github jdx/mise v2026.10.6
v2026.10.6: Per-machine [vars] prompts, local config includes, and working-tree changes in --affected

3 hours ago

[vars] entries can now ask once per machine and remember the answer, include accepts local files, and mise run --affected now counts uncommitted work and no longer needs experimental = true. On a fresh machine, mise bootstrap can install git and ssh before it clones. The release also fixes several dotfiles history issues and stops lazy tools from triggering remote version lookups when something else launches.

Added

  • Per-machine [vars] prompts. Give a var a prompt, plus either a default or required. mise asks for it once and saves the answer in $MISE_STATE_DIR/vars.toml, outside your config and dotfiles history. Templates, tasks and tools then read it as usual. One shared dotfiles setup can use this to set a different Git identity on each machine. #14190

    [vars.git_name]
    default = "Ada Lovelace"
    prompt = "Git author name"
    
    [vars.git_email]
    required = "Run mise vars prompt to set git_email"
    prompt = "Git email"
    mise vars                       # list every var and where its value comes from
    mise vars prompt                # ask for every unanswered prompt var (or name some)
    mise vars git_name=Ada          # save a value without a prompt
    mise vars unset git_name        # forget a saved value
    mise bootstrap --prompt-vars    # prompt during a bootstrap run, e.g. with --adopt

    Only mise vars prompt and mise bootstrap --prompt-vars ever ask. Everything else uses the saved answer, then the default. Precedence, highest first: the process environment, a value from a higher-precedence config file, the saved answer, the default. Answers are keyed by var name, so projects that use the same name share one answer on a machine. prompt is not allowed in [env].

  • Local paths in include. include in mise.toml now accepts local TOML files, not just git:: and oci:: references. A path can be relative to the including file or absolute. Local files merge the same way as remote ones, ranking just below the including file. They are read on every load, so edits apply immediately and invalidate the cached env. Paranoid mode rejects local includes, and safe mode still skips all includes in project config. #14178

    include = ["./config/tools.toml", "/etc/mise/team.toml"]
  • mise bootstrap installs git and ssh before cloning. mise bootstrap --from and --adopt used to fail with a spawn error when git was missing. Now mise checks for git, and for ssh when the URL is ssh:// or user@host:path, and offers to install whatever is missing with the host package manager. Supported managers are apt, dnf, pacman, apk, zypper, Homebrew, scoop and winget. --yes accepts the offer without asking, and --dry-run only reports what is missing. #14188

  • mise dot save --re-encrypt. After you change [history.encryption] recipients, a normal save leaves some encrypted files under their old keys: manual-save entries the save doesn't name, and other-platform variants. Add --re-encrypt to re-encrypt every saved file in the new checkpoint to the current recipients. It never captures unsaved edits. If this machine can't unlock some of the files, nothing is saved and the error lists all of them. #14210

  • mise dot status shows unsaved changes. It now lists tracked paths that changed since the latest checkpoint. Unsaved edits were previously invisible there when the watcher was stopped or an entry used --no-autosave. --json reports these paths as history.unsaved. The value is null when they can't be determined, for example with no checkpoint yet or with encrypted files this machine can't compare without prompting. #14209

Changed

  • mise run --affected now counts working-tree changes, and the workspace graph is no longer experimental. Besides the committed base...head range, --affected now also counts staged and unstaged edits and untracked files that aren't ignored. You can narrow it with --affected-committed, --affected-uncommitted and --affected-untracked, which can be combined (environment variables: MISE_AFFECTED_*). Working-tree changes only count when the head is your current checkout. To get the old committed-only selection, for example in a CI job that writes untracked files before it runs, use --affected-committed. --affected, mise tasks graph, [monorepo.task_defaults], [monorepo.projects] and task.auto_infer no longer require experimental = true. #14214

    mise run --affected build                                         # committed + uncommitted + untracked
    mise run --affected --affected-uncommitted --affected-untracked build  # only what you haven't committed yet
    mise run --affected --affected-committed build                    # committed range only, as before
  • Credential checks for dotfiles. Files with names ending in .example, .sample or .template no longer match the credential name rules. The content scan before publishing still checks them. Once you approve a file for plaintext tracking, mise no longer warns about it on every save. #14204

  • mise dot track only asks about plaintext at a terminal. Before saving a credential-named file in plaintext, it now asks only when both stdin and stderr are terminals. Previously, a piped line, such as the next entry in a while read loop, could be taken as the answer. Scripts need --allow-plaintext or --encrypt. #14205

Fixed

  • Lazy tools no longer trigger remote lookups for other lazy tools. Previously, mise looked up versions for configured lazy tools that weren't installed, even though they weren't being launched. With a cold cache and no network, launching one tool waited on each lookup and could print "Failed to resolve tool version list" warnings. In one offline test a launch took 41 seconds. This no longer happens in these cases:

    • the update that runs before an auto_update tool launches (#14195)
    • after mise x or a shim installs a new version (#14197)
    • the first launch of a lazy tool through its shim (#14201)

    mise install, mise upgrade and mise use still resolve everything.

  • Too many open files with parallel npm: installs. Parallel installs could fail under macOS's default launchd soft limit of 256, for example when mise was started from a LaunchAgent. On Unix, mise now raises its soft open-file limit at startup toward the hard limit, up to 10240, and never lowers it. #14174, #14216

  • go: tools with an untidy go.mod. Tools whose published go.mod is missing a requirement now install, for example go:tailscale.com/cmd/tailscale. mise now passes -mod=mod to go install instead of -mod=readonly. A project's GOFLAGS=-mod=vendor still doesn't affect these installs. #14180 (@JamBalaya56562)

  • Config at the filesystem root. A config file at /, such as /mise.toml in a Docker image, made mise install and mise exec panic. It now works. #14182

  • .NET installs. Installing a .NET SDK no longer fails with "was not found in dotnet --list-sdks output" when another mise-managed SDK comes before the shims on PATH. The post-install check now runs the new SDK's dotnet directly. #14189

  • Shims and directories. Shims and mise which no longer resolve a bin name to a directory in another tool's bin path. Previously, hunk's skills/ directory blocked npm:skills with "Permission denied". #14193

  • mise oci build and multiple versions. A tool pinned to several versions is now written to the embedded /etc/mise/config.toml as a single array, in resolution order. Previously each version got its own duplicate key, which made the config unreadable inside the container. #14200 (@JamBalaya56562)

  • Encrypted files a sync can't unlock. mise bootstrap --adopt, mise dot pull and mise dot sync now list every encrypted file they can't unlock in one error, instead of stopping at the first one. Damaged files still stop the sync immediately. #14208

  • Rollback and undo messages. mise dot rollback <path> now names the checkpoint that saved the restored version, which matches mise dot history --path. Rollback and undo also name both checkpoints they record: the result, and the one holding the state before the operation. Previously, rollback could name a checkpoint that history --path didn't list. What gets restored is unchanged. #14207, #14211

  • mise dot status on adopted machines. On a machine that adopted a shared setup, it no longer prints "nothing configured in [dotfiles]" while history tracks entries. #14206

New Contributors

Full Changelog: v2026.10.5...v2026.10.6

💚 Sponsor mise

mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

Don't miss a new mise release

NewReleases is sending notifications on new releases.