Skip to content

chore(deps): update dependency jdx/mise to v2026.7.15 - #87

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

chore(deps): update dependency jdx/mise to v2026.7.15#87
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
jdx/mise minor 2026.3.172026.7.15

Release Notes

jdx/mise (jdx/mise)

v2026.7.15: : Experimental Task Output Caching

Compare Source

This release lands the first version of experimental local task output caching, letting eligible tasks restore their declared outputs and replay their logs without rerunning. It also adds structured registry idiomatic-version-file parsing, a standalone Aube installer mode, and a broad batch of task, Homebrew, shell, and Windows path fixes.

Highlights
  • Experimental local task artifact caching restores task outputs (and replays their logs) across deletions, checkouts, and unchanged CI runs, with cache keys derived from source contents, task config, tools, and environment. It works for tasks that produce files, tasks with no filesystem outputs, and multi-task graphs, and stays opt-in and conservative on any failure.
  • Registry-backed tools can now parse idiomatic version files (like dagger.json, Taskfile.yml, .chezmoiversion, and 8 more) in-process, with no plugin or shell execution.
Added
  • task: experimental, opt-in local artifact caching. Tasks with sources and explicit outputs can restore their outputs from a content-addressed cache instead of rerunning, and successful stdout/stderr are replayed through whatever output mode the current run uses. Cache keys combine source contents, task configuration and arguments, declared and allowlisted ambient environment, resolved tools, OS, and architecture. Cache failures degrade to misses or warnings rather than failing a task. (#​11328, #​11347 by @​jdx)

    [tasks.build]
    run = "..."
    sources = ["src/**/*.rs"]
    outputs = ["dist/app"]
    cache = { enabled = true, env = ["CI"] }
  • task: dependency artifact keys now fold into a task's cache key, so downstream tasks reuse cached outputs when their dependencies resolve to the same artifacts, and an upstream input change correctly invalidates downstream results. (#​11340 by @​jdx)

  • task: result-only caching via outputs = [] for checks like lint, test, and typecheck that produce no files. Their successful result and replayable logs are cached without writing an archive. (#​11351 by @​jdx)

  • task: reusable and global cache inputs. Define named [task_config.input_groups] referenced from sources as @group:<name>, and task_config.global_inputs to apply config-rooted patterns to every task in scope, so shared lockfiles and toolchain files no longer need repeating per task. (#​11356 by @​jdx)

  • task: task_config.global_env for scoped environment inputs that participate in cache keys, plus pass_through_env / task_config.global_pass_through_env to keep selected ambient variables (like tokens) available under deny_env without affecting cache keys. (#​11363 by @​jdx)

  • task: outputs now support ordered ! exclusions and re-inclusions (mirroring sources), with \! escaping. Excluded paths are omitted from freshness hashes and cache archives, and existing excluded files are preserved on restore. (#​11367 by @​jdx)

  • task: task_config.shell sets a project-scoped default shell for tasks, with task-local and template shell still taking precedence. This gives users a safe migration path after the 2026.7.14 change that ignored project-level default shell-arg settings. (#​11354 by @​jdx)

  • config: registry idiomatic_files entries can now define structured version_regex, version_json_path, and version_expr parsers, adding in-process idiomatic version-file parsing for 11 tools including Dagger, Task, chezmoi, CMake, Earthly, golangci-lint, GoReleaser, Lefthook, Pixi, pre-commit, and Ruff. Parsing runs without executing plugin or shell code, and remains opt-in per tool. (#​11341 by @​jdx)

    mise settings add idiomatic_version_file_enable_tools dagger task lefthook
  • npm: new npm.package_manager = "aube_cli" mode installs npm: tools through a separately installed standalone Aube executable while mise still resolves versions itself, avoiding Aube's npm compatibility shim. The default embedded aube behavior is unchanged. (#​11357 by @​jdx)

  • deps: explicitly configured mise deps providers that are currently inapplicable now stay visible. mise deps --list shows an active/inactive status with a reason (e.g. inactive (missing package-lock.json)), and mise deps <provider> --explain or an explicit run fails with that reason instead of silently disappearing. (#​11182 by @​risu729)

Fixed
  • task: source_freshness_hash_contents = true now skips mtime comparison entirely, so tasks no longer re-run on every CI job after a cache restore resets timestamps. Output integrity is tracked with a content hash that also detects missing, partially deleted, and modified outputs. (#​11319 by @​rabadin)
  • task: confirming (or auto-confirming) the executable-bit prompt for a file task now runs the task in the same mise run, instead of chmod-ing the file and still failing with "no task found". Respects --yes, MISE_YES, and the trusted yes setting. (#​11337 by @​jdx)
  • task: circular dependency detection now runs on the fully resolved graph, so cycles through wait_for, {{usage.*}} dependencies, and depends_post are reported with a concrete path before any task runs, while valid post-dependency graphs are no longer rejected. (#​11329 by @​jdx)
  • task: $ ... task headers now display forwarded arguments accurately for inline and shebang tasks, no longer making multiline tasks appear to pass args to their first command. (#​11344 by @​jdx)
  • task: --output and MISE_TASK_OUTPUT overrides now honor raw and interactive tasks the same way task.output config does, fixing mixed command/timing output for tasks that need inherited stdio. (#​11355 by @​jdx)
  • brew: mise bootstrap packages upgrade no longer fails to link kegs when formulae were already installed and linked by real Homebrew. mise now recognizes brew's directory symlinks, resolves link targets one hop like brew does, and expands directory symlinks into real directories before linking. This also fixes second-upgrade failures for formulae shipping versioned dylib aliases in pure-mise setups. (#​11320 by @​mjun0812)
  • brew: mise bootstrap packages prune now correctly removes a keg's unversioned dylib alias links instead of leaving them dangling. (#​11330 by @​mjun0812)
  • env: ~/ paths now expand using the platform path separator, so Windows install and tool locations no longer surface mixed separators (e.g. C:\Users\me\.local/share/mise) through mise where, shims, and related output. (#​11312 by @​JamBalaya56562)
  • shell: mise activate pwsh now works under Set-StrictMode, guarding uninitialized globals that previously aborted activation, fixing a bare mise invocation, restoring chpwd hook chaining, and silencing command-not-found errors when PSReadLine is unavailable. (#​11314 by @​JamBalaya56562)
  • backend: a plugin whose backend is listed in disable_backends no longer shadows the registry entry, so a registry shorthand falls back to an enabled backend instead of failing to install. Already-installed tools keep reporting their recorded backend. (#​11362 by @​JamBalaya56562)
  • generate: mise generate task-docs --inject now errors with a clear message when the <!-- mise-tasks --> markers are missing or reversed, instead of truncating or clobbering the target file. (#​11359 by @​JamBalaya56562)
  • mcp: the MCP initialize response now reports the server as mise at mise's version, instead of inheriting rmcp's default identity. (#​11361 by @​jdx)
Documentation
Registry
New Contributors

Full Changelog: jdx/mise@v2026.7.14...v2026.7.15

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.7.14: : Multi-asset GitHub installs, safer defaults, and Windows pip

Compare Source

This release adds overlay installs for GitHub-based tools, closes a config-trust security gap around default shell arguments, and lands a wide batch of correctness fixes across tasks, lockfiles, npm, Swift, brew casks, and Windows Python.

Added
  • github: the GitHub/GitLab/Forgejo release backend now accepts additional_asset_patterns, so a single install can overlay multiple release archives from the same tag into one installation directory. Each supplemental artifact is locked and verified (checksums and provenance) on its own, and --locked fails if the recorded set no longer matches. This models release layouts like Ollama's optional ROCm archive without making a large payload unconditional. (#​11272 by @​jdx)

    [tools."github:ollama/ollama"]
    version = "latest"
    additional_asset_patterns = ["ollama-linux-amd64-rocm.tgz"]
  • npm: new allow_low_downloads tool option lets an embedded aube install bypass the weekly-download popularity gate for the requested package only, so curated tools like bibtex-tidy and purty install again without npm.shell_out. Transitive dependencies still hit the gate. (#​11305 by @​jdx)

  • env: structured env files (env._.file loading JSON/YAML/TOML) support an explicit expand = true option for shell-style variable expansion, including references to earlier values. See Fixed below for the default-behavior change. (#​11269 by @​jdx)

Fixed
  • env: values loaded from JSON/YAML/TOML env files are literal by default again, fixing a regression where every value was shell-expanded when env_shell_expand was on. That corrupted literals such as bcrypt-style $6$salt$hash and could pull in matching process-environment values. Opt back into expansion with expand = true. (#​11269 by @​jdx)
  • python: pip is now usable on fresh Windows installs. mise synthesizes pip.cmd/pip3.cmd wrappers, adds the install's Scripts directory to PATH so pip-installed console scripts resolve, and fixes default-package installation on Windows. (#​11278 by @​JamBalaya56562)
  • github: .exe release assets are now preferred on Windows, so tools that ship both an extensionless and .exe binary no longer install the non-runnable one and fail with "cannot find binary path". (#​11257 by @​gologames)
  • github: a rejected GitHub token (401) now produces an actionable error that names the token source (gh CLI, github_tokens.toml, OAuth, env var, etc.) and includes GitHub's response and a remediation hint, instead of a bare 401 Unauthorized. (#​11236 by @​Marukome0743)
  • backend: an archive containing a single binary with an OS/arch suffix (e.g. gdscript-formatter-macos-aarch64) is now renamed to its clean name on PATH, matching the existing behavior for single-file downloads. (#​11232 by @​Marukome0743)
  • brew: brew-cask installs handle more real-world casks — completion stanzas and system_command in lifecycle blocks are supported, and artifact links into root-owned directories like /usr/local/bin now elevate through mise's sudo policy instead of failing with permission errors. Fixes installing docker-desktop. (#​11273 by @​jdx)
  • lockfile: prefix: tool requests now honor the locked version on mise install instead of silently re-resolving to the newest match. Constrained upgrades via mise upgrade/mise lock --bump still work. (#​11255 by @​JamBalaya56562)
  • aqua: cross-platform lockfiles for aqua HTTP packages preserve a reachable v-prefixed URL, fixing 404s where an entry locked to another platform's unprefixed URL. (#​11267 by @​jdx)
  • swift: Swift lockfile entries now record the target Linux distro (ubuntu24.04, fedora39, ubi9, ...) so checksums are no longer verified across mismatched distro tarballs, and mise lock writes meaningful entries and re-locks correctly after changing swift.platform. (#​11299 by @​jdx)
  • task: with a git worktree checked out inside the main checkout, mise no longer loads the enclosing monorepo root's tasks into the nested root's namespace. Env, tools, and vars still inherit as before. (#​11283 by @​jdx)
  • task: changing a task's run command, sources, or outputs now invalidates its cached state, so tasks are no longer incorrectly skipped after such edits. (#​11288 by @​rabadin)
  • task: a task's source hash is now persisted only after a successful run, so a failed run no longer marks stale sources as up to date. (#​11296 by @​rabadin)
  • completions: shell completion no longer offers mise's own global flags after a task name (where they aren't valid), and a task flag that shares a name with a mise flag now completes its own values correctly. (#​11284 by @​jdx)
  • npm: npm package versions with very large numeric components (up to Number.MAX_SAFE_INTEGER) now sort correctly, fixing cases where a 0.0.* build could be picked over a newer stable release. (#​11280 by @​jdx)
  • npm: aube trust-downgrade failures now surface a clearer explanation, and aube's own progress display no longer competes with mise's output (bumped to 1.33.1). (#​11292, #​11308 by @​jdx)
  • npm: aube allow_builds is now serialized as a map. (#​11262 by @​jdx)
  • version: the update-check cache now negative-caches, so machines that can't reach the network (or run a build newer than the latest release) stop re-running the full check — including building an HTTP client and parsing the CA trust store — on every invocation. This is a significant speedup for commands like mise --version in those cases. (#​11285 by @​jdx)
  • env: remaining std::env::vars() call sites now use vars_safe(). (#​11309 by @​JamBalaya56562)
Changed
  • usage: every mise command now declares its effect on the system — read-only, modifies state, or destructive — surfaced in the command reference. This requires usage 4.0 (min_usage_version bumped), so shell completions and doc rendering now depend on it. (#​11306 by @​jdx)
Security
  • config: the Unix/Windows default file and inline shell-argument settings are now global-only. Because local config is loaded before trust evaluation, an untrusted repository could previously influence how commands from trusted sources were executed. Global config and MISE_* environment variables still apply. Reported by @​arpitjain099. (#​11293 by @​jdx)
Performance
  • cli: the clap command tree is no longer rebuilt twice on every invocation. (#​11297 by @​jdx)
Documentation
Registry
New Contributors

Full Changelog: jdx/mise@v2026.7.13...v2026.7.14

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.7.13: : Multi-binary renaming, cask completions, and go.mod support

Compare Source

This release expands archive backends to rename multiple binaries from a single release, adds Homebrew cask shell completions and go.mod version-file support, and fixes a broad batch of task, install, lockfile, and language-plugin correctness issues.

Added

  • backend: rename_exe now accepts a table mapping source patterns to target names, so an archive that ships several executables can expose all of them cleanly on PATH instead of only one. The existing string form is unchanged. (#​11231 by @​jdx)

    [tools."github:DanielGavin/ols"]
    version = "latest"
    rename_exe = { "ols-*" = "ols", "odinfmt-*" = "odinfmt" }
  • brew: brew-cask now installs shell completions (declared bash_completion/fish_completion/zsh_completion files and generate_completions_from_executable for bash, zsh, fish, and pwsh) instead of skipping them, tracking them in cask receipts and installed-state checks. (#​11198 by @​jdx)

  • go: go.mod can now be used as an idiomatic version file. A toolchain goX.Y.Z directive resolves as an exact pin, while a go X.Y minimum resolves to the latest matching patch. It is opt-in and unchanged unless enabled per-tool. (#​11213 by @​JamBalaya56562)

    mise settings add idiomatic_version_file_enable_tools go
  • task: PowerShell task shells (pwsh/powershell) now run with -NoProfile by default, matching how mise spawns POSIX shells, so a profile that mutates PATH (such as a mise activation snippet) can no longer shadow a task's own tools and cause confusing "cannot find binary path" errors. Opt out with the new windows_powershell_no_profile setting (MISE_WINDOWS_POWERSHELL_NO_PROFILE=false). (#​11199 by @​jdx)

Fixed

  • env: _.path/_.file/_.source directives within a single [env]._ block are now resolved in written order, so a _.path can reference a variable exported by a _.source written before it. (#​11163 by @​JamBalaya56562)
  • install: failed installs no longer print a contradictory "installed but not activated" hint before the real error. (#​11227 by @​jdx)
  • install: logical state mutations during install are now serialized to avoid races. (#​11207 by @​risu729)
  • lockfile: upgrading a locked github: tool to a newer version that is already installed on disk no longer triggers a false supply-chain "provenance regression" error. (#​11230 by @​jdx)
  • npm: aube install failures now surface the full cause chain instead of an opaque "failed to resolve dependencies" message, with mise-native remediation guidance (trust_policy_excludes or npm.shell_out) for trust-downgrade errors. (#​11226 by @​jdx)
  • task: inline task definitions now follow a consistent first-wins precedence model across local, conf.d, and monorepo configs, so lower-precedence metadata no longer leaks into script tasks and the winning config's context is preserved. (#​11103 by @​risu729)
  • task: source freshness now tracks files correctly for workspace-rooted sources patterns used in nested subproject tasks, so edits inside a subproject trigger a rerun. (#​11202 by @​rabadin)
  • brew: cask upgrades handle structured preflight_steps/postflight_steps for move/remove operations, and cleanup-only zap pkgutil IDs are no longer treated as install receipts (which could leave pkg cask status permanently missing). (#​11197 by @​jdx)
  • brew: cask upgrades no longer fail when removing a protected app backup (e.g. docker-desktop) hits "Permission denied", recovering permissions the way Homebrew does before retrying. (#​11219 by @​jdx)
  • python: a python3 executable is now provided on Windows. (#​11212 by @​jdx)
  • ruby: custom ruby.precompiled_url = "owner/repo" sources now fetch release metadata directly from GitHub instead of the restricted versions host, avoiding 403 warnings. (#​11154 by @​risu729)
  • ruby: Gemfile version pins with multi-digit segments (e.g. ruby "3.4.10") are now parsed correctly. (#​11229 by @​capnregex)
  • bootstrap: ./-prefixed relative [bootstrap.repos] paths no longer display with a leading ./ component. (#​11214 by @​lilienblum)
  • http: invalid URLs now return an error instead of panicking. (#​11160 by @​Marukome0743)
  • settings: avoid a panic when a parent settings key is an inline table. (#​11184 by @​Marukome0743)
  • self-update: the updater's TLS backend now matches the feature it was built with, fixing failures when compiled with native-tls. (#​10834 by @​bltavares)

Deprecated

  • python: the legacy virtualenv tool option is deprecated in favor of the _.python.venv env directive. It now emits a warning and is scheduled for removal around 2027.7.0. (#​11234 by @​JamBalaya56562)

Documentation

New Contributors

Full Changelog: jdx/mise@v2026.7.12...v2026.7.13

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.7.12: : Safe mode, node-free npm, and a built-in OCI push client

Compare Source

This release centers on running mise safely against untrusted config, shipping node-free npm: version resolution and installs, and replacing external tools (skopeo/crane, gpg) with built-in, dependency-free implementations. Along the way it fixes a prefer_offline timeout regression, several config/env correctness issues, and platform-specific problems on Windows and macOS.

Highlights

  • New MISE_SAFE=1 mode turns mise into an inert config reader so automation (CI, Renovate) can run mise lock --bump against untrusted branches without trust prompts or arbitrary code execution.
  • The npm: backend no longer needs node or npm installed to resolve or install packages — version metadata is fetched over HTTP and installs run in-process via the embedded aube package manager.
  • mise oci push gained a full built-in registry client: no more skopeo/crane, with blob dedup, chunked uploads, retries, cross-repo mounts, layer reuse from prior images, and multi-arch image indexes.

Added

  • Safe mode: a new global-only safe setting (MISE_SAFE=1) makes mise refuse or ignore anything that would let project config execute code or inject environment. Blocked (with errors): template exec()/read_file(), _.source, hooks, tasks, asdf plugin scripts, and plugin installs. Ignored: project [env], _.path, _.file, [shell_alias], and [settings]. HTTP-based version resolution, lockfile refresh/bump, and already-installed/embedded plugins keep working. Because a config loaded this way is inert, safe mode also skips the trust requirement. (#​11146, #​11151 by @​jdx)

    MISE_SAFE=1 mise lock --bump --dry-run --json   # detect updates with zero code execution, no trust needed
  • mise lock --bump: advance fuzzy lockfile selectors (latest, lts, prefixes like "20") to the newest matching remote versions without installing anything and without touching mise.toml. Exact pins stay put. Pairs with --json and --dry-run for a CI job that opens lockfile-only PRs. (#​11145 by @​jdx)

    $ mise lock --bump --dry-run --json
    [{ "name": "node", "backend": "core:node", "old_versions": ["22.14.0"], "new_versions": ["22.15.0"] }]
  • Node-free npm: backend: mise ls-remote npm:* and latest resolution now query the npm registry directly over HTTP, and installs run in-process through the embedded aube package manager. node is only needed to run installed tools (and their lifecycle scripts), not to install them. User ~/.npmrc, scoped registries, auth, and minimum_release_age are honored. A new npm.shell_out setting (MISE_NPM_SHELL_OUT) routes both metadata and installs through the npm CLI for setups relying on npm-only config like cafile or client certs. (#​11147, #​11149 by @​jdx)

  • Built-in OCI registry client: mise oci push no longer requires skopeo or crane. It uses an in-tree OCI Distribution client that uploads only blobs the registry is missing, resolves credentials the way docker/podman do (docker login/podman login is all the setup needed), and answers registry auth challenges so private base-image pulls via --from also work. mise oci run --engine docker now streams the image into docker load instead of needing skopeo. The --tool flag was removed. (#​11132 by @​jdx)

  • OCI push robustness: large layers upload in 64 MiB chunks, transient failures retry with mise's standard backoff, base layers are mounted cross-repo (?mount=) when they already live on the destination registry (zero bytes transferred), and pushes/pulls now show byte progress. A new oci.insecure_registries setting opts non-loopback registries into plain HTTP. (#​11141 by @​jdx)

  • OCI layer reuse: mise oci push reuses unchanged tool layers from the previously pushed image (or --cache-from REF), skipping the tar/gzip build entirely — reused tools don't even need to be installed locally. --no-cache forces a full rebuild. (#​11142 by @​jdx)

  • Multi-arch OCI images: mise oci push --update-index points a tag at an OCI image index and upserts the current platform while preserving entries pushed by other architectures, so one runner per arch can assemble a multi-arch tag. (#​11144 by @​jdx)

  • Built-in signature verification: Node.js and Swift download signatures are now verified in-process with the pure-Rust rPGP crate against the bundled keyrings, dropping the external gpg binary dependency. Note: previously, if gpg was missing and the setting was unset, verification was silently skipped; now verification always runs when enabled — opt out with gpg_verify = false. (#​11148 by @​jdx)

  • Relative bootstrap repo paths: [bootstrap.repos] destination keys can now be relative paths, resolved against the declaring project's root (with guards preventing escape outside the project tree), making a project's mise.toml portable across machines. (#​11155 by @​lilienblum)

Fixed

  • http: mise lock, ls-remote, outdated, and upgrade no longer get capped to a single 3s no-retry attempt when prefer_offline is set — they honor the configured fetch_remote_versions_timeout and retry budget again, fixing spurious timeouts. Interactive fast paths keep their bounded behavior. (#​11190 by @​jdx)
  • lock: unfiltered mise lock no longer prunes OS-restricted tool entries (e.g. os = ["macos"]) when run on a platform that doesn't target them, keeping shared lockfiles stable across platforms. (#​11175 by @​jdx)
  • env: values loaded from _.file env files now resolve references to variables defined in earlier files or [env] blocks instead of collapsing to empty, fixing flaky dotenv behavior. (#​11158 by @​Marukome0743)
  • env: [env] _.source now works on Windows by resolving a real POSIX bash (Git Bash / MSYS2, honoring MISE_BASH_PATH) instead of the WSL launcher or a missing bash.exe, and correctly filters MSYS runtime noise and converts prepended PATH entries back to Windows form. (#​11097 by @​JamBalaya56562)
  • config: trusted_config_paths (MISE_TRUSTED_CONFIG_PATHS) now overrides configs previously added to the ignore list, so a settings-trusted config is actually discovered and loaded. (#​11152 by @​JamBalaya56562)
  • config: env/vars array parsing is now consistent — accidental array forms for vars and task env/vars are rejected with clear errors, while the intentional [[env]] and directive-level arrays (_.source, _.file, _.path) remain supported. (#​11060 by @​risu729)
  • config: mise config set no longer panics when descending into a non-table value. (#​11153 by @​Marukome0743)
  • config: clearer warnings for unsupported semver ranges. (#​11176 by @​risu729)
  • hook-env: entering a directory with an untrusted config now prints a single concise warning (... is not trusted, run 'mise trust' to enable it) instead of the full error chain. Explicit commands still show the full trust error and prompt. (#​11159 by @​lilienblum)
  • activate: mise activate zsh no longer hangs non-interactive login shells under Rosetta — a v2026.7.11 regression where env-state snapshotting autoloaded the zsh/parameter module via dlopen. (#​11188 by @​jdx)
  • brew-cask: case-insensitive app bundle lookup (fixing casks like yaak) and correct resolution of preflight-generated wrapper scripts on the extract stage (fixing vlc). (#​11164 by @​donbeave)
  • brew: cask binaries can symlink into /usr/local on arm64. (#​11174 by @​jdx)
  • backend: qualified prerelease suffixes are now detected correctly. (#​11179 by @​risu729)
  • completions: avoid a network lookup during usage completion. (#​11169 by @​jdx)
  • link: clear a stale incomplete marker when linking a tool. (#​11150 by @​Marukome0743)
  • shim: unresolved Windows exe-shim dispatch (e.g. a project-scoped tool run outside the project) now shows the actionable "no version is set" guidance instead of an opaque "cannot find binary path". (#​11189 by @​jdx)
  • vfox: preserve inner quotes when a vfox Lua command dispatches through cmd.exe on Windows, fixing commands such as the Yarn 2+ install flow. (#​11166 by @​finalchild)
  • github/gitlab/forgejo: statically-linked linux-musl assets are now considered a fallback for Android/Termux when a package publishes no Android-specific asset, so tools like starship, bat, and hk can install there. (#​10730 by @​bltavares)
  • deps: avoid installing tools during dry runs, and enforce the experimental gate for task providers. (#​11016, #​11177 by @​risu729)

Documentation

  • Document environment-variable backing for file-task arguments and flags, including CLI/env/default precedence. (#​11165 by @​zeitlinger)

Breaking Changes

  • mise oci push --tool has been removed. Use mise oci build -o ./img followed by skopeo copy if you need the old escape hatch. (#​11132)
  • Node/Swift signature verification now always runs when enabled (external gpg is no longer required). If you relied on a missing gpg binary to skip verification, set gpg_verify = false explicitly. (#​11148)
  • The unreleased npm.use_npm_view setting is replaced by npm.shell_out (MISE_NPM_SHELL_OUT). (#​11149)

New Contributors

Full Changelog: jdx/mise@v2026.7.11...v2026.7.12

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.7.11: : Task Source Tracking and Activation Speedups

Compare Source

This release sharpens task handling around remote files, global config, and tool selectors, trims redundant work from shell activation, and fixes several bootstrap and platform-specific edge cases.

[!NOTE]
This is the first published release since v2026.7.7 — versions 2026.7.8 through 2026.7.10 were tagged but never published due to a release pipeline issue. Their changes are included here; see Also in this release below.

Added

  • config: structured tool definitions now accept version, path, prefix, and ref selectors consistently in root [tools], inline task definitions, task templates, and file-task headers. Exactly one selector is required, and conflicting, missing, or non-string selectors now fail with a clear configuration error instead of silently defaulting or panicking. (#​11069 by @​risu729)

    node = { version = "20" }
    go = { prefix = "1.22" }
    python = { ref = "main" }
    shellcheck = { path = "/opt/shellcheck" }

Fixed

  • task: remote HTTP and Git-backed task files now have their #MISE headers parsed, so metadata like tools, description, and hide and inline TOML overrides are honored just like local file tasks. Git-backed task files are also made executable after cloning and on cache hits. (#​11111 by @​Marukome0743)
  • task: file tasks loaded from user-global or system configs are now correctly treated as global regardless of their include path, so custom global scripts appear under mise tasks --global, stay out of --local, and use the invoking project root. (#​11106 by @​risu729)
  • task: mise tasks info, extended listings, task help, and the MCP tasks resource now report every configuration source contributing to a task, with a new config_sources array in JSON output. Changing metadata in a TOML overlay now correctly invalidates the merged file task's cache. (#​11098 by @​risu729)
  • watch: mise --env <profile> watch now propagates the selected environment to the watched task, so profile-specific tasks resolve correctly on each rerun. (#​11114 by @​Marukome0743)
  • http: raw executables (such as PHP PHARs like Composer) installed via the HTTP backend are now created readable as well as executable (mode 0755 rather than 0711), fixing "Could not open input file" errors for interpreters run by non-owner users. (#​11135 by @​jdx)
  • java: mise latest java@<vendor> now prefers the base vendor variant over dashed specializations and sorts multi-feature vendor prefixes correctly. (#​11109 by @​roele)
  • config: reject conflicting tool selectors at parse time (see Added). (#​11069 by @​risu729)
  • bootstrap: systemd timers can now reference a managed service by its bare TOML key (e.g. unit = "dotfiles-maintain"), which resolves to dev.mise.<name>.service. Fully qualified names like nginx.service are still written verbatim. (#​11128 by @​jdx)
  • bootstrap: Homebrew casks that declare auto_updates are now accepted instead of failing with an unsupported-lifecycle error. (#​11107 by @​casparbreloh)
  • bootstrap: macOS defaults handling now treats a missing key or domain as unset rather than erroring during initial setup. (#​11118 by @​roele)
  • windows: mise uninstall now removes dangling runtime version pointer files (like 16 or latest) and cleans up the now-empty tool directory. (#​11095 by @​JamBalaya56562)

Performance

  • activate: the redundant initial prompt hook that ran immediately after activation is now skipped for bash, zsh, and fish when the session is unchanged, avoiding an extra mise process on shell startup. (#​11130, #​11131, #​11134 by @​jdx)
  • backend: archive extraction and macOS hdiutil/pkgutil waits now run via block_in_place, so parallel installs no longer starve download progress and other tasks of runtime threads. (#​11136 by @​jdx)

Registry

  • Allow the reviewed @nubjs/nub postinstall lifecycle script to run via the npm backend so upgrades keep the ~/.nub/shims hardlinks refreshed; default-deny behavior is preserved for all other packages. (#​11126 by @​risu729)

Documentation


Also in this release: v2026.7.8–v2026.7.10

Due to a release pipeline issue, versions 2026.7.8 through 2026.7.10 were tagged but never published. This is the first release since v2026.7.7, so it also ships everything below.

Added
  • bootstrap: package manager plugins — vfox Lua plugins can now act as system package managers, with a declarative [bootstrap.plugins] config and mise bootstrap plugins apply|status commands. Declared plugins install before built-in packages, then plugin-managed packages apply once host tools are available. (#​11023, #​11024 by @​jdx)
  • bootstrap: new mise bootstrap repos update and mise bootstrap repos exec commands. Unpinned [bootstrap.repos] entries are intentionally never pulled by declarative apply; repos update gives an explicit fetch + fast-forward path (with dry-run and path filtering), and repos exec runs a command across configured checkouts. mise bootstrap --update now also updates repos. (#​11022 by @​jdx)
  • registry: opt-in floating registries — with registry_floating, mise fetches the latest released registry metadata (and the current aqua registry) instead of the release-pinned copies. Useful on distributions whose mise package lags behind releases while registry entries keep changing. (#​10971 by @​jdx)
  • backend: exact-version fast path — when a request is an exact semver version, the cargo, npm, go, gem, pipx, and dotnet backends now skip fetching the remote version list entirely and let the underlying installer validate it. This speeds up exact pins without a lockfile, first-time mise install tool@x.y.z, and mise x tool@x.y.z. (#​11013 by @​Turbo87, #​11070 by @​jdx)
  • task: dependencies whose templated names render to an empty string are now skipped, so templates can conditionally disable a dependency. Empty templated dependency args are omitted as well. (#​11057 by @​risu729, #​11055 by @​jdx)
Fixed
  • http: mise now fails fast when the network is unavailable: DNS resolver failures are treated as non-retryable, a process-local circuit opens after hard DNS/connection failures, and remote-version lookups are capped at 3 seconds under prefer_offline. Shims, shell activation, and mise x make one bounded attempt instead of grinding through full retry schedules per endpoint. (#​11066 by @​jdx)
  • config: stricter, clearer configuration validation: env directive value aliases (#​11062), env.mise directives (#​11053), and the experimental monorepo root key (#​11052) are deprecated, and non-string postinstall hooks are rejected at parse time (#​11061) (all by @​risu729)
  • hooks: hook definitions are validated more strictly — unknown table fields (#​11047) and nested hook arrays (#​11051) are rejected, and the spawned-scripts form is deprecated (#​11043) (all by @​risu729)
  • schema: a large batch of JSON schema corrections so editors validate real configs correctly: OCI copy entries (#​11009), bootstrap shell activation (#​11004) and bootstrap hooks (#​11039), structured task tool options (#​11021), required watch file patterns (#​11040), plugin manifest fields (#​11035), root hook definitions (#​11041), integer types for integer settings (#​11037), array-typed deps provider paths (#​11064) (all by @​risu729), and systemd timer/lifecycle options (#​11050 by @​jdx)
  • **dry ru

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.3.18 chore(deps): update dependency jdx/mise to v2026.4.0 Apr 1, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.0 chore(deps): update dependency jdx/mise to v2026.4.1 Apr 2, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 7bca63d to 78cde9b Compare April 3, 2026 13:52
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.1 chore(deps): update dependency jdx/mise to v2026.4.3 Apr 3, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.3 chore(deps): update dependency jdx/mise to v2026.4.4 Apr 5, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 71dfc7c to 2c2deda Compare April 6, 2026 13:24
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.4 chore(deps): update dependency jdx/mise to v2026.4.5 Apr 6, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.5 chore(deps): update dependency jdx/mise to v2026.4.6 Apr 8, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 9807261 to 23e68ca Compare April 9, 2026 10:49
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.6 chore(deps): update dependency jdx/mise to v2026.4.7 Apr 9, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.7 chore(deps): update dependency jdx/mise to v2026.4.8 Apr 10, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.8 chore(deps): update dependency jdx/mise to v2026.4.9 Apr 11, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.9 chore(deps): update dependency jdx/mise to v2026.4.10 Apr 12, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.10 chore(deps): update dependency jdx/mise to v2026.4.11 Apr 13, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.11 chore(deps): update dependency jdx/mise to v2026.4.14 Apr 16, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.14 chore(deps): update dependency jdx/mise to v2026.4.15 Apr 16, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.15 chore(deps): update dependency jdx/mise to v2026.4.16 Apr 17, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.16 chore(deps): update dependency jdx/mise to v2026.4.17 Apr 18, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.22 chore(deps): update dependency jdx/mise to v2026.4.23 Apr 26, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.23 chore(deps): update dependency jdx/mise to v2026.4.24 Apr 27, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.24 chore(deps): update dependency jdx/mise to v2026.4.25 Apr 28, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.25 chore(deps): update dependency jdx/mise to v2026.4.26 Apr 29, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.26 chore(deps): update dependency jdx/mise to v2026.4.27 Apr 29, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.27 chore(deps): update dependency jdx/mise to v2026.4.28 Apr 30, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from 1d8da69 to 0837f8f Compare May 3, 2026 22:13
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.4.28 chore(deps): update dependency jdx/mise to v2026.5.0 May 3, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from 0837f8f to 5599c9b Compare May 5, 2026 14:44
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.0 chore(deps): update dependency jdx/mise to v2026.5.1 May 5, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from 5599c9b to 4c38329 Compare May 7, 2026 13:38
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.1 chore(deps): update dependency jdx/mise to v2026.5.2 May 7, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from 4c38329 to 951583f Compare May 8, 2026 12:59
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.2 chore(deps): update dependency jdx/mise to v2026.5.3 May 8, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from 951583f to 406abab Compare May 9, 2026 13:44
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.3 chore(deps): update dependency jdx/mise to v2026.5.4 May 9, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from 406abab to ac5e40c Compare May 10, 2026 12:44
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.4 chore(deps): update dependency jdx/mise to v2026.5.5 May 10, 2026
@renovate
renovate Bot force-pushed the renovate/all branch from ac5e40c to a88eca2 Compare May 11, 2026 18:01
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.5 chore(deps): update dependency jdx/mise to v2026.5.6 May 11, 2026
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.6 chore(deps): update dependency jdx/mise to v2026.5.7 May 13, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from ce968d3 to ca638bd Compare May 14, 2026 21:39
@renovate renovate Bot changed the title chore(deps): update dependency jdx/mise to v2026.5.7 chore(deps): update dependency jdx/mise to v2026.5.8 May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants