v2026.5.1

jdx/misev2026.5.1May 5, 2026by mise-en-dev

AI Summary

Adds top-level cosign verification for the Aqua backend and fixes a critical bug where `mise reshim` would fail if a literal `latest` directory existed on disk.

Key Highlights

  • Aqua backend now honors top-level `cosign` metadata for verification.
  • `mise reshim` no longer crashes when an install directory named `latest` exists on disk.
  • Schema validation now uses `draft/2020-12` in strict mode with `oneOf` instead of union types.

New Features

  • Cosign verification for Aqua
  • Rescue for `mise reshim` failure

Full Release Notes

A small follow-up to v2026.5.0 that lands top-level cosign verification for the aqua backend, fixes a `mise reshim` failure caused by stale `latest` install directories, and tightens schema validation.

## Added

- **(backend)** The aqua backend now honors top-level `cosign` metadata when verifying packages, covering both checksum and artifact flows and reusing the existing native sigstore path. Lockfiles record top-level cosign provenance, with new e2e and lockfile regression coverage ([#9111](https://github.com/jdx/mise/pull/9111)) by @risu729.
- **(registry)** Added `wasm-tools` via `aqua:bytecodealliance/wasm-tools` for working with the WebAssembly Component Model ([#9596](https://github.com/jdx/mise/pull/9596)) by @2xdevv.

## Fixed

- **(shim)** `mise reshim` no longer aborts with `failed to rebuild shims: no versions found for <tool>` when an install directory literally named `latest` (or any other non-resolvable name) is left on disk. `Toolset::list_installed_versions` already reads concrete version directory names, so it now constructs `ToolVersion` directly instead of calling `.resolve()` (no network), and per-tool `ToolRequest::new` failures are warned-and-skipped instead of aborting the entire rebuild ([#9599](https://github.com/jdx/mise/pull/9599)) by @jdx. Repro:

  ```sh
  mkdir -p ~/.mise/installs/buck2/latest/bin
  touch ~/.mise/installs/buck2/latest/bin/buck2
  mise reshim   # previously failed; now succeeds
  ```

- **(schema)** All files under `schema/` are now validated against `draft/2020-12` in strict mode. Hand-written schemas and the `BoolOrString` renderer in `schema.ts` use `oneOf` instead of union type arrays so AJV's `strictTypes` no longer rejects them; the bogus `--strict-schema` flag is replaced with `--strict-types=true --strict-tuples=true` ([#9594](https://github.com/jdx/mise/pull/9594)) by @risu729.
- **(registry)** `elixir-ls` re-enables `symlink_bins` so the move to the aqua backend stops exposing internal binaries that aren't meant to be called directly ([#9592](https://github.com/jdx/mise/pull/9592)) by @AlternateRT.

## Changed

- **(registry)** `rebar` now installs from the GitHub backend (`erlang/rebar3`) since rebar3 is just an `escript`; the asdf plugin fallback is removed. Versions before rebar 3 are no longer supported, and the installed executable remains `rebar3` to match upstream docs ([#9576](https://github.com/jdx/mise/pull/9576)) by @risu729.
- **(registry)** `bashly` drops the `asdf:mise-plugins/mise-bashly` fallback and the redundant explicit `ruby` dependency, since the `gem` backend already pulls in Ruby ([#9578](https://github.com/jdx/mise/pull/9578)) by @risu729.
- **(release)** Restored the "Sponsor mise" block on every successful GitHub release. It had been accidentally scoped to the communique-failure fallback in [#9395](https://github.com/jdx/mise/pull/9395), so normal releases since v2026.4.22 lost it ([#9580](https://github.com/jdx/mise/pull/9580)) by @jdx.

## Documentation

- **(dev-tools)** Clarified that vfox metadata `depends` runs install hooks for the listed dependency tools ([#9573](https://github.com/jdx/mise/pull/9573)) by @risu729.
- **(plugins)** Removed outdated registry submission guidance from the plugins docs ([#9577](https://github.com/jdx/mise/pull/9577)) by @risu729.

## Aqua Registry Updates

New packages:

- [`salesforce/reactive-grpc/protoc-gen-reactor-grpc`](https://github.com/salesforce/reactive-grpc)
- [`spinframework/spin`](https://github.com/spinframework/spin)

Updated:

- [`pnpm/pnpm`](https://github.com/pnpm/pnpm)

**Full Changelog**: https://github.com/jdx/mise/compare/v2026.5.0...v2026.5.1
## 💚 Sponsor mise

mise is built by [@jdx](https://github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent.