github jdx/mise v2026.10.7
v2026.10.7: Background tool updates at the shell prompt, a verified download cache, and `mise upgrade --global`

5 hours ago

Tools with auto_update now update in the background from an activated shell, and a new tool_update.global_auto setting turns this on for every global tool. mise also keeps finished downloads in a content-addressed cache and checks them again before reusing them. This release also fixes .env parsing regressions from 2026.10.3 and a crash in mise run.

Added

  • Automatic updates at the shell prompt. Before, auto_update only ran when a shim or mise exec launched a tool. With mise activate, tools run straight from PATH, so they were never updated. Now, when a check is due, mise hook-env starts the update in a detached background process. The prompt doesn't wait and nothing is printed. The next command after the update finishes uses the new version. The existing rules still apply: only global config counts, exact versions don't move, nothing updates offline, in CI or with locked, and minimum_release_age is honored. While the tool-update service is running, prompts leave updates to it. Failed background updates show up in mise doctor. #14239

  • tool_update.global_auto turns on automatic updates for every tool in global config at once. It takes the same values as auto_update: true checks every tool_update.check_duration (24h by default), and a duration sets the interval. A tool's own auto_update takes precedence, so auto_update = false opts a tool out. Projects can't enable this setting. You can also set it with MISE_TOOL_UPDATE_GLOBAL_AUTO. self_update.auto now accepts an interval too, for example self_update.auto = "1d". #14237

    # ~/.config/mise/config.toml
    [settings]
    tool_update.global_auto = "12h"
    
    [tools]
    claude = "latest"                                   # checked every 12h
    node = { version = "24", auto_update = "6h" }       # its own interval wins
    python = { version = "3.13", auto_update = false }  # opted out
  • mise upgrade --global and mise outdated --global act only on the tool requests in global and system config, even inside a project that pins its own version or when MISE_<TOOL>_VERSION is set. The project's mise.toml, lockfile and [env] are not read or changed. --bump writes to the global config. --global can't be combined with --local or --inactive. A new "Self-updating tools" docs page explains how tools that update themselves, such as coding agents, can detect a mise install and update through mise instead of overwriting their own install. #14243

    mise outdated --global claude --json
    mise upgrade --global claude
  • Verified download cache. Finished downloads are stored once in $MISE_CACHE_DIR/downloads-cas and hashed again before every reuse. A cached file that no longer matches is dropped and downloaded again. #14222, #14242

    • When the server sent an ETag or Last-Modified header, the next request for the same URL is conditional. On 304 Not Modified, mise reuses the cached file without downloading it again. This applies to every download through mise's HTTP client.
    • For tools with a pinned checksum (from tool options, mise.lock or a packslip digest), http, github, aqua, packslip and the precompiled core tools (Node, Go, Bun, Deno, Zig, Java, Python, Ruby, Erlang, Elixir, Swift) reuse the cached file without any network request. The file is hard-linked into place, so it doesn't use extra disk space.
    • With --locked or paranoid, mise only uses the cache for downloads with a pinned checksum. This means a CI cache you restore can save downloads but can't change what gets installed. The CI guide now shows how to cache ~/.cache/mise/downloads-cas instead of installed tools.
    • download_cache_max_size sets the size limit (default 2GiB, 0 for no limit). When the cache is full, the least recently used files are removed. download_cache = false (MISE_DOWNLOAD_CACHE=0) turns the cache off.
  • npm: packages that install no executables now trigger a warning. For example, mise use npm:lodash used to succeed silently even though it created no shims. The install still succeeds. #14246

Fixed

  • .env parsing regressions from 2026.10.3, affecting [env] _.file and the env_file setting:
    • Backslashes in single-quoted values are literal again, so Windows paths like '\\fileserver\share' and 'C:\temp\' load correctly. To embed a single quote, use double quotes. #14228
    • Quoted and unquoted parts placed next to each other are joined again, as in shell. For example, A='it'\''s' gives it's and B=a'b c'd gives ab cd. These lines used to cause syntax errors that dropped the rest of the file. Quotes inside an unquoted value are now removed, so JSON that needs to keep its quotes must be single-quoted (CONFIG='{"debug": true}'). A quote with no matching closing quote on the same line stays literal, so NAME=O'Brien reads as written. #14231
  • mise run no longer crashes now and then with called Option::unwrap() on a None value when it reads the tool list while it's being reloaded after an install. #14240
  • On Windows with core.autocrlf=true, mise bootstrap repos status no longer reports freshly cloned repos as dirty. #14225
  • On Windows, mise dot apply can now repoint a mode = "symlink" dotfile whose target is a directory junction after its source changes. It used to fail with os error 5. #14226
  • history.describe_command now works for files tracked through a variant (such as home@work/...), including files added or removed inside variant directories. Encrypted files are still left out of the diff. #14194 (@oppegard)
  • mise doctor now shows the dotfiles: section, including the history repo: and origin:, when history.enabled = false. mise doctor --json adds dotfiles.history_enabled and dotfiles.tracking_error. #14244
  • mise lock now applies aqua registry version prefixes (such as Codex's rust- prefix) before it chooses version overrides. Before, platform entries like windows-x64 were skipped. When several prefix families match, mise now warns and skips the entry instead of picking one arbitrarily. #14218 (@nettlesh)
  • The rustup profile aliases m, d, c and the empty value are now treated like minimal, default and complete. With profile = "d", mise install now restores missing components like clippy and rustfmt. Unknown profile names now fail with rustup's list of valid names. #14220 (@JamBalaya56562)
  • The cargo backend now takes the same rust-state lock as the rust plugin when CARGO_HOME/RUSTUP_HOME are set through the rust.cargo_home/rust.rustup_home settings or MISE_CARGO_HOME/MISE_RUSTUP_HOME in [env]. Before, parallel source-build installs could race and fail. #14219 (@wislertt)
  • The hint to enable self_update.auto now appears on every mise version and mise self-update run, not just the first time. It stops once you enable auto-update or run mise settings add disable_hints auto_update. #14233
  • The JSON schema now matches what mise accepts, so editors and linters like tombi and Taplo report the right errors (@JamBalaya56562):
    • Task arrays can contain { task = ... } and { tasks = [...] } entries. #14229
    • depends, depends_post and wait_for accept a single table, and empty nested lists like depends = [[]] are rejected. #14236
    • [env] entries that combine value with required = true or a help string, and { required = false } with no value, are rejected. #14247

Deprecated

  • always_keep_download is deprecated because downloads are now kept in the download cache. It will warn starting in 2026.11.0 and will be removed in 2027.11.0. #14222

Documentation

  • The automatic tool updates docs now explain that minimum_release_age (24h by default) plus the check interval can delay an update by 24 to 48 hours after a release. You can set minimum_release_age per tool. Docs and hints now use the shorter mise settings KEY=VALUE form. #14235

New Contributors

Full Changelog: v2026.10.6...v2026.10.7

💚 Sponsor mise

mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.

Don't miss a new mise release

NewReleases is sending notifications on new releases.