Skip to content

chore(deps): update dependency jdx/mise to v2026 - #220

Open
renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x
Open

renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x

Conversation

@renovate

@renovate renovate Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update New value References Sourcegraph
jdx/mise uses-with major 2026.10.7 source code search for "jdx/mise"

Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.


Release Notes

jdx/mise (jdx/mise)

v2026.10.7: : Background tool updates at the shell prompt, a verified download cache, and mise upgrade --global

Compare Source

Tools with auto_update now update in the background from an activated shell, and a new tool_update.global_auto setting turns this on for every global tool. mise also keeps finished downloads in a content-addressed cache and checks them again before reusing them. This release also fixes .env parsing regressions from 2026.10.3 and a crash in mise run.

Added

  • Automatic updates at the shell prompt. Before, auto_update only ran when a shim or mise exec launched a tool. With mise activate, tools run straight from PATH, so they were never updated. Now, when a check is due, mise hook-env starts the update in a detached background process. The prompt doesn't wait and nothing is printed. The next command after the update finishes uses the new version. The existing rules still apply: only global config counts, exact versions don't move, nothing updates offline, in CI or with locked, and minimum_release_age is honored. While the tool-update service is running, prompts leave updates to it. Failed background updates show up in mise doctor. #​14239

  • tool_update.global_auto turns on automatic updates for every tool in global config at once. It takes the same values as auto_update: true checks every tool_update.check_duration (24h by default), and a duration sets the interval. A tool's own auto_update takes precedence, so auto_update = false opts a tool out. Projects can't enable this setting. You can also set it with MISE_TOOL_UPDATE_GLOBAL_AUTO. self_update.auto now accepts an interval too, for example self_update.auto = "1d". #​14237

    # ~/.config/mise/config.toml
    [settings]
    tool_update.global_auto = "12h"
    
    [tools]
    claude = "latest"                                   # checked every 12h
    node = { version = "24", auto_update = "6h" }       # its own interval wins
    python = { version = "3.13", auto_update = false }  # opted out
  • mise upgrade --global and mise outdated --global act only on the tool requests in global and system config, even inside a project that pins its own version or when MISE_<TOOL>_VERSION is set. The project's mise.toml, lockfile and [env] are not read or changed. --bump writes to the global config. --global can't be combined with --local or --inactive. A new "Self-updating tools" docs page explains how tools that update themselves, such as coding agents, can detect a mise install and update through mise instead of overwriting their own install. #​14243

    mise outdated --global claude --json
    mise upgrade --global claude
  • Verified download cache. Finished downloads are stored once in $MISE_CACHE_DIR/downloads-cas and hashed again before every reuse. A cached file that no longer matches is dropped and downloaded again. #​14222, #​14242

    • When the server sent an ETag or Last-Modified header, the next request for the same URL is conditional. On 304 Not Modified, mise reuses the cached file without downloading it again. This applies to every download through mise's HTTP client.
    • For tools with a pinned checksum (from tool options, mise.lock or a packslip digest), http, github, aqua, packslip and the precompiled core tools (Node, Go, Bun, Deno, Zig, Java, Python, Ruby, Erlang, Elixir, Swift) reuse the cached file without any network request. The file is hard-linked into place, so it doesn't use extra disk space.
    • With --locked or paranoid, mise only uses the cache for downloads with a pinned checksum. This means a CI cache you restore can save downloads but can't change what gets installed. The CI guide now shows how to cache ~/.cache/mise/downloads-cas instead of installed tools.
    • download_cache_max_size sets the size limit (default 2GiB, 0 for no limit). When the cache is full, the least recently used files are removed. download_cache = false (MISE_DOWNLOAD_CACHE=0) turns the cache off.
  • npm: packages that install no executables now trigger a warning. For example, mise use npm:lodash used to succeed silently even though it created no shims. The install still succeeds. #​14246

Fixed

  • .env parsing regressions from 2026.10.3, affecting [env] _.file and the env_file setting:
    • Backslashes in single-quoted values are literal again, so Windows paths like '\\fileserver\share' and 'C:\temp\' load correctly. To embed a single quote, use double quotes. #​14228
    • Quoted and unquoted parts placed next to each other are joined again, as in shell. For example, A='it'\''s' gives it's and B=a'b c'd gives ab cd. These lines used to cause syntax errors that dropped the rest of the file. Quotes inside an unquoted value are now removed, so JSON that needs to keep its quotes must be single-quoted (CONFIG='{"debug": true}'). A quote with no matching closing quote on the same line stays literal, so NAME=O'Brien reads as written. #​14231
  • mise run no longer crashes now and then with called Option::unwrap() on a None value when it reads the tool list while it's being reloaded after an install. #​14240
  • On Windows with core.autocrlf=true, mise bootstrap repos status no longer reports freshly cloned repos as dirty. #​14225
  • On Windows, mise dot apply can now repoint a mode = "symlink" dotfile whose target is a directory junction after its source changes. It used to fail with os error 5. #​14226
  • history.describe_command now works for files tracked through a variant (such as home@work/...), including files added or removed inside variant directories. Encrypted files are still left out of the diff. #​14194 (@​oppegard)
  • mise doctor now shows the dotfiles: section, including the history repo: and origin:, when history.enabled = false. mise doctor --json adds dotfiles.history_enabled and dotfiles.tracking_error. #​14244
  • mise lock now applies aqua registry version prefixes (such as Codex's rust- prefix) before it chooses version overrides. Before, platform entries like windows-x64 were skipped. When several prefix families match, mise now warns and skips the entry instead of picking one arbitrarily. #​14218 (@​nettlesh)
  • The rustup profile aliases m, d, c and the empty value are now treated like minimal, default and complete. With profile = "d", mise install now restores missing components like clippy and rustfmt. Unknown profile names now fail with rustup's list of valid names. #​14220 (@​JamBalaya56562)
  • The cargo backend now takes the same rust-state lock as the rust plugin when CARGO_HOME/RUSTUP_HOME are set through the rust.cargo_home/rust.rustup_home settings or MISE_CARGO_HOME/MISE_RUSTUP_HOME in [env]. Before, parallel source-build installs could race and fail. #​14219 (@​wislertt)
  • The hint to enable self_update.auto now appears on every mise version and mise self-update run, not just the first time. It stops once you enable auto-update or run mise settings add disable_hints auto_update. #​14233
  • The JSON schema now matches what mise accepts, so editors and linters like tombi and Taplo report the right errors (@​JamBalaya56562):
    • Task arrays can contain { task = ... } and { tasks = [...] } entries. #​14229
    • depends, depends_post and wait_for accept a single table, and empty nested lists like depends = [[]] are rejected. #​14236
    • [env] entries that combine value with required = true or a help string, and { required = false } with no value, are rejected. #​14247

Deprecated

  • always_keep_download is deprecated because downloads are now kept in the download cache. It will warn starting in 2026.11.0 and will be removed in 2027.11.0. #​14222

Documentation

  • The automatic tool updates docs now explain that minimum_release_age (24h by default) plus the check interval can delay an update by 24 to 48 hours after a release. You can set minimum_release_age per tool. Docs and hints now use the shorter mise settings KEY=VALUE form. #​14235

New Contributors

Full Changelog: jdx/mise@v2026.10.6...v2026.10.7

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.6: : Per-machine [vars] prompts, local config includes, and working-tree changes in --affected

Compare Source

[vars] entries can now ask once per machine and remember the answer, include accepts local files, and mise run --affected now counts uncommitted work and no longer needs experimental = true. On a fresh machine, mise bootstrap can install git and ssh before it clones. The release also fixes several dotfiles history issues and stops lazy tools from triggering remote version lookups when something else launches.

Added

  • Per-machine [vars] prompts. Give a var a prompt, plus either a default or required. mise asks for it once and saves the answer in $MISE_STATE_DIR/vars.toml, outside your config and dotfiles history. Templates, tasks and tools then read it as usual. One shared dotfiles setup can use this to set a different Git identity on each machine. #​14190

    [vars.git_name]
    default = "Ada Lovelace"
    prompt = "Git author name"
    
    [vars.git_email]
    required = "Run mise vars prompt to set git_email"
    prompt = "Git email"
    mise vars                       # list every var and where its value comes from
    mise vars prompt                # ask for every unanswered prompt var (or name some)
    mise vars git_name=Ada          # save a value without a prompt
    mise vars unset git_name        # forget a saved value
    mise bootstrap --prompt-vars    # prompt during a bootstrap run, e.g. with --adopt

    Only mise vars prompt and mise bootstrap --prompt-vars ever ask. Everything else uses the saved answer, then the default. Precedence, highest first: the process environment, a value from a higher-precedence config file, the saved answer, the default. Answers are keyed by var name, so projects that use the same name share one answer on a machine. prompt is not allowed in [env].

  • Local paths in include. include in mise.toml now accepts local TOML files, not just git:: and oci:: references. A path can be relative to the including file or absolute. Local files merge the same way as remote ones, ranking just below the including file. They are read on every load, so edits apply immediately and invalidate the cached env. Paranoid mode rejects local includes, and safe mode still skips all includes in project config. #​14178

    include = ["./config/tools.toml", "/etc/mise/team.toml"]
  • mise bootstrap installs git and ssh before cloning. mise bootstrap --from and --adopt used to fail with a spawn error when git was missing. Now mise checks for git, and for ssh when the URL is ssh:// or user@host:path, and offers to install whatever is missing with the host package manager. Supported managers are apt, dnf, pacman, apk, zypper, Homebrew, scoop and winget. --yes accepts the offer without asking, and --dry-run only reports what is missing. #​14188

  • mise dot save --re-encrypt. After you change [history.encryption] recipients, a normal save leaves some encrypted files under their old keys: manual-save entries the save doesn't name, and other-platform variants. Add --re-encrypt to re-encrypt every saved file in the new checkpoint to the current recipients. It never captures unsaved edits. If this machine can't unlock some of the files, nothing is saved and the error lists all of them. #​14210

  • mise dot status shows unsaved changes. It now lists tracked paths that changed since the latest checkpoint. Unsaved edits were previously invisible there when the watcher was stopped or an entry used --no-autosave. --json reports these paths as history.unsaved. The value is null when they can't be determined, for example with no checkpoint yet or with encrypted files this machine can't compare without prompting. #​14209

Changed

  • mise run --affected now counts working-tree changes, and the workspace graph is no longer experimental. Besides the committed base...head range, --affected now also counts staged and unstaged edits and untracked files that aren't ignored. You can narrow it with --affected-committed, --affected-uncommitted and --affected-untracked, which can be combined (environment variables: MISE_AFFECTED_*). Working-tree changes only count when the head is your current checkout. To get the old committed-only selection, for example in a CI job that writes untracked files before it runs, use --affected-committed. --affected, mise tasks graph, [monorepo.task_defaults], [monorepo.projects] and task.auto_infer no longer require experimental = true. #​14214

    mise run --affected build                                         # committed + uncommitted + untracked
    mise run --affected --affected-uncommitted --affected-untracked build  # only what you haven't committed yet
    mise run --affected --affected-committed build                    # committed range only, as before
  • Credential checks for dotfiles. Files with names ending in .example, .sample or .template no longer match the credential name rules. The content scan before publishing still checks them. Once you approve a file for plaintext tracking, mise no longer warns about it on every save. #​14204

  • mise dot track only asks about plaintext at a terminal. Before saving a credential-named file in plaintext, it now asks only when both stdin and stderr are terminals. Previously, a piped line, such as the next entry in a while read loop, could be taken as the answer. Scripts need --allow-plaintext or --encrypt. #​14205

Fixed

  • Lazy tools no longer trigger remote lookups for other lazy tools. Previously, mise looked up versions for configured lazy tools that weren't installed, even though they weren't being launched. With a cold cache and no network, launching one tool waited on each lookup and could print "Failed to resolve tool version list" warnings. In one offline test a launch took 41 seconds. This no longer happens in these cases:

    • the update that runs before an auto_update tool launches (#​14195)
    • after mise x or a shim installs a new version (#​14197)
    • the first launch of a lazy tool through its shim (#​14201)

    mise install, mise upgrade and mise use still resolve everything.

  • Too many open files with parallel npm: installs. Parallel installs could fail under macOS's default launchd soft limit of 256, for example when mise was started from a LaunchAgent. On Unix, mise now raises its soft open-file limit at startup toward the hard limit, up to 10240, and never lowers it. #​14174, #​14216

  • go: tools with an untidy go.mod. Tools whose published go.mod is missing a requirement now install, for example go:tailscale.com/cmd/tailscale. mise now passes -mod=mod to go install instead of -mod=readonly. A project's GOFLAGS=-mod=vendor still doesn't affect these installs. #​14180 (@​JamBalaya56562)

  • Config at the filesystem root. A config file at /, such as /mise.toml in a Docker image, made mise install and mise exec panic. It now works. #​14182

  • .NET installs. Installing a .NET SDK no longer fails with "was not found in dotnet --list-sdks output" when another mise-managed SDK comes before the shims on PATH. The post-install check now runs the new SDK's dotnet directly. #​14189

  • Shims and directories. Shims and mise which no longer resolve a bin name to a directory in another tool's bin path. Previously, hunk's skills/ directory blocked npm:skills with "Permission denied". #​14193

  • mise oci build and multiple versions. A tool pinned to several versions is now written to the embedded /etc/mise/config.toml as a single array, in resolution order. Previously each version got its own duplicate key, which made the config unreadable inside the container. #​14200 (@​JamBalaya56562)

  • Encrypted files a sync can't unlock. mise bootstrap --adopt, mise dot pull and mise dot sync now list every encrypted file they can't unlock in one error, instead of stopping at the first one. Damaged files still stop the sync immediately. #​14208

  • Rollback and undo messages. mise dot rollback <path> now names the checkpoint that saved the restored version, which matches mise dot history --path. Rollback and undo also name both checkpoints they record: the result, and the one holding the state before the operation. Previously, rollback could name a checkpoint that history --path didn't list. What gets restored is unchanged. #​14207, #​14211

  • mise dot status on adopted machines. On a machine that adopted a shared setup, it no longer prints "nothing configured in [dotfiles]" while history tracks entries. #​14206

New Contributors

Full Changelog: jdx/mise@v2026.10.5...v2026.10.6

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.5: : Java defaults to Temurin, per-machine and local-only dotfile history, packslip workflow pinning

Compare Source

Java versions without a vendor prefix now install Eclipse Temurin builds. Dotfiles gain per-machine and local-only history, a merge = "missing" mode, and a secret check before mise dot sync publishes anything. Packslip tools can be pinned to the workflow that signs their releases. Several features documented as experimental now actually require experimental = true. The rest of the release is fixes across tasks, shims, config loading, bootstrap and backends.

Breaking Changes

  • java@21, java@lts and java@latest now install Temurin. The default of java.shorthand_vendor changes from openjdk to temurin. The jdk.java.net OpenJDK builds stop at the next feature release, so java@21 was stuck on 21.0.2 from January 2024. Vendor-prefixed requests (openjdk-21, corretto-21, ...) are not affected. Installed OpenJDK versions keep working, and mise upgrade offers the Temurin build. Shorthand versions now include Temurin's build suffix (for example 21.0.12+101.0.LTS). Temurin has no builds of Java 9, 10 or 12–15, so use openjdk-12 and similar for those. #​14146
    • Lockfiles: existing shorthand lock entries record shorthand_vendor = "openjdk". Without that setting, mise install --locked fails with java@21 is not in the lockfile. Either keep OpenJDK:
      [settings]
      java.shorthand_vendor = "openjdk"
      # or per project: java = "openjdk-21"
      or switch to Temurin with mise lock --bump java and commit the result.
  • Some experimental features now require experimental = true (or MISE_EXPERIMENTAL=1) when you use them. Config that only mentions them still loads. #​14114
    • Running a task with a git:: remote file, including through mise run --dry-run, mise watch, or as a dependency. Commands that only inspect tasks (tasks ls, tasks info, tasks deps, generate task-docs) show the task from its TOML and warn once that the file wasn't fetched. These were documented as experimental but were missing the check in the codebase.
    • git:: and oci:: entries in task_config.includes. These are skipped with a warning.
    • OpenTelemetry export of mise run when an OTLP endpoint is set.
    • Installing spinel: tools.
  • mise.local.toml now overrides mise.<env>.toml in the same directory, as the docs already said. Before, the committed environment file won in project directories, and also in ~/.config/mise when the walk up from the cwd reached it. Within each directory the order is now, highest first: mise.<env>.local.toml, mise.local.toml, mise.<env>.toml, mise.toml. If you relied on the environment file winning, move those keys into mise.<env>.local.toml. #​14148
  • MCP: in the mise://tasks resource, env is now an array of env directive strings, the same format as mise tasks ls --json. It was always an empty object before. #​14111
  • mise settings set and add refuse writes that would have no effect. This covers early-init settings (env, ceiling_paths, env_conf_d, ...) written to a config file, and global-only settings (yes, paranoid, trusted_config_paths, ...) written with --local. The error says where the setting has to go: miserc.toml, the global config, or the MISE_* variable. #​14126

Added

Dotfiles
  • Per-machine tracked files. Some files describe the machine, such as a monitor layout. Use variants = [{ machine = true }] or mise dot track --machine to keep a separate history for each machine. Sync pushes every machine's version to the origin but never applies one machine's version on another. Each machine gets a generated name, which you can set with [history] machine = "desk". A machine variant must be the entry's only variant and can't be combined with encrypt. Upgrade every machine that shares a setup before using it. #​14062
    [dotfiles]
    "~/.config/hypr/monitors.lua" = { mode = "track", variants = [{ machine = true }] }
  • mode = "track-local" (or mise dot track --local) keeps a file's history in a separate store on this machine, with no origin. The file never reaches the shared manifest, a commit or a push. Commands that name a path use the history that holds it. Use mise dot --local history or mise dot --local undo to work with the local history directly. save, capture and watch cover both histories. #​14082
  • merge = "missing" sets only the keys the target file doesn't have yet. Values an app writes itself, such as the model picked with /model in Codex or Claude Code, are left alone. Works with TOML, YAML and JSON. #​14081
    [dotfiles]
    "~/.codex/config.toml/shared" = { merge = true }
    "~/.codex/config.toml/defaults" = { source = "codex/defaults.toml", merge = "missing" }
  • Merge entries can leave out source. mise then reads the target's path under dotfiles.root. Switching an entry from symlink to merge now replaces a link that points at the merge source with a writable copy, so the app's own keys survive. #​14076
  • mise dot sync refuses to publish saved versions that look like secrets. It checks for provider tokens, private key blocks, and *_KEY/*_TOKEN/*_SECRET/*_PASSWORD assignments. Only versions the origin doesn't have yet are checked. The error names the file, line and version, never the value. --allow-plaintext-history skips the check. #​14171
  • mise bootstrap --adopt <url> --take-remote-all takes the repository's version of every file that differs, in one step. Combined with --replace-history, it also adopts the repository on a machine that already has history of its own. #​14065
  • mise doctor shows the dotfiles history repo path and the connected origin (URL, branch, sync mode), in both text and --json output. #​14173
Bootstrap
  • [bootstrap.files] and [bootstrap.directories] accept the same os selector as packages. Entries that don't match the host are skipped completely. #​14058
    [bootstrap.files."/etc/docker/daemon.json"]
    os = "linux"
    source = "./files/docker-daemon.json"
  • fish = "auto" in [bootstrap.mise_shell_activate] writes a block that runs mise activate fish in interactive shells and --shims everywhere else. #​14172
  • [bootstrap] is now allowed in config includes. It merges below the including file, so a shared baseline can declare packages, hooks and services, and the project still wins on any key it sets itself. #​14176
  • Systemd units accept state = "absent", which stops, disables and deletes the matching mise-managed service and timer. mise bootstrap unapply now also removes the units an environment added. #​14139
Tools and backends
  • Packslip workflow option. It accepts only releases signed by the named GitHub Actions workflow on tags. It takes one workflow or a list, and an entry can name a ref (release.yml@refs/heads/main). It can't be combined with pubkey, identity, identity_prefix or issuer. #​14075, #​14093
    [tools]
    "packslip:github.com/aubepkg/aube" = { version = "latest", workflow = ["release-plz.yml", "release.yml"] }
    • Registry entries for dagu, timoni, helmfile, fnox, hk, usage, communique, mr-boxington, pitchfork, aube and worktrunk are now pinned to the workflow that signs their releases. A workflow or pubkey you set yourself replaces the registry pin. #​14092, #​14091, #​14073 (@​max-sixty)
  • MCP install_tool is implemented. It installs the requested version, or the configured version, or latest, and returns the resolved version and install path. install_tool and run_task now refuse to act on untrusted config instead of trusting it on the client's behalf. #​14111
  • mise installs migrate no longer fails on installs it can't reinstall, such as withdrawn releases, signer changes or no network. It moves them into the identity layout as they are and leaves a link at the old path. It also handles lockfile-suffixed ~aube~/~uv~ directories correctly. #​14079
  • Registry: mprocs is renamed to dekit to match upstream, and mprocs stays as an alias. From v0.10.0 the binary is dekit. #​14169

Changed

  • Dotfile operations you can undo no longer ask for confirmation after showing their plan. This covers dot pull, dot track, undo, rollback, connect and bootstrap --adopt. Destructive ones still ask, such as --replace-history, dot recover --keep-current and implode. --yes and MISE_YES are still accepted. #​14077, #​14071, #​14067
  • Safe mode (MISE_SAFE=1) now ignores a project's [bootstrap], [dotfiles] and [dotfile_groups]. Before, an untrusted repo could link files into $HOME or clone repositories. Global and system config still apply. #​14110
  • Node downloads are checked against the GPG signature for every version that publishes one. Before, only versions starting with 2 were checked. Set node.gpg_verify = false for mirrors without signatures. #​14132
  • mise generate github-action now uses actions/checkout@v7 and jdx/mise-action@v5 and no longer sets MISE_EXPERIMENTAL. mise generate devcontainer now adds "postCreateCommand": "mise install". #​14145

Deprecated

  • task.cache.stats_report, sops.age_recipients and plugin_autoupdate_last_check_duration never had any effect. Setting one now prints a warning, and they will be removed in 2027.10.5. #​14112
  • mise bootstrap launchd|systemd|macos-defaults, the old --only/--skip part names (launchd, systemd, defaults, shell) and mise direnv now print a warning that names the replacement. They will be removed in 2027.10.4. #​14113

Fixed

Tasks
  • A raw or interactive task with cache enabled is now skipped when its sources are fresh and its cache key hasn't changed. Before, it ran every time. #​14121
  • A typo in sources that matches no files now prints a warning. mise tasks deps <task> now shows depends_post tasks. Scripts in $MISE_CONFIG_DIR/tasks load even without a global config file. #​14122
  • mise run ./script resolves relative to the current directory. #​14120
  • Script extensions are stripped only from file task names. #​14159
  • Requests to the remote task cache include the mbx-cache headers. #​14147
  • mise generate task-stubs skips hidden and global tasks. #​14127
Shims and exec
  • Shims, mise x and mise env no longer look up remote versions for lazy tools that aren't installed. With 20 lazy tools and no network, running an installed tool went from about 42s to 0.09s. #​14063
  • On Unix, a system wrapper that execs the same command name can no longer send an unconfigured shim into an endless loop. #​14088
  • Windows lazy shim names now match regardless of letter case. #​14090
  • mise x tool@1.2.3 installs the exact version when the version list times out, instead of failing with "couldn't exec process". #​14164
  • mise doctor recognizes a mise entry in the dedicated shims dir. #​14069
Config, settings and CLI
  • With an environment active and no config.toml yet, mise use -g creates config.toml instead of writing into config.<env>.toml. #​14179
  • Booleans set through mise config set --type bool and boolean settings accept yes/no/1/0. For env.* and other keys that aren't settings, only true and false become booleans, and anything else is stored as written. mise latest tool@prefix:X works, and --log-level warn is accepted. mise doctor prints the full chain when config fails to load. #​14125
  • Help output uses the command name you typed. #​14123
  • mise edit no longer overwrites an existing config when there is no terminal. #​14124
  • .monorepo markers are verified in paranoid mode. #​14105
  • Bad input now gives an error instead of a panic, in places including mise config ls and mise prune with an invalid tool version, the --monorepo flags, and mise plugins uninstall --purge. #​14118, #​14094 (@​JamBalaya56562), #​14103 (@​JamBalaya56562), #​14116, #​14117
  • mise env --redacted honors redact = false exclusions. watch_files hooks don't run in safe mode or with --no-hooks. #​14109, #​14108
  • mise watch passes watchexec flags through to watchexec. #​14115
  • Error and warning hints point at current commands, for example the PATH advice from bootstrap remote and the watchexec install hint. #​14142
  • If stderr can't be written to during a migration, mise no longer aborts. #​14158 (@​JamBalaya56562)
  • When the default cache and temp directories overlap (the Windows default), temp files now go to <temp>/mise-tmp, so mise cache clear no longer deletes files that are still in use. #​14134
Bootstrap and dotfiles
  • mise bootstrap keeps writing the shell activation block into a startup file that is only tracked. #​14135
  • If one package manager fails, the others still run. #​14138
  • The firewall section is skipped on systems that don't support it. #​14137
  • Dry runs show hooks that use exec(). #​14136
  • Pulling onto a machine with no history now saves the files it replaces first, so mise dot undo restores them. --replace-history no longer fails on its first attempt. #​14065
  • mise dot pull says so when incoming history changes no files on this machine. #​14066
Backends and plugins
  • mise install cargo:... no longer uses an inactive cargo-binstall shim. It falls back to native binstall or cargo install. #​14070
  • With npm.shell_out, a mise shim from another data dir can no longer be run as npm and fork until the machine runs out of memory. #​14084 (originally found and fixed by @​tfournet)
  • Java: changing java.shorthand_vendor takes effect without waiting for the cache to expire. Inline java[release_type=ea] is respected when listing and resolving versions. #​14131
  • Ruby precompiled URLs expand {os} and {arch} correctly. #​14133
  • ls-remote respects disable_backends. #​14130
  • SPM uses a custom api_url for cloning and skips lockfile URLs. #​14129
  • GitHub assets are size-checked even when there is no checksum. GitLab release lookups percent-encode the tag. #​14128, #​14102 (@​thespags)
  • Brew infers the formula version from the GitHub release tag path, and detaches a DMG left attached by an interrupted install. #​14165 (@​JamBalaya56562), #​14177
  • git:: plugins install from a subdirectory, and [plugins] entries compare those sources correctly. Packslip entries in [plugins] install as vfox plugins. #​14140, #​14150 (@​onokonem), #​14141
  • vfox: an env plugin with no source no longer makes every command fail. Embedded plugin files are found relative to the manifest directory. #​14119, #​14167
Daemons and sandbox
  • On Windows, deferred daemon commands are quoted for cmd.exe. Argv and Windows readiness probes run in the tool environment. #​14055, #​14080 (@​JamBalaya56562)
  • --deny-env clears inherited variables on Windows. On macOS, allow_net is rejected instead of writing invalid sandbox rules. #​14107, #​14106

Security

  • Remote task cache keys store env, [vars] and task arg values as blake3: digests instead of plaintext, so secret values are no longer uploaded. Existing cache entries miss once after upgrading. #​14104
  • URL credentials are redacted from HTTP debug logs and from npm Git-source and SSH diagnostics. #​14155, #​14057, #​14064

Documentation

New Contributors

Full Changelog: jdx/mise@vfox-v2026.10.4...v2026.10.5

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.10.4: : Task-scoped fnox secrets, automatic global tool updates, and an opt-in identity install layout

Compare Source

This release adds experimental task-scoped secrets backed by fnox, automatic updates for global tools, and an experimental opt-in install layout that names installations by what they contain. It also adds dotfile merge entries, headers auth for the http: backend, npm installs from git, and a set of prune, install and lockfile fixes.

Added

Secrets (experimental)

These need mise settings experimental=true and fnox 1.39.0 or newer. They are refused in safe mode.

  • [secrets.fnox] and mise secrets ls. A project can name fnox as its secrets source in its own mise.toml. mise secrets ls lists key names and metadata but never values. -J prints JSON. Global, system and home-level [secrets] config is ignored, and mise doctor reports it. #​13967

  • Tasks get only the secrets they list. Add secrets = [...] to a task, or #MISE secrets=[...] in a file task header. Only that task gets the values, only while it runs, and they are redacted from its output. Dependencies, hooks, mise env, hook-env and shims get nothing. A task without grants never calls fnox. Tasks that list secrets need a trusted config, aren't artifact-cached, and ignore --raw unless the task sets raw or interactive. Hooks, watch_files, daemons and mise bootstrap can't run them, and remote or global-config tasks can't list secrets. #​13974

    min_version = "2026.10.4"   # older mise rejects `secrets` on a task
    
    [secrets.fnox]
    profile = "prod"
    
    [tasks.deploy]
    depends = ["build"]                       # build receives nothing
    secrets = ["DEPLOY_KEY", "DATABASE_URL"]
    run = "./deploy.sh"
  • One-off grants from the command line. --secrets KEY[,KEY] and --secrets-all work on mise run, mise tasks run and mise x. For mise run, only the tasks named on the command line get them, not their dependencies. mise x gets nothing unless you pass a flag, and it can't receive file secrets. Flags placed after the task name go to the task, and mise warns when that happens. #​13975

    mise run --secrets STRIPE_KEY deploy
    mise x --secrets GH_TOKEN -- gh release list
  • {{ secrets.X }} in task env values. A task can build an env var from a secret, for example env.PGURL = "postgres://app:{{ secrets.DB_PASSWORD }}@db/app". The reference counts as the grant. References are rejected in run, [env], [vars] and other fields. #​13978

  • fnox daemon cache. If the project's fnox config enables the daemon and it's running, an interactive run reads cached values over its socket without starting an fnox process. mise never starts the daemon itself. CI, non-TTY runs and Windows always use the fnox CLI. #​13979

Automatic global tool updates
  • auto_update for global tools. Set auto_update on a tool in your global config. When a shim or mise x is about to run that tool and its check interval is due, mise upgrades it within the configured range and then runs the new version. true uses the new tool_update.check_duration setting (default 24h), and a duration string sets that tool's own interval (minimum 1h). #​14026

    • Exact pins never update.
    • It never runs offline, in CI, with locked = true, from tasks or hook-env, or from project configs.
    • If an update fails, mise warns and runs the installed version. The failure shows in mise doctor.
    # ~/.config/mise/config.toml
    [tools]
    claude = { version = "latest", auto_update = true }
    node = { version = "22", auto_update = "6h" }   # newest 22.x, never 23
  • Background tool-update service. A built-in bootstrap service checks auto_update tools hourly, so launches don't wait for downloads and tools run directly from PATH under activation also stay current. It installs a systemd user unit, LaunchAgent or scheduled task. #​14040

    [bootstrap.services.mise-tool-update]
    builtin = "tool-update"
Identity install layout (experimental, opt-in)
  • install_layout = "identity". With experimental = true, each installation lives in installs/<label>-<hash>/. The hash covers the canonical backend, version, platform and install-affecting options. installs/<tool>/<version> becomes a link to that directory, a real junction on Windows. As a result: #​13951

    • age and aqua:FiloSottile/age share one installation.
    • Variants of one version with different options can exist side by side.
    • Windows IDEs can follow the version links.

    Existing installs keep working and aren't moved. Nothing changes unless you set this. MISE_INSTALL_LAYOUT=identity also turns it on. See the new install layout docs.

  • On Windows, identity-layout installations go into the shorter %LOCALAPPDATA%\mise\i\, while version links stay in installs\. MISE_INSTALL_STORE_DIR sets the location on any platform. #​13952

  • mise installs ls lists installations as selected, pinned or shared. mise installs select <dir> chooses which installation requests without a lockfile use. When several installations match and none is selected, mise lists them instead of guessing. #​13953

  • mise installs migrate [--dry-run] [TOOL[@VERSION]] reinstalls legacy installations into the new layout and leaves a link at the old path. If a run is interrupted, the next run recovers it. #​13955

  • In the layout, mise backends switch installs the new backend's version and points the link at it. mise where and the other commands now resolve versions named on the command line the same way, and mise where lists variants instead of picking one. #​13957

  • mise prune handles templated tool versions such as node = "{{ vars.node }}". It uses snapshots of what each project last rendered and keeps installs when it isn't sure they are unused. #​14025

Other additions
  • Dotfile merge entries. A merge = true entry sets only the keys from its source in a JSON, TOML or YAML file, and leaves keys added by the application (Codex, Claude Code, etc.) alone. TOML and YAML keep comments and formatting. mise dot status and mise dot diff only report drift in those keys. A target that doesn't parse is never overwritten. #​14012

    [dotfiles]
    "~/.codex/config.toml/shared" = { source = "codex/shared.toml", merge = true }
  • headers for the http: backend. You can now authenticate with bearer tokens or API keys, for example to download OCI blobs from ghcr.io. Values are templates. Headers are sent with downloads, version_list_url and checksum_url requests, and dropped on cross-host redirects unless the host is listed in headers_forward. Changing a token doesn't trigger a reinstall. #​14022

    [tools."http:polaris"]
    version = "0.9.2"
    headers = { Authorization = "Bearer {{ env.GITHUB_TOKEN | b64_encode }}" }
  • npm packages from git. git+ URLs and github:, gitlab: and bitbucket: specs now install. The version is a git ref, and latest is the default branch. #​14044

    mise use 'npm:github:owner/repo@v1.2.0'
  • settings.write_targets. Sends new global [tools], [bootstrap.packages] and [dotfiles] entries to separate conf.d files. Existing entries are updated where they're already declared. #​14018

    [settings.write_targets]
    tools = "~/.config/mise/conf.d/10-tools.toml"
    dotfiles = "~/.config/mise/conf.d/30-dotfiles.toml"
  • prune.exclude (or MISE_PRUNE_EXCLUDE) lists tools that mise prune, mise ls --prunable and upgrade pruning never remove. Short and full names both work, e.g. node or aqua:BurntSushi/ripgrep. #​14030

  • lockfile_auto_prune = false keeps lockfile entries for tools missing from the active config. This is useful when profiles share one lockfile. The default (true) keeps the current pruning behavior. #​13980

  • mise dot notify sends a test desktop notification, which also triggers the macOS permission prompt. mise doctor and mise dot status now show whether notifications can be delivered. #​14009

Changed

  • mise's own auto-update settings moved under self_update.*. auto_update is now self_update.auto (MISE_SELF_UPDATE_AUTO), and auto_update_check_duration is now self_update.check_duration (MISE_SELF_UPDATE_CHECK_DURATION). The old names keep working. The new key wins when both are set. Deprecation warnings start in 2027.4.0. Older mise versions ignore a settings file that has unknown self_update keys, so keep the old spelling if a config has to work with both. #​14038

  • mise prune, mise unuse --prune, mise ls --prunable and deferred pruning after an upgrade now keep any version a running process was started from, on Linux, macOS and Windows. They say which process kept it. #​14020

  • pypi:/pipx: tools installed with uv are now built on mise's Python when mise manages one. Previously uv could use its own downloaded interpreter, which broke CI caches that only restore the mise data dir. A package whose requires-python excludes mise's Python now fails; to override, pass --python in uvx_args. #​14024

  • With python.uv_venv_auto, mise install now creates the project venv with mise's Python instead of whatever uv found. #​13981 by @​halms

  • Inherited secrets: when a parent mise marks variables as secrets in __MISE_SECRET_KEYS, a nested mise now does the following #​13966:

    • redacts them from logs
    • hides them from templates, get_env() and exec()
    • disables the env cache
    • keeps them out of __MISE_DIFF, other tasks and pitchfork

    mise x and shims still pass them through.

Fixed

  • Install state
    • A failed tool-level postinstall hook no longer leaves its version listed as installed or selectable. The next install retries it. #​14037
    • Incomplete-install markers moved from the cache to $MISE_STATE_DIR, so mise cache clear no longer makes a half-installed version look installed. Existing markers are migrated. #​14051
  • Lockfiles and backends

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the bot label Jul 20, 2026
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from b069281 to 4210d96 Compare July 30, 2026 03:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 7255dd3 to 18a73a9 Compare August 5, 2026 03:26
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 2752ba1 to 661a5bf Compare August 12, 2026 20:16
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 6445a85 to c5325ef Compare August 20, 2026 23:10
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 9dd559c to fac6f2e Compare August 26, 2026 03:48
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 61548e9 to 844f10e Compare September 3, 2026 00:28
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from b504efd to 25c7628 Compare September 11, 2026 04:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from 5986910 to e80a868 Compare September 18, 2026 07:31
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 64f8ae1 to 980f1fd Compare September 27, 2026 11:53
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 7 times, most recently from 224319d to e51efa8 Compare October 5, 2026 11:58
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 6922c36 to bb271c6 Compare October 9, 2026 11:35
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch from bb271c6 to 5c67a95 Compare October 10, 2026 02:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants