v2026.5.1
jdx/misev2026.5.1May 5, 2026by mise-en-dev
AI Summary
Adds top-level cosign verification for the Aqua backend and fixes a critical bug where `mise reshim` would fail if a literal `latest` directory existed on disk.
Key Highlights
- Aqua backend now honors top-level `cosign` metadata for verification.
- `mise reshim` no longer crashes when an install directory named `latest` exists on disk.
- Schema validation now uses `draft/2020-12` in strict mode with `oneOf` instead of union types.
New Features
- Cosign verification for Aqua
- Rescue for `mise reshim` failure
Full Release Notes
A small follow-up to v2026.5.0 that lands top-level cosign verification for the aqua backend, fixes a `mise reshim` failure caused by stale `latest` install directories, and tightens schema validation. ## Added - **(backend)** The aqua backend now honors top-level `cosign` metadata when verifying packages, covering both checksum and artifact flows and reusing the existing native sigstore path. Lockfiles record top-level cosign provenance, with new e2e and lockfile regression coverage ([#9111](https://github.com/jdx/mise/pull/9111)) by @risu729. - **(registry)** Added `wasm-tools` via `aqua:bytecodealliance/wasm-tools` for working with the WebAssembly Component Model ([#9596](https://github.com/jdx/mise/pull/9596)) by @2xdevv. ## Fixed - **(shim)** `mise reshim` no longer aborts with `failed to rebuild shims: no versions found for <tool>` when an install directory literally named `latest` (or any other non-resolvable name) is left on disk. `Toolset::list_installed_versions` already reads concrete version directory names, so it now constructs `ToolVersion` directly instead of calling `.resolve()` (no network), and per-tool `ToolRequest::new` failures are warned-and-skipped instead of aborting the entire rebuild ([#9599](https://github.com/jdx/mise/pull/9599)) by @jdx. Repro: ```sh mkdir -p ~/.mise/installs/buck2/latest/bin touch ~/.mise/installs/buck2/latest/bin/buck2 mise reshim # previously failed; now succeeds ``` - **(schema)** All files under `schema/` are now validated against `draft/2020-12` in strict mode. Hand-written schemas and the `BoolOrString` renderer in `schema.ts` use `oneOf` instead of union type arrays so AJV's `strictTypes` no longer rejects them; the bogus `--strict-schema` flag is replaced with `--strict-types=true --strict-tuples=true` ([#9594](https://github.com/jdx/mise/pull/9594)) by @risu729. - **(registry)** `elixir-ls` re-enables `symlink_bins` so the move to the aqua backend stops exposing internal binaries that aren't meant to be called directly ([#9592](https://github.com/jdx/mise/pull/9592)) by @AlternateRT. ## Changed - **(registry)** `rebar` now installs from the GitHub backend (`erlang/rebar3`) since rebar3 is just an `escript`; the asdf plugin fallback is removed. Versions before rebar 3 are no longer supported, and the installed executable remains `rebar3` to match upstream docs ([#9576](https://github.com/jdx/mise/pull/9576)) by @risu729. - **(registry)** `bashly` drops the `asdf:mise-plugins/mise-bashly` fallback and the redundant explicit `ruby` dependency, since the `gem` backend already pulls in Ruby ([#9578](https://github.com/jdx/mise/pull/9578)) by @risu729. - **(release)** Restored the "Sponsor mise" block on every successful GitHub release. It had been accidentally scoped to the communique-failure fallback in [#9395](https://github.com/jdx/mise/pull/9395), so normal releases since v2026.4.22 lost it ([#9580](https://github.com/jdx/mise/pull/9580)) by @jdx. ## Documentation - **(dev-tools)** Clarified that vfox metadata `depends` runs install hooks for the listed dependency tools ([#9573](https://github.com/jdx/mise/pull/9573)) by @risu729. - **(plugins)** Removed outdated registry submission guidance from the plugins docs ([#9577](https://github.com/jdx/mise/pull/9577)) by @risu729. ## Aqua Registry Updates New packages: - [`salesforce/reactive-grpc/protoc-gen-reactor-grpc`](https://github.com/salesforce/reactive-grpc) - [`spinframework/spin`](https://github.com/spinframework/spin) Updated: - [`pnpm/pnpm`](https://github.com/pnpm/pnpm) **Full Changelog**: https://github.com/jdx/mise/compare/v2026.5.0...v2026.5.1 ## 💚 Sponsor mise mise is built by [@jdx](https://github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent.