This release adds experimental task-scoped secrets backed by fnox, automatic updates for global tools, and an experimental opt-in install layout that names installations by what they contain. It also adds dotfile merge entries, headers auth for the http: backend, npm installs from git, and a set of prune, install and lockfile fixes.
Added
Secrets (experimental)
These need mise settings experimental=true and fnox 1.39.0 or newer. They are refused in safe mode.
-
[secrets.fnox]andmise secrets ls. A project can name fnox as its secrets source in its ownmise.toml.mise secrets lslists key names and metadata but never values.-Jprints JSON. Global, system and home-level[secrets]config is ignored, andmise doctorreports it. #13967 -
Tasks get only the secrets they list. Add
secrets = [...]to a task, or#MISE secrets=[...]in a file task header. Only that task gets the values, only while it runs, and they are redacted from its output. Dependencies, hooks,mise env, hook-env and shims get nothing. A task without grants never calls fnox. Tasks that list secrets need a trusted config, aren't artifact-cached, and ignore--rawunless the task setsraworinteractive. Hooks,watch_files, daemons andmise bootstrapcan't run them, and remote or global-config tasks can't list secrets. #13974min_version = "2026.10.4" # older mise rejects `secrets` on a task [secrets.fnox] profile = "prod" [tasks.deploy] depends = ["build"] # build receives nothing secrets = ["DEPLOY_KEY", "DATABASE_URL"] run = "./deploy.sh"
-
One-off grants from the command line.
--secrets KEY[,KEY]and--secrets-allwork onmise run,mise tasks runandmise x. Formise run, only the tasks named on the command line get them, not their dependencies.mise xgets nothing unless you pass a flag, and it can't receive file secrets. Flags placed after the task name go to the task, and mise warns when that happens. #13975mise run --secrets STRIPE_KEY deploy mise x --secrets GH_TOKEN -- gh release list
-
{{ secrets.X }}in task env values. A task can build an env var from a secret, for exampleenv.PGURL = "postgres://app:{{ secrets.DB_PASSWORD }}@db/app". The reference counts as the grant. References are rejected inrun,[env],[vars]and other fields. #13978 -
fnox daemon cache. If the project's fnox config enables the daemon and it's running, an interactive run reads cached values over its socket without starting an fnox process. mise never starts the daemon itself. CI, non-TTY runs and Windows always use the fnox CLI. #13979
Automatic global tool updates
-
auto_updatefor global tools. Setauto_updateon a tool in your global config. When a shim ormise xis about to run that tool and its check interval is due, mise upgrades it within the configured range and then runs the new version.trueuses the newtool_update.check_durationsetting (default 24h), and a duration string sets that tool's own interval (minimum 1h). #14026- Exact pins never update.
- It never runs offline, in CI, with
locked = true, from tasks or hook-env, or from project configs. - If an update fails, mise warns and runs the installed version. The failure shows in
mise doctor.
# ~/.config/mise/config.toml [tools] claude = { version = "latest", auto_update = true } node = { version = "22", auto_update = "6h" } # newest 22.x, never 23
-
Background
tool-updateservice. A built-in bootstrap service checksauto_updatetools hourly, so launches don't wait for downloads and tools run directly from PATH under activation also stay current. It installs a systemd user unit, LaunchAgent or scheduled task. #14040[bootstrap.services.mise-tool-update] builtin = "tool-update"
Identity install layout (experimental, opt-in)
-
install_layout = "identity". Withexperimental = true, each installation lives ininstalls/<label>-<hash>/. The hash covers the canonical backend, version, platform and install-affecting options.installs/<tool>/<version>becomes a link to that directory, a real junction on Windows. As a result: #13951ageandaqua:FiloSottile/ageshare one installation.- Variants of one version with different options can exist side by side.
- Windows IDEs can follow the version links.
Existing installs keep working and aren't moved. Nothing changes unless you set this.
MISE_INSTALL_LAYOUT=identityalso turns it on. See the new install layout docs. -
On Windows, identity-layout installations go into the shorter
%LOCALAPPDATA%\mise\i\, while version links stay ininstalls\.MISE_INSTALL_STORE_DIRsets the location on any platform. #13952 -
mise installs lslists installations asselected,pinnedorshared.mise installs select <dir>chooses which installation requests without a lockfile use. When several installations match and none is selected, mise lists them instead of guessing. #13953 -
mise installs migrate [--dry-run] [TOOL[@VERSION]]reinstalls legacy installations into the new layout and leaves a link at the old path. If a run is interrupted, the next run recovers it. #13955 -
In the layout,
mise backends switchinstalls the new backend's version and points the link at it.mise whereand the other commands now resolve versions named on the command line the same way, andmise wherelists variants instead of picking one. #13957 -
mise prunehandles templated tool versions such asnode = "{{ vars.node }}". It uses snapshots of what each project last rendered and keeps installs when it isn't sure they are unused. #14025
Other additions
-
Dotfile
mergeentries. Amerge = trueentry sets only the keys from its source in a JSON, TOML or YAML file, and leaves keys added by the application (Codex, Claude Code, etc.) alone. TOML and YAML keep comments and formatting.mise dot statusandmise dot diffonly report drift in those keys. A target that doesn't parse is never overwritten. #14012[dotfiles] "~/.codex/config.toml/shared" = { source = "codex/shared.toml", merge = true }
-
headersfor thehttp:backend. You can now authenticate with bearer tokens or API keys, for example to download OCI blobs fromghcr.io. Values are templates. Headers are sent with downloads,version_list_urlandchecksum_urlrequests, and dropped on cross-host redirects unless the host is listed inheaders_forward. Changing a token doesn't trigger a reinstall. #14022[tools."http:polaris"] version = "0.9.2" headers = { Authorization = "Bearer {{ env.GITHUB_TOKEN | b64_encode }}" }
-
npm packages from git.
git+URLs andgithub:,gitlab:andbitbucket:specs now install. The version is a git ref, andlatestis the default branch. #14044mise use 'npm:github:owner/repo@v1.2.0' -
settings.write_targets. Sends new global[tools],[bootstrap.packages]and[dotfiles]entries to separateconf.dfiles. Existing entries are updated where they're already declared. #14018[settings.write_targets] tools = "~/.config/mise/conf.d/10-tools.toml" dotfiles = "~/.config/mise/conf.d/30-dotfiles.toml"
-
prune.exclude(orMISE_PRUNE_EXCLUDE) lists tools thatmise prune,mise ls --prunableand upgrade pruning never remove. Short and full names both work, e.g.nodeoraqua:BurntSushi/ripgrep. #14030 -
lockfile_auto_prune = falsekeeps lockfile entries for tools missing from the active config. This is useful when profiles share one lockfile. The default (true) keeps the current pruning behavior. #13980 -
mise dot notifysends a test desktop notification, which also triggers the macOS permission prompt.mise doctorandmise dot statusnow show whether notifications can be delivered. #14009
Changed
-
mise's own auto-update settings moved under
self_update.*.auto_updateis nowself_update.auto(MISE_SELF_UPDATE_AUTO), andauto_update_check_durationis nowself_update.check_duration(MISE_SELF_UPDATE_CHECK_DURATION). The old names keep working. The new key wins when both are set. Deprecation warnings start in 2027.4.0. Older mise versions ignore a settings file that has unknownself_updatekeys, so keep the old spelling if a config has to work with both. #14038 -
mise prune,mise unuse --prune,mise ls --prunableand deferred pruning after an upgrade now keep any version a running process was started from, on Linux, macOS and Windows. They say which process kept it. #14020 -
pypi:/pipx:tools installed with uv are now built on mise's Python when mise manages one. Previously uv could use its own downloaded interpreter, which broke CI caches that only restore the mise data dir. A package whoserequires-pythonexcludes mise's Python now fails; to override, pass--pythoninuvx_args. #14024 -
With
python.uv_venv_auto,mise installnow creates the project venv with mise's Python instead of whatever uv found. #13981 by @halms -
Inherited secrets: when a parent mise marks variables as secrets in
__MISE_SECRET_KEYS, a nested mise now does the following #13966:- redacts them from logs
- hides them from templates,
get_env()andexec() - disables the env cache
- keeps them out of
__MISE_DIFF, other tasks and pitchfork
mise xand shims still pass them through.
Fixed
- Install state
- A failed tool-level
postinstallhook no longer leaves its version listed as installed or selectable. The next install retries it. #14037 - Incomplete-install markers moved from the cache to
$MISE_STATE_DIR, somise cache clearno longer makes a half-installed version look installed. Existing markers are migrated. #14051
- A failed tool-level
- Lockfiles and backends
mise install --lockednow works fordotnet:tools. #13971 by @james-newell-forgemise lockforpypi:tools on registries with a<root>/pypi/{}/jsontemplate, such as Artifactory, now uses<root>/simple/. #14007 by @deiga- Parallel
cargo:installs that fall back tocargo installno longer corrupt the shared rustup toolchain. #14042 mise upgrade --bumpandmise outdated --bumpno longer rewrite vendor-only requests likejava = "temurin"to a bare version from another vendor. #14031- A registry move within the same backend kind, such as
vfox:mise-plugins/*tovfox:jdx/*, no longer triggers the backend-switch warning or appears inmise backends switchormise doctor. #14032 mise doctoronly warns about a backend mismatch when the registry's backend actually serves the installed version. It now suggestsmise backends switch. #14005mise uninstall --dry-runlists each version once. #13992
- Network
- Downloads are retried when an HTTP/2 stream reset breaks reading the response body. #14049
- mise no longer retries a 429 whose
Retry-Afteris longer than the backoff. #14027 - Fewer duplicate requests: concurrent callers share one fetch of a cached GitHub release, and packslip release lists are read once per command. #13990, #13991
mise oci pushuploads layers larger than 64 MiB in a single streamed PATCH. GHCR previously rejected these with416. #14017
- GitHub attestations
- Config and bootstrap
- A project's
ignored_config_pathsno longer hides your global config when~/.config/miseis a symlink into that project. A global config can no longer be ignored only through its symlink target. #14006 mise bootstrapno longer fails withanother history operation is runningwhen it has no file history to record. Parallel CI jobs that share a state dir no longer block each other. #14029
- A project's
- Dotfiles
- Secrets, MCP and tasks
- Changing a Ruby version file that a Gemfile references no longer prints a
watch_file hook has neither run nor task setwarning. #13985 by @DahanItamar
Documentation
url_replacementsdocs now include a package proxy example. #14050
Breaking Changes
mise secretsis now a built-in command. If you have a task namedsecrets, run it withmise run secrets. #13967
New Contributors
- @james-newell-forge made their first contribution in #13971
- @deiga made their first contribution in #14007
- @DahanItamar made their first contribution in #14034
Full Changelog: vfox-v2026.10.3...v2026.10.4
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.