mise-en-place

jdx/mise last check 317 releases today
Notes

The front-end to your dev env Pronounced "MEEZ ahn plahs"

Release notes
v2026.9.17: Self-update waits 24 hours for new s and verifies signed packslips · today
view on github

mise self-update and the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local global miserc, an opt-in way for command-not-found to install registry tools, and a postinstall mode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode.

Changed

  • Self-update and installs wait for a minimum release age. When no version is pinned, mise self-update, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with --force. The age is taken from, in order: --minimum-release-age, then self_update.minimum_release_age, then the global minimum_release_age setting, then 24h. Use 0s to get releases right away. #13782

    [settings]
    self_update.minimum_release_age = "7d"
    
    mise self-update --minimum-release-age 0s
    curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d sh
    

    The installer reads environment variables only (MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE, MISE_MINIMUM_RELEASE_AGE), and it accepts integer s/m/h/d/w durations. A saved copy of the installer no longer pins a default version, so set MISE_VERSION if you need reproducible installs.

  • Self-update verifies signed packslips. For releases v2026.9.3 and later, mise self-update now requires a valid signed packslip, on top of the embedded archive signature it already checked. mise checks the archive digest and size, the version, the release workflow, and the transparency-log timestamp. Trust is pinned to mise's GitHub repository ID (586920414), so a rename or move to another organization still works, but a different repository that takes over the name is rejected. If the manifest is missing or invalid, mise stops and leaves the current binary in place. Releases 2026.9.2 and older still update with signature-only checks. Custom mirrors must serve the original signed manifests and archives. #13785

  • mise self-update now downloads with mise's own HTTP client and progress display, and extracts only the expected executable from the verified archive. Plugin-update failures during self-update now show as warnings and no longer fail the command. #13783

  • Registry: timoni (0.35.0+) and worktrunk (0.80.0+) now install from signed packslips, which include completions and skills. Older versions still install through their existing backends, and you can list them with mise ls-remote aqua:stefanprodan/timoni or mise ls-remote aqua:max-sixty/worktrunk. #13780

Added

  • Machine-local global miserc. ~/.config/mise/miserc.local.toml applies from any directory and overrides fields in the shared global miserc.toml. You can use it to pick an environment on one machine without editing shared files. Project miserc files, MISE_ENV, and -E still take precedence over it. #13778

    # ~/.config/mise/miserc.local.toml
    env = ["work"]
    
  • Command-not-found can install tools you haven't configured (opt-in). With not_found_auto_install_registry = true, running an unknown command installs the matching registry tool at latest and adds it to your global config. This only happens when exactly one registry tool provides that command. mise skips commands with several providers, and it skips disabled tools and tools that don't support your OS. The default is false. #13781

    [settings]
    not_found_auto_install_registry = true
    
  • postinstall that runs on every install. With when = "always", a tool's postinstall command runs on every mise install that selects the tool, even when that version is already installed. Dry runs skip it. The plain string form and tables without when still run only on a fresh install or repair. #13789

    [tools]
    node = { version = "26", postinstall = { run = "npm install -g corepack", when = "always" } }
    
  • Warnings for outdated lockfile formats. If a lockfile format was replaced more than six months ago, mise warns once per file during commands like mise install, mise exec, and task runs. The warning shows the command to fix it: mise lock --upgrade, or mise lock --global --upgrade for a global config. #13779

  • Per-machine email for dotfiles history commits. The new [history].git_email setting sets the commit email, and {hostname} is filled in when each commit is made, so you can tell which machine saved a checkpoint. Without the setting, commits still use mise@localhost. #13791

    [history]
    git_email = "mise@{hostname}"
    

Fixed

  • Paranoid mode: --yes, MISE_YES=1, and CI auto-confirmation no longer approve trust for new or edited config files. Unattended runs now fail until you approve the file with mise trust or at an interactive prompt. #13796
  • npm with pnpm 12: mise now passes minimum_release_age to pnpm as --config.minimum-release-age. pnpm 12 silently ignored the camelCase spelling, so the cutoff wasn't applied to transitive dependencies. The new spelling also works on pnpm 10.16+ and 11. #13764 (@Nagato-Yuzuru)
  • mise upgrade --bump now updates an exact-release request to the latest release with the same prefix, for example 29.1 to 29.1.1. Before, it kept the old version. #13759 (@ryoikarashi)
  • go: installs that resolve latest to a version no longer retry without the v prefix after a failure. That extra retry used to hide Go's original error. Explicit unprefixed versions still get the retry, and if both attempts fail, the error now shows both failures. #13794
  • Homebrew formula builds:
    • Formulas that write files with Pathname#write no longer fail after the build with super: no superclass method 'write'. This affected generated completions (such as starship) and inreplace. #13760 (@jacobbednarz)
    • Formulas that include Homebrew's Language::* mixins (such as qmk) no longer fail with a NameError while mise reads them. Install-time helpers that mise doesn't support now produce a clear error message. #13328 (@waynehoover)
    • Source archives whose URL has no file extension, such as GitHub codeload tarballs, are now detected by their contents and unpacked. Before, they were copied into the build directory unextracted. This also applies to casks. #13750 (@jacobbednarz)

Documentation

  • The landing page now has a seven-minute showreel of mise, and the mise run music video replaces the theme song. #13797, #13799

New Contributors

  • @ryoikarashi made their first contribution in #13759

Full Changelog: https://github.com/jdx/mise/compare/vfox-v2026.9.18...v2026.9.17

💚 Sponsor mise

mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.