Skip to content

chore(deps): update dependency jdx/mise to v2026.9.15 - #1086

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/jdx-mise-2026.x
Open

renovate[bot] wants to merge 2 commits into
mainfrom
renovate/jdx-mise-2026.x

Conversation

@renovate

@renovate renovate Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change Pending
jdx/mise patch 2026.9.12 → 2026.9.15 v2026.10.0 (+3)

Release notes are maintained in a PR comment by the renovate-release-notes-comment workflow.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • "after 4pm on thursday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from scottames as a code owner October 2, 2026 02:10
@renovate renovate Bot added the dependencies label Oct 2, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 2, 2026 02:10
@scottames-github-bot

Copy link
Copy Markdown
Contributor

Renovate Release Notes

Generated from Renovate's update table by the renovate-release-notes-comment workflow.

Packages that cannot be summarized from GitHub releases are listed explicitly below.

jdx/mise (jdx/mise)

v2026.9.15: v2026.9.15: vfox tools in OCI images, faster shell prompts, and safer dotfiles pattern matching

Compare Source

mise oci build can now package tools installed by vfox plugins, and vfox plugins can repair an existing install when its tool options change. Shell prompts, cd, and settings loading are faster. Dotfiles include/exclude patterns now follow .gitignore rules for * and a leading /, which fixes a case where rollback could delete a live file.

Added

  • vfox tools in OCI images (experimental). mise oci build used to reject every tool installed by a vfox plugin. It now builds those tools into the image, with one layer per tool plus one layer per plugin at /mise/plugins/<name>/, so mise inside the image can resolve the tool without cloning the plugin. The plugin's env hook runs on the build host. Install-dir paths are rewritten to their in-image location, and mise warns when a value points into the host's home directory. Changing a plugin invalidates the reused layers of its tools on mise oci push. asdf plugins are still rejected. #13670

  • vfox plugins can repair installs that no longer match tool options. Plugins can add an optional hooks/mise_install_satisfied.lua hook that tells mise an installed version no longer matches its options, for example after a component is added to a gcloud config. mise install and auto-install (such as mise x) then rerun the plugin's PostInstall and the tool's postinstall script on the existing install without downloading it again. If the hook itself errors, mise warns and keeps the install. Plugins without the hook work as before. See docs/tool-plugin-development.md. #13668

    [tools]
    gcloud = { version = "latest", components = ["gke-gcloud-auth-plugin"] }
  • Git subdirectory installs for pypi:. Git sources now accept a #subdirectory= fragment (other fragment keys are passed through as written), and git+<scheme>:// URLs work without a trailing .git. Each subdirectory is its own tool with its own install directory. latest still means the repository's newest GitHub release, so pin a branch or commit if those releases predate the subdirectory. #13607 (@​jakedgy)

    [tools]
    "pypi:git+https://github.com/runpantheon/ltui#subdirectory=ltui" = "main"
    "pypi:runpantheon/ltui#subdirectory=jtui" = "main"
  • max_version for registry backends. Registry entries can now set an exclusive max_version, alone or together with min_version, so older releases can come from a legacy backend and newer ones from another. It requires version_order = "semver". A locked backend is used only for versions it serves. #13676

  • Mac App Store names in mise bootstrap packages status. Installed mas: packages now show the app name next to the numeric ID (for example 1056643111 (Clocker)), and --json adds a name field. Apps that aren't installed still show only their ID. #13622

  • Registry: added sofka (#13612, @​jylenhof), imessage-exporter (#13640, @​i-api), and spotify-downloader (#13641, @​i-api). nub 0.9.5 and later now installs from github:nubjs/nub, and the entry lists the nubr bin (#13643, @​colinhacks). cocogitto now lists cog as its bin (#13657).

Changed

  • mise exec warns when a missing pinned tool falls back to PATH. When auto-install is off (exec_auto_install = false, auto_install = false, or auto_install_disable_tools) and the command belongs to a pinned tool that isn't installed, mise used to run a same-named binary from PATH without saying anything. It still runs it, but now prints a warning such as jq@&#8203;1.7.1 is not installed and auto-install is disabled, so mise looks for jq on PATH instead. There's no warning when another configured version of the tool, a command wrapper, or a project env._.path entry provides the command. #13650, #13658
  • mise tasks validate fails on unparseable usage specs. A file task's #USAGE spec (or a TOML task's usage) that doesn't parse is now a usage-parse-error error, so validation exits 1, including with --errors-only. Before, it was only a warning and validation passed. mise run and mise tasks ls behave as before. CI that runs mise tasks validate will now fail on these specs. #13672
  • Linux GNU release binaries are linked non-PIE. Every mise command on Linux x64, arm64, and armv7 (GNU) now starts about 3 ms faster. The tradeoff is that ASLR no longer applies to mise's own code and data, though the heap, stack, and shared libraries are still randomized. musl, macOS, source builds, and cargo install are unchanged. #13687

Fixed

Dotfiles

  • * no longer crosses / in tracked include patterns. Capture and rollback used to disagree about what rules/*.md selected. After you widened the list, mise dot rollback to an older checkpoint could delete a nested file such as rules/deep/two.md. include now follows .gitignore rules: * stops at /, and you need ** to match nested files. exclude lists keep matching what they matched before, but mise now prints a deprecation warning when an exclusion depends on * crossing /. Use ** in those patterns instead. #13618
  • A leading / anchors include/exclude patterns to the entry root. Before, these patterns matched nothing at all. Now exclude = ["/cache"] skips only the top-level cache directory, and include = ["/rules/*.md"] works. In the global [history] exclude list, a leading / still means an absolute path. #13621

Tasks and config

  • Tasks in a conf.d folder fragment now run in that folder, with {{config_root}} and MISE_CONFIG_ROOT pointing there. Each folder's [task_config] applies only to its own tasks, so a fragment's includes no longer hides the default task directories like ~/.config/mise/tasks. #13662
  • A settings load that was already running could cache a stale snapshot after another thread changed settings, which dropped a just-applied override. This is fixed. #13646

Plugins and shims

  • mise now warns when an installed git plugin's origin URL or checked-out commit doesn't match its [plugins] entry. The warning appears in mise install, mise plugins install, and mise doctor. Related fixes #13663:
    • mise plugins install --force <name> now reinstalls from the [plugins] pin.
    • A failed ref checkout no longer leaves an unpinned clone behind.
    • Short SHAs fail with a clear error, since a full SHA is required.
    • Shorthand pins like owner/repo#v1.2.0 keep their ref.
  • On Windows, [wrappers.*] command wrappers (including the cargo wrapper that mr_boxington generates) now run through exe- and file-mode shims and mise x. Before, the real tool ran instead. #13673

Bootstrap

  • On apt systems, mise now simulates the install first and runs apt-get update once if the simulation fails. This fixes has no installation candidate failures on machines whose package lists cover only the install media. #13659
  • On macOS, mise bootstrap macos defaults now reads and writes the container plist for sandboxed apps such as Safari, which the app actually uses. Launch the app once first so its container exists. Writing another app's container may require Full Disk Access for your terminal. #13660
  • When mise bootstrap packages prune fails on a brew: formula it can't resolve, the error now names the config file that declares it. When the name is actually a cask, mise suggests brew-cask:<name>. #13661

Performance

  • Faster shell prompts. When nothing has changed, mise hook-env no longer loads all settings or starts the async runtime (6.6 ms to 4.9 ms on Linux in the PR's measurements), as long as hook_env.chpwd_only and hook_env.cache_ttl are unset. #13686
  • Faster cd with npm tools installed. The npm install health check now reads the virtual store's directory listing instead of calling stat on every package. #13685
  • Faster settings loading. Config discovery skips conf.d globs for directories that don't exist, which halves settings load time in deep checkouts. #13688
  • Faster brew-cask: lookups. Official casks are resolved from Homebrew's bulk cask.json index, cached locally and re-checked with a conditional request after 7.5 minutes, instead of one request per cask. In the PR's test, bootstrap packages status with 143 casks dropped from about 26s to about 2s. #13349 (@​waynehoover)
  • Fixed slowdowns from deferred prunes. When a deferred-prune receipt from mise upgrade comes due but the version is still in use, mise now re-checks it once a day instead of on every command. This could make trivial commands about 9x slower. Pruning can now happen up to a day after the last reference is removed. #13674
  • mise ls, mise prune, and shim rebuilds scan install directories in a single pass. #13675

Full Changelog: jdx/mise@vfox-v2026.9.16...v2026.9.15

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.14: v2026.9.14: conf.d folder fragments, Stow-style dotfiles options, and mise-versions for any public GitHub repo

Compare Source

A folder inside any conf.d directory now loads as its own config fragment and serves as the config root for the files in it, which gives [bootstrap].config_roots users a direct migration path. [dotfiles] gains two GNU Stow-style options: relative symlinks and dot-<name> sources. Release metadata for any public github.com repo now comes from mise-versions, and the registry can require GitHub attestations for specific tools.

Added

  • conf.d folder fragments. A folder in a global, system, or project conf.d directory now loads as a fragment. Relative paths, {{ config_root }}, and task working directories resolve inside that folder, so a bundle can keep its files next to its config. Each folder can hold mise.toml, mise.local.toml, mise.<env>.toml, and mise.<env>.local.toml. Folders are not searched recursively, and folders whose names start with . are skipped. A folder can be a symlink. Folder fragments load after the single-file fragments in the same conf.d (in folder-name order) and before config.toml. mise use/mise set never write to them. #13603

    ~/.config/mise/conf.d/
    ├── git.toml          # single-file fragment, unchanged
    └── git-tools/        # folder fragment
        ├── mise.toml
        └── gitconfig
    
    # ~/.config/mise/conf.d/git-tools/mise.toml
    [dotfiles]
    "~/.gitconfig" = "gitconfig"   # resolves to conf.d/git-tools/gitconfig

    Compatibility: if a directory inside a conf.d that mise reads already contains a mise.toml, that file now loads.

  • Relative dotfile symlinks. symlink and symlink-each entries can now point at their source by a relative path, so links keep working when a home directory is mounted at a different path or moved. Turn this on for all entries with dotfiles.relative_symlinks = true (or MISE_DOTFILES_RELATIVE_SYMLINKS=1), or per entry with relative = true/false. When you turn it on, existing absolute links are re-pointed on the next apply. Turning it off does not convert relative links back to absolute ones. This option has no effect on Windows. #13583

    [settings]
    dotfiles.relative_symlinks = true
    
    [dotfiles]
    "~/.config/foo" = { source = "~/dotfiles/foo", mode = "symlink" }   # -> ../dotfiles/foo
    "~/.bashrc"     = { source = "~/dotfiles/bashrc", relative = false } # stays absolute
  • dot_prefix for dotfiles. With dot_prefix = true on a symlink-each or directory copy entry, any path component named dot-<name> deploys as .<name> (for example, home/dot-config/foo deploys as ~/.config/foo). exclude and manifest = "git" still match source names. If two sources map to the same target, apply fails. mise dot add refuses to capture into dot_prefix entries, and mise oci builds use the same mapping. #13585

    [dotfiles]
    "~" = { source = "home", mode = "symlink-each", dot_prefix = true, exclude = ["README.md"] }
  • mise-versions for any public github.com repo. For github:, aqua:, and packslip: tools that aren't in the registry, version listing, release lookup, and attestation lookup now go through mise-versions, so they no longer use your GitHub API rate limit in the common case. Private repos still use your own token against api.github.com. #13584

    • mise treats the mirror as untrusted. Download URLs must match the configured repo, release tag, and asset name, and mirrored attestations must name the requested repo.
    • In paranoid mode, mise checks a "no attestations" answer from the mirror against GitHub before skipping verification.
    • If url_replacements reroutes GitHub API paths, mise skips mise-versions for that metadata.
    • If mise-versions fails for any reason other than a 404, mise falls back to api.github.com and logs a warning.
  • Registry-required GitHub attestations. Registry github: backends can declare attestations_since = "<semver>". For versions at or after that boundary:

    • mise lock records github-attestations provenance.
    • Installs require a verified attestation for every downloaded asset. This requirement overrides weaker provenance recorded in a lockfile.
    • A missing attestation is a hard error.

    42 registry tools now set this boundary, including aube, aqua, pixi, ty, pandoc, fnox, doppler, and syncthing. Users who have turned off github_attestations are not affected. #13586

Fixed

  • Install lock waits: when one process is waiting for another to finish installing the same tool version, the message now names the process holding the lock (waiting for install lock held by pid 61907). This is usually a shim auto-installing the tool. #13588
  • Slow downloads: mise now warns once per download if throughput stays below 16 KiB/s for a full minute, naming the host and suggesting a mirror. The download is not aborted; http_download_timeout is still the hard limit. #13589
  • Interrupted installs: a half-installed version no longer appears in version listings, can't be picked as the latest installed version, and doesn't keep latest/1/1.2 runtime symlinks pointing into it. #13596
  • mise prune: no longer deletes versions pinned by another project when you run it from a directory whose .miserc.toml lists that project in ignored_config_paths. The same fix applies to mise ls --prunable and the stale-version check in mise upgrade. These commands now honor ignored_config_paths only from MISE_IGNORED_CONFIG_PATHS and global or system miserc.toml. #13602
  • mise oci build: directory [dotfiles] entries (symlink-each and directory copy) now honor exclude and manifest = "git", so the image contains the same files mise dot apply deploys. #13591
  • pipx/pypi: latest no longer resolves to PEP 440 developmental releases such as 2026.9.16.232951.dev0, matching what pip and uv do. Local labels like 1.1+gpu.dev0 are still treated as stable. #13601
  • pipx/pypi: mise use 'pypi:git+ssh://git@&#8203;github.com/psf/black.git' now works. Previously, the @&#8203; in git@&#8203; was read as the version separator. #13610
  • MISE_USE_VERSIONS_HOST=0: now fetches the version list from the source instead of reusing a cached, possibly older list from the versions host. #13605
  • brew source builds: checksum-pinned formula source downloads now follow HTTPS-to-HTTP mirror redirects (such as those from ftpmirror.gnu.org) and still reject tarballs whose checksum doesn't match. This affects Unix only. Every other download still refuses HTTPS-to-HTTP redirects. #13611
  • npm backend on Windows: updating the bundled aube to v2.4.0 fixes lifecycle scripts failing with EISDIR: illegal operation on a directory, lstat 'C:' during npm: installs. #13608

Changed

  • The [bootstrap].config_roots deprecation warning now explains how to move each root into a conf.d folder, either by moving it or by symlinking it. The removal date (mise 2027.3.3) is unchanged. #13598
  • Registry: spin-framework now installs through aqua by default. The previous backend is still available. #13594 by @​scop

Full Changelog: jdx/mise@vfox-v2026.9.15...v2026.9.14

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.13: v2026.9.13: OpenTelemetry for tasks, shared daemon providers, mise backends switch, and declarative dotfile removal

Compare Source

mise run can now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the new mise backends switch command does it when you ask. [dotfiles] and [bootstrap.files] can now remove files and manage permissions, and mise bootstrap unapply removes what a module set up. The experimental pkgx: backend has been removed.

Highlights

  • Observability and shared services (experimental): task runs export OTLP traces and, if you opt in, task output as logs. Global [daemon_providers] run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout.
  • Safer lockfiles: locked tools stay on their locked backend, mise lock --bump checks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project's mise.lock.
  • Declarative cleanup: mode = "absent", remove_empty templates, permissions-only entries, removal of empty directories mise created, and mise bootstrap unapply let a config describe what should not be on a machine.

Added

Tasks

  • OpenTelemetry export for mise run (experimental). Each run becomes one trace, with a span per task (grouped by monorepo package) that carries its exit code and redacted args. W3C TRACEPARENT is read from the environment and passed to each task, so nested mise run calls and instrumented tools appear in the same trace. Nothing is exported unless otel.enabled = true and an OTLP endpoint is set. Offline mode disables export, and each export times out after 3s by default. A separate otel.logs = true setting exports task stdout (INFO) and stderr (WARN) as log records linked to their spans, with redactions applied first. With otel.logs on, tasks in interleave/quiet modes no longer get a TTY; use --raw for tasks that need one. #13557, #13558, #13559 (built on work by @​MatthiasGrandl and @​zeitlinger)

    [settings]
    otel.enabled = true
    otel.logs = true   # optional; exports task output too
    export OTEL_EXPORTER_OTLP_ENDPOINT=<your OTLP/HTTP collector URL>
    mise run build ::: test

Daemons (experimental)

  • Shared server providers. Declare long-lived PostgreSQL, CockroachDB, or NATS servers in global config under [daemon_providers] and manage them with mise daemons providers ls|start|stop|restart. Providers have their own tools, ports, and persistent data. They run in an isolated environment and are not tied to any checkout. #13534

  • Per-checkout databases and accounts on a shared server. A project daemon with provider = "..." gets its own database (PostgreSQL/CockroachDB) or its own NATS account with separate subjects and JetStream data. Each checkout path gets a stable name, so worktrees share the server but not the data. Give several daemons the same resource name to share data on purpose. Connection env vars point at the right database, and NATS gets an authenticated NATS_URL. #13536, #13537

    # ~/.config/mise/config.toml
    [daemon_providers.local-postgres]
    preset = "postgres"
    version = "18"
    port = "auto"
    
    # project mise.toml
    [daemons.db]
    provider = "local-postgres"
    # resource = "shared_app"   # opt in to sharing data

Lockfiles and backends

  • mise backends switch. When the registry moves a tool to a new backend (as happened with hk and communique moving to packslip:), a tool locked to the old backend now stays there. mise install and mise lock print a warning that points to the new command, which moves lock entries to the registry's backend at the same versions, relocks their platforms, and reinstalls. It supports --dry-run, --global, and TOOL@&#8203;VERSION. If any relock fails, every lockfile it changed is restored. #13543

  • Tool stubs lock into the project's mise.lock. mise generate tool-stub --lock now records the stub in the nearest project lockfile (listed under tool-stubs), so installs verify the recorded checksums and --locked/MISE_LOCKED=1 accept stubs. Previously the [lock] section written into the stub was never used, so checksums were never checked. #13502

  • Install from a local archive. The http: backend accepts file:// URLs. It copies the archive instead of downloading it, still verifies checksum, and works offline. #13574

    [tools]
    "http:my-tool" = { version = "1.0.0", url = "file:///opt/archives/my-tool-v1.0.0-linux-x64.tar.gz", checksum = "sha256:..." }
  • Checksum mismatch hints for re-uploaded GitHub assets. When a github: or aqua: install fails a checksum check, mise asks GitHub for the asset's current digest. If that digest matches the download, the error says the maintainer probably re-uploaded the asset. The install still fails. #13512

  • vfox BackendUninstall hook. Backend plugins can define hooks/backend_uninstall.lua to clean up outside the install directory. It runs before removal on uninstall, upgrade, and prune. If the hook errors, the install directory is kept. #13522

CLI

  • mise search checks package registries. Add a prefix to search npm, crates.io, RubyGems, or NuGet (mise search npm:typescript-language, cargo:, gem:, dotnet:). --all searches every source at once. Plain searches and shell completion still make no registry requests, and MISE_OFFLINE=1 skips them. #13550
  • mise ls by backend. -b/--backend (repeatable) filters by backend and also works with --json. --grouped prints one section per backend. #13530
  • Key completion for mise config get/set. Tab completes dotted keys, with descriptions, from the schema and from the target file. --file, --global, and --system are respected. #13551
  • Coloured help and a logo. mise --help is now coloured on terminals (and respects NO_COLOR), wraps at the terminal's real width, and shows the mise logo on mise/mise --help when there's room. #13449
  • Project URLs in the registry. Registry entries can set a url, which appears in mise tool (and mise tool <name> --url) and in mise registry --json. #13533

Configuration and hooks

  • .miserc.local.toml. Sets per-checkout early config, such as env = ["native"], without editing the shared .miserc.toml. At each directory level it is read before .miserc.toml. CLI flags and MISE_ENV still take precedence. #13440
  • backend and install_path in MISE_INSTALLED_TOOLS. Postinstall hooks can now see where each tool came from and exactly where it was installed. #13421 (@​garysassano)
  • A configured pnpm overrides Node's bundled pnpm, whichever order the tools are listed in. #13498 (@​EMcCormack)

Dotfiles

  • Choose what a tracked directory saves. exclude and include lists on mode = "track" entries. Exclusions always win. include = [] selects nothing. Narrowing a list does not delete the files on other machines. #13418, #13432

    [dotfiles]
    "~/.codex" = { mode = "track", include = ["config.toml", "rules/**"], exclude = ["*.log"] }
  • Preview before tracking. mise dot track --dry-run and mise dot paths --preview show file counts, sizes, exclusions, and skipped nested repositories. Large trees get a warning. #13417

  • mode = "absent" removes a file or symlink at the target, with support for OS variants. Directories and special files are refused, even with --force. #13513

  • permissions key. Overrides the mode of copy, template, and content entries, or manages only the permissions of an existing file such as ~/.ssh/config. Status, diff, and apply report and fix drift. The key is ignored on Windows. #13514

  • remove_empty = true on templates removes the target when the template renders empty. A file you have edited since mise last wrote it is kept unless you pass --force. #13515

  • Empty parent directories mise created are removed along with their target on apply and unapply. This only applies inside $HOME and never to directories that already existed. #13518

  • Warnings from background captures, such as credential-named files saved in plaintext, are now shown by the next mise dot command or mise bootstrap. Previously they only went to the watcher logs. #13483

Bootstrap

  • mise bootstrap unapply <ENV>... removes the files, directories, user services, and dotfile entries a module added after you deselect it. Anything another environment still declares is kept. Supports --dry-run and --force. #13441
  • Permissions-only [bootstrap.files] entries. Declare only mode/owner/group to manage a file's metadata without taking over its contents. #13511
  • remove_empty = true on templated [bootstrap.files] removes the target when the template renders empty. #13510
  • More systemd directives: before, binds_to, part_of, conflicts, exec_start_pre, exec_start_post, and exec_stop_post. ~ now expands after exec prefixes such as -~/bin/check. #13526

Registry

  • Added mole (#13363, @​casparbreloh), reviewdog (#13562, @​takumin), and nim (#13461, @​elijahr). aube now points at aubepkg/aube (#13541).

Fixed

Tools, installs, and lockfiles

  • mise cache prune could delete files from installed tools: it followed symlinks out of the cache into install directories and left npm cache entries half-empty. It now never follows symlinks and removes stale entries as a whole. cache_prune_age = "0s" now also turns off mise cache prune. #13424
  • mise lock --bump now checks remote versions for every selector (for example "6", not only latest) and fails when the version list can't be fetched, where it used to exit 0 with stale versions. Packslip registry tools no longer call api.github.com in normal use, which avoids rate-limit errors. #13544
  • mise lock refuses to record an aqua version that only resolved to its own request string because the version list failed to load. When such an install fails, the error now says why. #13552
  • mise lock --global no longer skips global tools that the project config shadows, and no longer overwrites a global pin with the project's version. #13547
  • mise lock no longer tries to lock 3.9.6~aube~<digest>-style install directory names for npm and pipx tools. #13542
  • mise upgrade --bump tool@&#8203;selector now saves the selector to the config, as mise use does. #13179 (@​zeitlinger)
  • npm packages whose lifecycle scripts call back into the package manager through npm_execpath (such as re2) now run through aube, not mise's task runner. #13484
  • Command wrappers such as [wrappers.cargo] command = "mbx" now install the missing provider tool before running it. #13532
  • A GitHub, GitLab, or Forgejo token containing a newline or other invalid header character now gives a redacted error, where mise used to crash. Tokens read from *_tokens.toml are trimmed. #13488
  • .tar.zst archives compressed with a long window now extract. #13566
  • aqua creates .mise-bins for registry files listed by name only (#13525), and reports only the provenance and signature checks mise actually performs (#13549).
  • Renaming a raw Windows download with bin keeps the .exe extension. #13529
  • brew-cask percent-decodes artifact filenames taken from cask URLs. #13431
  • mise self-update fails before downloading when it can't write to the install directory. #13453
  • Per-tool progress bars line up in interactive installs. #13494

Tasks

  • A metadata-only [tasks.hello] block no longer creates an empty task that hides mise-tasks/hello.sh. It now configures the script, and dependency groups keep their depends when another config layer adds metadata. #13448
  • A run under a file task's name now replaces the script. #13458 (see Breaking Changes)
  • Dependencies that use optional usage flags or args in templates are no longer dropped when those values are omitted. #13569 (@​nettlesh)
  • When parallel tasks fail together, only the task that caused the stop prints its error chain. #13556

Shell, CLI, and platforms

  • The bash mise function now embeds the path to the mise binary, so it keeps working in shells that copied the function but not $__MISE_EXE (for example Claude Code's Bash tool on Windows). #13491
  • Windows release builds no longer abort with "panic in a function that cannot unwind" when a vfox plugin hits a Lua error. #13503
  • cargo install mise for Windows targets works again. #13573
  • Help and completion output exit quietly when the reader closes the pipe. #13575, #13527

Dotfiles, history, and bootstrap

  • On Windows, user services that set environment no longer run through cmd.exe behind a console window that killed the service when closed, and shell metacharacters in the environment are no longer rejected. The history watcher also runs without a console window. #13429, #13428
  • mise bootstrap now runs [history.reload] commands after its dotfiles phase writes matching files, as mise dot apply does. #13509
  • Nested Git repositories inside tracked directories are skipped and reported, not saved as commit pointers. Track the repository's root directly to capture its files. #13416
  • Global history exclusions apply consistently to tracked paths (#13427), and files left out by credential filtering are reported (#13415).
  • A postgres daemon that would start as root now fails early with a clear error. #13567

Security

  • When [bootstrap.files] and [bootstrap.directories] changes run as root, mise no longer follows a symlink in the path that another user could have planted (CWE-59). Status and dry-run show these paths as unknown, and apply refuses them. Symlinks inside root-owned directories that no one else can write, such as /etc on macOS, still work. #13539, #13546

Breaking Changes

  • The experimental pkgx: backend is removed. Entries like "pkgx:stedolan.github.io/jq" no longer resolve; switch to the registry shorthand (jq) or aqua:/github:. Lockfiles with pkgx sections still load, and those sections are dropped the next time mise writes the file. The pkgx registry entry for the pkgx CLI itself is unchanged. #13555
  • Locked tools keep their locked backend. A short-name tool no longer follows the registry to a new backend if mise.lock records a different one. Run mise backends switch to move it. #13543
  • TOML commands replace file tasks. [tasks."hello.sh"] run = ... used to be ignored and now runs. [tasks.hello] run = ... no longer leaves hello.sh available as a separate task. To keep both, give the inline command its own name. #13458
  • mise generate tool-stub --lock needs a project config above the stub. It writes to that project's mise.lock and no longer pins the stub's version. Any old [lock] section is ignored and removed. Older mise releases drop tool-stubs from mise.lock. #13502
  • Dotfiles include/exclude need current mise on every machine. Upgrade every machine that shares the dotfiles setup before using include lists. New checkpoints use schema version 2, which older clients can't roll back. #13432
  • Recursive [bootstrap.directories] removals always run as root, so a path that crosses a symlink in a user-writable directory is now refused, even under $HOME. Declare the resolved path instead. #13546

New Contributors

  • @​EMcCormack made their first contribution in #13498
  • @​elijahr made their first contribution in #13461
  • @​takumin made their first contribution in #13562

Full Changelog: jdx/mise@v2026.9.12...v2026.9.13

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch from 98bd3b8 to 42b2779 Compare October 2, 2026 03:06
@renovate

renovate Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Rebase not applied

This branch has not been rebased, as its update has not yet met the internal checks configured for it, such as minimumReleaseAge. Rebasing it now would add a dependency version which is still within its configured observation period.

Renovate will rebase this branch once its update has met those checks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants