Skip to content

chore(deps): update dependency jdx/mise to v2026 - #220

Open
renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x
Open

renovate[bot] wants to merge 1 commit into
scipfrom
renovate/jdx-mise-2026.x

Conversation

@renovate

@renovate renovate Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update New value References Sourcegraph
jdx/mise uses-with major 2026.9.9 source code search for "jdx/mise"

Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.


Release Notes

jdx/mise (jdx/mise)

v2026.9.9: : Dotfiles false-deletion fix, encrypted mise dot track, semantic uv options for PyPI tools

Compare Source

The dotfiles history watcher no longer records files as deleted when a checkpoint and a sync compose snapshots at the same time, mise dot track --encrypt enrolls a file with encrypted history from its first checkpoint, mise bootstrap --adopt --replace-history discards unrelated local history in one shot, and pypi: tools gain lock-aware with, expose, and dependency_prereleases options. Also fixed: packslip: installs from private GitHub repositories, stale history watchers after upgrading, global npm tools being reinstalled under lockfile = true, and the -- separator in activated PowerShell sessions.

Added

  • dotfiles: mise dot track --encrypt writes encrypt = true into the tracked declaration and encrypts the initial baseline checkpoint, for files that must never have plaintext history. [history.encryption].recipients must be configured first; if the encrypted baseline cannot be saved, enrollment fails closed and rolls back the declaration without committing history metadata. Run it as a standalone command rather than inside mise dot capture. Enabling encryption on a file that already has plaintext history does not rewrite that history. (#​13180 by @​jdx)

    mise dot track ~/.config/app/credentials --encrypt
  • bootstrap: Fresh mise bootstrap --adopt now compares existing live files against the incoming setup before creating any local history, so identical files adopt the origin's history instead of being rejected as an unrelated root (for example right after the history store was removed). Differences still pause for an explicit decision. For machines that genuinely hold unrelated local history, --replace-history discards it and adopts the setup repository's branch in one shot; --dry-run previews the local and origin commits, and a failed replacement restores the previous branch and sync state. Ordinary sync never replaces divergent history and there is no persistent force setting. (#​13182 by @​jdx)

    mise bootstrap --adopt <url> --replace-history --yes
  • pypi: Three new tool options express common uv install behavior without opaque uvx_args, and unlike free-form arguments they participate in dependency graph locking: with installs extra requirements, expose installs extra requirements and links their executables (requires uv 0.8.5 or newer), and dependency_prereleases sets uv's prerelease policy (disallow, allow, if-necessary, explicit). Setting any of them selects uv as the installer. uvx_args and pipx_args remain available as version-only escape hatches. The Ansible and Azure CLI registry entries now use these options by default; if you force pipx for one of them, clear the default with an empty list, e.g. "pypi:ansible" = { version = "latest", uvx = false, expose = [], pipx_args = "--include-deps" }. (#​13181 by @​jdx)

    [tools]
    "pypi:azure-cli" = { version = "latest", with = ["pip"], dependency_prereleases = "allow" }
    "pypi:ansible" = { version = "latest", expose = ["ansible-core"] }
  • registry: Added nubr (npm:@nubjs/runner), the Nub project's TypeScript runner for a file, package.json script, or installed bin on plain Node. (#​13191 by @​colinhacks)

Fixed

  • dotfiles: With history.sync = "sync" and a running watcher, a checkpoint could record a sorted prefix of tracked files as deleted even though they were untouched on disk; those deletions then synced to other machines and removed their copies. Two compositions in one process (the watcher's checkpoint and the sync it started) shared a single scratch git index, and one resetting it mid-flight truncated the other's tree. Each composition now uses its own scratch index, and indexes left by killed processes are swept. Files recorded as falsely deleted are still in history and can be restored from an earlier checkpoint. (#​13195 by @​jdx)
  • dotfiles: A history watcher started before mise 2026.9.5 (which moved history locks into $MISE_STATE_DIR/history/), or started with a different MISE_STATE_DIR than the shell, kept running the old process without watching the current store, while mise bootstrap services apply considered the unchanged service converged and skipped it. services apply now restarts a history-watch service whose process is not watching this store, and mise doctor and mise dot status report "running but not watching this store" instead of "not running" (service-not-watching in mise dot status --json). Users already in this state are recovered by running mise bootstrap services apply. (#​13190 by @​jdx)
  • npm: With lockfile = true in effect, an npm tool pinned in the global config was resolved with a graph-specific install identity that no automatic flow could persist, so every mise exec treated the installed tool as unsatisfied, re-ran an install pass, and warned that it was missing. Global requests now stay version-only unless resolved from an explicitly generated revision 2 global lockfile; opt in with mise lock --global. (#​13186 by @​jdx)
  • packslip: Installing from a private GitHub repository failed with 404 Not Found on the manifest because GitHub only serves private release assets through its API, not the releases/download/ URLs a packslip records. mise now falls back to the API asset endpoint using the same credentials as the github: backend (MISE_GITHUB_TOKEN, GITHUB_API_TOKEN, or GITHUB_TOKEN) with no configuration changes; signature, identity, digest, and size verification are unchanged. Tags containing / (such as @biomejs/biome@2.5.2 or monorepo tool/v1.0.0 tags) and # are also resolved correctly now. Non-GitHub hosts and GitHub Enterprise are not covered. (#​13188 by @​jdx)
  • activate: In a shell activated with mise activate pwsh, mise exec -- pnpm --version failed with unexpected argument '--version' because PowerShell's parameter binder removes the first bare -- before the mise wrapper function sees its arguments. The wrapper now recovers the separator from the raw invocation line, fixing mise exec/mise x, mise tasks add, mise dotfiles capture, mise oci run, mise generate git-pre-commit, and mise bootstrap; mise run was not affected. Open sessions pick up the fix the next time mise activate pwsh runs (normally at shell start). The doubled mise exec -- -- cmd workaround now fails in an activated shell, as it always did without activation, so drop back to a single --. (#​13202 by @​jdx)
  • registry: The dbt-fusion install test now expects dbt <version>, matching what dbt --version actually prints. (873c400 by @​jdx)

Documentation

  • The GitHub star count on mise.jdx.dev now also appears in the nav overflow menu at medium viewport widths. (#​13193 by @​jdx)

Full Changelog: jdx/mise@v2026.9.8...v2026.9.9

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.8: : Top-level mise dot command, faster brew bootstrap installs, and npm safety-check fixes

Compare Source

Dotfile management moves to the top level as mise dot, Homebrew bootstrap installs run their download, extraction, and linking stages concurrently, and several install paths are corrected: embedded aube reputation gates now report the real reason and honor --yes, PyPI tools fall back to version-only installs when a dependency graph cannot be built, lazy tools no longer trigger missing: warnings, and lockfiles no longer resurrect disabled backends.

Added

  • dotfiles: The full dotfiles command tree is now available as mise dotfiles, with mise dot as a short alias. mise bootstrap dotfiles remains supported and all three spellings share the same behavior, including bootstrap hooks around apply. Generated history-watch services now invoke mise dot watch. (#​13158 by @​jdx)

    mise dot track ~/.zshrc
    mise dot status
    mise dot history
  • dotfiles: Enabling encryption on a file that was previously saved in plaintext left older commits that blocked sync. mise dot sync --allow-plaintext-history lets that history reach the origin for one run, and the global-only setting settings.history.allow_plaintext_history = true (default false, env MISE_HISTORY_ALLOW_PLAINTEXT_HISTORY) does the same for sync, publish, the history watcher, and incoming history on pull. New saves still follow the file's encryption policy; the history guide also documents how to remove the old commits instead. (#​13175 by @​jdx)

  • registry: Added poppler (conda:poppler), providing pdftotext, pdfinfo, pdftoppm, pdftocairo, pdfunite, and the other Poppler PDF utilities. (#​13133 by @​i-api)

Fixed

  • npm: Embedded aube reputation gates (low weekly downloads, similar-name, new package name) no longer surface as a misleading user aborted mise add error when stdin is closed or no terminal is attached. Non-interactive installs now report the measured signal (for example 569 weekly downloads against the 1000 threshold) and suggest the mise-native fix, allow_low_downloads = true on the tool; an explicit "no" reports user declined to add <package>. An explicit CLI --yes now reaches the aube prompt and approves it, including auto-installs through use, exec, run, shell, and upgrade; CI mode and a configured yes = true setting alone do not approve reputation gates. (#​13123 by @​jdx)
  • pypi: Ordinary mise install of pypi:/pipx: tools no longer fails when a uv dependency graph cannot represent the package or its configuration, such as a source-only dependency or free-form uvx_args/pipx_args. mise warns and falls back to the version-only install path, reusing an existing version-only installation on later runs. mise lock and mise install --locked remain strict and still reject unsupported arguments or dependencies without usable wheels. (#​13170 by @​jdx)
  • Tools declared with lazy = true are no longer reported as missing: <tool> when entering a project or running a bare mise install, regardless of status.missing_tools; ordinary missing tools are still reported as before. (#​13169 by @​jdx)
  • backend: Backend discovery from lockfiles now skips backends listed in disable_backends. When a parent mise.lock pins a shorthand such as yarn to asdf:yarn and a child project disables asdf, mise tool yarn --backend and a fresh child mise lock now select the first enabled recorded backend or fall back to the enabled registry backend (aqua:yarnpkg/berry) instead of the disabled pin. The parent lockfile is left unchanged and explicitly installing a disabled backend still fails. (#​13178 by @​jdx)

Changed

  • bootstrap: mise bootstrap packages apply installs Homebrew packages substantially faster. Formula metadata for each dependency frontier is fetched concurrently, bottles are extracted, relocated, signed, and receipted concurrently, and each job now downloads and prepares its own bottle so prepared bottles are committed as soon as dependency order allows. All stages respect the existing jobs limit with no new settings; Cellar commits and prefix linking stay dependency-ordered, opt/<name> is linked last so an interrupted install cannot look complete, and a failure cancels queued work while cleaning up in-flight staging. On Apple silicon, a fresh install of brew:jq brew:tree brew:wget brew:just brew:shellcheck dropped from roughly 6.6s to 4.0s, and dependency resolution for brew:ffmpeg from 288ms to 112ms. (#​13151, #​13152, #​13155 by @​jdx)

Documentation

  • The npm backend, PyPI backend, and mise.lock guides now open with quick-start and everyday workflows (mise use node@24 npm:prettier, mise use python@3.14 uv pypi:black, mise lock, mise install --locked) and group dependency-graph locking, sidecar management, and strict-mode details afterward. The lockfile guide clarifies that URL-lock exemptions do not exempt dependency graphs from validation. (#​13149 by @​jdx)

Full Changelog: jdx/mise@v2026.9.7...v2026.9.8

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.7: : Lockfile revision 2 with npm and Python dependency graphs, dotfile conflict inspection

Compare Source

This release introduces mise.lock revision 2, which records complete transitive dependency graphs for npm tools (via embedded aube) and Python tools (via uv) in native sidecar files, and adds mise bootstrap dotfiles conflicts for inspecting dotfile sync conflicts before resolving them. It also lets dotfile templates consume bootstrap secrets, stops minimum_release_age from rejecting versions already committed to a lockfile, and closes a security gap in history.describe_command.

Added
  • lock: Lockfile revision 2 records the full dependency graph of npm tools installed by embedded aube and of pypi: tools installed by uv, then replays it with a strict frozen install so two projects on the same top-level version can still receive their own reviewed transitive graph. Graphs live in native sidecar files (uv.lock / aube-lock.yaml plus a manifest) under .mise/locks/<backend-tool>/<version>/, referenced from mise.lock by relative path and SHA-256 digest, so the lockfile itself stays small. Commit the sidecar directory with mise.lock. New lockfiles use revision 2; existing revision 0 and 1 files keep their format until you run mise lock --upgrade. mise lock --bump <tool> refreshes a tool's transitive graph even when its top-level version is unchanged, ordinary mise install validates and accepts hand-edited sidecars, and mise install --locked rejects digest mismatches until you run mise lock. Python graph locking requires uv 0.12.10 or newer and published wheels for the target platform; Git sources, standalone pipx installs, and free-form uvx_args/pipx_args stay version-only. (#​13131, #​13146 by @​jdx)

    mise lock --upgrade        # move an existing lockfile to revision 2 and resolve graphs
    mise install --locked      # replay the recorded graphs
    mise lock --bump pypi:black  # refresh Black's dependencies without changing its version
  • pypi: pypi: is now the preferred name for the Python CLI backend; pipx: remains fully supported as an alias with no warnings, and settings accept both pypi.* and pipx.* names. The two spellings are distinct tool identities (pypi-black vs pipx-black install directories and lock entries), so switching spelling creates a new installation. (#​13146 by @​jdx)

  • bootstrap: mise bootstrap dotfiles conflicts [PATH...] shows a read-only comparison of the saved local and fetched remote versions of a conflicted dotfile so you can decide between --take-remote and --keep-local with full context. The default output is a unified diff including file-mode changes; --difftool opens the configured Git diff.tool (falling back to merge.tool) and --tool <name> picks one explicitly. Encrypted contents are decrypted only into private temporary files, and inspection never modifies either side or marks the conflict resolved. Bootstrap secrets are also now resolved from the same composed config maps as dotfile discovery, so root-scoped dotfile templates can use secrets declared by their bootstrap root. (#​13144 by @​jdx)

    mise bootstrap dotfiles conflicts ~/.config/mise/config.toml
    mise bootstrap dotfiles conflicts --difftool ~/.config/mise/config.toml
  • dotfiles: Dotfile templates (mode = "template") can reference [bootstrap.secrets] values with {{ secret(name="...") }}, matching managed bootstrap file templates. Dotfiles commands that render templates (add, apply, diff, edit, status, unapply) accept --prompt-secrets; without an available value, rendering fails closed. A full mise bootstrap run preflights dotfile templates before making changes, mise bootstrap status reports secrets used only by dotfiles, and textual diffs redact resolved secret values. (#​13140 by @​jdx)

    [bootstrap.secrets]
    api_token = "EXAMPLE_API_TOKEN"
    
    [dotfiles."~/.config/example/credentials"]
    source = "dotfiles/credentials.tmpl"
    mode = "template"
Fixed
  • lock: Installing from a committed mise.lock no longer fails when the locked release is younger than minimum_release_age. The cutoff still applies when resolving unlocked fuzzy requests and when generating or bumping a lockfile, and npm:/pypi: still forward it to unpinned transitive dependencies, but a reviewed lock entry now reproduces immediately in CI instead of waiting for the release to cool. (#​13128 by @​jdx)
  • config: A .python-version (or other idiomatic version file) containing system selects the system interpreter without printing the mise-specific @system deprecation warning, matching the existing .tool-versions exception. Explicit python@system requests from mise configuration or command arguments still warn. (#​13132 by @​jdx)
  • npm: Embedded aube is updated to 2.2.16, fixing the Bun checksum install regression and ensuring local npm tarballs keep their manifest package name. (#​13145 by @​jdx)
  • registry: The mc shorthand uses aqua:minio/mc again now that the upstream Aqua registry entry is restored, with asdf:mise-plugins/mise-mc kept as the fallback. (#​13124 by @​jdx)
Security
  • history: history.describe_command is now global-only. Previously an implicitly trusted project could set it and have a later dotfiles history checkpoint execute the project-controlled command with unencrypted tracked-file diffs. The setting is honored only from system/global configuration or MISE_HISTORY_DESCRIBE_COMMAND; project values are ignored with a warning. (#​13134 by @​jdx)
  • oci: mise oci build now renders dotfile templates with a restricted engine: secret() is rejected and the env context, get_env(), exec(), and read_file() are unavailable, so ambient credentials cannot be baked into a publishable image layer. (#​13140 by @​jdx)
Breaking Changes
  • Lockfile revision 2 is not readable by older mise versions. Newly created lockfiles use revision 2, and existing files switch only when you run mise lock --upgrade. Upgrade collaborators and CI to this release before committing a revision 2 mise.lock, and commit the .mise/locks/ (or .config/mise/locks/) sidecar directory alongside it. Revision 2 --locked installs fail if a recorded graph is missing or its digest does not match. If you gitignore mise.local.lock, also ignore its matching sidecar subdirectory (for example .mise/locks/mise.local/).
  • history.describe_command in project configuration is ignored. Move it to ~/.config/mise/config.toml or set MISE_HISTORY_DESCRIBE_COMMAND.
  • mise oci build dotfile templates can no longer call secret(), get_env(), exec(), or read_file() or read the env context.

Full Changelog: jdx/mise@v2026.9.6...v2026.9.7

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.6: : Project daemons, mise doctor project, and vfox backend tool discovery

Compare Source

This release adds experimental project daemons backed by pitchfork, a mise doctor project command for project-declared diagnostic checks, and tool discovery from vfox backend plugins in mise search. It also changes the HTTP backend's default install layout so uninstall and prune reclaim disk space, speeds up warm lockfile_mode = "generate" installs and repeated OCI builds, and fixes a batch of nushell, monorepo, lockfile, brew, and Windows bootstrap issues.

Highlights

  • Services next to tools: [daemons] declares background processes and PostgreSQL/Redis presets in mise.toml, managed through mise daemons and optionally started when you enter the project. [doctor.checks.<name>] lets projects declare their own environment probes for mise doctor project.
  • Discovery and output: mise search, shell completion, and interactive mise use now include tools published by installed vfox backend plugins, and settings.truncate / --no-truncate disable terminal-width truncation (automatically when a coding agent is detected).
  • Storage and speed: HTTP tools now extract into their own install directory by default (opt back into deduplication with shared_extraction = true), warm generate-mode installs skip needless lockfile rewrites, and OCI builds share a local tool-layer cache.

Added

  • daemons: New experimental [daemons] section and mise daemons command family (start, stop, restart, ls, status, logs, tui) manage project background processes with pitchfork. PostgreSQL and Redis presets install the database as a tool (participating in lockfiles), supply connection environment variables and readiness checks, and keep project data across stop/start. Daemons with auto = ["start", "stop"] start when entering the project from an activated Bash, Zsh, or Fish shell and are released when the last shell session leaves. Requires experimental = true and pitchfork 2.25.0 or later; database presets are Unix-only and PostgreSQL uses loopback trust authentication intended for local development. (#​13085 by @​jdx)

    [settings]
    experimental = true
    
    [daemons]
    postgres = "18"
    redis = "8"
    
    [daemons.web]
    run = "npm run dev"
    port = 3000
    auto = ["start", "stop"]
  • doctor: mise doctor project runs checks declared in [doctor.checks.<name>] with the project's environment and installed tools, reporting PASS/FAIL/error/skipped per check in text or --json. Checks support description, hint, timeout (default 10s), dir, shell, and os selectors, run concurrently under the jobs limit, and exit nonzero when any check fails. Ordinary mise doctor does not run them, and hints are never executed. A follow-up aligned dir resolution with task conventions (config root for project configs including ~/mise.toml, ~/ expansion), fixed head-of-line blocking when one probe hangs, and kept nohup mise doctor project alive on SIGHUP. (#​13062, #​13089 by @​jdx)

    [doctor.checks.openssl]
    description = "OpenSSL development files are discoverable"
    run = "pkg-config --exists openssl"
    hint = "Run `mise bootstrap packages apply` to install the declared build dependencies."
    timeout = "5s"
    os = ["linux", "macos"]
  • vfox: Tools provided by installed vfox backend plugins now appear in mise search, shell completion, and interactive mise use, namespaced as <plugin>:<tool>. Plugins can implement BackendListTools for a finite catalog and/or BackendSearchTools for query-driven discovery in large ecosystems; a prefixed query like npm:eslint is routed only to that plugin. Results are cached, slow plugins fall back to stale cache, and existing plugins need no changes. mise registry remains registry-only. (#​13111 by @​jdx)

  • cli: New settings.truncate (and MISE_TRUNCATE, default true) controls terminal-width shortening of table cells and task metadata. mise ls, mise config ls, and mise bootstrap dotfiles status gain --truncate / --no-truncate, and output is kept complete automatically when a known coding agent is detected. (#​13112 by @​jdx)

    mise bootstrap dotfiles status --no-truncate
  • bootstrap: [bootstrap.macos.dock] gains apps, an ordered list of pinned application paths. Status compares identity and order (ignoring Dock-added metadata), apply adds, removes, and reorders application tiles while preserving other tiles and persistent-others, and an empty list removes all application tiles. Paths must be absolute or home-relative .app bundles. (#​13075 by @​azohra)

    [bootstrap.macos.dock]
    apps = [
      "/System/Applications/Utilities/Terminal.app",
      "/Applications/Firefox.app",
    ]
  • bootstrap: mise bootstrap packages where brew:<formula> prints an installed formula's stable opt root (for example /opt/homebrew/opt/unzip), so scripts can put keg-only executables on PATH without hardcoding the Homebrew prefix or Cellar version. Missing installs exit nonzero with empty stdout. (#​13083 by @​himkt)

  • dotfiles: Destination variants can omit source when every variant sets a target; the entry key is then resolved as a relative path under settings.dotfiles.root instead of next to mise.toml. Parent traversal is rejected. (#​13087 by @​jdx)

    [dotfiles."vscode/settings.json"]
    mode = "copy"
    variants = [
      { os = "macos", target = "~/Library/Application Support/Code/User/settings.json" },
      { os = "linux", target = "~/.config/Code/User/settings.json" },
    ]
  • fmt: mise fmt now sorts lists whose order has no meaning: redactions lexically, and task sources/outputs, task_templates sources/outputs, task_config.global_inputs, and input_groups by reach (@group: references, then globs, then literal paths). Lists containing ! exclusions, entries starting with template syntax, or comments are left untouched, and precedence-sensitive lists such as env_file, tools.*, includes, and depends are never sorted. (#​13058 by @​jrandolf)

  • oci: mise oci build gains --no-cache to bypass the new local tool-layer cache; entries live under each tool's cache directory and are removed by mise cache clear TOOL. (#​13056 by @​jdx)

Changed

  • http: New http: installations extract directly into their own install directory, so mise uninstall and mise prune now remove their files instead of leaving payloads in $MISE_DATA_DIR/http-tarballs/. Set shared_extraction = true on a tool to keep the previous deduplicated symlink layout. Existing symlinked installs keep working; mise install --force <tool> migrates one to independent files without disturbing other installs that share the content. Legacy http-tarballs entries are not reclaimed automatically. Shared raw and compressed binary caches now also include the executable filename in their key, so differently named tools no longer reuse the wrong filename. (#​13059 by @​jdx)
  • oci: mise oci push --no-cache now bypasses both the remote registry cache and the local tool-layer cache. (#​13056 by @​jdx)
  • registry: postgres, redis, and mongodb now prefer conda: backends, installing prebuilt conda-forge binaries in seconds instead of compiling through vfox; vfox and asdf remain as fallbacks. conda:redis-server covers Linux and macOS only. (#​13061 by @​jdx)

Performance

  • lockfile: Warm mise install runs in lockfile_mode = "generate" skip scheduling work for tools whose artifact metadata is already reusable, and skip rebuilding, serializing, and staging the lockfile entirely when nothing was installed and the on-disk lock already matches (preserving comments in the file). Explicit mise lock, forced provenance verification, upgrades, and new platforms still regenerate. (#​13101, #​13103 by @​jdx)
  • oci: mise oci push --from BASE no longer downloads base layers when the base and target live in the same repository, and oci build, oci run, and oci push share a local cache of packaged tool layers keyed on file contents, so repeated builds with overlapping tools skip tar and gzip work. (#​13055, #​13056 by @​jdx)

Fixed

  • nushell: mise activate nu no longer throws env_variable_not_found on every prompt or cd when a variable to hide is absent from the current scope; hide-env is now wrapped in try, matching the no-op behavior of other shells. (#​13071 by @​i-api)
  • task: Task-level tools are now auto-installed for tasks referenced from run entries, including names rendered at runtime, right before they execute; --skip-tools is honored and install failures are reported as task failures without blocking siblings. (#​13086 by @​jdx)
  • config: [monorepo] settings are now merged across same-directory config layers (base plus mise.<env>.toml overlays): omitted fields are inherited, an overlay's config_roots replaces the base list, and monorepo_root = false in an overlay disables the root and its descendant trust. (#​13084 by @​jdx)
  • lockfile: Runtime tool requests such as mise which hk --tool hk@latest now use the lockfile belonging to the config that effectively defines the tool, instead of merging project and global pins and reporting a false "multiple resolutions" ambiguity or selecting an overridden pin. mise which --tool warns when a lower-precedence config has a matching pin the effective config lacks. (#​13042 by @​nettlesh)
  • lockfile: Complete lockfile generation for Packslip tools skips platforms with no published artifact while still writing supported targets, and a verified Packslip signer may now replace legacy github-attestations metadata on upgrade instead of being rejected as a provenance downgrade. (#​13102, #​13105 by @​jdx)
  • upgrade: mise upgrade now detects updates between letter-suffixed versions such as tmux 3.7b to 3.7c; sub-N aliases keep resolving numeric components as before. (#​13119 by @​jdx)
  • brew: Formulae that are keg-only solely because macOS ships them (such as brew:zip and brew:unzip) are now linked into <prefix>/bin on Linux, matching Homebrew. Kegs installed by earlier mise versions stay unlinked until the next mise bootstrap packages upgrade or a reinstall. (#​13108 by @​lil-lon)
  • brew-cask: Tap casks with preflight_steps or postflight_steps no longer fail during metadata extraction; declarative run steps are captured as structured steps and executed by mise, with support for must_succeed = false. (#​13060 by @​jdx)
  • bootstrap: mise bootstrap remote on Windows now finds ssh.exe and tar.exe on PATH instead of failing with required command 'ssh' not found. (#​13117 by @​JamBalaya56562)
  • bootstrap: macOS defaults status explains type mismatches, showing for example 2 (real; expected integer) instead of two identical-looking values marked differs. (#​13096 by @​jdx)
  • dotfiles: mise bootstrap dotfiles track honors the global yes setting for confirmations, and warns when tracking a symlink whose resolved source is not itself tracked, suggesting the command to enroll it. (#​13072 by @​nettlesh, #​13095 by @​jdx)
  • schema: The JSON schema now models Git directory manifest dotfile entries, restricting explicit modes to copy or symlink-each and rejecting combinations with inline content or file-edit fields. (#​12741 by @​risu729)
  • asdf: mise asdf install and mise asdf reshim no longer re-enter the full CLI dispatch, avoiding stack overflows on small-stack Linux environments; asdf install now follows the same implicit config trust as mise install. Bash completions are regenerated for the updated usage-rs word-break handling. (#​13114 by @​jdx)

Registry

  • Added mpv (conda:mpv, Linux and macOS) (#​13049 by @​i-api), agent-browser (aqua:vercel-labs/agent-browser) (#​13088 by @​3w36zj6), and himalaya (github:pimalaya/himalaya) (#​13091 by @​i-api).
  • editorconfig-checker installs again after 4.0.1 renamed its assets and executable; the shorthand now uses the GitHub backend. (#​13098 by @​jdx)
  • mc installs from MinIO's GitHub releases instead of the retired Aqua download URL that returned HTTP 410. (#​13113 by @​jdx)

Documentation

  • The docs landing page gains interactive diagrams for project environment switching, bootstrap machine resources, tool configuration precedence, artifact cache execution, and tracked dotfile synchronization. (#​13065, #​13066, #​13067, #​13068, #​13069 by @​jdx)
  • The task-running guide is reorganized around finding and running tasks, passing arguments, then controlling execution. (#​13077 by @​azohra)

New Contributors

Full Changelog: jdx/mise@v2026.9.5...v2026.9.6

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.5: : macOS defaults, per-platform dotfiles, and complete lockfiles

Compare Source

This release deepens macOS bootstrap support with current-host and nested defaults, lets dotfiles and tasks adapt to the platform and to parsed arguments, and adds an opt-in trial of complete lockfile generation. It also carries a batch of install progress, self-update, brew-cask, and sandbox fixes.

Added

  • bootstrap: New [[bootstrap.macos.defaults_entries]] blocks let you set macOS preferences explicitly with domain, key, value, and an optional host (any by default, or current), covering preferences normally written via defaults -currentHost while keeping the existing [bootstrap.macos.defaults] shorthand. Entries also accept an optional path to patch a nested dictionary value without replacing its siblings, preserving property-list types and creating missing parents. (#​12983 by @​azohra, #​12984 by @​azohra)

    [[bootstrap.macos.defaults_entries]]
    domain = "com.apple.dock"
    key = "autohide"
    value = true
    host = "current"
  • bootstrap: More friendly macOS preferences: Finder folder sorting and default cloud save location, Dock autohide delay and timing (integers or floats), and keyboard automatic capitalization and spelling correction, all using snake_case names consistent with the existing sections. (#​13032 by @​jdx)

  • bootstrap: [bootstrap.files] and [bootstrap.directories] entries gain phase = "pre-packages" so repository definitions, apt sources, and signing keys can be applied before package installation instead of only afterward. Existing declarations default to "post-packages". (#​13052 by @​jdx)

    [bootstrap.files."/etc/apt/sources.list.d/vendor.sources"]
    source = "./files/vendor.sources"
    phase = "pre-packages"
  • bootstrap: Ordinary [bootstrap.files] templates can now reference resolved [vars] values, alongside the existing config_root, target, and secret() helpers. (#​13033 by @​nettlesh)

  • dotfiles: A single dotfiles source can deploy to different destinations per operating system, architecture, or mise profile using variants with an optional target. This works for copy, symlink, symlink-each, and template modes. (#​13050 by @​jdx)

    [dotfiles.settings]
    source = "dotfiles/vscode/settings.json"
    mode = "copy"
    variants = [
      { os = "macos", target = "~/Library/Application Support/Code/User/settings.json" },
      { os = "linux", target = "~/.config/Code/User/settings.json" },
    ]
  • task: Task sources and outputs can now use {{usage.*}} templates, resolved per invocation from parsed arguments and flags before freshness and artifact-cache checks run, so different argument values track freshness independently. (#​13051 by @​jdx)

  • brew-cask: Casks with structured set_permissions preflight/postflight steps now install correctly (for example brew-cask:blender), running an unprivileged chmod over resolved staged or appdir paths instead of failing with an unsupported step-type error. (#​13043 by @​azohra)

  • lock: Opt-in trial of complete lockfile generation via lockfile_mode = "generate" (or MISE_LOCKFILE_MODE=generate). The default remains incremental merge. Generate mode rebuilds lockfiles from current requests while treating the previous file as an immutable baseline, reusing unchanged artifacts and publishing through staged atomic writes so failures or concurrent edits do not clobber a good lockfile. This mode records only cryptographically verified provenance per target platform; provenance_verified is no longer treated as a trust signal. (#​13031 by @​jdx)

  • self-update: New disable_update_warning setting (MISE_DISABLE_UPDATE_WARNING) suppresses "newer mise available" notices in mise version, mise --version, and mise doctor. Explicit self-update and automatic updates are unaffected. (#​13028 by @​jdx)

Fixed

  • install: Interactive installs no longer leave a permanent line for every resolved, skipped, or already-installed tool; live progress shows what is happening while the final summary lists what changed (for example installed 1 tool in 1.1s: dummy@1.0.0). mise upgrade no longer duplicates its old to new version list. (#​13030 by @​jdx)
  • install: Long non-TTY installs no longer flood CI logs with a snapshot every three seconds. The heartbeat now scales to roughly 10% of elapsed time, clamped between 3 seconds and 1 minute. (#​13036 by @​jdx)
  • self-update: On 32-bit ARM, mise self-update now selects the correct linux-armv7 archive instead of requesting a missing linux-arm one and falling back to an ARM64 binary that failed signature verification. A missing archive now fails asset selection rather than picking the wrong architecture. (#​13023 by @​jdx)
  • self-update: npm installs now ship the instructions file that redirects update guidance to the package manager, so they no longer advertise mise self-update. (#​13028 by @​jdx)
  • brew-cask: mise bootstrap packages upgrade no longer replaces the bundle of a running self-updating app (for example Chrome), which could strand helper processes and blank out tabs. Such apps are skipped while running and left to update themselves. (#​13041 by @​azohra)
  • brew-cask: The cask metadata fetch error no longer includes stale advice about installing with brew and a broken documentation anchor; it now gives a short, accurate message. (#​12800 by @​Marukome0743)
  • bootstrap: mise bootstrap dotfiles origin set <url> now uses the repository's own default branch when --branch is omitted, so repositories on master connect correctly instead of publishing a second root branch. A missing requested branch is now reported clearly rather than mistaken for an empty repository. (#​13037 by @​Dhaulagiri)
  • dotfiles: History watcher locks now live alongside the history store in the state directory instead of being hashed into the cache directory, so a launchd watcher and an interactive shell using different cache directories coordinate correctly and dotfiles status no longer misreports declared-not-running. Existing watchers must be stopped and restarted with the updated binary. (#​13038 by @​ascarter)
  • sandbox: The macOS Seatbelt profile now allows file-read-metadata on the ancestors of readable paths, fixing Operation not permitted failures when a portable Ruby resolves its own executable during third-party tap evaluation. Symlinked data directories and allow-listed paths are also handled. (#​13039 by @​Marukome0743)

Registry

New Contributors

Full Changelog: jdx/mise@v2026.9.4...v2026.9.5

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.4: : Nix Bootstrap, Environment Selectors, and Man Pages

Compare Source

This release expands the bootstrap package model with Nix support and environment selectors, teaches packslip tools to ship man pages, and adds a task-scoped quiet setting. It also carries a wide batch of packslip, bootstrap, and cross-platform fixes plus a major speedup to dotfiles history rebuilds.

Added

  • bootstrap: Nix is now a built-in [bootstrap.packages] manager on Linux and macOS. Declare packages with the nix: prefix and apply them through your normal Nix profile; the manager supports use, apply, status JSON, and targeted upgrades while leaving Nix sources, caches, trust, and profile rollback under Nix control. This also adds mise bootstrap packages export --format nix to emit a deterministic NixOS module from your nix: declarations and packages use --no-install to record declarations without touching package managers. (#​13013 by @​jdx)

    [bootstrap.packages]
    "nix:ripgrep" = "latest"
  • bootstrap: [bootstrap.packages] entries gain an env selector (a single environment or a list), so a package is only enabled when one of its listed mise environments is active via -E or MISE_ENV. When both os and env are set, both must match. Packages for inactive environments stay declared and are protected from pruning. (#​12956 by @​jdx)

    [bootstrap.packages]
    "brew:postgresql" = { version = "latest", env = ["dev", "test"] }
  • packslip: Packslip-installed tools can now ship man pages declared as static man resources, alongside completions and agent skills. While a tool version is active, mise prepends its man root to MANPATH and keeps system and caller-defined paths visible, so man <tool> works. Existing installs need to be reinstalled to pick up man pages. (#​13012 by @​jdx)

  • task: New task.quiet setting (and MISE_TASK_QUIET) suppresses mise's own task messages, prefixes, and command-echo headers without hiding task output or affecting other commands. The bundled output = "quiet" mode is deprecated in favor of explicit output style plus this setting; removal is scheduled for 2027.9.3. (#​12980 by @​jdx)

Fixed

  • install: A lazy tool whose depends target is also lazy now installs correctly on first use through a shim, mise x, or a task; mise installs the provider together with its still-missing configured dependencies instead of failing the preflight. (#​12997 by @​balintant)
  • backend: 32-bit ARM resolution now uses Go's canonical arm architecture name for Aqua (so registry replacements apply), and automatic GitHub release asset selection no longer picks a generic source.tar.gz when no published binary targets the host. (#​13004 by @​jdx)
  • bootstrap: Homebrew bottles with hard-linked Mach-O executables are now signed correctly on macOS. Every hard-link alias is tracked and included in the signing list after relocation, fixing cases like fish where an aliased binary was killed with SIGKILL after a successful install. (#​12988 by @​nettlesh)
  • packslip: mise lock --platform now verifies the signed release manifest and records the correct URL, checksum, size, and signer for each requested target platform (including Windows x64), so locked installs work across platforms. (#​13002 by @​jdx)
  • packslip: On glibc Linux, an artifact's glibc_min is now honored during selection: when the GNU build requires a newer glibc than the host, mise falls back to a matching static musl build if one exists. (#​13009 by @​jdx)
  • packslip: Windows installs now link shims with the correct .exe filename, while Unix keeps extensionless names. (#​13006 by @​jdx)
  • packslip: Activated man roots are now scoped to Packslip-backed tool versions, and the caller's original MANPATH is included in the environment-cache identity so one cached process cannot serve another cal

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the bot label Jul 20, 2026
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 6 times, most recently from b069281 to 4210d96 Compare July 30, 2026 03:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 7255dd3 to 18a73a9 Compare August 5, 2026 03:26
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 2752ba1 to 661a5bf Compare August 12, 2026 20:16
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 6445a85 to c5325ef Compare August 20, 2026 23:10
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 9dd559c to fac6f2e Compare August 26, 2026 03:48
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from 61548e9 to 844f10e Compare September 3, 2026 00:28
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 4 times, most recently from b504efd to 25c7628 Compare September 11, 2026 04:03
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch 3 times, most recently from 6034a8a to f714847 Compare September 14, 2026 20:44
@renovate
renovate Bot force-pushed the renovate/jdx-mise-2026.x branch from f714847 to 6e7311c Compare September 15, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants