Skip to content

Commit cb169ed

Browse files
chore(deps): update dependency jdx/mise to v2026.9.15 (#2504)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [jdx/mise](https://redirect.github.com/jdx/mise) | uses-with | patch | `v2026.9.12` → `v2026.9.17` | --- ### Release Notes <details> <summary>jdx/mise (jdx/mise)</summary> ### [`v2026.9.17`](https://redirect.github.com/jdx/mise/releases/tag/v2026.9.17): : Self-update waits 24 hours for new releases and verifies signed packslips [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.16...vfox-v2026.9.17) `mise self-update` and the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local global `miserc`, an opt-in way for command-not-found to install registry tools, and a `postinstall` mode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode. ##### Changed - **Self-update and installs wait for a minimum release age.** When no version is pinned, `mise self-update`, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with `--force`. The age is taken from, in order: `--minimum-release-age`, then `self_update.minimum_release_age`, then the global `minimum_release_age` setting, then `24h`. Use `0s` to get releases right away. [#&#8203;13782](https://redirect.github.com/jdx/mise/pull/13782) ```toml [settings] self_update.minimum_release_age = "7d" ``` ```sh mise self-update --minimum-release-age 0s curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d sh ``` The installer reads environment variables only (`MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE`, `MISE_MINIMUM_RELEASE_AGE`), and it accepts integer `s`/`m`/`h`/`d`/`w` durations. A saved copy of the installer no longer pins a default version, so set `MISE_VERSION` if you need reproducible installs. - **Self-update verifies signed packslips.** For releases v2026.9.3 and later, `mise self-update` now requires a valid signed packslip, on top of the embedded archive signature it already checked. mise checks the archive digest and size, the version, the release workflow, and the transparency-log timestamp. Trust is pinned to mise's GitHub repository ID (`586920414`), so a rename or move to another organization still works, but a different repository that takes over the name is rejected. If the manifest is missing or invalid, mise stops and leaves the current binary in place. Releases 2026.9.2 and older still update with signature-only checks. Custom mirrors must serve the original signed manifests and archives. [#&#8203;13785](https://redirect.github.com/jdx/mise/pull/13785) - `mise self-update` now downloads with mise's own HTTP client and progress display, and extracts only the expected executable from the verified archive. Plugin-update failures during self-update now show as warnings and no longer fail the command. [#&#8203;13783](https://redirect.github.com/jdx/mise/pull/13783) - **Registry:** `timoni` (0.35.0+) and `worktrunk` (0.80.0+) now install from signed packslips, which include completions and skills. Older versions still install through their existing backends, and you can list them with `mise ls-remote aqua:stefanprodan/timoni` or `mise ls-remote aqua:max-sixty/worktrunk`. [#&#8203;13780](https://redirect.github.com/jdx/mise/pull/13780) ##### Added - **Machine-local global miserc.** `~/.config/mise/miserc.local.toml` applies from any directory and overrides fields in the shared global `miserc.toml`. You can use it to pick an environment on one machine without editing shared files. Project miserc files, `MISE_ENV`, and `-E` still take precedence over it. [#&#8203;13778](https://redirect.github.com/jdx/mise/pull/13778) ```toml # ~/.config/mise/miserc.local.toml env = ["work"] ``` - **Command-not-found can install tools you haven't configured (opt-in).** With `not_found_auto_install_registry = true`, running an unknown command installs the matching registry tool at `latest` and adds it to your global config. This only happens when exactly one registry tool provides that command. mise skips commands with several providers, and it skips disabled tools and tools that don't support your OS. The default is `false`. [#&#8203;13781](https://redirect.github.com/jdx/mise/pull/13781) ```toml [settings] not_found_auto_install_registry = true ``` - **`postinstall` that runs on every install.** With `when = "always"`, a tool's `postinstall` command runs on every `mise install` that selects the tool, even when that version is already installed. Dry runs skip it. The plain string form and tables without `when` still run only on a fresh install or repair. [#&#8203;13789](https://redirect.github.com/jdx/mise/pull/13789) ```toml [tools] node = { version = "26", postinstall = { run = "npm install -g corepack", when = "always" } } ``` - **Warnings for outdated lockfile formats.** If a lockfile format was replaced more than six months ago, mise warns once per file during commands like `mise install`, `mise exec`, and task runs. The warning shows the command to fix it: `mise lock --upgrade`, or `mise lock --global --upgrade` for a global config. [#&#8203;13779](https://redirect.github.com/jdx/mise/pull/13779) - **Per-machine email for dotfiles history commits.** The new `[history].git_email` setting sets the commit email, and `{hostname}` is filled in when each commit is made, so you can tell which machine saved a checkpoint. Without the setting, commits still use `mise@localhost`. [#&#8203;13791](https://redirect.github.com/jdx/mise/pull/13791) ```toml [history] git_email = "mise@{hostname}" ``` ##### Fixed - **Paranoid mode:** `--yes`, `MISE_YES=1`, and CI auto-confirmation no longer approve trust for new or edited config files. Unattended runs now fail until you approve the file with `mise trust` or at an interactive prompt. [#&#8203;13796](https://redirect.github.com/jdx/mise/pull/13796) - **npm with pnpm 12:** mise now passes `minimum_release_age` to pnpm as `--config.minimum-release-age`. pnpm 12 silently ignored the camelCase spelling, so the cutoff wasn't applied to transitive dependencies. The new spelling also works on pnpm 10.16+ and 11. [#&#8203;13764](https://redirect.github.com/jdx/mise/pull/13764) ([@&#8203;Nagato-Yuzuru](https://redirect.github.com/Nagato-Yuzuru)) - `mise upgrade --bump` now updates an exact-release request to the latest release with the same prefix, for example `29.1` to `29.1.1`. Before, it kept the old version. [#&#8203;13759](https://redirect.github.com/jdx/mise/pull/13759) ([@&#8203;ryoikarashi](https://redirect.github.com/ryoikarashi)) - `go:` installs that resolve `latest` to a version no longer retry without the `v` prefix after a failure. That extra retry used to hide Go's original error. Explicit unprefixed versions still get the retry, and if both attempts fail, the error now shows both failures. [#&#8203;13794](https://redirect.github.com/jdx/mise/pull/13794) - **Homebrew formula builds:** - Formulas that write files with `Pathname#write` no longer fail after the build with `super: no superclass method 'write'`. This affected generated completions (such as starship) and `inreplace`. [#&#8203;13760](https://redirect.github.com/jdx/mise/pull/13760) ([@&#8203;jacobbednarz](https://redirect.github.com/jacobbednarz)) - Formulas that include Homebrew's `Language::*` mixins (such as `qmk`) no longer fail with a `NameError` while mise reads them. Install-time helpers that mise doesn't support now produce a clear error message. [#&#8203;13328](https://redirect.github.com/jdx/mise/pull/13328) ([@&#8203;waynehoover](https://redirect.github.com/waynehoover)) - Source archives whose URL has no file extension, such as GitHub codeload tarballs, are now detected by their contents and unpacked. Before, they were copied into the build directory unextracted. This also applies to casks. [#&#8203;13750](https://redirect.github.com/jdx/mise/pull/13750) ([@&#8203;jacobbednarz](https://redirect.github.com/jacobbednarz)) ##### Documentation - The landing page now has a seven-minute showreel of mise, and the mise run music video replaces the theme song. [#&#8203;13797](https://redirect.github.com/jdx/mise/pull/13797), [#&#8203;13799](https://redirect.github.com/jdx/mise/pull/13799) ##### New Contributors - [@&#8203;ryoikarashi](https://redirect.github.com/ryoikarashi) made their first contribution in [#&#8203;13759](https://redirect.github.com/jdx/mise/pull/13759) **Full Changelog**: <https://github.com/jdx/mise/compare/vfox-v2026.9.18...v2026.9.17> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. ### [`v2026.9.16`](https://redirect.github.com/jdx/mise/releases/tag/v2026.9.16): : Per-tool libc for aqua tools, monorepo task path aliases, and packslip pins that survive repo renames [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.15...vfox-v2026.9.16) Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in `mise run --no-timings`, `cargo +nightly` and the `outdated`/`upgrade` version comparison, and speeds up shims and config loading. ##### Added - **Per-tool `libc` for aqua tools.** On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such as `aqua:domcyrus/rustnet`. You can now pick the build for a single tool instead of changing the global `libc` setting. [#&#8203;13701](https://redirect.github.com/jdx/mise/pull/13701) ```toml [tools] "aqua:domcyrus/rustnet" = { version = "latest", libc = "musl" } ``` The option accepts `glibc` (or `gnu`) and `musl`. mise never falls back to the other libc for that tool. The option applies to install, `mise lock`, and checksum, signature and provenance lookups, and it is recorded in the lockfile's tool options. A platform that already names a libc (a musl host or a `linux-*-musl` lockfile platform) still wins. A version that is already installed keeps its build until you run `mise install --force`. `mise ls-remote` still uses the host libc. If a registry template uses a variable named `libc`, set it as `vars.libc`. - **Path aliases for monorepo tasks.** Deeply nested config roots can now have a short name. [#&#8203;13756](https://redirect.github.com/jdx/mise/pull/13756) ```toml monorepo_root = true [monorepo] config_roots = ["foo/bar/baz/abc/123"] [monorepo.path_aliases] "123" = "foo/bar/baz/abc/123" ``` `mise run //123:build` runs `//foo/bar/baz/abc/123:build`. Aliases also work in task dependencies, in patterns like `//123:*`, and in child paths like `//123/sub:build`. Each alias must be a single path segment, must point at a configured root, and can't overlap an existing root path. A task's full path is still its canonical name. - **Packslip tools keep installing after a repository rename.** mise now pins GitHub and GitLab packslip projects by the repository ID recorded in the signing certificate, not only by name. If `old/tool` is renamed to `new/tool` under the same owner, `packslip:github.com/old/tool` keeps installing and prints a warning once, asking you to update the config. You don't need `mise packslip forget`. mise refuses a transfer to another owner. It also refuses a different repository that takes over a pinned name, which is how a deleted and re-created name looks. To accept either one, run `mise packslip forget` for the old name, and for a re-created repository also remove the tool's `mise.lock` entries. [#&#8203;13702](https://redirect.github.com/jdx/mise/pull/13702), [#&#8203;13738](https://redirect.github.com/jdx/mise/pull/13738) In lockfile revision 3, the IDs are stored as: ```toml [tools.hk."platforms.linux-x64"] repository_ids = { repository = "922514152", owner = "216188" } ``` - **`mise dot track --allow-plaintext`.** Directly tracking a file with a credential-like name (for example `~/commit-mossy-token.md`) used to report success while every history save quietly left the file out. `mise dot track` now asks whether to save the file in plaintext, and the default answer is No. In non-interactive use, pass `--allow-plaintext`. `--yes` does not approve plaintext. The choice is saved as `allow_plaintext = true` on the `[dotfiles]` entry. For real credentials, use `--encrypt`. [#&#8203;13749](https://redirect.github.com/jdx/mise/pull/13749) - **Registry:** `mise use mbx` now resolves to `mr-boxington`. [#&#8203;13752](https://redirect.github.com/jdx/mise/pull/13752) ##### Fixed - `mise outdated` and upgrade warnings no longer offer an older release as an update when the installed version has a `v` or `V` prefix. For example, `v2.1.280 → 2.1.278` was shown as an update. Versions that differ only in build metadata (for example `1.36.4+k3s1` and `1.36.4+k3s2`) are now treated as equal. [#&#8203;13690](https://redirect.github.com/jdx/mise/pull/13690) ([@&#8203;himkt](https://redirect.github.com/himkt)) - `mise run --no-cache` and `mise tasks run --no-cache` now clone remote `git::` task includes again, and fetch remote tasks that run as dependencies again. Before, both kept using the cached copy. [#&#8203;13697](https://redirect.github.com/jdx/mise/pull/13697) ([@&#8203;irisTa56](https://redirect.github.com/irisTa56)) - `mise run --no-timings` hides each task's "Finished in …" line again, not only the run total. It also overrides `MISE_TASK_TIMINGS=1`. This had regressed in v2025.11.2. [#&#8203;13718](https://redirect.github.com/jdx/mise/pull/13718) - `cargo +nightly` works again with `rust = "nightly"`. Since 2026.8.6 mise installs a dated nightly, so rustup had no toolchain named `nightly`. Depending on rustup's auto-install setting, `cargo +nightly` then either failed or downloaded a second, unpinned nightly. mise now also sets up rustup's `nightly-<host>` toolchain from the pinned nightly, using reflinks or hardlinks. It leaves alone a rustup nightly that is newer or has extra components or targets. Explicitly dated requests such as `nightly-2026-08-13` don't touch it. Existing installs pick this up on their next nightly install, or right away with `mise install -f rust`. [#&#8203;13707](https://redirect.github.com/jdx/mise/pull/13707) - Running `mise dot track` again on a path that is already tracked now reports "already tracked". It no longer prompts, rewrites the config, or records an empty checkpoint. Changed file contents and flags that change the declaration (such as `--no-autosave`) are still saved. [#&#8203;13648](https://redirect.github.com/jdx/mise/pull/13648) - Blob-pack downloads from the remote cache now retry transient stream errors, the same way single blob downloads do. [#&#8203;13715](https://redirect.github.com/jdx/mise/pull/13715) ##### Security - **SLSA provenance must come from the expected signer.** Before, any valid Sigstore signature, even from an unrelated workflow, passed SLSA verification. mise now checks the certificate's URI identity and OIDC issuer against the values configured for the tool: - aqua registry entries: `signer_identity` and `signer_issuer` under `slsa_provenance` - `github:` tools: the `slsa_signer_identity` and `slsa_signer_issuer` tool options (the identity supports `{{version}}` templating) - vfox plugins: `slsa_signer_identity` and `slsa_signer_issuer` returned from `PreInstall` If a tool doesn't configure both values, mise skips the SLSA check and uses any other verification available. For now this applies to the bundled aqua packages that have SLSA metadata but no signer fields. SLSA lock entries are checked again on every install, even when a checksum is present. [#&#8203;13725](https://redirect.github.com/jdx/mise/pull/13725) - Public-key DSSE bundles used by aqua and vfox verification must now have a SHA-256 subject digest that matches the downloaded artifact. Before, a valid bundle could be reused to verify a different download. [#&#8203;13721](https://redirect.github.com/jdx/mise/pull/13721) ##### Performance - Shims no longer run `rustup` checks when `rust` is configured alongside other tools. The same goes for `mise exec` with auto-install disabled. One report measured the `go` shim at about 31 ms with `rust` in the config, compared with 12 ms without it. `mise install`, and `mise exec` with auto-install on, still detect and repair missing rustup components. [#&#8203;13705](https://redirect.github.com/jdx/mise/pull/13705) - Config loading and fuzzy version resolution (for example `node = "24"`) do less work: plugin shorthands are built without checking every registry tool's backends, global-config checks stop resolving symlinks for every tool, and fuzzy matching no longer compiles regexes. [#&#8203;13694](https://redirect.github.com/jdx/mise/pull/13694), [#&#8203;13695](https://redirect.github.com/jdx/mise/pull/13695), [#&#8203;13696](https://redirect.github.com/jdx/mise/pull/13696) ##### Documentation - The task docs now give the correct default job count (8). They also describe the default output mode correctly: `prefix` when tasks run in parallel and `interleave` when they run in sequence. [#&#8203;13716](https://redirect.github.com/jdx/mise/pull/13716) ##### Breaking Changes - **Lockfile revision 3.** New and empty `mise.lock` files are written as `lockfile_version = 3`, and older mise versions reject them. Existing lockfiles keep their revision when mise writes to them. When a revision 2 lockfile gets packslip repository IDs, mise warns and leaves them out. To store them, run `mise lock --upgrade` once everyone who shares the lockfile is on this release. - **SLSA checks for locked tools.** A lockfile entry that requires SLSA now fails with an explanation if the tool has no expected signer configured. To fix it, configure the signer or refresh the entry with `mise lock`. - **Dotfiles history shared across machines.** Older mise versions can't read enrollment metadata that includes `allow_plaintext`. Upgrade every machine that shares the history before you use `--allow-plaintext`. ##### New Contributors - [@&#8203;irisTa56](https://redirect.github.com/irisTa56) made their first contribution in [#&#8203;13697](https://redirect.github.com/jdx/mise/pull/13697) **Full Changelog**: <https://github.com/jdx/mise/compare/vfox-v2026.9.17...v2026.9.16> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. ### [`v2026.9.15`](https://redirect.github.com/jdx/mise/compare/v2026.9.14...v2026.9.15) [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.14...vfox-v2026.9.15) ### [`v2026.9.14`](https://redirect.github.com/jdx/mise/releases/tag/v2026.9.14): : conf.d folder fragments, Stow-style dotfiles options, and mise-versions for any public GitHub repo [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.13...vfox-v2026.9.14) A folder inside any `conf.d` directory now loads as its own config fragment and serves as the config root for the files in it, which gives `[bootstrap].config_roots` users a direct migration path. `[dotfiles]` gains two GNU Stow-style options: relative symlinks and `dot-<name>` sources. Release metadata for any public github.com repo now comes from mise-versions, and the registry can require GitHub attestations for specific tools. #### Added - **conf.d folder fragments.** A folder in a global, system, or project `conf.d` directory now loads as a fragment. Relative paths, `{{ config_root }}`, and task working directories resolve inside that folder, so a bundle can keep its files next to its config. Each folder can hold `mise.toml`, `mise.local.toml`, `mise.<env>.toml`, and `mise.<env>.local.toml`. Folders are not searched recursively, and folders whose names start with `.` are skipped. A folder can be a symlink. Folder fragments load after the single-file fragments in the same `conf.d` (in folder-name order) and before `config.toml`. `mise use`/`mise set` never write to them. [#&#8203;13603](https://redirect.github.com/jdx/mise/pull/13603) ```text ~/.config/mise/conf.d/ ├── git.toml # single-file fragment, unchanged └── git-tools/ # folder fragment ├── mise.toml └── gitconfig ``` ```toml # ~/.config/mise/conf.d/git-tools/mise.toml [dotfiles] "~/.gitconfig" = "gitconfig" # resolves to conf.d/git-tools/gitconfig ``` **Compatibility:** if a directory inside a `conf.d` that mise reads already contains a `mise.toml`, that file now loads. - **Relative dotfile symlinks.** `symlink` and `symlink-each` entries can now point at their source by a relative path, so links keep working when a home directory is mounted at a different path or moved. Turn this on for all entries with `dotfiles.relative_symlinks = true` (or `MISE_DOTFILES_RELATIVE_SYMLINKS=1`), or per entry with `relative = true/false`. When you turn it on, existing absolute links are re-pointed on the next apply. Turning it off does not convert relative links back to absolute ones. This option has no effect on Windows. [#&#8203;13583](https://redirect.github.com/jdx/mise/pull/13583) ```toml [settings] dotfiles.relative_symlinks = true [dotfiles] "~/.config/foo" = { source = "~/dotfiles/foo", mode = "symlink" } # -> ../dotfiles/foo "~/.bashrc" = { source = "~/dotfiles/bashrc", relative = false } # stays absolute ``` - **`dot_prefix` for dotfiles.** With `dot_prefix = true` on a `symlink-each` or directory `copy` entry, any path component named `dot-<name>` deploys as `.<name>` (for example, `home/dot-config/foo` deploys as `~/.config/foo`). `exclude` and `manifest = "git"` still match source names. If two sources map to the same target, apply fails. `mise dot add` refuses to capture into `dot_prefix` entries, and `mise oci` builds use the same mapping. [#&#8203;13585](https://redirect.github.com/jdx/mise/pull/13585) ```toml [dotfiles] "~" = { source = "home", mode = "symlink-each", dot_prefix = true, exclude = ["README.md"] } ``` - **mise-versions for any public github.com repo.** For `github:`, `aqua:`, and `packslip:` tools that aren't in the registry, version listing, release lookup, and attestation lookup now go through mise-versions, so they no longer use your GitHub API rate limit in the common case. Private repos still use your own token against api.github.com. [#&#8203;13584](https://redirect.github.com/jdx/mise/pull/13584) - mise treats the mirror as untrusted. Download URLs must match the configured repo, release tag, and asset name, and mirrored attestations must name the requested repo. - In `paranoid` mode, mise checks a "no attestations" answer from the mirror against GitHub before skipping verification. - If `url_replacements` reroutes GitHub API paths, mise skips mise-versions for that metadata. - If mise-versions fails for any reason other than a 404, mise falls back to api.github.com and logs a warning. - **Registry-required GitHub attestations.** Registry `github:` backends can declare `attestations_since = "<semver>"`. For versions at or after that boundary: - `mise lock` records `github-attestations` provenance. - Installs require a verified attestation for every downloaded asset. This requirement overrides weaker provenance recorded in a lockfile. - A missing attestation is a hard error. 42 registry tools now set this boundary, including `aube`, `aqua`, `pixi`, `ty`, `pandoc`, `fnox`, `doppler`, and `syncthing`. Users who have turned off `github_attestations` are not affected. [#&#8203;13586](https://redirect.github.com/jdx/mise/pull/13586) #### Fixed - **Install lock waits:** when one process is waiting for another to finish installing the same tool version, the message now names the process holding the lock (`waiting for install lock held by pid 61907`). This is usually a shim auto-installing the tool. [#&#8203;13588](https://redirect.github.com/jdx/mise/pull/13588) - **Slow downloads:** mise now warns once per download if throughput stays below 16 KiB/s for a full minute, naming the host and suggesting a mirror. The download is not aborted; `http_download_timeout` is still the hard limit. [#&#8203;13589](https://redirect.github.com/jdx/mise/pull/13589) - **Interrupted installs:** a half-installed version no longer appears in version listings, can't be picked as the latest installed version, and doesn't keep `latest`/`1`/`1.2` runtime symlinks pointing into it. [#&#8203;13596](https://redirect.github.com/jdx/mise/pull/13596) - **`mise prune`:** no longer deletes versions pinned by another project when you run it from a directory whose `.miserc.toml` lists that project in `ignored_config_paths`. The same fix applies to `mise ls --prunable` and the stale-version check in `mise upgrade`. These commands now honor `ignored_config_paths` only from `MISE_IGNORED_CONFIG_PATHS` and global or system `miserc.toml`. [#&#8203;13602](https://redirect.github.com/jdx/mise/pull/13602) - **`mise oci build`:** directory `[dotfiles]` entries (`symlink-each` and directory `copy`) now honor `exclude` and `manifest = "git"`, so the image contains the same files `mise dot apply` deploys. [#&#8203;13591](https://redirect.github.com/jdx/mise/pull/13591) - **pipx/pypi:** `latest` no longer resolves to PEP 440 developmental releases such as `2026.9.16.232951.dev0`, matching what pip and uv do. Local labels like `1.1+gpu.dev0` are still treated as stable. [#&#8203;13601](https://redirect.github.com/jdx/mise/pull/13601) - **pipx/pypi:** `mise use 'pypi:git+ssh://git@github.com/psf/black.git'` now works. Previously, the `@` in `git@` was read as the version separator. [#&#8203;13610](https://redirect.github.com/jdx/mise/pull/13610) - **`MISE_USE_VERSIONS_HOST=0`:** now fetches the version list from the source instead of reusing a cached, possibly older list from the versions host. [#&#8203;13605](https://redirect.github.com/jdx/mise/pull/13605) - **brew source builds:** checksum-pinned formula source downloads now follow HTTPS-to-HTTP mirror redirects (such as those from `ftpmirror.gnu.org`) and still reject tarballs whose checksum doesn't match. This affects Unix only. Every other download still refuses HTTPS-to-HTTP redirects. [#&#8203;13611](https://redirect.github.com/jdx/mise/pull/13611) - **npm backend on Windows:** updating the bundled aube to v2.4.0 fixes lifecycle scripts failing with `EISDIR: illegal operation on a directory, lstat 'C:'` during `npm:` installs. [#&#8203;13608](https://redirect.github.com/jdx/mise/pull/13608) #### Changed - The `[bootstrap].config_roots` deprecation warning now explains how to move each root into a `conf.d` folder, either by moving it or by symlinking it. The removal date (mise 2027.3.3) is unchanged. [#&#8203;13598](https://redirect.github.com/jdx/mise/pull/13598) - Registry: `spin-framework` now installs through aqua by default. The previous backend is still available. [#&#8203;13594](https://redirect.github.com/jdx/mise/pull/13594) by [@&#8203;scop](https://redirect.github.com/scop) **Full Changelog**: <https://github.com/jdx/mise/compare/vfox-v2026.9.15...v2026.9.14> #### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. ### [`v2026.9.13`](https://redirect.github.com/jdx/mise/releases/tag/v2026.9.13): : OpenTelemetry for tasks, shared daemon providers, `mise backends switch`, and declarative dotfile removal [Compare Source](https://redirect.github.com/jdx/mise/compare/vfox-v2026.9.12...vfox-v2026.9.13) `mise run` can now export OpenTelemetry traces and logs (experimental), and experimental daemon providers let several projects and worktrees share one PostgreSQL, CockroachDB, or NATS server, each with its own database or account. Lockfiles no longer switch backends on their own when the registry moves a tool: the new `mise backends switch` command does it when you ask. `[dotfiles]` and `[bootstrap.files]` can now remove files and manage permissions, and `mise bootstrap unapply` removes what a module set up. The experimental `pkgx:` backend has been removed. ##### Highlights - **Observability and shared services (experimental):** task runs export OTLP traces and, if you opt in, task output as logs. Global `[daemon_providers]` run long-lived servers, and projects attach to them with an isolated database or NATS account per checkout. - **Safer lockfiles:** locked tools stay on their locked backend, `mise lock --bump` checks remote versions and fails when it can't, lockfiles no longer record versions that were never confirmed, and tool stubs lock into the project's `mise.lock`. - **Declarative cleanup:** `mode = "absent"`, `remove_empty` templates, permissions-only entries, removal of empty directories mise created, and `mise bootstrap unapply` let a config describe what should *not* be on a machine. ##### Added ##### Tasks - **OpenTelemetry export for `mise run` (experimental).** Each run becomes one trace, with a span per task (grouped by monorepo package) that carries its exit code and redacted args. W3C `TRACEPARENT` is read from the environment and passed to each task, so nested `mise run` calls and instrumented tools appear in the same trace. Nothing is exported unless `otel.enabled = true` **and** an OTLP endpoint is set. Offline mode disables export, and each export times out after 3s by default. A separate `otel.logs = true` setting exports task stdout (INFO) and stderr (WARN) as log records linked to their spans, with redactions applied first. With `otel.logs` on, tasks in `interleave`/`quiet` modes no longer get a TTY; use `--raw` for tasks that need one. [#&#8203;13557](https://redirect.github.com/jdx/mise/pull/13557), [#&#8203;13558](https://redirect.github.com/jdx/mise/pull/13558), [#&#8203;13559](https://redirect.github.com/jdx/mise/pull/13559) (built on work by [@&#8203;MatthiasGrandl](https://redirect.github.com/MatthiasGrandl) and [@&#8203;zeitlinger](https://redirect.github.com/zeitlinger)) ```toml [settings] otel.enabled = true otel.logs = true # optional; exports task output too ``` ```sh export OTEL_EXPORTER_OTLP_ENDPOINT=<your OTLP/HTTP collector URL> mise run build ::: test ``` ##### Daemons (experimental) - **Shared server providers.** Declare long-lived PostgreSQL, CockroachDB, or NATS servers in global config under `[daemon_providers]` and manage them with `mise daemons providers ls|start|stop|restart`. Providers have their own tools, ports, and persistent data. They run in an isolated environment and are not tied to any checkout. [#&#8203;13534](https://redirect.github.com/jdx/mise/pull/13534) - **Per-checkout databases and accounts on a shared server.** A project daemon with `provider = "..."` gets its own database (PostgreSQL/CockroachDB) or its own NATS account with separate subjects and JetStream data. Each checkout path gets a stable name, so worktrees share the server but not the data. Give several daemons the same `resource` name to share data on purpose. Connection env vars point at the right database, and NATS gets an authenticated `NATS_URL`. [#&#8203;13536](https://redirect.github.com/jdx/mise/pull/13536), [#&#8203;13537](https://redirect.github.com/jdx/mise/pull/13537) ```toml # ~/.config/mise/config.toml [daemon_providers.local-postgres] preset = "postgres" version = "18" port = "auto" # project mise.toml [daemons.db] provider = "local-postgres" # resource = "shared_app" # opt in to sharing data ``` ##### Lockfiles and backends - **`mise backends switch`.** When the registry moves a tool to a new backend (as happened with hk and communique moving to `packslip:`), a tool locked to the old backend now stays there. `mise install` and `mise lock` print a warning that points to the new command, which moves lock entries to the registry's backend at the same versions, relocks their platforms, and reinstalls. It supports `--dry-run`, `--global`, and `TOOL@VERSION`. If any relock fails, every lockfile it changed is restored. [#&#8203;13543](https://redirect.github.com/jdx/mise/pull/13543) - **Tool stubs lock into the project's `mise.lock`.** `mise generate tool-stub --lock` now records the stub in the nearest project lockfile (listed under `tool-stubs`), so installs verify the recorded checksums and `--locked`/`MISE_LOCKED=1` accept stubs. Previously the `[lock]` section written into the stub was never used, so checksums were never checked. [#&#8203;13502](https://redirect.github.com/jdx/mise/pull/13502) - **Install from a local archive.** The `http:` backend accepts `file://` URLs. It copies the archive instead of downloading it, still verifies `checksum`, and works offline. [#&#8203;13574](https://redirect.github.com/jdx/mise/pull/13574) ```toml [tools] "http:my-tool" = { version = "1.0.0", url = "file:///opt/archives/my-tool-v1.0.0-linux-x64.tar.gz", checksum = "sha256:..." } ``` - **Checksum mismatch hints for re-uploaded GitHub assets.** When a `github:` or `aqua:` install fails a checksum check, mise asks GitHub for the asset's current digest. If that digest matches the download, the error says the maintainer probably re-uploaded the asset. The install still fails. [#&#8203;13512](https://redirect.github.com/jdx/mise/pull/13512) - **vfox `BackendUninstall` hook.** Backend plugins can define `hooks/backend_uninstall.lua` to clean up outside the install directory. It runs before removal on uninstall, upgrade, and prune. If the hook errors, the install directory is kept. [#&#8203;13522](https://redirect.github.com/jdx/mise/pull/13522) ##### CLI - **`mise search` checks package registries.** Add a prefix to search npm, crates.io, RubyGems, or NuGet (`mise search npm:typescript-language`, `cargo:`, `gem:`, `dotnet:`). `--all` searches every source at once. Plain searches and shell completion still make no registry requests, and `MISE_OFFLINE=1` skips them. [#&#8203;13550](https://redirect.github.com/jdx/mise/pull/13550) - **`mise ls` by backend.** `-b/--backend` (repeatable) filters by backend and also works with `--json`. `--grouped` prints one section per backend. [#&#8203;13530](https://redirect.github.com/jdx/mise/pull/13530) - **Key completion for `mise config get`/`set`.** Tab completes dotted keys, with descriptions, from the schema and from the target file. `--file`, `--global`, and `--system` are respected. [#&#8203;13551](https://redirect.github.com/jdx/mise/pull/13551) - **Coloured help and a logo.** `mise --help` is now coloured on terminals (and respects `NO_COLOR`), wraps at the terminal's real width, and shows the mise logo on `mise`/`mise --help` when there's room. [#&#8203;13449](https://redirect.github.com/jdx/mise/pull/13449) - **Project URLs in the registry.** Registry entries can set a `url`, which appears in `mise tool` (and `mise tool <name> --url`) and in `mise registry --json`. [#&#8203;13533](https://redirect.github.com/jdx/mise/pull/13533) ##### Configuration and hooks - **`.miserc.local.toml`.** Sets per-checkout early config, such as `env = ["native"]`, without editing the shared `.miserc.toml`. At each directory level it is read before `.miserc.toml`. CLI flags and `MISE_ENV` still take precedence. [#&#8203;13440](https://redirect.github.com/jdx/mise/pull/13440) - **`backend` and `install_path` in `MISE_INSTALLED_TOOLS`.** Postinstall hooks can now see where each tool came from and exactly where it was installed. [#&#8203;13421](https://redirect.github.com/jdx/mise/pull/13421) ([@&#8203;garysassano](https://redirect.github.com/garysassano)) - **A configured pnpm overrides Node's bundled pnpm**, whichever order the tools are listed in. [#&#8203;13498](https://redirect.github.com/jdx/mise/pull/13498) ([@&#8203;EMcCormack](https://redirect.github.com/EMcCormack)) ##### Dotfiles - **Choose what a tracked directory saves.** `exclude` and `include` lists on `mode = "track"` entries. Exclusions always win. `include = []` selects nothing. Narrowing a list does not delete the files on other machines. [#&#8203;13418](https://redirect.github.com/jdx/mise/pull/13418), [#&#8203;13432](https://redirect.github.com/jdx/mise/pull/13432) ```toml [dotfiles] "~/.codex" = { mode = "track", include = ["config.toml", "rules/**"], exclude = ["*.log"] } ``` - **Preview before tracking.** `mise dot track --dry-run` and `mise dot paths --preview` show file counts, sizes, exclusions, and skipped nested repositories. Large trees get a warning. [#&#8203;13417](https://redirect.github.com/jdx/mise/pull/13417) - **`mode = "absent"`** removes a file or symlink at the target, with support for OS `variants`. Directories and special files are refused, even with `--force`. [#&#8203;13513](https://redirect.github.com/jdx/mise/pull/13513) - **`permissions` key.** Overrides the mode of copy, template, and content entries, or manages only the permissions of an existing file such as `~/.ssh/config`. Status, diff, and apply report and fix drift. The key is ignored on Windows. [#&#8203;13514](https://redirect.github.com/jdx/mise/pull/13514) - **`remove_empty = true` on templates** removes the target when the template renders empty. A file you have edited since mise last wrote it is kept unless you pass `--force`. [#&#8203;13515](https://redirect.github.com/jdx/mise/pull/13515) - **Empty parent directories mise created** are removed along with their target on apply and unapply. This only applies inside `$HOME` and never to directories that already existed. [#&#8203;13518](https://redirect.github.com/jdx/mise/pull/13518) - **Warnings from background captures**, such as credential-named files saved in plaintext, are now shown by the next `mise dot` command or `mise bootstrap`. Previously they only went to the watcher logs. [#&#8203;13483](https://redirect.github.com/jdx/mise/pull/13483) ##### Bootstrap - **`mise bootstrap unapply <ENV>...`** removes the files, directories, user services, and dotfile entries a module added after you deselect it. Anything another environment still declares is kept. Supports `--dry-run` and `--force`. [#&#8203;13441](https://redirect.github.com/jdx/mise/pull/13441) - **Permissions-only `[bootstrap.files]` entries.** Declare only `mode`/`owner`/`group` to manage a file's metadata without taking over its contents. [#&#8203;13511](https://redirect.github.com/jdx/mise/pull/13511) - **`remove_empty = true`** on templated `[bootstrap.files]` removes the target when the template renders empty. [#&#8203;13510](https://redirect.github.com/jdx/mise/pull/13510) - **More systemd directives:** `before`, `binds_to`, `part_of`, `conflicts`, `exec_start_pre`, `exec_start_post`, and `exec_stop_post`. `~` now expands after exec prefixes such as `-~/bin/check`. [#&#8203;13526](https://redirect.github.com/jdx/mise/pull/13526) ##### Registry - Added `mole` ([#&#8203;13363](https://redirect.github.com/jdx/mise/pull/13363), [@&#8203;casparbreloh](https://redirect.github.com/casparbreloh)), `reviewdog` ([#&#8203;13562](https://redirect.github.com/jdx/mise/pull/13562), [@&#8203;takumin](https://redirect.github.com/takumin)), and `nim` ([#&#8203;13461](https://redirect.github.com/jdx/mise/pull/13461), [@&#8203;elijahr](https://redirect.github.com/elijahr)). `aube` now points at `aubepkg/aube` ([#&#8203;13541](https://redirect.github.com/jdx/mise/pull/13541)). ##### Fixed ##### Tools, installs, and lockfiles - `mise cache prune` could delete files from installed tools: it followed symlinks out of the cache into install directories and left npm cache entries half-empty. It now never follows symlinks and removes stale entries as a whole. `cache_prune_age = "0s"` now also turns off `mise cache prune`. [#&#8203;13424](https://redirect.github.com/jdx/mise/pull/13424) - `mise lock --bump` now checks remote versions for every selector (for example `"6"`, not only `latest`) and fails when the version list can't be fetched, where it used to exit 0 with stale versions. Packslip registry tools no longer call `api.github.com` in normal use, which avoids rate-limit errors. [#&#8203;13544](https://redirect.github.com/jdx/mise/pull/13544) - `mise lock` refuses to record an aqua version that only resolved to its own request string because the version list failed to load. When such an install fails, the error now says why. [#&#8203;13552](https://redirect.github.com/jdx/mise/pull/13552) - `mise lock --global` no longer skips global tools that the project config shadows, and no longer overwrites a global pin with the project's version. [#&#8203;13547](https://redirect.github.com/jdx/mise/pull/13547) - `mise lock` no longer tries to lock `3.9.6~aube~<digest>`-style install directory names for npm and pipx tools. [#&#8203;13542](https://redirect.github.com/jdx/mise/pull/13542) - `mise upgrade --bump tool@selector` now saves the selector to the config, as `mise use` does. [#&#8203;13179](https://redirect.github.com/jdx/mise/pull/13179) ([@&#8203;zeitlinger](https://redirect.github.com/zeitlinger)) - npm packages whose lifecycle scripts call back into the package manager through `npm_execpath` (such as `re2`) now run through aube, not mise's task runner. [#&#8203;13484](https://redirect.github.com/jdx/mise/pull/13484) - Command wrappers such as `[wrappers.cargo] command = "mbx"` now install the missing provider tool before running it. [#&#8203;13532](https://redirect.github.com/jdx/mise/pull/13532) - A GitHub, GitLab, or Forgejo token containing a newline or other invalid header character now gives a redacted error, where mise used to crash. Tokens read from `*_tokens.toml` are trimmed. [#&#8203;13488](https://redirect.github.com/jdx/mise/pull/13488) - `.tar.zst` archives compressed with a long window now extract. [#&#8203;13566](https://redirect.github.com/jdx/mise/pull/13566) - aqua creates `.mise-bins` for registry files listed by name only ([#&#8203;13525](https://redirect.github.com/jdx/mise/pull/13525)), and reports only the provenance and signature checks mise actually performs ([#&#8203;13549](https://redirect.github.com/jdx/mise/pull/13549)). - Renaming a raw Windows download with `bin` keeps the `.exe` extension. [#&#8203;13529](https://redirect.github.com/jdx/mise/pull/13529) - `brew-cask` percent-decodes artifact filenames taken from cask URLs. [#&#8203;13431](https://redirect.github.com/jdx/mise/pull/13431) - `mise self-update` fails before downloading when it can't write to the install directory. [#&#8203;13453](https://redirect.github.com/jdx/mise/pull/13453) - Per-tool progress bars line up in interactive installs. [#&#8203;13494](https://redirect.github.com/jdx/mise/pull/13494) ##### Tasks - A metadata-only `[tasks.hello]` block no longer creates an empty task that hides `mise-tasks/hello.sh`. It now configures the script, and dependency groups keep their `depends` when another config layer adds metadata. [#&#8203;13448](https://redirect.github.com/jdx/mise/pull/13448) - A `run` under a file task's name now replaces the script. [#&#8203;13458](https://redirect.github.com/jdx/mise/pull/13458) (see Breaking Changes) - Dependencies that use optional usage flags or args in templates are no longer dropped when those values are omitted. [#&#8203;13569](https://redirect.github.com/jdx/mise/pull/13569) ([@&#8203;nettlesh](https://redirect.github.com/nettlesh)) - When parallel tasks fail together, only the task that caused the stop prints its error chain. [#&#8203;13556](https://redirect.github.com/jdx/mise/pull/13556) ##### Shell, CLI, and platforms - The bash `mise` function now embeds the path to the mise binary, so it keeps working in shells that copied the function but not `$__MISE_EXE` (for example Claude Code's Bash tool on Windows). [#&#8203;13491](https://redirect.github.com/jdx/mise/pull/13491) - Windows release builds no longer abort with "panic in a function that cannot unwind" when a vfox plugin hits a Lua error. [#&#8203;13503](https://redirect.github.com/jdx/mise/pull/13503) - `cargo install mise` for Windows targets works again. [#&#8203;13573](https://redirect.github.com/jdx/mise/pull/13573) - Help and completion output exit quietly when the reader closes the pipe. [#&#8203;13575](https://redirect.github.com/jdx/mise/pull/13575), [#&#8203;13527](https://redirect.github.com/jdx/mise/pull/13527) ##### Dotfiles, history, and bootstrap - On Windows, user services that set `environment` no longer run through `cmd.exe` behind a console window that killed the service when closed, and shell metacharacters in the environment are no longer rejected. The history watcher also runs without a console window. [#&#8203;13429](https://redirect.github.com/jdx/mise/pull/13429), [#&#8203;13428](https://redirect.github.com/jdx/mise/pull/13428) - `mise bootstrap` now runs `[history.reload]` commands after its dotfiles phase writes matching files, as `mise dot apply` does. [#&#8203;13509](https://redirect.github.com/jdx/mise/pull/13509) - Nested Git repositories inside tracked directories are skipped and reported, not saved as commit pointers. Track the repository's root directly to capture its files. [#&#8203;13416](https://redirect.github.com/jdx/mise/pull/13416) - Global history exclusions apply consistently to tracked paths ([#&#8203;13427](https://redirect.github.com/jdx/mise/pull/13427)), and files left out by credential filtering are reported ([#&#8203;13415](https://redirect.github.com/jdx/mise/pull/13415)). - A postgres daemon that would start as root now fails early with a clear error. [#&#8203;13567](https://redirect.github.com/jdx/mise/pull/13567) ##### Security - When `[bootstrap.files]` and `[bootstrap.directories]` changes run as root, mise no longer follows a symlink in the path that another user could have planted (CWE-59). Status and dry-run show these paths as `unknown`, and apply refuses them. Symlinks inside root-owned directories that no one else can write, such as `/etc` on macOS, still work. [#&#8203;13539](https://redirect.github.com/jdx/mise/pull/13539), [#&#8203;13546](https://redirect.github.com/jdx/mise/pull/13546) ##### Breaking Changes - **The experimental `pkgx:` backend is removed.** Entries like `"pkgx:stedolan.github.io/jq"` no longer resolve; switch to the registry shorthand (`jq`) or `aqua:`/`github:`. Lockfiles with pkgx sections still load, and those sections are dropped the next time mise writes the file. The `pkgx` registry entry for the pkgx CLI itself is unchanged. [#&#8203;13555](https://redirect.github.com/jdx/mise/pull/13555) - **Locked tools keep their locked backend.** A short-name tool no longer follows the registry to a new backend if `mise.lock` records a different one. Run `mise backends switch` to move it. [#&#8203;13543](https://redirect.github.com/jdx/mise/pull/13543) - **TOML commands replace file tasks.** `[tasks."hello.sh"] run = ...` used to be ignored and now runs. `[tasks.hello] run = ...` no longer leaves `hello.sh` available as a separate task. To keep both, give the inline command its own name. [#&#8203;13458](https://redirect.github.com/jdx/mise/pull/13458) - **`mise generate tool-stub --lock` needs a project config above the stub.** It writes to that project's `mise.lock` and no longer pins the stub's `version`. Any old `[lock]` section is ignored and removed. Older mise releases drop `tool-stubs` from `mise.lock`. [#&#8203;13502](https://redirect.github.com/jdx/mise/pull/13502) - **Dotfiles `include`/`exclude` need current mise on every machine.** Upgrade every machine that shares the dotfiles setup before using `include` lists. New checkpoints use schema version 2, which older clients can't roll back. [#&#8203;13432](https://redirect.github.com/jdx/mise/pull/13432) - **Recursive `[bootstrap.directories]` removals** always run as root, so a path that crosses a symlink in a user-writable directory is now refused, even under `$HOME`. Declare the resolved path instead. [#&#8203;13546](https://redirect.github.com/jdx/mise/pull/13546) ##### New Contributors - [@&#8203;EMcCormack](https://redirect.github.com/EMcCormack) made their first contribution in [#&#8203;13498](https://redirect.github.com/jdx/mise/pull/13498) - [@&#8203;elijahr](https://redirect.github.com/elijahr) made their first contribution in [#&#8203;13461](https://redirect.github.com/jdx/mise/pull/13461) - [@&#8203;takumin](https://redirect.github.com/takumin) made their first contribution in [#&#8203;13562](https://redirect.github.com/jdx/mise/pull/13562) **Full Changelog**: <https://github.com/jdx/mise/compare/v2026.9.12...v2026.9.13> ##### 💚 Sponsor mise mise is built and maintained by [@&#8203;jdx](https://redirect.github.com/jdx), an open source developer at [**entire.io**](https://entire.io/), the title sponsor of his open source work. If mise saves you or your team time, please consider becoming an [individual or company sponsor](https://jdx.dev/sponsors.html). Your support funds ongoing development and helps keep mise fast, free, and independent. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/prometheus/client_java). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 1d5f3c4 commit cb169ed

16 files changed

Lines changed: 32 additions & 32 deletions

‎.github/workflows/acceptance-tests.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
1616
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
1717
with:
18-
version: v2026.9.12
19-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
18+
version: v2026.9.17
19+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
2020
- name: Run acceptance tests
2121
run: mise run acceptance-test

‎.github/workflows/api-diff.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,8 @@ jobs:
3434
persist-credentials: false
3535
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
3636
with:
37-
version: v2026.9.12
38-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
37+
version: v2026.9.17
38+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
3939
- name: Cache local Maven repository
4040
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
4141
with:

‎.github/workflows/build.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,8 @@ jobs:
1414
persist-credentials: false
1515
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
1616
with:
17-
version: v2026.9.12
18-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
17+
version: v2026.9.17
18+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
1919
- name: Cache local Maven repository
2020
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
2121
with:

‎.github/workflows/bump-api-diff-baseline.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,8 @@ jobs:
3535
persist-credentials: true
3636
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
3737
with:
38-
version: v2026.9.12
39-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
38+
version: v2026.9.17
39+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
4040
- name: Cache local Maven repository
4141
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
4242
with:

‎.github/workflows/generate-protobuf.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ jobs:
2020
persist-credentials: false
2121
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
2222
with:
23-
version: v2026.9.12
24-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
23+
version: v2026.9.17
24+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
2525
- name: Cache local Maven repository
2626
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
2727
with:

‎.github/workflows/github-pages.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,8 @@ jobs:
3939
fetch-depth: 0
4040
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
4141
with:
42-
version: v2026.9.12
43-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
42+
version: v2026.9.17
43+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
4444
cache: "false"
4545
- name: Setup Pages
4646
id: pages

‎.github/workflows/java-version-matrix-tests.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,8 +33,8 @@ jobs:
3333
- name: Set up mise
3434
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
3535
with:
36-
version: v2026.9.12
37-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
36+
version: v2026.9.17
37+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
3838

3939
- name: Cache local Maven repository
4040
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0

‎.github/workflows/jmx-exporter-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,8 @@ jobs:
2424
persist-credentials: false
2525
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
2626
with:
27-
version: v2026.9.12
28-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
27+
version: v2026.9.17
28+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
2929
- name: Cache local Maven repository
3030
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
3131
with:

‎.github/workflows/lint.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,8 @@ jobs:
2323
- name: Setup mise
2424
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
2525
with:
26-
version: v2026.9.12
27-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
26+
version: v2026.9.17
27+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
2828

2929
- name: Lint
3030
env:

‎.github/workflows/micrometer-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ jobs:
3232
persist-credentials: false
3333
- uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
3434
with:
35-
version: v2026.9.12
36-
sha256: e79ae57945034903aee8aa2ea66b4c7ca9cd4f4edd5a8a78a589cbae6d0f428a
35+
version: v2026.9.17
36+
sha256: 63049bc35fb9065e8dc35ac8b25fdae53e9bd6f1885a843aedeba398e046a1ee
3737
- name: Cache local Maven repository
3838
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
3939
with:

0 commit comments

Comments
 (0)