v2026.7.3

swisskyrepo/PayloadsAllTheThingsv2026.7.3Jul 8, 2026by mise-en-dev

AI Summary

This release introduces system dependency checks for source compilation plugins and adds lifecycle hooks for Homebrew casks. It also fixes lockfile metadata loss during upgrades.

Key Highlights

  • vfox plugins can now declare system dependencies in `metadata.lua` to ensure build tools are present.
  • Homebrew cask lifecycle hooks (`preflight` and `postflight`) are now supported.
  • Lockfile entries now retain their platform metadata (checksums and URLs) after upgrades.
  • Terminal width can now be overridden via the `MISE_TERM_WIDTH` environment variable.

New Features

  • System dependency declarations in vfox plugins
  • Homebrew cask lifecycle hooks (preflight/postflight)
  • Terminal width override via MISE_TERM_WIDTH
  • Tools switched to vfox backend

Full Release Notes

This release brings smarter builds for source-compiling tools, better Homebrew cask support, and a fix for lockfile entries losing their platform data during upgrades.

## Added
- **vfox: plugin-declared system dependencies.** Source-compiling plugins (php, mysql, erlang, ...) often need build tools and libraries that previously showed up only as a failed `./configure` twenty minutes into a build. vfox plugins can now declare these prerequisites in `metadata.lua`, and mise checks them before installing ([#10848](https://github.com/jdx/mise/pull/10848) by @jdx):
  ```lua
  PLUGIN.systemDependencies = {
      { bin = "bison", version = ">=3.0", packages = { brew = "bison", apt = "bison" } },
      { pkgconfig = "libxml-2.0", packages = { brew = "libxml2", apt = "libxml2-dev" } },
      { sharedlib = "libaio.so.1", packages = { apt = "libaio1" } },
  }
  ```
  Detection is the source of truth: a satisfied check passes regardless of how the capability was installed (Homebrew, apt, nix, from source), and the per-manager `packages` map is only used to offer installing the missing subset. A new `system_deps` setting controls behavior (`prompt` default, `auto`, `warn`, `ignore`); the check never fails an install. Missing deps also show up in `mise doctor` and `mise bootstrap status`. Declarations are inert on older mise versions and on upstream vfox.

- **brew: cask lifecycle hooks.** Homebrew cask installs now run supported `preflight` and `postflight` hooks via a mise-owned, sha256-verified Ruby shim (no `brew` delegation), which fixes wrapper-style casks like GIMP. Unsupported hook DSL fails with an explicit error ([#10837](https://github.com/jdx/mise/pull/10837) by @jdx).

- **cli: terminal width override.** In some CI environments width detection returns a bogus value and mise's table/list output (`mise ls`, `mise registry`, `mise settings`) renders oddly with no way to fix it. You can now override the detected width ([#10862](https://github.com/jdx/mise/pull/10862) by @JamBalaya56562):
  ```sh
  MISE_TERM_WIDTH=120 mise ls
  ```
  `MISE_TERM_WIDTH` takes precedence, with `COLUMNS` as a fallback. An explicit override is honored exactly (no 80-column floor); behavior is unchanged when neither is set.

## Fixed
- **upgrade:** `mise upgrade --bump` can rewrite more lockfile entries than the tools it actually installs. Those rewritten entries were previously reduced to bare version/backend records, losing their cross-platform checksums and URLs. mise now re-locks stale entries that are missing platform metadata, so tools like `ruff`, `biome`, and `typos` keep their full lock data ([#10752](https://github.com/jdx/mise/pull/10752) by @zeitlinger).
- **brew:** casks whose binary is created by a pkg installer at an absolute path (e.g. `karabiner-elements`) now install correctly, staged through the caskroom as symlinks ([#10841](https://github.com/jdx/mise/pull/10841) by @jdx).
- **vfox:** traditional vfox plugin downloads now go into mise's per-tool download directory so they are cleaned up after install ([#10840](https://github.com/jdx/mise/pull/10840) by @risu729).
- **brew:** included the cask shim in the published crate, fixing a `cargo publish` verification failure ([#10863](https://github.com/jdx/mise/pull/10863) by @jdx).

## Changed
- **registry:** switched a large batch of tools to the vfox backend: scala, groovy, mongodb, emsdk, teleport-community, teleport-ent, tinytex, mysql, elasticsearch, v, spring-boot, php, clojure, oci, jib, graalvm, gcc-arm-none-eabi, and tiny.

## Documentation
- De-slopified the landing page copy and visuals ([#10836](https://github.com/jdx/mise/pull/10836) by @jdx).

**Full Changelog**: https://github.com/jdx/mise/compare/v2026.7.2...v2026.7.3

## 💚 Sponsor mise

mise is maintained by [@jdx](https://github.com/jdx), an open source developer for [**entire.io**](https://entire.io), the title sponsor of the [jdx.dev](https://jdx.dev) open source tools. Development is funded by sponsors.

If mise saves you or your team time, please consider sponsoring at [jdx.dev](https://jdx.dev/sponsors.html). Individual and company sponsorships keep mise fast, free, and independent.