chore(deps): update dependency mise to v2026.9.1 - #4102
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/mise-2026.x
branch
from
September 4, 2026 00:39
4125d5f to
72508b5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2026.9.0→2026.9.1Release Notes
jdx/mise (mise)
v2026.9.1: : Bootstrap firewall limiting, scoped locked mode, and lazy tools in tasksCompare Source
This release expands bootstrap system setup with firewall rate limiting and more systemd directives, adds a scoped locked mode for mixing distribution and user tool policies, and fixes lazy tools so they install when invoked from tasks and
mise x.Added
bootstrap: New
action = "limit"for incoming TCP firewall rules rate-limits connections per source. It maps to UFW's native limiting and bounded per-source IPv4/IPv6 nftables meters; firewalld fails closed since it cannot express safe per-source limiting. Limit rules are treated as preserving SSH access by the lockout guard. (#12669 by @jdx)bootstrap: Bootstrap systemd units now support
requires(Requires=), repeatableenvironment_file(EnvironmentFile=),nice, andumask, with validation for nice ranges (-20 to 19) and octal umasks. Note thatrequiresdoes not imply ordering; useafterfor that. (#12683 by @jdx)config: New global-only
locked_scopessetting (alsoMISE_LOCKED_SCOPES) lets you scope locked mode to specific config sources, so a distribution can ship rolling or lazy tools through/etc/mise/config.tomlwithout forcing users to maintain a system lockfile. Defaults to all three scopes to preserve existing behavior. (#12667 by @jdx)Fixed
lazy = true) now install when their command is invoked from amise runtask ormise x, matching the behavior of an activated shell. mise inserts the shim farms after real tool paths for lazy toolsets and reconciles missing bootstrap shims for hand-edited declarations, so tasks no longer fail withcommand: not found. (#12687 by @jdx)falsevalues and unset directives) are now consistently unset acrossmise exec, tasks,mise env, hook-env, deps, and tool stubs, so inherited or secret variables are no longer leaked back into child processes. (#12664 by @jdx)mise reshimcan now safely target shared executable directories like~/.local/binor/usr/local/bin. It identifies mise-owned shims and only replaces or prunes those, leaving unmanaged files and symlinks in place, and--forcerebuilds mise-owned shims rather than wiping the whole directory. (#12675 by @jdx)codexthat exec helpers or read manifests from their own tree continue working after temporary install files are cleaned up. (#12686 by @azohra)--no-configcommands. (#12676 by @jdx)mise install --dry-runfor an s3 tool that only declares a URL for another platform now reports the missing platform and available options instead of falsely claiming it would install. (#12641 by @hktitof)Changed
binsdeclarations from hundreds of registry entries. Explicitbinsare kept only where mise intentionally exposes a different command set, andmise registry --jsonexposes the inferred names. (#12668 by @jdx)New Contributors
Full Changelog: jdx/mise@v2026.9.0...v2026.9.1
💚 Sponsor mise
mise is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.
If mise saves you or your team time, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep mise fast, free, and independent.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.