chore(deps): update dependency mise to v2026.8.11 - #2411
Merged
Conversation
Contributor
Benchmark resultsBenchmark run finished with conclusion
Benchmark summary artifact was not found; see the workflow run for details. |
zeitlinger
approved these changes
Aug 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2026.8.6→v2026.8.11Release Notes
jdx/mise (mise)
v2026.8.11: : Automatic updates, remote mise installs, and versioned lockfilesCompare Source
This release adds opt-in automatic self-updates, lets remote bootstrap leave a working mise behind on each target, and introduces versioned lockfiles that bind each request to the version it resolved. It also replaces the CLI parser with usage-rs, hardens remote Git task handling, and fixes a wide range of tool-installation, task, and config edge cases.
Highlights
mise lock --upgradefor safe migration and no surprise drift for existing files.Added
self-update: New opt-in automatic updates. Enable
auto_update(withauto_update_check_duration, default7d) and mise will update itself before eligible interactive commands, then re-exec your original invocation with the new binary. Updates are throttled and lock-serialized, skipped in CI, offline, non-interactive, and shell-integration contexts, and failures never block the requested command. Package-managed builds are steered toward the official optimized binaries. (#12288 by @jdx)bootstrap: Remote bootstrap can now install a persistent mise on each target instead of tearing it down with the staging directory. Set
install_misein[bootstrap.remote](or per host) or pass--install-mise[=/path]; the same checksum-verified executable that ran the bootstrap is installed, so the host converges on the orchestrating mise version. (#12284 by @jdx)lock: Lockfiles now carry
lockfile_version = 1and bind each original request to the entry it resolved, so overlapping requests like"1"and"1.0.0"can lock different versions. Existing unversioned lockfiles stay on format 0 during ordinarymise lock/install/upgradeto avoid drift; runmise lock --upgradeto migrate (transactional, rolls back on failure). (#12299 by @jdx)node: mise can now act as a Corepack replacement, honoring the
+sha...checksum suffixes inpackageManager/devEngines.packageManagerand verifying the exact npm, pnpm, Yarn, or bun artifact before installing. Adds SHA-224/SHA-384 hashing and a Windows script launcher for Yarn's JS CLI. (#12214 by @jdx)prune:
mise prune --dry-runnow explains why each version is prunable, naming either the kept versions and the configs requiring them or the fact that nothing tracked references the tool. (#12304 by @Marukome0743)java: Oracle GraalVM "innovation" feature releases are now recognized. (#12189 by @roele)
Fixed
python/latest) onto the image's Python, so tools no longer dangle at runtime. (#12211 by @jdx)--no-hook-env. (#12218 by @JamBalaya56562)PATHnow folds onto a single key on Windows. (#12312 by @JamBalaya56562)go installwarning paths render correctly, and mise suggests compatible package backends. (#12252, #12251, #12225 by @risu729)conf.dfragments load unconditionally again, and mise no longer prompts for trust when stdin is not a tty. (#12242 by @jdx, #12268 by @Marukome0743)mise lock" hint now points at--globalwhen only global config has tools. (#12260 by @jdx)mise set --filenow refuses a file it cannot read back. (#12207 by @JamBalaya56562)-cshell (#12277 by @JamBalaya56562).Changed
usageCLI, andmise completion --installwrites self-contained scripts. This raises the minimum supported Rust version to 1.95. (#12221 by @jdx)mise generate bootstrapis renamed tomise generate install-scriptto avoid confusion withmise bootstrap. The old spelling still works as a hidden, deprecated alias (removal scheduled for 2027.9.0). (#12247 by @jdx)Security
..traversal, Windows absolute/backslash and drive-qualified forms, and intermediate symlink escapes, and refusing non-regular-file targets. This closes escapes that couldchmod +xand execute attacker-chosen files outside the checkout. (#12254 by @risu729)Deprecated
all_compile = truedefault on Alpine now warns and is scheduled for removal in 2027.8.0; precompiled musl binaries become the default path. Setall_compile = trueexplicitly to keep building from source. (#12287 by @risu729)go.mod(go X.Y) andCMakeLists.txt(cmake_minimum_required) now warn when they resolve a version and stop being read in 2026.11.0.toolchain goX.Y.Zis unaffected. Only affects users who opted these tools intoidiomatic_version_file_enable_tools. (#12259 by @jdx)Documentation
_.sourcebeing bash-only (#12286 by @risu729) and its cacheable source example (#12278 by @Marukome0743), cross-file hook execution order (#12295 by @jdx), that--systemis shared storage rather than a mise-free install (#12253 by @jdx), which backends lockfile strict mode skips (#12306 by @Marukome0743), that task deps ignores run-array refs (#12285 by @risu729), and thatrawserializes execution (#12307 by @Marukome0743).Registry
Performance
Breaking Changes
mise completion's--include-bash-completion-lib/--usageflags are now no-ops. Command behavior, flags, and aliases are otherwise preserved.New Contributors
Full Changelog: jdx/mise@v2026.8.10...v2026.8.11
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.10: : Remote bootstrap environments and asset-matching fixesCompare Source
This release lets remote bootstrap pick which config environments run on each target, fixes several tool-installation edge cases (archive naming, Windows ZIP preference, renamed aqua packages, Homebrew cask metadata), and hardens pacman package detection and Windows self-update cleanup.
Added
bootstrap: Remote bootstrap can now select which
mise.<env>.tomllayers load on each SSH target without inheriting the orchestrator's full environment. Set a default with[bootstrap.remote].mise_env, override per host in your inventory, or pass--remote-env(repeatable or comma-separated) on the command line. (#12182 by @jdx)bootstrap: Independent config roots can now contribute
symlink-eachtrees that share the same target directory, as long as their leaf paths are disjoint. Overlapping leaves and file/directory collisions still fail before any changes, reporting both declaring config origins. (#12190 by @jdx)doctor:
mise doctornow detects leftover Windows self-update helper files (__relocated__/__selfdelete__copies in TEMP) and reports their count and total size, noting that a subsequentmise self-updateremoves them. (#12205 by @JamBalaya56562)Fixed
Providesare no longer reported as missing. mise now usespacman -Tto distinguish genuinely missing packages, recovers the provider's version for status, and skips provider-satisfied aliases during targeted upgrades so pacman does not try to replace the provider. (#12183 by @jdx)aqua:backends (including d2, typstyle, gitui, gradle, ktlint, kubeseal, and velero) now point at their renamed, canonical package ids, so they install even in networks whereapi.github.comis unreachable. A regression test prevents this drift from returning. (#12186 by @kkom)azure-clinow installs from the official bundled-Python ZIP release instead of PyPI, fixingazfailing with'python' is not recognizedorNo module named 'azure'. Linux and macOS continue to use the existing pipx install. (#12161 by @JamBalaya56562)"auto_updates": null, treating it as the defaultfalse. This was breaking metadata fetches for the majority of current casks. (#12192 by @jdx)tar.zst>tar.xz> other), which a prior change had accidentally reduced to a tiebreak. (#12200 by @risu729).tbzand.tbz2are now normalized correctly when matching preferred asset names and stem-only checksums, including mixed-case suffixes. This prevents assets from losing the preferred-name bonus and selecting the wrong archive. (#12199 by @risu729)Performance
Documentation
New Contributors
Full Changelog: jdx/mise@v2026.8.9...v2026.8.10
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.9: : Composable Bootstrap, Environment-Aware conf.d, and Faster StartupCompare Source
This release expands declarative bootstrap into a composable, multi-root system; adds environment-specific
conf.dfragments and glob-based ignored config paths; smooths out shell activation so runtime overrides stick; and delivers major startup performance gains for vfox-backed setups. It also includes several security hardening fixes worth noting.Highlights
Added
bootstrap: Compose declarative resources from multiple independent config roots via
[bootstrap].config_roots. Selected roots contribute[dotfiles],[bootstrap.files],[bootstrap.directories],[bootstrap.services], and[bootstrap.compose]without gaining precedence from list or glob order; identical declarations are deduplicated and conflicting declarations fail with both origins reported. (#12105, #12132 by @jdx)bootstrap: Declaration provenance is now retained and exposed for dotfiles and managed files/directories.
mise bootstrap plan, bootstrap status, andmise dotfiles statusinclude origin details (declaring config, config root, environment, resolved source) in JSON, and human-readable tables gain a Config column. (#12100 by @jdx)bootstrap: Homebrew-compatible support for self-updating and adopted casks in
[bootstrap.packages]. Casks declaringauto_updates: trueare left to update themselves, and existing app bundles can be adopted globally with[bootstrap.brew].adopt = trueor per cask withadopt = true. (#12074 by @ascarter)bootstrap: Remote bootstrap gains symlink materialization controls. Use
--copy-link <PATH>(repeatable) to dereference selected source-relative symlinks or--copy-linksto recursively dereference all archived symlinks; both are also configurable in[bootstrap.remote]and per-host. Default behavior is unchanged (links stay links). (#12121 by @jdx)config: Environment-specific
conf.dfragments. Files like.mise/conf.d/*.{env}.toml(and.localvariants) load only when that config environment is active, applying to project, global, and systemconf.ddirectories. (#12151 by @jdx)config:
ignored_config_pathsnow supports relative entries and glob patterns (including recursive**). Entries in.miserc.tomlresolve against the declaring file, whileMISE_IGNORED_CONFIG_PATHSresolves against the invocation directory — making it easy to exclude vendored repos portably. (#12169 by @jdx)config:
mise run, nakedmise <task>,mise install,mise exec, andmise watchnow implicitly trust and persist the active config in normal mode, avoiding a redundant prompt. Automatichook-env/inspection commands still require explicit trust, and paranoid and safe modes are unchanged. (#12107 by @jdx)system: Plugins can declare an ordered list of candidate package names per package manager in
systemDependencies, so the same capability can be expressed across distro renames (for exampleapt = { "libaio1t64", "libaio1" }). mise resolves the first available candidate. (#12149 by @jdx)vfox: Traditional vfox plugins can now read configured
[tools]options fromctx.optionsinPreInstallandPostInstallhooks, with scalars as strings and arrays/tables as structured Lua values. Existing hook environment variables continue to work. (#12174 by @jdx)Fixed
export, shell aliases, sourced scripts, or direct PATH edits are no longer reverted on every prompt, reversing the continuous enforcement introduced in 2026.8.0. (#12094 by @jdx)libcselections stay strict. (#12093 by @jdx)uveven when invoked through a tool override (for examplemise x tiny@3), sopython.uv_venv_autono longer reportsuvas missing right after mise installs it. (#12177 by @jdx)mise which <bin> --tool=<tool>@<version>now reports that the requested version is not installed (with an install hint) instead of the misleading "not currently active" message. (#12106 by @TrevorBurnham)--no-hook-envomits the hook. (#12089, #12131, #12117 by @JamBalaya56562)+, and key the remote version cache by listing tool options. (#12118 by @Marukome0743, #12164 by @JamBalaya56562)systemDependenciesin embedded plugins, and apply netrc credentials to HTTP requests. (#12155, #12152, #12168 by @jdx)Changed
RTX_*environment variables (includingRTX_TOOL_OPTS__*andRTX_ADD_PATH) passed to asdf and vfox plugin hooks. Plugin authors should use the equivalentMISE_*variables; standardASDF_*variables remain available to asdf plugins. (#12172 by @jdx)Performance
idiomatic_version_file_enable_tools, so mise no longer boots a Lua VM for every vfox plugin on ordinary invocations. Common commands dropped from hundreds of milliseconds to single-digit milliseconds, and nestedmise run/mise xchains improved dramatically. (#12143 by @jdx)hook-envtwice per directory change. (#12147 by @jdx)Security
MISE_SAFE=1) now blocks tool-levelpostinstallhooks andinstall_envfrom running during installation. (#12140 by @jdx)Registry
workerdviagithub:cloudflare/workerd. (#12180 by @mikea)vlangat the maintainedvfox:jdx/vfox-vbackend so it shares versions withv, replacing an unmaintained third-party version source. (#12153 by @jdx)Breaking Changes
conf.dfragment with an extra dot before.toml(for examplenode.tools.toml) is now interpreted as environment-specific. Use hyphens for unconditional multi-word fragment names (for examplenode-tools.toml). (#12151)vlang = "2026.x"-style versions must move to a real upstream version such as0.5.2or aweekly.*tag, since the previous version strings did not correspond to upstream tags. (#12153)RTX_*variables must switch toMISE_*. (#12172)New Contributors
Full Changelog: jdx/mise@v2026.8.8...v2026.8.9
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.8.8: : Restore ARMv7 release buildsCompare Source
This release restores the ARMv7 (hard-float) build so those binaries can be published again.
Fixed
armv7-unknown-linux-gnueabihfbuild now installs a newer libclang (LLVM 6), which theaws-lc-sysbindgen step requires. Previously the release job panicked on every ARMv7 build because the cross Ubuntu 16.04 image shipped libclang 3.8. (#12088 by @jdx)Full Changelog: jdx/mise@v2026.8.7...v2026.8.8
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
AI-assisted — Tool: Codex; model: openai/gpt-5; version: unavailable.
v2026.8.7: : Windows launchers, project conf.d, and safer installsCompare Source
This release expands Windows support across generated launchers, dotfiles, shells, and file tasks; adds project
conf.dfragments, task-specific tool installation, and APK bootstrap support; and includes a broad set of reliability and security fixes.Added
conf.dconfiguration fragments. (#12061 by @Marukome0743)--windowsbootstrap launchers and write Windows launchers beside generated tool stubs. (#11919, #11888 by @JamBalaya56562)MISE_BREW_CASK_OPT_APPDIRfor choosing the application installation directory. (#12068 by @st1971)Fixed
**source/output globs, and correct task-relative cache paths. Unknown file-task header keys now warn instead of failing. (#12013, #12070, #12022, #11995, #12007).shtask siblings, and avoid unsupported UNC working directories incmd.exe. (#12016, #12050, #12055, #11992, #12066 by @JamBalaya56562)PATH. (#12063 by @Marukome0743)MAX_PATHlimits safely and stop leaving large temporary copies behind after failed updates. (#12062, #12080 by @JamBalaya56562)TEMP. (#12064 by @JamBalaya56562)Full Changelog: jdx/mise@v2026.8.6...v2026.8.7
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
AI-assisted — Tool: Codex; model: openai/gpt-5; version: unavailable.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.