mise self-update and the mise.run installer now pick the newest stable release that is at least 24 hours old. Updates also check the release's signed packslip before replacing the binary. This release also adds a machine-local global miserc, an opt-in way for command-not-found to install registry tools, and a postinstall mode that runs on every install. It fixes several Homebrew formula builds and closes a trust gap in paranoid mode.
Changed
-
Self-update and installs wait for a minimum release age. When no version is pinned,
mise self-update, automatic updates, update notifications, and the mise.run installer now choose the newest stable release published at least 24 hours ago. Explicit versions skip the delay. An unpinned update never downgrades a newer installation, even with--force. The age is taken from, in order:--minimum-release-age, thenself_update.minimum_release_age, then the globalminimum_release_agesetting, then24h. Use0sto get releases right away. #13782[settings] self_update.minimum_release_age = "7d"
mise self-update --minimum-release-age 0s curl -fsSL https://mise.run | MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE=7d shThe installer reads environment variables only (
MISE_SELF_UPDATE_MINIMUM_RELEASE_AGE,MISE_MINIMUM_RELEASE_AGE), and it accepts integers/m/h/d/wdurations. A saved copy of the installer no longer pins a default version, so setMISE_VERSIONif you need reproducible installs. -
Self-update verifies signed packslips. For releases v2026.9.3 and later,
mise self-updatenow requires a valid signed packslip, on top of the embedded archive signature it already checked. mise checks the archive digest and size, the version, the release workflow, and the transparency-log timestamp. Trust is pinned to mise's GitHub repository ID (586920414), so a rename or move to another organization still works, but a different repository that takes over the name is rejected. If the manifest is missing or invalid, mise stops and leaves the current binary in place. Releases 2026.9.2 and older still update with signature-only checks. Custom mirrors must serve the original signed manifests and archives. #13785 -
mise self-updatenow downloads with mise's own HTTP client and progress display, and extracts only the expected executable from the verified archive. Plugin-update failures during self-update now show as warnings and no longer fail the command. #13783 -
Registry:
timoni(0.35.0+) andworktrunk(0.80.0+) now install from signed packslips, which include completions and skills. Older versions still install through their existing backends, and you can list them withmise ls-remote aqua:stefanprodan/timoniormise ls-remote aqua:max-sixty/worktrunk. #13780
Added
-
Machine-local global miserc.
~/.config/mise/miserc.local.tomlapplies from any directory and overrides fields in the shared globalmiserc.toml. You can use it to pick an environment on one machine without editing shared files. Project miserc files,MISE_ENV, and-Estill take precedence over it. #13778# ~/.config/mise/miserc.local.toml env = ["work"]
-
Command-not-found can install tools you haven't configured (opt-in). With
not_found_auto_install_registry = true, running an unknown command installs the matching registry tool atlatestand adds it to your global config. This only happens when exactly one registry tool provides that command. mise skips commands with several providers, and it skips disabled tools and tools that don't support your OS. The default isfalse. #13781[settings] not_found_auto_install_registry = true
-
postinstallthat runs on every install. Withwhen = "always", a tool'spostinstallcommand runs on everymise installthat selects the tool, even when that version is already installed. Dry runs skip it. The plain string form and tables withoutwhenstill run only on a fresh install or repair. #13789[tools] node = { version = "26", postinstall = { run = "npm install -g corepack", when = "always" } }
-
Warnings for outdated lockfile formats. If a lockfile format was replaced more than six months ago, mise warns once per file during commands like
mise install,mise exec, and task runs. The warning shows the command to fix it:mise lock --upgrade, ormise lock --global --upgradefor a global config. #13779 -
Per-machine email for dotfiles history commits. The new
[history].git_emailsetting sets the commit email, and{hostname}is filled in when each commit is made, so you can tell which machine saved a checkpoint. Without the setting, commits still usemise@localhost. #13791[history] git_email = "mise@{hostname}"
Fixed
- Paranoid mode:
--yes,MISE_YES=1, and CI auto-confirmation no longer approve trust for new or edited config files. Unattended runs now fail until you approve the file withmise trustor at an interactive prompt. #13796 - npm with pnpm 12: mise now passes
minimum_release_ageto pnpm as--config.minimum-release-age. pnpm 12 silently ignored the camelCase spelling, so the cutoff wasn't applied to transitive dependencies. The new spelling also works on pnpm 10.16+ and 11. #13764 (@Nagato-Yuzuru) mise upgrade --bumpnow updates an exact-release request to the latest release with the same prefix, for example29.1to29.1.1. Before, it kept the old version. #13759 (@ryoikarashi)go:installs that resolvelatestto a version no longer retry without thevprefix after a failure. That extra retry used to hide Go's original error. Explicit unprefixed versions still get the retry, and if both attempts fail, the error now shows both failures. #13794- Homebrew formula builds:
- Formulas that write files with
Pathname#writeno longer fail after the build withsuper: no superclass method 'write'. This affected generated completions (such as starship) andinreplace. #13760 (@jacobbednarz) - Formulas that include Homebrew's
Language::*mixins (such asqmk) no longer fail with aNameErrorwhile mise reads them. Install-time helpers that mise doesn't support now produce a clear error message. #13328 (@waynehoover) - Source archives whose URL has no file extension, such as GitHub codeload tarballs, are now detected by their contents and unpacked. Before, they were copied into the build directory unextracted. This also applies to casks. #13750 (@jacobbednarz)
- Formulas that write files with
Documentation
- The landing page now has a seven-minute showreel of mise, and the mise run music video replaces the theme song. #13797, #13799
New Contributors
- @ryoikarashi made their first contribution in #13759
Full Changelog: vfox-v2026.9.18...v2026.9.17
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.