Repository navigation
Update dependency jdx/mise to v2026.9.17 - #6296
Merged
Merged
Conversation
Contributor
|
Renovate Jira issue ID: SONARJAVA-7128 |
Contributor
|
vdiez
approved these changes
Oct 5, 2026
vdiez
left a comment
Contributor
There was a problem hiding this comment.
Auto-approved: Renovate dependency update.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.





This PR contains the following updates:
2026.9.16→2026.9.17v2026.10.2(+3)Release Notes
jdx/mise (jdx/mise)
v2026.9.17: : Self-update waits 24 hours for new releases and verifies signed packslipsCompare Source
mise self-updateand the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local globalmiserc, an opt-in way for command-not-found to install registry tools, and apostinstallmode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode.Changed
Self-update and installs wait for a minimum release age. When no version is pinned,
mise self-update, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with--force. The age is taken from, in order:--minimum-release-age, thenself_update.minimum_release_age, then the globalminimum_release_agesetting, then24h. Use0sto get releases right away. #13782mise self-update --minimum-release-age 0s curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d shThe installer reads environment variables only (
MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE,MISE_MINIMUM_RELEASE_AGE), and it accepts integers/m/h/d/wdurations. A saved copy of the installer no longer pins a default version, so setMISE_VERSIONif you need reproducible installs.Self-update verifies signed packslips. For releases v2026.9.3 and later,
mise self-updatenow requires a valid signed packslip, on top of the embedded archive signature it already checked. mise checks the archive digest and size, the version, the release workflow, and the transparency-log timestamp. Trust is pinned to mise's GitHub repository ID (586920414), so a rename or move to another organization still works, but a different repository that takes over the name is rejected. If the manifest is missing or invalid, mise stops and leaves the current binary in place. Releases 2026.9.2 and older still update with signature-only checks. Custom mirrors must serve the original signed manifests and archives. #13785mise self-updatenow downloads with mise's own HTTP client and progress display, and extracts only the expected executable from the verified archive. Plugin-update failures during self-update now show as warnings and no longer fail the command. #13783Registry:
timoni(0.35.0+) andworktrunk(0.80.0+) now install from signed packslips, which include completions and skills. Older versions still install through their existing backends, and you can list them withmise ls-remote aqua:stefanprodan/timoniormise ls-remote aqua:max-sixty/worktrunk. #13780Added
Machine-local global miserc.
~/.config/mise/miserc.local.tomlapplies from any directory and overrides fields in the shared globalmiserc.toml. You can use it to pick an environment on one machine without editing shared files. Project miserc files,MISE_ENV, and-Estill take precedence over it. #13778Command-not-found can install tools you haven't configured (opt-in). With
not_found_auto_install_registry = true, running an unknown command installs the matching registry tool atlatestand adds it to your global config. This only happens when exactly one registry tool provides that command. mise skips commands with several providers, and it skips disabled tools and tools that don't support your OS. The default isfalse. #13781postinstallthat runs on every install. Withwhen = "always", a tool'spostinstallcommand runs on everymise installthat selects the tool, even when that version is already installed. Dry runs skip it. The plain string form and tables withoutwhenstill run only on a fresh install or repair. #13789Warnings for outdated lockfile formats. If a lockfile format was replaced more than six months ago, mise warns once per file during commands like
mise install,mise exec, and task runs. The warning shows the command to fix it:mise lock --upgrade, ormise lock --global --upgradefor a global config. #13779Per-machine email for dotfiles history commits. The new
[history].git_emailsetting sets the commit email, and{hostname}is filled in when each commit is made, so you can tell which machine saved a checkpoint. Without the setting, commits still usemise@localhost. #13791Fixed
--yes,MISE_YES=1, and CI auto-confirmation no longer approve trust for new or edited config files. Unattended runs now fail until you approve the file withmise trustor at an interactive prompt. #13796minimum_release_ageto pnpm as--config.minimum-release-age. pnpm 12 silently ignored the camelCase spelling, so the cutoff wasn't applied to transitive dependencies. The new spelling also works on pnpm 10.16+ and 11. #13764 (@Nagato-Yuzuru)mise upgrade --bumpnow updates an exact-release request to the latest release with the same prefix, for example29.1to29.1.1. Before, it kept the old version. #13759 (@ryoikarashi)go:installs that resolvelatestto a version no longer retry without thevprefix after a failure. That extra retry used to hide Go's original error. Explicit unprefixed versions still get the retry, and if both attempts fail, the error now shows both failures. #13794Pathname#writeno longer fail after the build withsuper: no superclass method 'write'. This affected generated completions (such as starship) andinreplace. #13760 (@jacobbednarz)Language::*mixins (such asqmk) no longer fail with aNameErrorwhile mise reads them. Install-time helpers that mise doesn't support now produce a clear error message. #13328 (@waynehoover)Documentation
New Contributors
Full Changelog: jdx/mise@vfox-v2026.9.18...v2026.9.17
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (in timezone CET)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.