Skip to content

chore(github-release): update release jdx/mise to v2026.8.2 [automerge] - #325

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/mise
Open

chore(github-release): update release jdx/mise to v2026.8.2 [automerge]#325
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/mise

Conversation

@renovate

@renovate renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change Pending
jdx/mise patch 2026.8.02026.8.2 v2026.8.10 (+7)

Release Notes

jdx/mise (jdx/mise)

v2026.8.2: : Declarative System Bootstrap

Compare Source

This release turns mise bootstrap into a full declarative host-provisioning system: alongside packages, mise can now converge privileged files, Linux users and groups, systemd services, Docker Compose projects, and firewall rules — all with plan/apply/status workflows, secret handling, and the ability to run over SSH against remote hosts. It also makes Ruby's ruby.compile=false a strict precompiled-only mode and lands a batch of install and lockfile fixes.

Highlights

  • mise bootstrap gains a Terraform-style declarative model. A new mise bootstrap plan previews changes with table or JSON output and detailed exit codes, and each resource type has its own apply/status commands that converge only when something actually differs.
  • Bootstrap can now provision far more than tools and packages: privileged files and directories, Linux accounts, systemd services, Compose projects, and host firewall rules, with dependency ordering, fail-closed safety checks, and secret inputs sourced from environment variables (never stored in config).
  • The same bootstrap project can be applied to remote machines over SSH via mise bootstrap remote, including automatic detection of the target's OS/arch/libc and signature-verified download of the matching mise binary.

Added

  • bootstrap: declarative resource plans. mise bootstrap plan previews what bootstrap would change before applying, with table or --json output and optional --detailed-exitcode (0 = no changes, 2 = changes, 1 = error). Resources have stable identities, dependency graphs, and validation for duplicates, missing dependencies, and cycles. (#​11669 by @​jdx)
  • bootstrap: manage privileged files and directories via [bootstrap.files] and [bootstrap.directories], with content (inline or from a source), ownership, mode, and explicit present/absent state. Writes are atomic, removal is opt-in (and requires recursive = true for non-empty directories), and privileged work runs through hidden helpers that never expose file content in argv or logs. (#​11674 by @​jdx)
  • bootstrap: secret inputs for managed files. [bootstrap.secrets] references sensitive values through environment variables so nothing is stored in config, and managed files with template = true can render them via {{ secret(name="...") }}. mise bootstrap secrets status reports availability without revealing values, and --prompt-secrets prompts securely for anything missing. (#​11680 by @​jdx)
  • bootstrap: manage Linux users and groups via [bootstrap.users] and [bootstrap.groups], with create/update/remove, supplementary groups, home handling, and explicit state = "absent". Accounts converge before the files that reference them, and UID/GID collisions fail closed. (#​11681 by @​jdx)
  • bootstrap: manage Linux systemd services via [bootstrap.services] for running/stopped, enabled/disabled, and masked state. Managed files and directories can set notify to trigger reload, restart, or reload_or_restart handlers, but only after a real file change. (#​11688 by @​jdx)
  • bootstrap: manage Docker Compose projects via [bootstrap.compose] for running, stopped, and absent states, with pull/build/recreate/wait policies, one-shot services, orphan/volume/image removal, and explicit dependencies. Convergence compares live container runtime and health to the rendered Compose model (Compose v2 only). (#​11689 by @​jdx)
  • bootstrap: manage Linux host firewall rules via [bootstrap.linux.firewall] with nftables, firewalld, and UFW backends (backend = "auto"). Includes SSH-lockout protection (default-deny requires a covering allow rule or allow_lockout = true), drift detection, and preservation of undeclared rules unless exclusive is set. (#​11694 by @​jdx)
  • bootstrap: run bootstrap over SSH with mise bootstrap remote, targeting a named [bootstrap.remote.hosts] inventory or ad-hoc user@host targets. mise archives and stages your project, provisions a compatible mise binary on the host, runs bootstrap with forwarded flags, and cleans up staging afterward. (#​11690 by @​jdx)
  • bootstrap: remote provisioning now detects each target's OS, architecture, and Linux libc (glibc vs musl) and, when the local binary is not compatible, downloads the matching raw executable for the same release from GitHub with minisign-verified checksums. Custom or debug builds fail closed and require an explicit mise_bin, remote_mise, or bootstrap_command. (#​11693 by @​jdx)

Changed

  • ruby: ruby.compile = false is now a strict precompiled-only mode, matching python.compile. Installs error with no precompiled ruby found instead of silently falling back to ruby-build, and version listings (mise ls-remote ruby, fuzzy resolution) are filtered to versions that actually have a precompiled binary for your platform. Previously false was a no-op after precompiled binaries became the default in 2026.8.0. Unset and compile = true are unchanged; Windows is unaffected. (#​11710 by @​jdx)
  • task: workspace task inference is now opt-in per provider via task.auto_infer (e.g. task.auto_infer = ["node"]) instead of running whenever experimental features are enabled. Explicit mise tasks always take precedence over inferred package scripts on name and alias collisions. (#​11706 by @​jdx)

Fixed

  • brew: :any_skip_relocation bottles no longer leave unresolved @@HOMEBREW_*@@ placeholders in scripts and config files. That tag now only skips binary linkage relocation while text placeholders are still replaced. (#​11665 by @​jdx)
  • brew-cask: detect extensionless DMG downloads (such as Raycast) by their UDIF trailer instead of treating them as raw executables and failing to find the app bundle. (#​11692 by @​jacobbednarz)
  • lock: mise lock --bump now errors instead of writing an incomplete lockfile when a version bump would drop platform coverage that the previous locked version had. Best-effort skips are retained for platforms a tool never supported. (#​11664 by @​jdx)
  • pipx: release-age gating now uses PyPI's precise RFC3339 upload_time_iso_8601 timestamp instead of the timezone-naive upload_time, which previously made freshly released packages appear up to ~24h younger and over-gated them under minimum_release_age. (#​11662 by @​Guria)
  • pacman: pacman -Q is now parsed under LC_ALL=C so missing-package detection works in non-English locales; previously [bootstrap.packages] could bail on a translated "was not found" message. (#​11673 by @​rarandeyo)
  • sync: clear stale incomplete markers when an external link (from uv, nvm, pyenv, nodenv, or Homebrew) is confirmed healthy, so mise where no longer treats a working external version as incomplete after an interrupted install. (#​11172 by @​risu729)
  • completions: an explicit -- no longer hijacks task argument completion after usage v5. mise run <task> -- <TAB> again offers the task's declared choices instead of falling back to filenames, while still forwarding extra arguments. (#​11711 by @​jdx)
  • registry: shim auto-install uses new declared bins metadata to pick the correct provider before falling back to incidental executables, fixing cases where invoking the npm shim could run Node's bundled npm instead of the configured npm version. (#​11666, #​11671, #​11676, #​11677, #​11678 by @​jdx)

New Contributors

Full Changelog: jdx/mise@v2026.8.1...v2026.8.2

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

v2026.8.1: : Task Cache Goes Remote, Affected Tasks, and Config Ergonomics

Compare Source

This release rounds out mise's experimental task artifact cache with size/age limits, inspection tooling, and a full local-plus-remote cache backend (including authenticated CI caching), adds experimental mise run --affected for monorepos, and lands a batch of config, upgrade, and install fixes.

Highlights

  • The experimental task output cache now supports remote sharing: a composite store reads locally first, promotes remote hits, and mirrors writes, with authenticated requests backed by token files or GitHub Actions OIDC. Cache entries can be inspected, cleared per-task, and bounded by size and age.
  • Experimental mise run --affected runs only the tasks in monorepo projects touched by your Git changes, using workspace dependency graphs, global task inputs, and provider lockfile attribution to decide what is affected.
  • The config-writing flags are now more forgiving: --file and --path are interchangeable across the commands that write config, so you no longer have to remember which name each subcommand expects.

Added

  • task: experimental mise run --affected selects and runs only the tasks in projects affected by Git changes, combining the workspace dependency graph, global_inputs, and provider lockfile diffs. Base and head revisions can be overridden with --affected-base/--affected-head or MISE_AFFECTED_*. Includes JSON output and an --explain breakdown of why each task was selected. (#​11590, #​11587, #​11589, #​11591, #​11593 by @​jdx)

    mise run --affected test
    mise run --affected --affected-base main test
  • task: remote task cache. A composite store layers local and remote backends, reading local first and promoting remote hits, then committing locally before mirroring writes so a remote failure never loses a local hit. Requests are hardened, verified, streamed, and support read/write access modes. (#​11622, #​11623, #​11624, #​11626, #​11627 by @​jdx)

  • task: authenticated remote cache. Credentials resolve in fixed precedence: an explicit bearer token, a global-only token file (MISE_TASK_CACHE_REMOTE_TOKEN_FILE), then GitHub Actions OIDC when MISE_TASK_CACHE_REMOTE_OIDC_AUDIENCE is set. HTTPS is enforced except for loopback development endpoints. (#​11625, #​11653 by @​jdx)

  • task: task.cache_max_size and task.cache_max_age settings cap the task output cache independently of the global prune age, evicting least-recently-accessed entries after writes and rejecting expired entries on restore. (#​11610 by @​jdx)

  • task: inspect and selectively clear the cache with mise cache task <task> (table or --json, reporting stored size, restorable bytes, saved time, last access, and outputs) and mise cache clear --task <task>, which removes only that task's entries without touching your working-tree outputs. (#​11604 by @​jdx)

  • task: mise run --task-cache-explain <task> prints a structural breakdown of what feeds a task's cache key (input categories, counts, env/var names and presence, platform) without emitting secret-derived hashes, and works under --dry-run. Companion changes report cache miss reasons, cache statistics, resolved cache paths, and add JSON explanation output. (#​11595, #​11597, #​11599, #​11600, #​11601 by @​jdx)

  • task: cache artifacts are now checksum-verified and cache declarations are audited on load. (#​11605, #​11617 by @​jdx)

  • config: --file and --path are now interchangeable across the commands that write config: mise use, mise set, mise unuse, mise unset, mise config get, and mise config set. (#​11577, #​11616, #​11631, #​11640 by @​JamBalaya56562)

    mise use --file mise.local.toml node@22
    mise set --path mise.local.toml FOO=bar
  • upgrade: mise upgrade --no-prune keeps the version being replaced instead of uninstalling it, so external references such as virtualenvs built from a mise-managed Python keep working. Also works with --bump. (#​11639 by @​JamBalaya56562)

  • env: on Windows, mise now warns when the generated PATH exceeds the ~8191-character length at which cmd.exe silently drops the variable, which otherwise makes every command appear unrecognized. (#​11643 by @​JamBalaya56562)

  • vfox: Lua plugins gain strip_components = 1 on archiver.decompress plus sorted file.list, file.glob, and file.move, letting plugins flatten versioned archive roots and rename executables portably without shelling out. (#​11652 by @​jdx)

Fixed

  • config: tool versions may now contain a colon, so templated versions like {{ exec(...) | split(pat=': ') | last }} and selectors resolved from templates no longer fail config loading. (#​11580 by @​JamBalaya56562)
  • config: config writes no longer pick a target that config loading would ignore, honor ignore filters when a --path <dir> is given, and no longer write the global config into a conf.d drop-in. (#​11571, #​11609, #​11633 by @​JamBalaya56562)
  • upgrade: mise upgrade --bump now applies every eligible tool bump in the same config file instead of letting the last save overwrite earlier ones, and preserves successful bumps when another tool in the file fails to install. (#​11572 by @​Marukome0743)
  • install: a failed backend install no longer leaves runtime aliases such as latest pointing at the removed version; mise rebuilds valid symlinks (or removes dangling ones) after cleanup. (#​11579 by @​Marukome0743)
  • brew: Linux Homebrew bottles containing shebang executables with binary payloads (such as Watchman's watchman-diag zipapp) now relocate correctly with long Linuxbrew prefixes. (#​11632 by @​Marukome0743)
  • pipx: extras are now applied to git-based installs. (#​11586 by @​jdx)
  • prune: read-only shared installs are excluded from pruning. (#​11644 by @​Marukome0743)
  • task: dangling task symlinks are skipped, wildcard task matching respects group boundaries, shared pre/post dependencies are supported, and task-list flags are rejected on subcommands. Task cache writes are serialized and abandoned partial writes are cleaned up. (#​11574, #​11581, #​11578 by @​Marukome0743; #​11638, #​11606, #​11608 by @​jdx)
  • schema: JSON schemas are now published alongside the documentation. (#​11596 by @​jdx)

Documentation

Full Changelog: jdx/mise@v2026.8.0...v2026.8.1

💚 Sponsor mise

mise is maintained by @​jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • "every weekend,on Friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from DevSecNinja as a code owner August 21, 2026 00:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants