Repository navigation
chore(deps): update dependency jdx/mise to v2026 - #220
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
6 times, most recently
from
July 30, 2026 03:03
b069281 to
4210d96
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 5, 2026 03:26
7255dd3 to
18a73a9
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
3 times, most recently
from
August 12, 2026 20:16
2752ba1 to
661a5bf
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 20, 2026 23:10
6445a85 to
c5325ef
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 26, 2026 03:48
9dd559c to
fac6f2e
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 3, 2026 00:28
61548e9 to
844f10e
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 11, 2026 04:03
b504efd to
25c7628
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
6 times, most recently
from
September 18, 2026 07:31
5986910 to
e80a868
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 27, 2026 11:53
64f8ae1 to
980f1fd
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
7 times, most recently
from
October 5, 2026 11:58
224319d to
e51efa8
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
3 times, most recently
from
October 9, 2026 11:35
6922c36 to
bb271c6
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
from
October 10, 2026 02:37
bb271c6 to
5c67a95
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.
Release Notes
jdx/mise (jdx/mise)
v2026.10.7: : Background tool updates at the shell prompt, a verified download cache, andmise upgrade --globalCompare Source
Tools with
auto_updatenow update in the background from an activated shell, and a newtool_update.global_autosetting turns this on for every global tool. mise also keeps finished downloads in a content-addressed cache and checks them again before reusing them. This release also fixes.envparsing regressions from 2026.10.3 and a crash inmise run.Added
Automatic updates at the shell prompt. Before,
auto_updateonly ran when a shim ormise execlaunched a tool. Withmise activate, tools run straight fromPATH, so they were never updated. Now, when a check is due,mise hook-envstarts the update in a detached background process. The prompt doesn't wait and nothing is printed. The next command after the update finishes uses the new version. The existing rules still apply: only global config counts, exact versions don't move, nothing updates offline, in CI or withlocked, andminimum_release_ageis honored. While thetool-updateservice is running, prompts leave updates to it. Failed background updates show up inmise doctor. #14239tool_update.global_autoturns on automatic updates for every tool in global config at once. It takes the same values asauto_update:truechecks everytool_update.check_duration(24h by default), and a duration sets the interval. A tool's ownauto_updatetakes precedence, soauto_update = falseopts a tool out. Projects can't enable this setting. You can also set it withMISE_TOOL_UPDATE_GLOBAL_AUTO.self_update.autonow accepts an interval too, for exampleself_update.auto = "1d". #14237mise upgrade --globalandmise outdated --globalact only on the tool requests in global and system config, even inside a project that pins its own version or whenMISE_<TOOL>_VERSIONis set. The project'smise.toml, lockfile and[env]are not read or changed.--bumpwrites to the global config.--globalcan't be combined with--localor--inactive. A new "Self-updating tools" docs page explains how tools that update themselves, such as coding agents, can detect a mise install and update through mise instead of overwriting their own install. #14243Verified download cache. Finished downloads are stored once in
$MISE_CACHE_DIR/downloads-casand hashed again before every reuse. A cached file that no longer matches is dropped and downloaded again. #14222, #14242ETagorLast-Modifiedheader, the next request for the same URL is conditional. On304 Not Modified, mise reuses the cached file without downloading it again. This applies to every download through mise's HTTP client.mise.lockor a packslip digest),http,github,aqua,packslipand the precompiled core tools (Node, Go, Bun, Deno, Zig, Java, Python, Ruby, Erlang, Elixir, Swift) reuse the cached file without any network request. The file is hard-linked into place, so it doesn't use extra disk space.--lockedorparanoid, mise only uses the cache for downloads with a pinned checksum. This means a CI cache you restore can save downloads but can't change what gets installed. The CI guide now shows how to cache~/.cache/mise/downloads-casinstead of installed tools.download_cache_max_sizesets the size limit (default2GiB,0for no limit). When the cache is full, the least recently used files are removed.download_cache = false(MISE_DOWNLOAD_CACHE=0) turns the cache off.npm:packages that install no executables now trigger a warning. For example,mise use npm:lodashused to succeed silently even though it created no shims. The install still succeeds. #14246Fixed
.envparsing regressions from 2026.10.3, affecting[env] _.fileand theenv_filesetting:'\\fileserver\share'and'C:\temp\'load correctly. To embed a single quote, use double quotes. #14228A='it'\''s'givesit'sandB=a'b c'dgivesab cd. These lines used to cause syntax errors that dropped the rest of the file. Quotes inside an unquoted value are now removed, so JSON that needs to keep its quotes must be single-quoted (CONFIG='{"debug": true}'). A quote with no matching closing quote on the same line stays literal, soNAME=O'Brienreads as written. #14231mise runno longer crashes now and then withcalled Option::unwrap() on a None valuewhen it reads the tool list while it's being reloaded after an install. #14240core.autocrlf=true,mise bootstrap repos statusno longer reports freshly cloned repos as dirty. #14225mise dot applycan now repoint amode = "symlink"dotfile whose target is a directory junction after itssourcechanges. It used to fail withos error 5. #14226history.describe_commandnow works for files tracked through a variant (such ashome@work/...), including files added or removed inside variant directories. Encrypted files are still left out of the diff. #14194 (@oppegard)mise doctornow shows thedotfiles:section, including the historyrepo:andorigin:, whenhistory.enabled = false.mise doctor --jsonaddsdotfiles.history_enabledanddotfiles.tracking_error. #14244mise locknow applies aqua registry version prefixes (such as Codex'srust-prefix) before it chooses version overrides. Before, platform entries likewindows-x64were skipped. When several prefix families match, mise now warns and skips the entry instead of picking one arbitrarily. #14218 (@nettlesh)m,d,cand the empty value are now treated likeminimal,defaultandcomplete. Withprofile = "d",mise installnow restores missing components like clippy and rustfmt. Unknown profile names now fail with rustup's list of valid names. #14220 (@JamBalaya56562)CARGO_HOME/RUSTUP_HOMEare set through therust.cargo_home/rust.rustup_homesettings orMISE_CARGO_HOME/MISE_RUSTUP_HOMEin[env]. Before, parallel source-build installs could race and fail. #14219 (@wislertt)self_update.autonow appears on everymise versionandmise self-updaterun, not just the first time. It stops once you enable auto-update or runmise settings add disable_hints auto_update. #14233{ task = ... }and{ tasks = [...] }entries. #14229depends,depends_postandwait_foraccept a single table, and empty nested lists likedepends = [[]]are rejected. #14236[env]entries that combinevaluewithrequired = trueor a help string, and{ required = false }with no value, are rejected. #14247Deprecated
always_keep_downloadis deprecated because downloads are now kept in the download cache. It will warn starting in 2026.11.0 and will be removed in 2027.11.0. #14222Documentation
minimum_release_age(24h by default) plus the check interval can delay an update by 24 to 48 hours after a release. You can setminimum_release_ageper tool. Docs and hints now use the shortermise settings KEY=VALUEform. #14235New Contributors
Full Changelog: jdx/mise@v2026.10.6...v2026.10.7
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.6: : Per-machine [vars] prompts, local config includes, and working-tree changes in --affectedCompare Source
[vars]entries can now ask once per machine and remember the answer,includeaccepts local files, andmise run --affectednow counts uncommitted work and no longer needsexperimental = true. On a fresh machine,mise bootstrapcan install git and ssh before it clones. The release also fixes several dotfiles history issues and stops lazy tools from triggering remote version lookups when something else launches.Added
Per-machine
[vars]prompts. Give a var aprompt, plus either adefaultorrequired. mise asks for it once and saves the answer in$MISE_STATE_DIR/vars.toml, outside your config and dotfiles history. Templates, tasks and tools then read it as usual. One shared dotfiles setup can use this to set a different Git identity on each machine. #14190Only
mise vars promptandmise bootstrap --prompt-varsever ask. Everything else uses the saved answer, then thedefault. Precedence, highest first: the process environment, a value from a higher-precedence config file, the saved answer, thedefault. Answers are keyed by var name, so projects that use the same name share one answer on a machine.promptis not allowed in[env].Local paths in
include.includeinmise.tomlnow accepts local TOML files, not justgit::andoci::references. A path can be relative to the including file or absolute. Local files merge the same way as remote ones, ranking just below the including file. They are read on every load, so edits apply immediately and invalidate the cached env. Paranoid mode rejects local includes, and safe mode still skips all includes in project config. #14178mise bootstrapinstalls git and ssh before cloning.mise bootstrap --fromand--adoptused to fail with a spawn error when git was missing. Now mise checks for git, and for ssh when the URL isssh://oruser@host:path, and offers to install whatever is missing with the host package manager. Supported managers are apt, dnf, pacman, apk, zypper, Homebrew, scoop and winget.--yesaccepts the offer without asking, and--dry-runonly reports what is missing. #14188mise dot save --re-encrypt. After you change[history.encryption] recipients, a normal save leaves some encrypted files under their old keys: manual-save entries the save doesn't name, and other-platform variants. Add--re-encryptto re-encrypt every saved file in the new checkpoint to the current recipients. It never captures unsaved edits. If this machine can't unlock some of the files, nothing is saved and the error lists all of them. #14210mise dot statusshows unsaved changes. It now lists tracked paths that changed since the latest checkpoint. Unsaved edits were previously invisible there when the watcher was stopped or an entry used--no-autosave.--jsonreports these paths ashistory.unsaved. The value isnullwhen they can't be determined, for example with no checkpoint yet or with encrypted files this machine can't compare without prompting. #14209Changed
mise run --affectednow counts working-tree changes, and the workspace graph is no longer experimental. Besides the committedbase...headrange,--affectednow also counts staged and unstaged edits and untracked files that aren't ignored. You can narrow it with--affected-committed,--affected-uncommittedand--affected-untracked, which can be combined (environment variables:MISE_AFFECTED_*). Working-tree changes only count when the head is your current checkout. To get the old committed-only selection, for example in a CI job that writes untracked files before it runs, use--affected-committed.--affected,mise tasks graph,[monorepo.task_defaults],[monorepo.projects]andtask.auto_inferno longer requireexperimental = true. #14214Credential checks for dotfiles. Files with names ending in
.example,.sampleor.templateno longer match the credential name rules. The content scan before publishing still checks them. Once you approve a file for plaintext tracking, mise no longer warns about it on every save. #14204mise dot trackonly asks about plaintext at a terminal. Before saving a credential-named file in plaintext, it now asks only when both stdin and stderr are terminals. Previously, a piped line, such as the next entry in awhile readloop, could be taken as the answer. Scripts need--allow-plaintextor--encrypt. #14205Fixed
Lazy tools no longer trigger remote lookups for other lazy tools. Previously, mise looked up versions for configured lazy tools that weren't installed, even though they weren't being launched. With a cold cache and no network, launching one tool waited on each lookup and could print "Failed to resolve tool version list" warnings. In one offline test a launch took 41 seconds. This no longer happens in these cases:
auto_updatetool launches (#14195)mise xor a shim installs a new version (#14197)mise install,mise upgradeandmise usestill resolve everything.Too many open fileswith parallelnpm:installs. Parallel installs could fail under macOS's default launchd soft limit of 256, for example when mise was started from a LaunchAgent. On Unix, mise now raises its soft open-file limit at startup toward the hard limit, up to 10240, and never lowers it. #14174, #14216go:tools with an untidygo.mod. Tools whose publishedgo.modis missing a requirement now install, for examplego:tailscale.com/cmd/tailscale. mise now passes-mod=modtogo installinstead of-mod=readonly. A project'sGOFLAGS=-mod=vendorstill doesn't affect these installs. #14180 (@JamBalaya56562)Config at the filesystem root. A config file at
/, such as/mise.tomlin a Docker image, mademise installandmise execpanic. It now works. #14182.NET installs. Installing a .NET SDK no longer fails with "was not found in
dotnet --list-sdksoutput" when another mise-managed SDK comes before the shims onPATH. The post-install check now runs the new SDK'sdotnetdirectly. #14189Shims and directories. Shims and
mise whichno longer resolve a bin name to a directory in another tool's bin path. Previously,hunk'sskills/directory blockednpm:skillswith "Permission denied". #14193mise oci buildand multiple versions. A tool pinned to several versions is now written to the embedded/etc/mise/config.tomlas a single array, in resolution order. Previously each version got its own duplicate key, which made the config unreadable inside the container. #14200 (@JamBalaya56562)Encrypted files a sync can't unlock.
mise bootstrap --adopt,mise dot pullandmise dot syncnow list every encrypted file they can't unlock in one error, instead of stopping at the first one. Damaged files still stop the sync immediately. #14208Rollback and undo messages.
mise dot rollback <path>now names the checkpoint that saved the restored version, which matchesmise dot history --path. Rollback and undo also name both checkpoints they record: the result, and the one holding the state before the operation. Previously, rollback could name a checkpoint thathistory --pathdidn't list. What gets restored is unchanged. #14207, #14211mise dot statuson adopted machines. On a machine that adopted a shared setup, it no longer prints "nothing configured in [dotfiles]" while history tracks entries. #14206New Contributors
Full Changelog: jdx/mise@v2026.10.5...v2026.10.6
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.5: : Java defaults to Temurin, per-machine and local-only dotfile history, packslip workflow pinningCompare Source
Java versions without a vendor prefix now install Eclipse Temurin builds. Dotfiles gain per-machine and local-only history, a
merge = "missing"mode, and a secret check beforemise dot syncpublishes anything. Packslip tools can be pinned to the workflow that signs their releases. Several features documented as experimental now actually requireexperimental = true. The rest of the release is fixes across tasks, shims, config loading, bootstrap and backends.Breaking Changes
java@21,java@ltsandjava@latestnow install Temurin. The default ofjava.shorthand_vendorchanges fromopenjdktotemurin. The jdk.java.net OpenJDK builds stop at the next feature release, sojava@21was stuck on 21.0.2 from January 2024. Vendor-prefixed requests (openjdk-21,corretto-21, ...) are not affected. Installed OpenJDK versions keep working, andmise upgradeoffers the Temurin build. Shorthand versions now include Temurin's build suffix (for example21.0.12+101.0.LTS). Temurin has no builds of Java 9, 10 or 12–15, so useopenjdk-12and similar for those. #14146shorthand_vendor = "openjdk". Without that setting,mise install --lockedfails withjava@21 is not in the lockfile. Either keep OpenJDK:mise lock --bump javaand commit the result.experimental = true(orMISE_EXPERIMENTAL=1) when you use them. Config that only mentions them still loads. #14114git::remotefile, including throughmise run --dry-run,mise watch, or as a dependency. Commands that only inspect tasks (tasks ls,tasks info,tasks deps,generate task-docs) show the task from its TOML and warn once that the file wasn't fetched. These were documented as experimental but were missing the check in the codebase.git::andoci::entries intask_config.includes. These are skipped with a warning.mise runwhen an OTLP endpoint is set.spinel:tools.mise.local.tomlnow overridesmise.<env>.tomlin the same directory, as the docs already said. Before, the committed environment file won in project directories, and also in~/.config/misewhen the walk up from the cwd reached it. Within each directory the order is now, highest first:mise.<env>.local.toml,mise.local.toml,mise.<env>.toml,mise.toml. If you relied on the environment file winning, move those keys intomise.<env>.local.toml. #14148mise://tasksresource,envis now an array of env directive strings, the same format asmise tasks ls --json. It was always an empty object before. #14111mise settings setandaddrefuse writes that would have no effect. This covers early-init settings (env,ceiling_paths,env_conf_d, ...) written to a config file, and global-only settings (yes,paranoid,trusted_config_paths, ...) written with--local. The error says where the setting has to go:miserc.toml, the global config, or theMISE_*variable. #14126Added
Dotfiles
variants = [{ machine = true }]ormise dot track --machineto keep a separate history for each machine. Sync pushes every machine's version to the origin but never applies one machine's version on another. Each machine gets a generated name, which you can set with[history] machine = "desk". A machine variant must be the entry's only variant and can't be combined withencrypt. Upgrade every machine that shares a setup before using it. #14062mode = "track-local"(ormise dot track --local) keeps a file's history in a separate store on this machine, with no origin. The file never reaches the shared manifest, a commit or a push. Commands that name a path use the history that holds it. Usemise dot --local historyormise dot --local undoto work with the local history directly.save,captureandwatchcover both histories. #14082merge = "missing"sets only the keys the target file doesn't have yet. Values an app writes itself, such as the model picked with/modelin Codex or Claude Code, are left alone. Works with TOML, YAML and JSON. #14081source. mise then reads the target's path underdotfiles.root. Switching an entry fromsymlinktomergenow replaces a link that points at the merge source with a writable copy, so the app's own keys survive. #14076mise dot syncrefuses to publish saved versions that look like secrets. It checks for provider tokens, private key blocks, and*_KEY/*_TOKEN/*_SECRET/*_PASSWORDassignments. Only versions the origin doesn't have yet are checked. The error names the file, line and version, never the value.--allow-plaintext-historyskips the check. #14171mise bootstrap --adopt <url> --take-remote-alltakes the repository's version of every file that differs, in one step. Combined with--replace-history, it also adopts the repository on a machine that already has history of its own. #14065mise doctorshows the dotfiles history repo path and the connected origin (URL, branch, sync mode), in both text and--jsonoutput. #14173Bootstrap
[bootstrap.files]and[bootstrap.directories]accept the sameosselector as packages. Entries that don't match the host are skipped completely. #14058fish = "auto"in[bootstrap.mise_shell_activate]writes a block that runsmise activate fishin interactive shells and--shimseverywhere else. #14172[bootstrap]is now allowed in config includes. It merges below the including file, so a shared baseline can declare packages, hooks and services, and the project still wins on any key it sets itself. #14176state = "absent", which stops, disables and deletes the matching mise-managed service and timer.mise bootstrap unapplynow also removes the units an environment added. #14139Tools and backends
workflowoption. It accepts only releases signed by the named GitHub Actions workflow on tags. It takes one workflow or a list, and an entry can name a ref (release.yml@refs/heads/main). It can't be combined withpubkey,identity,identity_prefixorissuer. #14075, #14093workfloworpubkeyyou set yourself replaces the registry pin. #14092, #14091, #14073 (@max-sixty)install_toolis implemented. It installs the requested version, or the configured version, or latest, and returns the resolved version and install path.install_toolandrun_tasknow refuse to act on untrusted config instead of trusting it on the client's behalf. #14111mise installs migrateno longer fails on installs it can't reinstall, such as withdrawn releases, signer changes or no network. It moves them into the identity layout as they are and leaves a link at the old path. It also handles lockfile-suffixed~aube~/~uv~directories correctly. #14079mprocsis renamed todekitto match upstream, andmprocsstays as an alias. From v0.10.0 the binary isdekit. #14169Changed
dot pull,dot track,undo,rollback,connectandbootstrap --adopt. Destructive ones still ask, such as--replace-history,dot recover --keep-currentandimplode.--yesandMISE_YESare still accepted. #14077, #14071, #14067MISE_SAFE=1) now ignores a project's[bootstrap],[dotfiles]and[dotfile_groups]. Before, an untrusted repo could link files into$HOMEor clone repositories. Global and system config still apply. #141102were checked. Setnode.gpg_verify = falsefor mirrors without signatures. #14132mise generate github-actionnow usesactions/checkout@v7andjdx/mise-action@v5and no longer setsMISE_EXPERIMENTAL.mise generate devcontainernow adds"postCreateCommand": "mise install". #14145Deprecated
task.cache.stats_report,sops.age_recipientsandplugin_autoupdate_last_check_durationnever had any effect. Setting one now prints a warning, and they will be removed in 2027.10.5. #14112mise bootstrap launchd|systemd|macos-defaults, the old--only/--skippart names (launchd,systemd,defaults,shell) andmise direnvnow print a warning that names the replacement. They will be removed in 2027.10.4. #14113Fixed
Tasks
cacheenabled is now skipped when its sources are fresh and its cache key hasn't changed. Before, it ran every time. #14121sourcesthat matches no files now prints a warning.mise tasks deps <task>now showsdepends_posttasks. Scripts in$MISE_CONFIG_DIR/tasksload even without a global config file. #14122mise run ./scriptresolves relative to the current directory. #14120mise generate task-stubsskips hidden and global tasks. #14127Shims and exec
mise xandmise envno longer look up remote versions for lazy tools that aren't installed. With 20 lazy tools and no network, running an installed tool went from about 42s to 0.09s. #14063mise x tool@1.2.3installs the exact version when the version list times out, instead of failing with "couldn't exec process". #14164mise doctorrecognizes amiseentry in the dedicated shims dir. #14069Config, settings and CLI
config.tomlyet,mise use -gcreatesconfig.tomlinstead of writing intoconfig.<env>.toml. #14179mise config set --type booland boolean settings acceptyes/no/1/0. Forenv.*and other keys that aren't settings, onlytrueandfalsebecome booleans, and anything else is stored as written.mise latest tool@prefix:Xworks, and--log-level warnis accepted.mise doctorprints the full chain when config fails to load. #14125mise editno longer overwrites an existing config when there is no terminal. #14124.monorepomarkers are verified in paranoid mode. #14105mise config lsandmise prunewith an invalid tool version, the--monorepoflags, andmise plugins uninstall --purge. #14118, #14094 (@JamBalaya56562), #14103 (@JamBalaya56562), #14116, #14117mise env --redactedhonorsredact = falseexclusions.watch_fileshooks don't run in safe mode or with--no-hooks. #14109, #14108mise watchpasses watchexec flags through to watchexec. #14115bootstrap remoteand the watchexec install hint. #14142<temp>/mise-tmp, somise cache clearno longer deletes files that are still in use. #14134Bootstrap and dotfiles
mise bootstrapkeeps writing the shell activation block into a startup file that is only tracked. #14135exec(). #14136mise dot undorestores them.--replace-historyno longer fails on its first attempt. #14065mise dot pullsays so when incoming history changes no files on this machine. #14066Backends and plugins
mise install cargo:...no longer uses an inactivecargo-binstallshim. It falls back to native binstall orcargo install. #14070npm.shell_out, a mise shim from another data dir can no longer be run asnpmand fork until the machine runs out of memory. #14084 (originally found and fixed by @tfournet)java.shorthand_vendortakes effect without waiting for the cache to expire. Inlinejava[release_type=ea]is respected when listing and resolving versions. #14131{os}and{arch}correctly. #14133ls-remoterespectsdisable_backends. #14130api_urlfor cloning and skips lockfile URLs. #14129git::plugins install from a subdirectory, and[plugins]entries compare those sources correctly. Packslip entries in[plugins]install as vfox plugins. #14140, #14150 (@onokonem), #14141Daemons and sandbox
--deny-envclears inherited variables on Windows. On macOS,allow_netis rejected instead of writing invalid sandbox rules. #14107, #14106Security
[vars]and task arg values asblake3:digests instead of plaintext, so secret values are no longer uploaded. Existing cache entries miss once after upgrading. #14104Documentation
New Contributors
Full Changelog: jdx/mise@vfox-v2026.10.4...v2026.10.5
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.10.4: : Task-scoped fnox secrets, automatic global tool updates, and an opt-in identity install layoutCompare Source
This release adds experimental task-scoped secrets backed by fnox, automatic updates for global tools, and an experimental opt-in install layout that names installations by what they contain. It also adds dotfile
mergeentries,headersauth for thehttp:backend, npm installs from git, and a set of prune, install and lockfile fixes.Added
Secrets (experimental)
These need
mise settings experimental=trueand fnox 1.39.0 or newer. They are refused in safe mode.[secrets.fnox]andmise secrets ls. A project can name fnox as its secrets source in its ownmise.toml.mise secrets lslists key names and metadata but never values.-Jprints JSON. Global, system and home-level[secrets]config is ignored, andmise doctorreports it. #13967Tasks get only the secrets they list. Add
secrets = [...]to a task, or#MISE secrets=[...]in a file task header. Only that task gets the values, only while it runs, and they are redacted from its output. Dependencies, hooks,mise env, hook-env and shims get nothing. A task without grants never calls fnox. Tasks that list secrets need a trusted config, aren't artifact-cached, and ignore--rawunless the task setsraworinteractive. Hooks,watch_files, daemons andmise bootstrapcan't run them, and remote or global-config tasks can't list secrets. #13974One-off grants from the command line.
--secrets KEY[,KEY]and--secrets-allwork onmise run,mise tasks runandmise x. Formise run, only the tasks named on the command line get them, not their dependencies.mise xgets nothing unless you pass a flag, and it can't receive file secrets. Flags placed after the task name go to the task, and mise warns when that happens. #13975{{ secrets.X }}in task env values. A task can build an env var from a secret, for exampleenv.PGURL = "postgres://app:{{ secrets.DB_PASSWORD }}@db/app". The reference counts as the grant. References are rejected inrun,[env],[vars]and other fields. #13978fnox daemon cache. If the project's fnox config enables the daemon and it's running, an interactive run reads cached values over its socket without starting an fnox process. mise never starts the daemon itself. CI, non-TTY runs and Windows always use the fnox CLI. #13979
Automatic global tool updates
auto_updatefor global tools. Setauto_updateon a tool in your global config. When a shim ormise xis about to run that tool and its check interval is due, mise upgrades it within the configured range and then runs the new version.trueuses the newtool_update.check_durationsetting (default 24h), and a duration string sets that tool's own interval (minimum 1h). #14026locked = true, from tasks or hook-env, or from project configs.mise doctor.Background
tool-updateservice. A built-in bootstrap service checksauto_updatetools hourly, so launches don't wait for downloads and tools run directly from PATH under activation also stay current. It installs a systemd user unit, LaunchAgent or scheduled task. #14040Identity install layout (experimental, opt-in)
install_layout = "identity". Withexperimental = true, each installation lives ininstalls/<label>-<hash>/. The hash covers the canonical backend, version, platform and install-affecting options.installs/<tool>/<version>becomes a link to that directory, a real junction on Windows. As a result: #13951ageandaqua:FiloSottile/ageshare one installation.Existing installs keep working and aren't moved. Nothing changes unless you set this.
MISE_INSTALL_LAYOUT=identityalso turns it on. See the new install layout docs.On Windows, identity-layout installations go into the shorter
%LOCALAPPDATA%\mise\i\, while version links stay ininstalls\.MISE_INSTALL_STORE_DIRsets the location on any platform. #13952mise installs lslists installations asselected,pinnedorshared.mise installs select <dir>chooses which installation requests without a lockfile use. When several installations match and none is selected, mise lists them instead of guessing. #13953mise installs migrate [--dry-run] [TOOL[@VERSION]]reinstalls legacy installations into the new layout and leaves a link at the old path. If a run is interrupted, the next run recovers it. #13955In the layout,
mise backends switchinstalls the new backend's version and points the link at it.mise whereand the other commands now resolve versions named on the command line the same way, andmise wherelists variants instead of picking one. #13957mise prunehandles templated tool versions such asnode = "{{ vars.node }}". It uses snapshots of what each project last rendered and keeps installs when it isn't sure they are unused. #14025Other additions
Dotfile
mergeentries. Amerge = trueentry sets only the keys from its source in a JSON, TOML or YAML file, and leaves keys added by the application (Codex, Claude Code, etc.) alone. TOML and YAML keep comments and formatting.mise dot statusandmise dot diffonly report drift in those keys. A target that doesn't parse is never overwritten. #14012headersfor thehttp:backend. You can now authenticate with bearer tokens or API keys, for example to download OCI blobs fromghcr.io. Values are templates. Headers are sent with downloads,version_list_urlandchecksum_urlrequests, and dropped on cross-host redirects unless the host is listed inheaders_forward. Changing a token doesn't trigger a reinstall. #14022npm packages from git.
git+URLs andgithub:,gitlab:andbitbucket:specs now install. The version is a git ref, andlatestis the default branch. #14044mise use 'npm:github:owner/repo@v1.2.0'settings.write_targets. Sends new global[tools],[bootstrap.packages]and[dotfiles]entries to separateconf.dfiles. Existing entries are updated where they're already declared. #14018prune.exclude(orMISE_PRUNE_EXCLUDE) lists tools thatmise prune,mise ls --prunableand upgrade pruning never remove. Short and full names both work, e.g.nodeoraqua:BurntSushi/ripgrep. #14030lockfile_auto_prune = falsekeeps lockfile entries for tools missing from the active config. This is useful when profiles share one lockfile. The default (true) keeps the current pruning behavior. #13980mise dot notifysends a test desktop notification, which also triggers the macOS permission prompt.mise doctorandmise dot statusnow show whether notifications can be delivered. #14009Changed
mise's own auto-update settings moved under
self_update.*.auto_updateis nowself_update.auto(MISE_SELF_UPDATE_AUTO), andauto_update_check_durationis nowself_update.check_duration(MISE_SELF_UPDATE_CHECK_DURATION). The old names keep working. The new key wins when both are set. Deprecation warnings start in 2027.4.0. Older mise versions ignore a settings file that has unknownself_updatekeys, so keep the old spelling if a config has to work with both. #14038mise prune,mise unuse --prune,mise ls --prunableand deferred pruning after an upgrade now keep any version a running process was started from, on Linux, macOS and Windows. They say which process kept it. #14020pypi:/pipx:tools installed with uv are now built on mise's Python when mise manages one. Previously uv could use its own downloaded interpreter, which broke CI caches that only restore the mise data dir. A package whoserequires-pythonexcludes mise's Python now fails; to override, pass--pythoninuvx_args. #14024With
python.uv_venv_auto,mise installnow creates the project venv with mise's Python instead of whatever uv found. #13981 by @halmsInherited secrets: when a parent mise marks variables as secrets in
__MISE_SECRET_KEYS, a nested mise now does the following #13966:get_env()andexec()__MISE_DIFF, other tasks and pitchforkmise xand shims still pass them through.Fixed
postinstallhook no longer leaves its version listed as installed or selectable. The next install retries it. #14037$MISE_STATE_DIR, somise cache clearno longer makes a half-installed version look installed. Existing markers are migrated. #14051mise install --lockednow works fordotnet:tools. #13971 by @james-newell-forgemise lockforpypi:tools on registries with a<root>/pypi/{}/jsontemplate, such as Artifactory, now uses<root>/simple/. #14007 by [@&Investigate: Support Walrus Operator #8Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.