mise-en-place

jdx/mise last check 319 releases today
Notes

The front-end to your dev env Pronounced "MEEZ ahn plahs"

Release notes
v2026.10.0: Stricter signer checks for cosign and GitHub attestations, trust for inline options in .tool-s · today
view on github

This release tightens supply-chain verification. Keyless cosign bundles must now match a pinned signer identity, and GitHub attestation workflow checks no longer accept partial matches. It also closes a .tool-versions trust gap that could leak GITHUB_TOKEN, adds a per-cask appdir option for Homebrew casks, and fixes problems with locked SLSA installs, musl hosts and mise backends switch.

Security

  • Inline tool options in .tool-versions now require trust. This is the .tool-versions version of the mise.toml fix in 2026.9.18. An untrusted project could ship a github: entry with inline options, such as [api_url=...], pointing at another host. Commands such as mise ls, env, current, outdated and latest would then send your GITHUB_TOKEN to that host without asking for trust. Any entry whose tool name contains [ now requires trust, the same as Tera templates. Plain lines like node 20.0.0 still load without trust, and a [ inside a comment is ignored. Run mise trust for projects you rely on. MISE_SAFE=1 still skips trust checks. (GHSA-wcqh-j26q-g44x) #13869
  • Keyless cosign verification now checks who signed. Before, the aqua backend only checked that a bundle chained to Sigstore's Fulcio CA. Any GitHub Actions workflow in any repository can get such a certificate, so a bundle signed by the wrong workflow would still pass. mise now applies the registry's --certificate-identity[-regexp], --certificate-oidc-issuer[-regexp] and --certificate-github-workflow-{repository,ref,name,trigger,sha} options to the signing certificate. It does this for both current and legacy bundles. Keyless verification now requires a pinned identity, and an unknown or empty --certificate-* option is an error. Key-based verification (--key) is unchanged. Registry patterns that use RE2 \Q…\E quoted literals, such as the one for vfox, are supported. #13875, #13879
  • GitHub attestation signer workflow matching is anchored. The expected signer_workflow must now match the end of the certificate's workflow path as whole path segments. Before, it was a substring match against the whole identity, so a longer workflow file name such as release.yml.evil.yml, or a ref that contained the expected path, would pass. An empty signer_workflow now fails verification. Both the bare form (.github/workflows/release.yml) and the repository-qualified form (owner/repo/.github/workflows/release.yml) still work. #13877

Added

  • Per-cask app directories. A brew-cask: bootstrap package can set its own appdir. This overrides the global MISE_BREW_CASK_OPT_APPDIR setting, expands ~/, and also applies to the cask's dependencies. #13865

    [bootstrap.packages]
    "brew-cask:1password" = { appdir = "/Applications" }
    

    The setting only applies to installs and upgrades: apps that are already installed are not moved. A first install into a new appdir won't replace an existing app it doesn't own unless you set adopt = true. Other package managers ignore appdir and print a warning.

  • slsa_signer_identity and slsa_signer_issuer options for aqua tools. These work the same as in the github backend. They let mise lock verify and record SLSA provenance for packages whose registry entry has no signer, such as aqua:google/osv-scanner. You must set both options to non-empty strings, and together they override any signer in the registry, including version overrides. #13856

  • Registry: cloudflare-cf, Cloudflare's cf CLI, which is in beta and installs from npm:cf. It provides the cf and cloudflare binaries. Pin a beta version for now, such as mise use cloudflare-cf@1.0.0-beta.10. An unpinned install currently resolves to an unrelated old 0.x release. #13871

  • Docs: a new Releases page (under About in the docs) shows a timeline of release sizes, the issues each release resolved, and expandable release notes. #13855

Fixed

  • Locked SLSA installs work again without a registry signer. Since 2026.9.17, a lockfile that recorded a checksum and SLSA provenance failed with "Aqua registry metadata has no signer_identity and signer_issuer" for tools such as aqua:google/osv-scanner and aqua:fluxcd/flux2. A lock entry with a checksum and recorded provenance is now trusted for SLSA too: the install only checks the artifact digest, as it already did for other provenance types. locked_verify_provenance or paranoid mode still re-verify and still require a signer. #13856
  • aqua on musl hosts. On Alpine and other musl hosts, an aqua tool whose registry entry only names a glibc build (such as zizmor) failed with "no asset found: ...-unknown-linux-musl...". mise now installs the asset the registry names. The binary still needs glibc or gcompat to run. mise lock for linux-x64-musl records the same asset. #13857
  • mise backends switch handles stale lock entries. Sometimes mise install warned that a tool was locked to a replaced backend, for example asdf:clojure instead of vfox:jdx/vfox-clojure, but mise backends switch then reported there was nothing to switch. This happened when the config's version no longer matched the lock entry. The command now switches those entries too. Entries at a version the config no longer resolves to are relocked at the config's version and reported as replacing stale <tool>@<version>. #13859
  • Ctrl-C exits with status 130. Interrupting mise install, upgrade, exec and similar commands used to exit with 1, the same as an ordinary failure. They now exit with 130 (128 + SIGINT), matching mise run, so shells and scripts can tell when a user interrupted. A repeated Ctrl-C during mise run also exits with 130. This applies on Unix and Windows. #13862
  • Declining a trust prompt skips the config for that run. Before, declining still failed the current command with "not trusted". #13868
  • The one-time startup migration for stale latest runtime directories has been removed. It was due to expire in this release and would have blocked normal installs. mise install still repairs a stale latest directory, but passive commands such as mise ls no longer touch it. #13868
  • Stale dotfile history watchers are diagnosed. A history watcher started on an older mise can fail every capture with an unknown-field error for newer settings such as exclude. mise doctor and mise dot status now report that the watcher is outdated and tell you to run mise bootstrap services apply, which restarts it. #13864
  • Java: the missing-metadata error now names the target platform, for example no metadata found for version zulu-8 on windows-arm64. #13873 (@jsiu93)

Breaking Changes

  • --from-git removed from mise bootstrap. mise bootstrap --from-git and mise bootstrap remote --from-git now fail with an unexpected-argument error. Use --adopt, which has been the documented flag since 2026.9.3: #13872

    mise bootstrap --adopt git@github.com:me/dotfiles.git
    
  • vfox tool plugins that use keyless cosign must pin an identity. If a PreInstall attestation sets cosign_sig_or_bundle_path without cosign_public_key_path, it must also set cosign_certificate_identity or cosign_certificate_identity_regexp. You can also set cosign_certificate_oidc_issuer. Without an identity, the attestation is rejected. Registry entries that already work with the aqua CLI are not affected. #13875

  • Alpine/musl: if a registry entry names a gnu asset but the release also ships a musl build, mise now installs the gnu build. Before, it switched to musl. Set libc = "musl" on that tool to keep the musl build. #13857

  • Exit code on Ctrl-C: scripts that checked for exit status 1 after an interrupt should now check for 130. #13862

New Contributors

  • @jsiu93 made their first contribution in #13873

Full Changelog: https://github.com/jdx/mise/compare/vfox-v2026.9.20...v2026.10.0

💚 Sponsor mise

mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.