Update dependency jdx/mise to v2026.9.9 - #495
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
from
September 17, 2026 19:54
2afa3b3 to
3070c2c
Compare
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
from
September 18, 2026 09:07
3070c2c to
a15b8f7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.9.6→2026.9.9v2026.9.11(+1)Release Notes
jdx/mise (jdx/mise)
v2026.9.9: : Dotfiles false-deletion fix, encryptedmise dot track, semantic uv options for PyPI toolsCompare Source
The dotfiles history watcher no longer records files as deleted when a checkpoint and a sync compose snapshots at the same time,
mise dot track --encryptenrolls a file with encrypted history from its first checkpoint,mise bootstrap --adopt --replace-historydiscards unrelated local history in one shot, andpypi:tools gain lock-awarewith,expose, anddependency_prereleasesoptions. Also fixed:packslip:installs from private GitHub repositories, stale history watchers after upgrading, global npm tools being reinstalled underlockfile = true, and the--separator in activated PowerShell sessions.Added
dotfiles:
mise dot track --encryptwritesencrypt = trueinto the tracked declaration and encrypts the initial baseline checkpoint, for files that must never have plaintext history.[history.encryption].recipientsmust be configured first; if the encrypted baseline cannot be saved, enrollment fails closed and rolls back the declaration without committing history metadata. Run it as a standalone command rather than insidemise dot capture. Enabling encryption on a file that already has plaintext history does not rewrite that history. (#13180 by @jdx)mise dot track ~/.config/app/credentials --encryptbootstrap: Fresh
mise bootstrap --adoptnow compares existing live files against the incoming setup before creating any local history, so identical files adopt the origin's history instead of being rejected as an unrelated root (for example right after the history store was removed). Differences still pause for an explicit decision. For machines that genuinely hold unrelated local history,--replace-historydiscards it and adopts the setup repository's branch in one shot;--dry-runpreviews the local and origin commits, and a failed replacement restores the previous branch and sync state. Ordinary sync never replaces divergent history and there is no persistent force setting. (#13182 by @jdx)pypi: Three new tool options express common uv install behavior without opaque
uvx_args, and unlike free-form arguments they participate in dependency graph locking:withinstalls extra requirements,exposeinstalls extra requirements and links their executables (requires uv 0.8.5 or newer), anddependency_prereleasessets uv's prerelease policy (disallow,allow,if-necessary,explicit). Setting any of them selects uv as the installer.uvx_argsandpipx_argsremain available as version-only escape hatches. The Ansible and Azure CLI registry entries now use these options by default; if you force pipx for one of them, clear the default with an empty list, e.g."pypi:ansible" = { version = "latest", uvx = false, expose = [], pipx_args = "--include-deps" }. (#13181 by @jdx)registry: Added
nubr(npm:@nubjs/runner), the Nub project's TypeScript runner for a file,package.jsonscript, or installed bin on plain Node. (#13191 by @colinhacks)Fixed
history.sync = "sync"and a running watcher, a checkpoint could record a sorted prefix of tracked files as deleted even though they were untouched on disk; those deletions then synced to other machines and removed their copies. Two compositions in one process (the watcher's checkpoint and the sync it started) shared a single scratch git index, and one resetting it mid-flight truncated the other's tree. Each composition now uses its own scratch index, and indexes left by killed processes are swept. Files recorded as falsely deleted are still in history and can be restored from an earlier checkpoint. (#13195 by @jdx)$MISE_STATE_DIR/history/), or started with a differentMISE_STATE_DIRthan the shell, kept running the old process without watching the current store, whilemise bootstrap services applyconsidered the unchanged service converged and skipped it.services applynow restarts ahistory-watchservice whose process is not watching this store, andmise doctorandmise dot statusreport "running but not watching this store" instead of "not running" (service-not-watchinginmise dot status --json). Users already in this state are recovered by runningmise bootstrap services apply. (#13190 by @jdx)lockfile = truein effect, an npm tool pinned in the global config was resolved with a graph-specific install identity that no automatic flow could persist, so everymise exectreated the installed tool as unsatisfied, re-ran an install pass, and warned that it was missing. Global requests now stay version-only unless resolved from an explicitly generated revision 2 global lockfile; opt in withmise lock --global. (#13186 by @jdx)404 Not Foundon the manifest because GitHub only serves private release assets through its API, not thereleases/download/URLs a packslip records. mise now falls back to the API asset endpoint using the same credentials as thegithub:backend (MISE_GITHUB_TOKEN,GITHUB_API_TOKEN, orGITHUB_TOKEN) with no configuration changes; signature, identity, digest, and size verification are unchanged. Tags containing/(such as@biomejs/biome@2.5.2or monorepotool/v1.0.0tags) and#are also resolved correctly now. Non-GitHub hosts and GitHub Enterprise are not covered. (#13188 by @jdx)mise activate pwsh,mise exec -- pnpm --versionfailed withunexpected argument '--version'because PowerShell's parameter binder removes the first bare--before themisewrapper function sees its arguments. The wrapper now recovers the separator from the raw invocation line, fixingmise exec/mise x,mise tasks add,mise dotfiles capture,mise oci run,mise generate git-pre-commit, andmise bootstrap;mise runwas not affected. Open sessions pick up the fix the next timemise activate pwshruns (normally at shell start). The doubledmise exec -- -- cmdworkaround now fails in an activated shell, as it always did without activation, so drop back to a single--. (#13202 by @jdx)dbt-fusioninstall test now expectsdbt <version>, matching whatdbt --versionactually prints. (873c400 by @jdx)Documentation
Full Changelog: jdx/mise@v2026.9.8...v2026.9.9
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.8: : Top-levelmise dotcommand, faster brew bootstrap installs, and npm safety-check fixesCompare Source
Dotfile management moves to the top level as
mise dot, Homebrew bootstrap installs run their download, extraction, and linking stages concurrently, and several install paths are corrected: embedded aube reputation gates now report the real reason and honor--yes, PyPI tools fall back to version-only installs when a dependency graph cannot be built, lazy tools no longer triggermissing:warnings, and lockfiles no longer resurrect disabled backends.Added
dotfiles: The full dotfiles command tree is now available as
mise dotfiles, withmise dotas a short alias.mise bootstrap dotfilesremains supported and all three spellings share the same behavior, including bootstrap hooks aroundapply. Generated history-watch services now invokemise dot watch. (#13158 by @jdx)dotfiles: Enabling encryption on a file that was previously saved in plaintext left older commits that blocked sync.
mise dot sync --allow-plaintext-historylets that history reach the origin for one run, and the global-only settingsettings.history.allow_plaintext_history = true(defaultfalse, envMISE_HISTORY_ALLOW_PLAINTEXT_HISTORY) does the same for sync, publish, the history watcher, and incoming history on pull. New saves still follow the file's encryption policy; the history guide also documents how to remove the old commits instead. (#13175 by @jdx)registry: Added
poppler(conda:poppler), providingpdftotext,pdfinfo,pdftoppm,pdftocairo,pdfunite, and the other Poppler PDF utilities. (#13133 by @i-api)Fixed
user aborted mise adderror when stdin is closed or no terminal is attached. Non-interactive installs now report the measured signal (for example 569 weekly downloads against the 1000 threshold) and suggest the mise-native fix,allow_low_downloads = trueon the tool; an explicit "no" reportsuser declined to add <package>. An explicit CLI--yesnow reaches the aube prompt and approves it, including auto-installs throughuse,exec,run,shell, andupgrade; CI mode and a configuredyes = truesetting alone do not approve reputation gates. (#13123 by @jdx)mise installofpypi:/pipx:tools no longer fails when a uv dependency graph cannot represent the package or its configuration, such as a source-only dependency or free-formuvx_args/pipx_args. mise warns and falls back to the version-only install path, reusing an existing version-only installation on later runs.mise lockandmise install --lockedremain strict and still reject unsupported arguments or dependencies without usable wheels. (#13170 by @jdx)lazy = trueare no longer reported asmissing: <tool>when entering a project or running a baremise install, regardless ofstatus.missing_tools; ordinary missing tools are still reported as before. (#13169 by @jdx)disable_backends. When a parentmise.lockpins a shorthand such asyarntoasdf:yarnand a child project disables asdf,mise tool yarn --backendand a fresh childmise locknow select the first enabled recorded backend or fall back to the enabled registry backend (aqua:yarnpkg/berry) instead of the disabled pin. The parent lockfile is left unchanged and explicitly installing a disabled backend still fails. (#13178 by @jdx)Changed
mise bootstrap packages applyinstalls Homebrew packages substantially faster. Formula metadata for each dependency frontier is fetched concurrently, bottles are extracted, relocated, signed, and receipted concurrently, and each job now downloads and prepares its own bottle so prepared bottles are committed as soon as dependency order allows. All stages respect the existingjobslimit with no new settings; Cellar commits and prefix linking stay dependency-ordered,opt/<name>is linked last so an interrupted install cannot look complete, and a failure cancels queued work while cleaning up in-flight staging. On Apple silicon, a fresh install ofbrew:jq brew:tree brew:wget brew:just brew:shellcheckdropped from roughly 6.6s to 4.0s, and dependency resolution forbrew:ffmpegfrom 288ms to 112ms. (#13151, #13152, #13155 by @jdx)Documentation
mise.lockguides now open with quick-start and everyday workflows (mise use node@24 npm:prettier,mise use python@3.14 uv pypi:black,mise lock,mise install --locked) and group dependency-graph locking, sidecar management, and strict-mode details afterward. The lockfile guide clarifies that URL-lock exemptions do not exempt dependency graphs from validation. (#13149 by @jdx)Full Changelog: jdx/mise@v2026.9.7...v2026.9.8
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
v2026.9.7: : Lockfile revision 2 with npm and Python dependency graphs, dotfile conflict inspectionCompare Source
This release introduces
mise.lockrevision 2, which records complete transitive dependency graphs for npm tools (via embedded aube) and Python tools (via uv) in native sidecar files, and addsmise bootstrap dotfiles conflictsfor inspecting dotfile sync conflicts before resolving them. It also lets dotfile templates consume bootstrap secrets, stopsminimum_release_agefrom rejecting versions already committed to a lockfile, and closes a security gap inhistory.describe_command.Added
lock: Lockfile revision 2 records the full dependency graph of npm tools installed by embedded aube and of
pypi:tools installed by uv, then replays it with a strict frozen install so two projects on the same top-level version can still receive their own reviewed transitive graph. Graphs live in native sidecar files (uv.lock/aube-lock.yamlplus a manifest) under.mise/locks/<backend-tool>/<version>/, referenced frommise.lockby relative path and SHA-256 digest, so the lockfile itself stays small. Commit the sidecar directory withmise.lock. New lockfiles use revision 2; existing revision 0 and 1 files keep their format until you runmise lock --upgrade.mise lock --bump <tool>refreshes a tool's transitive graph even when its top-level version is unchanged, ordinarymise installvalidates and accepts hand-edited sidecars, andmise install --lockedrejects digest mismatches until you runmise lock. Python graph locking requires uv 0.12.10 or newer and published wheels for the target platform; Git sources, standalone pipx installs, and free-formuvx_args/pipx_argsstay version-only. (#13131, #13146 by @jdx)pypi:
pypi:is now the preferred name for the Python CLI backend;pipx:remains fully supported as an alias with no warnings, and settings accept bothpypi.*andpipx.*names. The two spellings are distinct tool identities (pypi-blackvspipx-blackinstall directories and lock entries), so switching spelling creates a new installation. (#13146 by @jdx)bootstrap:
mise bootstrap dotfiles conflicts [PATH...]shows a read-only comparison of the saved local and fetched remote versions of a conflicted dotfile so you can decide between--take-remoteand--keep-localwith full context. The default output is a unified diff including file-mode changes;--difftoolopens the configured Gitdiff.tool(falling back tomerge.tool) and--tool <name>picks one explicitly. Encrypted contents are decrypted only into private temporary files, and inspection never modifies either side or marks the conflict resolved. Bootstrap secrets are also now resolved from the same composed config maps as dotfile discovery, so root-scoped dotfile templates can use secrets declared by their bootstrap root. (#13144 by @jdx)dotfiles: Dotfile templates (
mode = "template") can reference[bootstrap.secrets]values with{{ secret(name="...") }}, matching managed bootstrap file templates. Dotfiles commands that render templates (add,apply,diff,edit,status,unapply) accept--prompt-secrets; without an available value, rendering fails closed. A fullmise bootstraprun preflights dotfile templates before making changes,mise bootstrap statusreports secrets used only by dotfiles, and textual diffs redact resolved secret values. (#13140 by @jdx)Fixed
mise.lockno longer fails when the locked release is younger thanminimum_release_age. The cutoff still applies when resolving unlocked fuzzy requests and when generating or bumping a lockfile, andnpm:/pypi:still forward it to unpinned transitive dependencies, but a reviewed lock entry now reproduces immediately in CI instead of waiting for the release to cool. (#13128 by @jdx).python-version(or other idiomatic version file) containingsystemselects the system interpreter without printing the mise-specific@systemdeprecation warning, matching the existing.tool-versionsexception. Explicitpython@systemrequests from mise configuration or command arguments still warn. (#13132 by @jdx)mcshorthand usesaqua:minio/mcagain now that the upstream Aqua registry entry is restored, withasdf:mise-plugins/mise-mckept as the fallback. (#13124 by @jdx)Security
history.describe_commandis now global-only. Previously an implicitly trusted project could set it and have a later dotfiles history checkpoint execute the project-controlled command with unencrypted tracked-file diffs. The setting is honored only from system/global configuration orMISE_HISTORY_DESCRIBE_COMMAND; project values are ignored with a warning. (#13134 by @jdx)mise oci buildnow renders dotfile templates with a restricted engine:secret()is rejected and theenvcontext,get_env(),exec(), andread_file()are unavailable, so ambient credentials cannot be baked into a publishable image layer. (#13140 by @jdx)Breaking Changes
mise lock --upgrade. Upgrade collaborators and CI to this release before committing a revision 2mise.lock, and commit the.mise/locks/(or.config/mise/locks/) sidecar directory alongside it. Revision 2--lockedinstalls fail if a recorded graph is missing or its digest does not match. If you gitignoremise.local.lock, also ignore its matching sidecar subdirectory (for example.mise/locks/mise.local/).history.describe_commandin project configuration is ignored. Move it to~/.config/mise/config.tomlor setMISE_HISTORY_DESCRIBE_COMMAND.mise oci builddotfile templates can no longer callsecret(),get_env(),exec(), orread_file()or read theenvcontext.Full Changelog: jdx/mise@v2026.9.6...v2026.9.7
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (in timezone America/Chicago)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.