Skip to content

chore(deps): update dependency jdx/mise to v2026.9.16 - #30

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/jdx-mise-2026.x
Oct 5, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/jdx-mise-2026.x

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending
jdx/mise uses-with patch 2026.9.14 → 2026.9.16 v2026.10.3 (+5)

Release Notes

jdx/mise (jdx/mise)

v2026.9.16: : Per-tool libc for aqua tools, monorepo task path aliases, and packslip pins that survive repo renames

Compare Source

Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in mise run --no-timings, cargo +nightly and the outdated/upgrade version comparison, and speeds up shims and config loading.

Added

  • Per-tool libc for aqua tools. On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such as aqua:domcyrus/rustnet. You can now pick the build for a single tool instead of changing the global libc setting. #​13701

    [tools]
    "aqua:domcyrus/rustnet" = { version = "latest", libc = "musl" }

    The option accepts glibc (or gnu) and musl. mise never falls back to the other libc for that tool. The option applies to install, mise lock, and checksum, signature and provenance lookups, and it is recorded in the lockfile's tool options. A platform that already names a libc (a musl host or a linux-*-musl lockfile platform) still wins. A version that is already installed keeps its build until you run mise install --force. mise ls-remote still uses the host libc. If a registry template uses a variable named libc, set it as vars.libc.

  • Path aliases for monorepo tasks. Deeply nested config roots can now have a short name. #​13756

    monorepo_root = true
    
    [monorepo]
    config_roots = ["foo/bar/baz/abc/123"]
    
    [monorepo.path_aliases]
    "123" = "foo/bar/baz/abc/123"

    mise run //123:build runs //foo/bar/baz/abc/123:build. Aliases also work in task dependencies, in patterns like //123:*, and in child paths like //123/sub:build. Each alias must be a single path segment, must point at a configured root, and can't overlap an existing root path. A task's full path is still its canonical name.

  • Packslip tools keep installing after a repository rename. mise now pins GitHub and GitLab packslip projects by the repository ID recorded in the signing certificate, not only by name. If old/tool is renamed to new/tool under the same owner, packslip:github.com/old/tool keeps installing and prints a warning once, asking you to update the config. You don't need mise packslip forget. mise refuses a transfer to another owner. It also refuses a different repository that takes over a pinned name, which is how a deleted and re-created name looks. To accept either one, run mise packslip forget for the old name, and for a re-created repository also remove the tool's mise.lock entries. #​13702, #​13738

    In lockfile revision 3, the IDs are stored as:

    [tools.hk."platforms.linux-x64"]
    repository_ids = { repository = "922514152", owner = "216188" }
  • mise dot track --allow-plaintext. Directly tracking a file with a credential-like name (for example ~/commit-mossy-token.md) used to report success while every history save quietly left the file out. mise dot track now asks whether to save the file in plaintext, and the default answer is No. In non-interactive use, pass --allow-plaintext. --yes does not approve plaintext. The choice is saved as allow_plaintext = true on the [dotfiles] entry. For real credentials, use --encrypt. #​13749

  • Registry: mise use mbx now resolves to mr-boxington. #​13752

Fixed

  • mise outdated and upgrade warnings no longer offer an older release as an update when the installed version has a v or V prefix. For example, v2.1.280 → 2.1.278 was shown as an update. Versions that differ only in build metadata (for example 1.36.4+k3s1 and 1.36.4+k3s2) are now treated as equal. #​13690 (@​himkt)
  • mise run --no-cache and mise tasks run --no-cache now clone remote git:: task includes again, and fetch remote tasks that run as dependencies again. Before, both kept using the cached copy. #​13697 (@​irisTa56)
  • mise run --no-timings hides each task's "Finished in …" line again, not only the run total. It also overrides MISE_TASK_TIMINGS=1. This had regressed in v2025.11.2. #​13718
  • cargo +nightly works again with rust = "nightly". Since 2026.8.6 mise installs a dated nightly, so rustup had no toolchain named nightly. Depending on rustup's auto-install setting, cargo +nightly then either failed or downloaded a second, unpinned nightly. mise now also sets up rustup's nightly-<host> toolchain from the pinned nightly, using reflinks or hardlinks. It leaves alone a rustup nightly that is newer or has extra components or targets. Explicitly dated requests such as nightly-2026-08-13 don't touch it. Existing installs pick this up on their next nightly install, or right away with mise install -f rust. #​13707
  • Running mise dot track again on a path that is already tracked now reports "already tracked". It no longer prompts, rewrites the config, or records an empty checkpoint. Changed file contents and flags that change the declaration (such as --no-autosave) are still saved. #​13648
  • Blob-pack downloads from the remote cache now retry transient stream errors, the same way single blob downloads do. #​13715

Security

  • SLSA provenance must come from the expected signer. Before, any valid Sigstore signature, even from an unrelated workflow, passed SLSA verification. mise now checks the certificate's URI identity and OIDC issuer against the values configured for the tool:

    • aqua registry entries: signer_identity and signer_issuer under slsa_provenance
    • github: tools: the slsa_signer_identity and slsa_signer_issuer tool options (the identity supports {{version}} templating)
    • vfox plugins: slsa_signer_identity and slsa_signer_issuer returned from PreInstall

    If a tool doesn't configure both values, mise skips the SLSA check and uses any other verification available. For now this applies to the bundled aqua packages that have SLSA metadata but no signer fields. SLSA lock entries are checked again on every install, even when a checksum is present. #​13725

  • Public-key DSSE bundles used by aqua and vfox verification must now have a SHA-256 subject digest that matches the downloaded artifact. Before, a valid bundle could be reused to verify a different download. #​13721

Performance

  • Shims no longer run rustup checks when rust is configured alongside other tools. The same goes for mise exec with auto-install disabled. One report measured the go shim at about 31 ms with rust in the config, compared with 12 ms without it. mise install, and mise exec with auto-install on, still detect and repair missing rustup components. #​13705
  • Config loading and fuzzy version resolution (for example node = "24") do less work: plugin shorthands are built without checking every registry tool's backends, global-config checks stop resolving symlinks for every tool, and fuzzy matching no longer compiles regexes. #​13694, #​13695, #​13696

Documentation

  • The task docs now give the correct default job count (8). They also describe the default output mode correctly: prefix when tasks run in parallel and interleave when they run in sequence. #​13716

Breaking Changes

  • Lockfile revision 3. New and empty mise.lock files are written as lockfile_version = 3, and older mise versions reject them. Existing lockfiles keep their revision when mise writes to them. When a revision 2 lockfile gets packslip repository IDs, mise warns and leaves them out. To store them, run mise lock --upgrade once everyone who shares the lockfile is on this release.
  • SLSA checks for locked tools. A lockfile entry that requires SLSA now fails with an explanation if the tool has no expected signer configured. To fix it, configure the signer or refresh the entry with mise lock.
  • Dotfiles history shared across machines. Older mise versions can't read enrollment metadata that includes allow_plaintext. Upgrade every machine that shares the history before you use --allow-plaintext.

New Contributors

Full Changelog: jdx/mise@vfox-v2026.9.17...v2026.9.16

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.15: : vfox tools in OCI images, faster shell prompts, and safer dotfiles pattern matching

Compare Source

mise oci build can now package tools installed by vfox plugins, and vfox plugins can repair an existing install when its tool options change. Shell prompts, cd, and settings loading are faster. Dotfiles include/exclude patterns now follow .gitignore rules for * and a leading /, which fixes a case where rollback could delete a live file.

Added

  • vfox tools in OCI images (experimental). mise oci build used to reject every tool installed by a vfox plugin. It now builds those tools into the image, with one layer per tool plus one layer per plugin at /mise/plugins/<name>/, so mise inside the image can resolve the tool without cloning the plugin. The plugin's env hook runs on the build host. Install-dir paths are rewritten to their in-image location, and mise warns when a value points into the host's home directory. Changing a plugin invalidates the reused layers of its tools on mise oci push. asdf plugins are still rejected. #​13670

  • vfox plugins can repair installs that no longer match tool options. Plugins can add an optional hooks/mise_install_satisfied.lua hook that tells mise an installed version no longer matches its options, for example after a component is added to a gcloud config. mise install and auto-install (such as mise x) then rerun the plugin's PostInstall and the tool's postinstall script on the existing install without downloading it again. If the hook itself errors, mise warns and keeps the install. Plugins without the hook work as before. See docs/tool-plugin-development.md. #​13668

    [tools]
    gcloud = { version = "latest", components = ["gke-gcloud-auth-plugin"] }
  • Git subdirectory installs for pypi:. Git sources now accept a #subdirectory= fragment (other fragment keys are passed through as written), and git+<scheme>:// URLs work without a trailing .git. Each subdirectory is its own tool with its own install directory. latest still means the repository's newest GitHub release, so pin a branch or commit if those releases predate the subdirectory. #​13607 (@​jakedgy)

    [tools]
    "pypi:git+https://github.com/runpantheon/ltui#subdirectory=ltui" = "main"
    "pypi:runpantheon/ltui#subdirectory=jtui" = "main"
  • max_version for registry backends. Registry entries can now set an exclusive max_version, alone or together with min_version, so older releases can come from a legacy backend and newer ones from another. It requires version_order = "semver". A locked backend is used only for versions it serves. #​13676

  • Mac App Store names in mise bootstrap packages status. Installed mas: packages now show the app name next to the numeric ID (for example 1056643111 (Clocker)), and --json adds a name field. Apps that aren't installed still show only their ID. #​13622

  • Registry: added sofka (#​13612, @​jylenhof), imessage-exporter (#​13640, @​i-api), and spotify-downloader (#​13641, @​i-api). nub 0.9.5 and later now installs from github:nubjs/nub, and the entry lists the nubr bin (#​13643, @​colinhacks). cocogitto now lists cog as its bin (#​13657).

Changed

  • mise exec warns when a missing pinned tool falls back to PATH. When auto-install is off (exec_auto_install = false, auto_install = false, or auto_install_disable_tools) and the command belongs to a pinned tool that isn't installed, mise used to run a same-named binary from PATH without saying anything. It still runs it, but now prints a warning such as jq@1.7.1 is not installed and auto-install is disabled, so mise looks for jq on PATH instead. There's no warning when another configured version of the tool, a command wrapper, or a project env._.path entry provides the command. #​13650, #​13658
  • mise tasks validate fails on unparseable usage specs. A file task's #USAGE spec (or a TOML task's usage) that doesn't parse is now a usage-parse-error error, so validation exits 1, including with --errors-only. Before, it was only a warning and validation passed. mise run and mise tasks ls behave as before. CI that runs mise tasks validate will now fail on these specs. #​13672
  • Linux GNU release binaries are linked non-PIE. Every mise command on Linux x64, arm64, and armv7 (GNU) now starts about 3 ms faster. The tradeoff is that ASLR no longer applies to mise's own code and data, though the heap, stack, and shared libraries are still randomized. musl, macOS, source builds, and cargo install are unchanged. #​13687

Fixed

Dotfiles
  • * no longer crosses / in tracked include patterns. Capture and rollback used to disagree about what rules/*.md selected. After you widened the list, mise dot rollback to an older checkpoint could delete a nested file such as rules/deep/two.md. include now follows .gitignore rules: * stops at /, and you need ** to match nested files. exclude lists keep matching what they matched before, but mise now prints a deprecation warning when an exclusion depends on * crossing /. Use ** in those patterns instead. #​13618
  • A leading / anchors include/exclude patterns to the entry root. Before, these patterns matched nothing at all. Now exclude = ["/cache"] skips only the top-level cache directory, and include = ["/rules/*.md"] works. In the global [history] exclude list, a leading / still means an absolute path. #​13621
Tasks and config
  • Tasks in a conf.d folder fragment now run in that folder, with {{config_root}} and MISE_CONFIG_ROOT pointing there. Each folder's [task_config] applies only to its own tasks, so a fragment's includes no longer hides the default task directories like ~/.config/mise/tasks. #​13662
  • A settings load that was already running could cache a stale snapshot after another thread changed settings, which dropped a just-applied override. This is fixed. #​13646
Plugins and shims
  • mise now warns when an installed git plugin's origin URL or checked-out commit doesn't match its [plugins] entry. The warning appears in mise install, mise plugins install, and mise doctor. Related fixes #​13663:
    • mise plugins install --force <name> now reinstalls from the [plugins] pin.
    • A failed ref checkout no longer leaves an unpinned clone behind.
    • Short SHAs fail with a clear error, since a full SHA is required.
    • Shorthand pins like owner/repo#v1.2.0 keep their ref.
  • On Windows, [wrappers.*] command wrappers (including the cargo wrapper that mr_boxington generates) now run through exe- and file-mode shims and mise x. Before, the real tool ran instead. #​13673
Bootstrap
  • On apt systems, mise now simulates the install first and runs apt-get update once if the simulation fails. This fixes has no installation candidate failures on machines whose package lists cover only the install media. #​13659
  • On macOS, mise bootstrap macos defaults now reads and writes the container plist for sandboxed apps such as Safari, which the app actually uses. Launch the app once first so its container exists. Writing another app's container may require Full Disk Access for your terminal. #​13660
  • When mise bootstrap packages prune fails on a brew: formula it can't resolve, the error now names the config file that declares it. When the name is actually a cask, mise suggests brew-cask:<name>. #​13661

Performance

  • Faster shell prompts. When nothing has changed, mise hook-env no longer loads all settings or starts the async runtime (6.6 ms to 4.9 ms on Linux in the PR's measurements), as long as hook_env.chpwd_only and hook_env.cache_ttl are unset. #​13686
  • Faster cd with npm tools installed. The npm install health check now reads the virtual store's directory listing instead of calling stat on every package. #​13685
  • Faster settings loading. Config discovery skips conf.d globs for directories that don't exist, which halves settings load time in deep checkouts. #​13688
  • Faster brew-cask: lookups. Official casks are resolved from Homebrew's bulk cask.json index, cached locally and re-checked with a conditional request after 7.5 minutes, instead of one request per cask. In the PR's test, bootstrap packages status with 143 casks dropped from about 26s to about 2s. #​13349 (@​waynehoover)
  • Fixed slowdowns from deferred prunes. When a deferred-prune receipt from mise upgrade comes due but the version is still in use, mise now re-checks it once a day instead of on every command. This could make trivial commands about 9x slower. Pruning can now happen up to a day after the last reference is removed. #​13674
  • mise ls, mise prune, and shim rebuilds scan install directories in a single pass. #​13675

Full Changelog: jdx/mise@vfox-v2026.9.16...v2026.9.15

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • "before 3am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 5, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 5, 2026 17:08
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

✅ Markdown lint — no issues found

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

✅ Renovate — configuration is valid

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

✅ ghasec — no issues found

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

✅ Gradle build — passed

@renovate
renovate Bot merged commit 667da1f into main Oct 5, 2026
6 checks passed
@renovate
renovate Bot deleted the renovate/jdx-mise-2026.x branch October 5, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants