Skip to content

Commit 85f6541

Browse files
chore(deps): update dependency jdx/mise to v2026.10.2 (#2525)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [jdx/mise](https://redirect.github.com/jdx/mise) | uses-with | minor | `v2026.9.17` → `v2026.10.2` | --- ### Release Notes <details> <summary>jdx/mise (jdx/mise)</summary> ### [`v2026.10.2`](https://redirect.github.com/jdx/mise/releases/tag/v2026.10.2): : Experimental spinel backend, typed tool options in the schema, and daemon presets on Windows [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.10.1...vfox-v2026.10.2) This release adds an experimental `spinel:` backend for compiling Ruby CLIs to native binaries. The `mise.toml` schema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting. ##### Added - **Experimental `spinel:` backend.** It builds a Ruby command-line tool from a GitHub repository into a native executable using [Spinel](https://redirect.github.com/matz/spinel), Matz's Ruby AOT compiler. Versions come from git tags through `git ls-remote`, so listing them doesn't call the GitHub API. Available options: `entrypoint`, `bin`, `tag_prefix`, `source_ref` and `spinel`. You need the `spinel` compiler on `PATH` (mise doesn't install it yet) and `mise settings experimental=true`. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on [nateberkopec/mise-backend-spinel](https://redirect.github.com/nateberkopec/mise-backend-spinel). [#&#8203;13922](https://redirect.github.com/jdx/mise/pull/13922) ```toml [tools."spinel:tobi/try"] version = "1.10.1" entrypoint = "try.rb" bin = "try" tag_prefix = "v" ``` - **Typed tool options in the JSON schema.** Editors that use `schema/mise.json` now validate and autocomplete options for each backend, based on the tool's prefix. This covers github, gitlab, forgejo, ubi, http, s3, aqua, cargo, npm, pypi/pipx, gem, go, conda, spm, packslip and spinel. It also covers core-tool options for `python`, `java`, `rust` and `dotnet`, per-platform overrides (`platforms.<os>-<arch>`) and `[tasks.*.tools]` tables. For example, a numeric `asset_pattern` or `java` `release_type = "stable"` is now flagged. Boolean options accept `true`/`false`, `"true"`/`"false"` and `1`/`0`, the same values mise accepts. `lazy_bins` accepts a single string. The deprecated `experimental_monorepo_root` key is allowed again. Runtime behavior is unchanged, but your editor may now flag mistakes in existing configs. [#&#8203;13924](https://redirect.github.com/jdx/mise/pull/13924) - **Daemon presets on Windows.** `mise daemons start` no longer refuses preset daemons on Windows. Every preset except `redis`, which has no Windows build, now runs under pitchfork's default `cmd /C` shell. For PostgreSQL to stop cleanly, you need pitchfork 2.29.0 or later. PostgreSQL also won't start from an elevated prompt. Windows reserves some port ranges for Hyper-V and WSL, so a preset's default port can be blocked. If it is, set a different one with `ports`. [#&#8203;13929](https://redirect.github.com/jdx/mise/pull/13929) by [@&#8203;JamBalaya56562](https://redirect.github.com/JamBalaya56562) ```toml [daemons.db] preset = "postgres" version = "18" options = { database = "app" } ``` - **Install mise with packslip.** The installation guide now covers installing mise's signed release without running an install script. packslip verifies the Sigstore signature and the archive digest. `mise self-update` works with this install method. [#&#8203;13710](https://redirect.github.com/jdx/mise/pull/13710) ```sh packslip install github.com/jdx/mise --pin ps1_nlhmwtfeufglxv5myvwvronk7a ``` ##### Fixed ##### Config and activation - **An untrusted project config no longer breaks shell activation.** Before, `mise hook-env` failed completely, so tools and env from your trusted global config were not applied either. Now it skips the untrusted file, prints the usual one-time warning and loads everything else. Explicit commands such as `mise run` and `mise x` still error on untrusted configs. [#&#8203;13919](https://redirect.github.com/jdx/mise/pull/13919) - **A failed settings reload is reported as an error instead of crashing.** Commands such as `mise install`, `mise use`, `mise upgrade` and `mise ls-remote --prerelease` reload settings partway through. Before, a failed reload aborted mise with SIGABRT and a core dump. Now mise prints `failed to reload settings` with the cause and keeps using the previous settings. [#&#8203;13925](https://redirect.github.com/jdx/mise/pull/13925) - **`--no-config` and `MISE_NO_CONFIG=1` now skip `.miserc.toml` discovery.** Before, a malformed project, global or system miserc broke commands like `mise --no-config version`. [#&#8203;13926](https://redirect.github.com/jdx/mise/pull/13926) by [@&#8203;donbeave](https://redirect.github.com/donbeave) ##### Tasks - **A timed-out task fails even if it exits cleanly.** On Unix, a task that caught SIGTERM and exited 0 after its `timeout` was reported as successful. Now `mise run` reports `timed out` and exits non-zero. [#&#8203;13930](https://redirect.github.com/jdx/mise/pull/13930) by [@&#8203;Marukome0743](https://redirect.github.com/Marukome0743) - **Timed-out tasks on Windows can clean up.** When a task hits its `timeout`, mise now sends it Ctrl+C and gives it 5 seconds before ending its process tree, the way Unix uses SIGTERM followed by SIGKILL. For example, PowerShell `finally` blocks now run. Only the timed-out task gets the Ctrl+C. The whole-run `mise run --timeout` still stops tasks immediately on Windows. [#&#8203;13889](https://redirect.github.com/jdx/mise/pull/13889) by [@&#8203;JamBalaya56562](https://redirect.github.com/JamBalaya56562) ##### Windows - **`mise exec -- cmd /c` keeps double quotes.** Before, `mise exec -- cmd /c 'echo "a b"'` printed `\"a b\"`. Pitchfork daemons with `mise = true` whose `run` contained a quote, such as a quoted program path with a space, also failed to start. mise now passes a single quoted command after `/c` or `/k` to cmd unchanged. [#&#8203;13887](https://redirect.github.com/jdx/mise/pull/13887) by [@&#8203;JamBalaya56562](https://redirect.github.com/JamBalaya56562) - **Task daemons with `init` steps start under `cmd.exe`.** Before, they failed with `'exec' is not recognized`. On Windows, mise now builds the command with cmd quoting and escaping. Write `init` steps as cmd commands. [#&#8203;13928](https://redirect.github.com/jdx/mise/pull/13928) by [@&#8203;JamBalaya56562](https://redirect.github.com/JamBalaya56562) ##### Other - **packslip follows repositories that moved to a new owner.** mise now treats a transfer like a rename, matching on repository ID with a one-time warning. It still refuses a different repository that reuses a deleted repository's name. Refusal messages now tell you which records to clear: `mise packslip forget`, the tool's `mise.lock` entries, or both. Existing pins and lockfile entries still load. [#&#8203;13710](https://redirect.github.com/jdx/mise/pull/13710) - **`mise dot save` and history sync work after a tracked directory is replaced by a symlink.** Before, they failed while reading older checkpoints. [#&#8203;13931](https://redirect.github.com/jdx/mise/pull/13931) ##### Registry - `helmfile` (1.8.1 and later) and `dagu` (2.18.0 and later) now install from signed packslip manifests. Older versions still install through `aqua:`. To list them, run `mise ls-remote aqua:helmfile/helmfile` or `mise ls-remote aqua:dagucloud/dagu`. [#&#8203;13933](https://redirect.github.com/jdx/mise/pull/13933) - New aqua packages: `goccy/tobari`, `ymmt2005/pbschema-lens`. **Full Changelog**: <jdx/mise@v2026.10.1...v2026.10.2> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. ### [`v2026.10.1`](https://redirect.github.com/jdx/mise/releases/tag/v2026.10.1): : Task timeout and Ctrl-C fixes, Windows daemon and shim fixes [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.10.0...vfox-v2026.10.1) This release is mostly bug fixes. `mise run` now stops tasks properly when `--timeout` expires or you press Ctrl-C. Task daemons and native shims work better on Windows. `core:rust` now follows `mise.lock` and picks up new stable and beta toolchains. Lockfile, GitHub asset selection, Homebrew cask and plugin update problems are also fixed. ##### Fixed ##### Tasks - **`mise run --timeout` now stops the tasks it was running.** Before, mise printed the timeout error and exited, but the task processes could keep running in the background. Now the whole-run timeout (`--timeout` or the `task.timeout` setting) stops tasks the same way a per-task `timeout` does. On Unix, mise sends SIGTERM and then SIGKILL after 5 seconds. On Windows, it runs `taskkill /F /T`. Tasks with `raw = true` are not stopped by the whole-run timeout. [#&#8203;13876](https://redirect.github.com/jdx/mise/pull/13876) by [@&#8203;Marukome0743](https://redirect.github.com/Marukome0743) - **A single Ctrl-C lets tasks shut down cleanly.** Before, one Ctrl-C could make mise exit right away while tasks were still cleaning up. This happened in three cases: a task that runs `mise run` itself got SIGINT twice; a tool like `docker compose up` treated the duplicate SIGINT as a force-quit; and a task that exits non-zero on SIGINT caused mise to send SIGTERM to its sibling tasks. Now mise waits for tasks to finish and then exits with status 130. A second Ctrl-C still force-quits. [#&#8203;13904](https://redirect.github.com/jdx/mise/pull/13904) - **Tab completion for the `:task` shorthand.** In a monorepo, `mise run :<TAB>` now suggests tasks from the current config root, and task flags complete after the shorthand. [#&#8203;13882](https://redirect.github.com/jdx/mise/pull/13882) by [@&#8203;pikeas](https://redirect.github.com/pikeas) ##### Daemons - **Task daemons start on Windows.** A daemon declared with `task =` failed under `cmd /C` with `'exec' is not recognized`. mise now registers it as an argv command that pitchfork starts without a shell, so `args` reach the task exactly as written on every platform. **This needs pitchfork 2.28.0 or later.** With an older pitchfork, mise shows an error that tells you to upgrade, for example with `mise use pitchfork@latest`. Task daemons that use `init` still run through a shell, so they still don't work under `cmd /C`. [#&#8203;13714](https://redirect.github.com/jdx/mise/pull/13714) by [@&#8203;JamBalaya56562](https://redirect.github.com/JamBalaya56562) - **Daemon `run` commands can use `[env]` and `[vars]`.** Before, a template such as `{{ vars.test_var }}` failed with `Variable 'vars' is not defined`. `mise x` now renders the command when the daemon starts, using the project's `[env]`, `[vars]` and mise template filters. Pitchfork's own variables, such as `{{ name }}`, still work. This applies only to `run` and requires a pitchfork release newer than 2.29.0. [#&#8203;13894](https://redirect.github.com/jdx/mise/pull/13894) ```toml [vars] greeting = "it's" [daemons.hello] run = "exec echo {{ vars.greeting | quote }} from {{ name }}" ``` ##### Windows shims - **No more endless process chains from duplicate shim copies.** If two copies of `mise-shim.exe` were on PATH (for example, one from winget's `Links` directory), they could keep calling each other through `mise x`. Running `mise-shim` by its own name now exits with an error. If `mise x` resolves a tool to another shim copy, mise stops after one step and names the PATH directory to remove. [#&#8203;13681](https://redirect.github.com/jdx/mise/pull/13681) by [@&#8203;JamBalaya56562](https://redirect.github.com/JamBalaya56562) - **Node IPC works through the `node.exe` shim.** A Node parent that spawned the shim with an `'ipc'` stdio entry used to wait forever. JSON IPC messages and disconnects now pass through the shim. Passing socket or server handles over the channel is still not supported. [#&#8203;13903](https://redirect.github.com/jdx/mise/pull/13903) ##### Rust - **`mise upgrade rust` updates `stable` and `beta`.** mise didn't recognize rustup 1.29's new `update available:` text. Even when it detected an update, the upgrade skipped the toolchain as already installed. mise now reads both spellings, counts only updates for the toolchain it manages, and updates the toolchain in place. If the update fails, the old toolchain stays usable. [#&#8203;13898](https://redirect.github.com/jdx/mise/pull/13898) - **`core:rust` follows `mise.lock`.** mise mistook rustup's symlinks for `mise link`ed versions, so it ignored the lockfile and installed the newest version even with `locked = true`. [#&#8203;13915](https://redirect.github.com/jdx/mise/pull/13915) ##### Backends, lockfiles and bootstrap - **GitHub auto-detection no longer installs metadata files.** SBOMs, signatures, checksums and other sidecar files with platform names, such as `*.tar.gz.sbom.json`, could be chosen as the tool and saved to `mise.lock`. Automatic selection now skips them. Explicit `url` and `asset_pattern` options are unchanged. [#&#8203;13908](https://redirect.github.com/jdx/mise/pull/13908) - **`mise lock` removes outdated duplicate entries.** After you changed a tool option, for example by adding `uvx = false` to a `pipx:` tool, `mise lock --upgrade` could leave the old unbound entry next to the new bound one. Unfiltered `mise lock` runs now remove the old entry, unless it has platform data (checksum or URL) that the new entry doesn't have. [#&#8203;13909](https://redirect.github.com/jdx/mise/pull/13909) - **Aqua registry cache errors after upgrading.** Compiled registry caches from earlier versions could load but then fail when a package was resolved. mise now ignores those caches and rebuilds them. [#&#8203;13884](https://redirect.github.com/jdx/mise/pull/13884) - **Packslip installs retry missing skills.** If the binary installed but a declared skill couldn't be fetched, mise still marked the install as complete. Now the install fails with an error. The next `mise install` fetches only the missing skills and doesn't reinstall the tool. [#&#8203;13885](https://redirect.github.com/jdx/mise/pull/13885) - **Pkg-based `brew-cask` packages are no longer reinstalled on every run.** Casks such as `google-drive` list package IDs for several architectures, and mise expected every one of them to be installed. Receipts now store only the patterns that match on your machine. Casks recorded by earlier versions are reinstalled once to write a corrected receipt. [#&#8203;13893](https://redirect.github.com/jdx/mise/pull/13893) - **`mise plugins update` works when the remote isn't named `origin`.** This happens, for example, when git's `clone.defaultRemoteName` is set to something else. mise uses `origin` if it exists and otherwise uses the first remote. [#&#8203;13914](https://redirect.github.com/jdx/mise/pull/13914) ##### Changed - `mise skills sync`, the table output of `mise skills ls`, and other human-facing messages now show paths under your home directory with `~`. This includes output from `mise deps install`, task source lines, `mise completion --install` and daemon messages. `--json` output and script-oriented commands still print full paths. [#&#8203;13910](https://redirect.github.com/jdx/mise/pull/13910) **Full Changelog**: <jdx/mise@vfox-v2026.10.0...v2026.10.1> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. ### [`v2026.10.0`](https://redirect.github.com/jdx/mise/releases/tag/v2026.10.0): : Stricter signer checks for cosign and GitHub attestations, trust for inline options in .tool-versions [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.18...vfox-v2026.10.0) This release tightens supply-chain verification. Keyless cosign bundles must now match a pinned signer identity, and GitHub attestation workflow checks no longer accept partial matches. It also closes a `.tool-versions` trust gap that could leak `GITHUB_TOKEN`, adds a per-cask `appdir` option for Homebrew casks, and fixes problems with locked SLSA installs, musl hosts and `mise backends switch`. ##### Security - **Inline tool options in `.tool-versions` now require trust.** This is the `.tool-versions` version of the `mise.toml` fix in 2026.9.18. An untrusted project could ship a `github:` entry with inline options, such as `[api_url=...]`, pointing at another host. Commands such as `mise ls`, `env`, `current`, `outdated` and `latest` would then send your `GITHUB_TOKEN` to that host without asking for trust. Any entry whose tool name contains `[` now requires trust, the same as Tera templates. Plain lines like `node 20.0.0` still load without trust, and a `[` inside a comment is ignored. Run `mise trust` for projects you rely on. `MISE_SAFE=1` still skips trust checks. (GHSA-wcqh-j26q-g44x) [#&#8203;13869](https://redirect.github.com/jdx/mise/pull/13869) - **Keyless cosign verification now checks who signed.** Before, the aqua backend only checked that a bundle chained to Sigstore's Fulcio CA. Any GitHub Actions workflow in any repository can get such a certificate, so a bundle signed by the wrong workflow would still pass. mise now applies the registry's `--certificate-identity[-regexp]`, `--certificate-oidc-issuer[-regexp]` and `--certificate-github-workflow-{repository,ref,name,trigger,sha}` options to the signing certificate. It does this for both current and legacy bundles. Keyless verification now requires a pinned identity, and an unknown or empty `--certificate-*` option is an error. Key-based verification (`--key`) is unchanged. Registry patterns that use RE2 `\Q…\E` quoted literals, such as the one for `vfox`, are supported. [#&#8203;13875](https://redirect.github.com/jdx/mise/pull/13875), [#&#8203;13879](https://redirect.github.com/jdx/mise/pull/13879) - **GitHub attestation signer workflow matching is anchored.** The expected `signer_workflow` must now match the end of the certificate's workflow path as whole path segments. Before, it was a substring match against the whole identity, so a longer workflow file name such as `release.yml.evil.yml`, or a ref that contained the expected path, would pass. An empty `signer_workflow` now fails verification. Both the bare form (`.github/workflows/release.yml`) and the repository-qualified form (`owner/repo/.github/workflows/release.yml`) still work. [#&#8203;13877](https://redirect.github.com/jdx/mise/pull/13877) ##### Added - **Per-cask app directories.** A `brew-cask:` bootstrap package can set its own `appdir`. This overrides the global `MISE_BREW_CASK_OPT_APPDIR` setting, expands `~/`, and also applies to the cask's dependencies. [#&#8203;13865](https://redirect.github.com/jdx/mise/pull/13865) ```toml [bootstrap.packages] "brew-cask:1password" = { appdir = "/Applications" } ``` The setting only applies to installs and upgrades: apps that are already installed are not moved. A first install into a new `appdir` won't replace an existing app it doesn't own unless you set `adopt = true`. Other package managers ignore `appdir` and print a warning. - **`slsa_signer_identity` and `slsa_signer_issuer` options for aqua tools.** These work the same as in the github backend. They let `mise lock` verify and record SLSA provenance for packages whose registry entry has no signer, such as `aqua:google/osv-scanner`. You must set both options to non-empty strings, and together they override any signer in the registry, including version overrides. [#&#8203;13856](https://redirect.github.com/jdx/mise/pull/13856) - **Registry:** `cloudflare-cf`, Cloudflare's `cf` CLI, which is in beta and installs from `npm:cf`. It provides the `cf` and `cloudflare` binaries. Pin a beta version for now, such as `mise use cloudflare-cf@1.0.0-beta.10`. An unpinned install currently resolves to an unrelated old `0.x` release. [#&#8203;13871](https://redirect.github.com/jdx/mise/pull/13871) - **Docs:** a new Releases page (under About in the docs) shows a timeline of release sizes, the issues each release resolved, and expandable release notes. [#&#8203;13855](https://redirect.github.com/jdx/mise/pull/13855) ##### Fixed - **Locked SLSA installs work again without a registry signer.** Since 2026.9.17, a lockfile that recorded a checksum and SLSA provenance failed with "Aqua registry metadata has no signer\_identity and signer\_issuer" for tools such as `aqua:google/osv-scanner` and `aqua:fluxcd/flux2`. A lock entry with a checksum and recorded provenance is now trusted for SLSA too: the install only checks the artifact digest, as it already did for other provenance types. `locked_verify_provenance` or paranoid mode still re-verify and still require a signer. [#&#8203;13856](https://redirect.github.com/jdx/mise/pull/13856) - **aqua on musl hosts.** On Alpine and other musl hosts, an aqua tool whose registry entry only names a glibc build (such as `zizmor`) failed with "no asset found: ...-unknown-linux-musl...". mise now installs the asset the registry names. The binary still needs glibc or `gcompat` to run. `mise lock` for `linux-x64-musl` records the same asset. [#&#8203;13857](https://redirect.github.com/jdx/mise/pull/13857) - **`mise backends switch` handles stale lock entries.** Sometimes `mise install` warned that a tool was locked to a replaced backend, for example `asdf:clojure` instead of `vfox:jdx/vfox-clojure`, but `mise backends switch` then reported there was nothing to switch. This happened when the config's version no longer matched the lock entry. The command now switches those entries too. Entries at a version the config no longer resolves to are relocked at the config's version and reported as `replacing stale <tool>@<version>`. [#&#8203;13859](https://redirect.github.com/jdx/mise/pull/13859) - **Ctrl-C exits with status 130.** Interrupting `mise install`, `upgrade`, `exec` and similar commands used to exit with 1, the same as an ordinary failure. They now exit with 130 (128 + SIGINT), matching `mise run`, so shells and scripts can tell when a user interrupted. A repeated Ctrl-C during `mise run` also exits with 130. This applies on Unix and Windows. [#&#8203;13862](https://redirect.github.com/jdx/mise/pull/13862) - **Declining a trust prompt skips the config for that run.** Before, declining still failed the current command with "not trusted". [#&#8203;13868](https://redirect.github.com/jdx/mise/pull/13868) - The one-time startup migration for stale `latest` runtime directories has been removed. It was due to expire in this release and would have blocked normal installs. `mise install` still repairs a stale `latest` directory, but passive commands such as `mise ls` no longer touch it. [#&#8203;13868](https://redirect.github.com/jdx/mise/pull/13868) - **Stale dotfile history watchers are diagnosed.** A history watcher started on an older mise can fail every capture with an unknown-field error for newer settings such as `exclude`. `mise doctor` and `mise dot status` now report that the watcher is outdated and tell you to run `mise bootstrap services apply`, which restarts it. [#&#8203;13864](https://redirect.github.com/jdx/mise/pull/13864) - **Java:** the missing-metadata error now names the target platform, for example `no metadata found for version zulu-8 on windows-arm64`. [#&#8203;13873](https://redirect.github.com/jdx/mise/pull/13873) ([@&#8203;jsiu93](https://redirect.github.com/jsiu93)) ##### Breaking Changes - **`--from-git` removed from `mise bootstrap`.** `mise bootstrap --from-git` and `mise bootstrap remote --from-git` now fail with an unexpected-argument error. Use `--adopt`, which has been the documented flag since 2026.9.3: [#&#8203;13872](https://redirect.github.com/jdx/mise/pull/13872) ```sh mise bootstrap --adopt git@github.com:me/dotfiles.git ``` - **vfox tool plugins that use keyless cosign must pin an identity.** If a `PreInstall` attestation sets `cosign_sig_or_bundle_path` without `cosign_public_key_path`, it must also set `cosign_certificate_identity` or `cosign_certificate_identity_regexp`. You can also set `cosign_certificate_oidc_issuer`. Without an identity, the attestation is rejected. Registry entries that already work with the aqua CLI are not affected. [#&#8203;13875](https://redirect.github.com/jdx/mise/pull/13875) - **Alpine/musl:** if a registry entry names a gnu asset but the release also ships a musl build, mise now installs the gnu build. Before, it switched to musl. Set `libc = "musl"` on that tool to keep the musl build. [#&#8203;13857](https://redirect.github.com/jdx/mise/pull/13857) - **Exit code on Ctrl-C:** scripts that checked for exit status 1 after an interrupt should now check for 130. [#&#8203;13862](https://redirect.github.com/jdx/mise/pull/13862) ##### New Contributors - [@&#8203;jsiu93](https://redirect.github.com/jsiu93) made their first contribution in [#&#8203;13873](https://redirect.github.com/jdx/mise/pull/13873) **Full Changelog**: <jdx/mise@vfox-v2026.9.20...v2026.10.0> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. ### [`v2026.9.18`](https://redirect.github.com/jdx/mise/releases/tag/v2026.9.18): : Remote config includes, OCI task catalogs, and a trust fix for inline tool options [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.17...vfox-v2026.9.18) `mise.toml` can now `include` a shared config file from a git repository or OCI registry, and `task_config.includes` accepts OCI artifacts. The release also closes a trust bypass that could send `GITHUB_TOKEN` to an attacker-controlled host, adds gem registry sources, and fixes several daemon and dotfiles problems. #### Security - **Inline tool options now require trust.** Before this change, a `mise.toml` in an untrusted directory could hide options in a tool key, for example a `github:` tool key with `[api_url=...]` pointing at another host. mise loaded the file without trust because the value was a plain version string. Commands such as `mise ls`, `env`, `current`, `outdated`, `upgrade --dry-run` and `latest` then sent `GITHUB_TOKEN` to that `api_url`. Now any tool key that contains `[` requires trust, the same as `{ ... }` option tables already did. Plain keys like `node` or `"cargo:eza"` still load without trust. If you use inline options in a project you haven't trusted yet, run `mise trust`. `MISE_SAFE=1` still skips trust checks entirely. [#&#8203;13849](https://redirect.github.com/jdx/mise/pull/13849) #### Added - **Include shared config from git or OCI.** Organizations can keep tool versions, env and hooks in one place and pull them into every repo: [#&#8203;13843](https://redirect.github.com/jdx/mise/pull/13843) ```toml include = [ "git::<repo-url>//mise.toml?ref=main", "oci::ghcr.io/myorg/platform-config@sha256:0f1e2d3c...", ] [tools] node = "22" # the file's own entries override the included ones ``` A `git::` include points at a `.toml` file in a repository. An `oci::` include points at an artifact with a `mise.toml` at its root. The included file is merged beneath the file that includes it, and a later include overrides an earlier one. It uses that file's trust, config root and lockfile. A fragment may contain `[tools]`, `[tool_alias]`, `[env]`, `[vars]`, `[hooks]`, `[alias]`, `[shell_alias]`, `[plugins]`, `[wrappers]` and `min_version`. Anything else is an error, including nested `include`, `[settings]`, tasks, `[dotfiles]` and `[daemons]`. - An untrusted config never fetches, and safe mode never fetches for project config. - Paranoid mode requires a full commit sha or an OCI digest. - Fragments are cached in `MISE_CACHE_DIR/config-includes`. Pinned refs are never fetched again. Branches and tags are refreshed after `fetch_remote_versions_cache` expires, and only by commands that check remote versions, such as `install`, `up` and `use`. If a refresh fails, the cached copy is used with a warning. - **OCI task catalogs.** `task_config.includes` accepts `oci::` references, in addition to `git::`. The artifact is pulled, verified against its digests, cached in `MISE_CACHE_DIR/remote-oci-tasks-cache`, and loaded like a local task directory. Credentials come from `docker login`/`podman login`. Artifacts with symlinks or special files are rejected. Signatures are not verified, so pin `@sha256:` if you need the contents to stay the same. [#&#8203;13820](https://redirect.github.com/jdx/mise/pull/13820) ```toml [task_config] includes = ["oci::ghcr.io/myorg/shared-tasks:1.0.0"] ``` ```sh oras push ghcr.io/myorg/shared-tasks:1.0.0 build.toml scripts/deploy ``` - **`mise bootstrap --from` accepts `?ref=`** to select a branch, tag or commit, for example `mise bootstrap --from 'git::<repo-url>?ref=v1'`. The `git::` prefix is optional. With `--update`, mise resolves the ref on origin again and fast-forwards branches. A ref that was deleted upstream is an error. [#&#8203;13822](https://redirect.github.com/jdx/mise/pull/13822) - **Install a gem from a specific registry.** The new `source` option sends version lookup and install for one gem to that registry, and leaves the machine's `gem sources` unchanged. Credentials in the URL are redacted from logs and install metadata. [#&#8203;13391](https://redirect.github.com/jdx/mise/pull/13391) ([@&#8203;waynehoover](https://redirect.github.com/waynehoover)) ```toml [tools] "gem:internal-tool" = { version = "latest", source = "<registry-url>" } ``` A GitHub Packages source (the `rubygems.pkg.github.com` host) without credentials now uses the GitHub token mise already resolves. The token needs `read:packages`. GitHub Packages has no versions API, so you must pin an exact version there. [#&#8203;13832](https://redirect.github.com/jdx/mise/pull/13832) ([@&#8203;waynehoover](https://redirect.github.com/waynehoover)) - **`mise lock --sidecars`** lists the native dependency sidecar directories (aube for npm, uv for Python) that must be committed along with `mise.lock`. It doesn't resolve, install or write anything. It marks missing sidecars, follows symlinked lockfiles, and supports `--json` for tools such as Renovate. [#&#8203;13819](https://redirect.github.com/jdx/mise/pull/13819) - **Daemon presets export their named ports** as environment variables, for example `CRDB_HTTP_PORT` for a `cockroachdb` daemon named `crdb`, or `AUTHZ_HTTP_PORT` and `AUTHZ_METRICS_PORT` for a `spicedb` daemon named `authz`. The values include worktree offsets from `port = "auto"` and any `ports.*` overrides, so you can use them in `[env]` without working out the port yourself. [#&#8203;13835](https://redirect.github.com/jdx/mise/pull/13835) - **`proxy_idle_timeout` for daemons** is now documented, typed in the JSON schema and validated. Set a duration such as `"30m"` to stop a proxy-started daemon, and then its dependencies, after that long without traffic. Set it to `false` to opt out. mise rejects `true`, bare numbers and values that don't look like durations, and names the daemon in the error. This requires pitchfork 2.27.0. [#&#8203;13830](https://redirect.github.com/jdx/mise/pull/13830), [#&#8203;13836](https://redirect.github.com/jdx/mise/pull/13836) - **Registry:** added `lstk`, the CLI that replaces LocalStack's old one. Installing `localstack` now warns that it is deprecated and suggests `mise use lstk`. Registry entries can now set a `deprecated` message. [#&#8203;13817](https://redirect.github.com/jdx/mise/pull/13817) #### Fixed - **`mise generate install-script`** no longer panics with or without `--version`. The generated wrapper now passes its pinned version to the installer. Before, a wrapper named for one release could install and keep running an older one. Without `--version`, the pin is the release `mise self-update` would pick. [#&#8203;13816](https://redirect.github.com/jdx/mise/pull/13816) - `mise oci build`, `push` and `run` no longer fail on a `required` env var when the project's `[oci.env]` gives it a value. You can now use a placeholder for a secret that only exists at runtime. Other commands still require the variable. [#&#8203;13821](https://redirect.github.com/jdx/mise/pull/13821) - `mise lock` now prints a warning with the cause when it skips a tool, for example a GitHub rate limit, instead of only counting it as skipped. You get one warning per tool. [#&#8203;13831](https://redirect.github.com/jdx/mise/pull/13831) - **Daemons:** - `mise daemons start|stop|restart --all` now works and applies to every daemon in the current project. Before, pitchfork rejected the command. `--all` can't be combined with daemon names or `--group`. [#&#8203;13827](https://redirect.github.com/jdx/mise/pull/13827) - The first `mise daemons start` or `restart` now installs the preset's tool. Before, it failed with a false "requires ... but \[tools] selects ..." error. Only the tools of the requested daemons and their dependencies are installed. [#&#8203;13837](https://redirect.github.com/jdx/mise/pull/13837) - URLs printed for projects without an explicit `[daemons_settings] namespace` now route through pitchfork's proxy instead of returning 404. This needs a pitchfork that supports `config add --label`. mise checks for the flag itself and picks it up when pitchfork is upgraded. [#&#8203;13833](https://redirect.github.com/jdx/mise/pull/13833) - When an automatically allocated daemon port is already taken, mise explains how to pin a different port in `mise.local.toml`. mise no longer adds its own error lines after pitchfork's message, and it exits with pitchfork's status. [#&#8203;13839](https://redirect.github.com/jdx/mise/pull/13839) - **Dotfiles:** - `mise dot` and other commands that use mise's internal Git calls work again with Git for Windows 2.56. [#&#8203;13812](https://redirect.github.com/jdx/mise/pull/13812) ([@&#8203;genskyff](https://redirect.github.com/genskyff)) - After an upgrade, the history watcher now notices that the mise binary was replaced, saves pending edits and exits so the service manager restarts it on the new version. A watcher started by hand with `mise dot watch` has to be started again. `mise dot status` now says when captures are failing. [#&#8203;13845](https://redirect.github.com/jdx/mise/pull/13845) **Full Changelog**: <jdx/mise@vfox-v2026.9.19...v2026.9.18> #### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 9e9deb6 commit 85f6541

16 files changed

Lines changed: 32 additions & 32 deletions

‎.github/workflows/acceptance-tests.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
1616
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
1717
with:
18-
version: v2026.9.17
19-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
18+
version: v2026.10.2
19+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
2020
- name: Run acceptance tests
2121
run: mise run acceptance-test

‎.github/workflows/api-diff.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,8 @@ jobs:
3434
persist-credentials: false
3535
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
3636
with:
37-
version: v2026.9.17
38-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
37+
version: v2026.10.2
38+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
3939
- name: Cache local Maven repository
4040
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
4141
with:

‎.github/workflows/build.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,8 @@ jobs:
1414
persist-credentials: false
1515
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
1616
with:
17-
version: v2026.9.17
18-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
17+
version: v2026.10.2
18+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
1919
- name: Cache local Maven repository
2020
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
2121
with:

‎.github/workflows/bump-api-diff-baseline.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,8 @@ jobs:
3535
persist-credentials: true
3636
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
3737
with:
38-
version: v2026.9.17
39-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
38+
version: v2026.10.2
39+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
4040
- name: Cache local Maven repository
4141
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
4242
with:

‎.github/workflows/generate-protobuf.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ jobs:
2020
persist-credentials: false
2121
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
2222
with:
23-
version: v2026.9.17
24-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
23+
version: v2026.10.2
24+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
2525
- name: Cache local Maven repository
2626
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
2727
with:

‎.github/workflows/github-pages.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,8 @@ jobs:
3939
fetch-depth: 0
4040
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
4141
with:
42-
version: v2026.9.17
43-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
42+
version: v2026.10.2
43+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
4444
cache: "false"
4545
- name: Setup Pages
4646
id: pages

‎.github/workflows/java-version-matrix-tests.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,8 +33,8 @@ jobs:
3333
- name: Set up mise
3434
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
3535
with:
36-
version: v2026.9.17
37-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
36+
version: v2026.10.2
37+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
3838

3939
- name: Cache local Maven repository
4040
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0

‎.github/workflows/jmx-exporter-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,8 @@ jobs:
2424
persist-credentials: false
2525
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
2626
with:
27-
version: v2026.9.17
28-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
27+
version: v2026.10.2
28+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
2929
- name: Cache local Maven repository
3030
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
3131
with:

‎.github/workflows/lint.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,8 @@ jobs:
2323
- name: Setup mise
2424
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
2525
with:
26-
version: v2026.9.17
27-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
26+
version: v2026.10.2
27+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
2828

2929
- name: Lint
3030
env:

‎.github/workflows/micrometer-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ jobs:
3232
persist-credentials: false
3333
- uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
3434
with:
35-
version: v2026.9.17
36-
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
35+
version: v2026.10.2
36+
sha256: 8f5f6660336f572830e33cd9b378d3131e529a0d4c4f0c553776be90a1ba302a
3737
- name: Cache local Maven repository
3838
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
3939
with:

0 commit comments

Comments
 (0)