You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This release adds opt-in automatic self-updates, lets remote bootstrap leave a working mise behind on each target, and introduces versioned lockfiles that bind each request to the version it resolved. It also replaces the CLI parser with usage-rs, hardens remote Git task handling, and fixes a wide range of tool-installation, task, and config edge cases.
Highlights
mise can now keep itself up to date and provision itself onto remote hosts, closing two long-standing gaps in unattended and remote workflows.
Lockfiles gained an explicit format version so overlapping loose and exact requests can pin distinct versions, with mise lock --upgrade for safe migration and no surprise drift for existing files.
The CLI parser moved from clap to usage-rs, and remote Git task paths are now contained against traversal, symlink, and Windows path escapes.
Added
self-update: New opt-in automatic updates. Enable auto_update (with auto_update_check_duration, default 7d) and mise will update itself before eligible interactive commands, then re-exec your original invocation with the new binary. Updates are throttled and lock-serialized, skipped in CI, offline, non-interactive, and shell-integration contexts, and failures never block the requested command. Package-managed builds are steered toward the official optimized binaries. (#12288 by @jdx)
bootstrap: Remote bootstrap can now install a persistent mise on each target instead of tearing it down with the staging directory. Set install_mise in [bootstrap.remote] (or per host) or pass --install-mise[=/path]; the same checksum-verified executable that ran the bootstrap is installed, so the host converges on the orchestrating mise version. (#12284 by @jdx)
[bootstrap.remote]
install_mise = true# installs to ~/.local/bin/mise
lock: Lockfiles now carry lockfile_version = 1 and bind each original request to the entry it resolved, so overlapping requests like "1" and "1.0.0" can lock different versions. Existing unversioned lockfiles stay on format 0 during ordinary mise lock/install/upgrade to avoid drift; run mise lock --upgrade to migrate (transactional, rolls back on failure). (#12299 by @jdx)
node: mise can now act as a Corepack replacement, honoring the +sha... checksum suffixes in packageManager / devEngines.packageManager and verifying the exact npm, pnpm, Yarn, or bun artifact before installing. Adds SHA-224/SHA-384 hashing and a Windows script launcher for Yarn's JS CLI. (#12214 by @jdx)
prune:mise prune --dry-run now explains why each version is prunable, naming either the kept versions and the configs requiring them or the fact that nothing tracked references the tool. (#12304 by @Marukome0743)
java: Oracle GraalVM "innovation" feature releases are now recognized. (#12189 by @roele)
Fixed
oci: pipx virtual environments are now relocated when packed into OCI images, rewriting host-absolute shebangs and rebasing venv interpreter links (including aliases like python/latest) onto the image's Python, so tools no longer dangle at runtime. (#12211 by @jdx)
ruby: glibc precompiled binaries are now skipped on musl Linux, falling back to ruby-build. (#12289 by @risu729)
bash: activation no longer applies the environment under --no-hook-env. (#12218 by @JamBalaya56562)
env: any spelling of PATH now folds onto a single key on Windows. (#12312 by @JamBalaya56562)
npm: deprecated versions are now filtered during resolution. (#12226 by @risu729)
aqua: cargo warnings use crate names, go install warning paths render correctly, and mise suggests compatible package backends. (#12252, #12251, #12225 by @risu729)
brew: cask artifacts behind flight-created symlinks now resolve correctly. (#12243 by @jdx)
bootstrap: progress display is suspended while sudo prompts, brew casks are no longer reinstalled on content drift, overlapping dotfile footprints are rejected, and brew cask pkgutil patterns match correctly. (#12244, #12222, #12290, #12297 by @jdx)
config: dotted conf.d fragments load unconditionally again, and mise no longer prompts for trust when stdin is not a tty. (#12242 by @jdx, #12268 by @Marukome0743)
lock: the "run mise lock" hint now points at --global when only global config has tools. (#12260 by @jdx)
ls-remote: JSON prerelease output now distinguishes unknown from stable. (#12265 by @risu729)
doctor: the new-version warning is now reported in JSON output too. (#12267 by @JamBalaya56562)
install-script: the pinned binary now defaults under the data dir rather than the cache dir. (#12261 by @Guria)
cli: The command-line parser, help output, and shell completions moved from clap to usage-rs. Completions and help are now generated from compiled usage metadata rather than an external usage CLI, and mise completion --install writes self-contained scripts. This raises the minimum supported Rust version to 1.95. (#12221 by @jdx)
generate:mise generate bootstrap is renamed to mise generate install-script to avoid confusion with mise bootstrap. The old spelling still works as a hidden, deprecated alias (removal scheduled for 2027.9.0). (#12247 by @jdx)
prompts: confirmation prompts now distinguish "could not ask" from an explicit "no". (#12273 by @Marukome0743)
Security
task: Remote Git task paths are now contained to the checkout root, rejecting .. traversal, Windows absolute/backslash and drive-qualified forms, and intermediate symlink escapes, and refusing non-regular-file targets. This closes escapes that could chmod +x and execute attacker-chosen files outside the checkout. (#12254 by @risu729)
Deprecated
config (Alpine): The distro-wide all_compile = true default on Alpine now warns and is scheduled for removal in 2027.8.0; precompiled musl binaries become the default path. Set all_compile = true explicitly to keep building from source. (#12287 by @risu729)
config (idiomatic files): Minimum-version floors in go.mod (go X.Y) and CMakeLists.txt (cmake_minimum_required) now warn when they resolve a version and stop being read in 2026.11.0. toolchain goX.Y.Z is unaffected. Only affects users who opted these tools into idiomatic_version_file_enable_tools. (#12259 by @jdx)
Aqua registry search avoids allocating registry ids (#12231 by @risu729), and install state is loaded per tool instead of scanning every install (#12236 by @jdx).
Breaking Changes
The CLI parser migration (#12221) raises the minimum supported Rust version to 1.95 for building from source, and mise completion's --include-bash-completion-lib / --usage flags are now no-ops. Command behavior, flags, and aliases are otherwise preserved.
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.10: : Remote bootstrap environments and asset-matching fixes
This release lets remote bootstrap pick which config environments run on each target, fixes several tool-installation edge cases (archive naming, Windows ZIP preference, renamed aqua packages, Homebrew cask metadata), and hardens pacman package detection and Windows self-update cleanup.
Added
bootstrap: Remote bootstrap can now select which mise.<env>.toml layers load on each SSH target without inheriting the orchestrator's full environment. Set a default with [bootstrap.remote].mise_env, override per host in your inventory, or pass --remote-env (repeatable or comma-separated) on the command line. (#12182 by @jdx)
[bootstrap.remote]
mise_env = ["production"]
bootstrap: Independent config roots can now contribute symlink-each trees that share the same target directory, as long as their leaf paths are disjoint. Overlapping leaves and file/directory collisions still fail before any changes, reporting both declaring config origins. (#12190 by @jdx)
doctor:mise doctor now detects leftover Windows self-update helper files (__relocated__ / __selfdelete__ copies in TEMP) and reports their count and total size, noting that a subsequent mise self-update removes them. (#12205 by @JamBalaya56562)
Fixed
system (pacman): Arch packages satisfied by an installed provider through Provides are no longer reported as missing. mise now uses pacman -T to distinguish genuinely missing packages, recovers the provider's version for status, and skips provider-satisfied aliases during targeted upgrades so pacman does not try to replace the provider. (#12183 by @jdx)
registry (aqua): Twelve aqua: backends (including d2, typstyle, gitui, gradle, ktlint, kubeseal, and velero) now point at their renamed, canonical package ids, so they install even in networks where api.github.com is unreachable. A regression test prevents this drift from returning. (#12186 by @kkom)
registry (azure-cli): On Windows x64, azure-cli now installs from the official bundled-Python ZIP release instead of PyPI, fixing az failing with 'python' is not recognized or No module named 'azure'. Linux and macOS continue to use the existing pipx install. (#12161 by @JamBalaya56562)
brew: Homebrew cask metadata now deserializes when the API sends "auto_updates": null, treating it as the default false. This was breaking metadata fetches for the majority of current casks. (#12192 by @jdx)
backend: Restored the strict preference for Windows ZIP archives over all tarball formats (tar.zst > tar.xz > other), which a prior change had accidentally reduced to a tiebreak. (#12200 by @risu729)
backend: Shorthand archive extensions like .tbz and .tbz2 are now normalized correctly when matching preferred asset names and stem-only checksums, including mixed-case suffixes. This prevents assets from losing the preferred-name bonus and selecting the wrong archive. (#12199 by @risu729)
sync: External-provider link reconciliation no longer removes links owned by another source or races with concurrent installs. Managed installs, runtime aliases, and links from unselected providers are preserved, and stale dangling links are correctly replaced with the winning provider's install. (#11682 by @risu729)
self-update: On Windows, stale helper copies in TEMP are now swept before the TEMP-length check, so cleanup still runs on the long-TEMP machines that need it most. (#12205 by @JamBalaya56562)
Performance
cache: Foreground blob lookups during rustc cache restores are now batched into a single blob-pack request when the remote supports it, instead of one request per digest, with response metadata validated and a safe fallback to individual blob GETs. (#12191, #12193 by @jdx)
Documentation
Fixed mobile table rendering and banner overlays on the docs site. (#12184 by @jdx)
Clarified the registry-addition popularity bar and used neutral config-file wording in trust help. (#12208, #12210 by @jdx, @risu729)
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.9: : Composable Bootstrap, Environment-Aware conf.d, and Faster Startup
This release expands declarative bootstrap into a composable, multi-root system; adds environment-specific conf.d fragments and glob-based ignored config paths; smooths out shell activation so runtime overrides stick; and delivers major startup performance gains for vfox-backed setups. It also includes several security hardening fixes worth noting.
Highlights
Bootstrap can now compose declarative resources (dotfiles, files, directories, services, and Compose projects) from multiple independent config roots, with provenance tracking and clear conflict diagnostics.
Startup is dramatically faster on machines with vfox plugins: idiomatic file detection is now gated on opt-in, and vfox plugin metadata is cached on disk, cutting common invocations from hundreds of milliseconds to single digits.
Security hardening: forge tokens no longer leak to third-party hosts, and safe mode now blocks tool-level install hooks.
Added
bootstrap: Compose declarative resources from multiple independent config roots via [bootstrap].config_roots. Selected roots contribute [dotfiles], [bootstrap.files], [bootstrap.directories], [bootstrap.services], and [bootstrap.compose] without gaining precedence from list or glob order; identical declarations are deduplicated and conflicting declarations fail with both origins reported. (#12105, #12132 by @jdx)
[bootstrap]
config_roots = ["bundles/*"]
bootstrap: Declaration provenance is now retained and exposed for dotfiles and managed files/directories. mise bootstrap plan, bootstrap status, and mise dotfiles status include origin details (declaring config, config root, environment, resolved source) in JSON, and human-readable tables gain a Config column. (#12100 by @jdx)
bootstrap: Homebrew-compatible support for self-updating and adopted casks in [bootstrap.packages]. Casks declaring auto_updates: true are left to update themselves, and existing app bundles can be adopted globally with [bootstrap.brew].adopt = true or per cask with adopt = true. (#12074 by @ascarter)
bootstrap: Remote bootstrap gains symlink materialization controls. Use --copy-link <PATH> (repeatable) to dereference selected source-relative symlinks or --copy-links to recursively dereference all archived symlinks; both are also configurable in [bootstrap.remote] and per-host. Default behavior is unchanged (links stay links). (#12121 by @jdx)
config: Environment-specific conf.d fragments. Files like .mise/conf.d/*.{env}.toml (and .local variants) load only when that config environment is active, applying to project, global, and system conf.d directories. (#12151 by @jdx)
config:ignored_config_paths now supports relative entries and glob patterns (including recursive **). Entries in .miserc.toml resolve against the declaring file, while MISE_IGNORED_CONFIG_PATHS resolves against the invocation directory — making it easy to exclude vendored repos portably. (#12169 by @jdx)
config:mise run, naked mise <task>, mise install, mise exec, and mise watch now implicitly trust and persist the active config in normal mode, avoiding a redundant prompt. Automatic hook-env/inspection commands still require explicit trust, and paranoid and safe modes are unchanged. (#12107 by @jdx)
system: Plugins can declare an ordered list of candidate package names per package manager in systemDependencies, so the same capability can be expressed across distro renames (for example apt = { "libaio1t64", "libaio1" }). mise resolves the first available candidate. (#12149 by @jdx)
vfox: Traditional vfox plugins can now read configured [tools] options from ctx.options in PreInstall and PostInstall hooks, with scalars as strings and arrays/tables as structured Lua values. Existing hook environment variables continue to work. (#12174 by @jdx)
Fixed
hook-env: Runtime environment overrides now persist between refreshes. Changes made with export, shell aliases, sourced scripts, or direct PATH edits are no longer reverted on every prompt, reversing the continuous enforcement introduced in 2026.8.0. (#12094 by @jdx)
aqua: Prefer glibc release assets on unqualified glibc Linux targets, falling back to a musl asset only when no glibc sibling exists. Explicit libc selections stay strict. (#12093 by @jdx)
python: Automatic venv creation now resolves the configured uv even when invoked through a tool override (for example mise x tiny@3), so python.uv_venv_auto no longer reports uv as missing right after mise installs it. (#12177 by @jdx)
which:mise which <bin> --tool=<tool>@<version> now reports that the requested version is not installed (with an install hint) instead of the misleading "not currently active" message. (#12106 by @TrevorBurnham)
shell: The pwsh command-not-found hook now branches on the command exit code and skips mise's own commands, and the environment is refreshed on auto-install when --no-hook-env omits the hook. (#12089, #12131, #12117 by @JamBalaya56562)
bootstrap: Create missing parent directories when bootstrapping. (#12096 by @jdx)
github: Match arm assets on arm64 hosts. (#12098 by @jdx)
use: Scope global install hooks correctly. (#12101 by @jdx)
task: Support Azure DevOps cloud SSH URLs as remote git task sources, and normalize Windows task environment paths. (#12102 by @cheesemans, #12173 by @jdx)
system: Resolve dependency executables on Windows. (#12178 by @jdx)
http: Order remote versions consistently. (#12170 by @jdx)
vfox: Follow symlinks when fingerprinting plugin sources, honor systemDependencies in embedded plugins, and apply netrc credentials to HTTP requests. (#12155, #12152, #12168 by @jdx)
Asset selection now handles non-gz tar variants. (#12156 by @sgammon)
Changed
backend: Removed the remaining legacy RTX_* environment variables (including RTX_TOOL_OPTS__* and RTX_ADD_PATH) passed to asdf and vfox plugin hooks. Plugin authors should use the equivalent MISE_* variables; standard ASDF_* variables remain available to asdf plugins. (#12172 by @jdx)
Performance
config: Idiomatic version file detection is now gated on idiomatic_version_file_enable_tools, so mise no longer boots a Lua VM for every vfox plugin on ordinary invocations. Common commands dropped from hundreds of milliseconds to single-digit milliseconds, and nested mise run/mise x chains improved dramatically. (#12143 by @jdx)
vfox: Filesystem plugin metadata (idiomatic filenames, dependencies, system dependencies) is now cached on disk and invalidated by plugin file changes, avoiding repeated Lua execution. (#12145 by @jdx)
activate: pwsh no longer runs hook-env twice per directory change. (#12147 by @jdx)
cache: Batch remote blob prefetch. (#12103 by @jdx)
Security
backend: GitLab and Forgejo authentication headers are now bound to the configured API origin, preventing tokens from leaking to third-party release asset hosts or cross-origin pagination URLs. (#12167 by @jdx)
Safe mode (MISE_SAFE=1) now blocks tool-level postinstall hooks and install_env from running during installation. (#12140 by @jdx)
Registry
Added workerd via github:cloudflare/workerd. (#12180 by @mikea)
Pointed vlang at the maintained vfox:jdx/vfox-v backend so it shares versions with v, replacing an unmaintained third-party version source. (#12153 by @jdx)
Breaking Changes
conf.d filenames: A conf.d fragment with an extra dot before .toml (for example node.tools.toml) is now interpreted as environment-specific. Use hyphens for unconditional multi-word fragment names (for example node-tools.toml). (#12151)
vlang versions: Configs pinning vlang = "2026.x"-style versions must move to a real upstream version such as 0.5.2 or a weekly.* tag, since the previous version strings did not correspond to upstream tags. (#12153)
*RTX_ variables:** Plugins relying on legacy RTX_* variables must switch to MISE_*. (#12172)
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
[!NOTE]
The automated v2026.8.7 release failed before binaries were published. v2026.8.8 includes all changes from v2026.8.7 and is the supported downloadable release for those changes.
This release restores the ARMv7 (hard-float) build so those binaries can be published again.
Fixed
release: the armv7-unknown-linux-gnueabihf build now installs a newer libclang (LLVM 6), which the aws-lc-sys bindgen step requires. Previously the release job panicked on every ARMv7 build because the cross Ubuntu 16.04 image shipped libclang 3.8. (#12088 by @jdx)
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
[!IMPORTANT]
The automated release for v2026.8.7 failed before binaries were published. This release is retained for changelog and version history only and intentionally has no assets. Use v2026.8.8 or newer for downloadable binaries containing these changes.
This release expands Windows support across generated launchers, dotfiles, shells, and file tasks; adds project conf.d fragments, task-specific tool installation, and APK bootstrap support; and includes a broad set of reliability and security fixes.
Added
install: include tools declared by tasks when installing project dependencies. (#11988 by @Marukome0743)
config: support project-level conf.d configuration fragments. (#12061 by @Marukome0743)
generate: add --windows bootstrap launchers and write Windows launchers beside generated tool stubs. (#11919, #11888 by @JamBalaya56562)
dotfiles: create real symlinks on Windows when Developer Mode or sufficient privileges allow it. (#11978 by @JamBalaya56562)
bootstrap: support launchd throttle intervals and queue-directory keys. (#12015 by @CallumKerson)
brew-cask: add MISE_BREW_CASK_OPT_APPDIR for choosing the application installation directory. (#12068 by @st1971)
generate: support selecting the checksum algorithm for generated tool stubs. (#12047 by @Marukome0743)
task: expose the selected prefix color to task processes. (#12056 by @Marukome0743)
cache: report action-cache phase timings. (#12077 by @jdx)
oci: support APK packages during bootstrap. (#12083 by @jdx)
Fixed
http: detect archive formats from the final URL after redirects. (#12011 by @Marukome0743)
backend: preserve metadata for installed backend versions. (#12010 by @jdx)
env: redact caller-provided values used by required environment directives. (#12017 by @stevenpollack)
config: write configuration files atomically and match runtime options against the configured version. (#12040 by @TheTrueFerret, #11714 by @risu729)
completion: avoid loading project configuration while generating completions. (#12018 by @Marukome0743)
tool: exclude OS-inactive versions from inspection results. (#12021 by @risu729)
task: support byte-order marks before file-task shebangs, attached run-option values, trailing ** source/output globs, and correct task-relative cache paths. Unknown file-task header keys now warn instead of failing. (#12013, #12070, #12022, #11995, #12007)
Windows: improve PowerShell quoting and shell detection, default environment output to PowerShell, handle POSIX .sh task siblings, and avoid unsupported UNC working directories in cmd.exe. (#12016, #12050, #12055, #11992, #12066 by @JamBalaya56562)
shims: match mise's own executable name case-insensitively on Windows and use the snap payload path for Unix shims. (#11986 by @JamBalaya56562, #12035 by @jdx)
sops/age: support multiple age keys and resolve key paths relative to their configuration files. (#12034, #12052 by @Marukome0743)
vfox: install the latest compatible ChromeDriver on Windows. (#12039 by @jdx)
brew: avoid copying cask applications more than once. (#12072 by @jdx)
use: preserve concurrent updates to the global configuration file. (#12069 by @jdx)
activate: prevent the shims directory from growing repeatedly in PATH. (#12063 by @Marukome0743)
self-update: handle Windows MAX_PATH limits safely and stop leaving large temporary copies behind after failed updates. (#12062, #12080 by @JamBalaya56562)
erlang: verify checksums for precompiled installations. (#12053 by @leosmigel)
file: safely inspect directory links and validate whether configured extensions are launchable by the current OS. (#11715 by @risu729, #12023 by @JamBalaya56562)
armv7: use the hard-float suffix for GNU EABI targets. (#12082 by @neheb)
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
This release adds resumable HTTP downloads, expands Homebrew cask support, and lands a large batch of fixes across tasks, config, install, and platform-specific behavior — with a particular focus on monorepos and Windows.
Highlights
Interrupted artifact downloads now resume instead of restarting from zero, and more transient network failures (including HTTP/2 REFUSED_STREAM) are retried automatically.
The Homebrew cask backend gained structured symlinks, generic artifacts, and copy/installer flight steps, closing several gaps in cask installation.
A wide round of monorepo task, config precedence, and Windows path handling fixes.
Added
http: interrupted downloads now resume via HTTP Range requests when a strong ETag or Last-Modified validator is available, keeping validated partial files across retries and mise invocations instead of re-downloading from byte zero. mise falls back to a clean restart when validators do not match, and abandoned partials expire after 30 days. (#11866 by @Marukome0743)
brew: the Homebrew cask backend now supports structured symlink steps (with path bases, templates, guards, source globs, and sudo control), generic cask artifacts, and copy/installer flight steps, with transactional rollback if an install fails. (#11962, #11963, #11964 by @jdx)
task:mise run --all opens the interactive task picker with tasks from the entire monorepo, matching the load path already used by mise tasks ls --all. The default picker stays scoped to the current directory hierarchy. (#11920 by @jdx)
mise run --all
task: add task.cache.audit_report (MISE_TASK_CACHE_AUDIT_REPORT) to write the complete cache-audit report to a JSON Lines file. The console still caps at 20 paths per task, but the file now captures every undeclared read and write so large audits (e.g. Jest over node_modules) are actually usable. (#11997 by @stevenpollack)
MISE_TASK_CACHE_AUDIT_REPORT=audit.jsonl mise run --force build
dotfiles: whole-file [dotfiles] entries can now declare their body inline with content = "..." instead of requiring a separate source file, useful for small configs and user-writable paths outside $HOME. content cannot be combined with source, mode, or exclude. (#11983 by @jdx)
deps: deps provider config fields (paths, commands, env, descriptions, timeouts) now render Tera templates using the defining config file's context, with shell-style environment expansion and rendered env values folded into freshness identity. Template errors surface as clear configuration errors before commands run. (#11886 by @Marukome0743)
config: add a config-root-scoped [tool_config] locked = true policy that requires tools declared by configs sharing that root to resolve and install from their lockfiles, without forcing global or parent-root tools into strict mode. [settings] locked, --locked, and MISE_LOCKED remain invocation-wide. (#11940 by @jdx)
Fixed
task: in monorepo mode, running a task by its bare or :-prefixed name now works from any directory below a config root, resolving to the nearest enclosing project instead of failing. (#11941 by @pikeas)
task: normalize task cwd for source freshness (#11987 by @jdx), bound buffered command output (#11922), avoid zsh process-substitution hangs (#11904), and normalize variadic usage env values (#11881) by @Marukome0743; mask archive modes in remote cache nodes (#11877 by @stevenpollack).
http: retry send failures that never produced a response, including HTTP/2 REFUSED_STREAM, which CDNs emit as backpressure and which previously failed on the first attempt even with retries enabled. (#11961 by @mariadeluna-tomtom)
aqua: when a downloaded checksum file lists per-file hashes but none match the target filename, mise now errors instead of silently returning a wrong checksum. (#11973 by @jakedgy)
pipx: discover wheel-only package versions from PEP 503 Simple API indexes, so packages published only as wheels now appear in mise ls-remote and latest resolution. (#11959 by @jdx)
rust: the rolling nightly channel now resolves to a concrete nightly-YYYY-MM-DD toolchain via the official channel manifest, making nightly lock, outdated, upgrade, and offline reuse reproducible while keeping mise.toml on nightly. (#11980 by @Marukome0743)
npm: render lifecycle logs through the progress display. (#11939 by @jdx)
oci: strip the tag from name:tag@digest references so pulling a base image by combined tag-and-digest no longer produces a malformed token scope, while preserving registry ports. (#11979 by @fire-ant)
install: write tool manifests atomically. (#11957 by @jdx)
deps: invalidate deps state when a provider's command, environment, working directory, or shell changes, so an edited run command is no longer skipped as fresh (#11849); honor source and output overrides (#11896) by @Marukome0743.
config: allow typing j/k to filter in the mise edit tool picker (#11969 by @jakedgy); create the config directory before writing into it (#11934) and stop a conf.d drop-in from becoming the write target (#11917) by @JamBalaya56562.
bootstrap: avoid sudo for user-writable files (#11984) and allow Windows bootstrap without system files (#12003) by @jdx.
toolset: accept a Windows tool path spelled with backslashes (#11937) and reject cmd.exe metacharacters in a Windows tool path ([#11947](https://redirect.gith
✂ Note
PR body was truncated to here.
Configuration
📅 Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.3.17→2026.8.12Release Notes
jdx/mise (jdx/mise)
v2026.8.12Compare Source
v2026.8.11: : Automatic updates, remote mise installs, and versioned lockfilesCompare Source
This release adds opt-in automatic self-updates, lets remote bootstrap leave a working mise behind on each target, and introduces versioned lockfiles that bind each request to the version it resolved. It also replaces the CLI parser with usage-rs, hardens remote Git task handling, and fixes a wide range of tool-installation, task, and config edge cases.
Highlights
mise lock --upgradefor safe migration and no surprise drift for existing files.Added
self-update: New opt-in automatic updates. Enable
auto_update(withauto_update_check_duration, default7d) and mise will update itself before eligible interactive commands, then re-exec your original invocation with the new binary. Updates are throttled and lock-serialized, skipped in CI, offline, non-interactive, and shell-integration contexts, and failures never block the requested command. Package-managed builds are steered toward the official optimized binaries. (#12288 by @jdx)bootstrap: Remote bootstrap can now install a persistent mise on each target instead of tearing it down with the staging directory. Set
install_misein[bootstrap.remote](or per host) or pass--install-mise[=/path]; the same checksum-verified executable that ran the bootstrap is installed, so the host converges on the orchestrating mise version. (#12284 by @jdx)lock: Lockfiles now carry
lockfile_version = 1and bind each original request to the entry it resolved, so overlapping requests like"1"and"1.0.0"can lock different versions. Existing unversioned lockfiles stay on format 0 during ordinarymise lock/install/upgradeto avoid drift; runmise lock --upgradeto migrate (transactional, rolls back on failure). (#12299 by @jdx)node: mise can now act as a Corepack replacement, honoring the
+sha...checksum suffixes inpackageManager/devEngines.packageManagerand verifying the exact npm, pnpm, Yarn, or bun artifact before installing. Adds SHA-224/SHA-384 hashing and a Windows script launcher for Yarn's JS CLI. (#12214 by @jdx)prune:
mise prune --dry-runnow explains why each version is prunable, naming either the kept versions and the configs requiring them or the fact that nothing tracked references the tool. (#12304 by @Marukome0743)java: Oracle GraalVM "innovation" feature releases are now recognized. (#12189 by @roele)
Fixed
python/latest) onto the image's Python, so tools no longer dangle at runtime. (#12211 by @jdx)--no-hook-env. (#12218 by @JamBalaya56562)PATHnow folds onto a single key on Windows. (#12312 by @JamBalaya56562)go installwarning paths render correctly, and mise suggests compatible package backends. (#12252, #12251, #12225 by @risu729)conf.dfragments load unconditionally again, and mise no longer prompts for trust when stdin is not a tty. (#12242 by @jdx, #12268 by @Marukome0743)mise lock" hint now points at--globalwhen only global config has tools. (#12260 by @jdx)mise set --filenow refuses a file it cannot read back. (#12207 by @JamBalaya56562)-cshell (#12277 by @JamBalaya56562).Changed
usageCLI, andmise completion --installwrites self-contained scripts. This raises the minimum supported Rust version to 1.95. (#12221 by @jdx)mise generate bootstrapis renamed tomise generate install-scriptto avoid confusion withmise bootstrap. The old spelling still works as a hidden, deprecated alias (removal scheduled for 2027.9.0). (#12247 by @jdx)Security
..traversal, Windows absolute/backslash and drive-qualified forms, and intermediate symlink escapes, and refusing non-regular-file targets. This closes escapes that couldchmod +xand execute attacker-chosen files outside the checkout. (#12254 by @risu729)Deprecated
all_compile = truedefault on Alpine now warns and is scheduled for removal in 2027.8.0; precompiled musl binaries become the default path. Setall_compile = trueexplicitly to keep building from source. (#12287 by @risu729)go.mod(go X.Y) andCMakeLists.txt(cmake_minimum_required) now warn when they resolve a version and stop being read in 2026.11.0.toolchain goX.Y.Zis unaffected. Only affects users who opted these tools intoidiomatic_version_file_enable_tools. (#12259 by @jdx)Documentation
_.sourcebeing bash-only (#12286 by @risu729) and its cacheable source example (#12278 by @Marukome0743), cross-file hook execution order (#12295 by @jdx), that--systemis shared storage rather than a mise-free install (#12253 by @jdx), which backends lockfile strict mode skips (#12306 by @Marukome0743), that task deps ignores run-array refs (#12285 by @risu729), and thatrawserializes execution (#12307 by @Marukome0743).Registry
Performance
Breaking Changes
mise completion's--include-bash-completion-lib/--usageflags are now no-ops. Command behavior, flags, and aliases are otherwise preserved.New Contributors
Full Changelog: jdx/mise@v2026.8.10...v2026.8.11
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.10: : Remote bootstrap environments and asset-matching fixesCompare Source
This release lets remote bootstrap pick which config environments run on each target, fixes several tool-installation edge cases (archive naming, Windows ZIP preference, renamed aqua packages, Homebrew cask metadata), and hardens pacman package detection and Windows self-update cleanup.
Added
bootstrap: Remote bootstrap can now select which
mise.<env>.tomllayers load on each SSH target without inheriting the orchestrator's full environment. Set a default with[bootstrap.remote].mise_env, override per host in your inventory, or pass--remote-env(repeatable or comma-separated) on the command line. (#12182 by @jdx)bootstrap: Independent config roots can now contribute
symlink-eachtrees that share the same target directory, as long as their leaf paths are disjoint. Overlapping leaves and file/directory collisions still fail before any changes, reporting both declaring config origins. (#12190 by @jdx)doctor:
mise doctornow detects leftover Windows self-update helper files (__relocated__/__selfdelete__copies in TEMP) and reports their count and total size, noting that a subsequentmise self-updateremoves them. (#12205 by @JamBalaya56562)Fixed
Providesare no longer reported as missing. mise now usespacman -Tto distinguish genuinely missing packages, recovers the provider's version for status, and skips provider-satisfied aliases during targeted upgrades so pacman does not try to replace the provider. (#12183 by @jdx)aqua:backends (including d2, typstyle, gitui, gradle, ktlint, kubeseal, and velero) now point at their renamed, canonical package ids, so they install even in networks whereapi.github.comis unreachable. A regression test prevents this drift from returning. (#12186 by @kkom)azure-clinow installs from the official bundled-Python ZIP release instead of PyPI, fixingazfailing with'python' is not recognizedorNo module named 'azure'. Linux and macOS continue to use the existing pipx install. (#12161 by @JamBalaya56562)"auto_updates": null, treating it as the defaultfalse. This was breaking metadata fetches for the majority of current casks. (#12192 by @jdx)tar.zst>tar.xz> other), which a prior change had accidentally reduced to a tiebreak. (#12200 by @risu729).tbzand.tbz2are now normalized correctly when matching preferred asset names and stem-only checksums, including mixed-case suffixes. This prevents assets from losing the preferred-name bonus and selecting the wrong archive. (#12199 by @risu729)Performance
Documentation
New Contributors
Full Changelog: jdx/mise@v2026.8.9...v2026.8.10
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.9: : Composable Bootstrap, Environment-Aware conf.d, and Faster StartupCompare Source
This release expands declarative bootstrap into a composable, multi-root system; adds environment-specific
conf.dfragments and glob-based ignored config paths; smooths out shell activation so runtime overrides stick; and delivers major startup performance gains for vfox-backed setups. It also includes several security hardening fixes worth noting.Highlights
Added
bootstrap: Compose declarative resources from multiple independent config roots via
[bootstrap].config_roots. Selected roots contribute[dotfiles],[bootstrap.files],[bootstrap.directories],[bootstrap.services], and[bootstrap.compose]without gaining precedence from list or glob order; identical declarations are deduplicated and conflicting declarations fail with both origins reported. (#12105, #12132 by @jdx)bootstrap: Declaration provenance is now retained and exposed for dotfiles and managed files/directories.
mise bootstrap plan, bootstrap status, andmise dotfiles statusinclude origin details (declaring config, config root, environment, resolved source) in JSON, and human-readable tables gain a Config column. (#12100 by @jdx)bootstrap: Homebrew-compatible support for self-updating and adopted casks in
[bootstrap.packages]. Casks declaringauto_updates: trueare left to update themselves, and existing app bundles can be adopted globally with[bootstrap.brew].adopt = trueor per cask withadopt = true. (#12074 by @ascarter)bootstrap: Remote bootstrap gains symlink materialization controls. Use
--copy-link <PATH>(repeatable) to dereference selected source-relative symlinks or--copy-linksto recursively dereference all archived symlinks; both are also configurable in[bootstrap.remote]and per-host. Default behavior is unchanged (links stay links). (#12121 by @jdx)config: Environment-specific
conf.dfragments. Files like.mise/conf.d/*.{env}.toml(and.localvariants) load only when that config environment is active, applying to project, global, and systemconf.ddirectories. (#12151 by @jdx)config:
ignored_config_pathsnow supports relative entries and glob patterns (including recursive**). Entries in.miserc.tomlresolve against the declaring file, whileMISE_IGNORED_CONFIG_PATHSresolves against the invocation directory — making it easy to exclude vendored repos portably. (#12169 by @jdx)config:
mise run, nakedmise <task>,mise install,mise exec, andmise watchnow implicitly trust and persist the active config in normal mode, avoiding a redundant prompt. Automatichook-env/inspection commands still require explicit trust, and paranoid and safe modes are unchanged. (#12107 by @jdx)system: Plugins can declare an ordered list of candidate package names per package manager in
systemDependencies, so the same capability can be expressed across distro renames (for exampleapt = { "libaio1t64", "libaio1" }). mise resolves the first available candidate. (#12149 by @jdx)vfox: Traditional vfox plugins can now read configured
[tools]options fromctx.optionsinPreInstallandPostInstallhooks, with scalars as strings and arrays/tables as structured Lua values. Existing hook environment variables continue to work. (#12174 by @jdx)Fixed
export, shell aliases, sourced scripts, or direct PATH edits are no longer reverted on every prompt, reversing the continuous enforcement introduced in 2026.8.0. (#12094 by @jdx)libcselections stay strict. (#12093 by @jdx)uveven when invoked through a tool override (for examplemise x tiny@3), sopython.uv_venv_autono longer reportsuvas missing right after mise installs it. (#12177 by @jdx)mise which <bin> --tool=<tool>@<version>now reports that the requested version is not installed (with an install hint) instead of the misleading "not currently active" message. (#12106 by @TrevorBurnham)--no-hook-envomits the hook. (#12089, #12131, #12117 by @JamBalaya56562)+, and key the remote version cache by listing tool options. (#12118 by @Marukome0743, #12164 by @JamBalaya56562)systemDependenciesin embedded plugins, and apply netrc credentials to HTTP requests. (#12155, #12152, #12168 by @jdx)Changed
RTX_*environment variables (includingRTX_TOOL_OPTS__*andRTX_ADD_PATH) passed to asdf and vfox plugin hooks. Plugin authors should use the equivalentMISE_*variables; standardASDF_*variables remain available to asdf plugins. (#12172 by @jdx)Performance
idiomatic_version_file_enable_tools, so mise no longer boots a Lua VM for every vfox plugin on ordinary invocations. Common commands dropped from hundreds of milliseconds to single-digit milliseconds, and nestedmise run/mise xchains improved dramatically. (#12143 by @jdx)hook-envtwice per directory change. (#12147 by @jdx)Security
MISE_SAFE=1) now blocks tool-levelpostinstallhooks andinstall_envfrom running during installation. (#12140 by @jdx)Registry
workerdviagithub:cloudflare/workerd. (#12180 by @mikea)vlangat the maintainedvfox:jdx/vfox-vbackend so it shares versions withv, replacing an unmaintained third-party version source. (#12153 by @jdx)Breaking Changes
conf.dfragment with an extra dot before.toml(for examplenode.tools.toml) is now interpreted as environment-specific. Use hyphens for unconditional multi-word fragment names (for examplenode-tools.toml). (#12151)vlang = "2026.x"-style versions must move to a real upstream version such as0.5.2or aweekly.*tag, since the previous version strings did not correspond to upstream tags. (#12153)RTX_*variables must switch toMISE_*. (#12172)New Contributors
Full Changelog: jdx/mise@v2026.8.8...v2026.8.9
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.8: : Restore ARMv7 release buildsCompare Source
This release restores the ARMv7 (hard-float) build so those binaries can be published again.
Fixed
armv7-unknown-linux-gnueabihfbuild now installs a newer libclang (LLVM 6), which theaws-lc-sysbindgen step requires. Previously the release job panicked on every ARMv7 build because the cross Ubuntu 16.04 image shipped libclang 3.8. (#12088 by @jdx)Full Changelog: jdx/mise@v2026.8.7...v2026.8.8
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
AI-assisted — Tool: Codex; model: openai/gpt-5; version: unavailable.
v2026.8.7: : Windows launchers, project conf.d, and safer installsCompare Source
This release expands Windows support across generated launchers, dotfiles, shells, and file tasks; adds project
conf.dfragments, task-specific tool installation, and APK bootstrap support; and includes a broad set of reliability and security fixes.Added
conf.dconfiguration fragments. (#12061 by @Marukome0743)--windowsbootstrap launchers and write Windows launchers beside generated tool stubs. (#11919, #11888 by @JamBalaya56562)MISE_BREW_CASK_OPT_APPDIRfor choosing the application installation directory. (#12068 by @st1971)Fixed
**source/output globs, and correct task-relative cache paths. Unknown file-task header keys now warn instead of failing. (#12013, #12070, #12022, #11995, #12007).shtask siblings, and avoid unsupported UNC working directories incmd.exe. (#12016, #12050, #12055, #11992, #12066 by @JamBalaya56562)PATH. (#12063 by @Marukome0743)MAX_PATHlimits safely and stop leaving large temporary copies behind after failed updates. (#12062, #12080 by @JamBalaya56562)TEMP. (#12064 by @JamBalaya56562)Full Changelog: jdx/mise@v2026.8.6...v2026.8.7
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
AI-assisted — Tool: Codex; model: openai/gpt-5; version: unavailable.
v2026.8.6: : Resumable downloads, richer Homebrew casks, and monorepo task fixesCompare Source
This release adds resumable HTTP downloads, expands Homebrew cask support, and lands a large batch of fixes across tasks, config, install, and platform-specific behavior — with a particular focus on monorepos and Windows.
Highlights
REFUSED_STREAM) are retried automatically.Added
http: interrupted downloads now resume via HTTP Range requests when a strong ETag or Last-Modified validator is available, keeping validated partial files across retries and mise invocations instead of re-downloading from byte zero. mise falls back to a clean restart when validators do not match, and abandoned partials expire after 30 days. (#11866 by @Marukome0743)
brew: the Homebrew cask backend now supports structured
symlinksteps (with path bases, templates, guards, source globs, and sudo control), generic cask artifacts, andcopy/installer flight steps, with transactional rollback if an install fails. (#11962, #11963, #11964 by @jdx)task:
mise run --allopens the interactive task picker with tasks from the entire monorepo, matching the load path already used bymise tasks ls --all. The default picker stays scoped to the current directory hierarchy. (#11920 by @jdx)mise run --alltask: add
task.cache.audit_report(MISE_TASK_CACHE_AUDIT_REPORT) to write the complete cache-audit report to a JSON Lines file. The console still caps at 20 paths per task, but the file now captures every undeclared read and write so large audits (e.g. Jest overnode_modules) are actually usable. (#11997 by @stevenpollack)MISE_TASK_CACHE_AUDIT_REPORT=audit.jsonl mise run --force builddotfiles: whole-file
[dotfiles]entries can now declare their body inline withcontent = "..."instead of requiring a separate source file, useful for small configs and user-writable paths outside$HOME.contentcannot be combined withsource,mode, orexclude. (#11983 by @jdx)deps: deps provider config fields (paths, commands,
env, descriptions, timeouts) now render Tera templates using the defining config file's context, with shell-style environment expansion and rendered env values folded into freshness identity. Template errors surface as clear configuration errors before commands run. (#11886 by @Marukome0743)config: add a config-root-scoped
[tool_config] locked = truepolicy that requires tools declared by configs sharing that root to resolve and install from their lockfiles, without forcing global or parent-root tools into strict mode.[settings] locked,--locked, andMISE_LOCKEDremain invocation-wide. (#11940 by @jdx)Fixed
:-prefixed name now works from any directory below a config root, resolving to the nearest enclosing project instead of failing. (#11941 by @pikeas)REFUSED_STREAM, which CDNs emit as backpressure and which previously failed on the first attempt even with retries enabled. (#11961 by @mariadeluna-tomtom)mise ls-remoteandlatestresolution. (#11959 by @jdx)nightlychannel now resolves to a concretenightly-YYYY-MM-DDtoolchain via the official channel manifest, making nightly lock, outdated, upgrade, and offline reuse reproducible while keepingmise.tomlonnightly. (#11980 by @Marukome0743)name:tag@digestreferences so pulling a base image by combined tag-and-digest no longer produces a malformed token scope, while preserving registry ports. (#11979 by @fire-ant)runcommand is no longer skipped as fresh (#11849); honor source and output overrides (#11896) by @Marukome0743.resolv.confinside the sandbox. (#11958 by @jdx)j/kto filter in themise edittool picker (#11969 by @jakedgy); create the config directory before writing into it (#11934) and stop aconf.ddrop-in from becoming the write target (#11917) by @JamBalaya56562.Windows fixes
mise activateandmise completionnow both acceptpwshandpowershell, and shell detection recognizes.exesuffixes. (#11928 by @JamBalaya56562)argv[0]as a shim name. (#11982 by @JamBalaya56562)cmd.exemetacharacters in a Windows tool path ([#11947](https://redirect.githConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.