Repository navigation
chore(deps): update dependency jdx/mise to v2026.10.3 - #309
Merged
Merged
Conversation
Contributor
Author
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead. |
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.10.2→2026.10.3v2026.10.5(+1)Release Notes
jdx/mise (jdx/mise)
v2026.10.3: : Dotfile groups, templated Compose projects, and secret hygiene for shell stateCompare Source
This release adds dotfile groups for Stow-style dotfiles repositories, templated
[bootstrap.compose]values, and custom labels for task confirm prompts. Secret values no longer get copied into__MISE_DIFF/__MISE_SESSIONor written to the env cache. It also fixes dotenv${VAR}expansion,mise x tool@latestreporting other tools as missing, and Ruby source builds ignoringdependstools.Added
Dotfile groups. You can now declare a directory tree as a group with
[dotfile_groups.<name>], using one directory per app or machine role like GNU Stow. mise walks the group'srootand deploys each file to the same path undertarget(default~), so you don't have to list files one by one. A machine picks which groups to apply with[bootstrap] dotfile_groups. If that list isn't set, every group applies. #13945mode(symlink-eachby default, orcopyorsymlink),exclude,dot_prefix,manifestandrelative. A[dotfile_groups.<name>.entries]table uses the same syntax as[dotfiles]and removes those paths from the walk, so you can link a directory whole, render a template, or mark a fileabsent.applyandstatusfail before anything is written, and the error names both groups.$MISE_STATE_DIR/dotfiles/groups/.mise dot statusshows files that no active entry deploys any more asorphaned.mise dot apply --pruneremoves them after asking you, andmise dot unapply --group <name>removes one group's files even after the group is gone from config. mise only removes links that still point at their source and copies that still match what it wrote, unless you pass--force.mise dot addandmise dot editput files under a group's target into that group's root, and both accept--groupwhen more than one group could match.mise oci builddoes not include group trees.Templates in
[bootstrap.compose]. Every string field in a Compose project, includingproject_dir,files,env_files,commandanddepends_on, is now rendered as a Tera template in the context of the config that declares it. Shared configs can use{{ config_root }},{{ vars.* }}or{{ env.* }}instead of hardcoded absolute paths.exec()isn't allowed in these templates. #13938Custom labels for task
confirmprompts. The object form ofconfirmnow acceptsyesandnolabels, which support the same templates asmessage.defaultis now optional and still defaults toyes. Piped answers still takey/n, and--yesstill skips the prompt. #13944Fixed
${VAR}expansion checks the file's own values first. Before,${VAR}in a dotenv file read the process environment first. Withmise activateexporting another.env, a reference could expand against the shell instead of an earlier line in the same file. Now the file's own earlier assignments come first, then values already loaded (withexpand = true) or the process environment. The${VAR:-default},${VAR:+alt}and${VAR:?message}forms now work too. When theenv_filesetting hits a syntax error, mise keeps the assignments it read before the error and shows one warning for the file. #13946mise x tool@latestno longer reports other tools as missing. Passing any@latestargument used to resolve every configured tool against its newest release and ignore the lockfile, so tools that were installed and locked showed up asmissing. Now only the tools named on the command line resolve to latest. #13943dependstools. ruby-build now gets the declared dependencies onPATH. For example, JRuby builds use a mise-managedjavainstead of the system JDK. PATH stays the same when no dependencies are declared. #13942 by @seurosSecurity
__MISE_DIFFand__MISE_SESSIONare passed to every child process. They now store ablake3:digest of each value mise sets instead of the value itself. The previous (old) values are still stored in plain text because mise needs them to restore the environment. These are plain hashes, not keyed ones, so a low-entropy value could be brute-forced from its digest.agevalues (also when used through[vars]), sops-encrypted_.fileentries, any directive withredact = true, and env modules that returncacheable = false. Before, a non-tool module'scacheable = falsewas ignored.redact: aredactsetting on an env module, such as_.my-plugin = { redact = false }, now overrides the plugin's own preference. Before, it was ignored. A non-boolean value is now a config error.mise x -- fish: env values no longer go in fish's command-line arguments, wherepscould read them.--deny-envnow applies there too.Registry
jactionlint(github:jdx/jactionlint), a maintained fork of actionlint with upstream fixes and new checks.actionlintis now deprecated, with a message pointing tojactionlint. Existingactionlintinstalls keep working. #13960Documentation
Full Changelog: jdx/mise@vfox-v2026.10.2...v2026.10.3
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (in timezone Europe/Oslo)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.