chore(deps): update dependency jdx/mise to v2026.7.12#87
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 1, 2026 14:51
b80483b to
e746981
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
April 3, 2026 13:52
7bca63d to
78cde9b
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
April 6, 2026 13:24
71dfc7c to
2c2deda
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
April 9, 2026 10:49
9807261 to
23e68ca
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 10, 2026 14:16
23e68ca to
5dbfe28
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 11, 2026 20:28
5dbfe28 to
0b27243
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 12, 2026 13:32
0b27243 to
4772b7b
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 13, 2026 13:17
4772b7b to
08413f6
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 16, 2026 10:41
08413f6 to
7f4fed8
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 16, 2026 17:43
7f4fed8 to
d106507
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 17, 2026 15:11
d106507 to
0d1ebc0
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 18, 2026 17:00
0d1ebc0 to
29746be
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 27, 2026 13:23
8f3ef1a to
647eacb
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 28, 2026 17:43
647eacb to
72020a7
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 29, 2026 16:37
72020a7 to
fd1ed23
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 29, 2026 23:24
fd1ed23 to
edf5298
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 30, 2026 16:05
edf5298 to
1d8da69
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
May 10, 2026 12:44
406abab to
ac5e40c
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
May 11, 2026 18:01
ac5e40c to
a88eca2
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
May 14, 2026 21:39
ce968d3 to
ca638bd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.3.17→2026.7.12Release Notes
jdx/mise (jdx/mise)
v2026.7.12Compare Source
v2026.7.11: : Task Source Tracking and Activation SpeedupsCompare Source
This release sharpens task handling around remote files, global config, and tool selectors, trims redundant work from shell activation, and fixes several bootstrap and platform-specific edge cases.
Added
config: structured tool definitions now accept
version,path,prefix, andrefselectors consistently in root[tools], inline task definitions, task templates, and file-task headers. Exactly one selector is required, and conflicting, missing, or non-string selectors now fail with a clear configuration error instead of silently defaulting or panicking. (#11069 by @risu729)Fixed
#MISEheaders parsed, so metadata liketools,description, andhideand inline TOML overrides are honored just like local file tasks. Git-backed task files are also made executable after cloning and on cache hits. (#11111 by @Marukome0743)mise tasks --global, stay out of--local, and use the invoking project root. (#11106 by @risu729)mise tasks info, extended listings, task help, and the MCP tasks resource now report every configuration source contributing to a task, with a newconfig_sourcesarray in JSON output. Changing metadata in a TOML overlay now correctly invalidates the merged file task's cache. (#11098 by @risu729)mise --env <profile> watchnow propagates the selected environment to the watched task, so profile-specific tasks resolve correctly on each rerun. (#11114 by @Marukome0743)0755rather than0711), fixing "Could not open input file" errors for interpreters run by non-owner users. (#11135 by @jdx)mise latest java@<vendor>now prefers the base vendor variant over dashed specializations and sorts multi-feature vendor prefixes correctly. (#11109 by @roele)unit = "dotfiles-maintain"), which resolves todev.mise.<name>.service. Fully qualified names likenginx.serviceare still written verbatim. (#11128 by @jdx)auto_updatesare now accepted instead of failing with an unsupported-lifecycle error. (#11107 by @casparbreloh)defaultshandling now treats a missing key or domain as unset rather than erroring during initial setup. (#11118 by @roele)mise uninstallnow removes dangling runtime version pointer files (like16orlatest) and cleans up the now-empty tool directory. (#11095 by @JamBalaya56562)Performance
miseprocess on shell startup. (#11130, #11131, #11134 by @jdx)hdiutil/pkgutilwaits now run viablock_in_place, so parallel installs no longer starve download progress and other tasks of runtime threads. (#11136 by @jdx)Registry
@nubjs/nubpostinstall lifecycle script to run via the npm backend so upgrades keep the~/.nub/shimshardlinks refreshed; default-deny behavior is preserved for all other packages. (#11126 by @risu729)Documentation
Also in this release: v2026.7.8–v2026.7.10
Due to a release pipeline issue, versions 2026.7.8 through 2026.7.10 were tagged but never published. This is the first release since v2026.7.7, so it also ships everything below.
Added
[bootstrap.plugins]config andmise bootstrap plugins apply|statuscommands. Declared plugins install before built-in packages, then plugin-managed packages apply once host tools are available. (#11023, #11024 by @jdx)mise bootstrap repos updateandmise bootstrap repos execcommands. Unpinned[bootstrap.repos]entries are intentionally never pulled by declarative apply;repos updategives an explicit fetch + fast-forward path (with dry-run and path filtering), andrepos execruns a command across configured checkouts.mise bootstrap --updatenow also updates repos. (#11022 by @jdx)registry_floating, mise fetches the latest released registry metadata (and the current aqua registry) instead of the release-pinned copies. Useful on distributions whose mise package lags behind releases while registry entries keep changing. (#10971 by @jdx)mise install tool@x.y.z, andmise x tool@x.y.z. (#11013 by @Turbo87, #11070 by @jdx)Fixed
prefer_offline. Shims, shell activation, andmise xmake one bounded attempt instead of grinding through full retry schedules per endpoint. (#11066 by @jdx)envdirective value aliases (#11062),env.misedirectives (#11053), and the experimental monorepo root key (#11052) are deprecated, and non-stringpostinstallhooks are rejected at parse time (#11061) (all by @risu729)mise prune --dry-runpreserves runtime symlinks (#11017) (all by @risu729)git@vshttps://remotes don't trigger spurious mismatches (#11034 by @jeremy); static systemd units no longer breakbootstrap status(#11056 by @jdx)1.2.3rc1) are detected correctly (#11032 by @jdx); cargo sparse-index version discovery is restored (#11011 by @Turbo87); go resolves direct package module prefixes (#11054 by @jdx)falseinstall env values are treated as removals (#11033 by @risu729)deactivateno longer errors on empty array expansions underset -u(#11026 by @jdx)outputsetting (#11059 by @risu729)bootoutEIO for not-loaded agents is tolerated on macOS (#10965 by @hsbt)TZDIRis set so timezone tests pass in the sandbox build (#11019 by @coryzibell)Performance
mise versiondrops from 8.1ms to 6.6ms,hook-envfrom 10.9ms to 9.3ms. (#11025 by @jdx)hook-env, env rendering, tasks, and exec — ~10% faster on hot paths and ~4% smaller binaries (#11031 by @jdx). macOS tarballs now target macOS 12 (#11027 by @jdx).Refactor
jdx-tar, removing the systemtarfallback and a duplicate tar implementation — consistent archive behavior across platforms (#11028 by @jdx)Registry
Documentation
execbehavior in dry runs (#11018 by @risu729)New Contributors
Full Changelog: jdx/mise@v2026.7.7...v2026.7.11
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.10Compare Source
v2026.7.8Compare Source
v2026.7.7: : Monorepo deps, systemd timers, and OAuth reliabilityCompare Source
This release extends dependency providers and systemd bootstrap to monorepo and timer-based workflows, and hardens GitHub OAuth token refreshes and cache clearing against concurrent mise processes.
Added
deps: experimental
mise deps --monoreporuns dependency providers across every explicitly configured[monorepo].config_rootsentry, aligned withmise install --monorepo. Provider IDs are qualified by config root (e.g.//apps/api:uv) so repeated provider names across subprojects no longer collide, and mise installs the union of tools declared across participating roots before running providers. Plainmise depsremains scoped to the current config root. (#10975 by @jdx)bootstrap: manage systemd user timers alongside services via
[bootstrap.linux.systemd.units]. Timer entries render to.timerunits with scheduling (on_boot_sec,on_unit_active_sec,on_unit_inactive_sec,on_calendar), persistence, andtimers.targetlinkage. Services gain optional directives includingtype,remain_after_exit,exec_stop, start/stop timeouts,no_new_privileges, andprivate_tmp. When a unit name switches between service and timer, the stale sibling unit is stopped, disabled, and removed on apply. (#10984 by @jdx)Fixed
mise cache clearno longer fails withDirectoryNotEmptywhen another mise process (e.g.hook-env) recreates cache files mid-removal. Removal now retries with bounded backoff and tolerates concurrently recreated entries, while permission and other errors still propagate. (#10993 by @jdx).apk,.deb,.rpm, DMG/PKG, MSI/MSIX/AppX and sidecars) during automatic asset selection for thegithub:,gitlab:, andforgejo:backends, so releases containing only unsupported packages now report that no platform asset matches instead of installing an unusable file. Explicitasset_patternand URL selection are unchanged. (#11001 by @risu729)falseoverrides forrosetta2,windows_arm_emulation, andno_asset, so a version or platform override can disable inherited emulation or asset flags instead of being treated as omitted. (#11002 by @risu729).gitURL followed by#v1.0.0), resolving explicit refs against exact remote branch and tag namespaces so annotated tags no longer fail to check out. (#10998 by @junior-ricon)Array#second,#third,#fourth, and#fifthhelpers to the cask shim, fixing casks (such as OrbStack) that referenceversion.csv.second. (#10992 by @casparbreloh)status.show_envoutput now respects thestatus.truncatesetting instead of always truncating. (#10983 by @ytjmt)bootstrap.macos.launchd.agents.<name>.start_calendar_intervalto the published schema (single schedule or array), so strict TOML validators and editors accept valid launchd calendar configurations. (#11008 by @risu729)Registry
New Contributors
Full Changelog: jdx/mise@v2026.7.6...v2026.7.7
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.6: : Sandbox defaults, Flatpak bootstrap, and smarter task outputCompare Source
Added
outputstyle field, decoupled from verbosity, so styles likeprefixand quietness combine freely #10885[settings.sandbox]deny defaults (deny_all,deny_read,deny_write,deny_net,deny_env) #10940[bootstrap.packages]on Linux #10951mise oci build --copy HOST_PATH:IMAGE_PATHand[[oci.copy]]#10952mise doctornow warns when a mise shim is shadowed by an earlier executable inPATH#10919github_contentandgithub_archivepackages via authenticated GitHub API endpoints #10915timeoutvalues now render Tera templates #10959http_download_timeoutsetting caps total download wall-clock time (default 30 minutes) #10920Fixed
nightly) when the installed content is outdated #10827minimum_release_ageis configured #10973os,depends,install_env) #10958usage_*variables per invocation so nested tasks don't inherit stale parser output #10963includesdirectory when editing/adding file tasks #10955language,on_system_conditional) and reuse existing Ruby #10950bin/rename_exeas install-time options #10925podman-remote#10826Changed
cargo.binstall_quickinstall = true#10923Performance
Documentation
Breaking Changes
--quiet/quiet = true/MISE_QUIET=1no longer collapse task output to un-prefixed interleave; they now preserve the resolved style. Use--output quiet(or-o interleave) for the old behavior #10885usage_*variables are now invocation-local; workflows that injected them as implicit inputs must declare an input withenv=instead #10963💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.5: : Worktree-Aware Trust and npm 12 SupportCompare Source
This release makes config trust smarter across git worktrees and monorepos, and fixes npm-backed tools on npm 12.
Added
git worktree addcheckout used to re-prompt for the same config. A config inside a linked worktree is now trusted automatically when the equivalent path in the repository's main checkout is trusted — trusting a repo once covers all of its worktrees. This is especially helpful for workflows that spin up many short-lived worktrees (e.g. AI-agent worktrees under.claude/worktrees/). Sharing flows one way, from main checkout to worktrees; an explicit--ignorestill wins, and paranoid mode is excluded since its trust is tied to per-file content hashes.mise untrustinside a worktree now warns that the main checkout still trusts the config (#10890 by @jdx).mise trust --allnow trusts nested subdirectory configs. Previously--allonly trusted config files in the current directory and its parents. It now also walks subdirectories and trusts each nested config root it finds, so a monorepo's nested configs can be trusted with one explicit command. The walk respects.gitignore, skips hidden directories, and skipsnode_modules,vendor,target,dist, andbuildso vendored configs are left untrusted. Each nested config gets its own trust record, so a config added later in a new subdirectory still prompts (#10889 by @jdx).Fixed
npm view --jsonresponses in a single-item array, which broke version listing and latest-version detection for npm-backed tools. mise now normalizes both the legacy object shape and the new wrapped shape, and tolerates missingtimemetadata (#10888 by @jdx).Changed
codexshorthand now prefersnpm:@​openai/codexover the aqua GitHub asset. The aqua asset for recent releases shipped only the maincodexbinary and omittedcodex-code-mode-host, which broke tool calling; the npm package installs the full vendor bundle. Aqua remains available as an explicit or fallback backend (#10893 by @jdx).Full Changelog: jdx/mise@v2026.7.4...v2026.7.5
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.4: : Bootstrap goes stableCompare Source
This release graduates
mise bootstrapandmise dotfilesout of experimental mode, teachesmise installto reconcile Rust components and targets, and restores Linux arm64 glibc compatibility for release builds.Added
mise bootstrapand all of its subcommands (packages, repos, macOS/Linux user services, shell activation, login shell) plusmise dotfilesno longer require experimental mode, so they work withMISE_EXPERIMENTAL=0. The relatedmise doctordiagnostics (system packages, macOS defaults, login-shell drift) and the missing[bootstrap.packages]hint onmise installare always on as well (#10869 by @jdx).mise.runinstall script. SettingMISE_INSTALL_SKIP_IF_EXISTSavoids re-downloading mise when the requested version is already present at the install path, which is handy for CI/Docker builds that re-run the installer on every build (#10882 by @JamBalaya56562):curl https://mise.run | MISE_INSTALL_SKIP_IF_EXISTS=1 shPATH), and default behavior is unchanged unless you opt in.Fixed
componentsandtargetsare actually installed before skipping an install, somise installreconciles missing components/targets on an already-installed toolchain instead of treating a bare symlink as complete. Array-form config is now parsed (with trimming and empty-entry filtering) and host-suffixed component names are matched (#10876 by @jdx).task_source_files()is once again available when a task definesusageargs and its run script is re-rendered with parsed CLI values (#10870 by @jdx).mise upgrade --minimum-release-ageno longer prints a misleading "newer release ignored" warning when the installed version already satisfies the hidden latest release (#10877 by @jdx).aarch64-unknown-linux-gnucross image back to a fixed tag and added a shared glibc-floor check to release packaging, restoring predictable glibc compatibility for Linux arm64 tarballs (#10875 by @jdx).Performance
Changed
vfox:mise-plugins/vfox-scalafork; theasdf:mise-plugins/mise-scalafallback is unchanged (#10864 by @jdx).Documentation
Aqua Registry Updates
New packages:
sderosiaux/launchdeck,syntax-sh/lexicon-releases.Full Changelog: jdx/mise@v2026.7.3...v2026.7.4
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.3: : System dependency checks and cask lifecycle hooksCompare Source
This release brings smarter builds for source-compiling tools, better Homebrew cask support, and a fix for lockfile entries losing their platform data during upgrades.
Added
vfox: plugin-declared system dependencies. Source-compiling plugins (php, mysql, erlang, ...) often need build tools and libraries that previously showed up only as a failed
./configuretwenty minutes into a build. vfox plugins can now declare these prerequisites inmetadata.lua, and mise checks them before installing (#10848 by @jdx):Detection is the source of truth: a satisfied check passes regardless of how the capability was installed (Homebrew, apt, nix, from source), and the per-manager
packagesmap is only used to offer installing the missing subset. A newsystem_depssetting controls behavior (promptdefault,auto,warn,ignore); the check never fails an install. Missing deps also show up inmise doctorandmise bootstrap status. Declarations are inert on older mise versions and on upstream vfox.brew: cask lifecycle hooks. Homebrew cask installs now run supported
preflightandpostflighthooks via a mise-owned, sha256-verified Ruby shim (nobrewdelegation), which fixes wrapper-style casks like GIMP. Unsupported hook DSL fails with an explicit error (#10837 by @jdx).cli: terminal width override. In some CI environments width detection returns a bogus value and mise's table/list output (
mise ls,mise registry,mise settings) renders oddly with no way to fix it. You can now override the detected width (#10862 by @JamBalaya56562):MISE_TERM_WIDTHtakes precedence, withCOLUMNSas a fallback. An explicit override is honored exactly (no 80-column floor); behavior is unchanged when neither is set.Fixed
mise upgrade --bumpcan rewrite more lockfile entries than the tools it actually installs. Those rewritten entries were previously reduced to bare version/backend records, losing their cross-platform checksums and URLs. mise now re-locks stale entries that are missing platform metadata, so tools likeruff,biome, andtyposkeep their full lock data (#10752 by @zeitlinger).karabiner-elements) now install correctly, staged through the caskroom as symlinks (#10841 by @jdx).cargo publishverification failure (#10863 by @jdx).Changed
Documentation
Full Changelog: jdx/mise@v2026.7.2...v2026.7.3
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.2: : Template and Extraction FixesCompare Source
This is a small bug-fix release focused on template compatibility, archive extraction, and a couple of tool-specific installs.
Fixed
get_envtemplate helper for Tera v2 templates, backed by mise's original process environment, so older templates keep working. Shared configs can also opt back into the temporary Tera v1 renderer with[env] MISE_TERA_V1 = true(which older mise versions safely ignore) (#10830 by @jdx):[settings](including nested keys likeaqua.registry_url), process env vars, or theMISE_TERA_V1[env]shim, now produce proper deprecation warnings. Warnings are held until the logger is ready so they honor-q,--silent, and--log-level, and no longer fire spuriously for unrelatedMISE_*values (#10832 by @jdx).GNU.sparse.*tar archives (such as thesmolvmrelease tarballs) now extract correctly by falling back to the systemtarwhen the built-in extractor can't safely unpack sparse content (#10821 by @JamBalaya56562).podmannow installs with the expectedpodmanbinary name instead ofpodman-remote-static, removing the need for manual symlink workarounds (#10822 by @konono).@biomejs/biome@2.5.2) are now accepted, so mise no longer rejects otherwise-valid download URLs and falls back to the GitHub API (#10750 by @zeitlinger).Full Changelog: jdx/mise@v2026.7.1...v2026.7.2
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.1: : Tera v2 Templates and Safer PruningCompare Source
Added
tera_v1/MISE_TERA_V1escape hatch to keep rendering templates with the old Tera v1 engine after the upgrade to Tera v2 (scheduled for removal in 2027.4.0) #10817cargo.binstall_nativefast path that installs prebuilt native binaries from cratepackage.metadata.binstallwhencargo-binstallis unavailable, falling back tocargo installon misses #10789start_calendar_intervalsupport for macOS launchd agents, allowing calendar-based schedules (hour/minute/day/weekday/month) in addition tostart_interval#10797trust_policy_excludesinstall option for aube installs to exempt reviewed packages from trust-policy downgrade checks without disabling the policy globally #10783Fixed
tera_v1escape hatch for templates that still need the old behavior #10756 #10814 #10815 #10817*_KEYscrubbed unrelated values from task output #10729sub-*:latestrequests offline during shell activation so already-installed versions are no longer reported as missing #10802mise pruneandmise upgraderetain the versions they need #10790--run-windowsis now honored bytask addand emitted asrun_windowsin the generated TOML #10769mise searchnow falls back to the built-in aqua registry when the mise registry has no match (e.g.mise search 7zipsurfacesaqua:ip7z/7zip) #10801featuresand warn on invalid feature array entries #10810 #10813$HOMEand return relative paths #10788str upcasedeprecation warning #10778$LASTEXITCODEafter_mise_hook#10718Documentation
env_shell_expandsetting #10787Registry
pi#10727twg#10780,apm#10766,nono#10675,miniserve#10760💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.0: : Shell expansion by default, monorepo lockfiles, and task usage mountsCompare Source
Added
env_shell_expand = false(#10702 by @jdx).Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.