Skip to content

Update dependency jdx/mise to v2026.9.12 - #110

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/github-actions
Oct 1, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
jdx/mise uses-with patch 2026.9.1 → 2026.9.12 v2026.9.18 (+5)

Release Notes

jdx/mise (jdx/mise)

v2026.9.12: : Tasks that require daemons, worktree-aware ports and URLs, Scoop and zypper packages, and official Docker images

Compare Source

The experimental [daemons] system grows substantially: tasks can declare the daemons they need, [daemon_groups] selects subsets of a project's services, port = "auto" and stable <NAME>_URL hostnames let several git worktrees run the same stack side by side, and CockroachDB, NATS, and SpiceDB join the PostgreSQL and Redis presets. Outside daemons, [bootstrap.packages] gains scoop: and zypper: managers, mise install --system elevates with sudo only for the final publish step, official mise images are published to GHCR and Docker Hub, and a run of brew-cask fixes lets many more casks install unattended.

Highlights

  • Daemons as part of the task graph (experimental): [tasks.x] daemons = [...] starts and waits for services before a task runs, daemons can run a mise task, [daemon_groups] and mise daemons start <group> select subsets, and mise daemons register, urls, and prune round out the lifecycle. Worktrees get deterministic ports, hostnames, and optionally checkout-local data_dir storage without hand-assigned numbers.
  • More host software from one config: Scoop on Windows and zypper on openSUSE/SLE join the bootstrap managers; brew-cask now picks the right build for the host macOS release, runs installers that need sudo, applies pkg installer choices and set_ownership steps, upgrades pkg-only self-updating casks, and survives DMGs with license prompts or unreadable metadata; brew: resolves formula aliases such as openssl.
  • Regressions and integrity fixes: enter hooks fire again when a shell starts inside a project, npm tools with only pre-releases resolve latest again, generated pre-push hooks no longer append git's arguments to the task command, and mise install refuses a lockfile entry whose download URL names a different release than its version. Lockfile sidecars now verify on Windows checkouts with CRLF line endings.

Added

  • daemons: Tasks can require daemons and daemons can run tasks. daemons = ["postgres", "nats"] (or true for all project daemons) on a task starts them via pitchfork, waits for readiness, and then runs the task; already-running daemons are left alone, and --skip-deps / --dry-run skip them. A daemon can declare task = "dev:core" with args instead of run, and init = [...] runs idempotent setup commands before the long-running process on every start. mise tasks info shows a task's daemons. (#​13340)

    [daemons]
    postgres = "18"
    
    [daemons.nats]
    run = "exec nats-server"
    ready_port = 4222
    
    [tasks.dev]
    daemons = ["postgres", "nats"]
    run = "npm run dev"
  • daemons: [daemon_groups] names project-scoped subsets of daemons; groups may nest other groups and work wherever a daemon name does, including --group. mise daemons start with no arguments now starts the default group when a project declares one, and every project daemon otherwise. (#​13347)

    [daemon_groups]
    default = ["postgres", "core", "node0"]
    two-cluster = ["default", "core2"]
  • daemons: A daemon entry with project = "../other-checkout" and optional name runs a daemon defined in another project under that project's tools, environment, and data, and can be used in depends. [daemons_settings] namespace = "services" gives daemons stable namespace/name IDs (with a per-worktree suffix unless namespace_per_worktree = false). Requires pitchfork 2.25.0 or later. (#​13339)

  • daemons: port = "auto" (or port = { auto = true, base = 3000, stride = 1 } for custom daemons) keeps the base port in the primary checkout and derives a deterministic offset in each linked git worktree. Resolved ports are exported before startup as PGPORT/DATABASE_URL for presets and <NAME>_PORT for custom daemons, and mise daemons ls --json reports port and port_auto. mise does not fall back to another port; startup diagnoses conflicts with running mise-managed daemons in other projects, and two daemons in one project claiming the same port now fail at config load. (#​13342)

  • daemons: Every daemon with a port gets a stable hostname served by pitchfork's reverse proxy, exported as <NAME>_URL (for example api.shop.localhost in the primary checkout, or api.shop-pr-42.shop.localhost in a linked worktree). Per-daemon proxy (a label, true, or false) and proxy_tls ("terminate" or "passthrough") control routing; the postgres and redis presets opt out. mise daemons urls lists hostnames, ports, proxy modes, and status. Set proxy = false on custom daemons that do not speak HTTP. (#​13368)

  • daemons: CockroachDB (preset = "cockroachdb"), NATS ("nats"), and SpiceDB ("spicedb") presets install the tool, initialize data, wait for readiness, and export DATABASE_URL, NATS_URL, SPICEDB_ENDPOINT, and SPICEDB_PRESHARED_KEY. Presets now support named-port overrides such as ports.http_port = 8081 and typed options. Unix-only; NATS and SpiceDB readiness checks need curl. (#​13346)

  • daemons: mise daemons register installs missing tools, validates the daemon graph, and registers pitchfork configuration without starting anything, so a fresh checkout can start on its first hostname request. (#​13399)

  • daemons: mise daemons prune finds daemon state left behind by deleted projects and worktrees, shows paths and sizes, and removes it after confirmation (--dry-run previews, --yes confirms ordinary cases). mise daemons ls --json adds root, state_dir, data_size, and data_size_human. (#​13338)

  • daemons: data_dir = ".data/postgres" keeps a preset's persistent data inside the checkout (relative to the project root; absolute and ~/ paths also work), so each worktree gets its own database. Changing the path does not move existing data. (#​13408)

  • bootstrap: A scoop manager for Windows. "scoop:extras/vscode" = "latest" adds the bucket if missing, pinned versions install via app@version, state = "absent" uninstalls, and --update opts in to scoop update. Only user-scope installs are managed; entries are skipped on other platforms. (#​13324)

  • bootstrap: A zypper manager for openSUSE and SUSE Linux Enterprise, supporting status, install, name=version pins (including downgrades), upgrade, and removal, with retries when zypper asks for a package-manager restart. (#​13335, @​m407)

  • bootstrap: process_type on [bootstrap.macos.launchd.agents.*] maps to launchd's ProcessType (Background, Standard, Adaptive, Interactive); misspellings are rejected at config time instead of being silently ignored by launchd. (#​13402, @​waynehoover)

  • install: mise install --system on Unix downloads, verifies, and unpacks as the invoking user, then uses sudo only to publish into the system install and shim directories. Supports relocatable tools from aqua, github, gitlab, forgejo, http, and s3 without a tool-level postinstall; system_packages.sudo = false disables elevation. (#​13384)

  • docker: Official release images at ghcr.io/jdx/mise and jdxcode/mise for linux/amd64 and linux/arm64, built from the minisign-verified release binaries. Tags 2026.9.12, 2026.9, and latest are a scratch image for COPY --from=; *-debian and debian are a Debian slim base with curl and git. (#​13413)

    FROM debian:13-slim
    COPY --from=ghcr.io/jdx/mise:2026.9.12 /usr/local/bin/mise /usr/local/bin/mise
  • config: unix is accepted as an os selector in [tools], [bootstrap.packages], [doctor.checks], and [dotfiles] variants, matching every non-Windows platform. A concrete OS variant still wins over a unix one. (#​13395)

  • go: With go in idiomatic_version_file_enable_tools, the toolchain line of an active go.work selects the Go version and, as with the go command, member go.mod files are ignored in workspace mode. GOWORK (auto, off, or an absolute path) is honored. (#​13337)

  • bazel: .bazelversion is an idiomatic version file for bazel when enabled; only concrete releases are read, so latest, last_green, 8.x, and commit hashes select nothing rather than failing. (#​13336)

  • tasks: File-task #USAGE include file="..." paths may be relative to the task file or use environment variables such as $MISE_CONFIG_ROOT, $MISE_TASK_DIR, and $MISE_PROJECT_ROOT, so shared flagsets no longer need absolute paths. (#​13372)

  • dotfiles: mise dot apply now runs matching [history.reload] commands for the targets it actually wrote, once each after all writes; --dry-run and no-op applies run none. (#​13414)

  • registry: Added codegraph (aqua:colbymchenry/codegraph). (#​13355, @​3w36zj6)

Fixed

  • activate: Starting a shell inside a trusted project runs its enter hook again; a regression in 2026.9.x had limited it to cd into the project. (#​13383)
  • npm: A tool that publishes only pre-releases (such as @deepseek-ai/dsh) is no longer reported missing after mise use npm:...@latest; latest falls back to the newest installed pre-release when no stable version is installed. (#​13390)
  • npm: On a shared Linux machine, users other than the first to install an npm: tool no longer fail with failed to acquire project lock: Permission denied. (#​13379)
  • generate: mise generate git-pre-commit hooks pass only the message file ("$1") for commit-msg, prepare-commit-msg, applypatch-msg, and sendemail-validate, and no arguments for other hooks, so a pre-push task no longer runs npm test origin <url>. Existing hooks change when regenerated. (#​13377)
  • lockfile: mise install fails before downloading when a locked platform URL provably names a different release than the entry's version (for example after a tool bumped version in mise.lock without refreshing the platform block, or a release dropped a platform). mise lock still repairs the entry. (#​13401)
  • lockfile: Dependency sidecars under .mise/locks/ verify on Windows checkouts where git rewrote them to CRLF, digests recorded from CRLF bytes by older versions keep working and heal on the next ordinary install, and a relocated sidecar is pinned to the bytes actually written. Repositories can drop .mise/locks/** -text workarounds. (#​13398, #​13403, #​13407)
  • brew-cask: Installs the variations entry Homebrew publishes for the host macOS release instead of always the newest release's build (Raycast on Sequoia now gets 1.104.x, not the Tahoe-only 2.x), and reports not available for this platform for null variations. (#​13376)
  • brew-cask: Installer scripts that declare sudo: true (such as logi-options+) run through mise's sudo path, and $HOMEBREW_PREFIX/$APPDIR placeholders in installer paths and arguments are expanded. (#​13380)
  • brew-cask: Casks with pkg installer choices (microsoft-outlook, microsoft-teams) install via installer -applyChoiceChangesXML; casks whose flight steps use set_ownership (parsec) install; and mise bootstrap packages upgrade handles self-updating casks that install only from a .pkg (tailscale-app, karabiner-elements) by comparing pkgutil receipt versions. (#​13385, #​13386, #​13387)
  • brew-cask: Third-party casks evaluated from Ruby can use staged_path, unblocking casks such as AeroSpace. (#​13369, @​soodoh)
  • install: DMGs with an embedded license agreement no longer stall at hdiutil's Agree Y/N? prompt, and DMGs with unreadable root metadata such as .Trashes (for example mysqlworkbench) extract instead of failing with Permission denied. Applies to brew-cask, macos-app, and aqua DMG downloads. (#​13353, @​hisaac; #​13378)
  • brew: Formula aliases and old names (openssl -> openssl@3, act_runner -> gitea-runner) resolve for brew: packages and tap formula dependencies instead of failing with a 404; mise warns to use the canonical name so status can track it. (#​13382)
  • bootstrap: Two spellings of one WinGet or Scoop package (winget:Git.Git and winget:git.git) that disagree on state or version are rejected with both names, instead of converging differently per machine. Entries kept apart by os or env selectors are not compared. (#​13334)
  • github: The GitHub token is sent to raw.githubusercontent.com, so private Homebrew taps resolve. (#​13345, @​waynehoover)
  • github: {{ version }} in platforms.<target>.url is rendered with the resolved version for the GitHub, GitLab, and Forgejo backends, so versioned source archives can follow latest. (#​13359, @​casparbreloh)
  • go: Version discovery for modules with hundreds of releases no longer times out with No versions found; latest resolves directly through the module proxy or go list, and release dates are fetched only for the newest versions. minimum_release_age stays exact by dating individual undated candidates on demand. (#​13362, #​13364)
  • tasks: mise tasks validate recognizes child monorepo task references such as depends = ["//crates/gui:dev"] in depends, depends_post, wait_for, and structured run. (#​13373, @​nettlesh)
  • daemons: ready_cmd and health_cmd probes run in the owning project's mise environment, so a supervisor shared by several worktrees no longer probes one checkout with another's API_PORT. (#​13396)
  • dotfiles: mise dot edit opens tracked files (mode = "track") in place and inline content entries in their declaring config, instead of failing with No such file or directory; it warns when editing a tracked symlink whose destination history does not capture. (#​13332)
  • history: Checkpoints record the non-default mode of directories containing tracked files, so a 0700 ~/.claude holding a tracked settings.json is recreated private on a new machine rather than 0755. (#​13412)
  • history: The "histories are unrelated" refusal from mise dot origin set and mise dot sync now names the commands for each way out. (#​13411)

Documentation

  • New "Set up a development stack" guide covering project daemons, worktree isolation, imports, registration, and idle shutdown. (#​13389)
  • Task templates guide documents Tera v2 components for repeated parameterized snippets inside a run script. (#​13388)
  • miser.nvim added to the IDE integration page. (#​13406, @​carldaws)
  • Bootstrap package conflict guidance shortened and corrected. (#​13341)

Breaking Changes

  • Docker latest tag: ghcr.io/jdx/mise:latest and jdxcode/mise:latest are now the scratch image (static binary and CA certificates, no shell). CI and dev-container users should switch to the debian tag and install their tools explicitly; the previous source-built image remains under the unsupported dev tag. (#​13413)
  • Lockfile version/URL mismatch: Lockfiles whose version disagrees with a platform URL now fail mise install instead of silently installing the wrong release. Run mise lock to regenerate the entry. (#​13401)
  • Generated git hooks: After regenerating with mise generate git-pre-commit, non-message hooks no longer receive git's arguments. To keep them, edit the hook to use "$@" and declare the arguments with usage. (#​13377)
  • Bootstrap package spellings: Configs declaring one WinGet or Scoop package under two spellings with conflicting state or version are rejected; delete one entry. (#​13334)
  • Daemons (experimental): mise daemons start with no arguments starts only the default group when one is declared; a project with two daemons resolving to the same port fails to load; custom daemons with a port now export <NAME>_PORT and <NAME>_URL, so set proxy = false on non-HTTP daemons. (#​13347, #​13342, #​13368)

New Contributors

Full Changelog: jdx/mise@v2026.9.11...v2026.9.12

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.11: : macos-app bootstrap packages, task template inheritance for flags and file tasks, and Swift on Linux fixes

Compare Source

A new macos-app bootstrap manager installs .app bundles from a pinned URL and checksum when no Homebrew cask exists, task templates now compose usage flags and can be extended from file tasks, and Swift on Linux picks its distro build from swift.org's release index instead of a hard-coded map that 404'd on arm64 and on newer Fedora, Amazon Linux, and Arch hosts. Install failures also become far more actionable: errors name the minimum_release_age cutoff that hid every version, the child's last stderr line, or the shared libraries a Swift toolchain cannot load.

Highlights
  • Apps without a cask: "macos-app:<name>" entries in [bootstrap.packages] download, checksum-verify, and install a .app into /Applications using mise's existing cask pipeline, with stricter ownership rules for apps already at the target.
  • Task templates that actually share things: a task that extends a template now inherits the template's usage flags alongside its own, file tasks can write #MISE extends="...", and a template's vars can read the values the extending task supplies.
  • Swift on Linux: arm64 downloads resolve on every distro, the build is chosen from what a release actually publishes (with a warning when a fallback is used), and a fallback that cannot start names the missing libraries instead of exiting 127 after a 1 GB download.
Added
  • bootstrap: The macos-app package manager installs a macOS .app bundle from a vendor or internal download. version, url, sha256, and artifact are all required ("latest" is rejected because mise cannot discover releases behind a plain URL); {{version}} is interpolated into url, so a release bump is a two-field edit. Only .dmg and .zip archives containing an app bundle are supported, state is kept in mise's state directory rather than Homebrew's Caskroom, and an app already at the destination that this entry does not own is refused unless adopt = true and the contents match. mise bootstrap packages upgrade cannot discover new versions for these entries, and prune --manager macos-app is unsupported. Prefer brew-cask wherever a cask exists. (#​13279)

    [bootstrap.packages."macos-app:example"]
    version = "1.2.3"
    url = "<HTTPS URL of the .dmg or .zip; {{version}} is interpolated>"
    sha256 = "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"
    artifact = "Example.app"
  • tasks: A task that names a template with extends and declares its own usage now gets the template's flags too, listed first in --help. Previously the task's spec replaced the template's entirely, so shared flags had to be copied into every task. Workspace-root task defaults still only fill in usage when the task has none. A flag declared in both places is listed twice; declare each flag in one place, or use usage flagsets for replacements. (#​13310)

    [task_templates.deploy]
    usage = 'flag "--env <env>" help="Target environment"'
    
    [tasks.deploy-api]
    extends = "deploy"
    usage = 'flag "--replicas <n>" help="How many to run"'
    run = 'echo "env=$usage_env replicas=$usage_replicas"'
  • tasks: File tasks (including remote HTTP and git:: scripts) can use #MISE extends="<template>" in their header to inherit tools, env, description, aliases, and other fields from a task template; previously the field was warned about and ignored. A task whose command is a script file no longer picks up a template's run. (#​13307)

  • swift: When a Linux install fails its swift --version check, mise runs ldd over the toolchain and lists every unresolved shared library (for example libform.so.6, libncurses.so.6, libpanel.so.6 on an Arch-family host running a ubi9 build), with the tool's install_env applied so an LD_LIBRARY_PATH remedy is not misreported. docs/lang/swift.md documents the workaround. (#​13319)

Fixed
  • swift: Installing Swift on arm64 failed with a 404 on every Linux distro except Ubuntu (and on Windows arm64 lock entries) because only Ubuntu used swift.org's <platform>-<arch> download directory. (#​13293, fixes #​13291)
  • swift: The Linux distro build is now chosen from swift.org's release index rather than a hard-coded map: the host's exact distro version wins, then the newest published build older than the host, then the family's oldest, with ID_LIKE consulted (Linux Mint gets an Ubuntu build) and unknown distros such as Arch falling back to ubi9. Every compromise is announced with a warning, musl hosts and unsupported architectures fail before downloading, and swift.platform still overrides selection without contacting swift.org. The swift_platform lockfile option now records the host as detected (e.g. fedora40 instead of fedora39); mismatched entries are re-resolved on the next lock. (#​13297, fixes #​13289)
  • config: install_env values are now rendered as templates like other tool options, so LD_LIBRARY_PATH = "{{env.HOME}}/.local/lib/compat" reaches the install subprocess expanded rather than literally. {{version}} is left unchanged. (#​13314)
  • install: When minimum_release_age (default 24h) hides every candidate, the error names the setting and cutoff, how many releases it hid, the newest one with its release and eligibility dates, and a copy-pasteable exact pin to install it now, instead of no versions found ... matching date filter. A query that matched nothing is no longer blamed on the filter. (#​13308)
  • cmd: A failing command run by mise (installs, tasks, plugin scripts) now appends the child's last non-empty stderr line to the error, e.g. exit code 127; last stderr: swift: error while loading shared libraries: libncurses.so.6 .... This also reaches the final error block under --quiet, where stderr was previously never shown. (#​13315)
  • tasks: A broken usage spec now reports the task name and the parser's diagnostic (invalid usage spec for task 'deploy' followed by the reason) instead of a bare Invalid usage config; file tasks render the same diagnostic rather than a Debug dump, and a missing or unreadable script is reported as such rather than as a bad spec. (#​13312)
  • tasks: A task template's vars can now read the vars the extending task supplies, so {{ vars.opt | default(value='none') }} in a template sees the task's opt instead of always taking the default. Literal vars within a single task are also bound first, so vars = { msg = "hi {{ vars.who }}", who = "world" } works regardless of declaration order. Config-level [vars] are unchanged. (#​13322)
  • runtime symlinks: latest and version-prefix links under installs/<tool>/ that point at an install no longer eligible for a link (for example a directory left with an incomplete marker by an interrupted install) are now removed on rebuild instead of surviving indefinitely. Configured aliases, hand-made names, and absolute symlinks are left alone. (#​13288)
  • npm: Semver pre-releases with numeric suffixes such as 1.3.1-3 no longer claim the latest, 1, and 1.3 runtime symlinks or satisfy "latest"/prefix requests over the newest stable install; links an older mise already wrote are cleaned up on the next install. An exact request or the prerelease option still selects them. (#​13272 by @​pataar)
  • lockfile: mise lock --global on a mise.lock symlinked into a dotfiles repository now keeps native dependency sidecars beside the target lockfile, so mise install --locked works from a fresh checkout. If you used this layout on 2026.9.7 through 2026.9.10 and see missing sidecars, run mise lock --global again to repair the pointers. (#​13268 by @​nettlesh)
  • lockfile: With lockfile_mode = "generate", mise unuse now removes the tool's entry from mise.lock and its .mise/locks/... sidecar immediately rather than leaving them until the next mise install or mise lock. Merge mode is unchanged. (#​13304)
  • conda: Commands from conda: packages that have nothing to activate (no activate.d scripts, no dependency executables, no script entry points) are now plain symlinks instead of shell launchers, so tools like conda:ripgrep or conda:gh no longer prepend the conda prefix to the PATH of every child process and skip the extra shell. Packages that need activation keep their launcher; Windows is unchanged. A relative MISE_DATA_DIR is also handled. Existing installs keep their current entries until reinstalled with mise install --force conda:<pkg>. (#​13305)
  • backends: A tool's postinstall hook now receives pre-tools [env] from the config on every backend (http, aqua, github, cargo, npm, core tools), not only for asdf plugins, and a hook that changes an env input is visible to hooks ordered after it. (#​13316)
  • github: Tools whose release tags repeat the configured version_prefix (tag a-a-1.2.3 with version_prefix = "a-", listed as a-1.2.3) can now be installed; prefix + version is tried first so every listed version round-trips to its tag. If a repo publishes both a-1.2.3 and a-a-1.2.3, requesting a-1.2.3 now resolves to the doubled tag. (#​13317)
Changed
  • brew-cask: Cask archives are downloaded concurrently at the configured jobs concurrency before the serial install pass, so --jobs/MISE_JOBS now speed up cask-heavy runs. Placement (mounting, swapping app bundles) remains serial. (#​13282 by @​waynehoover)
Security
  • http: Artifact downloads now refuse a redirect that steps down from HTTPS to HTTP, matching the policy the remote-version client already applied; the error names which kind of request was refused. URLs that are plain HTTP to begin with are unaffected. (#​13292)
  • brew-cask: The fingerprint used to adopt or refuse an existing app bundle is now computed entirely through the verified directory descriptor (fstatat/openat/readlinkat), so a path component swapped mid-check cannot make mise compare against a different tree than the one it will replace. Digests are unchanged, so existing receipts remain valid; large files are now hashed in-process, which can make adoption checks slower. (#​13294)
Documentation
  • The bootstrap packages guide is reorganized around choosing a manager, declaring packages, and the command reference, with a dedicated section for direct macos-app downloads and app ownership. (#​13298)
  • The variables guide explains when [vars] resolve and why a task-local override does not recompute a top-level var that already referenced it, with task templates as the way to defer a fragment. (#​13323)
  • Task Arguments documents sharing flags between tasks with usage flagset, use, and include, in both TOML and file tasks. (#​13313)
New Contributors

Full Changelog: jdx/mise@v2026.9.10...v2026.9.11

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.10: : shims.exclude, npm allow_exotic_deps, bulk dotfiles conflict resolution, and Windows Ctrl-C handling for tasks

Compare Source

New settings let mise manage a tool without claiming its command names (shims.exclude) and approve non-registry npm dependencies (allow_exotic_deps), mise dot pull can decide every sharing conflict at once, and vfox plugin hooks gain cmd.stream plus a working cmd.exec timeout. On the fix side, mise run now survives Ctrl-C on Windows instead of orphaning cmd.exe, fish shells launched through shims start much faster with correct PATH order, and several task-resolution, lockfile, and Homebrew cask bugs are corrected.

Highlights
  • Control over what mise puts on PATH and what it installs: settings.shims.exclude keeps names like python resolving to the OS while mise still manages the tool; allow_exotic_deps approves specific npm packages fetched from git or tarball URLs; exact packslip: pins install during a minimum_release_age cooling window; and mise upgrade --bump keeps SemVer build metadata such as +k3s1.
  • Dotfiles sharing on a second machine: mise dot pull --take-remote-all / --keep-local-all resolve all conflicts in one command, paths that cannot be decided are held rather than aborting the pass, and a directory sitting where a tracked file belongs is now reported as exactly that.
  • Task and shell reliability: Windows Ctrl-C shuts tasks down cleanly, a task's own name always beats another task's alias, glob expansions no longer drop file tasks, Bash completion of ns:task names no longer duplicates the prefix, and fish startup through mise exec/shims is no longer quadratic in the number of tools.
Added
  • shims: settings.shims.exclude (env MISE_SHIMS_EXCLUDE) lists command names mise never creates shims for. The tool stays installed and version-qualified names like python3.12 still resolve through mise, but the excluded name resolves to whatever else is on PATH; existing shims for those names are removed on the next mise reshim. Note that under mise activate without --shims the tool's bin directory still joins PATH, and excluding python3 means python3 -m venv silently uses the system interpreter. (#​13266)

    [settings.shims]
    exclude = ["python", "python3", "pip", "pip3"]
  • npm: allow_exotic_deps approves dependencies that aube's blockExoticSubdeps gate would otherwise block because they come from a git, file:, or direct tarball URL. List package names to exempt only those (the gate stays on for the rest of the graph), or set true to exempt the whole graph. Applies to the aube and aube_cli installers. Embedded-aube installs now also warn when install_env is set, since it never reached the in-process installer. (#​13231)

    [tools]
    "npm:@gmickel/gno" = { version = "2.3.0", allow_exotic_deps = ["xlsx"] }
  • dotfiles: mise dot pull --take-remote-all and --keep-local-all decide every pending conflict at once, with per-path --take-remote/--keep-local naming exceptions. The two blanket flags are mutually exclusive, and paused-sync and adoption messages now point at them. (#​13233)

    mise dot pull --take-remote-all --keep-local ~/.bashrc
  • bootstrap: Every string value in [bootstrap.linux.systemd.units] and [bootstrap.macos.launchd.agents] is rendered as a template before the unit file or plist is written, so {{ config_root }}/.env in environment_file resolves to the declaring config's directory. Values without template syntax (including %h and $HOME) pass through untouched, exec() is rejected, and a unit whose template fails is skipped by name without blocking the others. [bootstrap.services] is not yet templated. (#​13227)

  • hooks: Each MISE_INSTALLED_TOOLS entry passed to postinstall hooks now carries requested_version (for example latest, 22, or an alias) alongside the resolved version, so a hook can tell a floating request from a pin. The field is always present; existing hooks reading name/version are unaffected. (#​13274)

  • vfox plugins: cmd.stream runs a command with stdin connected and stdout/stderr streamed to the terminal, for hooks that genuinely need input such as a login or license prompt; it pauses the progress renderer and holds the terminal exclusively while it runs. cmd.exec and os.execute now detach stdin unless --raw is set, matching every other subprocess mise spawns, so a plugin that read stdin through os.execute should switch to cmd.stream. (#​13261)

  • vfox plugins: The timeout option on cmd.exec (and cmd.stream) now works instead of being silently ignored. It takes seconds (fractions allowed); on expiry the spawned shell is killed and the call raises a catchable error. Only the shell mise spawned is killed, so background processes it started may keep running. (#​13263)

    local ok, err = pcall(cmd.exec, "some-tool sync", { timeout = 30 })
Fixed
  • task: On Windows, pressing Ctrl-C during mise run no longer kills mise immediately and leaves a cmd.exe behind stuck on Terminate batch job (Y/N)?. The first Ctrl-C lets running commands exit and stops scheduling new tasks; a second one takes the remaining process tree down. Tasks ended by the console are reported as interrupted instead of failing with exit code -1073741510. (#​13226)
  • task: A task's own name now always wins over another task's alias. Previously a parent config's tests task with alias = "test" could shadow a test task in the current directory, depending on alphabetical order. Aliases still resolve wherever no task claims that name. (#​13230)
  • task: Glob expansions such as mise run '//...:lint' or '*:lint' no longer silently drop file tasks (mise-tasks/lint.sh) when a sibling package has an exact match. The same-package dedup that stops hello and hello.sh running twice is preserved. (#​13277)
  • completions: Bash completion of namespaced tasks like update:deps:no<TAB> no longer produces update:deps:update:deps:no-cooldown. Reinstall the script with mise completion bash --install if yours predates the prefix-aware wrapper. (#​13276)
  • exec: Launching fish through mise exec or a shim emitted one fish_add_path per directory, which made startup quadratic (over 1s with ~80 tools) and reversed mise's PATH order relative to bash. A single batched call restores both. (#​13235)
  • dotfiles: A blanket --take-remote-all/--keep-local-all no longer aborts the whole pass when one path cannot be decided (a directory on the live side, or unsaved local changes under --keep-local-all). Decisions for the other conflicts are recorded, and the error names the held paths so fixing just those finishes the setup. (#​13239, #​13242)
  • dotfiles: A directory or unreadable path where the repository has a file is now reported by mise dot conflicts, mise dot status, and mise doctor as exactly that, with advice to move it aside, instead of as a "changed type" conflict that --take-remote/--keep-local cannot resolve. Git or process failures while reading a live file now stop the sync with their own error instead of posing as a conflict. (#​13249)
  • upgrade: mise upgrade --bump preserves SemVer build metadata when rewriting a pin, so k3s bumps to 1.37.0+k3s1 rather than a nonexistent 1.37.0, and Temurin keeps its +7 build number. Coarser pins like 1.36 still bump to 1.37. (#​13258)
  • packslip: An exactly pinned version (for example "packslip:github.com/jdx/hk" = "2.0.1") now installs and locks while still inside its minimum_release_age window, as the setting documents. Fuzzy requests such as "2" or latest still wait out the cutoff. (#​13251)
  • install: MISE_LOCKED=1 mise install <tool> no longer warns about unrelated (often global) tools missing from the lockfile; installing the requested tool or a bare mise install still fails if that tool is not locked. (#​13259 by @​jamescassell)
  • pypi: mise lock no longer fails when a with/expose requirement is pinned to a release needing a newer Python than the tool itself (e.g. mkdocs 1.6.1 with mkdocstrings==1.0.6). The sidecar's requires-python is now intersected across every pinned requirement; unpinned requirements and pins behind an interpreter marker leave the range alone. Existing lockfiles remain valid. (#​13252)
  • aqua: With minimum_release_age set, the latest release no longer falls back to an older version when the hosted version list lags GitHub. The release date from the /releases/latest response mise already fetched is used directly, with no extra requests. (#​13228)
  • backend: Tools whose registry entry splits across backends at a version boundary (like hk) now list versions from the backend that actually resolves, so mise ls-remote hk@1.57 and mise latest hk@1.57 return 1.57.0 instead of nothing. Also covers backends promoted by MISE_DISABLE_BACKENDS, platform-scoped entries, and lockfile pins. (#​13238)
  • http: GitHub answers an exhausted rate limit with 403 rather than 429, so mise never retried it. A 403 carrying x-ratelimit-remaining: 0 or retry-after is now retried like a 429 under http_retries; a 403 with quota remaining is still treated as a refusal. Default backoff (~5s total) will not outlast a long reset, but brief contention no longer fails an install outright. (#​13256)
  • skills: mise skills ls and mise skills sync now warn when a packslip declares a skill the install does not hold, with the reason (skills.fetch off, packslip.exec off, or a failed download), instead of looking identical to "no skills declared". After an install with skills.auto_sync off, a one-time hint points at mise skills sync. --json output is unchanged. (#​13275)
  • brew: adopt is now honored for casks named on the command line (mise bootstrap packages apply brew-cask:menuwhere) and for tap-qualified names and aliases like brew-cask:homebrew/cask/firefox, so existing app bundles are adopted rather than replaced and macOS keeps their Privacy & Security grants. (#​13262)
  • brew: Tap formulae declaring requirement symbols such as depends_on :macos no longer make bootstrap packages try to fetch a formula named macos and abort the whole run with a 404. (#​13240 by @​waynehoover)
  • brew: Tap cask metadata evaluation now understands appdir and HOMEBREW_PREFIX interpolation, and casks whose app bundle sits in a nested archive directory (app "nested/Example.app") install as Example.app instead of being rejected as a relative target; duplicate app targets are rejected before anything is downloaded. (#​13138 by @​Guria, #​13199 and #​13200 by @​soodoh)
  • bootstrap: Selecting a Ruby to evaluate third-party Homebrew taps skips mise shims, which the metadata sandbox could not load, so package bootstrap no longer fails when Ruby is installed through mise. (#​13198 by @​jacobbednarz)
Documentation
  • The dotfiles history guide now explains encryption recipients (SSH keys, age-keygen, recovery keys) and warns that passphrase-protected SSH keys and plugin-only recipients cannot decrypt in the background; the setup guide covers adopting onto a machine that already has the files and using non-GitHub Git hosts. (#​13232)
  • The PyPI backend's locking limitations now point at the lockable with, expose, and dependency_prereleases options. (#​13222)
New Contributors

Full Changelog: jdx/mise@v2026.9.9...v2026.9.10

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.9: : Dotfiles false-deletion fix, encrypted mise dot track, semantic uv options for PyPI tools

Compare Source

The dotfiles history watcher no longer records files as deleted when a checkpoint and a sync compose snapshots at the same time, mise dot track --encrypt enrolls a file with encrypted history from its first checkpoint, mise bootstrap --adopt --replace-history discards unrelated local history in one shot, and pypi: tools gain lock-aware with, expose, and dependency_prereleases options. Also fixed: packslip: installs from private GitHub repositories, stale history watchers after upgrading, global npm tools being reinstalled under lockfile = true, and the -- separator in activated PowerShell sessions.

Added

  • dotfiles: mise dot track --encrypt writes encrypt = true into the tracked declaration and encrypts the initial baseline checkpoint, for files that must never have plaintext history. [history.encryption].recipients must be configured first; if the encrypted baseline cannot be saved, enrollment fails closed and rolls back the declaration without committing history metadata. Run it as a standalone command rather than inside mise dot capture. Enabling encryption on a file that already has plaintext history does not rewrite that history. (#​13180 by @​jdx)

    mise dot track ~/.config/app/credentials --encrypt
  • bootstrap: Fresh mise bootstrap --adopt now compares existing live files against the incoming setup before creating any local history, so identical files adopt the origin's history instead of being rejected as an unrelated root (for example right after the history store was removed). Differences still pause for an explicit decision. For machines that genuinely hold unrelated local history, --replace-history discards it and adopts the setup repository's branch in one shot; --dry-run previews the local and origin commits, and a failed replacement restores the previous branch and sync state. Ordinary sync never replaces divergent history and there is no persistent force setting. (#​13182 by @​jdx)

    mise bootstrap --adopt <url> --replace-history --yes
  • pypi: Three new tool options express common uv install behavior without opaque uvx_args, and unlike free-form arguments they participate in dependency graph locking: with installs extra requirements, expose installs extra requirements and links their executables (requires uv 0.8.5 or newer), and dependency_prereleases sets uv's prerelease policy (disallow, allow, if-necessary, explicit). Setting any of them selects uv as the installer. uvx_args and pipx_args remain available as version-only escape hatches. The Ansible and Azure CLI registry entries now use these options by default; if you force pipx for one of them, clear the default with an empty list, e.g. "pypi:ansible" = { version = "latest", uvx = false, expose = [], pipx_args = "--include-deps" }. (#​13181 by @​jdx)

    [tools]
    "pypi:azure-cli" = { version = "latest", with = ["pip"], dependency_prereleases = "allow" }
    "pypi:ansible" = { version = "latest", expose = ["ansible-core"] }
  • registry: Added nubr (npm:@nubjs/runner), the Nub project's TypeScript runner for a file, package.json script, or installed bin on plain Node. (#​13191 by @​colinhacks)

Fixed

  • dotfiles: With history.sync = "sync" and a running watcher, a checkpoint could record a sorted prefix of tracked files as deleted even though they were untouched on disk; those deletions then synced to other machines and removed their copies. Two compositions in one process (the watcher's checkpoint and the sync it started) shared a single scratch git index, and one resetting it mid-flight truncated the other's tree. Each composition now uses its own scratch index, and indexes left by killed processes are swept. Files recorded as falsely deleted are still in history and can be restored from an earlier checkpoint. (#​13195 by @​jdx)
  • dotfiles: A history watcher started before mise 2026.9.5 (which moved history locks into $MISE_STATE_DIR/history/), or started with a different MISE_STATE_DIR than the shell, kept running the old process without watching the current store, while mise bootstrap services apply considered the unchanged service converged and skipped it. services apply now restarts a history-watch service whose process is not watching this store, and mise doctor and mise dot status report "running but not watching this store" instead of "not running" (service-not-watching in mise dot status --json). Users already in this state are recovered by running mise bootstrap services apply. (#​13190 by @​jdx)
  • npm: With lockfile = true in effect, an npm tool pinned in the global config was resolved with a graph-specific install identity that no automatic flow could persist, so every mise exec treated the installed tool as unsatisfied, re-ran an install pass, and warned that it was missing. Global requests now stay version-only unless resolved from an explicitly generated revision 2 global lockfile; opt in with mise lock --global. (#​13186 by @​jdx)
  • packslip: Installing from a private GitHub repository failed with 404 Not Found on the manifest because GitHub only serves private release assets through its API, not the releases/download/ URLs a packslip records. mise now falls back to the API asset endpoint using the same credentials as the github: backend (MISE_GITHUB_TOKEN, GITHUB_API_TOKEN, or GITHUB_TOKEN) with no configuration changes; signature, identity, digest, and size verification are unchanged. Tags containing / (such as @biomejs/biome@2.5.2 or monorepo tool/v1.0.0 tags) and # are also resolved correctly now. Non-GitHub hosts and GitHub Enterprise are not covered. (#​13188 by @​jdx)
  • activate: In a shell activated with mise activate pwsh, mise exec -- pnpm --version failed with unexpected argument '--version' because PowerShell's parameter binder removes the first bare -- before the mise wrapper function sees its arguments. The wrapper now recovers the separator from the raw invocation line, fixing mise exec/mise x, mise tasks add, mise dotfiles capture, mise oci run, mise generate git-pre-commit, and mise bootstrap; mise run was not affected. Open sessions pick up the fix the next time mise activate pwsh runs (normally at shell start). The doubled mise exec -- -- cmd workaround now fails in an activated shell, as it always did without activation, so drop back to a single --. (#​13202 by @​jdx)
  • registry: The dbt-fusion install test now expects dbt <version>, matching what dbt --version actually prints. (873c400 by @​jdx)

Documentation

  • The GitHub star count on mise.jdx.dev now also appears in the nav overflow menu at medium viewport widths. (#​13193 by @​jdx)

Full Changelog: jdx/mise@v2026.9.8...v2026.9.9

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • On day 1 of the month (* * 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 1, 2026 05:22
@renovate
renovate Bot merged commit 021c102 into main Oct 1, 2026
3 checks passed
@renovate
renovate Bot deleted the renovate/github-actions branch October 1, 2026 05:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants