Update dependency jdx/mise to v2026.7.14 - #321
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/jdx-mise-2026.x
branch
from
July 29, 2026 17:12
9b450ba to
ec6c685
Compare
gtbuchanan
approved these changes
Jul 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.7.12→2026.7.14v2026.7.16(+1)Release Notes
jdx/mise (jdx/mise)
v2026.7.14: : Multi-asset GitHub installs, safer defaults, and Windows pipCompare Source
This release adds overlay installs for GitHub-based tools, closes a config-trust security gap around default shell arguments, and lands a wide batch of correctness fixes across tasks, lockfiles, npm, Swift, brew casks, and Windows Python.
Added
github: the GitHub/GitLab/Forgejo release backend now accepts
additional_asset_patterns, so a single install can overlay multiple release archives from the same tag into one installation directory. Each supplemental artifact is locked and verified (checksums and provenance) on its own, and--lockedfails if the recorded set no longer matches. This models release layouts like Ollama's optional ROCm archive without making a large payload unconditional. (#11272 by @jdx)npm: new
allow_low_downloadstool option lets an embedded aube install bypass the weekly-download popularity gate for the requested package only, so curated tools likebibtex-tidyandpurtyinstall again withoutnpm.shell_out. Transitive dependencies still hit the gate. (#11305 by @jdx)env: structured env files (
env._.fileloading JSON/YAML/TOML) support an explicitexpand = trueoption for shell-style variable expansion, including references to earlier values. See Fixed below for the default-behavior change. (#11269 by @jdx)Fixed
env_shell_expandwas on. That corrupted literals such as bcrypt-style$6$salt$hashand could pull in matching process-environment values. Opt back into expansion withexpand = true. (#11269 by @jdx)pipis now usable on fresh Windows installs. mise synthesizespip.cmd/pip3.cmdwrappers, adds the install'sScriptsdirectory to PATH so pip-installed console scripts resolve, and fixes default-package installation on Windows. (#11278 by @JamBalaya56562).exerelease assets are now preferred on Windows, so tools that ship both an extensionless and.exebinary no longer install the non-runnable one and fail with "cannot find binary path". (#11257 by @gologames)github_tokens.toml, OAuth, env var, etc.) and includes GitHub's response and a remediation hint, instead of a bare401 Unauthorized. (#11236 by @Marukome0743)gdscript-formatter-macos-aarch64) is now renamed to its clean name on PATH, matching the existing behavior for single-file downloads. (#11232 by @Marukome0743)system_commandin lifecycle blocks are supported, and artifact links into root-owned directories like/usr/local/binnow elevate through mise's sudo policy instead of failing with permission errors. Fixes installingdocker-desktop. (#11273 by @jdx)prefix:tool requests now honor the locked version onmise installinstead of silently re-resolving to the newest match. Constrained upgrades viamise upgrade/mise lock --bumpstill work. (#11255 by @JamBalaya56562)v-prefixed URL, fixing 404s where an entry locked to another platform's unprefixed URL. (#11267 by @jdx)ubuntu24.04,fedora39,ubi9, ...) so checksums are no longer verified across mismatched distro tarballs, andmise lockwrites meaningful entries and re-locks correctly after changingswift.platform. (#11299 by @jdx)runcommand,sources, oroutputsnow invalidates its cached state, so tasks are no longer incorrectly skipped after such edits. (#11288 by @rabadin)Number.MAX_SAFE_INTEGER) now sort correctly, fixing cases where a0.0.*build could be picked over a newer stable release. (#11280 by @jdx)allow_buildsis now serialized as a map. (#11262 by @jdx)mise --versionin those cases. (#11285 by @jdx)std::env::vars()call sites now usevars_safe(). (#11309 by @JamBalaya56562)Changed
min_usage_versionbumped), so shell completions and doc rendering now depend on it. (#11306 by @jdx)Security
MISE_*environment variables still apply. Reported by @arpitjain099. (#11293 by @jdx)Performance
Documentation
bin_path/asset_patterntemplate variable docs. (#11298 by @jdx)llms.txtindex for AI agents. (#11300 by @jdx)Registry
checkstyle(#11287 by @zeitlinger),grok(#11291), andtak(#11307) by @jdx.New Contributors
Full Changelog: jdx/mise@v2026.7.13...v2026.7.14
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
v2026.7.13: : Multi-binary renaming, cask completions, and go.mod supportCompare Source
This release expands archive backends to rename multiple binaries from a single release, adds Homebrew cask shell completions and
go.modversion-file support, and fixes a broad batch of task, install, lockfile, and language-plugin correctness issues.Added
backend:
rename_exenow accepts a table mapping source patterns to target names, so an archive that ships several executables can expose all of them cleanly on PATH instead of only one. The existing string form is unchanged. (#11231 by @jdx)brew: brew-cask now installs shell completions (declared
bash_completion/fish_completion/zsh_completionfiles andgenerate_completions_from_executablefor bash, zsh, fish, and pwsh) instead of skipping them, tracking them in cask receipts and installed-state checks. (#11198 by @jdx)go:
go.modcan now be used as an idiomatic version file. Atoolchain goX.Y.Zdirective resolves as an exact pin, while ago X.Yminimum resolves to the latest matching patch. It is opt-in and unchanged unless enabled per-tool. (#11213 by @JamBalaya56562)task: PowerShell task shells (
pwsh/powershell) now run with-NoProfileby default, matching how mise spawns POSIX shells, so a profile that mutatesPATH(such as a mise activation snippet) can no longer shadow a task's own tools and cause confusing "cannot find binary path" errors. Opt out with the newwindows_powershell_no_profilesetting (MISE_WINDOWS_POWERSHELL_NO_PROFILE=false). (#11199 by @jdx)Fixed
_.path/_.file/_.sourcedirectives within a single[env]._block are now resolved in written order, so a_.pathcan reference a variable exported by a_.sourcewritten before it. (#11163 by @JamBalaya56562)github:tool to a newer version that is already installed on disk no longer triggers a false supply-chain "provenance regression" error. (#11230 by @jdx)trust_policy_excludesornpm.shell_out) for trust-downgrade errors. (#11226 by @jdx)conf.d, and monorepo configs, so lower-precedence metadata no longer leaks into script tasks and the winning config's context is preserved. (#11103 by @risu729)sourcespatterns used in nested subproject tasks, so edits inside a subproject trigger a rerun. (#11202 by @rabadin)preflight_steps/postflight_stepsfor move/remove operations, and cleanup-onlyzappkgutilIDs are no longer treated as install receipts (which could leave pkg cask status permanently missing). (#11197 by @jdx)python3executable is now provided on Windows. (#11212 by @jdx)ruby.precompiled_url = "owner/repo"sources now fetch release metadata directly from GitHub instead of the restricted versions host, avoiding 403 warnings. (#11154 by @risu729)ruby "3.4.10") are now parsed correctly. (#11229 by @capnregex)./-prefixed relative[bootstrap.repos]paths no longer display with a leading./component. (#11214 by @lilienblum)native-tls. (#10834 by @bltavares)Deprecated
virtualenvtool option is deprecated in favor of the_.python.venvenv directive. It now emits a warning and is scheduled for removal around2027.7.0. (#11234 by @JamBalaya56562)Documentation
uv_venv_autorequires auv.lockfile. (#11223 by @jdx)New Contributors
Full Changelog: jdx/mise@v2026.7.12...v2026.7.13
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.
Configuration
📅 Schedule: (in timezone America/Chicago)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.