nightly install, or right away withmise install -f rust. #13707mise dot trackagain on a path that is already tracked now reports "already tracked". It no longer prompts, rewrites the config, or records an empty checkpoint. Changed file contents and flags that change the declaration (such as--no-autosave) are still saved. #13648Security
SLSA provenance must come from the expected signer. Before, any valid Sigstore signature, even from an unrelated workflow, passed SLSA verification. mise now checks the certificate's URI identity and OIDC issuer against the values configured for the tool:
signer_identityandsigner_issuerunderslsa_provenancegithub:tools: theslsa_signer_identityandslsa_signer_issuertool options (the identity supports{{version}}templating)slsa_signer_identityandslsa_signer_issuerreturned fromPreInstallIf a tool doesn't configure both values, mise skips the SLSA check and uses any other verification available. For now this applies to the bundled aqua packages that have SLSA metadata but no signer fields. SLSA lock entries are checked again on every install, even when a checksum is present. #13725
Public-key DSSE bundles used by aqua and vfox verification must now have a SHA-256 subject digest that matches the downloaded artifact. Before, a valid bundle could be reused to verify a different download. #13721
Performance
rustupchecks whenrustis configured alongside other tools. The same goes formise execwith auto-install disabled. One report measured thegoshim at about 31 ms withrustin the config, compared with 12 ms without it.mise install, andmise execwith auto-install on, still detect and repair missing rustup components. #13705node = "24") do less work: plugin shorthands are built without checking every registry tool's backends, global-config checks stop resolving symlinks for every tool, and fuzzy matching no longer compiles regexes. #13694, #13695, #13696Documentation
prefixwhen tasks run in parallel andinterleavewhen they run in sequence. #13716Breaking Changes
mise.lockfiles are written aslockfile_version = 3, and older mise versions reject them. Existing lockfiles keep their revision when mise writes to them. When a revision 2 lockfile gets packslip repository IDs, mise warns and leaves them out. To store them, runmise lock --upgradeonce everyone who shares the lockfile is on this release.mise lock.allow_plaintext. Upgrade every machine that shares the history before you use--allow-plaintext.New Contributors
Full Changelog: jdx/mise@vfox-v2026.9.17...v2026.9.16
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.15Compare Source
v2026.9.14: : conf.d folder fragments, Stow-style dotfiles options, and mise-versions for any public GitHub repoCompare Source
A folder inside any
conf.ddirectory now loads as its own config fragment and serves as the config root for the files in it, which gives[bootstrap].config_rootsusers a direct migration path.[dotfiles]gains two GNU Stow-style options: relative symlinks anddot-<name>sources. Release metadata for any public github.com repo now comes from mise-versions, and the registry can require GitHub attestations for specific tools.Added
conf.d folder fragments. A folder in a global, system, or project
conf.ddirectory now loads as a fragment. Relative paths,{{ config_root }}, and task working directories resolve inside that folder, so a bundle can keep its files next to its config. Each folder can holdmise.toml,mise.local.toml,mise.<env>.toml, andmise.<env>.local.toml. Folders are not searched recursively, and folders whose names start with.are skipped. A folder can be a symlink. Folder fragments load after the single-file fragments in the sameconf.d(in folder-name order) and beforeconfig.toml.mise use/mise setnever write to them. #13603Compatibility: if a directory inside a
conf.dthat mise reads already contains amise.toml, that file now loads.Relative dotfile symlinks.
symlinkandsymlink-eachentries can now point at their source by a relative path, so links keep working when a home directory is mounted at a different path or moved. Turn this on for all entries withdotfiles.relative_symlinks = true(orMISE_DOTFILES_RELATIVE_SYMLINKS=1), or per entry withrelative = true/false. When you turn it on, existing absolute links are re-pointed on the next apply. Turning it off does not convert relative links back to absolute ones. This option has no effect on Windows. #13583dot_prefixfor dotfiles. Withdot_prefix = trueon asymlink-eachor directorycopyentry, any path component nameddot-<name>deploys as.<name>(for example,home/dot-config/foodeploys as~/.config/foo).excludeandmanifest = "git"still match source names. If two sources map to the same target, apply fails.mise dot addrefuses to capture intodot_prefixentries, andmise ocibuilds use the same mapping. #13585mise-versions for any public github.com repo. For
github:,aqua:, andpackslip:tools that aren't in the registry, version listing, release lookup, and attestation lookup now go through mise-versions, so they no longer use your GitHub API rate limit in the common case. Private repos still use your own token against api.github.com. #13584paranoidmode, mise checks a "no attestations" answer from the mirror against GitHub before skipping verification.url_replacementsreroutes GitHub API paths, mise skips mise-versions for that metadata.Registry-required GitHub attestations. Registry
github:backends can declareattestations_since = "<semver>". For versions at or after that boundary:mise lockrecordsgithub-attestationsprovenance.42 registry tools now set this boundary, including
aube,aqua,pixi,ty,pandoc,fnox,doppler, andsyncthing. Users who have turned offgithub_attestationsare not affected. #13586Fixed
waiting for install lock held by pid 61907). This is usually a shim auto-installing the tool. #13588http_download_timeoutis still the hard limit. #13589latest/1/1.2runtime symlinks pointing into it. #13596mise prune: no longer deletes versions pinned by another project when you run it from a directory whose.miserc.tomllists that project inignored_config_paths. The same fix applies tomise ls --prunableand the stale-version check inmise upgrade. These commands now honorignored_config_pathsonly fromMISE_IGNORED_CONFIG_PATHSand global or systemmiserc.toml. #13602mise oci build: directory[dotfiles]entries (symlink-eachand directorycopy) now honorexcludeandmanifest = "git", so the image contains the same filesmise dot applydeploys. #13591latestno longer resolves to PEP 440 developmental releases such as2026.9.16.232951.dev0, matching what pip and uv do. Local labels like1.1+gpu.dev0are still treated as stable. #13601mise use 'pypi:git+ssh://git@github.com/psf/black.git'now works. Previously, the@ingit@was read as the version separator. #13610MISE_USE_VERSIONS_HOST=0: now fetches the version list from the source instead of reusing a cached, possibly older list from the versions host. #13605ftpmirror.gnu.org) and still reject tarballs whose checksum doesn't match. This affects Unix only. Every other download still refuses HTTPS-to-HTTP redirects. #13611EISDIR: illegal operation on a directory, lstat 'C:'duringnpm:installs. #13608Changed
[bootstrap].config_rootsdeprecation warning now explains how to move each root into aconf.dfolder, either by moving it or by symlinking it. The removal date (mise 2027.3.3) is unchanged. #13598spin-frameworknow installs through aqua by default. The previous backend is still available. #13594 by @scopFull Changelog: jdx/mise@vfox-v2026.9.15...v2026.9.14
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.13: : OpenTelemetry for tasks, shared daemon providers,mise backends switch, and declarative dotfile removalCompare Source
mise runcan now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the newmise backends switchcommand does it when you ask.[dotfiles]and[bootstrap.files]can now remove files and manage permissions, andmise bootstrap unapplyremoves what a module set up. The experimentalpkgx:backend has been removed.Highlights
[daemon_providers]run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout.mise lock --bumpchecks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project'smise.lock.mode = "absent",remove_emptytemplates, permissions-only entries, removal of empty directories mise created, andmise bootstrap unapplylet a config describe what should not be on a machine.Added
Tasks
OpenTelemetry export for
mise run(experimental). Each run becomes one trace, with a span per task (grouped by monorepo package) that carries its exit code and redacted args. W3CTRACEPARENTis read from the environment and passed to each task, so nestedmise runcalls and instrumented tools appear in the same trace. Nothing is exported unlessotel.enabled = trueand an OTLP endpoint is set. Offline mode disables export, and each export times out after 3s by default. A separateotel.logs = truesetting exports task stdout (INFO) and stderr (WARN) as log records linked to their spans, with redactions applied first. Withotel.logson, tasks ininterleave/quietmodes no longer get a TTY; use--rawfor tasks that need one. #13557, #13558, #13559 (built on work by @MatthiasGrandl and @zeitlinger)Daemons (experimental)
Shared server providers. Declare long-lived PostgreSQL, CockroachDB, or NATS servers in global config under
[daemon_providers]and manage them withmise daemons providers ls|start|stop|restart. Providers have their own tools, ports, and persistent data. They run in an isolated environment and are not tied to any checkout. #13534Per-checkout databases and accounts on a shared server. A project daemon with
provider = "..."gets its own database (PostgreSQL/CockroachDB) or its own NATS account with separate subjects and JetStream data. Each checkout path gets a stable name, so worktrees share the server but not the data. Give several daemons the sameresourcename to share data on purpose. Connection env vars point at the right database, and NATS gets an authenticatedNATS_URL. #13536, #13537Lockfiles and backends
mise backends switch. When the registry moves a tool to a new backend (as happened with hk and communique moving topackslip:), a tool locked to the old backend now stays there.mise installandmise lockprint a warning that points to the new command, which moves lock entries to the registry's backend at the same versions, relocks their platforms, and reinstalls. It supports--dry-run,--global, andTOOL@VERSION. If any relock fails, every lockfile it changed is restored. #13543Tool stubs lock into the project's
mise.lock.mise generate tool-stub --locknow records the stub in the nearest project lockfile (listed undertool-stubs), so installs verify the recorded checksums and--locked/MISE_LOCKED=1accept stubs. Previously the[lock]section written into the stub was never used, so checksums were never checked. #13502Install from a local archive. The
http:backend acceptsfile://URLs. It copies the archive instead of downloading it, still verifieschecksum, and works offline. #13574Checksum mismatch hints for re-uploaded GitHub assets. When a
github:oraqua:install fails a checksum check, mise asks GitHub for the asset's current digest. If that digest matches the download, the error says the maintainer probably re-uploaded the asset. The install still fails. #13512vfox
BackendUninstallhook. Backend plugins can definehooks/backend_uninstall.luato clean up outside the install directory. It runs before removal on uninstall, upgrade, and prune. If the hook errors, the install directory is kept. #13522CLI
mise searchchecks package registries. Add a prefix to search npm, crates.io, RubyGems, or NuGet (mise search npm:typescript-language,cargo:,gem:,dotnet:).--allsearches every source at once. Plain searches and shell completion still make no registry requests, andMISE_OFFLINE=1skips them. #13550mise lsby backend.-b/--backend(repeatable) filters by backend and also works with--json.--groupedprints one section per backend. #13530mise config get/set. Tab completes dotted keys, with descriptions, from the schema and from the target file.--file,--global, and--systemare respected. #13551mise --helpis now coloured on terminals (and respectsNO_COLOR), wraps at the terminal's real width, and shows the mise logo onmise/mise --helpwhen there's room. #13449url, which appears inmise tool(andmise tool <name> --url) and inmise registry --json. #13533Configuration and hooks
.miserc.local.toml. Sets per-checkout early config, such asenv = ["native"], without editing the shared.miserc.toml. At each directory level it is read before.miserc.toml. CLI flags andMISE_ENVstill take precedence. #13440backendandinstall_pathinMISE_INSTALLED_TOOLS. Postinstall hooks can now see where each tool came from and exactly where it was installed. #13421 (@garysassano)Dotfiles
Choose what a tracked directory saves.
excludeandincludelists onmode = "track"entries. Exclusions always win.include = []selects nothing. Narrowing a list does not delete the files on other machines. #13418, #13432Preview before tracking.
mise dot track --dry-runandmise dot paths --previewshow file counts, sizes, exclusions, and skipped nested repositories. Large trees get a warning. #13417mode = "absent"removes a file or symlink at the target, with support for OSvariants. Directories and special files are refused, even with--force. #13513permissionskey. Overrides the mode of copy, template, and content entries, or manages only the permissions of an existing file such as~/.ssh/config. Status, diff, and apply report and fix drift. The key is ignored on Windows. #13514remove_empty = trueon templates removes the target when the template renders empty. A file you have edited since mise last wrote it is kept unless you pass--force. #13515Empty parent directories mise created are removed along with their target on apply and unapply. This only applies inside
$HOMEand never to directories that already existed. #13518Warnings from background captures, such as credential-named files saved in plaintext, are now shown by the next
mise dotcommand ormise bootstrap. Previously they only went to the watcher logs. #13483Bootstrap
mise bootstrap unapply <ENV>...removes the files, directories, user services, and dotfile entries a module added after you deselect it. Anything another environment still declares is kept. Supports--dry-runand--force. #13441[bootstrap.files]entries. Declare onlymode/owner/groupto manage a file's metadata without taking over its contents. #13511remove_empty = trueon templated[bootstrap.files]removes the target when the template renders empty. #13510before,binds_to,part_of,conflicts,exec_start_pre,exec_start_post, andexec_stop_post.~now expands after exec prefixes such as-~/bin/check. #13526Registry
mole(#13363, @casparbreloh),reviewdog(#13562, @takumin), andnim(#13461, @elijahr).aubenow points ataubepkg/aube(#13541).Fixed
Tools, installs, and lockfiles
mise cache prunecould delete files from installed tools: it followed symlinks out of the cache into install directories and left npm cache entries half-empty. It now never follows symlinks and removes stale entries as a whole.cache_prune_age = "0s"now also turns offmise cache prune. #13424mise lock --bumpnow checks remote versions for every selector (for example"6", not onlylatest) and fails when the version list can't be fetched, where it used to exit 0 with stale versions. Packslip registry tools no longer callapi.github.comin normal use, which avoids rate-limit errors. #13544mise lockrefuses to record an aqua version that only resolved to its own request string because the version list failed to load. When such an install fails, the error now says why. #13552mise lock --globalno longer skips global tools that the project config shadows, and no longer overwrites a global pin with the project's version. #13547mise lockno longer tries to lock3.9.6~aube~<digest>-style install directory names for npm and pipx tools. #13542mise upgrade --bump tool@selectornow saves the selector to the config, asmise usedoes. #13179 (@zeitlinger)npm_execpath(such asre2) now run through aube, not mise's task runner. #13484[wrappers.cargo] command = "mbx"now install the missing provider tool before running it. #13532*_tokens.tomlare trimmed. #13488.tar.zstarchives compressed with a long window now extract. #13566.mise-binsfor registry files listed by name only (#13525), and reports only the provenance and signature checks mise actually performs (#13549).binkeeps the.exeextension. #13529brew-caskpercent-decodes artifact filenames taken from cask URLs. #13431mise self-updatefails before downloading when it can't write to the install directory. #13453Tasks
[tasks.hello]block no longer creates an empty task that hidesmise-tasks/hello.sh. It now configures the script, and dependency groups keep theirdependswhen another config layer adds metadata. #13448rununder a file task's name now replaces the script. #13458 (see Breaking Changes)Shell, CLI, and platforms
misefunction now embeds the path to the mise binary, so it keeps working in shells that copied the function but not$__MISE_EXE(for example Claude Code's Bash tool on Windows). #13491cargo install misefor Windows targets works again. #13573Dotfiles, history, and bootstrap
environmentno longer run throughcmd.exebehind a console window that killed the service when closed, and shell metacharacters in the environment are no longer rejected. The history watcher also runs without a console window. #13429, #13428mise bootstrapnow runs[history.reload]commands after its dotfiles phase writes matching files, asmise dot applydoes. #13509Security
[bootstrap.files]and[bootstrap.directories]changes run as root, mise no longer follows a symlink in the path that another user could have planted (CWE-59). Status and dry-run show these paths asunknown, and apply refuses them. Symlinks inside root-owned directories that no one else can write, such as/etcon macOS, still work. #13539, #13546Breaking Changes
pkgx:backend is removed. Entries like"pkgx:stedolan.github.io/jq"no longer resolve; switch to the registry shorthand (jq) oraqua:/github:. Lockfiles with pkgx sections still load, and those sections are dropped the next time mise writes the file. Thepkgxregistry entry for the pkgx CLI itself is unchanged. #13555mise.lockrecords a different one. Runmise backends switchto move it. #13543[tasks."hello.sh"] run = ...used to be ignored and now runs.[tasks.hello] run = ...no longer leaveshello.shavailable as a separate task. To keep both, give the inline command its own name. #13458mise generate tool-stub --lockneeds a project config above the stub. It writes to that project'smise.lockand no longer pins the stub'sversion. Any old[lock]section is ignored and removed. Older mise releases droptool-stubsfrommise.lock. #13502include/excludeneed current mise on every machine. Upgrade every machine that shares the dotfiles setup before usingincludelists. New checkpoints use schema version 2, which older clients can't roll back. #13432[bootstrap.directories]removals always run as root, so a path that crosses a symlink in a user-writable directory is now refused, even under$HOME. Declare the resolved path instead. #13546New Contributors
Full Changelog: jdx/mise@v2026.9.12...v2026.9.13
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.