Zum Inhalt springen

Mise Updates & Release Notes

34 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.10.4: Task-Secrets mit fnox und automatische Updates globaler Tools

Mise 2026.10.4 ergänzt experimentelle Task-Secrets auf Basis von fnox, automatische Updates für globale Tools, ein optionales experimentelles Installationslayout, merge-Einträge für Dotfiles, headers-Authentifizierung für das http:-Backend und npm-Installationen aus git sowie Korrekturen bei Prune, Installation und Lockfile.

This release adds experimental task-scoped secrets backed by fnox, automatic updates for global tools, and an experimental opt-in install layout that names installations by what they contain. It also adds dotfile merge entries, headers auth for the http: backend, npm installs from git, and a set of prune, install and lockfile fixes.

Added

Secrets (experimental)

These need mise settings experimental=true and fnox 1.39.0 or newer. They are refused in safe mode.

  • [secrets.fnox] and mise secrets ls. A project can name fnox as its secrets source in its own mise.toml. mise secrets ls lists key names and metadata but never values. -J prints JSON. Global, system and home-level [secrets] config is ignored, and mise doctor reports it. #13967

  • Tasks get only the secrets they list. Add secrets = [...] to a task, or #MISE secrets=[...] in a file task header. Only that task gets the values, only while it runs, and they are redacted from its output. Dependencies, hooks, mise env, hook-env and shims get nothing. A task without grants never calls fnox. Tasks that list secrets need a trusted config, aren't artifact-cached, and ignore --raw unless the task sets raw or interactive. Hooks, watch_files, daemons and mise bootstrap can't run them, and remote or global-config tasks can't list secrets. #13974

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.10.3: Dotfile-Gruppen, Compose-Templates und Schutz von Secrets

Mise 2026.10.3 ergänzt Dotfile-Gruppen im Stow-Stil, Templates in [bootstrap.compose] und eigene Labels für Task-Bestätigungen, verhindert das Kopieren von Secrets in __MISE_DIFF/__MISE_SESSION und den Env-Cache und behebt Fehler bei dotenv-${VAR}-Expansion, mise x tool@latest und Ruby-Source-Builds.

This release adds dotfile groups for Stow-style dotfiles repositories, templated [bootstrap.compose] values, and custom labels for task confirm prompts. Secret values no longer get copied into __MISE_DIFF/__MISE_SESSION or written to the env cache. It also fixes dotenv ${VAR} expansion, mise x tool@latest reporting other tools as missing, and Ruby source builds ignoring depends tools.

Added

  • Dotfile groups. You can now declare a directory tree as a group with [dotfile_groups.<name>], using one directory per app or machine role like GNU Stow. mise walks the group's root and deploys each file to the same path under target (default ~), so you don't have to list files one by one. A machine picks which groups to apply with [bootstrap] dotfile_groups. If that list isn't set, every group applies. #13945

    [dotfile_groups.home]
    root = "home"            # relative to dotfiles.root
    dot_prefix = true        # dot-config/ deploys as .config/
    exclude = ["README.md"]
    
    [dotfile_groups.home.entries]
    "~/.config/kitty" = { mode = "symlink" }                            # link this directory whole
    "~/.gitconfig" = { source = "git/config.tmpl", mode = "template" }
    
    [bootstrap]
    dotfile_groups = ["home", "zsh"]
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.10.2: Experimentelles spinel-Backend und Daemon-Presets unter Windows

Mise 2026.10.2 führt das experimentelle spinel:-Backend zum Kompilieren von Ruby-CLIs zu nativen Binaries ein, prüft im mise.toml-Schema die Tool-Optionen je Backend, unterstützt Daemon-Presets unter Windows und behebt Fehler bei Shell-Aktivierung mit nicht vertrauten Configs, Task-Timeouts und Windows-Quoting.

This release adds an experimental spinel: backend for compiling Ruby CLIs to native binaries. The mise.toml schema now checks each backend's own tool options, and daemon presets work on Windows. It also includes fixes for shell activation with untrusted configs, task timeouts and Windows quoting.

Added

  • Experimental spinel: backend. It builds a Ruby command-line tool from a GitHub repository into a native executable using Spinel, Matz's Ruby AOT compiler. Versions come from git tags through git ls-remote, so listing them doesn't call the GitHub API. Available options: entrypoint, bin, tag_prefix, source_ref and spinel. You need the spinel compiler on PATH (mise doesn't install it yet) and mise settings experimental=true. It works on macOS and Linux only, and it may be removed later if it becomes a maintenance burden. Based on nateberkopec/mise-backend-spinel. #13922

    [tools."spinel:tobi/try"]
    version = "1.10.1"
    entrypoint = "try.rb"
    bin = "try"
    tag_prefix = "v"
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.10.1: Fixes für Task-Timeouts, Ctrl-C sowie Windows-Daemons und -Shims

Mise 2026.10.1 behebt vor allem Fehler: mise run beendet Tasks bei --timeout und Ctrl-C korrekt, Task-Daemons und Shims laufen unter Windows besser, core:rust folgt mise.lock, und Probleme mit Lockfile, GitHub-Assets, Homebrew Casks und Plugin-Updates sind behoben.

This release is mostly bug fixes. mise run now stops tasks properly when --timeout expires or you press Ctrl-C. Task daemons and native shims work better on Windows. core:rust now follows mise.lock and picks up new stable and beta toolchains. Lockfile, GitHub asset selection, Homebrew cask and plugin update problems are also fixed.

Fixed

Tasks

  • mise run --timeout now stops the tasks it was running. Before, mise printed the timeout error and exited, but the task processes could keep running in the background. Now the whole-run timeout (--timeout or the task.timeout setting) stops tasks the same way a per-task timeout does. On Unix, mise sends SIGTERM and then SIGKILL after 5 seconds. On Windows, it runs taskkill /F /T. Tasks with raw = true are not stopped by the whole-run timeout. #13876 by @Marukome0743
  • A single Ctrl-C lets tasks shut down cleanly. Before, one Ctrl-C could make mise exit right away while tasks were still cleaning up. This happened in three cases: a task that runs mise run itself got SIGINT twice; a tool like docker compose up treated the duplicate SIGINT as a force-quit; and a task that exits non-zero on SIGINT caused mise to send SIGTERM to its sibling tasks. Now mise waits for tasks to finish and then exits with status 130. A second Ctrl-C still force-quits. #13904 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.10.0: Strengere Signer-Prüfungen und Vertrauen für Inline-Optionen

Mise 2026.10.0 verschärft die Lieferkettenprüfung durch feste Signer-Identitäten bei cosign und strengere GitHub-Attestation-Prüfungen, verlangt Vertrauen für Inline-Optionen in .tool-versions (Schutz vor GITHUB_TOKEN-Leak), ergänzt die Option appdir für Homebrew Casks und behebt Fehler bei gesperrten SLSA-Installs, musl-Hosts und mise backends switch.

This release tightens supply-chain verification. Keyless cosign bundles must now match a pinned signer identity, and GitHub attestation workflow checks no longer accept partial matches. It also closes a .tool-versions trust gap that could leak GITHUB_TOKEN, adds a per-cask appdir option for Homebrew casks, and fixes problems with locked SLSA installs, musl hosts and mise backends switch.

Security

  • Inline tool options in .tool-versions now require trust. This is the .tool-versions version of the mise.toml fix in 2026.9.18. An untrusted project could ship a github: entry with inline options, such as [api_url=...], pointing at another host. Commands such as mise ls, env, current, outdated and latest would then send your GITHUB_TOKEN to that host without asking for trust. Any entry whose tool name contains [ now requires trust, the same as Tera templates. Plain lines like node 20.0.0 still load without trust, and a [ inside a comment is ignored. Run mise trust for projects you rely on. MISE_SAFE=1 still skips trust checks. (GHSA-wcqh-j26q-g44x) #13869 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.18: Remote-Config-Includes, OCI-Task-Kataloge und Trust-Fix

Mise 2026.9.18 erlaubt das Einbinden gemeinsamer Configs aus Git oder OCI per include, akzeptiert OCI-Artefakte in task_config.includes, schließt eine Trust-Umgehung für Inline-Tool-Optionen, die GITHUB_TOKEN an fremde Hosts senden konnte, und ergänzt Gem-Registry-Quellen sowie Fixes für Daemons und Dotfiles.

mise.toml can now include a shared config file from a git repository or OCI registry, and task_config.includes accepts OCI artifacts. The release also closes a trust bypass that could send GITHUB_TOKEN to an attacker-controlled host, adds gem registry sources, and fixes several daemon and dotfiles problems.

Security

  • Inline tool options now require trust. Before this change, a mise.toml in an untrusted directory could hide options in a tool key, for example a github: tool key with [api_url=...] pointing at another host. mise loaded the file without trust because the value was a plain version string. Commands such as mise ls, env, current, outdated, upgrade --dry-run and latest then sent GITHUB_TOKEN to that api_url. Now any tool key that contains [ requires trust, the same as { ... } option tables already did. Plain keys like node or "cargo:eza" still load without trust. If you use inline options in a project you haven't trusted yet, run mise trust. MISE_SAFE=1 still skips trust checks entirely. #13849

Added

  • Include shared config from git or OCI. Organizations can keep tool versions, env and hooks in one place and pull them into every repo: #13843

    include = [
      "git::<repo-url>//mise.toml?ref=main",
      "oci::ghcr.io/myorg/platform-config@sha256:0f1e2d3c...",
    ]
    
    [tools] …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.17: Self-Update wartet 24 Stunden und prüft signierte Packslips

Mise 2026.9.17 lässt mise self-update und den mise.run-Installer standardmäßig nur Releases wählen, die mindestens 24 Stunden alt sind, prüft dabei das signierte Packslip und ergänzt eine globale miserc, optionale Installation per command-not-found sowie einen postinstall-Modus und mehrere Fixes.

mise self-update and the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local global miserc, an opt-in way for command-not-found to install registry tools, and a postinstall mode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode.

Changed

  • Self-update and installs wait for a minimum release age. When no version is pinned, mise self-update, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with --force. The age is taken from, in order: --minimum-release-age, then self_update.minimum_release_age, then the global minimum_release_age setting, then 24h. Use 0s to get releases right away. #13782

    [settings]
    self_update.minimum_release_age = "7d"
    
    mise self-update --minimum-release-age 0s
    curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d sh
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.16: libc pro aqua-Tool, Task-Pfad-Aliase und Packslip-Pins

Mise 2026.9.16 erlaubt die Wahl von glibc oder musl pro aqua-Tool, ergänzt Task-Pfad-Aliase für Monorepos, pinnt Packslip-Tools per Repository-ID (Lockfile-Revision 3), verlangt bei SLSA-Prüfungen die erwartete Signer-Identität und behebt Regressionen bei mise run --no-timings, cargo +nightly und outdated/upgrade.

Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in mise run --no-timings, cargo +nightly and the outdated/upgrade version comparison, and speeds up shims and config loading.

Added

  • Per-tool libc for aqua tools. On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such as aqua:domcyrus/rustnet. You can now pick the build for a single tool instead of changing the global libc setting. #13701

    [tools]
    "aqua:domcyrus/rustnet" = { version = "latest", libc = "musl" }
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.15: vfox-Tools in OCI-Images und schnellere Shell-Prompts

Mise 2026.9.15 packt mit mise oci build nun auch von vfox-Plugins installierte Tools in OCI-Images, beschleunigt Shell-Prompts, cd und das Laden von Einstellungen und lässt Dotfiles-Muster für include/exclude den .gitignore-Regeln folgen.

mise oci build can now package tools installed by vfox plugins, and vfox plugins can repair an existing install when its tool options change. Shell prompts, cd, and settings loading are faster. Dotfiles include/exclude patterns now follow .gitignore rules for * and a leading /, which fixes a case where rollback could delete a live file.

Added

  • vfox tools in OCI images (experimental). mise oci build used to reject every tool installed by a vfox plugin. It now builds those tools into the image, with one layer per tool plus one layer per plugin at /mise/plugins/<name>/, so mise inside the image can resolve the tool without cloning the plugin. The plugin's env hook runs on the build host. Install-dir paths are rewritten to their in-image location, and mise warns when a value points into the host's home directory. Changing a plugin invalidates the reused layers of its tools on mise oci push. asdf plugins are still rejected. #13670 …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.14: conf.d-Ordnerfragmente und Stow-artige Dotfile-Optionen

Mise 2026.9.14 lädt Ordner in conf.d als eigene Config-Fragmente, ergänzt [dotfiles] um relative Symlinks und dot-<name>-Quellen, bezieht Release-Metadaten öffentlicher github.com-Repos über mise-versions und kann in der Registry GitHub-Attestations für bestimmte Tools verlangen.

A folder inside any conf.d directory now loads as its own config fragment and serves as the config root for the files in it, which gives [bootstrap].config_roots users a direct migration path. [dotfiles] gains two GNU Stow-style options: relative symlinks and dot-<name> sources. Release metadata for any public github.com repo now comes from mise-versions, and the registry can require GitHub attestations for specific tools.

Added

  • conf.d folder fragments. A folder in a global, system, or project conf.d directory now loads as a fragment. Relative paths, {{ config_root }}, and task working directories resolve inside that folder, so a bundle can keep its files next to its config. Each folder can hold mise.toml, mise.local.toml, mise.<env>.toml, and mise.<env>.local.toml. Folders are not searched recursively, and folders whose names start with . are skipped. A folder can be a symlink. Folder fragments load after the single-file fragments in the same conf.d (in folder-name order) and before config.toml. mise use/mise set never write to them. #13603

    ~/.config/mise/conf.d/
    ├── git.toml          # single-file fragment, unchanged
    └── git-tools/        # folder fragment
        ├── mise.toml
        └── gitconfig
    
    # ~/.config/mise/conf.d/git-tools/mise.toml
    [dotfiles]
    "~/.gitconfig" = "gitconfig"   # resolves to conf.d/git-tools/gitconfig
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.13: OpenTelemetry für Tasks, geteilte Daemon-Provider, backends switch

Mise 2026.9.13 exportiert mit mise run experimentell OpenTelemetry-Traces und -Logs, erlaubt gemeinsame Daemon-Provider für PostgreSQL, CockroachDB und NATS, ergänzt mise backends switch und mise bootstrap unapply, ermöglicht das deklarative Entfernen von Dotfiles und entfernt das pkgx:-Backend.

mise run can now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the new mise backends switch command does it when you ask. [dotfiles] and [bootstrap.files] can now remove files and manage permissions, and mise bootstrap unapply removes what a module set up. The experimental pkgx: backend has been removed.

Highlights

  • Observability and shared services (experimental): task runs export OTLP traces and, if you opt in, task output as logs. Global [daemon_providers] run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout.
  • Safer lockfiles: locked tools stay on their locked backend, mise lock --bump checks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project's mise.lock.
  • Declarative cleanup: mode = "absent", remove_empty templates, permissions-only entries, removal of empty directories mise created, and mise bootstrap unapply let a config describe what should not be on a machine.

Added

Tasks …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.13: OpenTelemetry, Daemon-Provider und mise backends switch

Mise 2026.9.13 exportiert mit mise run experimentell OpenTelemetry-Traces und -Logs, erlaubt geteilte Daemon-Provider für PostgreSQL, CockroachDB und NATS, wechselt Backends in Lockfiles nur noch per mise backends switch, kann über [dotfiles] und [bootstrap.files] Dateien entfernen und Berechtigungen verwalten und entfernt das experimentelle pkgx:-Backend.

mise run can now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the new mise backends switch command does it when you ask. [dotfiles] and [bootstrap.files] can now remove files and manage permissions, and mise bootstrap unapply removes what a module set up. The experimental pkgx: backend has been removed.

Highlights

  • Observability and shared services (experimental): task runs export OTLP traces and, if you opt in, task output as logs. Global [daemon_providers] run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout.
  • Safer lockfiles: locked tools stay on their locked backend, mise lock --bump checks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project's mise.lock.
  • Declarative cleanup: mode = "absent", remove_empty templates, permissions-only entries, removal of empty directories mise created, and mise bootstrap unapply let a config describe what should not be on a machine.

Added

Tasks …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.12: Tasks mit Daemons, Scoop- und zypper-Pakete, offizielle Docker-Images

Mise 2026.9.12 erweitert das experimentelle Daemon-System um Tasks mit benötigten Daemons, [daemon_groups], port = "auto" und Presets für CockroachDB, NATS und SpiceDB, ergänzt die Bootstrap-Manager scoop: und zypper:, veröffentlicht offizielle Docker-Images und verbessert die Installation von brew-cask.

The experimental [daemons] system grows substantially: tasks can declare the daemons they need, [daemon_groups] selects subsets of a project's services, port = "auto" and stable <NAME>_URL hostnames let several git worktrees run the same stack side by side, and CockroachDB, NATS, and SpiceDB join the PostgreSQL and Redis presets. Outside daemons, [bootstrap.packages] gains scoop: and zypper: managers, mise install --system elevates with sudo only for the final publish step, official mise images are published to GHCR and Docker Hub, and a run of brew-cask fixes lets many more casks install unattended.

Highlights

  • Daemons as part of the task graph (experimental): [tasks.x] daemons = [...] starts and waits for services before a task runs, daemons can run a mise task, [daemon_groups] and mise daemons start <group> select subsets, and mise daemons register, urls, and prune round out the lifecycle. Worktrees get deterministic ports, hostnames, and optionally checkout-local data_dir storage without hand-assigned numbers.
  • More host software from one config: Scoop on Windows and zypper on openSUSE/SLE join the bootstrap managers; brew-cask now picks the right build for the host macOS release, runs installers that need sudo, applies pkg installer choices and set_ownership steps, upgrades pkg-only self-updating casks, and survives DMGs with license prompts or unreadable metadata; brew: resolves formula aliases such as openssl. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.11: macos-app-Bootstrap, Task-Template-Vererbung und Swift-Fixes

Mise 2026.9.11 ergänzt den Bootstrap-Manager macos-app für .app-Bundles, lässt Task-Templates usage-Flags vererben und von File-Tasks erweitern, wählt Swift-Builds unter Linux anhand des swift.org-Release-Index und liefert aussagekräftigere Installationsfehler.

A new macos-app bootstrap manager installs .app bundles from a pinned URL and checksum when no Homebrew cask exists, task templates now compose usage flags and can be extended from file tasks, and Swift on Linux picks its distro build from swift.org's release index instead of a hard-coded map that 404'd on arm64 and on newer Fedora, Amazon Linux, and Arch hosts. Install failures also become far more actionable: errors name the minimum_release_age cutoff that hid every version, the child's last stderr line, or the shared libraries a Swift toolchain cannot load.

Highlights

  • Apps without a cask: "macos-app:<name>" entries in [bootstrap.packages] download, checksum-verify, and install a .app into /Applications using mise's existing cask pipeline, with stricter ownership rules for apps already at the target.
  • Task templates that actually share things: a task that extends a template now inherits the template's usage flags alongside its own, file tasks can write #MISE extends="...", and a template's vars can read the values the extending task supplies.
  • Swift on Linux: arm64 downloads resolve on every distro, the build is chosen from what a release actually publishes (with a warning when a fallback is used), and a fallback that cannot start names the missing libraries instead of exiting 127 after a 1 GB download.

Added …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.10: shims.exclude, allow_exotic_deps und Windows-Ctrl-C-Fix

Mise 2026.9.10 ergänzt die Einstellungen shims.exclude und allow_exotic_deps, erlaubt mit mise dot pull das Lösen aller Konflikte auf einmal, fügt vfox-Hooks cmd.stream hinzu und behebt Ctrl-C-Probleme von mise run unter Windows, langsame fish-Starts über Shims sowie Fehler bei Tasks, Lockfiles und Homebrew Casks.

New settings let mise manage a tool without claiming its command names (shims.exclude) and approve non-registry npm dependencies (allow_exotic_deps), mise dot pull can decide every sharing conflict at once, and vfox plugin hooks gain cmd.stream plus a working cmd.exec timeout. On the fix side, mise run now survives Ctrl-C on Windows instead of orphaning cmd.exe, fish shells launched through shims start much faster with correct PATH order, and several task-resolution, lockfile, and Homebrew cask bugs are corrected.

Highlights

  • Control over what mise puts on PATH and what it installs: settings.shims.exclude keeps names like python resolving to the OS while mise still manages the tool; allow_exotic_deps approves specific npm packages fetched from git or tarball URLs; exact packslip: pins install during a minimum_release_age cooling window; and mise upgrade --bump keeps SemVer build metadata such as +k3s1.
  • Dotfiles sharing on a second machine: mise dot pull --take-remote-all / --keep-local-all resolve all conflicts in one command, paths that cannot be decided are held rather than aborting the pass, and a directory sitting where a tracked file belongs is now reported as exactly that. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.9: Dotfiles-Löschfix, verschlüsseltes mise dot track, uv-Optionen

Mise 2026.9.9 behebt fälschlich als gelöscht erfasste Dotfiles im History-Watcher, ergänzt mise dot track --encrypt und mise bootstrap --adopt --replace-history, fügt pypi:-Tools die Optionen with, expose und dependency_prereleases hinzu und behebt mehrere Installations- und PowerShell-Fehler.

The dotfiles history watcher no longer records files as deleted when a checkpoint and a sync compose snapshots at the same time, mise dot track --encrypt enrolls a file with encrypted history from its first checkpoint, mise bootstrap --adopt --replace-history discards unrelated local history in one shot, and pypi: tools gain lock-aware with, expose, and dependency_prereleases options. Also fixed: packslip: installs from private GitHub repositories, stale history watchers after upgrading, global npm tools being reinstalled under lockfile = true, and the -- separator in activated PowerShell sessions.

Added

  • dotfiles: mise dot track --encrypt writes encrypt = true into the tracked declaration and encrypts the initial baseline checkpoint, for files that must never have plaintext history. [history.encryption].recipients must be configured first; if the encrypted baseline cannot be saved, enrollment fails closed and rolls back the declaration without committing history metadata. Run it as a standalone command rather than inside mise dot capture. Enabling encryption on a file that already has plaintext history does not rewrite that history. (#13180 by @jdx)

    mise dot track ~/.config/app/credentials --encrypt
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.9: Dotfiles-Fix, verschlüsseltes mise dot track, uv-Optionen

Mise 2026.9.9 behebt falsch als gelöscht erfasste Dateien im Dotfiles-History-Watcher, ergänzt mise dot track --encrypt, mise bootstrap --adopt --replace-history sowie die pypi:-Optionen with, expose und dependency_prereleases und behebt weitere Fehler bei packslip:-Installationen, veralteten History-Watchern, globalen npm-Tools unter lockfile = true und dem ---Trenner in PowerShell.

The dotfiles history watcher no longer records files as deleted when a checkpoint and a sync compose snapshots at the same time, mise dot track --encrypt enrolls a file with encrypted history from its first checkpoint, mise bootstrap --adopt --replace-history discards unrelated local history in one shot, and pypi: tools gain lock-aware with, expose, and dependency_prereleases options. Also fixed: packslip: installs from private GitHub repositories, stale history watchers after upgrading, global npm tools being reinstalled under lockfile = true, and the -- separator in activated PowerShell sessions.

Added

  • dotfiles: mise dot track --encrypt writes encrypt = true into the tracked declaration and encrypts the initial baseline checkpoint, for files that must never have plaintext history. [history.encryption].recipients must be configured first; if the encrypted baseline cannot be saved, enrollment fails closed and rolls back the declaration without committing history metadata. Run it as a standalone command rather than inside mise dot capture. Enabling encryption on a file that already has plaintext history does not rewrite that history. (#13180 by @jdx)

    mise dot track ~/.config/app/credentials --encrypt
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.8: Top-Level-Befehl mise dot und schnellere brew-Bootstrap-Installation

Mise 2026.9.8 stellt die Dotfile-Verwaltung als mise dot bzw. mise dotfiles auf oberste Ebene, führt Homebrew-Bootstrap-Installationen nebenläufig aus und korrigiert Probleme bei aube-Reputationsprüfungen, PyPI-Fallbacks, missing:-Warnungen und deaktivierten Backends in Lockfiles.

Dotfile management moves to the top level as mise dot, Homebrew bootstrap installs run their download, extraction, and linking stages concurrently, and several install paths are corrected: embedded aube reputation gates now report the real reason and honor --yes, PyPI tools fall back to version-only installs when a dependency graph cannot be built, lazy tools no longer trigger missing: warnings, and lockfiles no longer resurrect disabled backends.

Added

  • dotfiles: The full dotfiles command tree is now available as mise dotfiles, with mise dot as a short alias. mise bootstrap dotfiles remains supported and all three spellings share the same behavior, including bootstrap hooks around apply. Generated history-watch services now invoke mise dot watch. (#13158 by @jdx)

    mise dot track ~/.zshrc
    mise dot status
    mise dot history
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.8: mise dot auf oberster Ebene und schnellere brew-Installs

Mise 2026.9.8 stellt die Dotfile-Verwaltung als mise dotfiles bzw. mise dot bereit, führt Download, Entpacken und Verlinken bei Homebrew-Bootstrap-Installationen gleichzeitig aus und korrigiert mehrere Installationspfade, darunter aube-Reputationsprüfungen mit --yes, PyPI-Fallback auf reine Versionsinstallationen, missing:-Warnungen bei Lazy-Tools und deaktivierte Backends in Lockfiles.

Dotfile management moves to the top level as mise dot, Homebrew bootstrap installs run their download, extraction, and linking stages concurrently, and several install paths are corrected: embedded aube reputation gates now report the real reason and honor --yes, PyPI tools fall back to version-only installs when a dependency graph cannot be built, lazy tools no longer trigger missing: warnings, and lockfiles no longer resurrect disabled backends.

Added

  • dotfiles: The full dotfiles command tree is now available as mise dotfiles, with mise dot as a short alias. mise bootstrap dotfiles remains supported and all three spellings share the same behavior, including bootstrap hooks around apply. Generated history-watch services now invoke mise dot watch. (#13158 by @jdx)

    mise dot track ~/.zshrc
    mise dot status
    mise dot history
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Mise von jdx

Mise 2026.9.7: Lockfile-Revision 2 mit Abhängigkeitsgraphen und Dotfile-Konflikten

Mise 2026.9.7 führt mise.lock Revision 2 mit vollständigen Abhängigkeitsgraphen für npm- und Python-Tools ein, ergänzt mise bootstrap dotfiles conflicts, erlaubt Bootstrap-Secrets in Dotfile-Templates, hindert minimum_release_age am Ablehnen bereits gelockter Versionen und schließt eine Sicherheitslücke bei history.describe_command.

This release introduces mise.lock revision 2, which records complete transitive dependency graphs for npm tools (via embedded aube) and Python tools (via uv) in native sidecar files, and adds mise bootstrap dotfiles conflicts for inspecting dotfile sync conflicts before resolving them. It also lets dotfile templates consume bootstrap secrets, stops minimum_release_age from rejecting versions already committed to a lockfile, and closes a security gap in history.describe_command.

Added

  • lock: Lockfile revision 2 records the full dependency graph of npm tools installed by embedded aube and of pypi: tools installed by uv, then replays it with a strict frozen install so two projects on the same top-level version can still receive their own reviewed transitive graph. Graphs live in native sidecar files (uv.lock / aube-lock.yaml plus a manifest) under .mise/locks/<backend-tool>/<version>/, referenced from mise.lock by relative path and SHA-256 digest, so the lockfile itself stays small. Commit the sidecar directory with mise.lock. New lockfiles use revision 2; existing revision 0 and 1 files keep their format until you run mise lock --upgrade. mise lock --bump <tool> refreshes a tool's transitive graph even when its top-level version is unchanged, ordinary mise install validates and accepts hand-edited sidecars, and mise install --locked rejects digest mismatches until you run mise lock. Python graph locking requires uv 0.12.10 or newer and pub…

Originalquelle(öffnet in neuem Tab)Problem melden