This release expands declarative bootstrap into a composable, multi-root system; adds environment-specific conf.d fragments and glob-based ignored config paths; smooths out shell activation so runtime overrides stick; and delivers major startup performance gains for vfox-backed setups. It also includes several security hardening fixes worth noting.
Highlights
- Bootstrap can now compose declarative resources (dotfiles, files, directories, services, and Compose projects) from multiple independent config roots, with provenance tracking and clear conflict diagnostics.
- Startup is dramatically faster on machines with vfox plugins: idiomatic file detection is now gated on opt-in, and vfox plugin metadata is cached on disk, cutting common invocations from hundreds of milliseconds to single digits.
- Security hardening: forge tokens no longer leak to third-party hosts, and safe mode now blocks tool-level install hooks.
Added
-
bootstrap: Compose declarative resources from multiple independent config roots via
[bootstrap].config_roots. Selected roots contribute[dotfiles],[bootstrap.files],[bootstrap.directories],[bootstrap.services], and[bootstrap.compose]without gaining precedence from list or glob order; identical declarations are deduplicated and conflicting declarations fail with both origins reported. (#12105, #12132 by @jdx)[bootstrap] config_roots = ["bundles/*"]
-
bootstrap: Declaration provenance is now retained and exposed for dotfiles and managed files/directories.
mise bootstrap plan, bootstrap status, andmise dotfiles statusinclude origin details (declaring config, config root, environment, resolved source) in JSON, and human-readable tables gain a Config column. (#12100 by @jdx) -
bootstrap: Homebrew-compatible support for self-updating and adopted casks in
[bootstrap.packages]. Casks declaringauto_updates: trueare left to update themselves, and existing app bundles can be adopted globally with[bootstrap.brew].adopt = trueor per cask withadopt = true. (#12074 by @ascarter) -
bootstrap: Remote bootstrap gains symlink materialization controls. Use
--copy-link <PATH>(repeatable) to dereference selected source-relative symlinks or--copy-linksto recursively dereference all archived symlinks; both are also configurable in[bootstrap.remote]and per-host. Default behavior is unchanged (links stay links). (#12121 by @jdx) -
config: Environment-specific
conf.dfragments. Files like.mise/conf.d/*.{env}.toml(and.localvariants) load only when that config environment is active, applying to project, global, and systemconf.ddirectories. (#12151 by @jdx) -
config:
ignored_config_pathsnow supports relative entries and glob patterns (including recursive**). Entries in.miserc.tomlresolve against the declaring file, whileMISE_IGNORED_CONFIG_PATHSresolves against the invocation directory — making it easy to exclude vendored repos portably. (#12169 by @jdx) -
config:
mise run, nakedmise <task>,mise install,mise exec, andmise watchnow implicitly trust and persist the active config in normal mode, avoiding a redundant prompt. Automatichook-env/inspection commands still require explicit trust, and paranoid and safe modes are unchanged. (#12107 by @jdx) -
system: Plugins can declare an ordered list of candidate package names per package manager in
systemDependencies, so the same capability can be expressed across distro renames (for exampleapt = { "libaio1t64", "libaio1" }). mise resolves the first available candidate. (#12149 by @jdx) -
vfox: Traditional vfox plugins can now read configured
[tools]options fromctx.optionsinPreInstallandPostInstallhooks, with scalars as strings and arrays/tables as structured Lua values. Existing hook environment variables continue to work. (#12174 by @jdx)
Fixed
- hook-env: Runtime environment overrides now persist between refreshes. Changes made with
export, shell aliases, sourced scripts, or direct PATH edits are no longer reverted on every prompt, reversing the continuous enforcement introduced in 2026.8.0. (#12094 by @jdx) - aqua: Prefer glibc release assets on unqualified glibc Linux targets, falling back to a musl asset only when no glibc sibling exists. Explicit
libcselections stay strict. (#12093 by @jdx) - python: Automatic venv creation now resolves the configured
uveven when invoked through a tool override (for examplemise x tiny@3), sopython.uv_venv_autono longer reportsuvas missing right after mise installs it. (#12177 by @jdx) - which:
mise which <bin> --tool=<tool>@<version>now reports that the requested version is not installed (with an install hint) instead of the misleading "not currently active" message. (#12106 by @TrevorBurnham) - shell: The pwsh command-not-found hook now branches on the command exit code and skips mise's own commands, and the environment is refreshed on auto-install when
--no-hook-envomits the hook. (#12089, #12131, #12117 by @JamBalaya56562) - bootstrap: Create missing parent directories when bootstrapping. (#12096 by @jdx)
- github: Match arm assets on arm64 hosts. (#12098 by @jdx)
- use: Scope global install hooks correctly. (#12101 by @jdx)
- task: Support Azure DevOps cloud SSH URLs as remote git task sources, and normalize Windows task environment paths. (#12102 by @cheesemans, #12173 by @jdx)
- system: Resolve dependency executables on Windows. (#12178 by @jdx)
- backend: Keep flavour queries from crossing a
+, and key the remote version cache by listing tool options. (#12118 by @Marukome0743, #12164 by @JamBalaya56562) - http: Order remote versions consistently. (#12170 by @jdx)
- vfox: Follow symlinks when fingerprinting plugin sources, honor
systemDependenciesin embedded plugins, and apply netrc credentials to HTTP requests. (#12155, #12152, #12168 by @jdx) - Asset selection now handles non-gz tar variants. (#12156 by @sgammon)
Changed
- backend: Removed the remaining legacy
RTX_*environment variables (includingRTX_TOOL_OPTS__*andRTX_ADD_PATH) passed to asdf and vfox plugin hooks. Plugin authors should use the equivalentMISE_*variables; standardASDF_*variables remain available to asdf plugins. (#12172 by @jdx)
Performance
- config: Idiomatic version file detection is now gated on
idiomatic_version_file_enable_tools, so mise no longer boots a Lua VM for every vfox plugin on ordinary invocations. Common commands dropped from hundreds of milliseconds to single-digit milliseconds, and nestedmise run/mise xchains improved dramatically. (#12143 by @jdx) - vfox: Filesystem plugin metadata (idiomatic filenames, dependencies, system dependencies) is now cached on disk and invalidated by plugin file changes, avoiding repeated Lua execution. (#12145 by @jdx)
- activate: pwsh no longer runs
hook-envtwice per directory change. (#12147 by @jdx) - cache: Batch remote blob prefetch. (#12103 by @jdx)
Security
- backend: GitLab and Forgejo authentication headers are now bound to the configured API origin, preventing tokens from leaking to third-party release asset hosts or cross-origin pagination URLs. (#12167 by @jdx)
- Safe mode (
MISE_SAFE=1) now blocks tool-levelpostinstallhooks andinstall_envfrom running during installation. (#12140 by @jdx)
Registry
- Added
workerdviagithub:cloudflare/workerd. (#12180 by @mikea) - Pointed
vlangat the maintainedvfox:jdx/vfox-vbackend so it shares versions withv, replacing an unmaintained third-party version source. (#12153 by @jdx)
Breaking Changes
- conf.d filenames: A
conf.dfragment with an extra dot before.toml(for examplenode.tools.toml) is now interpreted as environment-specific. Use hyphens for unconditional multi-word fragment names (for examplenode-tools.toml). (#12151) - vlang versions: Configs pinning
vlang = "2026.x"-style versions must move to a real upstream version such as0.5.2or aweekly.*tag, since the previous version strings did not correspond to upstream tags. (#12153) - RTX_ variables:* Plugins relying on legacy
RTX_*variables must switch toMISE_*. (#12172)
New Contributors
- @sgammon made their first contribution in #12156
- @ascarter made their first contribution in #12074
- @TrevorBurnham made their first contribution in #12106
Full Changelog: v2026.8.8...v2026.8.9
💚 Sponsor mise
mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.
If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.