chore(deps): update dependency jdx/mise to v2026.9.16 - #30
Merged
Merged
Conversation
✅ Markdown lint — no issues found |
✅ Renovate — configuration is valid |
✅ ghasec — no issues found |
✅ Gradle build — passed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.9.14→2026.9.16v2026.10.3(+5)Release Notes
jdx/mise (jdx/mise)
v2026.9.16: : Per-tool libc for aqua tools, monorepo task path aliases, and packslip pins that survive repo renamesCompare Source
Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in
mise run --no-timings,cargo +nightlyand theoutdated/upgradeversion comparison, and speeds up shims and config loading.Added
Per-tool
libcfor aqua tools. On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such asaqua:domcyrus/rustnet. You can now pick the build for a single tool instead of changing the globallibcsetting. #13701The option accepts
glibc(orgnu) andmusl. mise never falls back to the other libc for that tool. The option applies to install,mise lock, and checksum, signature and provenance lookups, and it is recorded in the lockfile's tool options. A platform that already names a libc (a musl host or alinux-*-musllockfile platform) still wins. A version that is already installed keeps its build until you runmise install --force.mise ls-remotestill uses the host libc. If a registry template uses a variable namedlibc, set it asvars.libc.Path aliases for monorepo tasks. Deeply nested config roots can now have a short name. #13756
mise run //123:buildruns//foo/bar/baz/abc/123:build. Aliases also work in task dependencies, in patterns like//123:*, and in child paths like//123/sub:build. Each alias must be a single path segment, must point at a configured root, and can't overlap an existing root path. A task's full path is still its canonical name.Packslip tools keep installing after a repository rename. mise now pins GitHub and GitLab packslip projects by the repository ID recorded in the signing certificate, not only by name. If
old/toolis renamed tonew/toolunder the same owner,packslip:github.com/old/toolkeeps installing and prints a warning once, asking you to update the config. You don't needmise packslip forget. mise refuses a transfer to another owner. It also refuses a different repository that takes over a pinned name, which is how a deleted and re-created name looks. To accept either one, runmise packslip forgetfor the old name, and for a re-created repository also remove the tool'smise.lockentries. #13702, #13738In lockfile revision 3, the IDs are stored as:
mise dot track --allow-plaintext. Directly tracking a file with a credential-like name (for example~/commit-mossy-token.md) used to report success while every history save quietly left the file out.mise dot tracknow asks whether to save the file in plaintext, and the default answer is No. In non-interactive use, pass--allow-plaintext.--yesdoes not approve plaintext. The choice is saved asallow_plaintext = trueon the[dotfiles]entry. For real credentials, use--encrypt. #13749Registry:
mise use mbxnow resolves tomr-boxington. #13752Fixed
mise outdatedand upgrade warnings no longer offer an older release as an update when the installed version has avorVprefix. For example,v2.1.280 → 2.1.278was shown as an update. Versions that differ only in build metadata (for example1.36.4+k3s1and1.36.4+k3s2) are now treated as equal. #13690 (@himkt)mise run --no-cacheandmise tasks run --no-cachenow clone remotegit::task includes again, and fetch remote tasks that run as dependencies again. Before, both kept using the cached copy. #13697 (@irisTa56)mise run --no-timingshides each task's "Finished in …" line again, not only the run total. It also overridesMISE_TASK_TIMINGS=1. This had regressed in v2025.11.2. #13718cargo +nightlyworks again withrust = "nightly". Since 2026.8.6 mise installs a dated nightly, so rustup had no toolchain namednightly. Depending on rustup's auto-install setting,cargo +nightlythen either failed or downloaded a second, unpinned nightly. mise now also sets up rustup'snightly-<host>toolchain from the pinned nightly, using reflinks or hardlinks. It leaves alone a rustup nightly that is newer or has extra components or targets. Explicitly dated requests such asnightly-2026-08-13don't touch it. Existing installs pick this up on their next nightly install, or right away withmise install -f rust. #13707mise dot trackagain on a path that is already tracked now reports "already tracked". It no longer prompts, rewrites the config, or records an empty checkpoint. Changed file contents and flags that change the declaration (such as--no-autosave) are still saved. #13648Security
SLSA provenance must come from the expected signer. Before, any valid Sigstore signature, even from an unrelated workflow, passed SLSA verification. mise now checks the certificate's URI identity and OIDC issuer against the values configured for the tool:
signer_identityandsigner_issuerunderslsa_provenancegithub:tools: theslsa_signer_identityandslsa_signer_issuertool options (the identity supports{{version}}templating)slsa_signer_identityandslsa_signer_issuerreturned fromPreInstallIf a tool doesn't configure both values, mise skips the SLSA check and uses any other verification available. For now this applies to the bundled aqua packages that have SLSA metadata but no signer fields. SLSA lock entries are checked again on every install, even when a checksum is present. #13725
Public-key DSSE bundles used by aqua and vfox verification must now have a SHA-256 subject digest that matches the downloaded artifact. Before, a valid bundle could be reused to verify a different download. #13721
Performance
rustupchecks whenrustis configured alongside other tools. The same goes formise execwith auto-install disabled. One report measured thegoshim at about 31 ms withrustin the config, compared with 12 ms without it.mise install, andmise execwith auto-install on, still detect and repair missing rustup components. #13705node = "24") do less work: plugin shorthands are built without checking every registry tool's backends, global-config checks stop resolving symlinks for every tool, and fuzzy matching no longer compiles regexes. #13694, #13695, #13696Documentation
prefixwhen tasks run in parallel andinterleavewhen they run in sequence. #13716Breaking Changes
mise.lockfiles are written aslockfile_version = 3, and older mise versions reject them. Existing lockfiles keep their revision when mise writes to them. When a revision 2 lockfile gets packslip repository IDs, mise warns and leaves them out. To store them, runmise lock --upgradeonce everyone who shares the lockfile is on this release.mise lock.allow_plaintext. Upgrade every machine that shares the history before you use--allow-plaintext.New Contributors
Full Changelog: jdx/mise@vfox-v2026.9.17...v2026.9.16
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.15: : vfox tools in OCI images, faster shell prompts, and safer dotfiles pattern matchingCompare Source
mise oci buildcan now package tools installed by vfox plugins, and vfox plugins can repair an existing install when its tool options change. Shell prompts,cd, and settings loading are faster. Dotfilesinclude/excludepatterns now follow.gitignorerules for*and a leading/, which fixes a case where rollback could delete a live file.Added
vfox tools in OCI images (experimental).
mise oci buildused to reject every tool installed by a vfox plugin. It now builds those tools into the image, with one layer per tool plus one layer per plugin at/mise/plugins/<name>/, so mise inside the image can resolve the tool without cloning the plugin. The plugin's env hook runs on the build host. Install-dir paths are rewritten to their in-image location, and mise warns when a value points into the host's home directory. Changing a plugin invalidates the reused layers of its tools onmise oci push. asdf plugins are still rejected. #13670vfox plugins can repair installs that no longer match tool options. Plugins can add an optional
hooks/mise_install_satisfied.luahook that tells mise an installed version no longer matches its options, for example after a component is added to a gcloud config.mise installand auto-install (such asmise x) then rerun the plugin'sPostInstalland the tool'spostinstallscript on the existing install without downloading it again. If the hook itself errors, mise warns and keeps the install. Plugins without the hook work as before. Seedocs/tool-plugin-development.md. #13668Git subdirectory installs for
pypi:. Git sources now accept a#subdirectory=fragment (other fragment keys are passed through as written), andgit+<scheme>://URLs work without a trailing.git. Each subdirectory is its own tool with its own install directory.lateststill means the repository's newest GitHub release, so pin a branch or commit if those releases predate the subdirectory. #13607 (@jakedgy)max_versionfor registry backends. Registry entries can now set an exclusivemax_version, alone or together withmin_version, so older releases can come from a legacy backend and newer ones from another. It requiresversion_order = "semver". A locked backend is used only for versions it serves. #13676Mac App Store names in
mise bootstrap packages status. Installedmas:packages now show the app name next to the numeric ID (for example1056643111 (Clocker)), and--jsonadds anamefield. Apps that aren't installed still show only their ID. #13622Registry: added
sofka(#13612, @jylenhof),imessage-exporter(#13640, @i-api), andspotify-downloader(#13641, @i-api).nub0.9.5 and later now installs fromgithub:nubjs/nub, and the entry lists thenubrbin (#13643, @colinhacks).cocogittonow listscogas its bin (#13657).Changed
mise execwarns when a missing pinned tool falls back toPATH. When auto-install is off (exec_auto_install = false,auto_install = false, orauto_install_disable_tools) and the command belongs to a pinned tool that isn't installed, mise used to run a same-named binary fromPATHwithout saying anything. It still runs it, but now prints a warning such asjq@1.7.1 is not installed and auto-install is disabled, so mise looks for jq on PATH instead. There's no warning when another configured version of the tool, a command wrapper, or a projectenv._.pathentry provides the command. #13650, #13658mise tasks validatefails on unparseable usage specs. A file task's#USAGEspec (or a TOML task'susage) that doesn't parse is now ausage-parse-errorerror, so validation exits 1, including with--errors-only. Before, it was only a warning and validation passed.mise runandmise tasks lsbehave as before. CI that runsmise tasks validatewill now fail on these specs. #13672cargo installare unchanged. #13687Fixed
Dotfiles
*no longer crosses/in trackedincludepatterns. Capture and rollback used to disagree about whatrules/*.mdselected. After you widened the list,mise dot rollbackto an older checkpoint could delete a nested file such asrules/deep/two.md.includenow follows.gitignorerules:*stops at/, and you need**to match nested files.excludelists keep matching what they matched before, but mise now prints a deprecation warning when an exclusion depends on*crossing/. Use**in those patterns instead. #13618/anchorsinclude/excludepatterns to the entry root. Before, these patterns matched nothing at all. Nowexclude = ["/cache"]skips only the top-levelcachedirectory, andinclude = ["/rules/*.md"]works. In the global[history] excludelist, a leading/still means an absolute path. #13621Tasks and config
conf.dfolder fragment now run in that folder, with{{config_root}}andMISE_CONFIG_ROOTpointing there. Each folder's[task_config]applies only to its own tasks, so a fragment'sincludesno longer hides the default task directories like~/.config/mise/tasks. #13662Plugins and shims
[plugins]entry. The warning appears inmise install,mise plugins install, andmise doctor. Related fixes #13663:mise plugins install --force <name>now reinstalls from the[plugins]pin.owner/repo#v1.2.0keep their ref.[wrappers.*]command wrappers (including thecargowrapper thatmr_boxingtongenerates) now run throughexe- andfile-mode shims andmise x. Before, the real tool ran instead. #13673Bootstrap
apt-get updateonce if the simulation fails. This fixeshas no installation candidatefailures on machines whose package lists cover only the install media. #13659mise bootstrap macos defaultsnow reads and writes the container plist for sandboxed apps such as Safari, which the app actually uses. Launch the app once first so its container exists. Writing another app's container may require Full Disk Access for your terminal. #13660mise bootstrap packages prunefails on abrew:formula it can't resolve, the error now names the config file that declares it. When the name is actually a cask, mise suggestsbrew-cask:<name>. #13661Performance
mise hook-envno longer loads all settings or starts the async runtime (6.6 ms to 4.9 ms on Linux in the PR's measurements), as long ashook_env.chpwd_onlyandhook_env.cache_ttlare unset. #13686cdwith npm tools installed. The npm install health check now reads the virtual store's directory listing instead of callingstaton every package. #13685conf.dglobs for directories that don't exist, which halves settings load time in deep checkouts. #13688brew-cask:lookups. Official casks are resolved from Homebrew's bulkcask.jsonindex, cached locally and re-checked with a conditional request after 7.5 minutes, instead of one request per cask. In the PR's test,bootstrap packages statuswith 143 casks dropped from about 26s to about 2s. #13349 (@waynehoover)mise upgradecomes due but the version is still in use, mise now re-checks it once a day instead of on every command. This could make trivial commands about 9x slower. Pruning can now happen up to a day after the last reference is removed. #13674mise ls,mise prune, and shim rebuilds scan install directories in a single pass. #13675Full Changelog: jdx/mise@vfox-v2026.9.16...v2026.9.15
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (in timezone Asia/Tokyo)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.