Repository navigation
Update dependency jdx/mise to v2026.9.12 - #110
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.9.1→2026.9.12v2026.9.18(+5)Release Notes
jdx/mise (jdx/mise)
v2026.9.12: : Tasks that require daemons, worktree-aware ports and URLs, Scoop and zypper packages, and official Docker imagesCompare Source
The experimental
[daemons]system grows substantially: tasks can declare the daemons they need,[daemon_groups]selects subsets of a project's services,port = "auto"and stable<NAME>_URLhostnames let several git worktrees run the same stack side by side, and CockroachDB, NATS, and SpiceDB join the PostgreSQL and Redis presets. Outside daemons,[bootstrap.packages]gainsscoop:andzypper:managers,mise install --systemelevates with sudo only for the final publish step, official mise images are published to GHCR and Docker Hub, and a run ofbrew-caskfixes lets many more casks install unattended.Highlights
[tasks.x] daemons = [...]starts and waits for services before a task runs, daemons can run a mise task,[daemon_groups]andmise daemons start <group>select subsets, andmise daemons register,urls, andpruneround out the lifecycle. Worktrees get deterministic ports, hostnames, and optionally checkout-localdata_dirstorage without hand-assigned numbers.brew-casknow picks the right build for the host macOS release, runs installers that need sudo, applies pkg installer choices andset_ownershipsteps, upgrades pkg-only self-updating casks, and survives DMGs with license prompts or unreadable metadata;brew:resolves formula aliases such asopenssl.enterhooks fire again when a shell starts inside a project, npm tools with only pre-releases resolvelatestagain, generatedpre-pushhooks no longer append git's arguments to the task command, andmise installrefuses a lockfile entry whose download URL names a different release than itsversion. Lockfile sidecars now verify on Windows checkouts with CRLF line endings.Added
daemons: Tasks can require daemons and daemons can run tasks.
daemons = ["postgres", "nats"](ortruefor all project daemons) on a task starts them via pitchfork, waits for readiness, and then runs the task; already-running daemons are left alone, and--skip-deps/--dry-runskip them. A daemon can declaretask = "dev:core"withargsinstead ofrun, andinit = [...]runs idempotent setup commands before the long-running process on every start.mise tasks infoshows a task's daemons. (#13340)daemons:
[daemon_groups]names project-scoped subsets of daemons; groups may nest other groups and work wherever a daemon name does, including--group.mise daemons startwith no arguments now starts thedefaultgroup when a project declares one, and every project daemon otherwise. (#13347)daemons: A daemon entry with
project = "../other-checkout"and optionalnameruns a daemon defined in another project under that project's tools, environment, and data, and can be used independs.[daemons_settings] namespace = "services"gives daemons stablenamespace/nameIDs (with a per-worktree suffix unlessnamespace_per_worktree = false). Requires pitchfork 2.25.0 or later. (#13339)daemons:
port = "auto"(orport = { auto = true, base = 3000, stride = 1 }for custom daemons) keeps the base port in the primary checkout and derives a deterministic offset in each linked git worktree. Resolved ports are exported before startup asPGPORT/DATABASE_URLfor presets and<NAME>_PORTfor custom daemons, andmise daemons ls --jsonreportsportandport_auto. mise does not fall back to another port; startup diagnoses conflicts with running mise-managed daemons in other projects, and two daemons in one project claiming the same port now fail at config load. (#13342)daemons: Every daemon with a
portgets a stable hostname served by pitchfork's reverse proxy, exported as<NAME>_URL(for exampleapi.shop.localhostin the primary checkout, orapi.shop-pr-42.shop.localhostin a linked worktree). Per-daemonproxy(a label,true, orfalse) andproxy_tls("terminate"or"passthrough") control routing; thepostgresandredispresets opt out.mise daemons urlslists hostnames, ports, proxy modes, and status. Setproxy = falseon custom daemons that do not speak HTTP. (#13368)daemons: CockroachDB (
preset = "cockroachdb"), NATS ("nats"), and SpiceDB ("spicedb") presets install the tool, initialize data, wait for readiness, and exportDATABASE_URL,NATS_URL,SPICEDB_ENDPOINT, andSPICEDB_PRESHARED_KEY. Presets now support named-port overrides such asports.http_port = 8081and typedoptions. Unix-only; NATS and SpiceDB readiness checks needcurl. (#13346)daemons:
mise daemons registerinstalls missing tools, validates the daemon graph, and registers pitchfork configuration without starting anything, so a fresh checkout can start on its first hostname request. (#13399)daemons:
mise daemons prunefinds daemon state left behind by deleted projects and worktrees, shows paths and sizes, and removes it after confirmation (--dry-runpreviews,--yesconfirms ordinary cases).mise daemons ls --jsonaddsroot,state_dir,data_size, anddata_size_human. (#13338)daemons:
data_dir = ".data/postgres"keeps a preset's persistent data inside the checkout (relative to the project root; absolute and~/paths also work), so each worktree gets its own database. Changing the path does not move existing data. (#13408)bootstrap: A
scoopmanager for Windows."scoop:extras/vscode" = "latest"adds the bucket if missing, pinned versions install viaapp@version,state = "absent"uninstalls, and--updateopts in toscoop update. Only user-scope installs are managed; entries are skipped on other platforms. (#13324)bootstrap: A
zyppermanager for openSUSE and SUSE Linux Enterprise, supporting status, install,name=versionpins (including downgrades), upgrade, and removal, with retries when zypper asks for a package-manager restart. (#13335, @m407)bootstrap:
process_typeon[bootstrap.macos.launchd.agents.*]maps to launchd'sProcessType(Background,Standard,Adaptive,Interactive); misspellings are rejected at config time instead of being silently ignored by launchd. (#13402, @waynehoover)install:
mise install --systemon Unix downloads, verifies, and unpacks as the invoking user, then uses sudo only to publish into the system install and shim directories. Supports relocatable tools fromaqua,github,gitlab,forgejo,http, ands3without a tool-levelpostinstall;system_packages.sudo = falsedisables elevation. (#13384)docker: Official release images at
ghcr.io/jdx/miseandjdxcode/miseforlinux/amd64andlinux/arm64, built from the minisign-verified release binaries. Tags2026.9.12,2026.9, andlatestare a scratch image forCOPY --from=;*-debiananddebianare a Debian slim base withcurlandgit. (#13413)config:
unixis accepted as anosselector in[tools],[bootstrap.packages],[doctor.checks], and[dotfiles]variants, matching every non-Windows platform. A concrete OS variant still wins over aunixone. (#13395)go: With
goinidiomatic_version_file_enable_tools, thetoolchainline of an activego.workselects the Go version and, as with thegocommand, membergo.modfiles are ignored in workspace mode.GOWORK(auto,off, or an absolute path) is honored. (#13337)bazel:
.bazelversionis an idiomatic version file forbazelwhen enabled; only concrete releases are read, solatest,last_green,8.x, and commit hashes select nothing rather than failing. (#13336)tasks: File-task
#USAGE include file="..."paths may be relative to the task file or use environment variables such as$MISE_CONFIG_ROOT,$MISE_TASK_DIR, and$MISE_PROJECT_ROOT, so shared flagsets no longer need absolute paths. (#13372)dotfiles:
mise dot applynow runs matching[history.reload]commands for the targets it actually wrote, once each after all writes;--dry-runand no-op applies run none. (#13414)registry: Added
codegraph(aqua:colbymchenry/codegraph). (#13355, @3w36zj6)Fixed
enterhook again; a regression in 2026.9.x had limited it tocdinto the project. (#13383)@deepseek-ai/dsh) is no longer reported missing aftermise use npm:...@latest;latestfalls back to the newest installed pre-release when no stable version is installed. (#13390)npm:tool no longer fail withfailed to acquire project lock: Permission denied. (#13379)mise generate git-pre-commithooks pass only the message file ("$1") forcommit-msg,prepare-commit-msg,applypatch-msg, andsendemail-validate, and no arguments for other hooks, so apre-pushtask no longer runsnpm test origin <url>. Existing hooks change when regenerated. (#13377)mise installfails before downloading when a locked platform URL provably names a different release than the entry'sversion(for example after a tool bumpedversioninmise.lockwithout refreshing the platform block, or a release dropped a platform).mise lockstill repairs the entry. (#13401).mise/locks/verify on Windows checkouts where git rewrote them to CRLF, digests recorded from CRLF bytes by older versions keep working and heal on the next ordinary install, and a relocated sidecar is pinned to the bytes actually written. Repositories can drop.mise/locks/** -textworkarounds. (#13398, #13403, #13407)variationsentry Homebrew publishes for the host macOS release instead of always the newest release's build (Raycast on Sequoia now gets 1.104.x, not the Tahoe-only 2.x), and reportsnot available for this platformfor null variations. (#13376)sudo: true(such aslogi-options+) run through mise's sudo path, and$HOMEBREW_PREFIX/$APPDIRplaceholders in installer paths and arguments are expanded. (#13380)choices(microsoft-outlook,microsoft-teams) install viainstaller -applyChoiceChangesXML; casks whose flight steps useset_ownership(parsec) install; andmise bootstrap packages upgradehandles self-updating casks that install only from a.pkg(tailscale-app,karabiner-elements) by comparingpkgutilreceipt versions. (#13385, #13386, #13387)staged_path, unblocking casks such as AeroSpace. (#13369, @soodoh)hdiutil'sAgree Y/N?prompt, and DMGs with unreadable root metadata such as.Trashes(for examplemysqlworkbench) extract instead of failing withPermission denied. Applies tobrew-cask,macos-app, and aqua DMG downloads. (#13353, @hisaac; #13378)openssl->openssl@3,act_runner->gitea-runner) resolve forbrew:packages and tap formula dependencies instead of failing with a 404; mise warns to use the canonical name sostatuscan track it. (#13382)winget:Git.Gitandwinget:git.git) that disagree onstateorversionare rejected with both names, instead of converging differently per machine. Entries kept apart byosorenvselectors are not compared. (#13334)raw.githubusercontent.com, so private Homebrew taps resolve. (#13345, @waynehoover){{ version }}inplatforms.<target>.urlis rendered with the resolved version for the GitHub, GitLab, and Forgejo backends, so versioned source archives can followlatest. (#13359, @casparbreloh)No versions found;latestresolves directly through the module proxy orgo list, and release dates are fetched only for the newest versions.minimum_release_agestays exact by dating individual undated candidates on demand. (#13362, #13364)mise tasks validaterecognizes child monorepo task references such asdepends = ["//crates/gui:dev"]independs,depends_post,wait_for, and structuredrun. (#13373, @nettlesh)ready_cmdandhealth_cmdprobes run in the owning project's mise environment, so a supervisor shared by several worktrees no longer probes one checkout with another'sAPI_PORT. (#13396)mise dot editopens tracked files (mode = "track") in place and inlinecontententries in their declaring config, instead of failing withNo such file or directory; it warns when editing a tracked symlink whose destination history does not capture. (#13332)0700~/.claudeholding a trackedsettings.jsonis recreated private on a new machine rather than0755. (#13412)mise dot origin setandmise dot syncnow names the commands for each way out. (#13411)Documentation
runscript. (#13388)Breaking Changes
latesttag:ghcr.io/jdx/mise:latestandjdxcode/mise:latestare now the scratch image (static binary and CA certificates, no shell). CI and dev-container users should switch to thedebiantag and install their tools explicitly; the previous source-built image remains under the unsupporteddevtag. (#13413)versiondisagrees with a platform URL now failmise installinstead of silently installing the wrong release. Runmise lockto regenerate the entry. (#13401)mise generate git-pre-commit, non-message hooks no longer receive git's arguments. To keep them, edit the hook to use"$@"and declare the arguments withusage. (#13377)stateorversionare rejected; delete one entry. (#13334)mise daemons startwith no arguments starts only thedefaultgroup when one is declared; a project with two daemons resolving to the same port fails to load; custom daemons with aportnow export<NAME>_PORTand<NAME>_URL, so setproxy = falseon non-HTTP daemons. (#13347, #13342, #13368)New Contributors
Full Changelog: jdx/mise@v2026.9.11...v2026.9.12
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.11: : macos-app bootstrap packages, task template inheritance for flags and file tasks, and Swift on Linux fixesCompare Source
A new
macos-appbootstrap manager installs.appbundles from a pinned URL and checksum when no Homebrew cask exists, task templates now composeusageflags and can be extended from file tasks, and Swift on Linux picks its distro build from swift.org's release index instead of a hard-coded map that 404'd on arm64 and on newer Fedora, Amazon Linux, and Arch hosts. Install failures also become far more actionable: errors name theminimum_release_agecutoff that hid every version, the child's last stderr line, or the shared libraries a Swift toolchain cannot load.Highlights
"macos-app:<name>"entries in[bootstrap.packages]download, checksum-verify, and install a.appinto/Applicationsusing mise's existing cask pipeline, with stricter ownership rules for apps already at the target.extendsa template now inherits the template'susageflags alongside its own, file tasks can write#MISE extends="...", and a template'svarscan read the values the extending task supplies.Added
bootstrap: The
macos-apppackage manager installs a macOS.appbundle from a vendor or internal download.version,url,sha256, andartifactare all required ("latest"is rejected because mise cannot discover releases behind a plain URL);{{version}}is interpolated intourl, so a release bump is a two-field edit. Only.dmgand.ziparchives containing an app bundle are supported, state is kept in mise's state directory rather than Homebrew's Caskroom, and an app already at the destination that this entry does not own is refused unlessadopt = trueand the contents match.mise bootstrap packages upgradecannot discover new versions for these entries, andprune --manager macos-appis unsupported. Preferbrew-caskwherever a cask exists. (#13279)tasks: A task that names a template with
extendsand declares its ownusagenow gets the template's flags too, listed first in--help. Previously the task's spec replaced the template's entirely, so shared flags had to be copied into every task. Workspace-root task defaults still only fill inusagewhen the task has none. A flag declared in both places is listed twice; declare each flag in one place, or use usage flagsets for replacements. (#13310)tasks: File tasks (including remote HTTP and
git::scripts) can use#MISE extends="<template>"in their header to inherit tools, env, description, aliases, and other fields from a task template; previously the field was warned about and ignored. A task whose command is a script file no longer picks up a template'srun. (#13307)swift: When a Linux install fails its
swift --versioncheck, mise runslddover the toolchain and lists every unresolved shared library (for examplelibform.so.6, libncurses.so.6, libpanel.so.6on an Arch-family host running a ubi9 build), with the tool'sinstall_envapplied so anLD_LIBRARY_PATHremedy is not misreported.docs/lang/swift.mddocuments the workaround. (#13319)Fixed
<platform>-<arch>download directory. (#13293, fixes #13291)ID_LIKEconsulted (Linux Mint gets an Ubuntu build) and unknown distros such as Arch falling back toubi9. Every compromise is announced with a warning, musl hosts and unsupported architectures fail before downloading, andswift.platformstill overrides selection without contacting swift.org. Theswift_platformlockfile option now records the host as detected (e.g.fedora40instead offedora39); mismatched entries are re-resolved on the next lock. (#13297, fixes #13289)install_envvalues are now rendered as templates like other tool options, soLD_LIBRARY_PATH = "{{env.HOME}}/.local/lib/compat"reaches the install subprocess expanded rather than literally.{{version}}is left unchanged. (#13314)minimum_release_age(default24h) hides every candidate, the error names the setting and cutoff, how many releases it hid, the newest one with its release and eligibility dates, and a copy-pasteable exact pin to install it now, instead ofno versions found ... matching date filter. A query that matched nothing is no longer blamed on the filter. (#13308)exit code 127; last stderr: swift: error while loading shared libraries: libncurses.so.6 .... This also reaches the final error block under--quiet, where stderr was previously never shown. (#13315)usagespec now reports the task name and the parser's diagnostic (invalid usage spec for task 'deploy'followed by the reason) instead of a bareInvalid usage config; file tasks render the same diagnostic rather than a Debug dump, and a missing or unreadable script is reported as such rather than as a bad spec. (#13312)varscan now read the vars the extending task supplies, so{{ vars.opt | default(value='none') }}in a template sees the task'soptinstead of always taking the default. Literal vars within a single task are also bound first, sovars = { msg = "hi {{ vars.who }}", who = "world" }works regardless of declaration order. Config-level[vars]are unchanged. (#13322)latestand version-prefix links underinstalls/<tool>/that point at an install no longer eligible for a link (for example a directory left with anincompletemarker by an interrupted install) are now removed on rebuild instead of surviving indefinitely. Configured aliases, hand-made names, and absolute symlinks are left alone. (#13288)1.3.1-3no longer claim thelatest,1, and1.3runtime symlinks or satisfy"latest"/prefix requests over the newest stable install; links an older mise already wrote are cleaned up on the next install. An exact request or theprereleaseoption still selects them. (#13272 by @pataar)mise lock --globalon amise.locksymlinked into a dotfiles repository now keeps native dependency sidecars beside the target lockfile, somise install --lockedworks from a fresh checkout. If you used this layout on 2026.9.7 through 2026.9.10 and see missing sidecars, runmise lock --globalagain to repair the pointers. (#13268 by @nettlesh)lockfile_mode = "generate",mise unusenow removes the tool's entry frommise.lockand its.mise/locks/...sidecar immediately rather than leaving them until the nextmise installormise lock. Merge mode is unchanged. (#13304)conda:packages that have nothing to activate (noactivate.dscripts, no dependency executables, no script entry points) are now plain symlinks instead of shell launchers, so tools likeconda:ripgreporconda:ghno longer prepend the conda prefix to thePATHof every child process and skip the extra shell. Packages that need activation keep their launcher; Windows is unchanged. A relativeMISE_DATA_DIRis also handled. Existing installs keep their current entries until reinstalled withmise install --force conda:<pkg>. (#13305)postinstallhook now receives pre-tools[env]from the config on every backend (http, aqua, github, cargo, npm, core tools), not only for asdf plugins, and a hook that changes an env input is visible to hooks ordered after it. (#13316)version_prefix(taga-a-1.2.3withversion_prefix = "a-", listed asa-1.2.3) can now be installed;prefix + versionis tried first so every listed version round-trips to its tag. If a repo publishes botha-1.2.3anda-a-1.2.3, requestinga-1.2.3now resolves to the doubled tag. (#13317)Changed
jobsconcurrency before the serial install pass, so--jobs/MISE_JOBSnow speed up cask-heavy runs. Placement (mounting, swapping app bundles) remains serial. (#13282 by @waynehoover)Security
fstatat/openat/readlinkat), so a path component swapped mid-check cannot make mise compare against a different tree than the one it will replace. Digests are unchanged, so existing receipts remain valid; large files are now hashed in-process, which can make adoption checks slower. (#13294)Documentation
macos-appdownloads and app ownership. (#13298)[vars]resolve and why a task-local override does not recompute a top-level var that already referenced it, with task templates as the way to defer a fragment. (#13323)flagset,use, andinclude, in both TOML and file tasks. (#13313)New Contributors
Full Changelog: jdx/mise@v2026.9.10...v2026.9.11
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.10: : shims.exclude, npm allow_exotic_deps, bulk dotfiles conflict resolution, and Windows Ctrl-C handling for tasksCompare Source
New settings let mise manage a tool without claiming its command names (
shims.exclude) and approve non-registry npm dependencies (allow_exotic_deps),mise dot pullcan decide every sharing conflict at once, and vfox plugin hooks gaincmd.streamplus a workingcmd.exectimeout. On the fix side,mise runnow survives Ctrl-C on Windows instead of orphaningcmd.exe, fish shells launched through shims start much faster with correct PATH order, and several task-resolution, lockfile, and Homebrew cask bugs are corrected.Highlights
settings.shims.excludekeeps names likepythonresolving to the OS while mise still manages the tool;allow_exotic_depsapproves specific npm packages fetched from git or tarball URLs; exactpackslip:pins install during aminimum_release_agecooling window; andmise upgrade --bumpkeeps SemVer build metadata such as+k3s1.mise dot pull --take-remote-all/--keep-local-allresolve all conflicts in one command, paths that cannot be decided are held rather than aborting the pass, and a directory sitting where a tracked file belongs is now reported as exactly that.ns:tasknames no longer duplicates the prefix, and fish startup throughmise exec/shims is no longer quadratic in the number of tools.Added
shims:
settings.shims.exclude(envMISE_SHIMS_EXCLUDE) lists command names mise never creates shims for. The tool stays installed and version-qualified names likepython3.12still resolve through mise, but the excluded name resolves to whatever else is onPATH; existing shims for those names are removed on the nextmise reshim. Note that undermise activatewithout--shimsthe tool'sbindirectory still joinsPATH, and excludingpython3meanspython3 -m venvsilently uses the system interpreter. (#13266)npm:
allow_exotic_depsapproves dependencies that aube'sblockExoticSubdepsgate would otherwise block because they come from a git,file:, or direct tarball URL. List package names to exempt only those (the gate stays on for the rest of the graph), or settrueto exempt the whole graph. Applies to theaubeandaube_cliinstallers. Embedded-aube installs now also warn wheninstall_envis set, since it never reached the in-process installer. (#13231)dotfiles:
mise dot pull --take-remote-alland--keep-local-alldecide every pending conflict at once, with per-path--take-remote/--keep-localnaming exceptions. The two blanket flags are mutually exclusive, and paused-sync and adoption messages now point at them. (#13233)mise dot pull --take-remote-all --keep-local ~/.bashrcbootstrap: Every string value in
[bootstrap.linux.systemd.units]and[bootstrap.macos.launchd.agents]is rendered as a template before the unit file or plist is written, so{{ config_root }}/.envinenvironment_fileresolves to the declaring config's directory. Values without template syntax (including%hand$HOME) pass through untouched,exec()is rejected, and a unit whose template fails is skipped by name without blocking the others.[bootstrap.services]is not yet templated. (#13227)hooks: Each
MISE_INSTALLED_TOOLSentry passed topostinstallhooks now carriesrequested_version(for examplelatest,22, or an alias) alongside the resolvedversion, so a hook can tell a floating request from a pin. The field is always present; existing hooks readingname/versionare unaffected. (#13274)vfox plugins:
cmd.streamruns a command with stdin connected and stdout/stderr streamed to the terminal, for hooks that genuinely need input such as a login or license prompt; it pauses the progress renderer and holds the terminal exclusively while it runs.cmd.execandos.executenow detach stdin unless--rawis set, matching every other subprocess mise spawns, so a plugin that read stdin throughos.executeshould switch tocmd.stream. (#13261)vfox plugins: The
timeoutoption oncmd.exec(andcmd.stream) now works instead of being silently ignored. It takes seconds (fractions allowed); on expiry the spawned shell is killed and the call raises a catchable error. Only the shell mise spawned is killed, so background processes it started may keep running. (#13263)Fixed
mise runno longer kills mise immediately and leaves acmd.exebehind stuck onTerminate batch job (Y/N)?. The first Ctrl-C lets running commands exit and stops scheduling new tasks; a second one takes the remaining process tree down. Tasks ended by the console are reported as interrupted instead of failing with exit code -1073741510. (#13226)teststask withalias = "test"could shadow atesttask in the current directory, depending on alphabetical order. Aliases still resolve wherever no task claims that name. (#13230)mise run '//...:lint'or'*:lint'no longer silently drop file tasks (mise-tasks/lint.sh) when a sibling package has an exact match. The same-package dedup that stopshelloandhello.shrunning twice is preserved. (#13277)update:deps:no<TAB>no longer producesupdate:deps:update:deps:no-cooldown. Reinstall the script withmise completion bash --installif yours predates the prefix-aware wrapper. (#13276)mise execor a shim emitted onefish_add_pathper directory, which made startup quadratic (over 1s with ~80 tools) and reversed mise's PATH order relative to bash. A single batched call restores both. (#13235)--take-remote-all/--keep-local-allno longer aborts the whole pass when one path cannot be decided (a directory on the live side, or unsaved local changes under--keep-local-all). Decisions for the other conflicts are recorded, and the error names the held paths so fixing just those finishes the setup. (#13239, #13242)mise dot conflicts,mise dot status, andmise doctoras exactly that, with advice to move it aside, instead of as a "changed type" conflict that--take-remote/--keep-localcannot resolve. Git or process failures while reading a live file now stop the sync with their own error instead of posing as a conflict. (#13249)mise upgrade --bumppreserves SemVer build metadata when rewriting a pin, so k3s bumps to1.37.0+k3s1rather than a nonexistent1.37.0, and Temurin keeps its+7build number. Coarser pins like1.36still bump to1.37. (#13258)"packslip:github.com/jdx/hk" = "2.0.1") now installs and locks while still inside itsminimum_release_agewindow, as the setting documents. Fuzzy requests such as"2"orlateststill wait out the cutoff. (#13251)MISE_LOCKED=1 mise install <tool>no longer warns about unrelated (often global) tools missing from the lockfile; installing the requested tool or a baremise installstill fails if that tool is not locked. (#13259 by @jamescassell)mise lockno longer fails when awith/exposerequirement is pinned to a release needing a newer Python than the tool itself (e.g.mkdocs1.6.1 withmkdocstrings==1.0.6). The sidecar'srequires-pythonis now intersected across every pinned requirement; unpinned requirements and pins behind an interpreter marker leave the range alone. Existing lockfiles remain valid. (#13252)minimum_release_ageset, the latest release no longer falls back to an older version when the hosted version list lags GitHub. The release date from the/releases/latestresponse mise already fetched is used directly, with no extra requests. (#13228)hk) now list versions from the backend that actually resolves, somise ls-remote hk@1.57andmise latest hk@1.57return1.57.0instead of nothing. Also covers backends promoted byMISE_DISABLE_BACKENDS, platform-scoped entries, and lockfile pins. (#13238)x-ratelimit-remaining: 0orretry-afteris now retried like a 429 underhttp_retries; a 403 with quota remaining is still treated as a refusal. Default backoff (~5s total) will not outlast a long reset, but brief contention no longer fails an install outright. (#13256)mise skills lsandmise skills syncnow warn when a packslip declares a skill the install does not hold, with the reason (skills.fetchoff,packslip.execoff, or a failed download), instead of looking identical to "no skills declared". After an install withskills.auto_syncoff, a one-time hint points atmise skills sync.--jsonoutput is unchanged. (#13275)adoptis now honored for casks named on the command line (mise bootstrap packages apply brew-cask:menuwhere) and for tap-qualified names and aliases likebrew-cask:homebrew/cask/firefox, so existing app bundles are adopted rather than replaced and macOS keeps their Privacy & Security grants. (#13262)depends_on :macosno longer makebootstrap packagestry to fetch a formula namedmacosand abort the whole run with a 404. (#13240 by @waynehoover)appdirandHOMEBREW_PREFIXinterpolation, and casks whose app bundle sits in a nested archive directory (app "nested/Example.app") install asExample.appinstead of being rejected as a relative target; duplicate app targets are rejected before anything is downloaded. (#13138 by @Guria, #13199 and #13200 by @soodoh)Documentation
age-keygen, recovery keys) and warns that passphrase-protected SSH keys and plugin-only recipients cannot decrypt in the background; the setup guide covers adopting onto a machine that already has the files and using non-GitHub Git hosts. (#13232)with,expose, anddependency_prereleasesoptions. (#13222)New Contributors
Full Changelog: jdx/mise@v2026.9.9...v2026.9.10
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.9: : Dotfiles false-deletion fix, encryptedmise dot track, semantic uv options for PyPI toolsCompare Source
The dotfiles history watcher no longer records files as deleted when a checkpoint and a sync compose snapshots at the same time,
mise dot track --encryptenrolls a file with encrypted history from its first checkpoint,mise bootstrap --adopt --replace-historydiscards unrelated local history in one shot, andpypi:tools gain lock-awarewith,expose, anddependency_prereleasesoptions. Also fixed:packslip:installs from private GitHub repositories, stale history watchers after upgrading, global npm tools being reinstalled underlockfile = true, and the--separator in activated PowerShell sessions.Added
dotfiles:
mise dot track --encryptwritesencrypt = trueinto the tracked declaration and encrypts the initial baseline checkpoint, for files that must never have plaintext history.[history.encryption].recipientsmust be configured first; if the encrypted baseline cannot be saved, enrollment fails closed and rolls back the declaration without committing history metadata. Run it as a standalone command rather than insidemise dot capture. Enabling encryption on a file that already has plaintext history does not rewrite that history. (#13180 by @jdx)mise dot track ~/.config/app/credentials --encryptbootstrap: Fresh
mise bootstrap --adoptnow compares existing live files against the incoming setup before creating any local history, so identical files adopt the origin's history instead of being rejected as an unrelated root (for example right after the history store was removed). Differences still pause for an explicit decision. For machines that genuinely hold unrelated local history,--replace-historydiscards it and adopts the setup repository's branch in one shot;--dry-runpreviews the local and origin commits, and a failed replacement restores the previous branch and sync state. Ordinary sync never replaces divergent history and there is no persistent force setting. (#13182 by @jdx)pypi: Three new tool options express common uv install behavior without opaque
uvx_args, and unlike free-form arguments they participate in dependency graph locking:withinstalls extra requirements,exposeinstalls extra requirements and links their executables (requires uv 0.8.5 or newer), anddependency_prereleasessets uv's prerelease policy (disallow,allow,if-necessary,explicit). Setting any of them selects uv as the installer.uvx_argsandpipx_argsremain available as version-only escape hatches. The Ansible and Azure CLI registry entries now use these options by default; if you force pipx for one of them, clear the default with an empty list, e.g."pypi:ansible" = { version = "latest", uvx = false, expose = [], pipx_args = "--include-deps" }. (#13181 by @jdx)registry: Added
nubr(npm:@nubjs/runner), the Nub project's TypeScript runner for a file,package.jsonscript, or installed bin on plain Node. (#13191 by @colinhacks)Fixed
history.sync = "sync"and a running watcher, a checkpoint could record a sorted prefix of tracked files as deleted even though they were untouched on disk; those deletions then synced to other machines and removed their copies. Two compositions in one process (the watcher's checkpoint and the sync it started) shared a single scratch git index, and one resetting it mid-flight truncated the other's tree. Each composition now uses its own scratch index, and indexes left by killed processes are swept. Files recorded as falsely deleted are still in history and can be restored from an earlier checkpoint. (#13195 by @jdx)$MISE_STATE_DIR/history/), or started with a differentMISE_STATE_DIRthan the shell, kept running the old process without watching the current store, whilemise bootstrap services applyconsidered the unchanged service converged and skipped it.services applynow restarts ahistory-watchservice whose process is not watching this store, andmise doctorandmise dot statusreport "running but not watching this store" instead of "not running" (service-not-watchinginmise dot status --json). Users already in this state are recovered by runningmise bootstrap services apply. (#13190 by @jdx)lockfile = truein effect, an npm tool pinned in the global config was resolved with a graph-specific install identity that no automatic flow could persist, so everymise exectreated the installed tool as unsatisfied, re-ran an install pass, and warned that it was missing. Global requests now stay version-only unless resolved from an explicitly generated revision 2 global lockfile; opt in withmise lock --global. (#13186 by @jdx)404 Not Foundon the manifest because GitHub only serves private release assets through its API, not thereleases/download/URLs a packslip records. mise now falls back to the API asset endpoint using the same credentials as thegithub:backend (MISE_GITHUB_TOKEN,GITHUB_API_TOKEN, orGITHUB_TOKEN) with no configuration changes; signature, identity, digest, and size verification are unchanged. Tags containing/(such as@biomejs/biome@2.5.2or monorepotool/v1.0.0tags) and#are also resolved correctly now. Non-GitHub hosts and GitHub Enterprise are not covered. (#13188 by @jdx)mise activate pwsh,mise exec -- pnpm --versionfailed withunexpected argument '--version'because PowerShell's parameter binder removes the first bare--before themisewrapper function sees its arguments. The wrapper now recovers the separator from the raw invocation line, fixingmise exec/mise x,mise tasks add,mise dotfiles capture,mise oci run,mise generate git-pre-commit, andmise bootstrap;mise runwas not affected. Open sessions pick up the fix the next timemise activate pwshruns (normally at shell start). The doubledmise exec -- -- cmdworkaround now fails in an activated shell, as it always did without activation, so drop back to a single--. (#13202 by @jdx)dbt-fusioninstall test now expectsdbt <version>, matching whatdbt --versionactually prints. (873c400 by @jdx)Documentation
Full Changelog: jdx/mise@v2026.9.8...v2026.9.9
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time
Configuration
📅 Schedule: (in timezone Asia/Tokyo)
* * 1 * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.