This release adds dotfile groups for Stow-style dotfiles repositories, templated [bootstrap.compose] values, and custom labels for task confirm prompts. Secret values no longer get copied into __MISE_DIFF/__MISE_SESSION or written to the env cache. It also fixes dotenv ${VAR} expansion, mise x tool@latest reporting other tools as missing, and Ruby source builds ignoring depends tools.
Added
-
Dotfile groups. You can now declare a directory tree as a group with
[dotfile_groups.<name>], using one directory per app or machine role like GNU Stow. mise walks the group'srootand deploys each file to the same path undertarget(default~), so you don't have to list files one by one. A machine picks which groups to apply with[bootstrap] dotfile_groups. If that list isn't set, every group applies. #13945[dotfile_groups.home] root = "home" # relative to dotfiles.root dot_prefix = true # dot-config/ deploys as .config/ exclude = ["README.md"] [dotfile_groups.home.entries] "~/.config/kitty" = { mode = "symlink" } # link this directory whole "~/.gitconfig" = { source = "git/config.tmpl", mode = "template" } [bootstrap] dotfile_groups = ["home", "zsh"]
- Groups support
mode(symlink-eachby default, orcopyorsymlink),exclude,dot_prefix,manifestandrelative. A[dotfile_groups.<name>.entries]table uses the same syntax as[dotfiles]and removes those paths from the walk, so you can link a directory whole, render a template, or mark a fileabsent. - If two selected groups write the same file,
applyandstatusfail before anything is written, and the error names both groups. - mise records what each group deployed under
$MISE_STATE_DIR/dotfiles/groups/.mise dot statusshows files that no active entry deploys any more asorphaned.mise dot apply --pruneremoves them after asking you, andmise dot unapply --group <name>removes one group's files even after the group is gone from config. mise only removes links that still point at their source and copies that still match what it wrote, unless you pass--force. mise dot addandmise dot editput files under a group's target into that group's root, and both accept--groupwhen more than one group could match.mise oci builddoes not include group trees.
- Groups support
-
Templates in
[bootstrap.compose]. Every string field in a Compose project, includingproject_dir,files,env_files,commandanddepends_on, is now rendered as a Tera template in the context of the config that declares it. Shared configs can use{{ config_root }},{{ vars.* }}or{{ env.* }}instead of hardcoded absolute paths.exec()isn't allowed in these templates. #13938[bootstrap.compose.mempalace] project_dir = "{{ config_root }}/mempalace" files = ["compose.yaml"] env_files = [".env"]
-
Custom labels for task
confirmprompts. The object form ofconfirmnow acceptsyesandnolabels, which support the same templates asmessage.defaultis now optional and still defaults toyes. Piped answers still takey/n, and--yesstill skips the prompt. #13944[tasks.deploy] confirm = { message = "Deploy to production?", yes = "Deploy", no = "Cancel", default = "no" } run = "deploy.sh"
Fixed
- Dotenv
${VAR}expansion checks the file's own values first. Before,${VAR}in a dotenv file read the process environment first. Withmise activateexporting another.env, a reference could expand against the shell instead of an earlier line in the same file. Now the file's own earlier assignments come first, then values already loaded (withexpand = true) or the process environment. The${VAR:-default},${VAR:+alt}and${VAR:?message}forms now work too. When theenv_filesetting hits a syntax error, mise keeps the assignments it read before the error and shows one warning for the file. #13946 mise x tool@latestno longer reports other tools as missing. Passing any@latestargument used to resolve every configured tool against its newest release and ignore the lockfile, so tools that were installed and locked showed up asmissing. Now only the tools named on the command line resolve to latest. #13943- Ruby source builds can see
dependstools. ruby-build now gets the declared dependencies onPATH. For example, JRuby builds use a mise-managedjavainstead of the system JDK. PATH stays the same when no dependencies are declared. #13942 by @seuros
Security
- No extra plaintext copies of secrets. #13950
- Shell state:
__MISE_DIFFand__MISE_SESSIONare passed to every child process. They now store ablake3:digest of each value mise sets instead of the value itself. The previous (old) values are still stored in plain text because mise needs them to restore the environment. These are plain hashes, not keyed ones, so a low-entropy value could be brute-forced from its digest. - Env cache: mise no longer writes environments that contain secrets to the env cache. This covers
agevalues (also when used through[vars]), sops-encrypted_.fileentries, any directive withredact = true, and env modules that returncacheable = false. Before, a non-tool module'scacheable = falsewas ignored. - Env module
redact: aredactsetting on an env module, such as_.my-plugin = { redact = false }, now overrides the plugin's own preference. Before, it was ignored. A non-boolean value is now a config error. mise x -- fish: env values no longer go in fish's command-line arguments, wherepscould read them.--deny-envnow applies there too.- Upgrading: shells started with an older mise still restore their environment correctly. mise rewrites their state in the new format at the next prompt.
- Shell state:
Registry
- Added
jactionlint(github:jdx/jactionlint), a maintained fork of actionlint with upstream fixes and new checks.actionlintis now deprecated, with a message pointing tojactionlint. Existingactionlintinstalls keep working. #13960
Documentation
- The installation guide shows how to pin the packslip bootstrapper while letting mise install the latest release. The Docker cookbook has a new multi-stage Debian example with a digest-pinned packslip image. #13935
Full Changelog: vfox-v2026.10.2...v2026.10.3
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.