Tools with auto_update now update in the background from an activated shell, and a new tool_update.global_auto setting turns this on for every global tool. mise also keeps finished downloads in a content-addressed cache and checks them again before reusing them. This release also fixes .env parsing regressions from 2026.10.3 and a crash in mise run.
Added
-
Automatic updates at the shell prompt. Before,
auto_updateonly ran when a shim ormise execlaunched a tool. Withmise activate, tools run straight fromPATH, so they were never updated. Now, when a check is due,mise hook-envstarts the update in a detached background process. The prompt doesn't wait and nothing is printed. The next command after the update finishes uses the new version. The existing rules still apply: only global config counts, exact versions don't move, nothing updates offline, in CI or withlocked, andminimum_release_ageis honored. While thetool-updateservice is running, prompts leave updates to it. Failed background updates show up inmise doctor. #14239 -
tool_update.global_autoturns on automatic updates for every tool in global config at once. It takes the same values asauto_update:truechecks everytool_update.check_duration(24h by default), and a duration sets the interval. A tool's ownauto_updatetakes precedence, soauto_update = falseopts a tool out. Projects can't enable this setting. You can also set it withMISE_TOOL_UPDATE_GLOBAL_AUTO.self_update.autonow accepts an interval too, for exampleself_update.auto = "1d". #14237# ~/.config/mise/config.toml [settings] tool_update.global_auto = "12h" [tools] claude = "latest" # checked every 12h node = { version = "24", auto_update = "6h" } # its own interval wins python = { version = "3.13", auto_update = false } # opted out
-
mise upgrade --globalandmise outdated --globalact only on the tool requests in global and system config, even inside a project that pins its own version or whenMISE_<TOOL>_VERSIONis set. The project'smise.toml, lockfile and[env]are not read or changed.--bumpwrites to the global config.--globalcan't be combined with--localor--inactive. A new "Self-updating tools" docs page explains how tools that update themselves, such as coding agents, can detect a mise install and update through mise instead of overwriting their own install. #14243mise outdated --global claude --json mise upgrade --global claude
-
Verified download cache. Finished downloads are stored once in
$MISE_CACHE_DIR/downloads-casand hashed again before every reuse. A cached file that no longer matches is dropped and downloaded again. #14222, #14242- When the server sent an
ETagorLast-Modifiedheader, the next request for the same URL is conditional. On304 Not Modified, mise reuses the cached file without downloading it again. This applies to every download through mise's HTTP client. - For tools with a pinned checksum (from tool options,
mise.lockor a packslip digest),http,github,aqua,packslipand the precompiled core tools (Node, Go, Bun, Deno, Zig, Java, Python, Ruby, Erlang, Elixir, Swift) reuse the cached file without any network request. The file is hard-linked into place, so it doesn't use extra disk space. - With
--lockedorparanoid, mise only uses the cache for downloads with a pinned checksum. This means a CI cache you restore can save downloads but can't change what gets installed. The CI guide now shows how to cache~/.cache/mise/downloads-casinstead of installed tools. download_cache_max_sizesets the size limit (default2GiB,0for no limit). When the cache is full, the least recently used files are removed.download_cache = false(MISE_DOWNLOAD_CACHE=0) turns the cache off.
- When the server sent an
-
npm:packages that install no executables now trigger a warning. For example,mise use npm:lodashused to succeed silently even though it created no shims. The install still succeeds. #14246
Fixed
.envparsing regressions from 2026.10.3, affecting[env] _.fileand theenv_filesetting:- Backslashes in single-quoted values are literal again, so Windows paths like
'\\fileserver\share'and'C:\temp\'load correctly. To embed a single quote, use double quotes. #14228 - Quoted and unquoted parts placed next to each other are joined again, as in shell. For example,
A='it'\''s'givesit'sandB=a'b c'dgivesab cd. These lines used to cause syntax errors that dropped the rest of the file. Quotes inside an unquoted value are now removed, so JSON that needs to keep its quotes must be single-quoted (CONFIG='{"debug": true}'). A quote with no matching closing quote on the same line stays literal, soNAME=O'Brienreads as written. #14231
- Backslashes in single-quoted values are literal again, so Windows paths like
mise runno longer crashes now and then withcalled Option::unwrap() on a None valuewhen it reads the tool list while it's being reloaded after an install. #14240- On Windows with
core.autocrlf=true,mise bootstrap repos statusno longer reports freshly cloned repos as dirty. #14225 - On Windows,
mise dot applycan now repoint amode = "symlink"dotfile whose target is a directory junction after itssourcechanges. It used to fail withos error 5. #14226 history.describe_commandnow works for files tracked through a variant (such ashome@work/...), including files added or removed inside variant directories. Encrypted files are still left out of the diff. #14194 (@oppegard)mise doctornow shows thedotfiles:section, including the historyrepo:andorigin:, whenhistory.enabled = false.mise doctor --jsonaddsdotfiles.history_enabledanddotfiles.tracking_error. #14244mise locknow applies aqua registry version prefixes (such as Codex'srust-prefix) before it chooses version overrides. Before, platform entries likewindows-x64were skipped. When several prefix families match, mise now warns and skips the entry instead of picking one arbitrarily. #14218 (@nettlesh)- The rustup profile aliases
m,d,cand the empty value are now treated likeminimal,defaultandcomplete. Withprofile = "d",mise installnow restores missing components like clippy and rustfmt. Unknown profile names now fail with rustup's list of valid names. #14220 (@JamBalaya56562) - The cargo backend now takes the same rust-state lock as the rust plugin when
CARGO_HOME/RUSTUP_HOMEare set through therust.cargo_home/rust.rustup_homesettings orMISE_CARGO_HOME/MISE_RUSTUP_HOMEin[env]. Before, parallel source-build installs could race and fail. #14219 (@wislertt) - The hint to enable
self_update.autonow appears on everymise versionandmise self-updaterun, not just the first time. It stops once you enable auto-update or runmise settings add disable_hints auto_update. #14233 - The JSON schema now matches what mise accepts, so editors and linters like tombi and Taplo report the right errors (@JamBalaya56562):
- Task arrays can contain
{ task = ... }and{ tasks = [...] }entries. #14229 depends,depends_postandwait_foraccept a single table, and empty nested lists likedepends = [[]]are rejected. #14236[env]entries that combinevaluewithrequired = trueor a help string, and{ required = false }with no value, are rejected. #14247
- Task arrays can contain
Deprecated
always_keep_downloadis deprecated because downloads are now kept in the download cache. It will warn starting in 2026.11.0 and will be removed in 2027.11.0. #14222
Documentation
- The automatic tool updates docs now explain that
minimum_release_age(24h by default) plus the check interval can delay an update by 24 to 48 hours after a release. You can setminimum_release_ageper tool. Docs and hints now use the shortermise settings KEY=VALUEform. #14235
New Contributors
Full Changelog: v2026.10.6...v2026.10.7
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.