Repository navigation
test(deps): update dependency mise to v2026.10.5 (main) - #7685
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.10.4→2026.10.5Release Notes
jdx/mise (mise)
v2026.10.5: : Java defaults to Temurin, per-machine and local-only dotfile history, packslip workflow pinningCompare Source
Java versions without a vendor prefix now install Eclipse Temurin builds. Dotfiles gain per-machine and local-only history, a
merge = "missing"mode, and a secret check beforemise dot syncpublishes anything. Packslip tools can be pinned to the workflow that signs their releases. Several features documented as experimental now actually requireexperimental = true. The rest of the release is fixes across tasks, shims, config loading, bootstrap and backends.Breaking Changes
java@21,java@ltsandjava@latestnow install Temurin. The default ofjava.shorthand_vendorchanges fromopenjdktotemurin. The jdk.java.net OpenJDK builds stop at the next feature release, sojava@21was stuck on 21.0.2 from January 2024. Vendor-prefixed requests (openjdk-21,corretto-21, ...) are not affected. Installed OpenJDK versions keep working, andmise upgradeoffers the Temurin build. Shorthand versions now include Temurin's build suffix (for example21.0.12+101.0.LTS). Temurin has no builds of Java 9, 10 or 12–15, so useopenjdk-12and similar for those. #14146shorthand_vendor = "openjdk". Without that setting,mise install --lockedfails withjava@21 is not in the lockfile. Either keep OpenJDK:mise lock --bump javaand commit the result.experimental = true(orMISE_EXPERIMENTAL=1) when you use them. Config that only mentions them still loads. #14114git::remotefile, including throughmise run --dry-run,mise watch, or as a dependency. Commands that only inspect tasks (tasks ls,tasks info,tasks deps,generate task-docs) show the task from its TOML and warn once that the file wasn't fetched. These were documented as experimental but were missing the check in the codebase.git::andoci::entries intask_config.includes. These are skipped with a warning.mise runwhen an OTLP endpoint is set.spinel:tools.mise.local.tomlnow overridesmise.<env>.tomlin the same directory, as the docs already said. Before, the committed environment file won in project directories, and also in~/.config/misewhen the walk up from the cwd reached it. Within each directory the order is now, highest first:mise.<env>.local.toml,mise.local.toml,mise.<env>.toml,mise.toml. If you relied on the environment file winning, move those keys intomise.<env>.local.toml. #14148mise://tasksresource,envis now an array of env directive strings, the same format asmise tasks ls --json. It was always an empty object before. #14111mise settings setandaddrefuse writes that would have no effect. This covers early-init settings (env,ceiling_paths,env_conf_d, ...) written to a config file, and global-only settings (yes,paranoid,trusted_config_paths, ...) written with--local. The error says where the setting has to go:miserc.toml, the global config, or theMISE_*variable. #14126Added
Dotfiles
variants = [{ machine = true }]ormise dot track --machineto keep a separate history for each machine. Sync pushes every machine's version to the origin but never applies one machine's version on another. Each machine gets a generated name, which you can set with[history] machine = "desk". A machine variant must be the entry's only variant and can't be combined withencrypt. Upgrade every machine that shares a setup before using it. #14062mode = "track-local"(ormise dot track --local) keeps a file's history in a separate store on this machine, with no origin. The file never reaches the shared manifest, a commit or a push. Commands that name a path use the history that holds it. Usemise dot --local historyormise dot --local undoto work with the local history directly.save,captureandwatchcover both histories. #14082merge = "missing"sets only the keys the target file doesn't have yet. Values an app writes itself, such as the model picked with/modelin Codex or Claude Code, are left alone. Works with TOML, YAML and JSON. #14081source. mise then reads the target's path underdotfiles.root. Switching an entry fromsymlinktomergenow replaces a link that points at the merge source with a writable copy, so the app's own keys survive. #14076mise dot syncrefuses to publish saved versions that look like secrets. It checks for provider tokens, private key blocks, and*_KEY/*_TOKEN/*_SECRET/*_PASSWORDassignments. Only versions the origin doesn't have yet are checked. The error names the file, line and version, never the value.--allow-plaintext-historyskips the check. #14171mise bootstrap --adopt <url> --take-remote-alltakes the repository's version of every file that differs, in one step. Combined with--replace-history, it also adopts the repository on a machine that already has history of its own. #14065mise doctorshows the dotfiles history repo path and the connected origin (URL, branch, sync mode), in both text and--jsonoutput. #14173Bootstrap
[bootstrap.files]and[bootstrap.directories]accept the sameosselector as packages. Entries that don't match the host are skipped completely. #14058fish = "auto"in[bootstrap.mise_shell_activate]writes a block that runsmise activate fishin interactive shells and--shimseverywhere else. #14172[bootstrap]is now allowed in config includes. It merges below the including file, so a shared baseline can declare packages, hooks and services, and the project still wins on any key it sets itself. #14176state = "absent", which stops, disables and deletes the matching mise-managed service and timer.mise bootstrap unapplynow also removes the units an environment added. #14139Tools and backends
workflowoption. It accepts only releases signed by the named GitHub Actions workflow on tags. It takes one workflow or a list, and an entry can name a ref (release.yml@refs/heads/main). It can't be combined withpubkey,identity,identity_prefixorissuer. #14075, #14093workfloworpubkeyyou set yourself replaces the registry pin. #14092, #14091, #14073 (@max-sixty)install_toolis implemented. It installs the requested version, or the configured version, or latest, and returns the resolved version and install path.install_toolandrun_tasknow refuse to act on untrusted config instead of trusting it on the client's behalf. #14111mise installs migrateno longer fails on installs it can't reinstall, such as withdrawn releases, signer changes or no network. It moves them into the identity layout as they are and leaves a link at the old path. It also handles lockfile-suffixed~aube~/~uv~directories correctly. #14079mprocsis renamed todekitto match upstream, andmprocsstays as an alias. From v0.10.0 the binary isdekit. #14169Changed
dot pull,dot track,undo,rollback,connectandbootstrap --adopt. Destructive ones still ask, such as--replace-history,dot recover --keep-currentandimplode.--yesandMISE_YESare still accepted. #14077, #14071, #14067MISE_SAFE=1) now ignores a project's[bootstrap],[dotfiles]and[dotfile_groups]. Before, an untrusted repo could link files into$HOMEor clone repositories. Global and system config still apply. #141102were checked. Setnode.gpg_verify = falsefor mirrors without signatures. #14132mise generate github-actionnow usesactions/checkout@v7andjdx/mise-action@v5and no longer setsMISE_EXPERIMENTAL.mise generate devcontainernow adds"postCreateCommand": "mise install". #14145Deprecated
task.cache.stats_report,sops.age_recipientsandplugin_autoupdate_last_check_durationnever had any effect. Setting one now prints a warning, and they will be removed in 2027.10.5. #14112mise bootstrap launchd|systemd|macos-defaults, the old--only/--skippart names (launchd,systemd,defaults,shell) andmise direnvnow print a warning that names the replacement. They will be removed in 2027.10.4. #14113Fixed
Tasks
cacheenabled is now skipped when its sources are fresh and its cache key hasn't changed. Before, it ran every time. #14121sourcesthat matches no files now prints a warning.mise tasks deps <task>now showsdepends_posttasks. Scripts in$MISE_CONFIG_DIR/tasksload even without a global config file. #14122mise run ./scriptresolves relative to the current directory. #14120mise generate task-stubsskips hidden and global tasks. #14127Shims and exec
mise xandmise envno longer look up remote versions for lazy tools that aren't installed. With 20 lazy tools and no network, running an installed tool went from about 42s to 0.09s. #14063mise x tool@1.2.3installs the exact version when the version list times out, instead of failing with "couldn't exec process". #14164mise doctorrecognizes amiseentry in the dedicated shims dir. #14069Config, settings and CLI
config.tomlyet,mise use -gcreatesconfig.tomlinstead of writing intoconfig.<env>.toml. #14179mise config set --type booland boolean settings acceptyes/no/1/0. Forenv.*and other keys that aren't settings, onlytrueandfalsebecome booleans, and anything else is stored as written.mise latest tool@prefix:Xworks, and--log-level warnis accepted.mise doctorprints the full chain when config fails to load. #14125mise editno longer overwrites an existing config when there is no terminal. #14124.monorepomarkers are verified in paranoid mode. #14105mise config lsandmise prunewith an invalid tool version, the--monorepoflags, andmise plugins uninstall --purge. #14118, #14094 (@JamBalaya56562), #14103 (@JamBalaya56562), #14116, #14117mise env --redactedhonorsredact = falseexclusions.watch_fileshooks don't run in safe mode or with--no-hooks. #14109, #14108mise watchpasses watchexec flags through to watchexec. #14115bootstrap remoteand the watchexec install hint. #14142<temp>/mise-tmp, somise cache clearno longer deletes files that are still in use. #14134Bootstrap and dotfiles
mise bootstrapkeeps writing the shell activation block into a startup file that is only tracked. #14135exec(). #14136mise dot undorestores them.--replace-historyno longer fails on its first attempt. #14065mise dot pullsays so when incoming history changes no files on this machine. #14066Backends and plugins
mise install cargo:...no longer uses an inactivecargo-binstallshim. It falls back to native binstall orcargo install. #14070npm.shell_out, a mise shim from another data dir can no longer be run asnpmand fork until the machine runs out of memory. #14084 (originally found and fixed by @tfournet)java.shorthand_vendortakes effect without waiting for the cache to expire. Inlinejava[release_type=ea]is respected when listing and resolving versions. #14131{os}and{arch}correctly. #14133ls-remoterespectsdisable_backends. #14130api_urlfor cloning and skips lockfile URLs. #14129git::plugins install from a subdirectory, and[plugins]entries compare those sources correctly. Packslip entries in[plugins]install as vfox plugins. #14140, #14150 (@onokonem), #14141Daemons and sandbox
--deny-envclears inherited variables on Windows. On macOS,allow_netis rejected instead of writing invalid sandbox rules. #14107, #14106Security
[vars]and task arg values asblake3:digests instead of plaintext, so secret values are no longer uploaded. Existing cache entries miss once after upgrading. #14104Documentation
New Contributors
Full Changelog: jdx/mise@vfox-v2026.10.4...v2026.10.5
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.