v2026.7.0
takahirom/arbigentv2026.7.0Jul 2, 2026by mise-en-dev
AI Summary
This release enables shell expansion by default, introduces monorepo lockfile support, and adds task usage mounts. It also includes security updates and fixes for various tool backends like Brew, Aqua, and Dotnet.
Key Highlights
- Shell expansion enabled by default with opt-out option
- Monorepo lockfiles and `--monorepo` flags for unified roots
- Task usage mounts and improved subproject task rendering
- Security fix for transitive `quick-xml` advisories
- Enhanced Brew cask support including fonts and non-install artifacts
New Features
- Default shell expansion via `env_shell_expand`
- Monorepo lockfile support with tri-state config
- Task usage mounts via `#USAGE mount`
- Per-tool GitHub attestations option
- Brew support for cask fonts and completions
- Android asset detection for Termux packages
Full Release Notes
## Added - **env:** enable shell expansion by default; opt out with `env_shell_expand = false` ([#10702](https://github.com/jdx/mise/pull/10702) by @jdx). - **monorepo:** `mise install --monorepo` and `mise ls --monorepo` install/list the union of tools across `[monorepo].config_roots`; new tri-state `[monorepo].lockfile` for unified root lockfiles ([#10707](https://github.com/jdx/mise/pull/10707) by @jdx). - **task:** root-level `#USAGE mount ...` in file tasks (including shorthand `mount "cmd"`) hoists mounted usage specs onto the generated task command ([#10704](https://github.com/jdx/mise/pull/10704) by @jdx). - **github:** per-tool `github_attestations` option to disable GitHub Artifact Attestation verification for a single tool ([#10694](https://github.com/jdx/mise/pull/10694) by @jdx). - **upgrade:** `minimum_release_age` warnings now include the release date, when the version becomes eligible, and the effective cutoff value ([#10705](https://github.com/jdx/mise/pull/10705) by @jdx). - **bootstrap:** brew formulae prune is now prefix-inventory based and can remove any linked formula outside the resolved `[bootstrap.packages]` closure ([#10618](https://github.com/jdx/mise/pull/10618) by @jdx). - **brew:** support cask `font` artifacts and additional non-install artifact types (completions/manpages) ([#10671](https://github.com/jdx/mise/pull/10671) by @roele). - **platform:** Android asset detection for tools like Termux packages ([#10653](https://github.com/jdx/mise/pull/10653) by @bltavares). ## Fixed - **install:** respect the lockfile-recorded backend during `--locked` installs ([#10599](https://github.com/jdx/mise/pull/10599) by @risu729). - **install:** installer prints a clearer message and suggests `cargo install --locked mise` on unsupported architectures ([#10627](https://github.com/jdx/mise/pull/10627) by @risu729). - **install-into:** refuse to overwrite a non-empty target directory without `--yes` ([#10630](https://github.com/jdx/mise/pull/10630) by @JamBalaya56562). - **aqua:** resolve bin paths with `v`-prefixed version overrides (e.g. `sharkdp/fd@10.3.0`) ([#10696](https://github.com/jdx/mise/pull/10696) by @jdx). - **aqua:** download private GitHub release assets via the API asset endpoint when the browser URL 404s ([#10622](https://github.com/jdx/mise/pull/10622) by @yacchi). - **brew-cask:** handle raw executable binaries, resolve `$APPDIR` paths, and use `ditto` for app bundle copying to avoid macOS "damaged app" errors ([#10626](https://github.com/jdx/mise/pull/10626) by @arthurh4). - **config:** preserve set values in `mise config set` for comma-separated set-typed settings ([#10647](https://github.com/jdx/mise/pull/10647) by @KrishRVH). - **config:** render `task_config.includes` templates with resolved `vars` ([#10700](https://github.com/jdx/mise/pull/10700) by @jdx). - **config:** support `required` validation and `redact = true` on `[vars]`; render tool option templates recursively ([#10697](https://github.com/jdx/mise/pull/10697) by @jdx). - **dotnet:** validate SDK installs with `dotnet --list-sdks` so `global.json` roll-forward no longer causes false failures ([#10691](https://github.com/jdx/mise/pull/10691) by @jdx). - **generate:** `mise generate tool-stub --lock` respects configured `lockfile_platforms` ([#10709](https://github.com/jdx/mise/pull/10709) by @JamBalaya56562). - **github:** handle missing/empty `url_api` in older lockfile entries, falling back to the cached browser URL ([#10703](https://github.com/jdx/mise/pull/10703) by @jdx). - **hooks:** set `MISE_INSTALLED_TOOLS=[]` on no-op installs so `postinstall` always receives a valid JSON array ([#10615](https://github.com/jdx/mise/pull/10615) by @JamBalaya56562). - **http:** don't let netrc credentials clobber explicit forge tokens on un-redirected URLs, fixing private GitHub release asset downloads ([#10713](https://github.com/jdx/mise/pull/10713) by @yacchi). - **lockfile:** merge platform data when a tool's options newly diverge from an empty on-disk entry (e.g. java `shorthand_vendor`), preventing checksum/URL loss ([#10710](https://github.com/jdx/mise/pull/10710) by @JamBalaya56562). - **npm:** map `allow_builds` to npm 11.16+ `--allow-scripts` / `--dangerously-allow-all-scripts` instead of forcing `--ignore-scripts` ([#10690](https://github.com/jdx/mise/pull/10690) by @jdx). - **oci:** canonicalize install paths when rebasing `PATH`, fixing `mise oci` on systems with symlinked `/home` (Bluefin/Silverblue) ([#10624](https://github.com/jdx/mise/pull/10624) by @salim-b). - **oci:** account for darwin mode stripping in layer test expectations ([#10681](https://github.com/jdx/mise/pull/10681) by @laozc). - **ruby:** stop forcing `no-yjit` Ruby builds on older glibc ([#10620](https://github.com/jdx/mise/pull/10620) by @jdx). - **sigstore:** retry GitHub attestation verification with the TUF trust root after embedded-root failures; workflow mismatches remain non-retryable ([#10695](https://github.com/jdx/mise/pull/10695) by @jdx). - **task:** render monorepo subproject task templates with the subproject's own `[env]`; broken subprojects no longer fail discovery repo-wide ([#10706](https://github.com/jdx/mise/pull/10706) by @jdx). - **task:** correct env used for the `task.show_full_cmd` setting ([#10714](https://github.com/jdx/mise/pull/10714) by @muzimuzhi). - **vfox:** Lua `os.getenv` now reads from mise's env table like `cmd.exec`/`os.execute` ([#10719](https://github.com/jdx/mise/pull/10719) by @jdx). - **watch:** forward `--ignore`, `--ignore-file`, and `--print-events` to watchexec ([#10629](https://github.com/jdx/mise/pull/10629) by @JamBalaya56562). - **windows:** allow GHCUp to be installed on Windows via aqua ([#10670](https://github.com/jdx/mise/pull/10670) by @cprecioso). - **copr:** drop retired Fedora 42 chroots from the default build list ([#10698](https://github.com/jdx/mise/pull/10698) by @jdx). ## Security - Ignore transitive `quick-xml` advisories RUSTSEC-2026-0194/-0195 pending upstream fixes ([#10717](https://github.com/jdx/mise/pull/10717) by @jdx). ## 💚 Sponsor mise mise is built by [@jdx](https://github.com/jdx) under [**en.dev**](https://en.dev) — an independent studio making developer tooling (mise, [aube](https://aube.en.dev/), and more). Development is funded by sponsors. If mise saves you or your team time, please consider sponsoring at [en.dev](https://en.dev). Individual and company sponsorships keep mise fast, free, and independent.