Aqua tools can now choose glibc or musl builds one tool at a time, and monorepo roots can get short task path aliases. Packslip tools keep installing after their GitHub or GitLab repository is renamed, because mise now pins them by repository ID, recorded in a new lockfile revision 3. SLSA provenance checks now require the expected signer identity. This release also fixes regressions in mise run --no-timings, cargo +nightly and the outdated/upgrade version comparison, and speeds up shims and config loading.
Added
-
Per-tool
libcfor aqua tools. On glibc Linux, mise prefers a release's gnu build even when the aqua registry names the musl one. That breaks tools whose musl build is the fully static one, such asaqua:domcyrus/rustnet. You can now pick the build for a single tool instead of changing the globallibcsetting. #13701[tools] "aqua:domcyrus/rustnet" = { version = "latest", libc = "musl" }
The option accepts
glibc(orgnu) andmusl. mise never falls back to the other libc for that tool. The option applies to install,mise lock, and checksum, signature and provenance lookups, and it is recorded in the lockfile's tool options. A platform that already names a libc (a musl host or alinux-*-musllockfile platform) still wins. A version that is already installed keeps its build until you runmise install --force.mise ls-remotestill uses the host libc. If a registry template uses a variable namedlibc, set it asvars.libc. -
Path aliases for monorepo tasks. Deeply nested config roots can now have a short name. #13756
monorepo_root = true [monorepo] config_roots = ["foo/bar/baz/abc/123"] [monorepo.path_aliases] "123" = "foo/bar/baz/abc/123"
mise run //123:buildruns//foo/bar/baz/abc/123:build. Aliases also work in task dependencies, in patterns like//123:*, and in child paths like//123/sub:build. Each alias must be a single path segment, must point at a configured root, and can't overlap an existing root path. A task's full path is still its canonical name. -
Packslip tools keep installing after a repository rename. mise now pins GitHub and GitLab packslip projects by the repository ID recorded in the signing certificate, not only by name. If
old/toolis renamed tonew/toolunder the same owner,packslip:github.com/old/toolkeeps installing and prints a warning once, asking you to update the config. You don't needmise packslip forget. mise refuses a transfer to another owner. It also refuses a different repository that takes over a pinned name, which is how a deleted and re-created name looks. To accept either one, runmise packslip forgetfor the old name, and for a re-created repository also remove the tool'smise.lockentries. #13702, #13738In lockfile revision 3, the IDs are stored as:
[tools.hk."platforms.linux-x64"] repository_ids = { repository = "922514152", owner = "216188" }
-
mise dot track --allow-plaintext. Directly tracking a file with a credential-like name (for example~/commit-mossy-token.md) used to report success while every history save quietly left the file out.mise dot tracknow asks whether to save the file in plaintext, and the default answer is No. In non-interactive use, pass--allow-plaintext.--yesdoes not approve plaintext. The choice is saved asallow_plaintext = trueon the[dotfiles]entry. For real credentials, use--encrypt. #13749 -
Registry:
mise use mbxnow resolves tomr-boxington. #13752
Fixed
mise outdatedand upgrade warnings no longer offer an older release as an update when the installed version has avorVprefix. For example,v2.1.280 → 2.1.278was shown as an update. Versions that differ only in build metadata (for example1.36.4+k3s1and1.36.4+k3s2) are now treated as equal. #13690 (@himkt)mise run --no-cacheandmise tasks run --no-cachenow clone remotegit::task includes again, and fetch remote tasks that run as dependencies again. Before, both kept using the cached copy. #13697 (@irisTa56)mise run --no-timingshides each task's "Finished in …" line again, not only the run total. It also overridesMISE_TASK_TIMINGS=1. This had regressed in v2025.11.2. #13718cargo +nightlyworks again withrust = "nightly". Since 2026.8.6 mise installs a dated nightly, so rustup had no toolchain namednightly. Depending on rustup's auto-install setting,cargo +nightlythen either failed or downloaded a second, unpinned nightly. mise now also sets up rustup'snightly-<host>toolchain from the pinned nightly, using reflinks or hardlinks. It leaves alone a rustup nightly that is newer or has extra components or targets. Explicitly dated requests such asnightly-2026-08-13don't touch it. Existing installs pick this up on their next nightly install, or right away withmise install -f rust. #13707- Running
mise dot trackagain on a path that is already tracked now reports "already tracked". It no longer prompts, rewrites the config, or records an empty checkpoint. Changed file contents and flags that change the declaration (such as--no-autosave) are still saved. #13648 - Blob-pack downloads from the remote cache now retry transient stream errors, the same way single blob downloads do. #13715
Security
-
SLSA provenance must come from the expected signer. Before, any valid Sigstore signature, even from an unrelated workflow, passed SLSA verification. mise now checks the certificate's URI identity and OIDC issuer against the values configured for the tool:
- aqua registry entries:
signer_identityandsigner_issuerunderslsa_provenance github:tools: theslsa_signer_identityandslsa_signer_issuertool options (the identity supports{{version}}templating)- vfox plugins:
slsa_signer_identityandslsa_signer_issuerreturned fromPreInstall
If a tool doesn't configure both values, mise skips the SLSA check and uses any other verification available. For now this applies to the bundled aqua packages that have SLSA metadata but no signer fields. SLSA lock entries are checked again on every install, even when a checksum is present. #13725
- aqua registry entries:
-
Public-key DSSE bundles used by aqua and vfox verification must now have a SHA-256 subject digest that matches the downloaded artifact. Before, a valid bundle could be reused to verify a different download. #13721
Performance
- Shims no longer run
rustupchecks whenrustis configured alongside other tools. The same goes formise execwith auto-install disabled. One report measured thegoshim at about 31 ms withrustin the config, compared with 12 ms without it.mise install, andmise execwith auto-install on, still detect and repair missing rustup components. #13705 - Config loading and fuzzy version resolution (for example
node = "24") do less work: plugin shorthands are built without checking every registry tool's backends, global-config checks stop resolving symlinks for every tool, and fuzzy matching no longer compiles regexes. #13694, #13695, #13696
Documentation
- The task docs now give the correct default job count (8). They also describe the default output mode correctly:
prefixwhen tasks run in parallel andinterleavewhen they run in sequence. #13716
Breaking Changes
- Lockfile revision 3. New and empty
mise.lockfiles are written aslockfile_version = 3, and older mise versions reject them. Existing lockfiles keep their revision when mise writes to them. When a revision 2 lockfile gets packslip repository IDs, mise warns and leaves them out. To store them, runmise lock --upgradeonce everyone who shares the lockfile is on this release. - SLSA checks for locked tools. A lockfile entry that requires SLSA now fails with an explanation if the tool has no expected signer configured. To fix it, configure the signer or refresh the entry with
mise lock. - Dotfiles history shared across machines. Older mise versions can't read enrollment metadata that includes
allow_plaintext. Upgrade every machine that shares the history before you use--allow-plaintext.
New Contributors
Full Changelog: vfox-v2026.9.17...v2026.9.16
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.