chore(deps): update dependency jdx/mise to v2026 - #220
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
6 times, most recently
from
July 30, 2026 03:03
b069281 to
4210d96
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 5, 2026 03:26
7255dd3 to
18a73a9
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
3 times, most recently
from
August 12, 2026 20:16
2752ba1 to
661a5bf
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 20, 2026 23:10
6445a85 to
c5325ef
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
August 26, 2026 03:48
9dd559c to
fac6f2e
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 3, 2026 00:28
61548e9 to
844f10e
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
4 times, most recently
from
September 11, 2026 04:03
b504efd to
25c7628
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
from
September 13, 2026 02:55
25c7628 to
d7b6a0c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.
Release Notes
jdx/mise (jdx/mise)
v2026.9.6: : Project daemons, mise doctor project, and vfox backend tool discoveryCompare Source
This release adds experimental project daemons backed by pitchfork, a
mise doctor projectcommand for project-declared diagnostic checks, and tool discovery from vfox backend plugins inmise search. It also changes the HTTP backend's default install layout so uninstall and prune reclaim disk space, speeds up warmlockfile_mode = "generate"installs and repeated OCI builds, and fixes a batch of nushell, monorepo, lockfile, brew, and Windows bootstrap issues.Highlights
[daemons]declares background processes and PostgreSQL/Redis presets inmise.toml, managed throughmise daemonsand optionally started when you enter the project.[doctor.checks.<name>]lets projects declare their own environment probes formise doctor project.mise search, shell completion, and interactivemise usenow include tools published by installed vfox backend plugins, andsettings.truncate/--no-truncatedisable terminal-width truncation (automatically when a coding agent is detected).shared_extraction = true), warm generate-mode installs skip needless lockfile rewrites, and OCI builds share a local tool-layer cache.Added
daemons: New experimental
[daemons]section andmise daemonscommand family (start,stop,restart,ls,status,logs,tui) manage project background processes with pitchfork. PostgreSQL and Redis presets install the database as a tool (participating in lockfiles), supply connection environment variables and readiness checks, and keep project data across stop/start. Daemons withauto = ["start", "stop"]start when entering the project from an activated Bash, Zsh, or Fish shell and are released when the last shell session leaves. Requiresexperimental = trueand pitchfork 2.25.0 or later; database presets are Unix-only and PostgreSQL uses loopback trust authentication intended for local development. (#13085 by @jdx)doctor:
mise doctor projectruns checks declared in[doctor.checks.<name>]with the project's environment and installed tools, reporting PASS/FAIL/error/skipped per check in text or--json. Checks supportdescription,hint,timeout(default10s),dir,shell, andosselectors, run concurrently under thejobslimit, and exit nonzero when any check fails. Ordinarymise doctordoes not run them, and hints are never executed. A follow-up aligneddirresolution with task conventions (config root for project configs including~/mise.toml,~/expansion), fixed head-of-line blocking when one probe hangs, and keptnohup mise doctor projectalive on SIGHUP. (#13062, #13089 by @jdx)vfox: Tools provided by installed vfox backend plugins now appear in
mise search, shell completion, and interactivemise use, namespaced as<plugin>:<tool>. Plugins can implementBackendListToolsfor a finite catalog and/orBackendSearchToolsfor query-driven discovery in large ecosystems; a prefixed query likenpm:eslintis routed only to that plugin. Results are cached, slow plugins fall back to stale cache, and existing plugins need no changes.mise registryremains registry-only. (#13111 by @jdx)cli: New
settings.truncate(andMISE_TRUNCATE, defaulttrue) controls terminal-width shortening of table cells and task metadata.mise ls,mise config ls, andmise bootstrap dotfiles statusgain--truncate/--no-truncate, and output is kept complete automatically when a known coding agent is detected. (#13112 by @jdx)bootstrap:
[bootstrap.macos.dock]gainsapps, an ordered list of pinned application paths. Status compares identity and order (ignoring Dock-added metadata), apply adds, removes, and reorders application tiles while preserving other tiles andpersistent-others, and an empty list removes all application tiles. Paths must be absolute or home-relative.appbundles. (#13075 by @azohra)bootstrap:
mise bootstrap packages where brew:<formula>prints an installed formula's stableoptroot (for example/opt/homebrew/opt/unzip), so scripts can put keg-only executables on PATH without hardcoding the Homebrew prefix or Cellar version. Missing installs exit nonzero with empty stdout. (#13083 by @himkt)dotfiles: Destination
variantscan omitsourcewhen every variant sets atarget; the entry key is then resolved as a relative path undersettings.dotfiles.rootinstead of next tomise.toml. Parent traversal is rejected. (#13087 by @jdx)fmt:
mise fmtnow sorts lists whose order has no meaning:redactionslexically, and tasksources/outputs,task_templatessources/outputs,task_config.global_inputs, andinput_groupsby reach (@group:references, then globs, then literal paths). Lists containing!exclusions, entries starting with template syntax, or comments are left untouched, and precedence-sensitive lists such asenv_file,tools.*,includes, anddependsare never sorted. (#13058 by @jrandolf)oci:
mise oci buildgains--no-cacheto bypass the new local tool-layer cache; entries live under each tool's cache directory and are removed bymise cache clear TOOL. (#13056 by @jdx)Changed
http:installations extract directly into their own install directory, somise uninstallandmise prunenow remove their files instead of leaving payloads in$MISE_DATA_DIR/http-tarballs/. Setshared_extraction = trueon a tool to keep the previous deduplicated symlink layout. Existing symlinked installs keep working;mise install --force <tool>migrates one to independent files without disturbing other installs that share the content. Legacyhttp-tarballsentries are not reclaimed automatically. Shared raw and compressed binary caches now also include the executable filename in their key, so differently named tools no longer reuse the wrong filename. (#13059 by @jdx)mise oci push --no-cachenow bypasses both the remote registry cache and the local tool-layer cache. (#13056 by @jdx)postgres,redis, andmongodbnow preferconda:backends, installing prebuilt conda-forge binaries in seconds instead of compiling through vfox; vfox and asdf remain as fallbacks.conda:redis-servercovers Linux and macOS only. (#13061 by @jdx)Performance
mise installruns inlockfile_mode = "generate"skip scheduling work for tools whose artifact metadata is already reusable, and skip rebuilding, serializing, and staging the lockfile entirely when nothing was installed and the on-disk lock already matches (preserving comments in the file). Explicitmise lock, forced provenance verification, upgrades, and new platforms still regenerate. (#13101, #13103 by @jdx)mise oci push --from BASEno longer downloads base layers when the base and target live in the same repository, andoci build,oci run, andoci pushshare a local cache of packaged tool layers keyed on file contents, so repeated builds with overlapping tools skip tar and gzip work. (#13055, #13056 by @jdx)Fixed
mise activate nuno longer throwsenv_variable_not_foundon every prompt orcdwhen a variable to hide is absent from the current scope;hide-envis now wrapped intry, matching the no-op behavior of other shells. (#13071 by @i-api)runentries, including names rendered at runtime, right before they execute;--skip-toolsis honored and install failures are reported as task failures without blocking siblings. (#13086 by @jdx)[monorepo]settings are now merged across same-directory config layers (base plusmise.<env>.tomloverlays): omitted fields are inherited, an overlay'sconfig_rootsreplaces the base list, andmonorepo_root = falsein an overlay disables the root and its descendant trust. (#13084 by @jdx)mise which hk --tool hk@latestnow use the lockfile belonging to the config that effectively defines the tool, instead of merging project and global pins and reporting a false "multiple resolutions" ambiguity or selecting an overridden pin.mise which --toolwarns when a lower-precedence config has a matching pin the effective config lacks. (#13042 by @nettlesh)github-attestationsmetadata on upgrade instead of being rejected as a provenance downgrade. (#13102, #13105 by @jdx)mise upgradenow detects updates between letter-suffixed versions such as tmux3.7bto3.7c;sub-Naliases keep resolving numeric components as before. (#13119 by @jdx)brew:zipandbrew:unzip) are now linked into<prefix>/binon Linux, matching Homebrew. Kegs installed by earlier mise versions stay unlinked until the nextmise bootstrap packages upgradeor a reinstall. (#13108 by @lil-lon)preflight_stepsorpostflight_stepsno longer fail during metadata extraction; declarativerunsteps are captured as structured steps and executed by mise, with support formust_succeed = false. (#13060 by @jdx)mise bootstrap remoteon Windows now findsssh.exeandtar.exeon PATH instead of failing withrequired command 'ssh' not found. (#13117 by @JamBalaya56562)2 (real; expected integer)instead of two identical-looking values markeddiffers. (#13096 by @jdx)mise bootstrap dotfiles trackhonors the globalyessetting for confirmations, and warns when tracking a symlink whose resolved source is not itself tracked, suggesting the command to enroll it. (#13072 by @nettlesh, #13095 by @jdx)manifestdotfile entries, restricting explicit modes tocopyorsymlink-eachand rejecting combinations with inline content or file-edit fields. (#12741 by @risu729)mise asdf installandmise asdf reshimno longer re-enter the full CLI dispatch, avoiding stack overflows on small-stack Linux environments;asdf installnow follows the same implicit config trust asmise install. Bash completions are regenerated for the updated usage-rs word-break handling. (#13114 by @jdx)Registry
mpv(conda:mpv, Linux and macOS) (#13049 by @i-api),agent-browser(aqua:vercel-labs/agent-browser) (#13088 by @3w36zj6), andhimalaya(github:pimalaya/himalaya) (#13091 by @i-api).editorconfig-checkerinstalls again after 4.0.1 renamed its assets and executable; the shorthand now uses the GitHub backend. (#13098 by @jdx)mcinstalls from MinIO's GitHub releases instead of the retired Aqua download URL that returned HTTP 410. (#13113 by @jdx)Documentation
New Contributors
Full Changelog: jdx/mise@v2026.9.5...v2026.9.6
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.5: : macOS defaults, per-platform dotfiles, and complete lockfilesCompare Source
This release deepens macOS bootstrap support with current-host and nested defaults, lets dotfiles and tasks adapt to the platform and to parsed arguments, and adds an opt-in trial of complete lockfile generation. It also carries a batch of install progress, self-update, brew-cask, and sandbox fixes.
Added
bootstrap: New
[[bootstrap.macos.defaults_entries]]blocks let you set macOS preferences explicitly withdomain,key,value, and an optionalhost(anyby default, orcurrent), covering preferences normally written viadefaults -currentHostwhile keeping the existing[bootstrap.macos.defaults]shorthand. Entries also accept an optionalpathto patch a nested dictionary value without replacing its siblings, preserving property-list types and creating missing parents. (#12983 by @azohra, #12984 by @azohra)bootstrap: More friendly macOS preferences: Finder folder sorting and default cloud save location, Dock autohide delay and timing (integers or floats), and keyboard automatic capitalization and spelling correction, all using snake_case names consistent with the existing sections. (#13032 by @jdx)
bootstrap:
[bootstrap.files]and[bootstrap.directories]entries gainphase = "pre-packages"so repository definitions, apt sources, and signing keys can be applied before package installation instead of only afterward. Existing declarations default to"post-packages". (#13052 by @jdx)bootstrap: Ordinary
[bootstrap.files]templates can now reference resolved[vars]values, alongside the existingconfig_root,target, andsecret()helpers. (#13033 by @nettlesh)dotfiles: A single dotfiles source can deploy to different destinations per operating system, architecture, or mise profile using
variantswith an optionaltarget. This works forcopy,symlink,symlink-each, andtemplatemodes. (#13050 by @jdx)task: Task
sourcesandoutputscan now use{{usage.*}}templates, resolved per invocation from parsed arguments and flags before freshness and artifact-cache checks run, so different argument values track freshness independently. (#13051 by @jdx)brew-cask: Casks with structured
set_permissionspreflight/postflight steps now install correctly (for examplebrew-cask:blender), running an unprivilegedchmodover resolved staged or appdir paths instead of failing with an unsupported step-type error. (#13043 by @azohra)lock: Opt-in trial of complete lockfile generation via
lockfile_mode = "generate"(orMISE_LOCKFILE_MODE=generate). The default remains incrementalmerge. Generate mode rebuilds lockfiles from current requests while treating the previous file as an immutable baseline, reusing unchanged artifacts and publishing through staged atomic writes so failures or concurrent edits do not clobber a good lockfile. This mode records only cryptographically verified provenance per target platform;provenance_verifiedis no longer treated as a trust signal. (#13031 by @jdx)self-update: New
disable_update_warningsetting (MISE_DISABLE_UPDATE_WARNING) suppresses "newer mise available" notices inmise version,mise --version, andmise doctor. Explicit self-update and automatic updates are unaffected. (#13028 by @jdx)Fixed
installed 1 tool in 1.1s: dummy@1.0.0).mise upgradeno longer duplicates its old to new version list. (#13030 by @jdx)mise self-updatenow selects the correctlinux-armv7archive instead of requesting a missinglinux-armone and falling back to an ARM64 binary that failed signature verification. A missing archive now fails asset selection rather than picking the wrong architecture. (#13023 by @jdx)mise self-update. (#13028 by @jdx)mise bootstrap packages upgradeno longer replaces the bundle of a running self-updating app (for example Chrome), which could strand helper processes and blank out tabs. Such apps are skipped while running and left to update themselves. (#13041 by @azohra)brewand a broken documentation anchor; it now gives a short, accurate message. (#12800 by @Marukome0743)mise bootstrap dotfiles origin set <url>now uses the repository's own default branch when--branchis omitted, so repositories onmasterconnect correctly instead of publishing a second root branch. A missing requested branch is now reported clearly rather than mistaken for an empty repository. (#13037 by @Dhaulagiri)dotfiles statusno longer misreportsdeclared-not-running. Existing watchers must be stopped and restarted with the updated binary. (#13038 by @ascarter)file-read-metadataon the ancestors of readable paths, fixingOperation not permittedfailures when a portable Ruby resolves its own executable during third-party tap evaluation. Symlinked data directories and allow-listed paths are also handled. (#13039 by @Marukome0743)Registry
clipboard(github:Slackadays/Clipboard) by @i-api in #13044New Contributors
Full Changelog: jdx/mise@v2026.9.4...v2026.9.5
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.4: : Nix Bootstrap, Environment Selectors, and Man PagesCompare Source
This release expands the bootstrap package model with Nix support and environment selectors, teaches packslip tools to ship man pages, and adds a task-scoped quiet setting. It also carries a wide batch of packslip, bootstrap, and cross-platform fixes plus a major speedup to dotfiles history rebuilds.
Added
bootstrap: Nix is now a built-in
[bootstrap.packages]manager on Linux and macOS. Declare packages with thenix:prefix and apply them through your normal Nix profile; the manager supports use, apply, status JSON, and targeted upgrades while leaving Nix sources, caches, trust, and profile rollback under Nix control. This also addsmise bootstrap packages export --format nixto emit a deterministic NixOS module from yournix:declarations andpackages use --no-installto record declarations without touching package managers. (#13013 by @jdx)bootstrap:
[bootstrap.packages]entries gain anenvselector (a single environment or a list), so a package is only enabled when one of its listed mise environments is active via-EorMISE_ENV. When bothosandenvare set, both must match. Packages for inactive environments stay declared and are protected from pruning. (#12956 by @jdx)packslip: Packslip-installed tools can now ship man pages declared as static
manresources, alongside completions and agent skills. While a tool version is active, mise prepends its man root toMANPATHand keeps system and caller-defined paths visible, soman <tool>works. Existing installs need to be reinstalled to pick up man pages. (#13012 by @jdx)task: New
task.quietsetting (andMISE_TASK_QUIET) suppresses mise's own task messages, prefixes, and command-echo headers without hiding task output or affecting other commands. The bundledoutput = "quiet"mode is deprecated in favor of explicit output style plus this setting; removal is scheduled for 2027.9.3. (#12980 by @jdx)Fixed
dependstarget is also lazy now installs correctly on first use through a shim,mise x, or a task; mise installs the provider together with its still-missing configured dependencies instead of failing the preflight. (#12997 by @balintant)armarchitecture name for Aqua (so registry replacements apply), and automatic GitHub release asset selection no longer picks a genericsource.tar.gzwhen no published binary targets the host. (#13004 by @jdx)mise lock --platformnow verifies the signed release manifest and records the correct URL, checksum, size, and signer for each requested target platform (including Windows x64), so locked installs work across platforms. (#13002 by @jdx)glibc_minis now honored during selection: when the GNU build requires a newer glibc than the host, mise falls back to a matching static musl build if one exists. (#13009 by @jdx).exefilename, while Unix keeps extensionless names. (#13006 by @jdx)MANPATHis included in the environment-cache identity so one cached process cannot serve another caller'sMANPATH. (#13016 by @jdx)mise pruneno longer exits successfully without pruning when it cannot show a confirmation prompt; it now fails with guidance to pass--yesor setMISE_YES=1. Follow-up prunes from commands likemise unusestill leave installs in place when nobody can answer. (#13003 by @jdx)mise generate tool-stubnow respects a stub's top-levelosselector when deciding whether to write a Windows.cmdlauncher, so a linux/macos-only stub no longer produces a launcher even with--lock. (#13008 by @jdx)HOMEis a symlink, so aliased, canonical, and tilde paths address the same history entry andshow latest/diffno longer report a missing checkpoint. (#12982 by @azohra)cargo install --locked misebuilds from crates.io. (#13001 by @jdx)Changed
[bootstrap].config_rootsand themise bootstrap config-rootscommand are now deprecated (hidden from help and removed from public docs), with removal scheduled for mise 2027.3.3. Existing configurations keep working during the compatibility window but emit a warning directing users to global or system bootstrap configuration. (#13010 by @jdx)Performance
Deprecated
output = "quiet"mode (usetask.quietinstead; removal in 2027.9.3) (#12980).[bootstrap].config_rootsandmise bootstrap config-roots(removal in mise 2027.3.3) (#13010).New Contributors
Full Changelog: jdx/mise@v2026.9.3...v2026.9.4
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.3: : Winget bootstrap, signed vfox plugins, and faster inline commandsCompare Source
This release brings Windows bootstrap into the package-manager era with WinGet support, extends the packslip signing model to vfox plugins, and speeds up simple tasks by skipping the shell on Unix. It also carries a batch of bootstrap, sandbox, and Windows ARM64 fixes.
Added
bootstrap: WinGet is now a built-in
[bootstrap.packages]manager on Windows, somise bootstrap packagescan check status, install, and upgrade apps by exact package ID. It supports version pins, source refresh, and automatic source-agreement acceptance. Scoop, Chocolatey, and package removal remain future work. (#12928 by @jdx)vfox: External vfox plugins can now be installed from signed packslip archives instead of a Git clone, reusing the packslip backend's release selection, signature verification, digest checks, and signer pins. This is aimed at non-registry plugins; registry defaults and embedded plugins are unchanged. (#12948 by @jdx)
mise plugins install vfox:bfs 'packslip:mise-plugins/vfox-bfs#0.1.0'bootstrap: Dotfile line edits gain
position = "prepend"to insert a managed line at the top of a file instead of appending (the default). An existing exact match is left in place, and unrelated bytes, CRLF endings, and a UTF-8 BOM are preserved. (#12941 by @jdx)bootstrap: macOS bootstrap
defaultsnow support nested TOML arrays and tables (for example Dockpersistent-apps), reading and writing preferences through Core Foundation so booleans, numbers, strings, arrays, and dictionaries keep their plist types. Collections apply as whole-value replacements; datetimes and binary plist data are still skipped with a warning. (#12947 by @jdx)Changed
mise bootstrap --adopt(andmise bootstrap remote --adopt), separate frommise bootstrap --fromfor running a bootstrap project. The dotfiles, history, setup, and services guides were reorganized to lead with usable examples. The previous--from-gitspelling still works as a hidden alias but warns and is scheduled for removal in mise 2026.10.0. (#12953 by @jdx)Fixed
github.comHTTPS credential helper. Tokens are kept out of command arguments and URLs, and Enterprise hosts are out of scope. (#12945 by @jdx)sh -o errexit -cso shells that consume the argument right after-c(such as FreeBSD sh) run your command instead of trying to execute-o. (#12949 by @jdx)cargo.exe) that caused recursive.exe/.cmddispatch after shim-mode changes are now pruned, and Aqua ARM64 emulation candidates apply the registry'samd64replacement so tools like LuaLS resolve their publishedwin32-x64assets. (#12931 by @jdx)pacman -Qprints a file advisory for a missing package that shares its name with a directory in the current working directory (for example afish/folder in a dotfiles checkout). (#12932 by @nettlesh)/private, fixing startup failures for load-relative binaries like Ruby 4.0.6 when run under/private/tmp. Directory listings and descendant reads stay denied. (#12940 by @jdx)dotfiles syncruns no longer race the helper and macOS accepts it. Unsigned source builds (such as Homebrew) disable notifications and warn during origin setup. (#12946 by @jdx)java -versionbanner shown during install verification now stays inside the interactive install progress row instead of printing to the terminal. (#12943 by @jdx)mise versionnow uses themise settings auto_update=truesyntax to match the rest ofmise settings. (#12957 by @jdx)Performance
node build.js) now run directly when a conservative planner deems them safe, skipping the shell wrapper. Anything involving shell syntax, quoting, expansion, builtins, ambiguous PATH lookup, explicit shell settings, or sandboxed/audited tasks still uses the shell, and Windows is unchanged. In a microbenchmark of short commands this cut about 11% off elapsed time. (#12950 by @jdx)Registry
Documentation
Full Changelog: jdx/mise@v2026.9.2...v2026.9.3
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.2: : Packslip Backend, SSH Relay, and Reimagined Install ProgressCompare Source
This is a large release headlined by the new stable
packslip:backend for installing tools from a vendor's own signed release manifest, a read-only GitHub SSH relay for remote onboarding, redesigned install progress for both terminals and CI logs, and a rebuilt dotfiles-tracking model for bootstrap. It also carries dozens of fixes across shims, tasks, brew, Go, npm, and the schema, plus two security fixes.Highlights
packslip:backend is now generally available: install tools directly from a project's cryptographically signed release manifest, with signer pinning, trusted stampers, host-requirement checks, shell completions, and agent skills all driven from the same signed source.--from-gitonboarding, an AUR package manager, and a rebuilt dotfiles-history model that tracks files through ordinary Git commits synchronized with an origin.Added
packslip: New
packslip:backend installs tools from a vendor-published, signed release manifest (a sigstore bundle) that names every artifact with its digest, platform, format, and executables. The tool name is a pin, like aknown_hostsentry:packslip:github.com/owner/repoaccepts only a packslip signed by that repository's release workflow, and signature, log entry, statement, digest, and size are all verified before anything is unpacked. Custom hosts and monorepo tools are supported. The backend is no longer experimental. (#12778, #12811 by @jdx)packslip: Signer pinning remembers, per project, the signer that signed the first accepted release in a
pins.tomlfile (like SSH's known_hosts) and records the signer inmise.lock, so a later release signed by anyone else, or one that weakens provenance, is refused.mise packslip pinslists what is pinned andmise packslip forget <project>accepts an announced key rotation. (#12783 by @jdx)packslip: New
packslip.stamperssetting lets you require that a trusted host has stamped a version before mise offers or installs it (a scanning service, a mirror, or eventually the registry), with a per-tooltrust = "vendor"override. (#12782 by @jdx)packslip: Declared host requirements (OS/glibc minimums, shared libraries, required commands) are checked before download; confirmed failures refuse the install, gaps mise cannot verify warn only, and
ignore_requirements = trueoverrides hard failures.latestalso resolves from verified vendor recommendations. (#12804, #12805 by @jdx)packslip: A tool's packslip can ship shell completions and agent skills.
mise completion <shell> --tool <name>prints (or--installwrites a version-aware stub for) completions for whichever version is active in the current directory, andmise skills ls/mise skills synclink a tool's Agent Skills into.claude/skillsat the pinned version. Completions are also loaded automatically in activated shells. (#12779, #12780, #12848 by @jdx)install: Redesigned install progress. Interactive terminals now show a live region with an install-wide fractional bar, per-tool phase/elapsed/artifact rows, dependency-wait rows ("waiting for node@24.20.0"), and permanent completion lines written into scrollback.
prune,uninstall, and upgrade removals reuse the same session, so pruning hundreds of versions no longer floods the screen. (#12906 by @jdx)install: CI logs, pipes, and AI-agent terminals (
CLAUDECODE/AI_AGENT) get a compact append-only reporter: one permanent line per finished tool plus a periodic snapshot of the bar, active phases, transfer rates, and queue count, instead of hundreds of scrolling status rows. Resolver hosts and retry progress are surfaced too. (#12902, #12907 by @jdx)ssh: New
mise sshruns ordinary OpenSSH sessions with optional session-scoped, read-only GitHub access, andmise bootstrap remote --from-gitonboards a remote host from a Git repo. The initiating machine keeps the credential and brokers authorized clone/fetch and REST reads over an SSH Unix-socket forward; no token is installed on the target. (#12830 by @jdx)bootstrap:
mise bootstrap --from-git <GIT_URL>clones a repository-backed global config into$MISE_CONFIG_DIRso itsconfig.toml,conf.d/, and tasks apply on the first bootstrap and stay active afterward. (#12715 by @jdx)bootstrap: New
aur:package manager installs from the Arch User Repository viayay(preferred) orparu, with foreign-package status detection so repo packages with colliding names cannot satisfy an AUR request. Bootstrap can also declare packages as absent to remove them, and now reports which root declarations were selected. (#12718, #12716, #12770 by @jdx)bootstrap: Rebuilt dotfiles tracking. Files enrolled with
mode = "track"stay in place while mise commits changes to a separate bare Git store with checkpoints, rollback/undo, and optional origin synchronization, including encryption of shared files before storage. (#12918 by @jdx)activate: New
activate_shims = false(MISE_ACTIVATE_SHIMS=false) keeps tool shim directories off PATH during activation and hooks without changing your auto-install or lazy-tool settings. Command wrappers such as mr-boxington'scargokeep working. (#12926 by @jdx)core: Rust tools accept
mr_boxington = trueandmise usegains a repeatable--tool-option KEY=VALUEflag, so setting up the Cargo wrapper is a single command. (#12908 by @jdx)ruby: mise now reads Bundler's
ruby file: ".ruby-version"form from aGemfile(resolving the path next to the Gemfile), so projects that pin Ruby through a sibling file resolve correctly. (#12914 by @jdx)self-update: New global-only
self_update.repositoryandself_update.api_urlsettings let organizations point manual updates, out-of-date hints, and automatic updates at a curated GitHub or GitHub Enterprise release mirror. Project config cannot redirect updates, and artifacts still pass the embedded-signature check. (#12735 by @jdx)backend:
install_envis now applied when resolving and downloading tools, not just at build time. (#12777 by @rabadin)brew: mise can now evaluate ordinary third-party taps. (#12774 by @jdx)
Fixed
mise-shim.exeresolves correctly through a symlinkedmise.exe. (#12699 by @jdx, #12915 by @acooler15)sourcesaccepts a single string, task status is preserved when the cache audit tracer fails, and POSIX shells no longer have PATH pre-converted (the shell already does it). (#12711, #12769 by @jdx, #12530 by @risu729, #12696 by @JamBalaya56562)auto_updatesenabled are upgraded correctly. (#12645 by @Marukome0743, #12837 by @soodoh, #12857 by @himkt)Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.