v2026.7.0
parruda/swarmv2026.7.0Jul 2, 2026by mise-en-dev
AI Summary
This release enables shell expansion by default, introduces unified monorepo lockfiles, and enhances task usage mounts. It also adds per-tool GitHub Artifact Attestations options and improves Brew formulae handling.
Key Highlights
- Shell expansion enabled by default (configurable)
- Monorepo lockfile support with unified roots
- Task usage mounts support in file tasks
- Per-tool GitHub Artifact Attestations option
- Brew formulae prefix-inventory based pruning
New Features
- Shell expansion by default
- Monorepo lockfile support
- Task usage mounts
- Per-tool GitHub Artifact Attestations
- Brew formulae prefix-inventory based pruning
- Android asset detection for tools
- Minimum release age warnings
- Brew support for cask fonts and artifacts
- Aqua bin path resolution
- GitHub API asset download fallback
- Brew-cask executable handling
- Config template resolution
- Dotnet SDK validation
- OCI install path canonicalization
- Ruby build improvements
- Sigstore retry logic
- Vfox Lua env reading
- Watchexec flags forwarding
- Windows GHCUp support
- Copr Fedora 42 removal
Full Release Notes
## Added - **env:** enable shell expansion by default; opt out with `env_shell_expand = false` ([#10702](https://github.com/jdx/mise/pull/10702) by @jdx). - **monorepo:** `mise install --monorepo` and `mise ls --monorepo` install/list the union of tools across `[monorepo].config_roots`; new tri-state `[monorepo].lockfile` for unified root lockfiles ([#10707](https://github.com/jdx/mise/pull/10707) by @jdx). - **task:** root-level `#USAGE mount ...` in file tasks (including shorthand `mount "cmd"`) hoists mounted usage specs onto the generated task command ([#10704](https://github.com/jdx/mise/pull/10704) by @jdx). - **github:** per-tool `github_attestations` option to disable GitHub Artifact Attestation verification for a single tool ([#10694](https://github.com/jdx/mise/pull/10694) by @jdx). - **upgrade:** `minimum_release_age` warnings now include the release date, when the version becomes eligible, and the effective cutoff value ([#10705](https://github.com/jdx/mise/pull/10705) by @jdx). - **bootstrap:** brew formulae prune is now prefix-inventory based and can remove any linked formula outside the resolved `[bootstrap.packages]` closure ([#10618](https://github.com/jdx/mise/pull/10618) by @jdx). - **brew:** support cask `font` artifacts and additional non-install artifact types (completions/manpages) ([#10671](https://github.com/jdx/mise/pull/10671) by @roele). - **platform:** Android asset detection for tools like Termux packages ([#10653](https://github.com/jdx/mise/pull/10653) by @bltavares). ## Fixed - **install:** respect the lockfile-recorded backend during `--locked` installs ([#10599](https://github.com/jdx/mise/pull/10599) by @risu729). - **install:** installer prints a clearer message and suggests `cargo install --locked mise` on unsupported architectures ([#10627](https://github.com/jdx/mise/pull/10627) by @risu729). - **install-into:** refuse to overwrite a non-empty target directory without `--yes` ([#10630](https://github.com/jdx/mise/pull/10630) by @JamBalaya56562). - **aqua:** resolve bin paths with `v`-prefixed version overrides (e.g. `sharkdp/fd@10.3.0`) ([#10696](https://github.com/jdx/mise/pull/10696) by @jdx). - **aqua:** download private GitHub release assets via the API asset endpoint when the browser URL 404s ([#10622](https://github.com/jdx/mise/pull/10622) by @yacchi). - **brew-cask:** handle raw executable binaries, resolve `$APPDIR` paths, and use `ditto` for app bundle copying to avoid macOS "damaged app" errors ([#10626](https://github.com/jdx/mise/pull/10626) by @arthurh4). - **config:** preserve set values in `mise config set` for comma-separated set-typed settings ([#10647](https://github.com/jdx/mise/pull/10647) by @KrishRVH). - **config:** render `task_config.includes` templates with resolved `vars` ([#10700](https://github.com/jdx/mise/pull/10700) by @jdx). - **config:** support `required` validation and `redact = true` on `[vars]`; render tool option templates recursively ([#10697](https://github.com/jdx/mise/pull/10697) by @jdx). - **dotnet:** validate SDK installs with `dotnet --list-sdks` so `global.json` roll-forward no longer causes false failures ([#10691](https://github.com/jdx/mise/pull/10691) by @jdx). - **generate:** `mise generate tool-stub --lock` respects configured `lockfile_platforms` ([#10709](https://github.com/jdx/mise/pull/10709) by @JamBalaya56562). - **github:** handle missing/empty `url_api` in older lockfile entries, falling back to the cached browser URL ([#10703](https://github.com/jdx/mise/pull/10703) by @jdx). - **hooks:** set `MISE_INSTALLED_TOOLS=[]` on no-op installs so `postinstall` always receives a valid JSON array ([#10615](https://github.com/jdx/mise/pull/10615) by @JamBalaya56562). - **http:** don't let netrc credentials clobber explicit forge tokens on un-redirected URLs, fixing private GitHub release asset downloads ([#10713](https://github.com/jdx/mise/pull/10713) by @yacchi). - **lockfile:** merge platform data when a tool's options newly diverge from an empty on-disk entry (e.g. java `shorthand_vendor`), preventing checksum/URL loss ([#10710](https://github.com/jdx/mise/pull/10710) by @JamBalaya56562). - **npm:** map `allow_builds` to npm 11.16+ `--allow-scripts` / `--dangerously-allow-all-scripts` instead of forcing `--ignore-scripts` ([#10690](https://github.com/jdx/mise/pull/10690) by @jdx). - **oci:** canonicalize install paths when rebasing `PATH`, fixing `mise oci` on systems with symlinked `/home` (Bluefin/Silverblue) ([#10624](https://github.com/jdx/mise/pull/10624) by @salim-b). - **oci:** account for darwin mode stripping in layer test expectations ([#10681](https://github.com/jdx/mise/pull/10681) by @laozc). - **ruby:** stop forcing `no-yjit` Ruby builds on older glibc ([#10620](https://github.com/jdx/mise/pull/10620) by @jdx). - **sigstore:** retry GitHub attestation verification with the TUF trust root after embedded-root failures; workflow mismatches remain non-retryable ([#10695](https://github.com/jdx/mise/pull/10695) by @jdx). - **task:** render monorepo subproject task templates with the subproject's own `[env]`; broken subprojects no longer fail discovery repo-wide ([#10706](https://github.com/jdx/mise/pull/10706) by @jdx). - **task:** correct env used for the `task.show_full_cmd` setting ([#10714](https://github.com/jdx/mise/pull/10714) by @muzimuzhi). - **vfox:** Lua `os.getenv` now reads from mise's env table like `cmd.exec`/`os.execute` ([#10719](https://github.com/jdx/mise/pull/10719) by @jdx). - **watch:** forward `--ignore`, `--ignore-file`, and `--print-events` to watchexec ([#10629](https://github.com/jdx/mise/pull/10629) by @JamBalaya56562). - **windows:** allow GHCUp to be installed on Windows via aqua ([#10670](https://github.com/jdx/mise/pull/10670) by @cprecioso). - **copr:** drop retired Fedora 42 chroots from the default build list ([#10698](https://github.com/jdx/mise/pull/10698) by @jdx). ## Security - Ignore transitive `quick-xml` advisories RUSTSEC-2026-0194/-0195 pending upstream fixes ([#10717](https://github.com/jdx/mise/pull/10717) by @jdx). ## 💚 Sponsor mise mise is built by [@jdx](https://github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent.