Skip to content

deps: update github actions - #1487

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending
codecov/codecov-action (changelog) action digest fb8b358 → 303a32d
jdx/mise uses-with patch 2026.9.11 → 2026.9.13 v2026.9.17 (+3)
jdx/mise-action (changelog) action digest 9e7f763 → c2a8761

Release Notes

jdx/mise (jdx/mise)

v2026.9.13: : OpenTelemetry for tasks, shared daemon providers, mise backends switch, and declarative dotfile removal

Compare Source

mise run can now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the new mise backends switch command does it when you ask. [dotfiles] and [bootstrap.files] can now remove files and manage permissions, and mise bootstrap unapply removes what a module set up. The experimental pkgx: backend has been removed.

Highlights
  • Observability and shared services (experimental): task runs export OTLP traces and, if you opt in, task output as logs. Global [daemon_providers] run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout.
  • Safer lockfiles: locked tools stay on their locked backend, mise lock --bump checks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project's mise.lock.
  • Declarative cleanup: mode = "absent", remove_empty templates, permissions-only entries, removal of empty directories mise created, and mise bootstrap unapply let a config describe what should not be on a machine.
Added
Tasks
  • OpenTelemetry export for mise run (experimental). Each run becomes one trace, with a span per task (grouped by monorepo package) that carries its exit code and redacted args. W3C TRACEPARENT is read from the environment and passed to each task, so nested mise run calls and instrumented tools appear in the same trace. Nothing is exported unless otel.enabled = true and an OTLP endpoint is set. Offline mode disables export, and each export times out after 3s by default. A separate otel.logs = true setting exports task stdout (INFO) and stderr (WARN) as log records linked to their spans, with redactions applied first. With otel.logs on, tasks in interleave/quiet modes no longer get a TTY; use --raw for tasks that need one. #​13557, #​13558, #​13559 (built on work by @​MatthiasGrandl and @​zeitlinger)

    [settings]
    otel.enabled = true
    otel.logs = true   # optional; exports task output too
    export OTEL_EXPORTER_OTLP_ENDPOINT=<your OTLP/HTTP collector URL>
    mise run build ::: test
Daemons (experimental)
  • Shared server providers. Declare long-lived PostgreSQL, CockroachDB, or NATS servers in global config under [daemon_providers] and manage them with mise daemons providers ls|start|stop|restart. Providers have their own tools, ports, and persistent data. They run in an isolated environment and are not tied to any checkout. #​13534

  • Per-checkout databases and accounts on a shared server. A project daemon with provider = "..." gets its own database (PostgreSQL/CockroachDB) or its own NATS account with separate subjects and JetStream data. Each checkout path gets a stable name, so worktrees share the server but not the data. Give several daemons the same resource name to share data on purpose. Connection env vars point at the right database, and NATS gets an authenticated NATS_URL. #​13536, #​13537

    # ~/.config/mise/config.toml
    [daemon_providers.local-postgres]
    preset = "postgres"
    version = "18"
    port = "auto"
    
    # project mise.toml
    [daemons.db]
    provider = "local-postgres"
    # resource = "shared_app"   # opt in to sharing data
Lockfiles and backends
  • mise backends switch. When the registry moves a tool to a new backend (as happened with hk and communique moving to packslip:), a tool locked to the old backend now stays there. mise install and mise lock print a warning that points to the new command, which moves lock entries to the registry's backend at the same versions, relocks their platforms, and reinstalls. It supports --dry-run, --global, and TOOL@VERSION. If any relock fails, every lockfile it changed is restored. #​13543

  • Tool stubs lock into the project's mise.lock. mise generate tool-stub --lock now records the stub in the nearest project lockfile (listed under tool-stubs), so installs verify the recorded checksums and --locked/MISE_LOCKED=1 accept stubs. Previously the [lock] section written into the stub was never used, so checksums were never checked. #​13502

  • Install from a local archive. The http: backend accepts file:// URLs. It copies the archive instead of downloading it, still verifies checksum, and works offline. #​13574

    [tools]
    "http:my-tool" = { version = "1.0.0", url = "file:///opt/archives/my-tool-v1.0.0-linux-x64.tar.gz", checksum = "sha256:..." }
  • Checksum mismatch hints for re-uploaded GitHub assets. When a github: or aqua: install fails a checksum check, mise asks GitHub for the asset's current digest. If that digest matches the download, the error says the maintainer probably re-uploaded the asset. The install still fails. #​13512

  • vfox BackendUninstall hook. Backend plugins can define hooks/backend_uninstall.lua to clean up outside the install directory. It runs before removal on uninstall, upgrade, and prune. If the hook errors, the install directory is kept. #​13522

CLI
  • mise search checks package registries. Add a prefix to search npm, crates.io, RubyGems, or NuGet (mise search npm:typescript-language, cargo:, gem:, dotnet:). --all searches every source at once. Plain searches and shell completion still make no registry requests, and MISE_OFFLINE=1 skips them. #​13550
  • mise ls by backend. -b/--backend (repeatable) filters by backend and also works with --json. --grouped prints one section per backend. #​13530
  • Key completion for mise config get/set. Tab completes dotted keys, with descriptions, from the schema and from the target file. --file, --global, and --system are respected. #​13551
  • Coloured help and a logo. mise --help is now coloured on terminals (and respects NO_COLOR), wraps at the terminal's real width, and shows the mise logo on mise/mise --help when there's room. #​13449
  • Project URLs in the registry. Registry entries can set a url, which appears in mise tool (and mise tool <name> --url) and in mise registry --json. #​13533
Configuration and hooks
  • .miserc.local.toml. Sets per-checkout early config, such as env = ["native"], without editing the shared .miserc.toml. At each directory level it is read before .miserc.toml. CLI flags and MISE_ENV still take precedence. #​13440
  • backend and install_path in MISE_INSTALLED_TOOLS. Postinstall hooks can now see where each tool came from and exactly where it was installed. #​13421 (@​garysassano)
  • A configured pnpm overrides Node's bundled pnpm, whichever order the tools are listed in. #​13498 (@​EMcCormack)
Dotfiles
  • Choose what a tracked directory saves. exclude and include lists on mode = "track" entries. Exclusions always win. include = [] selects nothing. Narrowing a list does not delete the files on other machines. #​13418, #​13432

    [dotfiles]
    "~/.codex" = { mode = "track", include = ["config.toml", "rules/**"], exclude = ["*.log"] }
  • Preview before tracking. mise dot track --dry-run and mise dot paths --preview show file counts, sizes, exclusions, and skipped nested repositories. Large trees get a warning. #​13417

  • mode = "absent" removes a file or symlink at the target, with support for OS variants. Directories and special files are refused, even with --force. #​13513

  • permissions key. Overrides the mode of copy, template, and content entries, or manages only the permissions of an existing file such as ~/.ssh/config. Status, diff, and apply report and fix drift. The key is ignored on Windows. #​13514

  • remove_empty = true on templates removes the target when the template renders empty. A file you have edited since mise last wrote it is kept unless you pass --force. #​13515

  • Empty parent directories mise created are removed along with their target on apply and unapply. This only applies inside $HOME and never to directories that already existed. #​13518

  • Warnings from background captures, such as credential-named files saved in plaintext, are now shown by the next mise dot command or mise bootstrap. Previously they only went to the watcher logs. #​13483

Bootstrap
  • mise bootstrap unapply <ENV>... removes the files, directories, user services, and dotfile entries a module added after you deselect it. Anything another environment still declares is kept. Supports --dry-run and --force. #​13441
  • Permissions-only [bootstrap.files] entries. Declare only mode/owner/group to manage a file's metadata without taking over its contents. #​13511
  • remove_empty = true on templated [bootstrap.files] removes the target when the template renders empty. #​13510
  • More systemd directives: before, binds_to, part_of, conflicts, exec_start_pre, exec_start_post, and exec_stop_post. ~ now expands after exec prefixes such as -~/bin/check. #​13526
Registry
Fixed
Tools, installs, and lockfiles
  • mise cache prune could delete files from installed tools: it followed symlinks out of the cache into install directories and left npm cache entries half-empty. It now never follows symlinks and removes stale entries as a whole. cache_prune_age = "0s" now also turns off mise cache prune. #​13424
  • mise lock --bump now checks remote versions for every selector (for example "6", not only latest) and fails when the version list can't be fetched, where it used to exit 0 with stale versions. Packslip registry tools no longer call api.github.com in normal use, which avoids rate-limit errors. #​13544
  • mise lock refuses to record an aqua version that only resolved to its own request string because the version list failed to load. When such an install fails, the error now says why. #​13552
  • mise lock --global no longer skips global tools that the project config shadows, and no longer overwrites a global pin with the project's version. #​13547
  • mise lock no longer tries to lock 3.9.6~aube~<digest>-style install directory names for npm and pipx tools. #​13542
  • mise upgrade --bump tool@selector now saves the selector to the config, as mise use does. #​13179 (@​zeitlinger)
  • npm packages whose lifecycle scripts call back into the package manager through npm_execpath (such as re2) now run through aube, not mise's task runner. #​13484
  • Command wrappers such as [wrappers.cargo] command = "mbx" now install the missing provider tool before running it. #​13532
  • A GitHub, GitLab, or Forgejo token containing a newline or other invalid header character now gives a redacted error, where mise used to crash. Tokens read from *_tokens.toml are trimmed. #​13488
  • .tar.zst archives compressed with a long window now extract. #​13566
  • aqua creates .mise-bins for registry files listed by name only (#​13525), and reports only the provenance and signature checks mise actually performs (#​13549).
  • Renaming a raw Windows download with bin keeps the .exe extension. #​13529
  • brew-cask percent-decodes artifact filenames taken from cask URLs. #​13431
  • mise self-update fails before downloading when it can't write to the install directory. #​13453
  • Per-tool progress bars line up in interactive installs. #​13494
Tasks
  • A metadata-only [tasks.hello] block no longer creates an empty task that hides mise-tasks/hello.sh. It now configures the script, and dependency groups keep their depends when another config layer adds metadata. #​13448
  • A run under a file task's name now replaces the script. #​13458 (see Breaking Changes)
  • Dependencies that use optional usage flags or args in templates are no longer dropped when those values are omitted. #​13569 (@​nettlesh)
  • When parallel tasks fail together, only the task that caused the stop prints its error chain. #​13556
Shell, CLI, and platforms
  • The bash mise function now embeds the path to the mise binary, so it keeps working in shells that copied the function but not $__MISE_EXE (for example Claude Code's Bash tool on Windows). #​13491
  • Windows release builds no longer abort with "panic in a function that cannot unwind" when a vfox plugin hits a Lua error. #​13503
  • cargo install mise for Windows targets works again. #​13573
  • Help and completion output exit quietly when the reader closes the pipe. #​13575, #​13527
Dotfiles, history, and bootstrap
  • On Windows, user services that set environment no longer run through cmd.exe behind a console window that killed the service when closed, and shell metacharacters in the environment are no longer rejected. The history watcher also runs without a console window. #​13429, #​13428
  • mise bootstrap now runs [history.reload] commands after its dotfiles phase writes matching files, as mise dot apply does. #​13509
  • Nested Git repositories inside tracked directories are skipped and reported, not saved as commit pointers. Track the repository's root directly to capture its files. #​13416
  • Global history exclusions apply consistently to tracked paths (#​13427), and files left out by credential filtering are reported (#​13415).
  • A postgres daemon that would start as root now fails early with a clear error. #​13567
Security
  • When [bootstrap.files] and [bootstrap.directories] changes run as root, mise no longer follows a symlink in the path that another user could have planted (CWE-59). Status and dry-run show these paths as unknown, and apply refuses them. Symlinks inside root-owned directories that no one else can write, such as /etc on macOS, still work. #​13539, #​13546
Breaking Changes
  • The experimental pkgx: backend is removed. Entries like "pkgx:stedolan.github.io/jq" no longer resolve; switch to the registry shorthand (jq) or aqua:/github:. Lockfiles with pkgx sections still load, and those sections are dropped the next time mise writes the file. The pkgx registry entry for the pkgx CLI itself is unchanged. #​13555
  • Locked tools keep their locked backend. A short-name tool no longer follows the registry to a new backend if mise.lock records a different one. Run mise backends switch to move it. #​13543
  • TOML commands replace file tasks. [tasks."hello.sh"] run = ... used to be ignored and now runs. [tasks.hello] run = ... no longer leaves hello.sh available as a separate task. To keep both, give the inline command its own name. #​13458
  • mise generate tool-stub --lock needs a project config above the stub. It writes to that project's mise.lock and no longer pins the stub's version. Any old [lock] section is ignored and removed. Older mise releases drop tool-stubs from mise.lock. #​13502
  • Dotfiles include/exclude need current mise on every machine. Upgrade every machine that shares the dotfiles setup before using include lists. New checkpoints use schema version 2, which older clients can't roll back. #​13432
  • Recursive [bootstrap.directories] removals always run as root, so a path that crosses a symlink in a user-writable directory is now refused, even under $HOME. Declare the resolved path instead. #​13546
New Contributors

Full Changelog: jdx/mise@v2026.9.12...v2026.9.13

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

v2026.9.12: : Tasks that require daemons, worktree-aware ports and URLs, Scoop and zypper packages, and official Docker images

Compare Source

The experimental [daemons] system grows substantially: tasks can declare the daemons they need, [daemon_groups] selects subsets of a project's services, port = "auto" and stable <NAME>_URL hostnames let several git worktrees run the same stack side by side, and CockroachDB, NATS, and SpiceDB join the PostgreSQL and Redis presets. Outside daemons, [bootstrap.packages] gains scoop: and zypper: managers, mise install --system elevates with sudo only for the final publish step, official mise images are published to GHCR and Docker Hub, and a run of brew-cask fixes lets many more casks install unattended.

Highlights

  • Daemons as part of the task graph (experimental): [tasks.x] daemons = [...] starts and waits for services before a task runs, daemons can run a mise task, [daemon_groups] and mise daemons start <group> select subsets, and mise daemons register, urls, and prune round out the lifecycle. Worktrees get deterministic ports, hostnames, and optionally checkout-local data_dir storage without hand-assigned numbers.
  • More host software from one config: Scoop on Windows and zypper on openSUSE/SLE join the bootstrap managers; brew-cask now picks the right build for the host macOS release, runs installers that need sudo, applies pkg installer choices and set_ownership steps, upgrades pkg-only self-updating casks, and survives DMGs with license prompts or unreadable metadata; brew: resolves formula aliases such as openssl.
  • Regressions and integrity fixes: enter hooks fire again when a shell starts inside a project, npm tools with only pre-releases resolve latest again, generated pre-push hooks no longer append git's arguments to the task command, and mise install refuses a lockfile entry whose download URL names a different release than its version. Lockfile sidecars now verify on Windows checkouts with CRLF line endings.

Added

  • daemons: Tasks can require daemons and daemons can run tasks. daemons = ["postgres", "nats"] (or true for all project daemons) on a task starts them via pitchfork, waits for readiness, and then runs the task; already-running daemons are left alone, and --skip-deps / --dry-run skip them. A daemon can declare task = "dev:core" with args instead of run, and init = [...] runs idempotent setup commands before the long-running process on every start. mise tasks info shows a task's daemons. (#​13340)

    [daemons]
    postgres = "18"
    
    [daemons.nats]
    run = "exec nats-server"
    ready_port = 4222
    
    [tasks.dev]
    daemons = ["postgres", "nats"]
    run = "npm run dev"
  • daemons: [daemon_groups] names project-scoped subsets of daemons; groups may nest other groups and work wherever a daemon name does, including --group. mise daemons start with no arguments now starts the default group when a project declares one, and every project daemon otherwise. (#​13347)

    [daemon_groups]
    default = ["postgres", "core", "node0"]
    two-cluster = ["default", "core2"]
  • daemons: A daemon entry with project = "../other-checkout" and optional name runs a daemon defined in another project under that project's tools, environment, and data, and can be used in depends. [daemons_settings] namespace = "services" gives daemons stable namespace/name IDs (with a per-worktree suffix unless namespace_per_worktree = false). Requires pitchfork 2.25.0 or later. (#​13339)

  • daemons: port = "auto" (or port = { auto = true, base = 3000, stride = 1 } for custom daemons) keeps the base port in the primary checkout and derives a deterministic offset in each linked git worktree. Resolved ports are exported before startup as PGPORT/DATABASE_URL for presets and <NAME>_PORT for custom daemons, and mise daemons ls --json reports port and port_auto. mise does not fall back to another port; startup diagnoses conflicts with running mise-managed daemons in other projects, and two daemons in one project claiming the same port now fail at config load. (#​13342)

  • daemons: Every daemon with a port gets a stable hostname served by pitchfork's reverse proxy, exported as <NAME>_URL (for example api.shop.localhost in the primary checkout, or api.shop-pr-42.shop.localhost in a linked worktree). Per-daemon proxy (a label, true, or false) and proxy_tls ("terminate" or "passthrough") control routing; the postgres and redis presets opt out. mise daemons urls lists hostnames, ports, proxy modes, and status. Set proxy = false on custom daemons that do not speak HTTP. (#​13368)

  • daemons: CockroachDB (preset = "cockroachdb"), NATS ("nats"), and SpiceDB ("spicedb") presets install the tool, initialize data, wait for readiness, and export DATABASE_URL, NATS_URL, SPICEDB_ENDPOINT, and SPICEDB_PRESHARED_KEY. Presets now support named-port overrides such as ports.http_port = 8081 and typed options. Unix-only; NATS and SpiceDB readiness checks need curl. (#​13346)

  • daemons: mise daemons register installs missing tools, validates the daemon graph, and registers pitchfork configuration without starting anything, so a fresh checkout can start on its first hostname request. (#​13399)

  • daemons: mise daemons prune finds daemon state left behind by deleted projects and worktrees, shows paths and sizes, and removes it after confirmation (--dry-run previews, --yes confirms ordinary cases). mise daemons ls --json adds root, state_dir, data_size, and data_size_human. (#​13338)

  • daemons: data_dir = ".data/postgres" keeps a preset's persistent data inside the checkout (relative to the project root; absolute and ~/ paths also work), so each worktree gets its own database. Changing the path does not move existing data. (#​13408)

  • bootstrap: A scoop manager for Windows. "scoop:extras/vscode" = "latest" adds the bucket if missing, pinned versions install via app@version, state = "absent" uninstalls, and --update opts in to scoop update. Only user-scope installs are managed; entries are skipped on other platforms. (#​13324)

  • bootstrap: A zypper manager for openSUSE and SUSE Linux Enterprise, supporting status, install, name=version pins (including downgrades), upgrade, and removal, with retries when zypper asks for a package-manager restart. (#​13335, @​m407)

  • bootstrap: process_type on [bootstrap.macos.launchd.agents.*] maps to launchd's ProcessType (Background, Standard, Adaptive, Interactive); misspellings are rejected at config time instead of being silently ignored by launchd. (#​13402, @​waynehoover)

  • install: mise install --system on Unix downloads, verifies, and unpacks as the invoking user, then uses sudo only to publish into the system install and shim directories. Supports relocatable tools from aqua, github, gitlab, forgejo, http, and s3 without a tool-level postinstall; system_packages.sudo = false disables elevation. (#​13384)

  • docker: Official release images at ghcr.io/jdx/mise and jdxcode/mise for linux/amd64 and linux/arm64, built from the minisign-verified release binaries. Tags 2026.9.12, 2026.9, and latest are a scratch image for COPY --from=; *-debian and debian are a Debian slim base with curl and git. (#​13413)

    FROM debian:13-slim
    COPY --from=ghcr.io/jdx/mise:2026.9.12 /usr/local/bin/mise /usr/local/bin/mise
  • config: unix is accepted as an os selector in [tools], [bootstrap.packages], [doctor.checks], and [dotfiles] variants, matching every non-Windows platform. A concrete OS variant still wins over a unix one. (#​13395)

  • go: With go in idiomatic_version_file_enable_tools, the toolchain line of an active go.work selects the Go version and, as with the go command, member go.mod files are ignored in workspace mode. GOWORK (auto, off, or an absolute path) is honored. (#​13337)

  • bazel: .bazelversion is an idiomatic version file for bazel when enabled; only concrete releases are read, so latest, last_green, 8.x, and commit hashes select nothing rather than failing. (#​13336)

  • tasks: File-task #USAGE include file="..." paths may be relative to the task file or use environment variables such as $MISE_CONFIG_ROOT, $MISE_TASK_DIR, and $MISE_PROJECT_ROOT, so shared flagsets no longer need absolute paths. (#​13372)

  • dotfiles: mise dot apply now runs matching [history.reload] commands for the targets it actually wrote, once each after all writes; --dry-run and no-op applies run none. (#​13414)

  • registry: Added codegraph (aqua:colbymchenry/codegraph). (#​13355, @​3w36zj6)

Fixed

  • activate: Starting a shell inside a trusted project runs its enter hook again; a regression in 2026.9.x had limited it to cd into the project. (#​13383)
  • npm: A tool that publishes only pre-releases (such as @deepseek-ai/dsh) is no longer reported missing after mise use npm:...@latest; latest falls back to the newest installed pre-release when no stable version is installed. (#​13390)
  • npm: On a shared Linux machine, users other than the first to install an npm: tool no longer fail with failed to acquire project lock: Permission denied. (#​13379)
  • generate: mise generate git-pre-commit hooks pass only the message file ("$1") for commit-msg, prepare-commit-msg, applypatch-msg, and sendemail-validate, and no arguments for other hooks, so a pre-push task no longer runs npm test origin <url>. Existing hooks change when regenerated. (#​13377)
  • lockfile: mise install fails before downloading when a locked platform URL provably names a different release than the entry's version (for example after a tool bumped version in mise.lock without refreshing the platform block, or a release dropped a platform). mise lock still repairs the entry. (#​13401)
  • lockfile: Dependency sidecars under .mise/locks/ verify on Windows checkouts where git rewrote them to CRLF, digests recorded from CRLF bytes by older versions keep working and heal on the next ordinary install, and a relocated sidecar is pinned to the bytes actually written. Repositories can drop .mise/locks/** -text workarounds. (#​13398, #​13403, #​13407)
  • brew-cask: Installs the variations entry Homebrew publishes for the host macOS release instead of always the newest release's build (Raycast on Sequoia now gets 1.104.x, not the Tahoe-only 2.x), and reports not available for this platform for null variations. (#​13376)
  • brew-cask: Installer scripts that declare sudo: true (such as logi-options+) run through mise's sudo path, and $HOMEBREW_PREFIX/$APPDIR placeholders in installer paths and arguments are expanded. (#​13380)
  • brew-cask: Casks with pkg installer choices (microsoft-outlook, microsoft-teams) install via installer -applyChoiceChangesXML; casks whose flight steps use set_ownership (parsec) install; and mise bootstrap packages upgrade handles self-updating casks that install only from a .pkg (tailscale-app, karabiner-elements) by comparing pkgutil receipt versions. (#​13385, #​13386, #​13387)
  • brew-cask: Third-party casks evaluated from Ruby can use staged_path, unblocking casks such as AeroSpace. (#​13369, @​soodoh)
  • install: DMGs with an embedded license agreement no longer stall at hdiutil's Agree Y/N? prompt, and DMGs with unreadable root metadata such as .Trashes (for example mysqlworkbench) extract instead of failing with Permission denied. Applies to brew-cask, macos-app, and aqua DMG downloads. (#​13353, @​hisaac; #​13378)
  • brew: Formula aliases and old names (openssl -> openssl@3, act_runner -> gitea-runner) resolve for brew: packages and tap formula dependencies instead of failing with a 404; mise warns to use the canonical name so status can track it. (#​13382)
  • bootstrap: Two spellings of one WinGet or Scoop package (winget:Git.Git and winget:git.git) that disagree on state or version are rejected with both names, instead of converging differently per machine. Entries kept apart by os or env selectors are not compared. (#​13334)
  • github: The GitHub token is sent to raw.githubusercontent.com, so private Homebrew taps resolve. (#​13345, @​waynehoover)
  • github: {{ version }} in platforms.<target>.url is rendered with the resolved version for the GitHub, GitLab, and Forgejo backends, so versioned source archives can follow latest. (#​13359, @​casparbreloh)
  • go: Version discovery for modules with hundreds of releases no longer times out with No versions found; latest resolves directly through the module proxy or go list, and release dates are fetched only for the newest versions. minimum_release_age stays exact by dating individual undated candidates on demand. (#​13362, #​13364)
  • tasks: mise tasks validate recognizes child monorepo task references such as depends = ["//crates/gui:dev"] in depends, depends_post, wait_for, and structured run. (#​13373, @​nettlesh)
  • daemons: ready_cmd and health_cmd probes run in the owning project's mise environment, so a supervisor shared by several worktrees no longer probes one checkout with another's API_PORT. (#​13396)
  • dotfiles: mise dot edit opens tracked files (mode = "track") in place and inline content entries in their declaring config, instead of failing with No such file or directory; it warns when editing a tracked symlink whose destination history does not capture. (#​13332)
  • history: Checkpoints record the non-default mode of directories containing tracked files, so a 0700 ~/.claude holding a tracked settings.json is recreated private on a new machine rather than 0755. (#​13412)
  • history: The "histories are unrelated" refusal from mise dot origin set and mise dot sync now names the commands for each way out. (#​13411)

Documentation

  • New "Set up a development stack" guide covering project daemons, worktree isolation, imports, registration, and idle shutdown. (#​13389)
  • Task templates guide documents Tera v2 components for repeated parameterized snippets inside a run script. (#​13388)
  • miser.nvim added to the IDE integration page. (#​13406, @​carldaws)
  • Bootstrap package conflict guidance shortened and corrected. (#​13341)

Breaking Changes

  • Docker latest tag: ghcr.io/jdx/mise:latest and jdxcode/mise:latest are now the scratch image (static binary and CA certificates, no shell). CI and dev-container users should switch to the debian tag and install their tools explicitly; the previous source-built image remains under the unsupported dev tag. (#​13413)
  • Lockfile version/URL mismatch: Lockfiles whose version disagrees with a platform URL now fail mise install instead of silently installing the wrong release. Run mise lock to regenerate the entry. (#​13401)
  • Generated git hooks: After regenerating with mise generate git-pre-commit, non-message hooks no longer receive git's arguments. To keep them, edit the hook to use "$@" and declare the arguments with usage. (#​13377)
  • Bootstrap package spellings: Configs declaring one WinGet or Scoop package under two spellings with conflicting state or version are rejected; delete one entry. (#​13334)
  • Daemons (experimental): mise daemons start with no arguments starts only the default group when one is declared; a project with two daemons resolving to the same port fails to load; custom daemons with a port now export <NAME>_PORT and <NAME>_URL, so set proxy = false on non-HTTP daemons. (#​13347, #​13342, #​13368)

New Contributors

Full Changelog: jdx/mise@v2026.9.11...v2026.9.12

💚 Sponsor mise

mise is built and maintained by @​jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • On day 15 of the month (* * 15 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 15, 2026 03:28
@renovate
renovate Bot force-pushed the renovate/github-actions branch 8 times, most recently from bba386b to 0011f9b Compare September 23, 2026 01:44
@renovate
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from 2430beb to 087ced9 Compare September 25, 2026 18:48
@renovate
renovate Bot force-pushed the renovate/github-actions branch from 087ced9 to a79fb7f Compare September 29, 2026 20:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants